skip to main |
skip to sidebar
As you may know, rumors have spread that Microsoft put a backdoor in its Vista program to accommodate law enforcement’s need to search on computers.
Microsoft denies this, which I tend to believe, but I know people who claim that it’s true. At the very least, it raises some interesting 4th amendment issues.Let’s begin with why the backdoor issue arises.
Vista incorporates a feature called BitLocker Drive Encryption. BitLocker, which “is included in the Enterprise and Ultimate editions of Vista,” encrypts data on a computer. BitLocker Drive Encryption, Wikipedia. “By default it uses the AES encryption algorithm in CBC mode with a 128 bit key, combined with the Elephant diffuser for additional security.” BitLocker Drive Encryption, Wikipedia. According to Microsoft, it prevents unauthorized users from gaining access to data contained on a computer: “with BitLocker all user and system files are encrypted including the swap and hibernation files.” BitLocker, Microsoft.Users’ ability to encrypt all the files on their computer obviously poses problems for law enforcement officers who want to search a computer for evidence of a crime. But as some have noted, BitLocker should not pose problems for law enforcement in two instances:
- One is if the computer is running; as one source notes, “forensic tools can access the encrypted volume of a running system just like any other program”. Simson Garfunkel, Drive Encryption: Two Tales, Technology Review. If the computer is running, the encryption key has already been entered into the computer, so the encryption is not an issue.
- The other instance in which BitLocker won’t pose problems for law enforcement is when people haven’t bothered to use it.
As we probably all now, encryption is not new; encryption is available on the Mac I am using to write this, and there are programs available which can be used to encrypt data. So far, most people simply don’t bother.Notwithstanding all this, BitLocker will still probably raise issues for law enforcement. One is how officers should proceed when they arrive to execute a computer search and the computer is running; the officers can presumably conduct a forensic analysis of the computer and thereby avoid BitLocker’s encryption, but that remains to be seen. I am not going to address that issue here. What I want to examine is the legality (or illegality) of including a backdoor on the Vista system to let law enforcement bypass encryption that has been installed on a system and that is in effect because the system has been shut down. We will assume, for the purposes of analysis only (which means this is all purely hypothetical), that Microsoft incorporates a backdoor that lets law enforcement bypass Vista encryption. For the purposes of analysis, we will also assume that officers arrive at John Doe’s home with a warrant to search his computer for evidence of a crime (child pornography, terrorism, murder, take your pick). He lets them in, takes them to the computer, the computer is not running and they quickly find out he has implemented BitLocker. Now, BitLocker can be implemented several ways, one of which involves storing the BitLocker encryption key on a USB drive; the USB drive must be inserted into the computer for it to boot. The officers ask Doe for the USB drive they need to boot the computer; he refuses to give it to them, says he “threw it away.”Absent a Vista backdoor, they have two and only two options at this point: They can use a grand jury subpoena or other means to “compel” Doe to surrender the key (assuming he lied when he said he threw it away), but to do this they probably will have to give him immunity for the act of handing it over. As I explained in an earlier post, immunity lets the government override his Fifth Amendment privilege, which Doe will assert as the basis for refusing to turn over the key. Doe will say, in effect, that by turning the key over he would be forced to be a witness against himself in violation of his Fifth Amendment privilege against self-incrimination. Unfortunately, giving Doe immunity for the act of handing over the USB drive probably means they will not be able to prosecute him, since the effect of the immunity is to bar the government from using his act of handing over the drive and any evidence derived, directly or indirectly, from that act against him in a criminal prosecution. Since the evidence, if any, found on the hard drive would derive from the act of handing over the USB drive, they would be giving up the opportunity to prosecute him. The other option is to break the encryption which, I believe, would be very difficult to do.What if, hypothetically, Microsoft had created a backdoor in Vista that would let law enforcement bypass BitLocker encryption and access the data on Doe’s computer? If Microsoft were to do this, could law enforcement then use the backdoor without violating the 4th amendment?I don’t know of any criminal cases in which this issue has arisen. It came up last year when Michael Crooker sued Compaq (now HP) for false advertising. Crooker claimed he bought a Compaq laptop because it was advertised as having a feature – DriveLock – that secured data on its hard drive. The FBI, which had a warrant to search Crooker’s laptop, apparently found some way around the DriveLock security. In his lawsuit, Crooker claimed they used a backdoor provided by Compaq (HP). Crooker’s suit was ultimately dismissed, for whatever reason, and is irrelevant to this discussion anyway, since it did not raise any constitutional claims. In the Doe case, the officers have a warrant to search Doe’s computer, and that allows them to access the data it contains. They, however, need outside help to access that data. There are state and federal statutes that let law enforcement obtain help from private citizens to execute search warrants; police, for example, have always needed help from phone company employees to tap landline telephone calls. The government would probably argue that the officers’ using the backdoor Microsoft installed on the system is no different from officers’ obtaining the assistance of telephone company employees to tap telephone calls. The warrant gives the officers the constitutional authority to obtain the evidence (here, the content of the calls); the telephone company employees are simply helping them to implement that authority.The defense would argue that law enforcement’s using our hypothetical Vista backdoor to access the data on Doe’s encrypted computer is different from the scenario I outline above. How is it different? Well, one difference goes to the issue Crooker raised in his lawsuit: Doe, the defense would argue, specifically purchased a computer with Vista in order to be able to use BitLocker to secure his data from any- and every-one, including law enforcement. Doe, the defense would say, believed he could rely on the technology he purchased from Microsoft to protect his data because (in our hypothetical) he had no reason to know there was a backdoor.The defense would then argue that by (hypothetically) installing the backdoor, Microsoft became an agent of law enforcement. As I’ve noted before, a private party can become a law enforcement agent, which means the private party’s conduct must comply with the 4th amendment. To become a law enforcement agent, the private party must act with the purpose of assisting law enforcement (which we have here) and law enforcement must encourage the party’s engaging in conduct that assists law enforcement (which we also have here). If, then, Microsoft were to install a Vista backdoor and let law enforcement use it, Microsoft would be a law enforcement agent, at least with regard to BitLocker overrides.The government, again, would say there’s no problem here, that the same rationale used to get phone companies to tap calls applies, i.e., the search warrant justifies what law enforcement does and what Microsoft-as-hypothetical-agent-of-law-enforcement does. Somehow, though, that just doesn’t seem right to me. It seems to me that here Microsoft is acting like a bailor, i.e., someone who has custody of another person’s property and who is legally obligated to keep it secure. Airlines are bailors for our luggage; banks are bailors for the things we put in our safe-deposit boxes, etc. Microsoft is not technically a bailor because Doe has not given his data to Microsoft to hold and keep secure. But the relationship is analogous to a bailor-bailee relationship in that Microsoft has, at least implicitly, assumed some responsibility for keeping Doe’s computer data secure. Doe, after all, bought a Vista-equipped computer because he wanted the protection provided by BitLocker; he had no idea Microsoft could and would nullify that protection when asked to do so by law enforcement.In a sense, what Microsoft is doing in our hypothetical is consenting to the search of Doe’s computer. Doe says “no” to the officers, Microsoft says “go ahead.” If we think of the hypothetical BitLocker backdoor as a type of consent, and if we analogize Microsoft to a bailor, then the consent would not be valid for 4th amendment purposes. There’s a federal case from the 8th Circuit Court of Appeals, United States v. James, 353 F.3d 606 (2003), in which James left disks in a sealed envelope with a friend. Federal agents asked the friend to open the envelope so they could search the disks, and the friend did. The Eighth Circuit held that this violated the 4th amendment because while the friend had lawful custody of the disks, he did not have the constitutional authority to consent to the opening of the package and to the search of the disks. Seems to me Doe could make a similar argument as to the hypothetical backdoor in Vista.All of this will probably never come up for BitLocker, since Microsoft vehemently denies putting a backdoor in Vista (and I tend to believe them). But that does not mean law will never have to confront the problem of backdoors.
My cybercrimes students and I are discussing hackback, or strikeback, in which the victim of a cybercrime retaliates directly against her victimizer without going through the police and the legal system.
I found our discussions useful in analyzing the arguments can be made for and against hackback, so I thought I'd share them with you.The first question, logically, is why even discuss hackback? The reason it comes up is the actual and perceived inability of law enforcement to track down, arrest and bring to justice all or even most of those who commit cybercrimes.
As I hope everyone knows, even in the real-world police cannot arrest EVERY criminal. Instead, their goal is to arrest ENOUGH criminals to keep crime under control in a society.
