Friday, August 21, 2009

Technical Difficulties

I apologize for the inconsistent fonts in my last post . . . and for some similar problems in earlier posts.

Since I upgraded Firefox, I'm occasionally having formatting problems when I upload posts to Blogger. I'll keep working on them, though.

Cyberterrorism . . . ?

This post is about a case in which one company sued another claiming it was the victim of cyber-terrorism.


The case is Margae, Inc. v. Clear Link Technologies, LLC, 2009 WL 1248952 (U.S. District Court for the District of Utah 2009), and here, according to Plaintiff Margae, is what led to the filing of the lawsuit:

Plaintiff is an internet marketing company that contracts with individuals and entities to act as an internet referral agent. Plaintiff performs internet marketing services for entities and individuals on its websites to generate sales leads for those entities and individuals, often known as `merchants.’ The sales leads are directed by Plaintiff to the merchants' websites or provided telephone numbers to reach a merchants' call center for each sales lead that generates an actual sale. Plaintiff receives a commission for each referral that leads to a sale. Additionally, Plaintiff performs search engine optimization for some merchants which results in a merchant's website appearing earlier when a customer performs an internet search. . . .

From January of 2004, Plaintiff entered into a series of agreements with Clear Link to provide affiliate and optimization services. . . .

Eventually, Clear Link terminated Plaintiff. . . .

Clear Link 1) misappropriated various websites associated with Plaintiff and 2) changed all of Plaintiff's account passwords so that Plaintiff could not (and cannot) access websites that it created pursuant to its work with Clear Link. In addition, Clear Link continues to utilize certain websites, sub-domains and optimization work provided by Plaintiff.

Plaintiff’s Memorandum in Support of Motion to Compel Arbitration and Stay Proceedings, Margae, Inc. v. Clear Link Technologies, LLC, 2008 WL 1906775.


In its complaint, Margae asserted several causes of action, one of which was unfair competition under the Utah Unfair Competition Act (UUCA).

The type of `unfair competition’ alleged by Margae is `cyber terrorism.’ `Cyber terrorism’ is defined, in part, as `willfully communicating, delivering, or causing the transmission of a program, code, or command without authorization or exceeding authorized access’ which `leads to a material diminution in value of intellectual property.’ . . . Margae contends . . . that Clear Link's unauthorized use of its web pages lead to the diminution of those web pages' value because Margae was deprived of the commissions it was owed from their use.

Margae, Inc. v. Clear Link Technologies, LLC, supra. Margae’s cyber-terrorism claim was brought under Utah Code § 13-5a-103, which creates a civil cause of action for unfair competition.


Section 13-5a-102(4)(a) of the Utah Code defines “unfair competition” as “an intentional business act or practice that” is (i) unlawful, unfair or fraudulent or leads to a material diminution in value of intellectual property AND constitutes (i) cyber-terrorism, infringement of a patent, trademark or trade name, a software license violation or predatory hiring practices. Section 13-5a-102(2) defines cyber-terrorism as any of the following:

(a) the unlawful use of computing resources to intimidate or coerce others;

(b) accessing a computer without authorization or exceeding authorized access;

(c) willfully communicating, delivering, or causing the transmission of a program, information, code, or command without authorization or exceeding authorized access;

(d) intentionally or recklessly:

(i) intends to defraud or materially cause damage or disruption to any computing resources or to the owner of any computing resources; or

(ii) intends to materially cause damage or disruption to any computing resources indirectly through another party's computing resources.


The last three alternatives (e.g., (b)-(d)) are very similar to crimes that are outlawed by Utah’s Criminal Code. Section 76-6-703 of the Utah Code makes it a crime to (i) access a computer without authorization and cause damage a computer, software or data, (ii) use a computer to execute a scheme to defraud and (iii) use a computer to interrupt computer services to someone authorized to receive them. So to a great extent, the UUCA pulls these basic computer crimes into its definition of cyber-terrorism as that term is used in the unfair competition statute.


I’m not sure why Utah did that and/or did it the way they did. If the Utah legislators wanted to incorporate computer crimes into the UUCA (as cyber-terrorism or whatever), it seems they could have cross-referenced the computer crimes sections of the Criminal Code in the UUCA, with any additions or modifications they thought appropriate. That, though, is a peripheral issue. Let’s get back to the cyber-terrorism claim.


Clear Link moved to dismiss the unfair competition claim. That claim, again, was based on Margae’s contention that “Clear Link's unauthorized use of its web pages lead to the diminution of those web pages' value because Margae was deprived of the commissions it was owed from their use.” Margae, Inc. v. Clear Link Technologies, LLC, supra. Clear Link argued that “this allegation does not state a claim for `cyber terrorism’ because the `program, code or command’ sent by a defendant must be different than the target `intellectual property.’” Margae, Inc. v. Clear Link Technologies, LLC, supra.


