skip to main |
skip to sidebar
A couple of days ago, I did a post on the recent case in which the Supreme Court held that to commit identity theft under the federal statute, you have to know you’re using the personal identifying information of a “real person.” In a comment to the post, someone asked what “real person” means, i.e., whether it’s someone who’s alive or can also be someone who has died.It’s a good question, one the federal statute at issue in that case doesn’t explicitly answer. I found some state statutes that do address this issue, but I’ll get to them in a minute. The question as to whether 18 U.S. Code § 1028A, the statute at issue in the Supreme Court case, encompasses a deceased person’s identity has been addressed by two of the U.S. Circuit Courts of Appeal. The U.S. Court of Appeals for the Eighth Circuit dealt with this issue a year ago in U.S. v. Kowal, 527 F.3d 741 (2008).
Kowal was charged with multiple violations of § 1028A, was convicted and appealed, arguing in part that the convictions on two of the counts should be reversed because “the statute does not cover the theft of a deceased person’s identity.” U.S. v. Kowal, supra.Since the statutes doesn’t SAY it encompasses the identity of one who’s deceased, the Court of Appeals had to rely on a general parsing of the term “person:”[T]here are varying dictionary definitions of `person.’ Some pertain only to living persons while others are not so limited. In common usage, however, the adjectives `living’ and `deceased’ may both properly be used to narrow . . .the meaning of the noun `person.’ The word `person' thus encompasses both the living and the deceased, and each of such persons possesses an identity which is susceptible to misappropriation. It is reasonable to assume Congress considered it unnecessary to distinguish between theft of the identity of a deceased person as opposed to a living person because the word `person’ is broad enough to cover both.
The context in which `person' is employed supports this conclusion. General principles of statutory construction provide that we look to the structure of the statute and the language surrounding the term to ascertain its meaning. When two statutory provisions employ the same word in close proximity, the `normal rule of statutory construction that identical words used in different parts of the same act are intended to have the same meaning' carries even greater weight. Both 18 U.S.C. §§ 1028A(a)(1) and 1028A(a)(2) prohibit the use `without lawful authority, of a means of identification of another person,’ but § 1028A(a)(2) adds an additional phrase prohibiting the use of a `false identification document.’ Section 1028A(a)(2) deals with identity theft related to acts of terrorism and imposes a mandatory five year sentence upon conviction. Cf. § 1028A(a)(1) (two year mandatory sentence). To interpret § 1028A(a)(2) to apply only to those terrorists who steal a living person's identity would be inconsistent with what otherwise appears to be an effort to achieve broad coverage, as evidenced by the statute's prohibition of false identification documents in addition to `means of identification of another person’ and the congressional purpose to prevent aggravated identity theft, as well as the provision for more serious sentences for violations of this subsection. Reading `person’ . . . to include a deceased person avoids the illogical result of limiting the scope of the terrorist provision, and the close proximity of the identical phrase in § 1028A(a)(1) leads to the conclusion that `person’ has the same meaning in both subsections. We conclude that the term “person” as used in § 1028A(a)(1) is not ambiguous.
The legislative purpose in protecting individual identity by passage of the aggravated identity theft statute supports this interpretation. An identity stolen from an actual person based on a real name, a real social security number, and a real birth date makes detection of the theft more difficult than if a perpetrator had fabricated a false identity. An identity stolen from a deceased person, however, is far less likely to be uncovered than one stolen from a living person. [Section] 1028A(a)(1) imposes a stiffer penalty on these types of identity thefts precisely because they are more difficult to uncover.
U.S. v. Kowal, supra. So this court held that the statute at issue in the Supreme Court case applies both to living and deceased persons; and the U.S. Court of Appeals for the First Circuit reached essentially the same conclusion in U.S. v. Jimenez, 507 F.3d 13 (2007). I also found a decision from a federal trial court, which agreed with these appellate courts. It seems, then, that a deceased person is a “real person” under the federal identity theft statute . . . unless and until the U.S. Supreme Court decides to address that issue, which I seriously doubt will happen. That led me to wonder if the states have addressed this issue and if so, how they’ve dealt with it.I found a few state statutes that do what the federal statute doesn’t, i.e., expressly state that identity theft can involve using the personal identifying information of someone who is deceased. Here, for example, is North Carolina’s identity theft statute:A person who knowingly obtains, possesses, or uses identifying information of another person, living or dead, with the intent to fraudulently represent that the person is the other person for the purposes of making financial or credit transactions in the other person's name, to obtain anything of value, benefit, or advantage, or for the purpose of avoiding legal consequences is guilty of a felony punishable as provided in [North Carolina General Statutes] 14-113.22(a).
North Carolina General Statutes § 14-113.20(a). Ohio has a similar provision (Ohio Revised Code § 2913.49(A), as do these states: Oklahoma (21 Oklahoma Statutes § 1533.1), Rhode Island (Rhode Island General Laws § 11-49.1-3), Utah (Utah Code § 76-6-1102(2)), Virginia (Virginia Code § 18.2-186.3(B1) and Washington (Washington Code § 9.35.020).Missouri does something a little different. Its statute makes identity theft a crime, just like the federal and other state statutes. It also creates a civil cause of action that lets the living victim of identity theft sue the perpetrator for damages. Missouri Statutes § 570.223. And then the statute includes this provision: “If the identifying information of a deceased person is used in a manner made unlawful by [this statute], the deceased person's estate shall have the right to recover damages pursuant to” the provision I just mentioned. Missouri Statutes § 570.223(6). I don’t think this provision means that the statute’s criminal provisions don’t apply to identity theft involving a deceased person. Another part of the Missouri statute says that the civil remedies do not “depend on whether a criminal prosecution has been or will be instituted” against the perpetrator. Missouri Statutes § 570.223(8).Kentucky’s identity theft statute also does something different. The statute makes it a crime (identity theft) to knowingly possess or use “any current or former identifying information of the other person or family member or ancestor of the other person”. Kentucky Revised Statutes § 514.160(1). I’m not really sure what that means in practice. As to the “family member” element, I don’t know why the statute makes it a crime to use John Doe Junior’s father’s identity, instead of just making it a crime to use John Doe Senior’s identity. And then there’s the ancestor issue: Maybe the ancestor element is just another way of addressing the issue of using the identity of a deceased person. If that’s true, then I don’t know why it matters that they have a descendant; in other words, it seems as if the crime would be using the deceased person’s identity, not using-the-identity-of-an-ancestor-of-John-Doe. Maybe I’m missing something. Washington’s identity theft statute used to have a similar provision, but they deleted it when the statute was revised in 2001. Washington Laws 2001, chapter 217 § 9. I have no idea why Washington did that.Finally, here’s my favorite identity theft statute. Oregon makes it a crime if someone “with the intent to deceive or defraud, obtains possesses, transfers, creates, utters or converts to the person’s own use the personal identification of another person.” Oregon Revised Statutes § 165,800(1). The Oregon statute then defines “another person” as “a real person, whether living or deceased, or an imaginary person.” Oregon Revised Statutes § 165,800(4)(a). Though I’m tempted to speculate otherwise, I assume the term “imaginary person” is intended to let Oregon prosecute someone who uses, say, “a fake social security card containing a fabricated social security number.” Mandujano-Real v. Mukasey, 526 F.3d 585 (U.S. Court of Appeals for the Ninth Circuit 2008). That’s what the Ninth Circuit Court of Appeals concluded in the Mandujano-Real case, and it’s probably correct. Either way, I can see a defendant using the Flores-Figueroa case, the Supreme Court case I mentioned earlier, to argue that the Oregon provision is unlawful because identity theft (as a generic crime) necessarily involves using the identification information of a “real” person . . . and imaginary persons are, I believe, definitely not real.
In 2001, I published an article on “virtual crime.” It analyzed the extent to which we needed to create a new vocabulary – and a new law – of “cybercrimes.” The article consequently focused on whether there is a difference between “crime” and “cybercrime.” It’s been a long time, and cybercrime has come a long way, since I wrote that article. I thought I’d use this post to look at what I said then and see how it’s held up, i.e., see if we have any additional perspective on the relationship between crime and cybercrime. In the article, I began by noting that in the Anglo-American common law tradition crimes have 3 elements: conduct (actus reus), intent (mens rea) and a forbidden result or “harm.”
