skip to main |
skip to sidebar
This post is about the nature of the information police officers rely on to get a magistrate to issue a search warrant.
As I’ve explained, the 4th Amendment’s default position is that to be “reasonable” a search (and seizure) must be conducted pursuant to a search (and seizure) warrant.
And as I noted in an earlier post, to get a warrant, officers must present the magistrate who an issue the warrant with information that establishes probable cause to believe evidence of a specific crime will be found in a particular place -- the place to be searched. If they do that, then the magistrate will issue the warrant. As I may have noted, probable cause is less than the beyond a reasonable doubt standard of proof used in criminal cases, and eve lower than the preponderance of the evidence standard used in civil cases. That makes sense because applications for and the issuance of search warrants takes place in a context that’s a lot more fluid than a civil or criminal trial. Police are investigating to see if they can bring criminal charges the validity of which will then be determined at a trial.The purpose of probable cause is to curb an officer’s discretion. As I may have noted, the 4th Amendment was adopted to abolish general warrants, a device British officers used in the colonial era. A general warrant was basically a blank check; it let an officer search anywhere just because he was so inclined. The colonists hated general warrants because they were easily abused. The 4th Amendment therefore requires that an officer get a search warrant – based on probable cause to believe evidence of a specific crime will be found in a specific place – before he can search that place. Requiring probable cause was not intended to prevent police officers from doing their jobs; it was intended to ensure that they could not search someone’s property on a whim.This post is a about a case that raised an issue related to probable cause: U.S. v. Silva, 2009 WL 1606453 (U.S. District Court for the Western District of Texas 2009). On May 5, 2008, federal agents obtained a search warrant for Fernando Silva’s home; they executed the warrant on May 6, seizing a computer, hard drives and thumb drives, among other things. On March 19, 2009, Silva was charged with possessing child pornography, and moved to suppress the evidence seized in the May 6 search.Silva argued the evidence should be suppressed because the “warrant lacked probable cause because the information relied upon was stale.” U.S. v. Silva, supra. The staleness principle adds a temporal element to the probable cause requirement. As one court noted, “[u]nder the staleness doctrine, `information supporting the . . . application for a warrant must show that probable cause exists at the time the warrant issues.’” U.S. v. Meryl, 2009 WL 943574 (U.S. Court of Appeals for the Eleventh Circuit 2009). The staleness doctrine is a matter of common sense: If an informant tells an officer that “a year ago they were selling drugs out of the house at 344 Brown Street, and I bought drugs from them”, that information probably can’t be used in establishing probable cause to search 344 Brown Street for drugs today. Because someone was selling drugs out of the house a year ago does not mean they’re selling drugs there today; to get a warrant to search 344 Brown Street, officers have to show probable cause to believe that drugs are being sold there now. Silva essentially claimed they hadn’t done that in his case.In analyzing the staleness issue, we start with the information the federal agents used to get the warrant. Here’s how the federal district court summarized what they had:Immigrations and Customs Enforcement (ICE) Special Agent Butler provided the Magistrate Judge a sworn affidavit. The affidavit stated that in April 2006, ICE began Operation Flicker, investigating a website known as the `Home Collection.’ The investigation revealed this organization was responsible for numerous commercial child pornography websites. Individuals would pay . . . $79.95 or $99.95 a month to gain access to the restricted websites. . . . [O]n January 18, 2007, the Defendant paid $99.95 to a PayPal account for Video Shop CD1, ID 1159. . . . The subject identifier 1159 refers to a child exploitation member restricted website known as `Video Shop CD 1.’ ICE agents purchased access to this member restricted website on February 12, 2007 and March 19, 2007. On these two occasions, the transaction was either identified by the subject identifier Video Shop CD1 or Item 1159. . . .
[O]n May 18, 2007, a summons was prepared and served on Time Warner requesting subscriber information for the Defendant's identity and residence. Time Warner confirmed that the Defendant was the subscriber and still had an active account. . . .
[O]n August 23, 2007, a Federal Grand Jury Subpoena was prepared and served on Wells Fargo Bank Texas, N.A., the financial institution responsible for issuing the check/debit card (# xxxx74013491xxxx) [redacted] to checking account number xxx-xxxxxxx. [redacted] On April 30, 2008, the account number was verified as belonging to the Defendant. The statement revealed that a check card purchase in the amount of $99.95 was debited by PayPal to Defendant's account. There was no information provided by Wells Fargo Bank that there had been any evidence of suspected fraud, identity theft, unauthorized use, or wrongful charges related to he purchase in question. A comparison of Webtrace records indicated the Defendant purchased access to a child pornography website on January 18, 2007. . . .
[A]gents in another investigation titled Operation FALCON identified Defendant as possibly . . . accessing suspected child pornography website on April 26, 2003 and May 20, 2003. The email account used to purchase access to the Operation FALCON website was the same account used to purchase access to the Video Shop CD 1 website. Defendant's current address was also identified by Operation Falcon at the time.
U.S. v. Silva, supra. The search warrant remember, issued on May 5, 2008. Silva said since “473 days had elapsed from when the illegal activity was discovered to the day the search warrant was issued,” the evidence was stale. U.S. v. Silva, supra. In ruling on Silva’s argument, the judge to whom the case is assigned pointed out that whether evidence used to obtain a warrant is stale is “not merely an exercise in counting the days or even months between the facts relied on and the issuance of the warrant.” U.S. v. Silva, supra. As the judge noted, the “age of inculpatory information” is only one facts in determining if a warrant was based on stale evidence:Staleness is to be determined on the facts of each case. A finding of staleness . . .can depend upon the nature of the unlawful activity, and when the information of the affidavit clearly shows a long-standing, ongoing pattern of criminal activity, even if fairly long periods of time have lapsed between the information and the issuance of the warrant. Information a year old is not necessarily stale as a matter of law, especially where child pornography is concerned.
U.S. v. Silva, supra. The judge found the evidence used in this case was not stale, and therefore could be used to establish probable cause for the warrant:[A]n investigation of child pornography involves a multitude of websites, companies, and individuals whose common goal is to elude detection. Given the complicated nature of a child pornography investigation, the evidence may take several months or years to accrue, and . . . may consist of bits and pieces from several camouflaged sources. It would frustrate the Fourth Amendment[] . . . to force those tasked with investigating child pornography to hastily charge an individual based upon incomplete and uncorroborated information because of fear that a more complete investigation would consume too much time, rendering some information stale and unable to support a search warrant. . . . [I]t is better [to give investigators] a reasonable amount of time so [they] may acquire as much corroborated information concerning the suspect and the alleged activity before taking the next step of entering his home or residence.
U.S. v. Silva, supra. In finding the evidence wasn’t stale, the judge also relied on the premise that information is less likely to be stale where the items sought in a search are of the type which could reasonably be expected to be kept in a particular location for long periods of time. At least one circuit has found that computer files are of a type that could be expected to be kept for long periods of time in the place to be searched.
U.S. v. Silva, supra. He also noted that evidence is “unlikely to be stale if it `clearly shows a long-standing, ongoing pattern of criminal activity”. U.S. v. Silva, supra. The judge found the evidence showed Silva purchased child pornography in 2007 and was “possibly purchasing child pornography” in 2003. U.S. v. Silva, supra. He also found that the information submitted in support of the warrant showed that the evidence being sought was of a type that could be expected to be kept for a long time: [T]he affidavit provided by Special Agent Butler . . . stated that persons involved in pornography and pedophilia tend to keep for long periods of time extensive pornography collections. This observation supports the conclusion that the more than a year gap between receipt of the information and issuance of the warrant is not excessive.
U.S. v. Silva, supra. As a matter of common sense, I suppose the judge is right. As he and other judges have noted, if the information law enforcement has shows someone is a collector of something, it’s reasonable to infer that they will hold on to that thing (or things of that types), even for a long time. And it probably makes sense to give law enforcement some latitude in investigations that involve concerted attempts to conceal online activity so they can satisfy the 4th Amendment’s requirements, instead of putting them in the position of having to act on inadequate information.