Modern legal systems operate on the premise that the best way to keep crime under control is to deter people from committing crimes, and the way they do that is to make enough of us believe we will get caught if we commit a crime. Getting caught is very important. Studies have shown that the perception you will get caught if you commit a crime is much more effective as a deterrent than is raising the severity of the penalty imposed on those who are caught. If, say, I think I have a 5% chance of getting caught if I steal $50 million, I may very well weigh the odds of getting caught against the benefits of committing the crime (large) against the chances of not getting caught (good), and go for it. The problem is, as I’ve said before, that cybercrime makes the implementation of this crime control strategy incredibly difficult. Aside from anything else, cybercrime often (usually) tends to come from “outside” the jurisdiction where the victim is, and this can pose terrific problems for police trying to investigate the crime and arrest the perpetrator. Another problem is that cybercrime is added to the crime that already exists in the real-world, so police have all that extra work to do, which means they often must triage their priorities: If people are being physically harmed in the real-world, that necessarily takes priority over what happens in the virtual world because, so far anyway, cybercrime involves little if any risk of direct physical injury or death to the victims.So, given law enforcement’s increasing inability to apprehend cybercriminals, it only makes sense that hackback – victim self-help – begins to sound appealing. It’s the same phenomenon that generates vigilante activity. (One difference between vigilante activity and hackback is that vigilantes – a la Perverted Justice – tend to affirmatively seek out perpetrators or would-be perpetrators, while hackbackers are retaliating for what was specifically done to them.)I’ve seen postings and articles that say hackback is permissible under our existing law because it constitutes self-defense. These sources sometimes note that the right of self-defense under U.S. (and most) law can encompass the use of deadly force against an attacker, and point out that since deadly force cannot (so far, anyway) be used online, the use of retaliatory force clearly falls within the doctrine of self-defense.The first problem I have with these views is that the scenarios involved in hackback (so far, anyway) do not involve the threat of physical injury or death to the perpetrator; they involve the threat of damage to or loss of the victim’s property, which is a very different thing.U.S. law (and, I believe, most other legal systems) recognizes two different justifications for using force against an attacker. One is self-defense, which means exactly what is says: I can protect my physical self from an attacker who threatens me with physical injury or death. The Model Penal Code – the set of model laws that are the template for contemporary U.S. criminal law – says, for example, that “the use of force upon . . . another person is justifiable when the actor believes that such force is immediately necessary for the purpose of protecting himself against the use of unlawful force by such other person on the present occasion.” Model Penal Code § 3.04(1). A later section of the MPC defines “unlawful force” as “force . . . that is employed without the consent of the person against whom it is directed and the employment of which constitutes an offense or actionable tort”. Model Penal Code § 3.11(1). So, under these provisions and laws based on them, I can use force to protect myself to the extent I personally believe it is necessary (no other alternative) to protect myself from someone else’s using force to harm me. The MPC limits the use of deadly force to instances in which the would-be victim believes it is necessary to protect herself “against death, serious bodily injury, kidnapping or sexual intercourse compelled by force or threat”. Model Penal Code § 3.04(2)(b). I do not see how these standards can apply online. The “force” that is used online is directed at things, not people. It is true that online activity can become the vector that is used to set a real-world physical attack in motion: A cyberstalker can use online postings and the manipulation of online information to try to persuade a naïf who likes to play sado-masochistic sexual games to attack the person the stalker is trying to set up, but the attack – and the victim’s use of defensive force, if any – all occur in the real-world.Unless and until we acquire the capacity to directly cause physical injury to one another via cyberspace, hackback is really about a very different problem: defending property. U.S. law (and law in many other countries) lets people use force to defend their property, but only within limits.Let’s go back to the Model Penal Code. Section 3.06 of the MPC says that you can use force “upon or toward the person of another” when you believe the use of such force “is immediately necessary . . . to prevent or terminate an unlawful entry or other trespass upon land or a trespass against or the unlawful carrying away of tangible, movable property” belonging to you. Model Penal Code § 3.06(1)(a). Under this provision, you can only use non-deadly force, i.e., force that is not likely to cause death or serious bodily injury. You can only use deadly force to protect property if (i) the attacker is trying to “dispossess” you of your “dwelling” or (ii) the attacker “is attempting to commit . . . arson, burglary, robbery or other felonious theft or property destruction” and has either used or threatened to use deadly force or the use of less than deadly force would expose you to a risk of death of serious bodily harm. The last option, of course, brings in self-defense. Model Penal Code § 3.06(3)(d). So, how can we apply this to hackback? Would hacking back against someone who had unlawfully accessed your computer/data or infected your system with a virus or launched a DDoS attack on your website be a valid use of force to defend your property?It doesn’t seem to me that these scenarios or any I can think of at the moment would qualify as “dispossessing” you from your “dwelling” . . . unless and until we decide that the computer system you use if your “dwelling.” I think that would be way too much of a stretch for the drafters of the MPC or for modern legislators, so we’ll give up on that option.Unauthorized access to a computer system for the purposes of committing a crime (such as destroying or copying data) clearly qualifies as burglary. I can’t think of any online misconduct that would qualify as arson, so we’ll give that a pass. Robbery is using force to steal someone’s property; if we read “force” as “physical force,” this option would not seem to apply online, either. Clearly, though, spreading malware could qualify as the attempted (and consummated) destruction of property, so it falls within the traditional defense of using force to protect one’s property. I think a DDoS attack can also qualify as a destruction/attempted destruction of property if, of course, we broaden our concept of property a bit, to include lost business opportunities and costs incurred in dealing with such an attack.One problem we do have with applying laws like the MPC provisions described above to hackback is the notion of “property.” If you look back at the MPC defensive use of force to protect property provision I quoted above, it only lets you use force to protect “tangible, movable property.” Data is certainly movable, but we’d have to qualify it as “tangible” property for this provision to apply to online attacks; the drafters of the MPC most certainly were not thinking of intangible property like data when they wrote this provision, but if we could convince legislators to broaden the scope of self-defense statutes, that would not be a problem.It seems, then, that we can apply the “defense of property” doctrine to hackback, at least in certain instances and with certain modifications to the traditional doctrine. The one condition a hackback-er would have to meet in order to invoke this defense is the issue noted above, i.e., that the use of defensive force was “immediately necessary.” This means the hackback-er had no other alternatives but self-help; and what that generally means is that it would have been futile for the hackback-er to have taken the usual route and contacted law enforcement. The “defense of property” doctrine is really meant to apply to instances in which there is a face-to-face confrontation between a perpetrator and a would-be victim that makes it impossible, or dangerous, for the potential victim to try to call police. The “immediately necessary” element means the victim had to act at that moment or face the loss of her property.That element might not be a problem for some instances of hackback . . . instances in which the hackback-er interrupted a perpetrator who was in the process of carrying out an attack. That scenario conforms more closely to the scenario the defense of property doctrine was intended to encompass. Applying the doctrine becomes much more difficult if the hackback occurs well after the attack has been completed and the damage has been inflicted. That starts to look a lot more like simple retaliation – hitting back to punish someone who has already hurt you – than the defense of property doctrine. The rules governing the defensive use of force all assume the victim is trying to prevent or minimize the infliction of “harm” in an ongoing, volatile situation. They do not sanction cold-blooded revenge.There are other problems with applying the laws governing the defensive use of force to hackback, one being the accuracy of the response. That tends to be less of a problem for real-world scenarios than for online attacks because, as I just noted, in real-world attacks the attacker and victim are face-to-face. The victim may err in estimating the need to use force (and the level of force used), but the victim is usually accurate in deciding whom the force should be used against. As I assume we all know, this is not true online; attacks can be vectored through computers in many locations, so if we were to sanction hackback we would either have to incorporate an “accurate identification of the perpetrator” element or limit it to confrontations arising from attacks in progress.Since this post is already long, I’ll take up that issue and a related issue (automating hackbacks) another time.
We’re probably all familiar with the NBC Dateline “To Catch a Predator” programs.
In these Dateline episodes, reporter Chris Hansen films interviews with men who have shown up at a location intending to have sex with what they believe is a minor male or female. The men are the targets of a “sting” operation. They've actually been chatting online with someone from the group Perverted Justice. As one court noted, Perverted Justice “is an organization dedicated to exposing child molesters” which NBC pays for its contributions to the Dateline episodes. (United States v. Kaye, 451 F. Supp.2d 775 (E.D. Va. 2006)).
The Dateline-Perverted Justice collaboration is just one, isolated instance of a “sting” model that has become popular in the United States. Police officers in jurisdictions all over the country (including one police department in a city about 30 miles from where I am writing this) go online and pretend to be barely adolescent females or males. The purpose is to identify pedophiles who will try to lure the children to a meeting for the purposes of having sex. I have spoken to officers who have run stings like these, and they tell me “it’s shooting fish in a barrel,” i.e., that once they go into an appropriate chat room pretending to be barely-pubescent “Melissa” or “Heather,” the pedophiles pounce almost immediately.