Historically, crimes were committed in the real world, which means all 3 elements occur – more or less simultaneously – in the physical world. The law of crimes is has therefore been concerned with imposing liability and sanctions (e.g., death, incarceration, fines) for conduct that results in the infliction of corporeal harms, such as injury to persons or property or the unauthorized taking of another person’s property.As I wrote in an earlier post, we tend to conceptualize cyberspace as if it were a “place,” probably because we lack a better analogy. For the purposes of this discussion, though, I’ll assume the analogy is apt. If we assume cyberspace is a domain that exists along with but apart from the real world, the question arises as whether the principles of criminal law we apply in the real world are adequate to address crimes the commission of which exploits the unique advantages of cyberspace. To answer this question in the negative (real world criminal law is not adequate for cybercrime), we have to conclude that crime and cybercrime differ as to the conduct used to inflict harm and/or as to the harms inflicted. Criminal law is, after all, about preventing the infliction of harm.We should not simply assume criminal conduct vectored through cyberspace represents an entirely new phenomenon, i.e., cybercrime. It may represent nothing more than perpetrators’ using cyberspace to engage in conduct that has long been outlawed. The development of the telephone, for example, made it possible to perpetrate fraud in new and different ways, but fraud itself has been outlawed for centuries. If cyberspace is simply an implement that is being used to commit traditional crimes, then there probably is no need to recognize a separate category of “cybercrimes” and develop specialized legislation to deal with them; existing laws should be adequate to do so. Law has, for example, long made it a crime intentionally to cause the death of another human being. For the most part, law defines this generically as homicide, rather than differentiating types of homicide depending on the method used to cause death. That is, we do not have method-specific crimes like “homicide by firearm,” “homicide by poison,” “homicide by stabbing,” etc. Instead, we focus on the harm that results from specific conduct -- conduct which is intended to cause the death of another person- -- and define a crime that encompasses that harm. In analyzing whether cybercrime is distinct from crime, it is useful to consider whether law has confronted other situations in which the infliction of a harm sufficiently severe to warrant the imposition of criminal liability has been predicated on conduct that did not occur entirely in the real, physical world. I’ve found two instances in which this occurred. The English Treason Act of 1351 made it a crime to “compass or imagine the death of our lord the King, or of our lady his Queen or of their eldest son and heir”. This is an example of a “thought crime,” i.e., a crime which does not require that the perpetrator commit a volitional act in our shared, external reality which causes, attempts to cause or threatens to cause harm to someone or something. The Treason Act of 1351 punished people for their thoughts alone. (Please don’t ask me how often it was used; I’d like to know that myself, but haven’t found any data on the topic.)The Treason Act of 1351 is an historical aberration: Anglo-American law has for a long time rejected the use of thought crimes, for various reasons. One is that as long as I do nothing more than think bad things, I have not caused harm in the real-world; criminal law is concerned with controlling harmful behavior, not internal malice. Another reason is that laws like this are obviously subject to abuse; when I read this statute, I imagine Lord A, who’d like to get Lord B out of the way as a potential rival, accusing Lord B of imagining the death of the King; I’ve no idea what, if any evidence Lord A had to produce to get the King to act on that claim. I fear it wasn’t much, which is yet another reason why Anglo-American law, anyway, doesn’t criminalize thoughts: There’s too much room for such a law to be abused. And then there is the matter of freedom -- of letting people think what they choose as long as they don’t act on it.The first instance in which Anglo-American law departed from predicating criminal liability on conduct that did not occur in the real-world is therefore not helpful in thinking about cybercrime. If may have been simply a symbolic gesture, a way of underlining the extent to which subjects should respect the Royal Family.The other instance was definitely not symbolic; it resulted in thousands of prosecutions and executions in Europe in the 15th, 16th and 17th centuries. I refer, of course, to witchcraft.Unlike imagining the king’s death, a crime no element of which manifested itself in the real world, witchcraft incorporated both virtual world and real world elements. Until 1951, English law made it a crime to engage in witchcraft, which was defined to include “invoking any evil spirit, or consulting, covenanting with, . . . or rewarding any evil spirit . . . or killing or otherwise hurting any person by such infernal arts” or using them to enrich oneself. United Kingdom - Witchcraft Act 1735. This crime targeted the harm of using one’s power over the virtual world to summon evil spirits to injure others, harm their property and/or enrich oneself. As I said, thousands and thousands of people were convicted of witchcraft.We no longer have the virtual crime of witchcraft because we no longer believe one can manipulate forces in the “spectral world” to influence things in the real world. For the purposes of argument, though, let’s assume we still entertain such a belief and therefore still have the crime of witchcraft. That crime would consist of using evil spirits for any of the purposes noted above, i.e., hurt someone, damage property and/or reap a profit. If we believe it is possible to manipulate evil spirits to this end, then it is reasonable to use this crime to impose liability on those who do this; unlike those who committed the thought crime of imagining the king’s death, those who commit this crime are using virtual world forces to have an effect on persons and property in the real world. In that regard, I can see an analogy between witchcraft and cybercrime: In both instances, the perpetrator is physically situated in the physical world, which means that at least a portion of the actus reus plus the offender’s mens rea are real world phenomena. In both, the perpetrator manipulates virtual world forces to harm someone or some thing in the real world. So what?, you ask. In the article I argued that even though cybercrime – like witchcraft – departs from the traditional model of crime insofar as it involves the use of “otherworldly” forces, this, alone, does not justify creating specific cybercrime offenses. In other words, I argued that even though it involves conduct vectored though a non-corporeal reality, cybercrime is merely a method crime, i.e., crime the commission of which is distinct due to the tool the perpetrator uses. So I argued that we do not need a “law of cybercrimes;” we can address cybercrime by using traditional offenses that are revised, as necessary, to encompass the digital versions of these crimes. And I haven’t changed my mind. I have been thinking about the witchcraft trials a bit, but not because of the crime-cybercrime issue. I’ve been thinking of an issue that came up during the Salem witchcraft trials: spectral evidence. In the Salem trials, as in earlier witchcraft trials held in England, the judges had to decide if it was permissible to admit spectral evidence, i.e., evidence that (allegedly) came from evil spirits and other denizens of the non-corporeal reality that (allegedly) supported witchcraft. The concern was whether or not the evidence was reliable because, of course, only the person who’d “conversed” with the evil spirit could verify what it said. There was quite a debate about that. Cotton Mather, a prominent minister involved in the Salem trials, wrote a book – Wonders of the Invisible World -- defending the use of spectral evidence. He also cautioned that a conviction should not be based purely on spectral evidence because of its innate uncertainty. Cotton’s father – Increase Mather – disagreed; he said spectral evidence should not be used in witch trials. Increase Mather famously said “It were better that Ten Suspected Witches should escape, than that one Innocent Person should be Condemned." And does that have to do with cybercrime, you ask? I’m not sure. I find myself thinking of the spectral evidence issue because I wonder if there are any analogies to digital evidence. I spoke at a conference recently where I was on a panel with a prosecutor; the prosecutor said, at one point, that defense attorneys are not, as yet, doing a good job of challenging prosecutors when it comes to digital evidence. He seemed to think they’re not as conversant with the technology and the issues it raises (can be used to raise) as they could be, and certainly will be. When I have conversations like that, I for some reason think of the old debate over spectral evidence. Maybe because it’s the only previous instance I know of in which courts had to consider the admissibility of “otherworldly” evidence.
The U.S. Supreme Court recently decided a case that deals with an issue I wrote about in an earlier post. So I thought I'd update that post a bit.
The post was on an issue that had arisen under federal criminal law: whether someone can be convicted of identity theft if they did not know they were using the identity of a real person.
As I explained in that post, the federal identity theft statute makes it a crime “knowingly” to use the means of identification of another person. In the case I wrote about, the defendant cloned her Social Security number; that is, she used it to produce a series of fabricated Social Security numbers, at least one of which turned out to belong to a real person. She argued that she could not be convicted of violating the statute because he had no idea she was using a real person’s identity; she though she was committing fraud, not identity theft. In the post, I said I think she should win because what she committed is fraud and could therefore be prosecuted as fraud. The premise behind identity theft statutes is that they reach harmful conduct we haven’t already criminalized, i.e., using someone else’s personal identifying information without their permission.As you may have heard, the U.S. Supreme Court decided a case raising this issue on Monday of this week. The case is Flores-Figueroa v. United States, 2009 WL 1174852. The Flores-Figueroa Court held that to convict someone of identity theft in violation of 18 U.S. Code § 1028A “requires the Government to show that the defendant knew the means of identification at issue belonged to another person.” In reaching this result, the Court noted that the statute has both a fraud crime and a theft crime, and thatCongress separated the fraud crime from the theft crime in the statute itself. The title of one provision (not here at issue) is `Fraud and related activity in connection with identification documents, authentication features, and information.’ 18 U.S.Code § 1028. The title of another provision (the provision here at issue) uses the words “identity theft.” § 1028A (emphasis added) Moreover, the examples of theft that Congress gives in the legislative history all involve instances where the offender would know that what he has taken identifies a different real person. H.R.Rep. No. 108-528, at 4-5, U.S.Code Cong. & Admin.News 2004, pp. 779, 780-81 (identifying as examples of``identity theft` ‘dumpster diving,’ `accessing information that was originally collected for an authorized purpose,’ `hack[ing] into computers,’ and `steal[ing] paperwork likely to contain personal information’).