I’ve done several posts about trying to get the government to return computers and computer storage media it seized while executing a search warrant or pursuant to an exception to the 4th Amendment’s warrant requirement. As I explained, someone whose computer equipment was seized can file a motion for return of property to try to get it back. The motion can be filed by someone who was never charged with a crime or by someone who was charged based on evidence found in the seized property. When a person who was never charged files a motion for return of property, he’s essentially saying the government is holding onto his stuff for no reason. In other words, if there’s no criminal case, the government doesn’t need it. Someone who is being prosecuted based on evidence found in property seized from him usually begins by moving to suppress the evidence found in that property because his primary goal is to make it as difficult as possible for the prosecution to convict him. But those who have been charged can also file motions for the return of their property; they usually do this when the criminal case seems to be at an end, i.e., when the defendant has pled guilty or been convicted and has been sentenced. The rationale for the motion is that while the government needed the property while the case was pending, the case is over and the government’s authority to retain it has been exhausted. One more bit of preface and we’ll get to the case this post is about: As I noted in a recent post, whether seized property will be returned to its owner depends to a great extent on whether it’s “evidence” or “contraband.” If it’s evidence, you have a chance at getting the property back because, as I noted above, the government is only authorized to keep evidence as long as it has some need for it, i.e., while the case is pending. But if the property is contraband (child pornography, say), you have no chance of getting it back because it’s illegal to possess that kind of property. This brings us to Genao v. U.S., 2009 WL 1033384 (U.S. District Court for the Southern District of New York 2009). In 2005, a jury convicted Ismael Genao of “advertising child pornography in interstate commerce in violation of 18 U.S. Code § 2251(c) and transporting child pornography in interstate commerce in violation of 18 U.S. Code § 2252A(a)(1).” U.S. v. Genao, 224 Fed. Appx. 39 (U.S. Court of Appeals for the Second Circuit 2007). The criminal case began when, on the morning of March 6, 2003, AgentAndrews of the [FBI] . . . used a computer in her office to access a chat room on the Internet Relay Chat. While on the IRC, Agent Andrews went to a chat room named `100reTeenGirlSexPics’ that she knew from her experience was dedicated to child pornography. Upon going to that chat room, Agent Andrews saw that file servers. . . had posted advertisements seeking to exchange child pornography.
U.S. v. Genao, supra. Andrews stayed online investigating two servers that seemed to be offering child pornography; she signed off after she “download[ed] seven images of children engaged in sexually explicit conduct” from one of them. U.S. v. Genao, supra. Andrews traced the images to an account owned by Genao and on “April 14, 2003, the FBI executed a search warrant” at his apartment in Yonkers, “where agents seized Genao’s computer and multiple computer hard drives.” U.S. v. Genao, supra.Genao was convicted on both counts, sentenced and appealed his conviction to the Second Circuit Court of Appeals; on March 16, 2007, the Court of Appeals upheld the conviction. On September 1, 2008, he filed a motion seeking the return of property the FBI seized from his home. The property he sought fell into several categories, but we’re only concerned with three of them: “(1) one computer with two hard drives, (2) two separate external hard drives, (3) 118 compact discs”. Genao v. U.S., supra. In ruling on Genao’s motion, the federal district judge noted that Genao and the FBI agreed thatthe hard drives . . . are contraband, in that they contain encrypted files containing child pornography. The government contends that the three CDs (numbered QNY31, QNY 33 and QNY 34) seized by the FBI contain what were described at trial as Ghost Image files, which would allow a user to restore encrypted information from the hard drives. The Government argues . . . that . . . the CDs numbered QNY31, QNY33, and QNY 34, cannot be returned to Plaintiff because they are contraband.
Genao v. U.S, supra. As to the Ghost Image files, the judge noted that they are `used to copy a partition or hard drive into one huge file so it can be restored. If a hard drive should go bad or if a partition should go bad, the operating system or whatever it was on, that partition can be restored rather quickly.’ There were password protected Ghost files on several of the CDs but not the password for the encrypted material.
Genao v. U.S., supra. Genao responded to the FBI’s contraband claim by claimingevidence at trial showed (1) that the FBI has cracked the password on the Ghost files . . . on some of the CDs and (2) that an FBI agent testified that `no contraband was found in said Ghost files.’ Plaintiff asks the Court to order the Government to produce FBI Agent Friesen and Assistant United States Attorney Collins . . . to testify at a hearing that the FBI opened and checked each Ghost file found on . . . the CDs and found no such contraband. Plaintiff further requests that he participate in the hearing by telephone.
Genao v. U.S., supra. The FBI opposed Genao’s request for a hearing: “First, the Government contends that it is reasonable to assume that the Ghost Image Files may indeed contain child pornography, and second, it would take the FBI two or three years conduct this particular forensic examination in preparation for the proposed hearing by Plaintiff.” Genao v. U.S., supra. And the FBI won:Agent Friesen did testify . . . that someone . . . had cracked the password on the some of the encrypted Ghost Image Files and provided the password to him. However, he also testified that when representatives of the Government tried this password on files that were encrypted by PGP (`Pretty Good Privacy’), they could not open the files. Thus, the Court has been presented with no trial testimony . . . that these encrypted CDs do not contain contraband. Since the encryption would only serve to hide an illegal activity, there is a strong presumption that the encrypted CD's are contraband.
Furthermore, in his complaint, [Genao] acknowledged that the hard drives containing the encrypted material . . . should not be returned to him. Since the CDs containing encrypted materials (QNY31, QNY33, and QNY34) can be used to restore the images encrypted on the hard drives . . . there is strong circumstantial evidence that the encrypted Ghost Image Files on CDs QNY31, QNY33, and QNY34 contain images [he] encrypted in an attempt to hide his alleged activity. The Court finds that the CDs contain contraband, and since [Genao] has offered no evidence to show that the encrypted materials on CDs QNY31, QNY33, and QNY34 do not contain pornographic materials, denies [his] demand for a hearing and dismisses [his] claim for return of those CDs.
Genao v. U.S., supra.So Genao lost because he couldn’t prove the encrypted data on the CDs did not include child pornography. I find that interesting because according to the leading expert on 4th Amendment law, when someone moves for the return of property AFTER the criminal case is over (as it was here), the government has the burden of proving that the property should not be returned because it’s contraband. Wayne R. LaVafe. Search and Seizure: A Treatise on the Fourth Amendment § 11.2(i) (4th ed. Thomson West 2008). He cites a couple of U.S. Court of Appeals cases which held that once the criminal case is over, the person from whom the property was seized is presumed to have a right to its return; to overcome that presumption, the government has to prove, by a preponderance of the evidence, that it cannot be returned because it’s contraband. Did the government do that here? The federal judge seems to have relied on another presumption – the presumption that the only reason to use encryption is to hide illegal activity – to find that it did. I don’t know what I think of that result.It’s an interesting issue: If the government seizes my property and I move to have it returned, either because I haven’t been charged or because I’ve been charged and convicted, can the government justifiably defeat my motion by showing that there are encrypted files on the computer and that, inferentially, the only reason to encrypt files is to conceal evidence of illegal activity? Do I have to give up the encryption key and let the government examine the files to prevail on my motion and get my property back?
This post is about an opinion a federal judge issued a little less than a year ago. It deals with some interesting issues involving the application of the general federal computer crimes statute: 18 U.S. Code § 1030.The case is U.S. v. Lanam, 2008 WL 2705514 (U.S. District Court for the Eastern District of Michigan 2008), and this is how it arose:In March 2006, [Kirk] Lanam was indicted on six counts of unauthorized computer intrusion in violation of 18 U.S.C. § 1030(a)(5)(A) (i). The government later voluntarily dismissed three of the six counts.
The remaining three counts asserted that Lanam: (1) accessed the computer system of Total Mortgage Corporation (`Total’) without authorization and entered `ping flood’ commands that rendered Total's telephone system inoperative; (2) accessed Total's computer system without authorization and disabled the `firewall,’ thereby rendering the system vulnerable to subsequent attacks via the Internet; and (3) accessed the computer system of Air Source One, Inc. without authorization in order to gain access to Total's computer system.
U.S. v. Lanam, supra. Lanam went to trial and was convicted on all three counts.
After being convicted, he “move[d] for relief pursuant to” 22 U.S. Code § 2255, which is the federal habeas statute. As Wikipedia explains, habeas corpus “is an action often taken after sentencing by a defendant who seeks relief for some perceived error in his criminal trial.” In his habeas petition, Lanam asked for a new trial based on any or all of three reasons: his attorney was ineffective; the evidence was not sufficient to support the convictions; and the indictment was multiplicitous. We’re not concerned with the first argument; we’ll focus on the other two.