The defendants in these cases will be prosecuted for what they have done. The charge, which takes slightly different forms in various states and at the federal level, is “luring” or enticing a child into a sexual rendezvous. I just read a relatively recent decision from a Virginia federal district court in which the defendant used a common argument in an effort to have the charges against him dismissed. (United States v. Kaye, 451 F. Supp.2d 775 (E.D. Va. 2006)).
This defendant, like many before him, argued that the charges against him should be dismissed because there was no child. That is, he said he was charged with luring or enticing a “child” into a sexual rendezvous, but the online chats he had were not with a child; they were with an adult representative of Perverted Justice. He argued, therefore, that the charges could not stand because no child was involved in what he did, and no child was ever in any danger of being sexually exploited.
That is a logical argument, and has succeeded on occasion, especially under older statutes which actually require that there have been a “child.” It fails, though, when the charges are brought (i) under a statute which makes the act of luring or enticing a child to a sexual rendezvous a crime in and of itself or (ii) under a provision which makes it a crime to attempt to lure or entice a child to a sexual rendezvous. Neither of these offenses requires that there have actually been a child victim. They focus on what the defendant intended to do, so if the evidence shows that the defendant believed he was corresponding with a child and if the defendant used that correspondence to entice what he truly believed was a child to a sexual rendezvous, then the defendant has committed this crime. It is irrelevant that he was actually corresponding with, say, a 45 year old male detective or a 30 year old female representative of Perverted Justice.
You might wonder why the law finds it necessary to adopt statutes which criminalize conduct that is impossible, which is the case here. As Kaye argued in the case I cited above, based on the facts involved in that instance it was both “factually and legally impossible” for him ever to have actually had sex with a minor, more precisely, with the minor male he apparently believed he was corresponding with. And Kaye is right; these statutes do criminalize conduct that is, at least in the contexts of these stings, totally impossible.
Why do that? The rationale is based in what the law calls inchoate, or incomplete, crimes. Attempt is an inchoate crime; it criminalizes unconsummated efforts toward the commission of a crime. So, say the FBI has learned that John Doe intends to rob the First National Bank. The FBI observes Doe as he “cases” the bank and makes other preparations and tracks him as he heads to the bank on the day he intends to commit the crime. FBI agents arrest him outside the bank before he is even able to begin the process of robbing it. Doe will be charged with attempting to rob the bank; he cannot be charged with robbing the bank because he never got the chance to do that.
The law criminalizes attempts on the theory that it protects public safety. If we did not criminalize attempts, the FBI would have to wait for Doe to rob the bank and then try to arrest him afterward. Aside from letting him take money that is not his, this could also expose people in the bank to the risk of death or serious injury if something went wrong in the robbery or if Doe simply became trigger-happy. The law says it is better to have a repertoire of inchoate offenses – like attempt in this scenario and like the luring or enticing offenses I noted above – to let law enforcement intervene and head off crime before it occurs.
Now, some claim that stings like those the Dateline crew films go too far . . . that they essentially represent the manufacture of a crime. Those who make this argument would say that the people, like Kaye, who are caught in the luring and enticing stings are not like Doe because they had not independently embarked on a course of criminal conduct. The critics of these stings say that law enforcement has played a much more active role in creating these crimes than in the bank robbery scenario I outlined above.
Advocates of the stings say they are taking a pro-active approach to protecting children, and that every sting represents the interception of what could have been a real crime.
I recently heard from someone whose employer searched his office computer and used the information obtained from it against him in a civil suit. He asked if this violated the Fourth Amendment. The answer, basically, is “almost certainly not” . . . and I want to try to explain WHY that is the answer.
To do that, I’m going to use a recent decision from the Ninth Circuit Court of Appeals: United States v. Ziegler, 474 F.3d 1184 (9th Cir. 2007). Here are the facts as the court described them:"On January 30, 2001, Anthony Cochenour, the owner of Frontline [Processing's] Internet-service provider . . . contacted Special Agent James A. Kennedy, Jr. of the FBI with a tip that a Frontline employee had accessed child-pornographic websites from a workplace computer. Kennedy pursued the report . . . , first contacting Frontline's Internet Technology Administrator, John Softich. One of Softich's duties . . . was to monitor employee use of the workplace computers including their Internet access. He informed Kennedy that the company had in place a firewall, which permitted constant monitoring of the employees' Internet activities. . . .
"Softich confirmed . . . that a Frontline employee had accessed child pornography via the Internet. . . . . Softich further informed Kennedy that, according to the Internet Protocol address and log-in information, the offending sites were accessed from a computer in the office of . . . Ziegler, who had been employed by Frontline as director of operations since August 2000. Softich also informed Kennedy that the IT department had already placed a monitor on Ziegler's computer to record its Internet traffic by copying its cache files.
"Kennedy next interviewed William Schneider, Softich's subordinate . . . Schneider confirmed that the IT department had placed a device in Ziegler's computer that would record his Internet activity. He . . . had `spot checked' Ziegler's cache files and uncovered . . . child pornography. A review of Ziegler's `search engine cache information' also disclosed that he had searched for “things like ‘preteen girls' and ‘underage girls.’ Furthermore, according to Schneider, Frontline owned and routinely monitored all workplace computers. The employees were aware of the IT department's monitoring capabilities. . . .
"According to . . . Softich and Schneider . . . Kennedy instructed them to make a copy of Ziegler's hard drive because he feared it might be tampered with before the FBI could make an arrest. Kennedy, however, denied that he directed the Frontline employees to do anything. . . . [H]is notes say, `IT Dept has backed up JZ's hard drive to protect info.' Kennedy testified that he instructed Softich only to ensure that no one could tamper with the backup copy.Whatever Agent Kennedy's actual instructions, . . . [a]round 10:00 p.m., Softich and Schneider obtained a key to Ziegler's private office . . . , entered Ziegler's office, opened his computer's outer casing, and made two copies of the hard drive."Shortly thereafter, Michael Freeman, Frontline's corporate counsel, contacted Kennedy and informed him that Frontline would cooperate fully in the investigation. Freeman indicated that the company would voluntarily turn over Ziegler's computer to the . . . . On February 5, Reavis delivered Ziegler's computer tower (containing the original hard drive) and one of the hard drive copies. . . .. Schneider delivered the second copy sometime later. Forensic examiners at the FBI discovered many images of child pornography."
United States v. Ziegler, supra. Ziegler was indicted for possession of child pornography and moved to suppress the evidence against him.
Ziegler argued that Agent Kennedy violated the Fourth Amendment by “directing” the Frontline employees to search Ziegler’s office and computer. So, Ziegler was claiming that the Frontline employees had become agents of the government, which he had to do to invoke the Fourth Amendment. The Fourth Amendment only protects us from action by the government; if a private citizen decides to search your home or office and takes what she finds there to the police, you are out of luck, as far as the Fourth Amendment goes. You can try suing the private citizen who searched your home or office for trespass or invasion of privacy or some other civil cause of action, but you have absolutely no claim under the Fourth Amendment . . . as long as the person was acting on their own.
This was Ziegler’s argument. He claimed, and the Ninth Circuit agreed, that he had a valid Fourth Amendment expectation of privacy in his office. The court noted, among other things, that the facts his computer was password-protected and his office had a lock on the door established this.
The Ninth Circuit then found that Softich and Schneider were “acting as de facto government agents,” that is, they searched Ziegler’s office because they wanted to help the FBI with its investigation, not for reasons associated with their employment by Frontline. The court also found that the government had encouraged them to do this, so that makes Softich and Schneider government agents and means their conduct has to have complied with the requirements of the Fourth Amendment, i.e., that they search of Ziegler’s office and seizure of data from his computer had to be “reasonable.”
Searches and seizures can be “reasonable” under the Fourth Amendment if (a) they are conducted pursuant to a search warrant (which was not true here) or (b) they are conducted pursuant to a valid exception to the warrant requirement, such as consent. The Ninth Circuit found that Frontline had the authority to consent to the search of Ziegler’s computer.