Flores-Figueroa v. United States, supra. I assume those, like the woman I wrote about last fall, who were convicted by courts that did not instruct the jury the defendant had to know the identification documents belong to another person will be bringing appeals. Sometimes, when the Supreme Court issues a decision it specifies that the decision is only prospective; that is, it doesn’t apply to cases already decided.
The Court does this when it’s deciding criminal procedure cases, e.g., cases that set the rules police have to follow in investigating crimes. If the Court changes a rule that tells police what they can and cannot do in, say, searching a car, it applies that rule prospectively because officers in the past cannot be expected to have followed it. You can’t follow a rule that didn’t exist.Here, though, the Court is saying that this statute has always required that the defendant know the identification information belonged to a real person. This means that any case in which a defendant was convicted without the jury being told they had to find that the government proved beyond a reasonable doubt that the defendant (like the one I wrote about last fall) knew the identification information belonged to a real person resulted in a conviction that is null and void (unless courts can come up with some way around that, which I doubt).
This post is, as the title indicates, about using a specific kind of evidence to impose a sentence on someone who has been convicted of a crime.
As I explained in an earlier post, the rules of evidence bar the use of hearsay in trials and in other judicial proceedings unless the hearsay in question falls into one of a number of exceptions to the general rule barring hearsay. As I explained, hearsay is “a statement, other than one made by the declarant while testifying at the trial or hearing, offered in evidence to prove the truth of the matter asserted.” Federal Rules of Evidence, Rule 801(c). The federal system and every state define hearsay similarly, and they all recognize the same set of exceptions to the rule. As I explained earlier, hearsay isn’t allowed, as a general rule, because it denies the party against whom it is introduced an opportunity to effectively challenge its accuracy and reliability. A rumor would be hearsay; so if I took the stand and said I’d heard a rumor that you’re an axe murderer, you couldn’t do much to attack the basic accuracy of the content of the rumor. You could try to attack my credibility, but since I’m saying I heard this story from John Doe, and I trust John Doe, you’re pretty well stymied in attacking the inherent believability and accuracy of the axe murderer story. One of the exceptions is the “business records” exception. As Wikipedia explains, the rationale of this exception is the premise that “employees are under a duty to be accurate in observing, reporting, and recording business facts. The . . . belief is that special reliability is provided by the regularity with which the records are made and kept, as well as the incentive of employees to keep accurate records (under threat of termination or other penalty).” The presumptive accuracy with which business records are kept is assumed to overcome the law’s skepticism about admitting regular hearsay. The records are hearsay because the contents – the statements – they contain are being introduced to prove the truth of the matter(s) they attest to.That brings me to the case this post is about: Whitley v. State, 1 So.3d 414 (Florida Court of Appeals 2009). Here’s how the court described the issue in the case:Whitley . . .appeals his judgment and sentence as a prison releasee eoffender (PRR). [He] argues . . . that the trial court erred in relying on a printout from the Department of Corrections' website to establish the date of his release from prison for purposes of PRR sentencing, as the printout constituted hearsay and was unauthenticated.
Whitley v. State, supra.PRR sentencing is created and governed by a state statute: Section 775.082(9)(a)(1) of the Florida Statutes defines a “prison releasee reoffender” as a “defendant who commits” any of a list of specified crimes within “3 years after being released from a . . . correctional facility . . . following incarceration for an offense for which the sentencing is punishable by more than 1 year in this state.” Robbery is one of the crimes specified in this section. If a prosecutor determines that a defendant qualifies under this section, the prosecutor can “seek to have the court sentence the defendant as a prison releasee reoffender. Florida Statutes § 775.082(9)(a)(3). If the prosecutor offers proof thatestablishes by a preponderance of the evidence that a defendant is a prison releasee reoffender . . . such defendant is not eligible for sentencing under the sentencing guidelines and must be sentenced as follows:
a. For a felony punishable by life, by a term of imprisonment for life;
b. For a felony of the first degree, by a term of imprisonment of 30 years;
c. For a felony of the second degree, by a term of imprisonment of 15 years; and
d. For a felony of the third degree, by a term of imprisonment of 5 years.
Florida Statutes § 775.082(9)(a)(3). Someone sentenced as a PRR is not eligible for parole; they will be released only after they have served all of the sentence imposed on them. Florida Statutes § 775.082(9)(a)(3).Mr. Whitley therefore had an obvious incentive to challenge the court’s sentencing him as a PRR. His argument, as noted above, is that the prosecutor relied on inadmissible hearsay to prove he qualified for PRR sentencing:[Whitley] was convicted of robbery following a jury trial. At sentencing, the State sought to have [him] classified as a PRR. . . . To justify this classification, the State was required to show that [he] committed the instant robbery within three years of his release from a correctional facility. . . . The State offered a printout from the Department of Corrections' website to establish [Whitley’s] prison release date. [He] objected, arguing that this printout was hearsay. . . . The trial court overruled the objection, finding that the printout was admissible as a business record. Ultimately, it found that [Whitley] was a PRR and sentenced him accordingly.
Whitley v. State, supra. The Florida business records exception appears in another statute. Section 90.803 of the Florida Statutes says the rule barring hearsay does not apply to the items listed in this statute, which include the following: A memorandum, report, record, or data compilation, in any form, of acts, events, conditions, opinion, or diagnosis, made at or near the time by, or from information transmitted by, a person with knowledge, if kept in the course of a regularly conducted business activity and if it was the regular practice of that business activity to make such memorandum, report, record, or data compilation, all as shown by the testimony of the custodian or other qualified witness, . . . unless the sources of information or other circumstances show lack of trustworthiness. The term `business’ . . . includes a business, institution, association, profession, occupation, and calling of every kind, whether or not conducted for profit.
Florida Statutes § 90.803(6)(a). The Department of Corrections would, therefore, qualify as “business” for the purposes of applying the exception. Notwithstanding that, the Florida Court of Appeals agreed with Whitley:The trial court should have sustained [Whitley’s] objection to the printout. For a document to be properly admitted under the business record hearsay exception, it must be created at or near the time of the event, from information transmitted by a person with knowledge, and must be kept in the course of regularly conducted business. . . . These requirements must be shown `by the testimony of the custodian or other qualified witness’ or must be properly certified. . . . In the instant case, the State did not introduce the testimony of a records custodian, and the printout from the website was not certified. Therefore, the trial court erred in admitting the printout from the Department of Corrections' website under the business record exception to the rule against hearsay.
Whitley v. State, supra. The Court of Appeals therefore affirmed Whitley’s conviction for robbery but reversed the sentence that had been imposed on him and remanded the case back to the trial court for resentencing. It noted that “[a]t resentencing, the State is not precluded from proving [Whitley] is a PRR by a properly-authenticated record." Whitley v. State, supra.Basically, the prosecutor simply messed up. I found an earlier decision from the same court in which it upheld the courts using a Department of Corrections printout in sentencing another defendant. Desue v. State, 908 So.2d 1116 (Florida Court of Appeals 2005). In that case, though, the Department of Corrections’ (DOC’s)custodian of records, Diane Thompson, testified that the `Crime and Time Report’ was an official document copied from DOC records, that an inmate's admit and release dates are recorded at or near the time the inmate is jailed or released, as the case may be, and that records of inmates' release dates are kept in the ordinary course of DOC's business.
Desue v. State, supra.
In an earlier post, I explained that the federal system and every U.S. state – and many other countries – criminalize what is commonly known as hacking.
As I explained there, U.S. statutes, anyway, tend to define hacking as “accessing” a computer without being authorized to do so. And as I noted in another post, the federal system – and at least some states – also make it a crime to access a computer without authorization in order to commit fraud. I just ran across a recent case that involved a charge of computer crime under Colorado law. What I find interesting about the case is that the statute the defendant was charged under doesn’t define computer crime in terms of “access.” It uses a different term, but we’ll get to that in a moment. First I need to describe how the prosecution arose and what the charges were.The case is People v. Robb, 2009 WL 1013744 (Colorado Court of Appeals 2009). Bruce Robb was convicted of one count of securities fraud and one count of computer crime, and appealed his conviction to the Colorado Court of Appeals. Here are the facts that led to his being charged with both crimes: Kidztime was created by owners and associates of an affiliate of the Children's Cable Network (CCN). Kidztime was intended to provide nonviolent television programming for children. . . . to air on various cable stations in different geographical locales throughout the United States. Each Kidztime franchise was . . . an independent partnership.
Capital Funding paid commissions to its independent sales offices for selling general partnership interests in Kidztime and CCN. The . . . offices would contact Capital Funding with sales leads for potential investors. Prospective partners were provided with a sales brochure that included information about the partnership and with a partnership agreement. The brochure was known as the `green brochure.’ Computers were used as part of this process, including generating copies of the green brochure that were sent to potential investors. . . .