To understand Lanam’s second argument, I need to review the prior and current versions of 18 U.S. Code § 1030(a)(5). Until last September, § 1030(a)(5)(A)(i), the statute Lanam was convicted under, required (i) that the defendant have launched a DDoS attack on a computer system or accessed the system without being authorized to do so AND (ii) that by doing either or both he caused “loss to 1 or more persons during any 1-year period (and . . . loss resulting from a related course of conduct affecting 1 or more other protected computers) aggregating at least $5,000 in value”.
Section 1030(a)(b) was revised last September, and one of the revisions eliminated the $5,000 requirement, which means it doesn’t apply to cases brought after September 26, 2008. Lanam, though, was indicted prior to September 26, 2008, so he was charged under the earlier version of the statute, which means that the caused “loss to 1 or more persons” provision applied to him. In challenging his conviction he initially argued “that the evidence adduced at trial was not sufficient to support the statutory loss element of $5,000 for any of the three counts on which he was convicted.” U.S. v. Lanam, supra.
The federal judge, though, found that § 1030(a)(5) “does not require a $5,000 loss stemming only from the conduct underlying each individual count of unauthorized intrusion. Rather, the statute requires only a total loss of $5,000, which may be aggregated based on the conduct charged and any related course of conduct during a one-year period. U.S. v. Lanam, supra. Lanam subsequently conceded that §1020(a)(5) only required aggregate loss totaling at least $5,000, but then argued that “the indictment was drafted in such a way that the government was required to prove a $5,000 loss stemming from each particular count.” U.S. v. Lanam, supra.
The federal judge didn’t agree. The judge began by noting that Count One of the indictment against Lanam read as follows:
On or about March 1, 2005 in the Eastern District of Michigan and elsewhere, Kirk Lanam . . . did knowingly cause the transmission of a computer command, and as a result . . . intentionally caused damage without authorization, to a protected computer, by accessing the computer system of Total Mortgage Corporation, which computer was used in interstate commerce, and entering commands that rendered Total Mortgage's telephone system inoperative that caused costs to be incurred . . . over $5,000, all in violation of Title 18, United States Code, [Section] 1030(a)(5)(A)(i).
U.S. v. Lanam, supra. The judge then noted that the other counts were phrased in an essentially identical manner.
The indictment is vague in that it does not explicitly state that the $5,000 loss may be aggregated from a related course of conduct. However, Lanam cites no law to support his contention that the sort of inartful drafting evident in this indictment may work to redefine the statutory elements of a crime. U.S. v. Lanam, supra. The judge found Lanam was not entitled to a new trial based on this claim because there was “no suggestion that the indictment failed to charge an essential element of the crime or to provide Lanam with fair notice of the charges against him.” U.S. v. Lanam, supra.
Since the judge found the losses resulting from the charges in the indictment “and any related course of conduct during a one-year period” could be aggregated, he rejected Lanam’s second argument for a new trial.
As I noted above, Lanam’s third and final argument was that the counts in the indictment were multiplicitous. As I explained in a post I did last year, multiplicity is an error in the structure of a charging document, such as an indictment. Multiplicity is often described, in a phrase I like, as “impermissibly fractionating a single course of conduct into multiple offenses.” It means the prosecution breaks what is really one crime up into pieces, and charges the pieces in different counts of an indictment. So when a prosecutor creates a multiplicitous indictment, the effect is to multiply the criminal liability the defendant faces in a manner that’s inconsistent with the level of “harm” he or she actually caused.
The federal judge summarily disposed of Lanam’s multiplicity argument:Lanam . . . argue[s] that if the loss element may be aggregated based on the conduct charged and any related course of conduct within a one-year period, the indictment is multiplicitous and violates . . . the Fifth Amendment. The . . . rule against multiplicity is properly invoked where a single illegal act is charged under more than one count, such that the defendant may be punished twice for the same crime. . . . Lanam's argument . . . is meritless because, although the losses from his conduct may be aggregated, each count of the indictment charged Lanam with committing a separate and discrete act of unauthorized intrusion.
U.S. v. Lanam, supra. It looks like Lanam ultimately decided this issue was a lost cause. Last September, he filed a motion to appeal the judge’s ruling on the ineffective assistance of counsel issue (only); last September the federal district court granted him a Certificate of Appealability, which a defendant must obtain in order to appeal a federal district court’s ruling on a claim in a habeas petition. Since Lanam didn’t include the multiplicity argument in the issues he intends to appeal, he presumably thought he didn’t have a chance of winning on that issue.
I suspect he didn’t. While I can see the argument that if the government can aggregate the loss resulting from all 3 crimes to satisfy the $5,000 requirement as to each crime, it’s essentially breaking a single crime (which would consist of the sum total of the actions that inflicted the $5,000+ loss) into parts, the argument doesn’t work in the end. The reason it doesn’t work is that when Congress revised 18 U.S. Code § 1030 in 1986, it added a jurisdictional damage requirement of $1,000 to limit the use of the statute:
The [Senate Judiciary] Committee believes this threshold is necessary to prevent the bringing of felony-level charges against every individual who modified another’s computer data. Some modifications or alterations, while constituting `damage’ in a sense, do not warrant felony-level punishment, particularly when almost no effort or expense is required to restore the affected data to its original condition
U.S. Senate Report No. 99-432, 1986 U.S. Code Congressional and Administrative News, pp. 2479-2496 (1986). Since the $1,000 (later $5,000) requirement was simply a threshold requirement for establishing federal jurisdiction to prosecute a person for one of the § 1030(a)(5) crimes, it wasn’t one of the elements of those crimes and therefore couldn’t support a multiplicity claim.
And as noted earlier, last September Congress eliminated any possibility of basing a multiplicity claim on the government’s aggregating the “loss” resulting from a series of crimes to satisfy the jurisdictional requirement by revising § 1030. One revision moved the “loss . . . aggregating at least $5,000 in value” provision that had been in § 1030(a)(5) to 18 U.S. Code § 1030(c). It’s now a sentencing provision; section 1030(c)(4)(A), one who gains unauthorized access to a computer can be sentenced to a fine and/or imprisonment for “not more than 5 years” if the crime caused loss “during any 1-year period” that aggregated “at least $5,000 in value”.
Why did Congress do that? I can’t say for sure. The revision clearly eliminated any possibility that a defendant could use the multiplicity argument if the government decided to aggregate loss across the counts of an indictment in order to establish the $5,00 loss requirement. Prior to the revision, some argued that the placement of the $5,000 requirement in the part of the statute that defined the unauthorized intrusion and DDoS crimes did, in fact, transform it into an element of the offense. I don’t really buy that argument because it’s clear the loss requirement was added, originally, to limit the use of the statute, which makes it a jurisdictional provision, not an offense element.Anecdotally, I’ve heard Congress eliminated the $5,000 requirement as a condition for bringing a prosecution in order to give federal prosecutors the ability to use § 1030 against people who gain unauthorized access to computers and/or hit them with DDoS attacks but do not cause $5,000 in loss, not even in the aggregate. I think that’s the real reason Congress made this change; in other words, Congress reversed the position it took in 1986, when it revised the original, 1984 version of § 1030.Because § 1030 now CAN be used against defendants who violate its provisions but don’t cause $5,000 in loss, does that mean we’ll see it being used a lot more often? I doubt it; I don’t think Congress meant to create the opportunity for a flood of § 1030 prosecutions. I think the goal was to give federal prosecutors the ability to use the statute in particular cases where, in their opinion, circumstances other than the amount of loss inflicted justified bringing a federal prosecution. I suspect they’ll use the new latitude they have carefully. Does that mean a federal prosecutor couldn’t abuse that latitude to prosecute someone under § 1030 when the nature of the “harm” – the loss – really doesn’t justify it? No, it doesn’t. Federal prosecutors have a great deal of discretion in deciding what cases they want to pursue, so such a scenario is at least conceivable. I, though, think it’s unlikely.
In a sense, this post is about the need for -- and difficulty of -- drafting criminal statutes that define crimes with precision while still addressing the "harm" to be outlawed,
As you may have noticed, I seldom do posts on child pornography or child exploitation cases . . . not because the “harm” involved isn’t important, but because the defendants tend to be so inept (to put it kindly) that the legal issues just aren’t novel or complex.
This post is about an Indiana defendant who appealed his conviction for child exploitation and a related charge, and won . . . by successfully challenging the substance and application of the statutes at issue. The case is Salter v. State, 2009 WL 1409484 (Indiana Court of Appeals 2009), and here are the facts that led to the charges:In the fall of 2006, the Indianapolis Police Department received information from Delaware authorities that Salter had been having communications of a sexual nature with M.B., a girl in Delaware who was under . . . eighteen. On October 23, IPD officers obtained and executed a search warrant at Salter's house. . . . [They] seized computer towers, CDs, DVDs . . . and miscellaneous documents. Upon searching . . . two of the CDs, officers discovered thirty-eight images of M.B., fully or partially nude, eight images of other nude `prepubescent’ children, and five images of Salter's genitals. In addition, Delaware State Police found the images of Salter's genitals on M.B.'s computer.