That authority derived from the fact that Frontline and its employees had common authority over Ziegler’s office and computer. Basically, Frontline had common authority over both because it had a key to the office and had the capacity to access his computer, notwithstanding the password Ziegler used. As the Ninth Circuit explained, while "use of each Frontline computer was subject to an individual log-in, Schneider and other IT-department employees `had complete administrative access to anybody's machine.' The company had also installed a firewall, . . .`a program that monitors Internet traffic ... from within the organization to make sure nobody is visiting any sites that might be unprofessional.' Monitoring was routine, and the IT department reviewed the log created by the firewall `[o]n a regular basis' . . . . Finally, upon their hiring, Frontline employees were apprised of the company's monitoring efforts through training and an employment manual, and they were told that the computers were company-owned and not to be used for activities of a personal nature." United States v. Ziegler, supra.
So Ziegler lost on his motion to suppress and will have to serve time for possessing child pornography.
This, I hope, illustrates why it is so difficult for employees of private companies to invoke the Fourth Amendment when their employer searches their computer. Unless the company has policies which explicitly state that the employee can use the computer for private purposes and that the company will not monitor the employee’s computer activity or otherwise investigate the contents of his or her computer, the company can, as Frontline did, consent to law enforcement’s searching the computer. And if the company itself does so for its own, private purposes, the Fourth Amendment is not implicated because there is no state action – the company is not acting for the state or federal government.
In law, jurisdiction is a court’s ability to act in a case, i.e., to hear evidence and enter a judgment. In criminal law it’s a court’s power to adjudicate the charges brought against someone. People often wonder if jurisdiction is a problem in cybercrime cases because the conduct involved in committing a cybercrime can cross sovereign borders. That is, as we all know, cybercrime can be committed state-to-state in the United States, say, or across two or more different countries.
This is significant because jurisdiction has historically been based on someone’s physical presence in a particular sovereign entity (nation-state or, in a federal system like the U.S. in a constituent state of a nation-state). The idea goes way, way back in history. At English common law, jurisdiction to prosecute was based on having custody of the alleged offender; it really didn’t matter how the officials got hold of that person as long as they had him. This historical principle still runs through much of our law of jurisdiction, so jurisdiction in civil and criminal cases is often predicated on one’s “presence” in the jurisdiction that seeks to prosecute.
What we have done, though, is to dramatically expand what “presence” is. It can be physical presence or it can be an attenuated version of physical presence: the notion that by engaging in conduct outside a state or nation-state one had a particular, foreseeable “effect” within that sovereign entity. This attenuated, expanded notion of “presence” emerged in civil law as a byproduct of the expansion of interstate commerce across state (and national) boundaries last century; it has since migrated into criminal law. So what you see in modern criminal law are statutes that give the courts of a sovereign the ability to prosecute someone whose conduct resulted in the infliction of “harm” inside the state, even though the perpetrator was never actually “in” that state. Here’s an example, from Arkansas: “A person may be convicted under a law of this state of an offense committed by his or her . . . conduct . . . if. . . [e]ither the conduct or a result that is an element of the offense occurs within this state”. Arkansas Code § 5-1-104(a)(1).To show you how a provision like that works, let’s consider a recent case from Arkansas, Powell v. State, 2007 WL 104103 (Arkansas Court of Appeals, January 17, 2007). Here are the facts, as given by the court of appeals:Christopher Joe Powell . . . . a resident of Georgia, met Vanneise Collins, a resident of Drew County, Arkansas, on an internet website for singles. Over the course of several months, the two engaged in lengthy e-mail and telephone communications, striking up a romance. The romance culminated in three face-to-face meetings in Georgia, and ultimately, a marriage proposal. Throughout the course of their romance, [Powell] made certain representations about himself that proved to be wholly fabricated, such as his being unmarried, being in the army, and being deployed in Iraq during portions of the time he and Collins were in contact. Collins made concrete marriage plans, such as putting a deposit down on a wedding dress and mailing out wedding invitations. All the while, Collins sent [Powell] money when he asked, via Western Union, for a variety of reasons, including new golf clubs, property taxes on inherited property, medical bills, a new military dress uniform, and to `grease palms’ while being separated from his unit in Iraq. [Powell] obtained about $15,000 from Collins. When she began to doubt him, she verified that there was no record of him being in the military and eventually went to the police.
Powell v. State, 2007 WL 104103 (Arkansas Court of Appeals, January 17, 2007).Powell was charged with, and convicted of, theft and computer fraud.
- The theft charge was based on a statute that defines “theft” as using “deception” to obtain the property of another person. Arkansas Code § 5-36-103.
- The computer fraud charge was based on a statute that defines “computer fraud” as using a computer or computer network to “devise” or execute a “scheme or artifice to defraud, i.e., to obtain “money, property, or a service with a false or fraudulent intent, representation, or promise. Arkansas Code § 5-41-103.
They may seem like the same offense, but the law would distinguish them on the premise that each contains a element the other does not. So the theft charge does not require the use of a computer and the computer fraud charge reaches conduct that is slightly different from theft, i.e., it requires false representations. (That’s essentially it, though it is a little more complicated.)In his appeal, Powell didn’t focus on the similarity of the charges but on the issue of jurisdictoin: Powell claimed " the trial court erred in asserting jurisdiction over this matter, contending that all elements of the offenses charged occurred outside the territorial jurisdiction of Arkansas.” Powell v. State, 2007 WL 104103 (Arkansas Court of Appeals, January 17, 2007). The Court of Appeals noted it was “undisputed that appellant never entered the State of Arkansas until such time as he was arrested and transported to Arkansas to answer the criminal charges of theft and computer fraud in Drew County.” Powell v. State, supra. Powell actually had a pretty creative argument. Here is what he said:Appellant claims that . . . these crimes are defined by the conscious act of the wrongdoer. Cousins v. State, 202 Ark. 500, 151 S.W.2d 658 (1941), provides that if a crime covers only the conscious act of the wrongdoer, regardless of its consequences, the crime takes place and is punishable only where he acts. Therefore, appellant argues that the conduct of obtaining the property of another by deception and accessing a computer system or network, occurred in Georgia.
He argues that he only sent an e-mail from Georgia through the network to Arkansas, which the complainant then accessed in Arkansas. The scheme was devised in Georgia, and the money was obtained in Georgia. . . . He claims that because the legislature defines these offenses as the purpose of the wrongdoer, all elements of the crimes occurred in Georgia, outside the territorial jurisdiction of Arkansas.
Powell v. State, supra.The Arkansas Court of Appeals, not surprisingly, disagreed:The State alleges that Ark.Code Ann. § 5-1-104(a)(1) controls because the State can show that the conduct or result that is an element of the offense occurred within Arkansas. We agree. Appellant sent e-mail correspondence to Collins and contacted her by telephone while she was in Arkansas. During the course of those communications, appellant actively deceived Collins into sending him money. Moreover, appellant caused Collins to access her computer by virtue of his e-mail correspondence, for the purpose of obtaining money with a false or fraudulent intent, representation, or promise. The deception and promises were his extensive fabrications. We hold, therefore, that substantial evidence existed to support the trial court's finding that it had jurisdiction in the instant case.
Powell v. State, supra. The Court of Appeals therefore affirmed Powell’s conviction, which presumably means he will now serve the sentence the trial court imposed on him: “eight years' imprisonment for theft of property, five years' imprisonment suspended for theft of property, six years' imprisonment for computer fraud, and three years' imprisonment for failure to appear for trial on August 24, 2005.” The approach the Arkansas court took in this case is common in other US cases, both state and federal, and is the predominant approach in cybercrime cases internationally. Any other result would let someone commit cybercrimes with complete impunity, as long as they targeted people in another country.
As you may know, law enforcement officers are using file-sharing programs like Limewire to search people’s hard drives for child pornography. This summary of facts from a recent case – United States v. O’Rourke, 2007 WL 104901 (U.S. District Court for the District of Arkansas – gives you an idea how this works:Defendant O'Rourke came to the attention of the FBI on January 3, 2005, when Special Agent Robin Andrews conducted an undercover investigation of people involved in the possession and distribution of child pornography. . . . Conducting a search through the peer-to-peer Internet file sharing software known as `Limewire,’ Agent Andrews downloaded images of child pornography from Defendant's computer. . . . The FBI was able to identify Defendant through his Internet Protocol address and a subpoena of his Internet Service Provider, and subsequently obtained a search warrant for Defendant's home and computer. . . . The search warrant was executed on February 22, 2005, and Defendant's computer was found to contain 46 movie files and several hundred still images of child pornography. . . . The Government alleges that these movies and images were saved on Defendant's hard drive and were available to be downloaded over the Internet by others using Limewire software. . . .
The Government seized Defendant's computer and presented evidence to a federal grand jury. The grand jury indicted Defendant. . . .