Beginning in 1995, Robb worked . . . as one of Capital Funding's first commissioned salespersons. Robb left . . . to pursue another job opportunity . . .was asked to return as a salesperson for Kidztime, which he did. Shortly thereafter, Robb . . . became a lead salesperson at an independent sales office in Colorado, where he supervised a team responsible for sales of partnership interests. . . .
In Robb's role as salesperson, he contacted people to tell them about investment opportunities with Kidztime. Robb followed the same script all the salespeople used when giving his sales pitch. If he found an interested prospective investor, that person's name was given to a staff member at Capital Funding, who would send out a copy of the green brochure to the potential investor. Robb received at least a fifteen percent commission for the units he succeeded in selling. . . .
The premise of the business model . . . was that local affiliates would generate revenue through advertising, which would fund . . . the programming . . . . Under . . . the partnership agreement, approximately eighty-five percent of the money raised was dedicated to fundraising expenses and . . . acquiring the programming. The remaining fifteen percent would serve as working capital for the affiliate. However, very few advertisements were sold. Because of this, the affiliates quickly ran out of money and could not continue to pay the leased access costs. After the advertising plan failed, the owners and operators of the organization attempted to conduct event-based marketing. . . . [but] very little money was generated . . . and the affiliates ran out of money.
In 2001, a . . . grand jury charged fourteen codefendants, including Robb, in an . . . indictment relating to the fraudulent sale of partnership interests during . . . . 1995-1998.
People v. Robb, supra. Robb was convicted and appealed, arguing that the evidence presented at trial was insufficient to show that he committed either securities fraud or computer crime. We, though, are only concerned with the computer crime charge, which was brought under this statute: Any person who knowingly uses any computer, computer system, computer network, or any part thereof for the purpose of . . . executing any scheme or artifice to defraud; obtaining money, property, or services by means of false or fraudulent pretenses. . . commits computer crime.
Colorado Statutes § 18-5.5-102(1). A related statute defines “`to use’” as “to instruct, communicate with, store data in, retrieve data from, or otherwise make use of any resources of a computer . . . or computer network.” Colorado Statutes § 18-5.5-101(10). As I explained in the post I did on hacking as access, many states define “access” – as in gaining unauthorized access to a computer – in essentially the same way.In his appeal, Robb claimed the evidence presented at trial “was insufficient to establish that he `used’ a computer or . . . network as the term `use” is defined in . . .Colorado's computer crime statute”. People v. Robb, supra. The Court of Appeals agreed:The evidence of Robb's use of a computer is sparse and shows that his interaction with computers at Capital Funding and Kidztime was remote and attenuated at best. Robb testified on direct examination that he was computer illiterate and did not even have a computer in his office, with the exception of a short period . . . before a computer left behind by the last person using the office was removed. He testified that he did not use that computer and . . . never even turned it on. On cross-examination, the prosecution did not ask Robb any questions about computer use. Nor have the People pointed us to any other evidence in the record (including documentary evidence such as emails) indicating that Robb used a computer or even directed the use of a computer. . . .
Indeed, the People's theory on appeal, as it was at trial, appears to be that evidence that other personnel in the organization actually used computers was sufficient evidence to convict Robb of computer crime, given his role as a salesperson. Thus, the record reflects that when Robb, in his role as a salesman, identified potential investors interested in purchasing a Kidztime unit, he gave those names to other staff members at Capital Funding. However, there is no evidence that Robb used a computer to do so. A staff person sent the potential investors materials about Kidztime, including the green brochure, which were apparently generated by a computer. However, according to [one witness], Robb and the other salespeople were not involved in generating those materials or sending them out to investors. . . . [T]he computer crime charge against Robb was not prosecuted on a complicity theory (nor was the jury so instructed). Thus, the People were required to prove beyond a reasonable doubt that he personally `used’ a computer as that term is defined in the statute, rather than that he simply aided and abetted others who may have actually used a computer in the sales process.
People v. Robb, supra. The Court of Appeals therefore held that the evidence was not“sufficient to prove use of a computer, where Robb simply provided information about prospective investors to another person, who sent out computer-generated materials to those prospects.” People v. Robb, supra. It therefore reversed Robb’s conviction on this count (but it affirmed his conviction on the securities fraud count). I think the Court of Appeals clearly reached the right result, in terms of the evidence the state offered to prove the computer crime charge. What I find interesting about the case is, as I noted before, that the Colorado statute predicated criminal liability on “using” a computer, rather than “accessing” a computer to commit fraud. Given the structure of the charge and the fact that the related statute defined “uses” in essentially the same way as other statutes define “accessing” a computer, the difference in terminology was really irrelevant; the crime and the conduct involved in committing the crime were the same as in “access” crimes.I wonder, then, why the Colorado legislature changed the statute Robb was prosecuted under. The indictment against Robb (and his codefendants) was returned in 2001, but it was based on conduct that occurred from 1995-1998. So he had to be charged under the version of the computer crime statute that was in effect during that period. That’s the version quoted above. In 2000, the state legislature rewrote the state’s computer crime statute, replacing “uses” with “accesses” in MOST of its provisions. (The exceptions are a section that makes it a crime to transmit malware and another section that makes it a crime to “use” a software application to circumvent limits on the online purchase of event tickets.) I can’t find any legislative history or articles or news stories that tell me why they made the revisions. My guess, and it’s only a guess, is that the legislature wanted to make the terminology used in Colorado’s computer crime statute consistent with the terminology in other U.S. computer crime statutes. So for all the appropriate crimes, they substituted “access” for “use.”
This post is basically about stings -- the ruses police use to catch people who are committing a crime. I got a question from someone who was curious about the use of “stings” in the online context. He wondered if it’s legal for an officer to go into a chat room or use some other online resource to engage in conversation with someone while pretending to be a child or a parent of a child who’s offering the child for sex. Many people, I suspect, think it is illegal for officers to trick people in order to gather evidence of a crime (or, as some argue, to create the conduct that’s later charged as a crime). It isn’t.
This post is about why it isn’t illegal for law enforcement officers to do this . . . or for private citizens to do it and then take the evidence to law enforcement. To explain that, I’m going to use the facts in U.S. v. Morris, 549 F.3d 548 (U.S. Court of Appeals for the Seventh Circuit 2008). Here they are:In October of 2007 [Morris] attempted to contact a minor at the minor's MySpace page. The minor's mother, Mrs. [X], responded to this unwelcome development by creating her own MySpace page, in which she pretended to be a 15 year old named `Kandice’ (not her daughter's name). On October 22, [Morris] began emailing `Kandice’ and they began chatting online on almost a daily basis. He asked her to have sex with him, and she agreed. On November 2, Mrs. [X] reported him to the FBI. Two days later he bought a bus ticket for `Kandice’ to travel to meet him, and mailed it to her. The FBI picked up the ticket and assumed `Kandice's’ identity and continued the online chats. On November 19 . . . the Bureau arrested [him].
U.S. v. Morris, supra. Morris was charged with attempting to transport a minor across state lines to engage in illegal sexual conduct in violation of 18 U.S. Code § 2423. He pled guilty but reserved his right to challenge the district court’s refusal to dismiss the charges against him.Morris argued that the charges should be dismissed because “the person he thought was a minor was neither a minor nor a law enforcement officer posing as one but was instead a private citizen.” U.S. v. Morris, supra. The Court of Appeals rejected the first part of his argument, noting that “case law uniformly holds that the fact that a defendant is mistaken in thinking that the person he is trying to entice is underage is not a defense to a charge of attempted illegal sexual contact with a minor.” U.S. v. Morris, supra.
The reason the law takes this position is that a defendant in this situation has shown he has the capacity to commit the crime and would have committed it, but for circumstances beyond his control; the theory is that since he’s demonstrated that he’s dangerous, it’s appropriate to punish this defendant to discourage him from doing the same thing again and to discourage others from doing the same thing.The Court of Appeals then addressed the other issue Morris raised: the fact that he was the victim of a sting run by a private citizen, not by a police officer. It noted that there is a
legitimate concern with vigilantism -- with private citizens conducting stings without the knowledge or authorization of the authorities. The vigilantes' aim might be to blackmail any offender whom they detect rather than to turn him over . . . for prosecution. . . . But stings, including private ones, must be distinguished from entrapment. Stings are schemes for getting a person who is predisposed to criminal activity to commit a crime at a time or place in which he can be immediately apprehended; they are an essential tool of law enforcement against crimes that have no complaining victim.
Entrapment refers to the use of inducements that cause a normally law-abiding person to commit a crime, and is a defense when the entrapment is conducted by law enforcement officers. . . .`For . . . targets of stings all that must be shown to establish predisposition and defeat the defense of entrapment is willingness to violate the law without extraordinary inducements. . . .'