State v. Salter, supra. Salter was charged with 46 counts of child exploitation plus 5 counts of disseminating matter harmful to minors. The child exploitation charges were brought under Indiana Code § 35-42-4-4(b)(1), which provides as follows: A person who knowingly or intentionally . . ., exhibits, photographs, films, videotapes, or creates a digitized image of any performance or incident that includes sexual conduct by a child under eighteen (18) years of age . . . commits child exploitation, a Class C felony.
The disseminating material harmful to minors charge was brought under Indiana Code § 35-49-3-3((a)(1), which provides as follows: “[A] person who knowingly or intentionally . . . disseminates matter to minors that is harmful to minors . . . commits a Class D felony.” To constitute material harmful to minors, the material disseminated must (i) be obscene, (ii) be child pornography or (iii) the person who sent the material must have sent it to “ a child less than eighteen (18) years of age believing of intending that the recipient is a child less than eighteen (18) years of age.” Indiana Code § 34-49-3-3(b). Salter was tried by a judge, not a jury, and convicted on 35 of the 46 counts. The counts he was convicted of included both child exploitation and disseminating material harmful to minors. State v. Salter, supra. As I may have mentioned, defense attorneys often go with a bench trial (trial by a judge) instead of a jury trial when the charges involve issues a jury is likely to find distasteful and the defense is based primarily on legal issues. My guess is that this is why Salter went with a bench trial, instead of a jury trial. On appeal, Salter challenged the legal sufficiency of the charges under both statutes. That means he isn’t challenging the facts; instead, he’s basically saying, “even if I did what you claim I did, it wasn’t a crime” (or maybe, more precisely, “it wasn’t the crime you charged me with”). If the charge is invalid, then the conviction can’t stand. As to the child exploitation charge, Salter argued that “the State's attempt to include downloading an electronic image and saving it on a CD in the definition of `creates a digitized image’ exceeds the permissible scope of the child exploitation statute.” State v. Salter, supra. In response, the prosecution argued that “a person who uses a computer to download an electronic image and save it on a CD `creates a digitized image’ as that phrase is used in Indiana Code subsection 35-42-4-4(b).” State v. Salter, supra. In deciding which argument was correct, the Court of Appeals reviewed the history of Indiana Code § 35-42-4-4(b). The version of the statute that was originally adopted in 1978 created only one crime, which it defined as follows: “A person who knowingly or intentionally photographs, films, or videotapes a child under sixteen (16) years of age while the child is performing or submitting to” sexual intercourse or other sexual activity “commits child exploitation, a Class D felony.” The Court of Appeals noted that the current version of the statute creates two crimes: child exploitation (which is defined above); and possession of child pornography. State v. Salter, supra. The court found that the legislature’s addition of the second offense indicated that it had “for good reason, decided to punish the production and distribution of child pornography more broadly -- extending to matter portraying sixteen and seventeen year olds -- and more severely -- Class C felony -- than mere possession of child pornography, which concerns only children under sixteen and is a Class D felony.” State v. Salter, supra.The Court of Appeals then looked at two cases from other states – a New Jersey case and a Maryland case – that dealt with essentially the same issue. Both of those courts held that “a person who prints an image from a computer or who downloads an image onto a computer does not `create’ the image. The image was already created. All the person is doing is saving a copy of the image.” The Indiana Court of Appeals therefore reached the same conclusion in the Salter case, noting that someone who opens an e-mail and saves an attached picture to his computer or a CD `creates’ something. He `creates’ a new unit of data on the computer or a file on a CD that was not there before. But is that what our legislature meant by `creates a digitized image of’?
To answer that question, we need look no further than the original statute, which was written to punish the photographing, the filming, and the videotaping of sexual activity involving a child. . . . [T]his was . . . aimed at eliminating the initial creation of these images, i.e., the original act of recording. Until the late 1990s, the only way to do so was to use a camera along with film or tape. But. . .`modern digital cameras do not use any kind of film, but record real-life images directly in digital form.’ . . . Because people who digitally record a performance or incident are not technically photographing, filming, or videotaping, our legislature acted to close a possible loophole for users of modern digital devices. As technology evolved, so did the statute. . . .
[T]he aim of statutes like ours . . . is the same: to stop the creation of child pornography. Here, Salter did not `create’ any of the images underlying Counts 1-46; M.B. created the thirty-eight pictures of herself, and some unknown person created the eight images of the other children before they were posted on the nudist websites visited by Salter. By downloading the images . . . and burning them onto CDs, Salter only saved copies of them, i.e., he possessed them.
Salter v. State, supra. The Court of Appeals therefore reversed Salter’s convictions on the child exploitation counts. It also addressed the possibility of charging him with possession of child pornography:As for the images of M.B., he has committed no crime. The State concedes M.B. was sixteen when she took the pictures of herself, and Indiana's possession of child pornography statute only extends to children under sixteen. . . . The children in the other eight images all appear to be under sixteen, but the State might implicate Indiana's Successive Prosecution Statute if it chooses to charge Salter with possession of child pornography based on those images. . . .
State v. Salter, supra. As to the 8 images of children that appear to be under 16, the court is saying that the State probably has a double jeopardy problem here, i.e., it prosecuted him for SOME crimes based on those images, and that probably means he cannot be prosecuted for other crimes based on the same images.Finally, Salter argued that the charges for disseminating material harmful to minors were void for vagueness and therefore unconstitutional. As the Court of Appeals explained, under the constitutional guarantee of due process established by the 14th Amendment, a penal statute is void for vagueness if it does not clearly define its prohibitions. . . . A penal statute must give a person of ordinary intelligence fair notice that his . . . conduct is forbidden so no man shall be held criminally responsible for conduct which he could not reasonably understand to be proscribed.
State v. Salter, supra. Salter’s argument here was based on this Indiana statute: “A person at least eighteen . . . who, with a child . . . less than sixteen . . ., performs or submits to sexual intercourse commits” what is usually known as statutory rape. Indiana Code § 35-42-4-9(a). Salter did not denythat he disseminated or displayed `matter’ to M.B. or that M.B. was a `minor’ for purposes of the statute. Rather, he contends that `[n]o person of ordinary intelligence would think that he could legally have sexual relations with another person, but could not send that same person an electronic image of his genitals. We understand Salter's argument to be that he had no way of knowing that pictures of his genitals would be considered `harmful’ to M.B., given that, under Indiana law, he could have been naked in front of M.B. and had sex with her without violating any law.
State v. Salter, supra. The Court of Appeals agreed:Such sexual activity could involve varying degrees of nudity and necessarily involves some exposure of the genitals. By setting the legal age of consent at sixteen, the Indiana legislature has made an implied policy choice that in-person viewing of another person's genitals is `suitable matter’ for a sixteen- or seventeen-year-old child. That being so, how could Salter have known that a picture of his genitals would be `harmful’ . . . for M.B.? . . . [I]f such images are harmful to sixteen- and seventeen-year-old children, then why would our legislature allow those children to view the same matter in-person, in the course of sexual activity? These questions reveal the flaw in Indiana Code section 35-49-3-3 as applied to Salter: it did not provide him with fair notice that the State would consider pictures of his genitals harmful to or unsuitable for a sixteen-year-old girl.
State v. Salter, supra. The Court of Appeals therefore reversed the convictions on the disseminating material harmful to minors charges, as well.
This is another post about how technology can make it difficult to decide if something is or is not "private."