Here’s a summary of what happened in a similar case involving a search by a state officer:[T]his case began on February 28, 2005, when at 4:35 p.m., Trooper Robert Erderly of the Pennsylvania State Police was logged onto a computer located at the Pennsylvania State Police barracks in Indiana, Pennsylvania. . . .
Installed on the computer. . . was a file-sharing software program called Phex. Trooper Erdely used the Phex program to search for files on the Gnutella network.. BearShare and LimeWire are other such file-sharing software programs. . . .
The Gnutella network, BearShare, Phex and LimeWire share all types of files, including music, movie, photograph/still image, and text files. . .
On February 28 2005, the defendant, Arthur Abraham, was logged on to his computer at his residence at 3129 West Queen Lane, Philadelphia, Pennsylvania, and running a peer-to-peer file-sharing program called BearShare, version 4.6.3. . . .Once BearShare is installed, any file a person chooses to share is available to anyone on the Gnutella network. Every computer that is running this Gnutella network can participate in the sharing of the files. In order to install . . . the BearShare program . . . the defendant had to have accepted the terms of an end user software licensing agreement. With this agreement, the user acknowledges that he is using a file sharing program which can be used both to download files and to send files out over the Internet, i.e. share files. . . .
Returning to . . . February 28, 2005, the. . . defendant had to have his computer on and be using the "share the files in the library" option . . . when Trooper Erdely did his search because Trooper Erdely found the file being shared and was able to download it from the defendant's computer. . . .
Trooper Erdely knew that there was a movie file that was being shared across the Internet which is named Hindoo. Utilizing the Phex program, he searched the word Hindoo and got a number of hits. Once the result of Trooper Erdely's search came up, the Internet Protocol ("IP") addresses of those sharing the files on which Trooper Erdely got a hit were visible.
One of the IP addresses from one of Trooper Erdely's hits was an IP address belonging to Verizon Internet service. The IP was 141.151.19.66. . . . The complete name of the file being shared by IP 141.151.19.66 was (Hussyfan)(pthc) (r@ygold) (babyshivid) Hindoo4.mpg. Exhibit 5, unnumbered page 2.
Trooper Erdely obtained a state court order compelling Verizon to tell him who was the subscriber with the IP address 141.151.19.66. Verizon informed Trooper Erdely that the subscriber of that service at that date and time was . . . Arthur Abraham of 3129 West Queen Lane, Philadelphia, Pennsylvania 19129.
Trooper Erdely downloaded the file "Hindoo" that IP address 141.151.19.66 was sharing onto a CD Rom. The file on the CD Rom that Trooper Erdely downloaded from IP address 141.151.19.66 contains child pornography as prohibited by law. . . .
On March 17, 2005, a warrant was obtained to search the defendant's house at 3129 West Queen Lane, Philadelphia, Pennsylvania 19129. . . .
United States v. Abraham, 2006 WL 3052702 (U.S. District Court for the Western District of Pennsylvania 2006).I find many things interesting about how law enforcement officers are using file-sharing programs to hunt for child pornography, but the one I want to focus on here wasn’t raise in the opinions in either of these cases, nor was it raised in the four other similar cases that are reported in Westlaw.The issue is the Fourth Amendment which, as I’ve noted before, protects us from the government’s conducting “unreasonable” searches and seizures. The issue that would determine the applicability of the Fourth Amendment to the conduct of Agent Andrews and Trooper Erdely is whether what they did resulted in a “search” or a “seizure.”As I’ve said before, a Fourth Amendment search is law enforcement’s intruding into a place, or an activity, in which the person has a “reasonable expectation of privacy.” You have a reasonable expectation of privacy in a place – your home, say – if (a) you think it’s private (subjective expectation) and (b) society agrees it is reasonable for you to think that (objective expectation). The home, of course, is clearly private – we all think our homes are private and our society emphatically agrees. That doesn’t mean law enforcement officers can’t search our homes; it just means they have to get a search warrant to do so.The computers in both of these cases were in homes. Was it, then, a search for the law enforcement officers to access the hard drives on the computers to locate and copy a file or files (which, arguably, is a seizure)? On the one hand, you could argue it was a search because we have an intrusion – a virtual kind of intrusion – by law enforcement into someone’s home. On the other hand, you can argue this is not a search because O’Rourke and Abraham both “opened the door” for law enforcement officers to “enter” their computers by installing and using the file-sharing software.
That is, as to the second argument, you can argue that (a) neither O'Rourke nor Abraham could have had a subjective expectation of privacy in their hard drives because they knew they were using file-sharing software and were online and (b) regardless of what they thought, society would not accept the notion that their hard drives were private given their use of that software. Society, in other words, would see their using the file-sharing software as the equivalent of my (hypothetically) putting my favorite marijuana plant (purely hypothetical) on a table next to the large window on the front of my house and pulling back the curtains so it could get plenty of sun. It would not be a search for a police officer to walk by and see the marijuana plant -- I gave up any expectation of privacy I had with regard to the plant by putting it on public display.
I assume none of the defendants raised the Fourth Amendment argument because they thought it would fail . . . or maybe they did raise it unsuccessfully and the courts simply did not issue a published opinion on that issue. I can see why the second argument would probably prevail . . . there's a long line of cases which say that if you engage in criminal activity with other people, don't complain if one of them turns out to be a snitch or, worse yet, an undercover FBI agent.
It seems to me, thought, that the second argument against law enforcement's using file-sharing software to explore people's hard drives raises a larger, perhaps more difficult issue: If I link my computer to a network, have I lost any Fourth Amendment expectation of privacy in the contents of my hard drive?
I don’t know about you, but for a while, a couple of weeks ago, I was being bombarded with emails telling me I’d won the UK National Lottery . . . which was pretty astonishing, given that I hadn’t played.The emails were, of course, a scam . . . scam spam. The initial email says you’ve won a million or three British pounds in the lottery, and all that needs to be done now is to arrange for transfer of the funds to you, the lucky winner. I didn’t follow up on any of the emails, of course, but from what I’ve seen online the ultimate goal is to get you to send personal and bank account information to the scammers, who will presumably then use that to clean out any accounts you happen to have.Seems pretty obvious, doesn’t it? They all – all of the 419 and other spam scams – seem pretty obvious to those of us who congratulate ourselves on being too clever to be taken in, but they must be working on some subset of the population or they wouldn’t keep cropping up in new and more or less creative guises.And that brings me to my point. According to Wikipedia, Barnum’s Law is “You’ll never go broke underestimating the intelligence of the American public.” I’d modify that a bit for our online environment, so that it emphasizes complacency instead of intelligence (or the lack thereof). What I find interesting about the UK lottery and all the other online scams is that ANYONE would be foolish enough to trust something that comes to them out of the blue from a purely unknown source . . . and yet people do. I’m reminded of a story I heard a few days ago, from a law enforcement officer who deals with cybercrime. He told me about overhearing another officer, who works with online fraud, having a conversation with an online fraud victim. That officer had apparently heard too much from victims of transparently fraudulent online scams because at one point he said to the victim, “I know $3,000 is a lot of money, sir . . . that’s why I wouldn’t sent it to Romania.” Why would anyone do that? Why would anyone send money out into the ether to an unknown someone in an unknown someplace and not expect to be scammed?It goes back to my comment about complacency. The picture accompanying this post is, obviously, the interior of a prison. The point is crime control: For roughly a century and a half, we have been relying exclusively on cadres of professional law enforcement officers to keep crime under control in our societies. We do not, indeed, cannot, eliminate crime; our goal therefore is simply to keep it within manageable levels so citizens can go about their daily, legitimate activities with relatively little risk of being victimized. We control crime by having dedicated professionals who apprehend criminals (most of whom are notably inept when it comes to evading identification and capture), who are charged, tried, convicted and sentenced to serve time in places like the prison in the picture. The premise is that this controls crime by (i) deterring and incapacitating the particular criminal for the time he/she is locked up and (ii) deters others from emulating his/her criminal activity by making an example of this person. It’s not a perfect strategy, but it has worked satisfactorily in the real-world since it became the dominant model well over a century ago.The problem for the online environment is that the dominance of this law enforcement crime control model in the real-world means that the average individual takes absolutely no responsibility for crime control. That is the police’s job, not mine – if my house is robbed because (hypothetically) I was foolish enough to leave my front door unlocked when I went to work, I can still call the police and they will still make a good-faith effort (maybe not their best effort, but an effort) to find the thief. The point is that my lack of responsibility, my failure to take even minimal precautions to protect my property, is irrelevant. In the civil law of torts, we have a doctrine called assumption of the risk, which can negate liability; so, basically, if I go bungee jumping knowing I have a fractured vertebrae, and wind up a paraplegic, I can’t recover from the bungee jumping people because I assumed the risk of my injury.We don’t have that principle in criminal law, because a crime is an offense against the state, not against the victim. That being the case, the victim’s stupidity or irresponsibility is irrelevant – the state still needs to go after the criminal for the reason I noted above: to deter/incapacitate him/her and to deter others from following his/her example.The result of all that, I submit, is a level of complacency. Most of us give little, if any, thought to the threat of being victimized by a criminal as we go about our daily lives. We may have alarm systems in our houses and cars and offices, but that, again, is a type of delegation – I don’t have to think about security, I delegate it to the professionals who will take care of it for me.Then we go online. There isn’t anyone to whom we can delegate the responsibility for protecting us when we are online. Unless and until there is (which I’m not sure I want to see – I tend to like the idea that cyberspace is a raucous place with varied experiences, good and bad), we will have to take care of ourselves online. And that brings me back to the title of this post: healthy paranoia.My sense is that people sixty, eighty, a hundred years ago were much less complacent and much more likely to be skeptical of strangers and their strange offers . . . and that the same was true for much of human history. Now, part of that would have bee a function of pure provincialism – the stranger coming to a small town/village would have been met with suspicion by people who seldom encountered anyone they had not known for years. But I also think much of it, particularly in more urbanized societies, was due to sad experience with face-to-face fraudsters. “The Big Con” by David Maurer, a book that was originally published in 1940 and was reprinted recently, describes the various types of scams real-world con artists used on civilians in the first several decades of the twentieth-century. Many of the scams had their roots in scams that went back centuries.The success of those scams throughout history tells us there have always been, and no doubt will always be, people who fall for what is clearly too-good-to-be-true. I suspect, though, that the combination of the online environment and our pretty much surrendering responsibility for protecting ourselves from crime has led us, as a population, to be more susceptible to con artists than people were in the past. If you don’t believe me, consider the story I described above: The person sent $3,000 to someone he knew nothing about in a country (Romania) known for harboring cybercrime . . . and expected a local police officer to get the money back and bring the perpetrator to justice. None of that computes, none of that works, none of that makes any sense at all . . . except, maybe the last part. This person, I would argue, did not exercise health paranoia in assessing the too-good-to-be-true offer from Romania because he assumed (i) that it was legitimate and (ii) that if it was not, law enforcement would take care of it.It wasn’t, they can’t . . . and somehow people have to realize that.
