Sunday, April 29, 2007

Confidence

Confidence: “n.That which is confided, a secret.”

I have an article coming out in the Mississippi Law Journal in which I analyze whether we should criminalize defamation as a way of controlling certain kinds of “problematic” speech online.

By “problematic” I mean cases like the one in Wisconsin in which the fired employee retaliated by using his former boss’ name, address and phone number in a posting he added to “Sex on the Side,” a website for married women who are looking for “action on the side.”

That Iwas a clever, nasty way to cause this woman a lot of grief.


It's also a good example of the kind of thing defamation law COULD be used to discourage because this incident has all the basic elements of defamation: a false statement, published intentionally that has the effect of holding the victim up to ridicule and/or damaging her reputation. Defamation has generally either not been criminalized in this country or, if it is criminalized in a state, tends to be a very minor crime that is seldom, if ever, prosecuted.

But I don’t want to talk about defamation here. I want to talk about a different, residual category of “harm” I encountered in researching the online defamation issue. This type of “harm” results when someone (Person A) posts ostensibly “private” information about another person (Person B).

A good example of the alleged infliction of this type of “harm” came in the Jessica Cutler-Robert Steinbuch case. The two Congressional staffers were lovers for a time. Cutler, without Steinbuch’s knowledge or consent, posted details of their sexual encounters online in her blog. The postings were later picked up by another blog and circulated widely. Steinbuch sued Cutler for “describing in graphic detail the intimate amorous and sexual relationship between Cutler and” himself. His complaint said that her “outrageous actions, setting before anyone in the world with access to the Internet intimate and private facts regarding [Steinbuch], constituted a gross invasion of his privacy, subjecting him to humiliation and anguish beyond that which any reasonable person should be expected to bear in a decent and civilized society.”

I’m perfectly willing to concede that the postings caused Steinbuch humiliation and anguish, both in excess of what a reasonable person would want to endure. My issue lies with the nature of his complaint against Cutler.

This isn’t a defamation case, a libel or slander case, because he doesn’t say that what she posted was untrue. His complaint, then, lies not with what she said but with the fact that she said it – that she “published” it to other people in a very public way. And that’s the issue I want to talk about, the residual issue that cropped up when I was researching the evolving, morphing phenomenon of online defamation.

Historically, defamation law has protected people from “harm” by discouraging others from (i) intentionally (ii) publishing (iii) false information about them that (iv) is calculated to cause them “harm” by damaging their reputation or holding them up to ridicule. For all intents and purposes, I think we can fold “ridicule” into damage to one’s reputation, so I won’t break those “harms” out into different categories.

The rationale the law has used for sanctioning defamatory material falls into two categories: Civil law allows people to seek monetary damages for the publication of defamatory material, on the premise that the compensation redresses the “harm” done to them. Criminal law historically imposed criminal sanctions on people who published defamatory material because its goal was prevent people from doing this and thereby discourage what the law calls “self-help”, i.e., defamed people taking the law into their own hands. This used to be a major concern back in the days of dueling, but this rationale has pretty much dropped out of modern defamation law, so the remaining rationale for both civil and criminal defamation is the damage to one’s reputation.


The Steinbuch case and similar cases in which someone publishes true information about another person can also damage that person’s reputation, but modern defamation law, anyway, would not see that as defamation because, as I noted above, the material is not false. Here, the damage to someone’s reputation results not from their being portrayed in a “false light”, but from information leakage. As everyone who’s ever taken a sociology course knows, we all play roles – we present one “face” to a certain group of people and a very different “face” to other people, or to another person.

We have historically been able to do this because we have been able to exert a fair degree of control over the segregation of personal (and professional) information we rely on to support these disparate roles. Assume, for example, John Doe: a Certified Public Accountant, a deacon in his Methodist church, a coach for his son’s Little League team, a husband and an habituĂ© of Sado-Masochistic clubs, He plays a different role for each activity . . . in effect, has a different “self” for each activity. His ability to segregate those selves depends on his ability to parse the relevant information out among the roles and among the people who experience him in these different roles. And because some of the roles are not inconsistent, the information leakage issue will only become an issue for a certain role or certain roles; in this example, the leakage issue would arise with regard to his recreational S-M activities.

In the real-world, we have always been able to manage this kind of information segregation pretty satisfactorily. Those who know us in our more discreditable roles are unlikely to be people who interact with those who known us in our more “public,” more conventional roles, so that helps sustain the information segregation. Those who know us in these roles may gossip about us, but that will generally have limited circulation in the real, physical world; the gossip will be shared with people who know each other, and since they probably do not participate in the aspects of our lives in which we play more creditable roles, the segregation holds. Information leaking issues can arise, of course, when someone we know from a more discreditable aspect of our lives either directly shared information about that aspect with our families, our co-workers or others whom we interact with in our more creditable roles. This results in some information leakage . . but for those of us, the vast majority of us, who are NOT celebrities, the leakage tends to be limited in scope. That means the damage will also be limited in scope.

Cyberspace changes all this. To paraphrase Louis Brandeis and Charles Warren, who wrote a law review article on invasions of privacy over a century ago, today “what is whispered in the closet” can now be broadcast to the world . . . over and over and over.

That is the Steinbuch problem . . . the information leakage problem. And it is a problem. We trust people. We have to trust people, whether we are being our creditable or our less-than-creditable selves. We realize at some level that people can betray us, but we do not expect them to do so. Like Steinbuch, we are hurt and embarrassed when this happens.

Is this a legal issue? Should this be a legal issue? By that, I mean should the law step in and create a new crime, a new civil cause of action or both to provide mechanisms by which those who betray confidences can be sanctioned? The goal of such innovations would be to discourage people from betraying confidences.

You may disagree, but I do not see how we can do that. When we have affairs, when we go to S-M clubs, when we do other things we would prefer not to have broadcast to the world, we know that can happen. We know we are relying on that most fragile of things: trust . . . confidence that others will not betray us.

How can we prosecute people (I tend to default to the criminal solution) for betraying us? We prosecute people for betraying their country, but that’s different, if only because it is an indirect path toward death, injury, destruction and other real, physical “harms.” When someone betrays us, we suffer a “harm,” a real “harm” . . . but it primarily a psychic “harm.” Criminal law, anyway, has, and is, loath to sanction people for inflicting psychic “harm” on each other. If we began to do that, where would we stop? Would it become a crime to gossip about others . . . about how they dress? How they look? How much they earn? How ugly their dog is? How tacky their apartment is? . . . and so on and so on.

We could try creating a civil cause of action allowing someone to recover damages for the infliction of this type of psychic “harm,” but there are several problems with doing that. One is that the number of lawsuits would very quickly overwhelm the current court system and any court system we’d care to design. The other is that most of the people who would be sued are what the law calls judgment-proof; that is, they don’t have enough assets to pay a judgment or even to pay the other side’s attorneys’ fees.

Law does not seem a good solution. I wonder, then, where all this will take us. Maybe we will become so inured to the “outing” of various aspects of people’s lives that we will lose interest in it. . . .

Friday, April 13, 2007

Snuff Online

A Friday the 13th topic: snuff films

Snuff films, as you may know, are films that show someone being murdered. Unlike video that inadvertently captures a murder, a snuff film is made deliberately; the murder is the purpose and the centerpiece of the film.

Some definitions say a snuff film has to be made for profit; for my purposes here, a profit motive is irrelevant.

What I want to analyze is the legality, or illegality, of “publishing” a snuff film online.


You may have read about the video recently posted to YouTube: It showed a man tied to a chair being beaten and interrogated about killings he eventually admits, after which he is beheaded on camera. This is apparently an installment in a series of videos being posted by Mexican drugs gangs who are waging an online war of intimidation.

YouTube reportedly removed the video after it was brought to their attention and posted a notice saying it violated the site’s terms of use. YouTube’s Community Guidelines say “graphic or gratuitous violence is not allowed.”