I’m going to speculate about cloud computing and the 4th Amendment’s protecting us from “unreasonable” searches and seizures. The issue briefly came up at a meeting I attended last week, as one of the so-far unresolved issues evolving technology raises. As I’ve explained in earlier posts, the 4th Amendment protects us from “unreasonable” searches and seizures; as I’ve also explained, the 4th Amendment’s guarantees only apply to state action, i.e., to searches and seizures conducted by law enforcement officers or other agents of the government. It follows, then, that the 4th Amendment doesn’t apply (i) if there isn’t a “search” or a “seizure;” or (ii) if the search or seizure is carried out by a private citizen, not an agent of the government. As I’ve explained, a “search” violates what the U.S. Supreme Court calls a reasonable expectation of privacy. Under the Supreme Court’s decision in Katz v. U.S., 389 U.S. 347 (1967), I have a reasonable expectation of privacy in a place or thing if (i) I think it’s private and (ii) society agrees that it’s private. So in the Katz case, the Court held that Katz had a reasonable expectation of privacy in the content of calls he made from a phone booth; he thought his calls were private, and the Court found that society (at least in 1967) agreed. A reasonable expectation of privacy is just that; it’s not a PERFECT expectation of privacy (though a perfect expectation of privacy would be a reasonable expectation). A perfect expectation of privacy would require that you do something to put the information you want to protect completely beyond the government’s reach; encrypting your data with a very secure encryption system would presumably create a perfect expectation of privacy.
The Supreme Court, however, has never imposed such a demanding and unrealistic standard because it would create a truly adversarial relationship between citizens and the government; that is, I would not be able to assume privacy based on my taking reasonable steps (like keeping my laptop in my home) to prevent the government from gaining access to my property or communications. As 4th Amendment law stands now, if we make a good-faith (reasonable) effort to keep our property or communications private, that’s enough; once we establish a 4th Amendment expectation of privacy in, say, a laptop, the government’s accessing the laptop becomes a search, which means the government has to get a search warrant or be able to rely on an exception to the warrant requirement (such as consent) to get into the laptop. As I’ve explained before, a seizure of property occurs when the government interferes with my possession and use of that property (by, say, taking it from me). As I’ve noted before, my favorite 4th Amendment seizure case is Soldal v. Cook County, 506 U.S. 56 (1992). In Soldal, the Cook County Sheriff and some of his deputies helped the owner of a trailer park tow the Soldals’ mobile home from where it had been parked on a lot in a mobile harm park. The owner of the park claimed she had the right to evict the Soldals – which involved evicting their mobile home – and relied on the law enforcement officers to keep Mr. Soldal from interfering.
The Soldals brought a civil rights suit, claiming that towing away their mobile home was an unlawful seizure under the 4th Amendment. It was clear there was state action (the Sheriff and his deputies), but for some reason the issue as to whether towing the mobile home was a 4th Amendment seizure went all the way to the U.S. Supreme Court. Sure enough, the Court said it was a seizure; how it could have been anything else is beyond me. If you tow away someone’s home, you’ve clearly interfered with their right to possess and use that property. All right, enough 4th Amendment context. Let’s talk about cloud computing. Specifically, let’s talk about whether I would have a 4th Amendment expectation of privacy in data I store in the cloud. As I explained in a law review article, the 4th Amendment was developed at a time when the only privacy was spatial privacy; for something to be private, I had to keep it IN my home or office (and maybe in a locked chest), which both made it difficult for law enforcement officers to gain access to it and symbolically invoked my right to assume they wouldn’t gain access to it. (In other words, I could assume privacy.) As I explained in that article, our lives have already moved far beyond spatial privacy; I talked about the 4th Amendment’s application to the contents of emails and what we do online -- arguing that it should apply to both, but noting that courts so far do not tend to agree. I think cloud computing will take this analysis to the next level. Currently, courts treat data containers – laptops, cell-phones, Blackberries, etc. – as “closed containers” analogous to a locked chest or, as one court said, a footlocker. Under the 4th Amendment, we’ve always have a constitutional expectation of privacy in containers, including opaque containers we carry around with us; a police officer cannot, for example, demand that you open your briefcase so he can look through it. Since you have a 4th Amendment expectation of privacy in the briefcase (a closed container), he has to get a search warrant or your consent to look through it. As I’ve explained in several posts, courts tend to analogize what we do online to our use of the U.S. mail; I think that analogy is valid to some extent because like sending a letter, emailing and surfing the web involve sending information via a third-party party. One problem I see with the analogy is that the U.S. mail is operated by the government, which means we’re sharing whatever information or property we send with agents of the government. When I email or do other things online, I share information with a privacy company, which I think differentiates online activity from the use of the mail, but so far no court has bought that proposition. Actually, courts tend to rely on two analogies in analyzing what we do online: One is, as I noted, our use of the mails; as I explained in an earlier post, in a nineteenth-century decision, the Supreme Court held that sealed letters and packages are protected by the 4th Amendment, but postcards are not. Sealed items are protected because we have made an effort to protect their contents from postal employees; they are, in effect, “closed containers.” The other analogy derives from the 1979 Smith v. Maryland case, in which the Court held that we have no 4th Amendment expectation of privacy in the numbers we dial from our telephones, even our home phones, because we voluntarily give that information to the phone company. According to the Smith Court, by giving that information to the phone company, we assume the risk the phone company will give it to the government, which means any expectation of privacy we have in it isn’t reasonable. What about privacy in an era of cloud computing? If I store my data in a cloud, is the data in a “closed container” and therefore private under the 4th Amendment? Or is putting data in a cloud analogous to giving the numbers I dial on my phone to the phone company? If courts decide the latter analogy is the correct one, then by putting data in a cloud I lose any 4th Amendment expectation of privacy in it unless and until the Supreme Court takes up this issue and holds otherwise. I can also see prosecutors making a third argument as to why cloud data is not protected by the 4th Amendment: They can say that data I store in a cloud is analogous to a postcard; that is, they can say that by giving the data to a third-party, I assume the risk that employees of the cloud computing service will access it and share it with law enforcement. I don’t think the third argument works: It think putting data in a cloud creates a bailment relationship between the cloud computing company (and its employees). As I explained in an earlier post, in a bailment relationship, I give my property to someone so they can hold onto it for me (a storage service, say) or transport it for me (Fed Ex, say). As I noted in that post, in a bailment I transfer possession of the property for a specific purpose and a limited time; I still retain ownership of the property, and the bailor (the person who has taken possession of it) doesn’t have the right to sell it or access it if I haven’t specifically authorized that. I also think the validity of the third argument depends on the extent to which the data I store in a cloud is secure from the cloud computing company and its employees. If they can read the contents of the data I’ve stored with them, then I can’t have a 4th Amendment expectation of privacy in that data; it’s essentially the equivalent of sending a postcard through the mail (only worse, because I’m leaving it with the cloud computing service for a lot longer than it takes a mail to travel from sender to recipient). I don’t think putting data in a cloud is the equivalent of sharing the numbers I dial on my phone with the phone company because to use the phone company’s service, I HAVE to give it those numbers. The phone company’s systems can’t connect my calls if I don’t let them know what phone number I’m calling and what phone number I’m calling from. Since all I’m doing in cloud computing is storing data on a system, I don’t see that I’m sharing it with the owner of the cloud computing service and its employees, unless, of course, the data isn’t encrypted or otherwise sealed in a virtual “closed container.” If it’s in a sealed, functionally-opaque container, then the neither the owner of the system nor its employees can read my data; it again is analogous to sending a sealed letter. My point is that even under current 4th Amendment law, I can make what I think are valid arguments as to why the 4th Amendment should apply to data stored in a cloud (as long as the appropriate conditions exist). I really think, though, that we shouldn’t be using cases that were decided thirty years ago or a hundred and thirty years ago to set the standard for 4th Amendment privacy in an era of advancing technology. As I argued in that law review article, I think we need to move beyond a purely spatial approach to privacy to approaches that encompass both spatial and non-spatial privacy.
Last year, I did a post (one of several I’ve done) on border searches, i.e., on the exception to the 4th Amendment’s warrant requirement that encompasses searching the luggage – and laptops – of people entering or leaving the United States.
In that post, I talked about a new policy – the Policy Regarding Border Search of Information – that had just been adopted by U.S. Customs.As I noted in that post, the policy implements the border search exception but carves out exceptions (exceptions to the exception, I guess) for certain kinds of information:The policy then includes sections dealing with particular types of data, such as business information (trade secrets, etc. . . . try to prevent unauthorized disclosure), attorney-client privileged information (try to preserve the privilege) and sealed letters (can’t be searched without first getting a search warrant, because mail is protected under another 4th Amendment principle).
Crossing Borders (August 4, 2008). A few days ago, someone posted this comment on what I said in that post:I note you mention 'sealed letters' as mail being protected from search as a person crosses the border.
Does it seem like there would be some sort of angle where placing a laptop inside a large envelope, addressing it and stamping it would give it some protection from a search?