In Quon v. Arch Wireless Operating Company, 445 F.Supp.2d 1116 (Central District of California, 2006), a federal district court held that a police sergeant had a Fourth Amendment expectation of privacy in messages sent from and received on the pager his department supplied him for official uses. (Note: Here I'm only talking about Fourth Amendment expectations of privacy. Other privacy issues can arise under statutes, under employment contracts, etc., especially for private employees. Here we’re dealing with a classic Fourth Amendment scenario: state employee and state action – the police department’s auditing the messages.)The case was a civil suit asserting violation of privacy, and presented many issues I won’t even attempt to go into. I want to address the issue of a public employee’s Fourth Amendment right to privacy in a pager (or other electronic communication device) provided by his or her employer.
In O'Connor v. Ortega, 480 U.S. 709 (1987), the U.S. Supreme Court held that public employees can have a Fourth Amendment expectation of privacy in their desk or other work-related areas. The Court said that the issue has to be decided on a case-by-case basis, and that "[p]ublic employees' expectations of privacy . . . may be reduced by virtue of actual office practices and procedures, or be legitimate regulation." So, what often happens in cases involving police searches or other official intrusions into a public employee’s email or other communications is that the court will see if the agency the person worked for had a policy which said, say, “there is absolutely no expectation of privacy in any email you send or receive on this system.” Email systems often have a banner that has an announcement to this effect, and courts usually find that this negates any expectation by the employee that his or her email will be private.Basically, the employee usually loses on the Fourth Amendment argument, but that didn’t happen here. The federal district court found that the police sergeant (Quon) did have a Fourth Amendment, reasonable expectation of privacy in the messages sent and received on his pager because of a basically ad hoc policy announced by a supervising police lieutenant. Here’s what the court said:Lieutenant Duke made it clear to the staff, and to Quon . . . that he would not audit their pagers so long as they agreed to pay for any overages. Given that Lieutenant Duke was the one in charge of administering the use of the city-owned pagers, his statements carry a great deal of weight. Indeed, before the events that transpired in this case the department did not audit any employee's use of the pager for the eight months the pagers had been in use. This was true even when overages were involved. Lieutenant Duke in effect turned a blind eye to whatever purpose an employee used the pager, thereby vitiating the department's policy of any force or substance. By doing so, Lieutenant Duke effectively provided employees a reasonable basis to expect privacy in the contents of the text messages they received or sent over their pagers; the only qualifier to guaranteeing that the messages remain private was that they pay for any overages. . . .
That the pager in question was owned by the City adds nothing by itself to the analysis. A per se rule that public employees cannot have a reasonable expectation of privacy when using property owned by their employer would be at odds with the Supreme Court's holding in [O’Connor v.] Ortega. There the Supreme Court held unanimously that the employee could have a reasonable expectation of privacy in the personal items he stored in a desk that was presumably owned by his employer. . . . . Here, any lessened expectation of privacy in one's pager messages due to it belonging to the City was canceled out by what the City, through Lieutenant Duke, communicated to its officers on how they could use that equipment.
Similarly, defendants' plea that the use of such equipment in the workplace is entitled to a lesser expectation of privacy given . . . `social norms’ -specifically, that `with the proliferation of’ various electronic communication systems "in the work place, it is extremely common for employers to monitor employee usage of these devices and systems"--loses its salience in light of the particular circumstances of this case. Appeals to broad societal norms quickly give way once an employer, like the defendants in this case, promulgates and announces a policy to its employees detailing how much privacy to expect in using specified equipment. At that point such general norms are trumped by the particular norm that was implemented in the work place in question. . . . The Court finds that it is unreasonable to expect that an employee would assume that some other unstated norm should inform their opinion on how much privacy to expect in using an employer's equipment once that employer expressly informs his or her employees of an actual policy regarding the use of that very equipment.
Quon v. Arch Wireless Operating Company, 445 F.Supp.2d 1116 (Central District of California, 2006).Here the employee wins on the Fourth Amendment privacy issue because a senior employee basically negated the policy the police department had established. I’ve seen another case or two where something like this happened, in one instance because the public agency had (very reasonably I’d say) told employees they could use their office computers for private data and private emails. Having said that, the agency then created a Fourth Amendment expectation of privacy.My sense, though, is that agencies are usually very careful to make it clear that their employees have no expectation of privacy in agency computers, pagers, etc., and do not send conflicting messages, as in this case.
I've been reading about the British government’s plans to implement a provision of the Regulation of Investigatory Powers (or RIPA) Act.
RIPA was enacted in 2000, but the government has held off on implementing Part 3 of the Act. Under British law, Part III must be activated by a ministerial order before it goes into effect.Part 3 of RIPA gives police the authority to order someone to give their encryption key to the police. If the person refuses to hand over the key, it is a crime.
Section 53 of RIPA makes it an offense, punishable by up to two years in prison, to knowingly refuse to surrender an encryption key after having been directed to do so by police.
The only defense the person can raise under the provisions of RIPA is that they did not have the key at the time they were ordered to turn it over. If they raise that defense, then the prosecution has to prove beyond a reasonable doubt that they did, in fact, have the key when they were ordered to produce it.The possibility the British government will implement Part III apparently has many concerned, especially, according to one article, those in the financial industry. The author of that article quotes various sources as saying that bankers and others in the financial industry would be concerned about bringing master encryption keys into the United Kingdom, for fear they would be seized by police, for whatever reason.