This post is not about YouTube. It is about the legality, or illegality, of posting a snuff film – a film that premeditatedly records the murder of a human being – online. This is not an issue we have ever had to address because we – the general media-consuming public – have never encountered a snuff film. Some have claimed they don’t exist, that they’re apocryphal. I’ve always doubted that. Life is cheap enough in various corners of this and other countries that I see no reason why a snuff film could not, and would not, be made.

Publicizing one, though, is a different issue: Prior to the rise of the Internet it would neither have been possible nor intelligent to distribute a snuff film. Media outlets would not have touched it, and distributing it would only have been asking for law enforcement to go after any- and every-one involved in its creation.

Murder

Anyone involved in creating a snuff film is liable for murder. Assume the YouTube beheading video had been filmed in the U.S. and that U.S. law enforcement tracked down those involved in its creation. The person (or persons, I’ve only seen parts of the video) who actually beheaded the man is a murderer, pure and simple. In case anyone does not know, law defines murder as purposely taking the life of another human being. Case closed: The video records what happened, and even a good defense lawyer won’t be able to convince a jury that the perpetrator “accidentally” or “innocently” beheaded the victim, at least not given the descriptions I’ve seen.

What about the others . . . the people who were present, filming and otherwise assisting with the murder and with its being recorded? They, too, are liable for murder, though on a different theory.

In law, you can be liable for a crime either as a principal (the killer, in this instance) or as an accessory to a crime (murder, here). Accessories are people who either (i) facilitate the crime by, say, tying up the victim or providing materials to be used in committing it; or (ii) encourage the commission of the crime. The person or people who recorded the beheading would be liable for murder, even if this is “all” they did, because the law would find that they encouraged its commission. The level of encouragement that suffices to hold someone liable as an accomplice does not have to be, as we say in law, the but-for cause of the crime; that is, it does not have to be the cause of the crime. Law does not want people playing any role in promoting the commission of crimes, so even a pretty low level of encouragement – such as videotaping the crime with the perpetrator’s knowledge – would qualify.

Okay, these people are easy. They participated, in various ways, in the commission of the crime and therefore helped set it in motion and bring it to its culmination. That, in law and in common sense, makes them liable for what happened.

Later

But what about people who come later, after the murderhas been committed and it is too late to stop it, but who “publish” the video of the crime? Do they bear – should they bear – any criminal liability for the crime?

They did not commit the murder, so they can’t be directly liable for it. They weren’t there when it was committed, indeed, probably knew nothing about the murder until after it was committed, so they can’t be liable as accomplices. As I noted above, the premise on which we hold accomplices liable is that they contributed to the commission of a crime; you can’t contribute if you weren’t there and knew nothing about what was going on until after it had already happened.

There is a related concept called “accessory after the fact,” but that only applies to people who help a criminal escape after the criminal has committed the crime. That obviously would not apply here, since showing the crime could, at the very least, help identify the perpetrators and bring them to justice.

All of the doctrines we have that impose criminal liability only operate prospectively, that is, they only apply to conduct that occurs before a crime is committed and that either actually contributed to the commission of the crime or was intended to do so. (You can be an accomplice if you try your best to facilitate the commission of a crime, but don’t succeed . . . if, say, you show up with the murder weapon but the murderer has already left and uses a different weapon. The law says you tried, so you’re an accomplice.)

That’s only common sense. As I said above, things you do after a crime has already been committed can’t possibly have contributed to its commission.

So, if snuff films were to start showing up online (which I most certainly hope does not happen), we’d need to come up with a different theory to impose criminal liability on those who were “publishing” them . . . if, of course, we thought that was a good idea.

Policy

Do you think that’s a good idea? Do you think we should make it a crime to post snuff films online?

If a U.S. jurisdiction were to do that, the law would certainly be challenged as violating the First Amendment. I’m not going to get into First Amendment issues here, though, because I have enough to do without that.

I’m speculating about the possibility of criminalizing the online publication of a particular type of crime that has already occurred: an orchestrated, intentionally-filmed homicide. Opponents of such a law might point out that television and online news outlets show, and have shown, films of other crimes being committed and that this has never given rise to calls for criminalizing these broadcasts.

Proponents of such a law would argue that a real snuff film – even a not-for-profit snuff film like the one that just surfaced – is different. They would argue that the filming is itself an integral part of the crime being committed, that the entire purpose of a snuff film is to memorialize the act. Those who would support criminalizing the online distribution of snuff films would conclude that if we do not criminalize the distribution of snuff films we are not only playing into the filmmakers’ hands – giving them the fame or whatever else it is they wanted – we are also doing something even more harmful.

They could argue that letting these films be distributed online could encourage the production of other, similar films. That is, the proponents of criminalizing the online (or whatever) distribution of snuff films could argue that the act of “publishing” such a film can, in effect, do what accomplices do – it can encourage someone to commit a crime. Now, in this context the encouragement would not be focused on the commission of a specific crime as it has always been in the real-world; it would be a more general, global act of encouragement.

The opponents of criminalizing the distribution of snuff films could counter with the argument that this goes too far . . . that we do not, and cannot, criminalize everything that has a generalized potential to encourage someone, somewhere, to commit a crime.

This may seem an irrelevant, unnecessary train of thought, since snuff films have never publicly surfaced and have never been publicly distributed . . . at least not until that brief time period while the Mexican video was on YouTube. But one could, quite rationally, dismiss that as an aberration.

I hope it is. I like cyberspace. I like cyberspace with its variously creative, entertaining, obnoxious, disgusting, frightening, depressing, fascinating content. I, personally, don’t want to see it cut back, restrained and civilized. I will not, though, be surprised if the snuff film issue crops up again . . . and in a domestic context that makes it more difficult for us to ignore.

Much of the online content is currently being filtered in an ad hoc way to conform to certain standards of what the public is deemed to find acceptable. A few years ago, there was a furor because a U.S. website posted the video of reporter Daniel Pearl’s being beheaded. The site operator invoked the First Amendment as the reason for posting the video in an argument I, for one, could buy; this was a record of a past crime, of something we may not want to see but that had happened to an American because he was an American. There is a political context there, which I think justifies the invocation of the First Amendment.

The online filtering etiquette will probably develop cracks as things go along, and tend to degrade . . . which means we may very well see a site that hosts a snuff film, or two, or three, one of these days. If that happens, I will be curious to see how we react as individuals and how, if at all, the law reacts.

Happy Friday the 13th.

Tuesday, April 10, 2007

If a crime falls in the forest . . . ?

That vaguely Zen-ish caption is my way of launching this exploration of the possibility of using real-world law – specifically, U.S. federal law – to prosecute people who run virtual casinos in places like Second Life.

As The Register noted, this possibility raises the prospect of “virtual prosecutions” and of “virtual FBI agents kicking down virtual doors”. As The Register also noted, “the mind spins.”

The context here is that Linden Labs, operator of Second Life, has recently invited FBI agents to “take a look around” in Second Life and “raise any concerns” they may have about gambling going on there. According to a Linden Lab representative, the agents “did look around in a virtual casino” but no made no arrests.

The reason for that, of course, is it is far from clear whether gambling in Second Life, or in any other virtual would, would violate U.S. law. If it did, prosecutors and agents would then have to figure out how to enforce the law in this context, which is an issue I’ll get to in a minute. I want to start with whether virtual world-based gambling is, or should be, a crime. I’ll outline what the law is first, and then throw in my own two cents.


There are basically three federal statutes that could (emphasize “could”) be used to prosecute gambling in Second Life. One is the Travel Act, 18 U.S. Code § 1952. The Travel Act basically makes it a federal crime to travel in interstate or foreign commerce or use the mail or any facility in interstate or foreign commerce with to (i) distribute the proceeds of or (ii) otherwise “promote, manage, establish, carry on, or facilitate the promotion, management, establishment, or carrying on, of any unlawful activity”. 18 U.S. Code § 1952(a). “Unlawful activity” includes gambling that is carried on in violation of the laws of the state in which it occurs. ” 18 U.S. Code § 1952(a). So, to qualify for prosecution under this statute, gambling in a virtual casino in Second Life or in any other online world would have to violate the law of the “state in which it occurs” . . . which raises a very interesting question.