U.S. v. Morris, supra. If the sting that caught Morris had been conducted by a law enforcement officer, he could have argued that he was entrapped, which is a defense to a criminal charge. To show he was entrapped, Morris would have had to show he was not predisposed to commit the crime, i.e., was neither interested in nor willing to violate the law without the government’s using “extraordinary inducements” to get him to do so. Defendants usually have a hard time making this showing, but some do succeed.In Jacobsen v. U.S., 503 U.S. 540 (1992) the U.S. Supreme Court reversed Jacobsen’s conviction for receiving child pornography because it found the government had not rebutted his defense of entrapment. In 1984, Jacobsen, “a 56-year-old veteran-turned-farmer who supported his elderly father in Nebraska, ordered two magazines . . . from a California adult bookstore.” The magazines were entitled “Bare Boys I and Bare Boys II and “contained photographs of nude preteen and teenage boys. The contents . . . startled [Jacobsen], who . . . expected to receive photographs of `young men 18 years or older.’” U.S. v. Jacobsen, supra. The boys in the magazines “were not engaged in sexual activity and [his] receipt of the[m] was legal under” federal and Nebraska law. Three months later, Congress made the “receipt through the mails of sexually explicit children a crime.” U.S. v. Jacobsen, supra.Postal inspectors found Jacobsen’s name on the mailing list of the bookstore that sent him Bare Boys I and II and for 34 months postal inspectors unsuccessfully bombarded him with mail offering to let him order child pornography. The Customs Service made its own, unsuccessful attempt at that point, followed by yet another effort from the Postal Service. This time Jacobsen ordered Boys Who Love Boys and was arrested “after a controlled delivery" of the magazine. U.S. v. Jacobsen, supra. When asked at trial why he ordered the magazine, Jacobsen said, “the statement was made of all the . . . hysteria over pornography and I wanted to see what the material was. . . . I didn’t know for sure what kind of sexual action they were referring to”. U.S. v. Jacobsen, supra. He relied on the defense of entrapment at trial, but lost. The U.S. Supreme Court found that the government failed to prove beyond a reasonable doubt that Jacobsen had been predisposed to order child pornography:Petitioner's ready response to these solicitations cannot be enough to establish beyond reasonable doubt that he was predisposed, prior to the Government acts intended to create predisposition, to commit the crime of receiving child pornography through the mails. The evidence that petitioner was ready and willing to commit the offense came only after the Government had devoted 2 1/2 years to convincing him that he had or should have the right to engage in the very behavior proscribed by law. Rational jurors could not say beyond a reasonable doubt that petitioner possessed the requisite predisposition prior to the Government's investigation and that it existed independent of the Government's many and varied approaches to petitioner. As was explained in Sherman, . . . `the Government [may not] pla[y] on the weaknesses of an innocent party and beguil[e] him into committing crimes which he otherwise would not have attempted.’
Because. . . the prosecution failed, as a matter of law, to adduce evidence to support the jury verdict that petitioner was predisposed, independent of the Government's acts and beyond a reasonable doubt, to violate the law by receiving child pornography through the mails, we reverse the . . . the conviction of Keith Jacobson.
U.S. v. Jacobsen, supra. To prevail on an entrapment defense, Morris would have to show his situation was analogous to that of Jacobsen. From the few facts we have, it appears he would have had a difficult time doing that, but his point was that he should have had the opportunity to try. Morris claimed he should not be prevented from raising entrapment simply because the sting was not run by a law enforcement officer.The Court of Appeals didn’t buy his argument. It explained that there is no “defense of private entrapment.” U.S. v. Morris, supra. The court also noted that private stings have become much more significant in the online world than they are in the real world:[W]e read that `the inexpensive, relatively invisible nature of [Internet sting operations] . . . permits private entrapment to become rampant, which is not the case in off-line settings. . . . On-line vigilantism against pedophiles has taken on unexpected proportions. Traditional entrapment rules do not allow consideration of “private entrapment.” Individuals . . . induced or set up by anyone besides a state agent cannot raise an entrapment defense to criminal charges. Historically this was not a problem because most individuals, even if they had the motivation to entrap others, did not have the resources to orchestrate a sting while protecting themselves from retaliation if caught. Private entrapment was therefore a rare occurrence. The Internet has changed this, for better or worse, at least for the crimes perpetrated partly on-line.’ Dru Stevenson, Entrapment by Numbers, 16 U. Fla. J.L. & Public Policy 1, 70 (2005).
U.S. v. Morris, supra. The court then returned to the point it made earlier -- that private stings can be legally problematic. Those who run private stings may use them to blackmail the targets or may “botch their investigation, alerting the offender in time for him to elude justice.” U.S. v. Morris, supra. The court noted that private stings can be problematic for yet another reason: the stinger may commit a crime “in his attempt to catch others.” U.S. v. Morris, supra. It cited two cases in which those who claimed to have been operating private stings were charged with possessing child pornography. U.S. v. Morris, supra. Ultimately, though, this Court of Appeals found that none of these concerns justified a private entrapment defense:[I]f the law wants to deter private sting operations, . . . the way to do that is `by imposing criminal liability on private parties who encourage crimes . . .’ rather than by letting another guilty person -- the object of the successful sting -- get away with his crime. Just as there is no defense of private entrapment, so there is no exclusionary rule applicable to evidence obtained improperly by private persons. . . .
U.S. v. Morris, supra. So if you're the victim of a government sting, you might be able to use entrapment as a defense, but you're going to have to show, essentially, the the idea of committing the crime originated with the government, not you. If you're the victim of a private sting, under this decision, anyway, you can't raise the defense of entrapment . . . but you may be able to get the stinger prosecuted if he or she violated the law by, say, sending you child pornography.
Not long ago, something I’d written was peer-reviewed as part of being vetted for publication. In it, I wrote about the problem of keeping order in cyberspace, and one reviewer criticized me for not analogizing cyberspace to the Old West. I submitted my response to that reviewer’s comments – and the comments of the other reviewers – to the press considering my manuscript. The editors were apparently happy with my response, at least happy enough to publish what I’d written. What I found a little unsatisfactory is that my response didn’t make its way to the person who’d advocated the Old West analogy. I didn’t find it unsatisfactory out of pique, at least I don’t think that was the reason. I think I was aggravated because I didn’t get the chance to respond to the person and debate the utility of the Old West analogy. So I decided to do a blog post on the issue. I don’t know who first came up with the idea of analogizing cyberspace to the Old West (a/k/a Wild West). I did some searches and found that the analogy was being used in articles at least as far back as 1995. Maybe it was in use before that, maybe not. It’s been around for a long time, and still crops up in articles about cyberspace, usually articles dealing with the presumed lawlessness of cyberspace.My first question is why do we need to analogize cyberspace to anything? Why can’t we just approach cyberspace as . . . cyberspace?I think our inclination to analogize cyberspace to the Old West – or some other place – is a function of how we experience it. As we know, cyberspace isn’t a “place” at all, at least not in the physical sense. It’s an experiential reality, not a physical reality. That is, it’s made up of the sum – and often transient – total of our experiences, which take the form of digital communications (oral, visual and text). We use those communications to interact with each other – and sometimes with automated systems – and, in so doing, “experience” cyberspace as a distinct and discrete part of our lives.Which brings me back to my question: Why do we need to analogize our experiencing cyberspace to being in a specific physical place? I think it’s because we have a rather limited conceptual repertoire. Except for cyberspace, all the experiences I will have in my life will occur in a given place; it may be a mundane place (my home, my office) or a more or less exotic place (a foreign country, a domestic location I don’t/can’t frequent except once, say) or a transitory place (an airplane or train or hotel). When I think of an experience, I inevitably think of a place; our experiences are grounded in, and consequently associated with, “places.” We see that in our dreams. Conceptually, I suppose, we could have perfectly abstract dreams . . . dreams in which our experiences were not situated in dream spaces, the more or less skewed versions of physical reality that serve as the stage for whatever goes on in a particular dream. People may or may not dream in color, but I suspect we all dream of places. As I write this, I’m trying to conceptualize an experience that would not be grounded in a place, and I find I can’t. Maybe it’s just me, but I suspect not. It follows, then, that we analogize our experiences in – and of – cyberspace to being in a particular physical place. To paraphrase William Gibson, cyberspace is a consensual hallucination orchestrated and shared by millions of people. More precisely, cyberspace is the sum total of discrete hallucinations that are orchestrated by congeries of people, congeries that shift in size and constituency. When we contribute to orchestrating the hallucinations that create and sustain cyberspace, we need a way to think about what we’re doing . . . and that brings us back to the spatial analogy. Think about it: How do we refer to our participation in cyberspace? We say we’re “going online” or we’re “in cyberspace”. “Going” and “in” are terms we use to refer to action that is grounded in physical reality. I go to work; I’m in my office.Why do we analogize cyberspace to physical reality when we don’t use a spatial analogy for the comparable experience of talking on the phone? I don’t say I’m “going into phone space” when I’m making a call or joining a teleconference (I hate teleconferences). We seem to experience telephone communication differently from cyberspace, at least for as long as the two remain separate experiences. I’m not sure why that is. Part of it probably derives from the fact that for over a century a phone call only involved two people. So a phone call was really just a conversation, a remote conversation but still a conversation between two people, both of whom were situated in discrete parts of physical space. I wonder if things would have been different if the phone had not evolved as a one-to-one mode of communication. When telephones were new, in the mid- to late-nineteenth century, they were used to broadcast news and music. You could sign up to listen to an orchestra playing (live, of course) or to get news via your phone. For some reason, that broadcast use of the telephone never caught on, maybe because radio came along and seemed to do the same things much more efficiently.