Under Part III of RIPA, to get an order requiring disclosure of an encryption key police only need believe “on reasonable grounds” that the key is in the possession of a specific person and that its disclosure is “necessary” (i) in “the interests of national security,” (ii) for the purpose of preventing or detective crime” or (iii) “in the interests of the economic well-being of the United Kingdom.” (I assume (iii) goes to investigating possible economic espionage.)The British police claim they need the ability to require the production of encryption keys to be able to effectively investigate terrorism, child abuse and other serious crimes. One detective was quoted as saying police had “over 200 PCs” containing encrypted data “sitting in property cupboards,” the inference being that the encrypted data includes evidence of crimes (or terrorism). So, police argue that unless they have the power to obtain encryption keys any clever criminal or terrorist can stymie an investigation by encrypting critical evidence.There is no statutory analogue of Part III of RIPA in the United States, for what I think is a very good reason: the Fifth Amendment privilege against self-incrimination. The Fifth Amendment protects individuals (not corporations or other artificial entities) from being “compelled” to be a “witness against” themselves. The Supreme Court has construed this as meaning that you cannot be compelled to testify against yourself, but you can be compelled to give up physical evidence – samples of your blood, hair, etc.The Supreme Court’s reasoning is that witnesses “testify,” so the historical meaning of the Fifth Amendment is rather narrow: You can’t be forced to testify against yourself, but you can be forced to cooperate with an investigation as long as you don’t have to testify.In the U.S., police have no way to force someone to give up an encryption key – they can ask for it, but if the person refuses to give up the key, that’s that. A prosecutor can, however, use a grand jury subpoena (state or federal) to compel someone to give up an encryption key. If the person does not give up the key in compliance with the subpoena, they will be held in civil contempt and incarcerated until they do. (Think Judith Miller, the NY Times reporter who refused to identify a source when ordered to by a grand jury, and who then served time in jail for contempt.)Could you take the Fifth and refuse to give up your encryption key if a grand jury issued a subpoena ordering you to do so? You can if giving up the key is “testimony,” but you can’t if it’s only the act of producing physical evidence (like handing over a gun).If you have memorized the key (which is unlikely), then providing it to law enforcement should clearly be testimony. The dynamic would be as follows: The grand jury issues a subpoena ordering you to appear before the grand jury and give them the key. You show up on the date and time ordered. The prosecutor asks you what the key is and you recite it. I don’t think anyone would dispute that this would be testimony, which means you could invoke the Fifth and refuse to comply. But what if, as is far more likely, you have recorded the very long and complicated key somewhere? Now instead of reciting it you’d be handing it over. That could be dicey. Under the Supreme Court’s interpretation of the Fifth Amendment privilege, you can take the Fifth for the act of handing over evidence to the government if, in doing so, you “tell” them something they don’t know. You can’t take the Fifth if they already know you have the thing; here, you’re not “telling” them anything.Much as I’d like to say that you could take the Fifth and refuse to hand over the recorded key, I’m not sure that’s true. The government wouldn’t be asking for it if they didn’t know it existed and didn’t know you have it . . . so it doesn’t seem you tell them much if you hand it over. Now, I suppose you could argue that you do “tell” them something, in that you give them the data – the characters – the constitute the key. A prosecutor would respond to that argument by pointing out that you already “testified” to that information when you recorded it – you’re not, as in the previous instance, being asked to “speak” the information. You’re merely being asked to hand over information you wrote – information you “spoke” – at an earlier time. If a court buys that argument, then we would have, in effect, the same result in the U.S. as will exist if and when Part III of the RIPA goes into effect in Britain.It’s a very difficult set of issues. On the one hand, encryption is an essential component in preserving privacy in an increasingly-automated world. On the other hand, what the British police said is quite true: criminals and terrorists can use encryption to put data outside the reach of law enforcement.This may be a transient issue. I understand U.S. intelligence agencies are able to break even very sophisticated encryption. If and when that ability migrates to local police, they won’t need the power to coerce someone into giving up their encryption key . . . at least not unless and until someone comes up with a mode of encryption that cannot be broken or with some other way of securing data in an unbreakable way.
Last time I wrote about online stalking.
Today I want to write about a related issue: online imposture. Basically, online imposture consists of going online and pretending to be someone else.
It can be relatively harmless; I remember reading about ten years ago about an expert on online culture. She was puzzled when she got emails from people complimenting her on comment she'd made in a chat room the other night. Problem was, she had not been in the chat room. It seems someone had simply taken her identiy out for a ride -- had a good time pretending to be her and pontificating online for a bit.
That was harmless online imposture. It can also be harmful, and that is the kind I want to address.
I’m going to begin by summarizing a couple of incidents to illustrate what harmful online imposture is and how it occurs. Then I’ll talk a bit about the legal issues online imposture raises.Let’s start with the incidents:- The following facts come from an article in the Milwaukee Journal-Sentinel. (Lisa Sink & Linda Spice, Man Charged with Defamation, Milwaukee Journal Sentinel (June 7, 2000), 2000 WLNR 3077063.) After his boss fired him, David Dabbert went to the “`Sex on the Side’” website, which “features `attached’ women who are seeking sexual encounters `on the side’”. Dabbart posted an ad on the site that purportedly came from his former boss, using her real name and email address. The ad “described her chest size and hair color and, in part, said: `I'm highly stressed out. . . . I've only been with my hubby. He's gone at work 24 hours at a time . . . I want someone to make me their slut for the night’”. The woman received many responses to the ad, which left her frightened and embarrassed.
- Here’s another case reported by the same newspaper. (Lisa Sink, Family Therapist Investigated in Internet Complaint, Milwaukee Journal Sentinel (March 14, 2000), 2000 WLNR 3057614.) According to the article, a family therapist “posed as his former wife's new husband and posted an ad on an Internet site for swingers, asking interested men to call the couple.” It gave “the ex-wife's body measurements and home phone number and said: `Wife and I desire 3some with a male." The ad “prompted a slew of calls to the woman and her new husband”, which, again, left them frightened and embarrassed.
If we assume, as I do, that the facts were correctly reported in both stories, then we have two instances of online imposture: cases in which person A goes online and pretends to be person B. Before we deal with the legal issues, let’s just consider this as a phenomenon. Online imposture has several dimensions: In these cases , it seems the imposture was undertaken for vindictive purposes – to embarrass the person who was the object of the imposture. Now one can embarrass another person – offline or online – by publishing discreditable information about them. So if someone (hypothetically) went online and published an allegation that I am a drug addict, that allegation would embarrass me, whether it was true or not. If the allegation were true (and I assure you it is not), then the embarrassment would result from the dissemination of true information. The publisher of the information would in effect have invaded my privacy by revealing that which I chose to keep secret. If the allegation were not true (as I assure you it is not), then the embarrassment takes on a different tone. Now it is not merely an invasion of privacy – the revelation of true information I am trying to conceal – but a misrepresentation that casts me in a “false light” . . . that depicts me as being something I am not, something that is disreputable.