Does the gambling that goes on in Second Life occur “in” any U.S. state? Linden Labs itself is located in San Francisco. I don’t know where the Second Life servers are located, but for the sake of analysis let’s assume they are also located in California. And let’s make this analysis even easier by assuming the kind of gambling that goes on in Second Life casinos does violate California state law (again, that’s just an assumption).

Okay, let’s further assume that John Doe (our favorite person to pick on in law school) operates a casino in Second Life. Doe lives in Maine, and his customers come from various U.S. states (including California). They also come from outside the U.S., from countries where online gambling is, let’s say, either legal or has not been declared to be illegal. Can Doe be prosecuted for violating the Travel Act?

We have no indication he traveled in interstate commerce as part of operating his online casino, so that option is out. Using the Internet would qualify as using a facility in interstate or foreign commerce, so if we can say he used the Internet to carry on or facilitate the conduct of a gambling operation that violated California law, then he could, it seems, be prosecuted for violating the Travel Act. Doe, who lives in Maine where, we’ll assume, this type of gambling is not illegal, might argue that what he was doing is legal in the state where he lives . . . and, besides, he’d argue, how can anyone say that the online gambling that occurred “in” Second Life took place in California? Doe was never in California, nor where most of his customers (a few were, just to make things interesting).

That raises a very interesting issue, one that runs through a lot of legal analysis involving online activities. We’re dealing with an emergent reality here – with a virtual construct that becomes the scene of conceptual human activity as surely as the real, physical world is the scene of physical human activity. Do we treat this emergent reality as a “real” reality or do we reduce it to a physical reality? That is, do we say that the gambling going on in Doe’s casino occurred in Second Life and nowhere else . . . which would put it outside the scope of the Travel Act? Or do we say it occurred, presumably simultaneously, in California and in any other venue where one of the players was physically located?

These are very important questions because the other two federal statutes that could criminalize gambling in virtual worlds such as Second Life also require that the gambling have been illegal under the law of a U.S. state. 18 U.S. Code § 1955 & 31 U.S. Code §§ 5362(10), 5363 & 5366. So whether or not this type of online gambling can be prosecuted under current federal law depends on how we answer the questions I posed above? (Whether or not a state, such as California in this hypothetical, could prosecute will also depend on how we answer these questions.)

This is where we come to my two cents. It seems incredible to me that we would create these complex, heterogeneous online worlds and then attempt to reduce them to parochial venues. As far as I can tell (having dabbled a bit in Second Life), one reason, if not the principal reason, people participate in Second Life is to have experiences that transcend what is available to them in their localized physical reality. For that matter, many of the experiences people can have in Second Life transcend what is available to anyone in any physical reality currently existing anywhere on the globe, which makes it even more interesting.

The U.S. Supreme Court has implicitly recognized that it will have to deal with this issue in a different context – in the matter of defining what is and is not obscene. For some reason, in the U.S. we still criminalize matter that is “obscene” but do not criminalize mere “pornography.” The Supreme Court long ago articulated a test for determining whether something is obscene, a test that incorporates local community standards as one of the factors it considers.

Now, that test may have made sense when sexually-oriented material was only available in hard copy and had to be physically shipped to a location and displayed there for sale. In that world, the material itself came into the community which, at least arguably, could give the community the interest and the right to exercise some control over it.


The migration of sexually-explicit material online makes that standard changes that equation and makes that standard essentially meaningless. The material does not come into the community; the community (or those members of the community who are interested in such material) seek out this material by going online. This means that they gain access to something that is being distributed for a much wider audience – a global audience, in effect. As the Supreme Court has intimated, it is clear that relying on the community standard to define what is and is not obscene is an obsolete artifact of a different world. What made sense when New York City and Peoria (sorry, Peoria) were physically and culturally isolated makes no sense when precisely the same material and same experiences are available online to people in either city.

Obviously, I think the current federal approach to criminalizing gambling should not apply to activity in Second Life or in any other virtual world. So far I’ve based that argument simply on parsing the language of the applicable law, with a gloss added as to how we interpret when – if – virtual activity occurs “in” a physical venue.

Let’s go beyond that now and discuss a related issue: If online gambling occurs purely online, and if it only involves the use of virtual currency, what, then, is the “harm” with which the law should be concerned? I’ve never been quite clear as to what “harm” is involved in real-world gambling. The social concern seems to be to protect people from themselves, i.e., to protect people from gambling away all their money.

I don’t see why we need to be concerned with this victimless crime, when people are quite free to fritter away their money on cars, worthless real estate, jewelry, or their latest infatuation. Nor do I see how criminalizing gambling can be justified selectively; as we all probably know, in the U.S. many states conduct lotteries and/or operate casinos, which is quite legal. It’s just illegal, outside a couple of states, if private parties do that.

But let’s go with the premise that there is some justification for criminalizing gambling in the real-world because of the loss of “real” assets. The proponents of online gambling might point out that in Second Life, anyway, the gambling involves the use of Linden dollars, not U.S. dollars or any other real-world currency. They could use this to argue that whatever “harm” is involved in real-world gambling does not exist for online gambling.


The opponents of online gambling would no doubt point out that gambling in Second Life involves the use of Linden dollars which can be “exported” to the real-world. Their argument, then, would be that the same “harm” targeted by real-world gambling (whatever it is) results from online gambling because people can (I assume) move real-world currency into Second Life and use it for gambling . . . and there irresponsibly dissipate their assets. If you buy the argument for criminalizing gambling in the real-world, you’d no doubt buy that argument. If, of course, a virtual world only allowed gambling to be conducted with virtual currency that was not transportable into or from the real-world, the validity of this argument radically erodes.

Let’s still assume, for the purposes of analysis, that there is a valid reason to criminalize gambling in virtual worlds like Second Life and that we have figured out a rational way to apply federal law to this end. One logical possibility would be to quit using state law as a definitional component of the statue criminalizing online gambling and just adopt a federal statute that made online gambling a crime. There are reasons why that approach might be problematic, but while we’re hypothesizing let’s just assume that was done and it worked. This brings us to the enforcement issue.

If everything else is in place, how would federal agents enforce laws criminalizing gambling in Second Life (and similar online venues)? The obvious way to do this is to put pressure on Linden Labs to crack down on virtual casinos. Since Linden Labs is located in the United States, and since Linden Labs has a real, external presence in the territory of the United States, federal agents and prosecutors could tell Linden Labs to shut down virtual casinos in Second Life or face prosecution. The government’s theory there would be that Linden Labs was liable for aiding and abetting illegal gambling if it did not shut down the illegal virtual casinos. (The government could also argue that Linden Labs was conspiring with the operators of the virtual casinos to violate the federal law we’re assuming applies here.)

If that were to happen, I’m sure Linden Labs would comply, to the best of its ability. The problem is, as a Linden Labs representative recently pointed out, since there are millions of registered accounts in Second Life and millions of places and objects in Second Life, it simply would not be feasible for Linden Labs to be able to keep track of every virtual casino that cropped up . . . especially not if the operators took steps to conceal what they were doing.

So, what would be the solution? As
The Register said in the quote I began with, we’d presumably wind up with virtual federal agents conducting virtual undercover investigations (virtual snitches?) in Second Life. I don’t know about you, but I’m just not persuaded that we need to go there.

Friday, March 30, 2007

Vista, Backdoors and the 4th Amendment

As you may know, rumors have spread that Microsoft put a backdoor in its Vista program to accommodate law enforcement’s need to search on computers.

Microsoft denies this, which I tend to believe, but I know people who claim that it’s true. At the very least, it raises some interesting 4th amendment issues.


Let’s begin with why the backdoor issue arises.