Somehow I doubt that phones could ever have evolved into a version of cyberspace, even if the notion of using them for more than one-to-one (or teleconferences) had caught on. You wouldn’t have had the visual aspect, which I think is an important element in experiencing communicative reality as an analog of physical reality. And I don’t think purely oral communication could have sustained an experiential reality of the complexity that we see in cyberspace; oral communications are, after all, transient.I digress. I need to get back to my real point – the Old West analogy for cyberspace. I’ve made my argument as to why we seem to need to analogize cyberspace to A place. That brings us to my second question: Why the Old West?I think people tended to analogize cyberspace to the Old West because it was a familiar analogy (especially to those of us in the U.S.) and because it captures the notion of being in an experiential environment in which the rules that govern us in the real-world either don’t apply at all or are relaxed. So, as I recall, many of the early articles written about cyberspace analogized it to the U.S.’ Western frontier on the grounds that, like the Old West, it was a place (the term is inevitable) where there wasn’t much, if any law . . . or, maybe, where there wasn’t much in the way of law enforcement. As I’m sure we all know, cyberspace is pretty lawless compared to the contemporary physical world. Many people, including me, have written about why law enforcement finds it difficult to deal effectively with many of the things that go on “in” cyberspace. It’s much easier to be anonymous or assume a pseudonym in cyberspace than in the real world; and cyberspace transcends the boundaries of nation-states, which hampers law enforcement’s ability to pursue law-breakers even if they are able to identify them.I could go on about the challenges cyberspace creates for law enforcement, but that’s not my point in this post. If you want to read more about that, check out some of my articles or my latest book. My point finally, is that while I think spatial analogies are inevitable, I don’t think the Old West is the best spatial analogy for cyberspace. The Old West analogy assumes that cyberspace is a frontier, like the Western part of the U.S. in the nineteenth century or like Australia during the early years of its colonization. Dictionary.com defines a frontier as “the land or territory that forms the furthest extent of a country’s settled . . . regions.” That’s what the Old West was: The Eastern and Southern U.S. states had been settled and civilized for a long time. The challenge the U.S. faced was extending the law that applied in the Eastern and Southern states to the Western areas of the country. That process was facilitated by the fact that the people who lived on the frontier had come from the settled parts of the country where the law was enforced; they had experience with the rule of law and, for the most part, wanted to see that rule applied to the areas where they now lived. I think all of that makes the Old West analogy inapt: it’s a lot easier to expand law and law enforcement into areas that are owned by and therefore under the absolute control of a sovereign nation than it is to institute law and law enforcement in a “place” – a world” -- that has neither. I don’t see cyberspace as a frontier than can be civilized by exporting U.S. law or European law or Asian law or an amalgam of global law (assuming such a thing could be created) “into” cyberspace because I see cyberspace as a vacuum when it comes to law and law enforcement.The analogy I prefer – and it has its own imperfections – is to Europe in the early Middle Ages, what some have called the Dark Ages. It’s not a perfect analogy because it was an environment in which law and law enforcement had existed but disintegrated with the collapse of the Roman Empire. The reason I prefer the medieval analogy is because the world that evolved (or devolved) after the Empire collapsed was one in which there was no generalized governing structure and therefore no consistent, reliable order; there was law, but it was parochial, just as governance was parochial.The medieval analogy is far from perfect, but since I can’t come up with a real-world analogy based on a “place” in which there had never been any source of law and law enforcement, it’s the best I can do. As I argued in an article I published a few years ago, I don’t think any human grouping can exist and survive without having some system of law and law enforcement to guarantee the stability people need to carry out the activities essential to their survival and the survival of their group.
At least that has always been true in the physical world; since cyberspace is in a sense a luxury, in that we inhabit it by choice rather than by necessity, perhaps my argument does not apply there. Perhaps cyberspace can – and should – survive in a state of greater or lesser chaos, in which people depend on themselves and perhaps some associates for their security. That’s pretty much what it came to in the Middle Ages.
This post is about a federal civil case in Louisiana. Becker v. Toca, Civil Action No. 07-7202 (U.S. District Court for the Eastern District of Louisiana). I’m doing a post on this civil case because it arose from the defendant’s allegedly installing a Trojan horse on a law firm’s computers. Here are the facts alleged in the plaintiff’s complaint, i.e., the pleading that got the case started:Plaintiff, PHILLIP M. BECKER individually operates his law firm in Lake Charles, Louisiana, with the use of tools and equipment including computer hardware and software, which is connected to the Internet by typical means. . . .
Prior to 25th of October, 2006, BECKER . . . and personnel employed by his law firm, began to experience considerable difficulties in both their home and office computers. This consisted of error messages, slow processing, and other indicators of technical problems with the operations of the computers.
BECKER . . .retained the services of WebTronics LLC, a third party contractor with expertise in computer operation, to evaluate both his home and office computers.
After an extensive evaluation, WebTronics . . . identified . . .spyware and viruses on two Compaq computers and one Toshiba laptop . . . and advised BECKER . . . to take further action with an Internet forensic team located in Baton Rouge.
Upon further examination, it became apparent the computers . . . were infected with an interest `Trojan Horse’ virus named `Infostealer.’ Infostealer is used to detect and steal passwords from computers . . . by gathering the passwords from the compromised computer and sending them to a remote computer by email or other means.
The Infostealer virus was sent to BECKER and to his law firm by the Defendant, TOCA by means of various emails and attachments.
The Defendant, TOCA knew that the use of the Infostealer Trojan Horse virus would give her unauthorized access to her ex-husband's personal and business computers.
The actions of . . . TOCA were . . . done . . . in the hopes that private information disseminated to her by means of the Infostealer . . . would provide her with some kind of . . . advantage in ongoing domestic litigation . . . between the two parties.
Becker v. Toca, Complaint (October 23, 2007), 2007 WL 4546306 (E.D.La.). Becker claimed the installation and use of the Trojan violated three federal statutes: the Wiretap Act, 18 U.S. Code § 2510, the Stored Communications Act, 18 U.S. Code § 2701 and the Computer Fraud and Abuse Act, 18 U.S. Code § 1030. Becker v. Toca, 2008 WL 4443050 (U.S. District Court for the Eastern District of Lousiana). Toca responded by filing a motion to dismiss all three claims. When a defendant files a motion to dismiss civil claims, he/she says that even if the facts alleged in the plaintiff’s complaint are true, they don’t establish a valid claim under the law the plaintiff is relying on. So in ruling on her motion to dismiss, the judge had to assume – for the limited purpose of ruling on the motion – that the facts alleged in the complaint were true. Toca’s first argument was that sending a “virus to detect and steal passwords . . . on a computer does not constitute an attempt to `intercept’ an “electronic communication” for purposes of the Federal Wiretap Act.” Becker v. Toca, supra. In ruling on this argument, the federal judge noted that the “The Federal Wiretap Act subjects to criminal liability any person who `intentionally intercepts . . . any wire, oral or electronic communication,’ except as otherwise permitted by law.” Becker v. Toca, supra (quoting 18 U.S. Code § 2511(1)(a). The Wiretap Act makes it permissible to intercept communications in certain circumstances – such as when someone is a party to the communication or when they are a law enforcement officer who has a court order authorizing the interception – but none of them applied to Toca.The issue was whether the Infostealer Trojan “intercepted” electronic communications. The opinion doesn’t tell me what Toca’s argument was, but I assume she claimed the information the Trojan detected was stored on the computers it targeted; courts have found that to “intercept” a communication, you have to capture its contents while it is “in flight,” i.e., while it is traveling from one person to another. If the Trojan simply took data that was stored on the computers, it didn’t “intercept” a communication. The federal judge rejected Toca’s effort to have the Wiretap Count dismissed, at least as this point in the litigation. The complaint said the targeted computers were “`connected to the Internet by typical means’”. Becker v. Toca, supra. Given that allegation, which the court had to assume was true for the purpose of ruling on the motion to dismiss, the judge found it was “reasonable at this time to infer that the Trojan Horse program may have collected information contemporaneous to its transmission over the internet.” So that claim is still live; once she’s able to introduce evidence to support her argument, Toca may be able to show there was no interception of an electronic communication, but the claim survives unless and until she does. Toca’s second argument was that “the Stored Communications Act (SCA) does not apply to the instant case because the Plaintiff's computers are not `facilit[ies] through which an electronic communication service is provided.’” Becker v. Toca, supra. The Wiretap Act makes it a crime to intercept data while it is in transmission; the SCA makes it a crime to intentionally access “without authorization a facility through which an electronic communication service is provided” and obtain, alter or prevent “authorized access to a wire or electronic communication while it is in electronic storage in such system.” Becker v. Toca, supra (quoting 18 U.S. Code § 2701(a)). The SCA defines an electronic communication service as “any service which provides to users . . . the ability to send or receive . . . electronic communications.” 18 U.S.. Code § 2510(15). It defines electronic storage as “any temporary, intermediate storage of a[n] . . . electronic communication incidental to the electronic transmission thereof; and [ ] any storage of such communication by an electronic communication service for purposes of backup protection of such communication.” 18 U.S. Code § 2510(17).The federal judge held that he could not dismiss the SCA claim at this point in the casebecause it is unclear to what extent the program may have accessed . . . information stored with an electronic communication service provider. Although the Plaintiff does not allege that his personal or office computers were `facilities through which an electronic communication service is provided,’ the computers may qualify as such because the Plaintiff does allege that he used the computers to run his business. Further, the Plaintiff alleges that the Defendant transmitted the Trojan Horse program to him via email and that the program sent information back to the Defendant `by email or other means.’ It is therefore unclear whether the program may have accessed files stored with an electronic service provider during its transmission of data. Finally, the Plaintiff alleges that the Trojan Horse program targeted passwords, and it is unclear . . . whether the targeted passwords were system passwords saved on the Plaintiff's hard drive or web-based passwords captured during transmission over the internet.