Anonymous (May 30, 2009).Anonymous raises a really good point which, I’m afraid, won’t work. It’s a perfectly logical argument, but sometimes law isn’t logical – or, more accurately, law doesn’t seem to be logical because there are so many complementary and interacting rules it’s difficult to apply straight logic to issues, sometimes. I posted a brief response to Anonymous’ comment. In this post, I’m going to try to explain why the option he/she suggests won’t work in practice. Let’s start with the 4th Amendment and mail. As I explained in an earlier post, in 1877, in a case called Ex parte Jackson, the Supreme Court held that we have a 4th Amendment expectation of privacy in sealed letters (not postcards) and packages we send through the U.S. mails, which means police have to get a search warrant to open a letter or package while it’s in transit. Jackson applies to searches of mail traveling within U.S. borders. Later cases raised the issue of whether it trumps the border search exception, which would mean officers would have to get a search warrant to open and read mail traveling into or out of the United States. The Supreme Court dealt with this issue in U.S. v. Ramsey, 432 U.S. 606 (1977). Customs Inspector George Kallnischkies was inspecting a sack of incominginternational mail from Thailand [when he] spotted eight envelopes that were bulky and which he believed might contain merchandise. The envelopes, all of which appeared . . . to have been typed on the same typewriter, were addressed to four different locations in the Washington, D. C., area. . . . Kallnischkies, based on the fact that the letters were from Thailand, a known source of narcotics, and were `rather bulky,’ suspected the envelopes might contain . . . contraband rather than correspondence. He took the letters to an examining area . . . and felt one of the[m]: It `felt like there was something in there. . . . It was not just plain paper that the envelope is supposed to contain.’ He weighed one of the envelopes, and found it weighed . . . some three to six times the normal weight of an airmail letter. Inspector Kallnischkies then opened that envelope [and found heroin].
U.S. v. Ramsey, supra. Federal agents arrested Ramsey, the intended recipient of the envelopes; he was subsequently indicted for drug smuggling. He moved to suppress the heroin found in the envelopes under Ex parte Jackson; that is, Ramsey claimed the Customs Inspector needed a warrant to open the envelopes. The Court of Appeals for the D.C. Circuit agreed, and the case went to the Supreme Court.The Supreme Court did not directly address the constitutional issue. It held that the search of the envelopes was lawful under 19 U.S. Code § 482(a) which says that the officers who areauthorized to . . . search vessels may stop, search, and examine . . . any vehicle . . . or person, on which or whom he or they shall suspect there is merchandise which . . . shall have been introduced into the United States in any manner contrary to law . . . and to search any trunk or envelope . . .in which he may have a reasonable cause to suspect there is merchandise which was imported contrary to law.
The Ramsey Court held that since Kallnischkies had “reasonable cause” to believe contraband was in the envelope, the “search, therefore, was plainly authorized by the statute.” U.S. v. Ramsey, supra. The Court had this to say about the 4th Amendment:Since the search . . . was authorized by statute, we are left simply with the question of whether the search, nevertheless violated the Constitution. . . . [W]e need not decide whether Congress conceived the statute as a necessary precondition to the validity of the search or whether it was viewed, instead, as a limitation on otherwise existing authority of the Executive. Having acted pursuant to, and within the scope of, a congressional Act, Inspector Kallnischkies' searches were permissible unless they violated the Constitution.
U.S. v. Ramsey, supra. What the Court is saying in this paragraph is that the statute might be implementing the 4th Amendment (which means the search was valid under both the statute and the 4th Amendment) or it might be giving us more protection than the 4th Amendment, in which case the search would still be valid. As I may have mentioned, constitutional provisions like the 4th Amendment set the baseline of protection – the absolute minimum of protection – for privacy and other rights. Congress can give us more privacy (or more protection for other rights) by adopting statutes and implementing federal regulations. If, in enacting 19 U.S. Code § 482, Congress gave us more protection than we get under the 4th Amendment, then the search could not have been unconstitutional. If Congress meant for the statute to simply implement what the 4th Amendment requires, then Ramsey still could not complain AND we know that mail searches do not fall automatically under the border search exception.
Under our current understanding of the law, an officer can conduct a routine border search of luggage merely because he wants to; the Customs agent doesn’t have to show he had probable cause or reasonable cause to believe there was contraband inside the luggage. If § 482 implements the 4th Amendment, an agent can’t search mail just because he wants to; he has to have reasonable cause to believe there’s contraband inside. It’s been 32 years since the Court decided Ramsey, and we still don’t know if § 482 implements the 4th Amendment or goes beyond it. To makes things more complicated, § 145.3(b) of Title 19 of the Code of Federal Regulations provides as follows:No Customs officer or employee shall open sealed letter class mail which appears to contain only correspondence unless prior to the opening:
(1) A search warrant authorizing that action has been obtained from an appropriate judge of United States magistrate, or
(2) The sender or the addressee has given written authorization for the opening.
Section 145.3(c) of Title 19 of the Code fo Federal Regulations imposes the same restrictions on a Customs officer’s reading “any correspondence contained in letter class mail”. The Ramsey Court cited both of these regulations, but didn’t seem to find that they had any particular bearing on the case, presumably because there’s regulations and § 482 is a federal statute (or maybe for some other reason – I don’t claim to be an expert on federal postal regulations). So where does that leave us with the original question, i.e., whether sealing a laptop in an addressed, sealed and stamped envelope would protect it from a border search. To implicate the application of the border search exception to mail issue, we have to have “mail.” Mail is “[a]nything sent through the postal system”. If you’re carrying it, then it’s not “mail”, it’s luggage, and the border exception applies with full force to luggage.As I noted in my response to Anonymous’ comment, the Ex parte Jackson holding is based on the fact that mail – like FedEx and other transactions – is a bailment. In a bailment one person transfers possession – but not ownership – of property to another, usually for a limited purpose. If you’ve ever left a bag with a bellman while you’re in a meeting, that’s a bailment; the bellman has possession of the bag till you get back, but that doesn’t entitle him to open it or sell it or give it away. When we send things through the mail, that’s a bailment. The Postal Service has my letter; I do not. In Ex parte Jackson, the Supreme Court applied the 4th Amendment to the bailment that results when we mail a letter or a package. If I’m carrying a laptop in a sealed, addressed and stamped envelope, that isn’t a mail bailment because I haven’t turned the laptop over to the Postal Service. So Ex parte Jackson doesn’t apply; as I noted earlier, the laptop is luggage and the border search exception applies to it.
This post is about a case that doesn’t raise any interesting legal issues. It’s just really creepy, so I decided to write about it.The case is Thompson v. State, 2009 WL 1382020 (Court of Appeals of Texas – Houston 2009). Earl Thompson appealed his conviction for stalking (and for unlawfully carrying a weapon in a liquor-licensed premises, but we’re not interested in that one), which arose from these facts:On October 25, 2006, [Thompson] began sending Suzi Hanks, a Houston radio personality, a series of strange and threatening emails. The emails included references to guns, Jack the Ripper, and a bronze chariot; they also contained sexual innuendos. In the emails, [Thompson] used the names Earl Thompson, Mystery Knight, Knights Elite, Saucy Jack, Black Jack, and Jack Porns. These emails made Hanks `very afraid,’ and she told her supervisor about them and reported the situation to the Pasadena Police Department. Hanks did not respond to any of the emails, which prompted [Thompson] to make numerous unsuccessful attempts to telephone her at the radio station where she worked.
On October 31, 2006, Hanks's radio station planned a live broadcast from Vito's Deck House to promote a Halloween costume contest. When Hanks arrived, she told the promotion workers who were already there about the emails, and let them know that she was nervous about the situation. When she walked in, she saw a man in a booth dressed in black, and he `immediately made eye contact with [her] and got kind of very excited.’ Concerned, Hanks told the promotion workers there was a `guy sitting in the booth’ and asked them to keep an eye on her.
As they broadcasted, people came by to pick up . . . promotional items. Eventually, [Thompson], who indeed was the `guy sitting in the booth,’ approached the table and introduced himself as `Jack Porns.’ Hanks was `petrified.’ She gave him a t-shirt and tried to get him to leave. After [Thompson] walked away, Hanks was so frightened that she went out to her car to get her gun, for which she had a concealed-handgun license. In the parking lot, she saw a bronze Lincoln Town Car in a handicapped parking space and was reminded of the email references to a bronze chariot. At that point, Hanks realized the emails from Jack Porns and Earl Thompson were from the same person.