Vista incorporates a feature called BitLocker Drive Encryption. BitLocker, which “is included in the Enterprise and Ultimate editions of Vista,” encrypts data on a computer. BitLocker Drive Encryption, Wikipedia. “By default it uses the AES encryption algorithm in CBC mode with a 128 bit key, combined with the Elephant diffuser for additional security.”
BitLocker Drive Encryption, Wikipedia. According to Microsoft, it prevents unauthorized users from gaining access to data contained on a computer: “with BitLocker all user and system files are encrypted including the swap and hibernation files.” BitLocker, Microsoft.

Users’ ability to encrypt all the files on their computer obviously poses problems for law enforcement officers who want to search a computer for evidence of a crime. But as some have noted, BitLocker should not pose problems for law enforcement in two instances:
  • One is if the computer is running; as one source notes, “forensic tools can access the encrypted volume of a running system just like any other program”. Simson Garfunkel, Drive Encryption: Two Tales, Technology Review. If the computer is running, the encryption key has already been entered into the computer, so the encryption is not an issue.
  • The other instance in which BitLocker won’t pose problems for law enforcement is when people haven’t bothered to use it.
As we probably all now, encryption is not new; encryption is available on the Mac I am using to write this, and there are programs available which can be used to encrypt data. So far, most people simply don’t bother.

Notwithstanding all this, BitLocker will still probably raise issues for law enforcement. One is how officers should proceed when they arrive to execute a computer search and the computer is running; the officers can presumably conduct a forensic analysis of the computer and thereby avoid BitLocker’s encryption, but that remains to be seen. I am not going to address that issue here. What I want to examine is the legality (or illegality) of including a backdoor on the Vista system to let law enforcement bypass encryption that has been installed on a system and that is in effect because the system has been shut down.

We will assume, for the purposes of analysis only (which means this is all purely hypothetical), that Microsoft incorporates a backdoor that lets law enforcement bypass Vista encryption. For the purposes of analysis, we will also assume that officers arrive at John Doe’s home with a warrant to search his computer for evidence of a crime (child pornography, terrorism, murder, take your pick). He lets them in, takes them to the computer, the computer is not running and they quickly find out he has implemented BitLocker. Now, BitLocker can be implemented several ways, one of which involves storing the BitLocker encryption key on a USB drive; the USB drive must be inserted into the computer for it to boot. The officers ask Doe for the USB drive they need to boot the computer; he refuses to give it to them, says he “threw it away.”

Absent a Vista backdoor, they have two and only two options at this point: They can use a grand jury subpoena or other means to “compel” Doe to surrender the key (assuming he lied when he said he threw it away), but to do this they probably will have to give him immunity for the act of handing it over. As I explained in an earlier post, immunity lets the government override his Fifth Amendment privilege, which Doe will assert as the basis for refusing to turn over the key. Doe will say, in effect, that by turning the key over he would be forced to be a witness against himself in violation of his Fifth Amendment privilege against self-incrimination.

Unfortunately, giving Doe immunity for the act of handing over the USB drive probably means they will not be able to prosecute him, since the effect of the immunity is to bar the government from using his act of handing over the drive and any evidence derived, directly or indirectly, from that act against him in a criminal prosecution. Since the evidence, if any, found on the hard drive would derive from the act of handing over the USB drive, they would be giving up the opportunity to prosecute him. The other option is to break the encryption which, I believe, would be very difficult to do.

What if, hypothetically, Microsoft had created a backdoor in Vista that would let law enforcement bypass BitLocker encryption and access the data on Doe’s computer? If Microsoft were to do this, could law enforcement then use the backdoor without violating the 4th amendment?

I don’t know of any criminal cases in which this issue has arisen. It came up last year when Michael Crooker sued Compaq (now HP) for false advertising. Crooker claimed he bought a Compaq laptop because it was advertised as having a feature – DriveLock – that secured data on its hard drive. The FBI, which had a warrant to search Crooker’s laptop, apparently found some way around the DriveLock security. In his lawsuit, Crooker claimed they used a backdoor provided by Compaq (HP). Crooker’s suit was ultimately dismissed, for whatever reason, and is irrelevant to this discussion anyway, since it did not raise any constitutional claims.

In the Doe case, the officers have a warrant to search Doe’s computer, and that allows them to access the data it contains. They, however, need outside help to access that data. There are state and federal statutes that let law enforcement obtain help from private citizens to execute search warrants; police, for example, have always needed help from phone company employees to tap landline telephone calls. The government would probably argue that the officers’ using the backdoor Microsoft installed on the system is no different from officers’ obtaining the assistance of telephone company employees to tap telephone calls. The warrant gives the officers the constitutional authority to obtain the evidence (here, the content of the calls); the telephone company employees are simply helping them to implement that authority.

The defense would argue that law enforcement’s using our hypothetical Vista backdoor to access the data on Doe’s encrypted computer is different from the scenario I outline above. How is it different? Well, one difference goes to the issue Crooker raised in his lawsuit: Doe, the defense would argue, specifically purchased a computer with Vista in order to be able to use BitLocker to secure his data from any- and every-one, including law enforcement. Doe, the defense would say, believed he could rely on the technology he purchased from Microsoft to protect his data because (in our hypothetical) he had no reason to know there was a backdoor.

The defense would then argue that by (hypothetically) installing the backdoor, Microsoft became an agent of law enforcement. As I’ve noted before, a private party can become a law enforcement agent, which means the private party’s conduct must comply with the 4th amendment. To become a law enforcement agent, the private party must act with the purpose of assisting law enforcement (which we have here) and law enforcement must encourage the party’s engaging in conduct that assists law enforcement (which we also have here). If, then, Microsoft were to install a Vista backdoor and let law enforcement use it, Microsoft would be a law enforcement agent, at least with regard to BitLocker overrides.

The government, again, would say there’s no problem here, that the same rationale used to get phone companies to tap calls applies, i.e., the search warrant justifies what law enforcement does and what Microsoft-as-hypothetical-agent-of-law-enforcement does. Somehow, though, that just doesn’t seem right to me.

It seems to me that here Microsoft is acting like a bailor, i.e., someone who has custody of another person’s property and who is legally obligated to keep it secure. Airlines are bailors for our luggage; banks are bailors for the things we put in our safe-deposit boxes, etc. Microsoft is not technically a bailor because Doe has not given his data to Microsoft to hold and keep secure. But the relationship is analogous to a bailor-bailee relationship in that Microsoft has, at least implicitly, assumed some responsibility for keeping Doe’s computer data secure. Doe, after all, bought a Vista-equipped computer because he wanted the protection provided by BitLocker; he had no idea Microsoft could and would nullify that protection when asked to do so by law enforcement.

In a sense, what Microsoft is doing in our hypothetical is consenting to the search of Doe’s computer. Doe says “no” to the officers, Microsoft says “go ahead.” If we think of the hypothetical BitLocker backdoor as a type of consent, and if we analogize Microsoft to a bailor, then the consent would not be valid for 4th amendment purposes. There’s a federal case from the 8th Circuit Court of Appeals, United States v. James, 353 F.3d 606 (2003), in which James left disks in a sealed envelope with a friend. Federal agents asked the friend to open the envelope so they could search the disks, and the friend did. The Eighth Circuit held that this violated the 4th amendment because while the friend had lawful custody of the disks, he did not have the constitutional authority to consent to the opening of the package and to the search of the disks. Seems to me Doe could make a similar argument as to the hypothetical backdoor in Vista.

All of this will probably never come up for BitLocker, since Microsoft vehemently denies putting a backdoor in Vista (and I tend to believe them). But that does not mean law will never have to confront the problem of backdoors.

Saturday, March 24, 2007

Hackback as Self-Defense

My cybercrimes students and I are discussing hackback, or strikeback, in which the victim of a cybercrime retaliates directly against her victimizer without going through the police and the legal system.

I found our discussions useful in analyzing the arguments can be made for and against hackback, so I thought I'd share them with you.


The first question, logically, is why even discuss hackback? The reason it comes up is the actual and perceived inability of law enforcement to track down, arrest and bring to justice all or even most of those who commit cybercrimes.