Becker v. Toca, supra. Again, the court was not saying that Toca was liable for violating the SCA. All he’s saying is that he can’t dismiss this claim at this point; later, she may be able to produce evidence at trial showing that she did not, in fact, violate the statute.Finally, Toca argued that the Computer Fraud and Abuse Act (CFAA) did “not apply because the Plaintiff only alleges the Defendant sought to recover passwords and did not intend to `harm’ the Plaintiff's computer.” Becker v. Toca, supra. As I noted in an earlier post, the CFAA – or, as I prefer, 18 U.S. Code § 1030 – creates a number of federal computer crimes and creates a civil cause of action for people who have been the victim of such a crime. Becker’s claim under § 1030 alleges Toca violated the statute, which gives him the right to sue for “damage” he sustained as a result of the violation. 18 U.S. Code § 1030(g). In moving to dismiss this claim, Toca argued that Becker had “failed to establish that the Defendant intentionally caused `damage’ to the Plaintiff's computers. Specifically, the Defendant argues that a person cannot simultaneously seek to damage a computer and gather passwords from the computer, because a person cannot recover passwords from a non-functioning computer.” Becker v. Toca, supra. Once again, Toca lost. The federal judge explained that § 1030 does not, as Tocasuggests, apply only in the instance that a person intends to render a computer completely inoperable. Rather, the statute defines `damage’ as `any impairment to the integrity or availability of data, a program, a system, or information.’ 18 U.S. Code § 1030(e)(8). The Plaintiff alleges that his computers presented `error messages, slow processing, and other indicators of technical problems.’ . . . Error messages and slow processing constitute impairments to the integrity or availability of data. Therefore, assuming that all of the Plaintiff's allegations are true, it is reasonable to infer that the Defendant may have intended to cause such limited damage to the computers at issue, even if she did not intend to render them completely inoperable. Accordingly, the Court finds that the Plaintiff has stated a valid claim under the Computer Fraud and Abuse Act.
Becker v. Toca, supra. So there you have it. I don’t know if the case has since settled or will wend its way to trial at some point. It’s not the first use of spyware I’ve seen in “domestic litigation,” but it’s the first time I’ve seen it used against a law firm.
On April 21, the U.S. Supreme Court decided a case that significantly reduces a police officer’s ability to conduct a search incident to arrest when the person arrested was in a vehicle. The case is Arizona v. Gant. As I’ve explained before, search incident to arrest is an exception to the 4th Amendment’s warrant requirement. The 4th Amendment requires that searches be reasonable, and the reasonableness requirement can be satisfied either by a warrant (a search warrant, in this instance) or by an exception to the warrant requirement.The search incident exception lets a police officer search the person being arrested and the area immediately around the person (the lunge area) to find weapons and evidence. The rationale for letting an officer search has two parts: The first premise is that when an officer takes someone into custody, that creates a potentially dangerous situation; it is therefore reasonable to let the officer search for and seize any weapons that could be used against the officer (or anyone else). The other premise is that it is reasonable to let the officer search the person for evidence of crime to prevent him from destroying it.Gant isn’t about the part of search incident that lets an officer search the person being arrested; it’s about the scope of a search of the area around the person being arrested. For arrests that are made anywhere other than in a vehicle, the Supreme Court uses a fact-sensitive test. That is, in each case the officer has to justify why he searched a particular area. So if, say, an officer arrests someone in a small motel room and then searches under the bed, claiming it’s part of search incident to arrest, the officer will have to convince the court that he had good reason to search under the bed. If, say, the suspect didn’t have shoes on and the officer were going to let him reach under the bed to get his shoes, then it would be reasonable for the officer to check under the bed. Until yesterday, when an officer arrested someone in a vehicle, a special rule – called the Belton rule – applied to the scope of the search incident of the lunge area. In the Belton case, the Supreme Court held that a standard test defines the lunge area when someone is arrested in a car. Under Belton, an officer could search the passenger compartment of the vehicle – including the glove compartment and console – plus any containers in the passenger compartment. Containers included anything that could hold evidence or a weapon . . . bottles, a jacket pocket, a purse, etc. The U.S. Supreme Court didn’t explicitly address this issue, but over the years most lower courts held that the officer could conduct a Belton search even though the person being arrested was in handcuffs in the back of a patrol car. Some state courts said that didn’t make any sense, because if the person isn’t going to get back in the car, there’s no reason to let the officer do a Belton search because the person can’t grab any weapons in the car or destroy evidence in it. Most courts, though, held that Belton applied even if the person was in a police cruiser and was not getting back into the car. Indeed, that’s what happened in the Belton case; Belton was under arrest and in handcuffs and definitely not getting back in the car, but the Court said the search was a valid search incident to arrest. For several years, I’ve been speculating about whether Belton could be used to justify a search of the files on a laptop that was in the passenger compartment of the vehicle in which the driver was arrested. I found a lower-court case in which the court said the government argued that such a search would be proper . . . but since that issue really wasn’t before this court, it didn’t rule on whether such a search would be proper under Belton or not.Well, Belton’s gone . . . that’s what Gant has done. The Gant Court held that [p]olice may search a vehicle incident to a recent occupant’s arrest only if the arrestee is within reaching distance of the passenger compartment at the time of the search or it is reasonable to believe the vehicle contains evidence of the offense of arrest. When these justifications are absent, a search of an arrestee’s vehicle will be unreasonable unless police obtain a warrant or show that another exception to the warrant requirement applies.
Arizona v. Gant, supra.That’s going to make things interesting. Under Belton, officers could open a container in a vehicle without having probable cause to believe it contained evidence; the Supreme Court has held that in the context of arrests, we need “bright line” rules, i.e., rules that are standardized. The rationale was that arrests can be dangerous, fluid situations and we don’t want officers having to figure out whether they can search an area or not. Now they’re going to have to do just that.I assume (and I’d hope) that officers aren’t going to leave arrestees in a vehicle just so they can search it; that seems a very dangerous thing to do. So pretty much the only time they’ll be able to do a search incident of the vehicle is when they have reason to believe there’s evidence of the crime for which the person has been arrested. (I assume reason to believe is less than probable cause because officers can search a vehicle under a different exception, the vehicle exception, if they have probable cause to believe it contains evidence of a crime.) That’s significant: it means that if someone is arrested on a traffic violation, it’s going to be very hard for an officer to search a vehicle under the search incident exception . . . because as many defendants have pointed out, it isn’t likely that evidence of the traffic violation (not having an operator’s license, for example) will be found in the vehicle.So where does that leave us with the laptop in the vehicle of someone who’s been arrested? It looks like it’s going to be hard to search the laptop under this exception. I suppose if an officer arrested someone for having such perpetrated a terrorist bombing, the officer MIGHT be able to search the laptop he/she found in the arrestee’s car. I’m really not sure. I am sure that this is going to make it much, much harder to use the vehicle search incident exception to search a laptop.
Last year I did a post in which I talked about how the use of cyberspace challenges the efficacy of the law enforcement model in dealing with crime and terrorism.