Hanks called 911, and while she was speaking to the dispatcher, she saw a police car and flagged it down. As she was talking to the police officer, the promotion workers came outside and handed her a threatening note that [Thompson] had given them. While they were talking, a waitress came out and handed them a note she had found in the restroom, which was a poem about Jack the Ripper.
The officer called for assistance, and when the other officers arrived, they detained [Thompson]. [He] had a concealed-handgun permit, and officers found a loaded Derringer handgun in his pocket. The officers arrested [him] for unlawfully carrying a weapon inside a bar, and handcuffed him with his hands behind his back. [Thompson] requested that he be handcuffed in front, but his request was denied. Later, at the jail, officers discovered that [he] had concealed a second handgun in a `pouch that covered his crotch.’ Additionally, in a black bag [Thompson] had with him, police found a pair of rubber gloves and a steak knife.
Thompson v. State, supra. As I said, Thompson was charged with stalking Hanks. The Texas stalking statute provides as follows:(a) A person commits an offense if the person, on more than one occasion and pursuant to the same scheme or course of conduct that is directed specifically at another person, knowingly engages in conduct, including following the other person, that:
(1) the actor knows or reasonably believes the other person will regard as threatening:
(A) bodily injury or death for the other person; . . .
(2) [omitted]; . . . [or]
(3) would cause a reasonable person to fear:
(A) bodily injury or death for himself or herself;
(B) bodily injury or death for a member of the person's family or household; or
(C) that an offense will be committed against the person's property.
Texas Penal Code § 42.072(a). For some reason I cannot fathom, Thompson pled not guilty and went to trial on the stalking charge. At trial, he took the stand in his defense, and, although he stated that he did not intend the emails to be threatening, he admitted that he sent them to Hanks and that he `kept calling’ her at the radio station. He also admitted that he asked someone at Vito's to hand Hanks the threatening note referencing Jack the Ripper, and that he had a handgun with him when he went to Vito's.
Thompson v. State, supra. After being convicted, he appealed his conviction on two grounds, both procedural. In one, he claimed the trial court judge made “an incorrect statement of law to the jury venire during the voir dire process.” Thompson v. State, supra. As Wikipedia notes, the venire is the jury pool, the group of potential jurors from whom the jurors who will decide a case are chosen. As Wikipedia also notes, voir dire is the process of choosing trial jurors from the venire. Thompson pointed out that the trial judge told the venire that if someone had been convicted of prostitution, they were disqualified from serving as a juror. That apparently was an error, but the Court of Appeals held that since Thompson did not raise the issue at trial, he was foreclosed from raising it on appeal.The other issue was that one of the officers who arrested Thompson testified that he said nothing about the second gun (the one in his crotch) during the 30-45 minute drive to the station. Thompson pointed out that commenting on a defendant’s post-arrest silence violated both the Fifth Amendment and the comparable provision of the Texas state Constitution. Thompson v. State, supra. The Texas Court of Appeals rejected this argument because the trial judge immediately instructed the jury to disregard what the officer said. At that point, Thompson moved for a mistrial, which the trial judge denied. On appeal, he claimed the judge should have granted his motion for a mistrial, but the Court of Appeals disagreed. It found that the instruction was adequate and was given promptly and “nothing . . . suggests that the trial court’s instruction was not adequate” to ensure that the jurors did not consider what the officer had said. The Court of Appeals also found that the error was not reversible error because “the State’s case against appellant was overwhelming.” Thompson v. State, supra. It reviewed the facts outlined at the beginning of this post – all of which were proved at trial – and the testimony Thompson gave, in which he basically admitted doing all of it. The court therefore upheld his conviction.As I said, there aren’t any novel or interesting legal issues in this case, just a really creepy set of facts. I also find it interesting that Mr. Thompson – who apparently idolizes Jack the Ripper – seems to have missed the fact that the Ripper was never caught because he managed to maintain a very low profile. Makes you wonder if Thompson was trying to get caught. File this one under amazingly inept cybercriminals.
I recently exchanged several emails with Lokkju Brennr, Lokkju brought up an interesting issue about the way law approaches the crime of gaining unauthorized access to a computer (often generically referred to as “hacking” a computer). Before I get to that issue, I want to review how law deals with this crime.In a post I did a couple of years ago I explained that lawyers usually analogize the crime of gaining unauthorized access to a computer to the crime of criminal trespass: In each instance, you’re doing something you’re not supposed to do and, as a result, are “harming” the owner of the computer/property in some respect.
The “harm” resulting from trespass on physical property seems to be an amalgam of privacy (if you come onto my property without my permission, you’ve violated my privacy) and my right to exclusive possession of the property. The “harm” resulting from unauthorized access to a computer system is . . . a little murkier. I think it definitely encompasses the second “harm” that justifies criminalizing physical trespass, i.e., you’re violating my exclusive right to possess and access my property (my computer/computer system, in this context). And it probably also encompasses the first “harm,” as well, because if you get into my computer system you are in a sense violating my privacy (or at least have acquired the capacity to violate my privacy by getting into the data I don’t want anyone else to know about). I think the unauthorized access-criminal trespass analogy is far from perfect, but it’s pretty much all we have. It’s difficult, if not impossible, to develop analogies that symmetrically track digital and physical “harms” with any precision. That, however, is not the issue Lokkju Brennr raised. That issue, I think, is both more interesting and more difficult to resolve. Here it is:The majority of the time when you do an activity, such as a sending an email, you don't know whether or not you have the authorization to do so. For instance, when I sent my initial email to you, even without going into the underlying protocol issues, I did not know if I had authorization to access your email server or not. Now, I could make an educated guess that since you published your email address, it was permissible to contact you - but I did not have any specific authorization. Lokkju also pointed out that given this state of affairs, unauthorized access statutes effectively criminalize “all normal use of the Internet.” That’s an interesting point; I’m going to use this post to speculate a bit about Lokkju’s point and about how the law deals with it . . . and maybe even how the law might change how it deals with it.Let’s start with an unauthorized access crime statute. The federal statute is remarkably straightforward: “[Whoever] intentionally accesses a protected computer without authorization and, as a result of such conduct, recklessly causes damage” commits a federal crime. 18 U.S. Code § 1030(a)(5)(B). As I noted in an earlier post, the federal statute does not define “access”, but a number of state statutes do.Most states define it as “to instruct, communicate with, store data in, retrieve data from or otherwise make use of any resources of a computer, computer system or network.” Arizona Statutes § 13-2301(E)(1). California’s definition is similar but a little more elaborate: “`Access’ means to gain entry to, instruct, or communicate with the logical, arithmetical, or memory function resources of a computer, computer system, or computer network.” California Penal Code § 502(1). Okay, U.S. states (and the criminal codes of other countries) define access. But do they define what it means to gain access “without authorization”? Surprisingly, a few states do. Here’s how Colorado defines it: “`Authorization’ means the express consent of a person which may include an employee’s job description to use said person’s computer, computer network, computer program, computer software, computer system, property, or services as those terms are defined in this [statute.]” Colorado Revised Statutes § 18-5.5-101(1). And here’s how Hawaii defines it: “`Without authorization’ means without the permission of or in excess of the permission of an owner, lessor, or rightful user or someone licensed or privileged by an owner, lessor, or rightful user to grant the permission [to access the computer or computer system].” Hawaii Revised Statutes § 708-890. Minnesota has a slightly different and rather interesting approach to defining authorization:`Authorization’ means with the permission of the owner of the computer, computer system, computer network, computer software, or other property. Authorization may be limited by the owner by:
(1) giving the user actual notice orally or in writing;
(2) posting a written notice in a prominent location adjacent to the computer being used; or
(3) using a notice displayed on or announced by the computer being used.
Minnesota Statutes § 609.87(2a). And New Hampshire throws in a new element that expands the scope of authorization: `Authorization’ means the express or implied consent given by a person to another to access or use said person's computer, computer network, computer program, computer software, password, identifying code, or personal identification number.