As I hope everyone knows, even in the real-world police cannot arrest EVERY criminal. Instead, their goal is to arrest ENOUGH criminals to keep crime under control in a society.

Modern legal systems operate on the premise that the best way to keep crime under control is to deter people from committing crimes, and the way they do that is to make enough of us believe we will get caught if we commit a crime. Getting caught is very important. Studies have shown that the perception you will get caught if you commit a crime is much more effective as a deterrent than is raising the severity of the penalty imposed on those who are caught. If, say, I think I have a 5% chance of getting caught if I steal $50 million, I may very well weigh the odds of getting caught against the benefits of committing the crime (large) against the chances of not getting caught (good), and go for it.


The problem is, as I’ve said before, that cybercrime makes the implementation of this crime control strategy incredibly difficult. Aside from anything else, cybercrime often (usually) tends to come from “outside” the jurisdiction where the victim is, and this can pose terrific problems for police trying to investigate the crime and arrest the perpetrator. Another problem is that cybercrime is added to the crime that already exists in the real-world, so police have all that extra work to do, which means they often must triage their priorities: If people are being physically harmed in the real-world, that necessarily takes priority over what happens in the virtual world because, so far anyway, cybercrime involves little if any risk of direct physical injury or death to the victims.

So, given law enforcement’s increasing inability to apprehend cybercriminals, it only makes sense that hackback – victim self-help – begins to sound appealing. It’s the same phenomenon that generates vigilante activity. (One difference between vigilante activity and hackback is that vigilantes – a la Perverted Justice – tend to affirmatively seek out perpetrators or would-be perpetrators, while hackbackers are retaliating for what was specifically done to them.)

I’ve seen postings and articles that say hackback is permissible under our existing law because it constitutes self-defense. These sources sometimes note that the right of self-defense under U.S. (and most) law can encompass the use of deadly force against an attacker, and point out that since deadly force cannot (so far, anyway) be used online, the use of retaliatory force clearly falls within the doctrine of self-defense.

The first problem I have with these views is that the scenarios involved in hackback (so far, anyway) do not involve the threat of physical injury or death to the perpetrator; they involve the threat of damage to or loss of the victim’s property, which is a very different thing.

U.S. law (and, I believe, most other legal systems) recognizes two different justifications for using force against an attacker. One is self-defense, which means exactly what is says: I can protect my physical self from an attacker who threatens me with physical injury or death.

The Model Penal Code – the set of model laws that are the template for contemporary U.S. criminal law – says, for example, that “the use of force upon . . . another person is justifiable when the actor believes that such force is immediately necessary for the purpose of protecting himself against the use of unlawful force by such other person on the present occasion.” Model Penal Code § 3.04(1). A later section of the MPC defines “unlawful force” as “force . . . that is employed without the consent of the person against whom it is directed and the employment of which constitutes an offense or actionable tort”. Model Penal Code § 3.11(1). So, under these provisions and laws based on them, I can use force to protect myself to the extent I personally believe it is necessary (no other alternative) to protect myself from someone else’s using force to harm me. The MPC limits the use of deadly force to instances in which the would-be victim believes it is necessary to protect herself “against death, serious bodily injury, kidnapping or sexual intercourse compelled by force or threat”. Model Penal Code § 3.04(2)(b).

I do not see how these standards can apply online. The “force” that is used online is directed at things, not people. It is true that online activity can become the vector that is used to set a real-world physical attack in motion: A cyberstalker can use online postings and the manipulation of online information to try to persuade a naĂŻf who likes to play sado-masochistic sexual games to attack the person the stalker is trying to set up, but the attack – and the victim’s use of defensive force, if any – all occur in the real-world.

Unless and until we acquire the capacity to directly cause physical injury to one another via cyberspace, hackback is really about a very different problem: defending property. U.S. law (and law in many other countries) lets people use force to defend their property, but only within limits.

Let’s go back to the Model Penal Code. Section 3.06 of the MPC says that you can use force “upon or toward the person of another” when you believe the use of such force “is immediately necessary . . . to prevent or terminate an unlawful entry or other trespass upon land or a trespass against or the unlawful carrying away of tangible, movable property” belonging to you. Model Penal Code § 3.06(1)(a). Under this provision, you can only use non-deadly force, i.e., force that is not likely to cause death or serious bodily injury. You can only use deadly force to protect property if (i) the attacker is trying to “dispossess” you of your “dwelling” or (ii) the attacker “is attempting to commit . . . arson, burglary, robbery or other felonious theft or property destruction” and has either used or threatened to use deadly force or the use of less than deadly force would expose you to a risk of death of serious bodily harm. The last option, of course, brings in self-defense. Model Penal Code § 3.06(3)(d).

So, how can we apply this to hackback? Would hacking back against someone who had unlawfully accessed your computer/data or infected your system with a virus or launched a DDoS attack on your website be a valid use of force to defend your property?

It doesn’t seem to me that these scenarios or any I can think of at the moment would qualify as “dispossessing” you from your “dwelling” . . . unless and until we decide that the computer system you use if your “dwelling.” I think that would be way too much of a stretch for the drafters of the MPC or for modern legislators, so we’ll give up on that option.

Unauthorized access to a computer system for the purposes of committing a crime (such as destroying or copying data) clearly qualifies as burglary. I can’t think of any online misconduct that would qualify as arson, so we’ll give that a pass. Robbery is using force to steal someone’s property; if we read “force” as “physical force,” this option would not seem to apply online, either. Clearly, though, spreading malware could qualify as the attempted (and consummated) destruction of property, so it falls within the traditional defense of using force to protect one’s property. I think a DDoS attack can also qualify as a destruction/attempted destruction of property if, of course, we broaden our concept of property a bit, to include lost business opportunities and costs incurred in dealing with such an attack.

One problem we do have with applying laws like the MPC provisions described above to hackback is the notion of “property.” If you look back at the MPC defensive use of force to protect property provision I quoted above, it only lets you use force to protect “tangible, movable property.” Data is certainly movable, but we’d have to qualify it as “tangible” property for this provision to apply to online attacks; the drafters of the MPC most certainly were not thinking of intangible property like data when they wrote this provision, but if we could convince legislators to broaden the scope of self-defense statutes, that would not be a problem.

It seems, then, that we can apply the “defense of property” doctrine to hackback, at least in certain instances and with certain modifications to the traditional doctrine. The one condition a hackback-er would have to meet in order to invoke this defense is the issue noted above, i.e., that the use of defensive force was “immediately necessary.” This means the hackback-er had no other alternatives but self-help; and what that generally means is that it would have been futile for the hackback-er to have taken the usual route and contacted law enforcement. The “defense of property” doctrine is really meant to apply to instances in which there is a face-to-face confrontation between a perpetrator and a would-be victim that makes it impossible, or dangerous, for the potential victim to try to call police. The “immediately necessary” element means the victim had to act at that moment or face the loss of her property.

That element might not be a problem for some instances of hackback . . . instances in which the hackback-er interrupted a perpetrator who was in the process of carrying out an attack. That scenario conforms more closely to the scenario the defense of property doctrine was intended to encompass. Applying the doctrine becomes much more difficult if the hackback occurs well after the attack has been completed and the damage has been inflicted. That starts to look a lot more like simple retaliation – hitting back to punish someone who has already hurt you – than the defense of property doctrine. The rules governing the defensive use of force all assume the victim is trying to prevent or minimize the infliction of “harm” in an ongoing, volatile situation. They do not sanction cold-blooded revenge.

There are other problems with applying the laws governing the defensive use of force to hackback, one being the accuracy of the response. That tends to be less of a problem for real-world scenarios than for online attacks because, as I just noted, in real-world attacks the attacker and victim are face-to-face. The victim may err in estimating the need to use force (and the level of force used), but the victim is usually accurate in deciding whom the force should be used against. As I assume we all know, this is not true online; attacks can be vectored through computers in many locations, so if we were to sanction hackback we would either have to incorporate an “accurate identification of the perpetrator” element or limit it to confrontations arising from attacks in progress.