In this post, I want to talk about how, and why, cyberspace can blur the distinctions between the three categories of threats nation-states have to deal with if they are to survive and prosper.The three categories are crime, terrorism and war and the distinctions between each are reasonably well defined and reasonably stable in the physical world. The definitional clarity and empirical stability of the threat categories is a function of the fact that the physical environment is far less malleable and therefore far less ambiguous than the conceptual environment of cyberspace.
Three years ago, I did a post analyzing how our use of cyberspace can erode the distinctions between crime, terrorism and warfare. In this post, I want to address a related issue: how cyberspace erodes the assumption that is responsible for our dividing threats in to the three categories noted above. To do that, I need to briefly review the differences between the three categories. (If you want to read more on that issue, check out my prior post on cyberthreats.)A crime consists of someone’s violating a law forbidding certain conduct and/or the infliction of certain harm. The crime of murder prohibits one person’s intentionally causing the death of another person; the crime of theft outlaws one person’s taking another person’s property without their permission and with the intention to deprive them of that property. Crimes are committed by people. The purpose of criminal law, as I’ve noted hear and elsewhere, is to maintain the baseline of order within a society that is essential if the members of that society are to be able to carry out the activities (e.g., procure food, clothing and shelter, reproduce the population, etc.) essential to ensure their own survival and that of the society. A society cannot, as I’ve noted elsewhere, survive if its members are free to prey on each other in ways that would undermine the critical level of order needed to fend off chaos.Societies control crime by using two sets of rules: One is a set of civil rules. So every society has civil rules that deal with status (when people become adults, which adults have which rights, etc.), property (who can own property, how one acquires, maintains and transfers ownership, etc.), familial bonds (kinship, marriage, divorce, custody, etc.) and other critical matters. Some of these civil rules are informal norms; most of us internalize those norms and that keeps our behavior within socially acceptable bounds. Some of these civil rules are laws, the enforcement of which falls to civil courts and civil litigation (suits between individuals).Societies also use criminal rules to maintain order. As I’ve explained elsewhere, while other biological systems (e.g., ants, termites) can get along with just civil rules, humans cannot because we have the ability to deviate. That is, because of our individual intelligence, humans can simply decide not to follow a civil rule; most of us cannot, or do not, make such a decision, but there is always a subset of people who do. Criminal law is intended to keep them in line by letting the state impose sanctions – punishment – on those who violate criminal laws that are designed to discourage conduct that seriously challenges a society’s ability to maintain order. So when Jane Doe murders John Doe, the society she belongs to will convict her of murder and impose a sanction which, in the modern world, is usually incarceration (or perhaps execution). The primary purpose of this is to deter Jane from breaking any more criminal rules; a secondary purpose is to deter others from following her example. Criminal trials are a type of theater – a public denunciation of the conduct criminals like Jane engage in. The punishment imposed on Jane underscores the unacceptability of engaging in such conduct and implicitly threatens the imposition of similar consequences on those who follow Jane’s example.Implicit in all of that is a basic assumption: Individuals commit crimes. That assumption also applies to terrorism, which is essentially the commission of crime(s) for ideological reasons. Criminals commit crimes for financial reasons (e.g., fraud, theft, extortion) and for what I call passion (e.g., anger, sexual/emotional pressures). The motive behind the commission of crimes is personal: I steal to benefit myself, directly or indirectly; I murder out of revenge or jealousy or some psychological need or to eliminate someone who is a threat to me. Terrorists commit crimes (they kill and injure people, damage and destroy property) but for different reasons; terrorists commit their crimes to promote a particular ideology, usually by trying to coerce or intimidate the population of a particular society.This brings us to the third category: war. War is, and has always been, waged not by discrete individuals but by a society . . . by nation-states in our world. War is a struggle between two collective entities; while it is wages by discrete individuals, the players are the nation-states (or other sovereign entities) who are engaged in a struggle, usually a struggle for the survival. War has historically been a zero-sum affair in which one state or sovereign entity wins and the other loses; the loser has traditionally lost its identity and either been subsumed by the victorious state or eliminated (think Carthage). War is and has been a struggle between nation-states for at least two reasons: One is that it is transnational. War by definition transcends national boundaries; civil war, of course, occurs within the territory of a nation-state but I don’t include civil war in the concept of war I’m using in this post. Civil wars display many of the characteristics of war (e.g., carnage), but are more properly understood as an internal struggle; civil wars occur when some part of the citizenry of a nation-state rebel against its established government, as happened in the U.S. Civil War. War, as such, is a struggle between two sovereigns; since nation-states are the sovereigns in our world, war in our world consists of a struggle between two nation-states, e.g., between two territorially-based governing entities. The other reason war is a struggle between two nation-states is that only nation-states have been able to summon the resources needed to wage war. Al Qaeda has for some time considered itself to beat war with the United States, but no group of individuals can truly wage war in the physical world. Al Qaeda’s attacks are terrorism, not war; the 911 attacks were terrible things, but isolated, low-level attacks like those cannot constitute war because they do not pose a serious threat to the survival of the United States as a sovereign entity. When Hitler invaded Poland in 1939, that was clearly the onset of war between two sovereign entities; the invasion required Poland to reciprocate with force that was commensurate with the force used by the invaders and was quite beyond the capability of any individual or group of individuals. So, to recapitulate, crime and terrorism are committed by individuals and take place inside the territory of a specific nation-state. War, on the other hand, is committed by nation-states and necessarily involves a struggle that transcends national boundaries.I want to use something that didn’t happen to illustrate how cyberspace erodes the distinctions between crime/terrorism and war. In 2001, Interior Minister Otto Schily said it might be necessary for Germany to use “denial-of-service attacks . . . to shut down some sites based in the United States.” Wired (January 10, 2002). The sites in question were neo-Nazi sites operated by Gary Lauck of Nebraska. They distribute pro-Nazi material; distributing such material is a crime in Germany, so if Lauck were in Germany, he could be prosecuted for violating German law. Since Lauck is in the United States, he and his websites are protected by our First Amendment. Since the First Amendment gives him the right to distribute the material, he has not committed any crimes in the U.S. and therefore cannot be extradited to Germany to stand trial for violating German law. (Extradition requires that the person’s conduct have been a crime in both countries.)Let’s start with Lauck. He didn’t commit any crimes in the U.S. Did he commit a crime, terrorism or war in Germany? Distributing neo-Nazi material is a crime “in” Germany; if Lauck was handing out neo-Nazi literature in Berlin, he would clearly be committing a crime “in” Germany. Lauck’s use of cyberspace muddies the analysis because it means his conduct simultaneously occurs “in” the U.S. and “in” Germany. If we approach crime as a unitary construct in which all the elements of a crime must occur in a nation-state for the activity to constitute a crime there, Luack would not have committed a crime in Germany. Modern criminal law, though, says you can be prosecuted in a jurisdiction if you cause “harm” there by engaging in activity outside that jurisdiction. Under that theory, Lauck committed a crime “in” Germany (if the Germans can show he intentionally distributed the material in Germany, as opposed to putting it online for anyone to see.)What about Schily’s proposal (which he later retreated from)? If Germany had launched a DDoS attack on the Nebraska servers hosting Lauck’s websites, would that be war? Crime? Terrorism? It wouldn’t be terrorism, for the simple reason that Germany would not be launching such an attack to coerce the U.S. civilian population into, what?, repealing the First Amendment. That leaves us with crime and war. Would it be an act of war for Germany to launch such an attack? It would, in a sense, be an invasion . . . a kind of digital analogue of Japan’s attack on Pearl Harbor . . . without, of course, the intention to start an armed conflict between the two countries. It would not be a physical invasion of U.S. territory, but a DDOS attack could certainly be seen as a hostile act by the targeted country. I suspect that if the CIA launched such an attack on a North Korean facility, the North Koreans would consider it an act of war.It looks more like a crime, though, because Germany would be targeting an individual, not the United States. And in the U.S. federal law and the laws of many states define DDoS attacks as a crime, as do the laws of other countries. But can a country commit a crime? Crimes are committed by individuals; war crimes prosecutions target the acts of specific individuals, not the country of which they were citizens. if we assume a country can commit a crime, how would we handle that? Would the U.S. prosecute Germany (something that, as far as I know, is simply not possible under existing law)? Or would the U.S. ask German authorities to hand over Mr. Schily and the individuals who executed the DDoS attack so we could prosecute them for a crime? Since it looks to me like § 303b of the German Penal Code makes a DDoS attack a crime, they might be subject to extradition under the principle I noted earlier, i.e., DDoS attacks are a crime in the U.S. and in Germany. I suspect, though, that the German authorities would not be inclined to turn them over to us, even if extradition was permissible under the law. My point simply is that cyberspace makes threats more complex: Individuals can launch attacks (like DDoS attacks on facilities in another country) that have at least some of the characteristics of an act of war (e.g., transnational, ability to launch repeated attacks that shut down essential systems). And countries can engage in activity that looks a lot like crime. And then there’s terrorism . . . .