New Hampshire Revised Statutes § 638:16(II). A few other states also have statutory provisions that define authorization, but they all tend to resemble one of more of these statutes.So where does that leave us in terms of the issue Lokkju raised? When I send an email to you – to someone who didn’t email me first and whom I don’t know in the real world – how do I know if I’m accessing their email server (or, more accurately, I think, the email server that handles their email) with or without authorization? As a matter of fact, I don’t. As a matter of fact, I simply assume I have authorization to access that server. All of the statutes quoted above define authorization as acting with the consent/permission of the owner of the computer system (the server); in so doing, they implicitly assume that the person KNOWS they are acting with the permission or consent of the owner of the system (server). Logically, I could argue that they assume (also or in the alternative) that it’s sufficient if I believe I have permission or consent to access the computer. I don’t think a subjective belief (however accurate or erroneous) works here, though, because I think the language of most of the statutes incorporate a higher standard, i.e., I think they predicate authorization as your having obtained some signal, some indication, from the owner of the system that it’s okay for you to access it. (But I could be wrong.)The New Hampshire statute broadens that by adding “implied consent.” The other statutes expressly or (I would argue) implicitly require that there have been express consent from the owner of the system for access to be authorized. That’s why I believe they require a much higher standard than simple belief (“I thought it was ok, really I did”). The New Hampshire statute doesn’t tell us how implied consent arises. Pennsylvania’s computer crime statute does shed a little light on this issue. It defines authorization as including “express or implied consent, including by trade usage, course of dealing, course of performance or commercial programming practices.” This language appears in a statute entitled “defense.” Here is the statute in its entirety:It is a defense to an action brought pursuant to Subchapter B (relating to hacking and similar offenses) that the actor:
(1) was entitled by law or contract to engage in the conduct constituting the offense; or
(2) reasonably believed that he had the authorization or permission of the owner, lessee, licensee, authorized holder, authorized possessor or agent of the computer, computer network, computer software, computer system, database or telecommunication device or that the owner or authorized holder would have authorized or provided permission to engage in the conduct constituting the offense. As used in this section, the term `authorization’ includes express or implied consent, including by trade usage, course of dealing, course of performance or commercial programming practices.
18 Pennsylvania Consolidated Statutes § 7605(2). Connecticut has a similar defense to a charge of unauthorized access statute. Like the Pennsylvania statute, it bases the defense on the fact that the defendant “reasonably believed” that the owner of the computer system or the owner’s agent had authorized the access. Connecticut General Statutes § 53a-251(b)(2). The Connecticut statute, though, throws in another option: It’s also a defense if the person charged with gaining unauthorized access to a computer “reasonably could not have known that his access was unauthorized." So this statute essentially puts the risk on the owner of the system; the owner must make it "reasonably" clear access is not authorized unless you do something, have something, etc.So where does that leave us? It’s pretty clear that U.S. law, anyway, doesn’t address the issue Lokkju raised, i.e., the problem of letting someine know whether their access is authorized prior to their act of accessing a system. It looks like a few U.S. states (New York has a statute similar to the Pennsylvania defense statute) deal with this issue by giving someone charged with unauthorized access the ability to use their belief that they were authorized to use the system as an affirmative defense. In U.S. criminal law, when someone raises an affirmative defense to a charge, they admit they committed the crime but use the defense to argue that they shouldn’t be convicted. Self-defense and insanity are affirmative defenses; someone charged with murder can concede that they killed the victim but argue that they are not guilty of murder because they acted in self-defense or were insane at the time. Does that approach seem reasonable? If not, any alternatives?
This post is about a case that demonstrates the hazards that can sometimes attend being a Good Samaritan. The case also raises an evidentiary issue.The case is State v. Mellert, 2009 WL 1365024 (Ohio Court of Appeals 2009). Here are the facts that led to Karen Mellert being charged with knowingly making a false statement with the purpose of committing a theft offense:[William] Oakes . . . lives by himself in a three bedroom house. One evening, he had his friend Liz over, who lives at a hotel. Liz brought Ms. Mellert with her, who also lived at the hotel. When Mr. Oakes learned from Liz that Ms. Mellert could not afford to stay at the hotel any longer because she was out of money, he offered to let her stay at his house in one of the extra bedrooms.
According to Mr. Oakes, Ms. Mellert stayed with him for six or seven weeks. She did the grocery shopping, cooked for them, and cleaned the house. Her boyfriend sometimes came by to take her out. One afternoon, however, Mr. Oakes received a call from his financial advisor asking him about a letter he had received that directed him to `cut a check for $5,000.00 made payable to Karen L. Mellert, as a gift.’ The letter identified Mr. Oakes's account number and universal ID number. Mr. Oakes said the financial advisor called him about the letter because he usually did all of his transactions by telephone and the financial advisor had never seen Ms. Mellert's name before on any of his documents.
State v. Mellert, supra. At Mellert’s trial, Oakes testifiedthat he did not write the letter. He said he did not know Ms. Mellert's middle initial or how to spell her last name. He also said that the signature at the bottom of the letter was not his, noting that it misspelled his name. He further said that Ms. Mellert regularly used his computer and had access to his account information.
State v. Mellert, supra. The opinion does not say, but I assume the prosecution believed Mellert accessed Oakes’ computer – with his permission, so we don't have an unauthorized access charge – and thereby gained access to his account information. She may also have used the computer to write and print the letter, but that’s just a guess.The jury convicted Mellert on the false statement in furtherance of theft charge, which an Ohio statute defines as follows: “[n]o person shall knowingly make a false statement ... when . . . [t]he statement is made with purpose to commit . . . a theft offense.” Ohio Revised Code § 2921.13(A)(9). I’m always amazed at the variety of crimes that crop up in state statutes; I’m not exactly sure what the point of this statute is. I assume the idea is that if you lie in order to commit theft, you’re compounding the “harm” you’ve inflicted and so should face liability for the lie (the deception) aspect of the theft. Anyway, Mellert was convicted. She appealed the conviction, arguing that “the State failed to produce sufficient evidence to support her conviction.” State v. Mellert, supra. Specifically, Mellert argued that there “was only circumstantial evidence that she wrote the letter”, which was true. State v. Mellert, supra. And that brings me to the evidentiary issue I noted earlier.Wikipedia does a nice job of distinguishing circumstantial evidence from the other type of evidence, direct evidence: If a witness testifies that the defendant was seen entering a house, then screaming was heard, then the defendant was seen leaving, carrying a bloody knife, that is circumstantial evidence; if a witness testifies that he/she actually saw the defendant stabbing the victim, that is direct evidence.
Here’s part of a jury instruction California courts use to explain the difference between direct and circumstantial evidence to jurors:Evidence consists of the testimony of witnesses, writings, material objects, or anything presented to the senses and offered to prove the existence or non-existence of a fact.
Evidence is either direct or circumstantial.
Direct evidence is evidence that directly proves a fact. It is evidence which by itself, if found to be true, establishes that fact.
Circumstantial evidence is evidence that, if found to be true, proves a fact from which an inference of the existence of another fact may be drawn.
An inference is a deduction of fact that may logically and reasonably be drawn from another fact or group of facts established by the evidence.
[It is not necessary that facts be proved by direct evidence. They also may be proved by circumstantial evidence or by a combination of direct and circumstantial evidence. Both direct and circumstantial evidence are acceptable as a means of proof. Neither is entitled to any greater weight than the other.]
California Jury Instructions – Criminal (Spring 2009). (The brackets in the last paragraph were added by the people who drafted this instruction, not by me. They give a judge the option of including that portion of the instruction, or not.]In the Wikipedia example, the witness saw facts from which he inferred the defendant stabbed the victim. In the Mellert case, the only evidence the prosecution had to prove Mellert knowingly made a false statement to commit theft was circumstantial evidence. As I noted above, Mellert seemed to be arguing that circumstantial evidence, by itself, was not enough to support a conviction. That, as the Calfornia jury instruction makes very clear, is not true. I’m always amused when I see commentators on TV talking about how “all the prosecution has is circumstantial evidence,” as if that is inherently suspect or inadequate. It is not. As the California jury instruction makes very clear, a conviction can be based purely on circumstantial evidence, as long as it proves the defendant’s guilt beyond a reasonable doubt. The Ohio Court of Appeals concluded that the evidence in the Mellert case was sufficient to prove her guilt beyond a reasonable doubt:The State presented sufficient circumstantial evidence for the jury to infer that Ms. Mellert had both the motive and opportunity to draft the letter. It was logical for the jury to believe that, since Ms. Mellert was the beneficiary of the intended transfer, she was the one who sent the letter to the financial advisor. This Court, therefore, concludes that Ms. Mellert's conviction is supported by sufficient evidence.
State v. Mellert, supra. I guess I agree with that; I don’t really know why I wouldn’t. For some reason, I have a little discomfort with convicting her without having a little more evidence . . . say, her fingerprints on the letter or a computer forensics expert’s testimony that she did, indeed, access Oakes’ financial information at or around the time the letter was written, something like that. I’m not questioning her guilt; I’m just saying the evidence of her guilt doesn’t exactly overwhelm me.