Since this post is already long, I’ll take up that issue and a related issue (automating hackbacks) another time.

Thursday, March 22, 2007

To Catch a Predator . . . Must There Be Prey?

We’re probably all familiar with the NBC Dateline “To Catch a Predator” programs.

In these Dateline episodes, reporter Chris Hansen films interviews with men who have shown up at a location intending to have sex with what they believe is a minor male or female.


The men are the targets of a “sting” operation. They've actually been chatting online with someone from the group Perverted Justice.

As one court noted, Perverted Justice “is an organization dedicated to exposing child molesters” which NBC pays for its contributions to the Dateline episodes. (United States v. Kaye, 451 F. Supp.2d 775 (E.D. Va. 2006)).

The Dateline-Perverted Justice collaboration is just one, isolated instance of a “sting” model that has become popular in the United States. Police officers in jurisdictions all over the country (including one police department in a city about 30 miles from where I am writing this) go online and pretend to be barely adolescent females or males. The purpose is to identify pedophiles who will try to lure the children to a meeting for the purposes of having sex. I have spoken to officers who have run stings like these, and they tell me “it’s shooting fish in a barrel,” i.e., that once they go into an appropriate chat room pretending to be barely-pubescent “Melissa” or “Heather,” the pedophiles pounce almost immediately.

The defendants in these cases will be prosecuted for what they have done. The charge, which takes slightly different forms in various states and at the federal level, is “luring” or enticing a child into a sexual rendezvous. I just read a relatively recent decision from a Virginia federal district court in which the defendant used a common argument in an effort to have the charges against him dismissed. (United States v. Kaye, 451 F. Supp.2d 775 (E.D. Va. 2006)).

This defendant, like many before him, argued that the charges against him should be dismissed because there was no child. That is, he said he was charged with luring or enticing a “child” into a sexual rendezvous, but the online chats he had were not with a child; they were with an adult representative of Perverted Justice. He argued, therefore, that the charges could not stand because no child was involved in what he did, and no child was ever in any danger of being sexually exploited.

That is a logical argument, and has succeeded on occasion, especially under older statutes which actually require that there have been a “child.” It fails, though, when the charges are brought (i) under a statute which makes the act of luring or enticing a child to a sexual rendezvous a crime in and of itself or (ii) under a provision which makes it a crime to attempt to lure or entice a child to a sexual rendezvous. Neither of these offenses requires that there have actually been a child victim. They focus on what the defendant intended to do, so if the evidence shows that the defendant believed he was corresponding with a child and if the defendant used that correspondence to entice what he truly believed was a child to a sexual rendezvous, then the defendant has committed this crime. It is irrelevant that he was actually corresponding with, say, a 45 year old male detective or a 30 year old female representative of Perverted Justice.

You might wonder why the law finds it necessary to adopt statutes which criminalize conduct that is impossible, which is the case here. As Kaye argued in the case I cited above, based on the facts involved in that instance it was both “factually and legally impossible” for him ever to have actually had sex with a minor, more precisely, with the minor male he apparently believed he was corresponding with. And Kaye is right; these statutes do criminalize conduct that is, at least in the contexts of these stings, totally impossible.

Why do that? The rationale is based in what the law calls inchoate, or incomplete, crimes. Attempt is an inchoate crime; it criminalizes unconsummated efforts toward the commission of a crime. So, say the FBI has learned that John Doe intends to rob the First National Bank. The FBI observes Doe as he “cases” the bank and makes other preparations and tracks him as he heads to the bank on the day he intends to commit the crime. FBI agents arrest him outside the bank before he is even able to begin the process of robbing it. Doe will be charged with attempting to rob the bank; he cannot be charged with robbing the bank because he never got the chance to do that.

The law criminalizes attempts on the theory that it protects public safety. If we did not criminalize attempts, the FBI would have to wait for Doe to rob the bank and then try to arrest him afterward. Aside from letting him take money that is not his, this could also expose people in the bank to the risk of death or serious injury if something went wrong in the robbery or if Doe simply became trigger-happy. The law says it is better to have a repertoire of inchoate offenses – like attempt in this scenario and like the luring or enticing offenses I noted above – to let law enforcement intervene and head off crime before it occurs.

Now, some claim that stings like those the Dateline crew films go too far . . . that they essentially represent the manufacture of a crime. Those who make this argument would say that the people, like Kaye, who are caught in the luring and enticing stings are not like Doe because they had not independently embarked on a course of criminal conduct. The critics of these stings say that law enforcement has played a much more active role in creating these crimes than in the bank robbery scenario I outlined above.

Advocates of the stings say they are taking a pro-active approach to protecting children, and that every sting represents the interception of what could have been a real crime.

Wednesday, March 21, 2007

Employees, Employers and the Fourth Amendment

I recently heard from someone whose employer searched his office computer and used the information obtained from it against him in a civil suit.

He asked if this violated the Fourth Amendment. The answer, basically, is “almost certainly not” . . . and I want to try to explain WHY that is the answer.
To do that, I’m going to use a recent decision from the Ninth Circuit Court of Appeals: United States v. Ziegler, 474 F.3d 1184 (9th Cir. 2007).


Here are the facts as the court described them:

"On January 30, 2001, Anthony Cochenour, the owner of Frontline [Processing's] Internet-service provider . . . contacted Special Agent James A. Kennedy, Jr. of the FBI with a tip that a Frontline employee had accessed child-pornographic websites from a workplace computer. Kennedy pursued the report . . . , first contacting Frontline's Internet Technology Administrator, John Softich. One of Softich's duties . . . was to monitor employee use of the workplace computers including their Internet access. He informed Kennedy that the company had in place a firewall, which permitted constant monitoring of the employees' Internet activities. . . .

"Softich confirmed . . . that a Frontline employee had accessed child pornography via the Internet. . . . . Softich further informed Kennedy that, according to the Internet Protocol address and log-in information, the offending sites were accessed from a computer in the office of . . . Ziegler, who had been employed by Frontline as director of operations since August 2000. Softich also informed Kennedy that the IT department had already placed a monitor on Ziegler's computer to record its Internet traffic by copying its cache files.

"Kennedy next interviewed William Schneider, Softich's subordinate . . . Schneider confirmed that the IT department had placed a device in Ziegler's computer that would record his Internet activity. He . . . had `spot checked' Ziegler's cache files and uncovered . . . child pornography. A review of Ziegler's `search engine cache information' also disclosed that he had searched for “things like ‘preteen girls' and ‘underage girls.’ Furthermore, according to Schneider, Frontline owned and routinely monitored all workplace computers. The employees were aware of the IT department's monitoring capabilities. . . .

"According to . . . Softich and Schneider . . . Kennedy instructed them to make a copy of Ziegler's hard drive because he feared it might be tampered with before the FBI could make an arrest. Kennedy, however, denied that he directed the Frontline employees to do anything. . . . [H]is notes say, `IT Dept has backed up JZ's hard drive to protect info.' Kennedy testified that he instructed Softich only to ensure that no one could tamper with the backup copy.Whatever Agent Kennedy's actual instructions, . . . [a]round 10:00 p.m., Softich and Schneider obtained a key to Ziegler's private office . . . , entered Ziegler's office, opened his computer's outer casing, and made two copies of the hard drive.


"Shortly thereafter, Michael Freeman, Frontline's corporate counsel, contacted Kennedy and informed him that Frontline would cooperate fully in the investigation. Freeman indicated that the company would voluntarily turn over Ziegler's computer to the . . . . On February 5, Reavis delivered Ziegler's computer tower (containing the original hard drive) and one of the hard drive copies. . . .. Schneider delivered the second copy sometime later. Forensic examiners at the FBI discovered many images of child pornography."

United States v. Ziegler, supra. Ziegler was indicted for possession of child pornography and moved to suppress the evidence against him.