The distinction between publishing true discreditable information and not-true discreditable information gets us into the first legal issue we need to deal with. In either of the above scenarios, I would certainly be angry about the publication of the (again, purely hypothetical) allegation that I am a drug addict. If I were like most people, I would probably want some kind of redress – some kind of vindication/revenge/all that. So I might decide to sue the person who published this allegation (if, of course, I can identify who published the allegation). If the allegation were true, then I would probably not have a case for defamation. The basic rule in this country is that truth is a defense to an action for defamation. So, think about that: if I decide to sue the person who published the allegation that I am a drug addict, I will in essence have to prove in court that I am not, never have been, a drug addict. Now, I may be able to prove that quite easily . . . but I would still have to go through the embarrassing process of having to prove I am not a drug addict, something I used to be able to assume people know. (I might also have to deal with the possibility that, even if I won, some people would always wonder if the allegation was true . . . . ) If the allegation were not true and I could prove that, then I should be able to win in my defamation suit against the person who published it. Now, though, we come to a practical problem. Most of the people I know – probably most of the people you know – don’t have a lot of money. So what good is m civil suit if the person who published the allegation doesn’t have thousands and thousands (millions and millions) of dollars to pay me and my lawyers when I win? If the person I want to sue clearly doesn’t have enough money to pay a judgment and attorneys’ fees, then most lawyers won’t want to take my case unless I can show, up front, that I can pay the very large sum of money it will cost to litigate and win. I don’t have that much money, so even though I would have the legal basis for a defamation suit, in practice that’s really not an option. I assume it was not an option for the victims in the online imposture cases I described earlier. I might try to deal with the defendant-who-has-no-money problem by suing the operator of the website on which my tormentor published the false allegation that I am a drug addict . . . but that raises another problem. Historically, those who published defamatory material could be held civilly liable for their role in defaming someone. This is not true for online publication: A section of the Communications Decency Act, “overrides the traditional treatment of publishers. . . . ‘such as newspapers, magazines or television and radio stations, all of which may be held liable for publishing . . . defamatory material written or prepared by others.’” Batzel v. Smith, 333 F.3d 1018, 1026 (9th Cir. 2003). Concerned about lawsuits inhibiting free speech online, Congress added Section 230(c)(1) to title 47 of the U.S. Code. It states that “[n]o provider or user of an interactive computer service shall be treated as the publisher . . . of any information provided by another information content provider.” 47 U.S. Code § 230(c)(1). The effect of this provision is to immunize those who post content that is provided by someone like the hypothetical individual who posted the (quite false) allegation that I am a drug addict. The result is that my attempt to seek civil redress for the embarrassment I suffer from having that false allegation published will fail because (a) the person who posted the false information has no assets to pay a judgment or attorney’s fees and (b) the website operator is immune from suit.In the Dabbart case, the local district attorney’s office prosecuted him for criminal defamation . . . and won. (Lisa Sink, Man Convicted Of Posting Ex-Boss' Name On Sex Site Defamation Case Believed To Be County's First Such Internet Prosecution, Milwaukee Journal Sentinel (August 11, 2000), 2000 WLNR 3037734.) Dabbart wound up pleading no contest to a misdemeanor defamation charge; he was sentenced to serve 15 days in jail, to two years on probation, to pay $1,280 in restitution and to perform 100 hours of community service. According to this new story, the victim urged Wisconsin lawmakers to “find new ways to charge individuals who pose as others over the Internet for lewd purposes.” (Sink, Man Convicted Of Posting Ex-Boss' Name On Sex Site Defamation Case, supra.) This is an issue I explored in a long law review article I wrote recently. Criminal defamation (criminal libel) is very seldom used in this country – indeed, does not even seem to be a crime in many states. The reason is that our state criminal law was very much influenced by the Model Penal Code – a template of state criminal law that was drafted about fifty years ago. The Model Penal Code did many great things in terms of modernizing what had been a patchwork of criminal law derived from English common law.It departed from English common law, though, in basically rejecting the notion of treating defamation as a crime. The drafters of the Model Penal Code (who said this was the most difficult decision they made) decided that defamation was better handled civilly than criminally.I think they were probably right when they made that decision, about fifty years ago, but the landscape has since changed dramatically. When the drafters of the Model Penal Code decided defamation should not be a crime, they assumed that defamatory material would be published on television, in a newspaper, in a magazine – in the mainstream-media, in other words. And that was true when they wrote – if you think about it, fifty years ago someone with a grudge could not simply publish the kind of claims involved in the two cases I described at the beginning of this post. If they took that material to a newspaper or a magazine, they would have been sent packing.The drafters of the Model Penal Code therefore implicitly assumed that someone injured by the publication of defamatory material would be able to find a deep-pocket to sue . . . someone with assets to pay attorneys’ fees and a judgment. As I’ve explained, that is no longer true: With online publication, anyone can pretend to be someone else and publish information that casts them in a seriously embarrassing light. The person who has been embarrassed cannot sue the individual who published the defamatory material unless that individual has enough assets to pay a judgment and attorneys fees (or unless the injured party does). The person who has been embarrassed may not even be able to identify the individual responsible for publishing the material, because it is so easy to be anonymous online. And, as I explained earlier, the operator of the website on which the material was published is, unlike conventional mainstream-media outlets, immune from suit for publishing the material.So, maybe we should reconsider criminalizing defamation.
In 1999, a new and bizarre kind of stalking occurred in a small town, as is described in detail by Boston Globe reporter Michele Kurtz. (The “Stalker” Who Stayed at Home: A Town Terrorized Over the Internet, Boston Globe (Sept. 2, 2001)).
Twenty-year old Christian Hunold, who lived in Smithville, Missouri, stalked the students and faculty of the Hawthorne Brooke Middle School in Townsend, Massachusetts. Hunold, a high-school athlete and honor student, was seriously injured in a 1995 auto accident. He recovered from most of his injuries but lost the ability to walk. According to Michele Kurtz, his disability left Hunold “seething” . . . and bored. She says he turned to the Internet, where he could become someone else: “Someone physically strong, someone living thousands of miles from Smithville. In the cyber world, no one would know the difference.” (Kurtz, The “Stalker” Who Stayed at Home). He apparently met students from the Hawthorne Brooke Middle School in a chat room devoted to Limp Bizkit, and struck up a friendship with the eighth graders, who invited him to join them in a private chat room. Hunold decided to pretend he was one of them, and to show them a thing or two about the real world.
By studying the kids' Internet profiles, Hunold was able to learn some of their birth dates, addresses, and hobbies. He created a computer file where he detailed what he knew about each student. Every online conversation with one of the kids contained another helpful nugget about someone else.
`When he talked to these kids, he knew specific things, like where they lived, what their house looked like, if they had a dog, what table they sat at at lunch,’ says Townsend Police Sergeant Cheryl Mattson, who investigated the case.
Within a few weeks, the banter between Hunold and the Townsend kids became more threatening. Hunold bragged he was a serial rapist and would come after them. He pointed students to child pornography online, including pictures of a 5-year-old girl being raped.
(Kurtz, The “Stalker” Who Stayed at Home).It became increasingly difficult for him to sustain the pretense that he was a Hawthorne Brooke student. The students began challenging him, a “loss of control that infuriated him.” (Kurtz, The “Stalker” Who Stayed at Home). He responded by telling them he was going to blow up the school and then by posting a website that depicted Hawthorne Brook Middle School seen through the crosshairs of a rifle scope. There was a picture of the school principal, made to look like he was bleeding through bullet holes in his head and chest. And there were references to Columbine, which had shocked the nation only five months before. . . .
(Kurtz, The “Stalker” Who Stayed at Home). He posted a “hit list” that contained the first names of 24 students and the last names of 3 Hawthorne Brooke teachers. Underneath the list he wrote: `You lucky individuals will go home with more holes in your body than you came with.’” (Kurtz, The “Stalker” Who Stayed at Home).Hunold was halfway across the country, had no weapons and no intention of carrying through on this threats. For him, it was a game – he was manipulating the students (and, indirectly, their teachers and their families) for his own amusement – to boost his ego. (Kurtz, The “Stalker” Who Stayed at Home).Not surprisingly, the Hawthorne Brooke teachers, students and parents were terrified. They knew the person who was sending the threats “had to be” local because he knew so much about the students. They assumed he was a Hawthorne Brooke eighth-grader; Hunold encouraged this by identifying himself as a particular eighth-grader, who was harassed because of that. Parents whose children were on the “hit list” didn’t know what to do – whether to send the children to school or keep them at home. Police brought in bomb-sniffing dogs to patrol the hallways and classrooms of the school. Teachers searched student bags and other possessions, and some parents considered arming themselves to protect their children and themselves.The Massachusetts State Police traced some of the mysterious person’s Internet activity to Missouri. At first they assumed the person was in Townsend and was routing his messages through Missouri, but they rather quickly figured out that the person was in Missouri. (Kurtz, The “Stalker” Who Stayed at Home). Massachusetts and Missouri officers collaborated in searching Hunold’s computer and interviewing him; he readily confessed to what he had done. In October, 2000, Hunold pled guilty in Missouri to three felony counts of attempted promotion of child pornography and one misdemeanor count of harassment. (Similar charges were filed in Massachusetts but dismissed on the grounds that Massachusetts law did not criminalize the use of computer technology to distribute child pornography.) He was sentenced to 15 years in prison and served 120 days.For some reason, the Hunold case reminds me of the Twilight Zone episode “The Monsters Are Due on Maple Street.” In that episode, space aliens (who look a lot like humans) manipulate electricity and a few other things to create paranoia in the good citizens of a pleasant suburb. The locals decide aliens are among them and turn on each other. As one source puts it, “total madness breaks out.”It reminds me of that Twilight Zone episode because there really was no danger to the students or anyone else in Townsend, but Hunold was able to make everyone believe there was. My sense, from speaking to people familiar with the case, is that a little bit of the Twilight Zone episode began to happen in that no one knew who to trust. The mysterious person sending the threats might have been one of the students, might have been a teacher, might have been a staff person . . . might have been anyone. Hunold’s activities are a great example of how someone can use online imposture to break down the trust we assume, and rely on, in our everyday lives.What I find most chilling about the Hunold episode is not what happened in Townsend, but what might have happened after. When police searched Hunold’s computer, they found evidence that led them to believe he was planning to do the same thing to a school in Georgia. I suspect he would have done an even better job of cultivating paranoia and inculcating terror the second (or third?) time around. What he did in Townsend seems to have been pretty much an accident, something that evolved as he developed an online relationship with the eighth-graders, whom he sought to control. The next time his efforts would have been more calculated and therefore, I think, even more devastating.In terms of today’s law, Hunold could also have been charged with cyberstalking, which basically means someone used computer technology to engage in a course of conduct that inflicted serious (or substantial) emotional distress on another person. It can also encompass threatening someone with death or serious bodily injury. So I see no reason why Hunold could not have been charged with stalking, at least under current law. What I see as interesting is that he did not merely stalk. He played with the lives of people in Townsend just as the fictive Twilight Zone aliens played with the people in that suburb. Somehow, that seems more than stalking.