Ziegler argued that Agent Kennedy violated the Fourth Amendment by “directing” the Frontline employees to search Ziegler’s office and computer. So, Ziegler was claiming that the Frontline employees had become agents of the government, which he had to do to invoke the Fourth Amendment. The Fourth Amendment only protects us from action by the government; if a private citizen decides to search your home or office and takes what she finds there to the police, you are out of luck, as far as the Fourth Amendment goes. You can try suing the private citizen who searched your home or office for trespass or invasion of privacy or some other civil cause of action, but you have absolutely no claim under the Fourth Amendment . . . as long as the person was acting on their own.

This was Ziegler’s argument. He claimed, and the Ninth Circuit agreed, that he had a valid Fourth Amendment expectation of privacy in his office. The court noted, among other things, that the facts his computer was password-protected and his office had a lock on the door established this.

The Ninth Circuit then found that Softich and Schneider were “acting as de facto government agents,” that is, they searched Ziegler’s office because they wanted to help the FBI with its investigation, not for reasons associated with their employment by Frontline. The court also found that the government had encouraged them to do this, so that makes Softich and Schneider government agents and means their conduct has to have complied with the requirements of the Fourth Amendment, i.e., that they search of Ziegler’s office and seizure of data from his computer had to be “reasonable.”

Searches and seizures can be “reasonable” under the Fourth Amendment if (a) they are conducted pursuant to a search warrant (which was not true here) or (b) they are conducted pursuant to a valid exception to the warrant requirement, such as consent. The Ninth Circuit found that Frontline had the authority to consent to the search of Ziegler’s computer.

That authority derived from the fact that Frontline and its employees had common authority over Ziegler’s office and computer. Basically, Frontline had common authority over both because it had a key to the office and had the capacity to access his computer, notwithstanding the password Ziegler used. As the Ninth Circuit explained, while "use of each Frontline computer was subject to an individual log-in, Schneider and other IT-department employees `had complete administrative access to anybody's machine.' The company had also installed a firewall, . . .`a program that monitors Internet traffic ... from within the organization to make sure nobody is visiting any sites that might be unprofessional.' Monitoring was routine, and the IT department reviewed the log created by the firewall `[o]n a regular basis' . . . . Finally, upon their hiring, Frontline employees were apprised of the company's monitoring efforts through training and an employment manual, and they were told that the computers were company-owned and not to be used for activities of a personal nature." United States v. Ziegler, supra.

So Ziegler lost on his motion to suppress and will have to serve time for possessing child pornography.

This, I hope, illustrates why it is so difficult for employees of private companies to invoke the Fourth Amendment when their employer searches their computer. Unless the company has policies which explicitly state that the employee can use the computer for private purposes and that the company will not monitor the employee’s computer activity or otherwise investigate the contents of his or her computer, the company can, as Frontline did, consent to law enforcement’s searching the computer. And if the company itself does so for its own, private purposes, the Fourth Amendment is not implicated because there is no state action – the company is not acting for the state or federal government.


Tuesday, February 13, 2007

Jurisdiction, Fraud and the Fake Soldier

In law, jurisdiction is a court’s ability to act in a case, i.e., to hear evidence and enter a judgment. In criminal law it’s a court’s power to adjudicate the charges brought against someone.

People often wonder if jurisdiction is a problem in cybercrime cases because the conduct involved in committing a cybercrime can cross sovereign borders. That is, as we all know, cybercrime can be committed state-to-state in the United States, say, or across two or more different countries.

This is significant because jurisdiction has historically been based on someone’s physical presence in a particular sovereign entity (nation-state or, in a federal system like the U.S. in a constituent state of a nation-state). The idea goes way, way back in history.


At English common law, jurisdiction to prosecute was based on having custody of the alleged offender; it really didn’t matter how the officials got hold of that person as long as they had him. This historical principle still runs through much of our law of jurisdiction, so jurisdiction in civil and criminal cases is often predicated on one’s “presence” in the jurisdiction that seeks to prosecute.

What we have done, though, is to dramatically expand what “presence” is. It can be physical presence or it can be an attenuated version of physical presence: the notion that by engaging in conduct outside a state or nation-state one had a particular, foreseeable “effect” within that sovereign entity.


This attenuated, expanded notion of “presence” emerged in civil law as a byproduct of the expansion of interstate commerce across state (and national) boundaries last century; it has since migrated into criminal law. So what you see in modern criminal law are statutes that give the courts of a sovereign the ability to prosecute someone whose conduct resulted in the infliction of “harm” inside the state, even though the perpetrator was never actually “in” that state. Here’s an example, from Arkansas: “A person may be convicted under a law of this state of an offense committed by his or her . . . conduct . . . if. . . [e]ither the conduct or a result that is an element of the offense occurs within this state”. Arkansas Code § 5-1-104(a)(1).

To show you how a provision like that works, let’s consider a recent case from Arkansas, Powell v. State, 2007 WL 104103 (Arkansas Court of Appeals, January 17, 2007). Here are the facts, as given by the court of appeals:
Christopher Joe Powell . . . . a resident of Georgia, met Vanneise Collins, a resident of Drew County, Arkansas, on an internet website for singles. Over the course of several months, the two engaged in lengthy e-mail and telephone communications, striking up a romance. The romance culminated in three face-to-face meetings in Georgia, and ultimately, a marriage proposal. Throughout the course of their romance, [Powell] made certain representations about himself that proved to be wholly fabricated, such as his being unmarried, being in the army, and being deployed in Iraq during portions of the time he and Collins were in contact. Collins made concrete marriage plans, such as putting a deposit down on a wedding dress and mailing out wedding invitations. All the while, Collins sent [Powell] money when he asked, via Western Union, for a variety of reasons, including new golf clubs, property taxes on inherited property, medical bills, a new military dress uniform, and to `grease palms’ while being separated from his unit in Iraq. [Powell] obtained about $15,000 from Collins. When she began to doubt him, she verified that there was no record of him being in the military and eventually went to the police.
Powell v. State, 2007 WL 104103 (Arkansas Court of Appeals, January 17, 2007).

Powell was charged with, and convicted of, theft and computer fraud.
  • The theft charge was based on a statute that defines “theft” as using “deception” to obtain the property of another person. Arkansas Code § 5-36-103.
  • The computer fraud charge was based on a statute that defines “computer fraud” as using a computer or computer network to “devise” or execute a “scheme or artifice to defraud, i.e., to obtain “money, property, or a service with a false or fraudulent intent, representation, or promise. Arkansas Code § 5-41-103.
They may seem like the same offense, but the law would distinguish them on the premise that each contains a element the other does not. So the theft charge does not require the use of a computer and the computer fraud charge reaches conduct that is slightly different from theft, i.e., it requires false representations. (That’s essentially it, though it is a little more complicated.)

In his appeal, Powell didn’t focus on the similarity of the charges but on the issue of jurisdictoin: Powell claimed " the trial court erred in asserting jurisdiction over this matter, contending that all elements of the offenses charged occurred outside the territorial jurisdiction of Arkansas.” Powell v. State, 2007 WL 104103 (Arkansas Court of Appeals, January 17, 2007). The Court of Appeals noted it was “undisputed that appellant never entered the State of Arkansas until such time as he was arrested and transported to Arkansas to answer the criminal charges of theft and computer fraud in Drew County.” Powell v. State, supra.

Powell actually had a pretty creative argument. Here is what he said:
Appellant claims that . . . these crimes are defined by the conscious act of the wrongdoer. Cousins v. State, 202 Ark. 500, 151 S.W.2d 658 (1941), provides that if a crime covers only the conscious act of the wrongdoer, regardless of its consequences, the crime takes place and is punishable only where he acts. Therefore, appellant argues that the conduct of obtaining the property of another by deception and accessing a computer system or network, occurred in Georgia.

He argues that he only sent an e-mail from Georgia through the network to Arkansas, which the complainant then accessed in Arkansas. The scheme was devised in Georgia, and the money was obtained in Georgia. . . . He claims that because the legislature defines these offenses as the purpose of the wrongdoer, all elements of the crimes occurred in Georgia, outside the territorial jurisdiction of Arkansas.
Powell v. State, supra.

The Arkansas Court of Appeals, not surprisingly, disagreed:
The State alleges that Ark.Code Ann. § 5-1-104(a)(1) controls because the State can show that the conduct or result that is an element of the offense occurred within Arkansas. We agree. Appellant sent e-mail correspondence to Collins and contacted her by telephone while she was in Arkansas. During the course of those communications, appellant actively deceived Collins into sending him money. Moreover, appellant caused Collins to access her computer by virtue of his e-mail correspondence, for the purpose of obtaining money with a false or fraudulent intent, representation, or promise. The deception and promises were his extensive fabrications. We hold, therefore, that substantial evidence existed to support the trial court's finding that it had jurisdiction in the instant case.
Powell v. State, supra.

The Court of Appeals therefore affirmed Powell’s conviction, which presumably means he will now serve the sentence the trial court imposed on him: “eight years' imprisonment for theft of property, five years' imprisonment suspended for theft of property, six years' imprisonment for computer fraud, and three years' imprisonment for failure to appear for trial on August 24, 2005.”

The approach the Arkansas court took in this case is common in other US cases, both state and federal, and is the predominant approach in cybercrime cases internationally. Any other result would let someone commit cybercrimes with complete impunity, as long as they targeted people in another country.

Sunday, February 04, 2007

Can you trust your network?

As you may know, law enforcement officers are using file-sharing programs like Limewire to search people’s hard drives for child pornography.

This summary of facts from a recent case – United States v. O’Rourke, 2007 WL 104901 (U.S. District Court for the District of Arkansas – gives you an idea how this works:
Defendant O'Rourke came to the attention of the FBI on January 3, 2005, when Special Agent Robin Andrews conducted an undercover investigation of people involved in the possession and distribution of child pornography. . . . Conducting a search through the peer-to-peer Internet file sharing software known as `Limewire,’ Agent Andrews downloaded images of child pornography from Defendant's computer. . . . The FBI was able to identify Defendant through his Internet Protocol address and a subpoena of his Internet Service Provider, and subsequently obtained a search warrant for Defendant's home and computer. . . . The search warrant was executed on February 22, 2005, and Defendant's computer was found to contain 46 movie files and several hundred still images of child pornography. . . . The Government alleges that these movies and images were saved on Defendant's hard drive and were available to be downloaded over the Internet by others using Limewire software. . . .

The Government seized Defendant's computer and presented evidence to a federal grand jury. The grand jury indicted Defendant. . . .
Here’s a summary of what happened in a similar case involving a search by a state officer:
[T]his case began on February 28, 2005, when at 4:35 p.m., Trooper Robert Erderly of the Pennsylvania State Police was logged onto a computer located at the Pennsylvania State Police barracks in Indiana, Pennsylvania. . . .

Installed on the computer. . . was a file-sharing software program called Phex. Trooper Erdely used the Phex program to search for files on the Gnutella network.. BearShare and LimeWire are other such file-sharing software programs. . . .

The Gnutella network, BearShare, Phex and LimeWire share all types of files, including music, movie, photograph/still image, and text files. . .

On February 28 2005, the defendant, Arthur Abraham, was logged on to his computer at his residence at 3129 West Queen Lane, Philadelphia, Pennsylvania, and running a peer-to-peer file-sharing program called BearShare, version 4.6.3. . . .Once BearShare is installed, any file a person chooses to share is available to anyone on the Gnutella network. Every computer that is running this Gnutella network can participate in the sharing of the files. In order to install . . . the BearShare program . . . the defendant had to have accepted the terms of an end user software licensing agreement. With this agreement, the user acknowledges that he is using a file sharing program which can be used both to download files and to send files out over the Internet, i.e. share files. . . .

Returning to . . . February 28, 2005, the. . . defendant had to have his computer on and be using the "share the files in the library" option . . . when Trooper Erdely did his search because Trooper Erdely found the file being shared and was able to download it from the defendant's computer. . . .

Trooper Erdely knew that there was a movie file that was being shared across the Internet which is named Hindoo. Utilizing the Phex program, he searched the word Hindoo and got a number of hits. Once the result of Trooper Erdely's search came up, the Internet Protocol ("IP") addresses of those sharing the files on which Trooper Erdely got a hit were visible.

One of the IP addresses from one of Trooper Erdely's hits was an IP address belonging to Verizon Internet service. The IP was 141.151.19.66. . . . The complete name of the file being shared by IP 141.151.19.66 was (Hussyfan)(pthc) (r@ygold) (babyshivid) Hindoo4.mpg. Exhibit 5, unnumbered page 2.

Trooper Erdely obtained a state court order compelling Verizon to tell him who was the subscriber with the IP address 141.151.19.66. Verizon informed Trooper Erdely that the subscriber of that service at that date and time was . . . Arthur Abraham of 3129 West Queen Lane, Philadelphia, Pennsylvania 19129.

Trooper Erdely downloaded the file "Hindoo" that IP address 141.151.19.66 was sharing onto a CD Rom. The file on the CD Rom that Trooper Erdely downloaded from IP address 141.151.19.66 contains child pornography as prohibited by law. . . .

On March 17, 2005, a warrant was obtained to search the defendant's house at 3129 West Queen Lane, Philadelphia, Pennsylvania 19129. . . .
United States v. Abraham, 2006 WL 3052702 (U.S. District Court for the Western District of Pennsylvania 2006).

I find many things interesting about how law enforcement officers are using file-sharing programs to hunt for child pornography, but the one I want to focus on here wasn’t raise in the opinions in either of these cases, nor was it raised in the four other similar cases that are reported in Westlaw.

The issue is the Fourth Amendment which, as I’ve noted before, protects us from the government’s conducting “unreasonable” searches and seizures. The issue that would determine the applicability of the Fourth Amendment to the conduct of Agent Andrews and Trooper Erdely is whether what they did resulted in a “search” or a “seizure.”

As I’ve said before, a Fourth Amendment search is law enforcement’s intruding into a place, or an activity, in which the person has a “reasonable expectation of privacy.” You have a reasonable expectation of privacy in a place – your home, say – if (a) you think it’s private (subjective expectation) and (b) society agrees it is reasonable for you to think that (objective expectation). The home, of course, is clearly private – we all think our homes are private and our society emphatically agrees. That doesn’t mean law enforcement officers can’t search our homes; it just means they have to get a search warrant to do so.

The computers in both of these cases were in homes. Was it, then, a search for the law enforcement officers to access the hard drives on the computers to locate and copy a file or files (which, arguably, is a seizure)?

On the one hand, you could argue it was a search because we have an intrusion – a virtual kind of intrusion – by law enforcement into someone’s home. On the other hand, you can argue this is not a search because O’Rourke and Abraham both “opened the door” for law enforcement officers to “enter” their computers by installing and using the file-sharing software.

That is, as to the second argument, you can argue that (a) neither O'Rourke nor Abraham could have had a subjective expectation of privacy in their hard drives because they knew they were using file-sharing software and were online and (b) regardless of what they thought, society would not accept the notion that their hard drives were private given their use of that software. Society, in other words, would see their using the file-sharing software as the equivalent of my (hypothetically) putting my favorite marijuana plant (purely hypothetical) on a table next to the large window on the front of my house and pulling back the curtains so it could get plenty of sun. It would not be a search for a police officer to walk by and see the marijuana plant -- I gave up any expectation of privacy I had with regard to the plant by putting it on public display.

I assume none of the defendants raised the Fourth Amendment argument because they thought it would fail . . . or maybe they did raise it unsuccessfully and the courts simply did not issue a published opinion on that issue. I can see why the second argument would probably prevail . . . there's a long line of cases which say that if you engage in criminal activity with other people, don't complain if one of them turns out to be a snitch or, worse yet, an undercover FBI agent.

It seems to me, thought, that the second argument against law enforcement's using file-sharing software to explore people's hard drives raises a larger, perhaps more difficult issue: If I link my computer to a network, have I lost any Fourth Amendment expectation of privacy in the contents of my hard drive?