Clear Link won. The federal judge found that the UUCA

clearly requires that the transmitted `program, code or command’ must be different from the damaged `intellectual property.’ That is, by using the term `cyber terrorism,’ the legislature signaled that it meant to cover only a situation where the `program, code or command’ was the tool for an attack and the `intellectual property’ was the target of an attack. Had the legislature wanted to define `cyber terrorism’ as the unauthorized use of intellectual property, it could have easily done so.

Margae, Inc. v. Clear Link Technologies, LLC, supra. The judge noted, however, that Margae might still be able to save the claim:

Margae has argued that Clear Link's actions meet the definition of `cyber terrorism’ because Clear Link's unauthorized use of Margae's Clear Link-related web pages damages the value of Margae's non-Clear Link web pages and web sites. The court will not consider this argument, because it is not tied to any express allegation Margae made in its complaint. . . . Margae may amend its complaint to make this factual allegation clear and Clear Link is free to challenge whether such an allegation meets the definition of `cyber terrorism.’

Margae, Inc. v. Clear Link Technologies, LLC, supra.


Several things about the UUCA’s cyber-terrorism provision mystify me. First of all, as far as I can tell no other state creates a civil cause of action for victims of cyber-terrorism, regardless of who commits it or the type of injury it inflicts. I don’t think federal law does this, either. I don’t think civil liability has ever been seriously floated as a way to deal with terrorists; the U.S. certainly hasn’t sued Al Qaeda for the damage to the Pentagon and the Twin Towers and the loss of life in all the 911 attacks.


I discovered, though, that the Utah Code includes provisions that can require a terrorist to pay reparations to his victim(s). Section 63M-7-502(9)(b) defines “criminally injurious conduct” as including actions that cause or pose a substantial risk of bodily injury or death or an act of terrorism as defined in the federal terrorism statute, 18 U.S. Code § 2331, that is committed outside the U.S. against a Utah citizen. A subsequent provision of the state’s Crime Victims’ Reparations Act, § 63M-7-511, allows victims of terrorism to receive reparations for medical expenses, lost wages and other losses. So Utah has apparently decided to let victims of international terrorism and victims of unfair-competition-as-cyber-terrorism recover civilly.


Another thing that perplexes me is Utah’s styling the alternatives in § 13-5a-102(2) as “cyber-terrorism.” The first one, § 13-5a-102(2)(a), looks like a terrorism provision because it refers to using computing resources to intimidate or coerce others. As I noted in an earlier post, the generic definition of terrorism is that it consists of using force (of whatever type) to coerce or intimidate civilians in order to further a political agenda. The Utah statute has the “coerce or intimidate” element, but the focus of the coercion and/or intimidation is unfair competition.


Finally, what surprises me, given the effort the Utah legislature apparently put into creating a civil cause of action for cyber-terrorism-as-unfair-competition is that the state doesn’t seem to have a criminal cyber-terrorism provision. The “coerce or intimidate” option doesn’t appear in the state’s general cybercrime statute, and I can’t find a Utah statute that makes terrorism and/or cyber-terrorism a crime.


Unless I’m missing something, then, it looks like Utah’s decided to create civil remedies for victims of terrorism/cyberterrorism, but hasn’t actually criminalized either.

Thursday, August 20, 2009

Cyberbullying??

Fox and some other news sites are reporting that a Missouri woman has been charged with “cyberbullying” in violation of the statute that was adopted after Megan Meier’s suicide.


According to the Fox story, 40-year-old Elizabeth Thrasher posted a 17-year-old girl’s picture, email address and cell phone number on the “Casual Encounters” of Craigslist “in a posting that suggested the girl was seeking a sexual encounter.” According to Fox, the girl contacted police after she received “lewd messages and photographs from men she didn’t know”.


Why, you ask, did Thrasher do this? According to Fox (again), the girl is the daughter of Thrasher’s ex-husband’s girlfriend and Thrasher and the girlfriend had been arguing. The Fox story says this resulted in some “back-and-forth bickering on MySpace among all three”, which apparently resulted in Thrasher’s doing the Craigslist posting. If convicted, Thrasher could face up to 4 years in prison or up to a year in county jail and a $5,000 fine, again according to Fox.


The Smoking Gun has the probable cause statement that accompanied the criminal complaint (also on the Smoking Gun) filed against Thrasher. The complaint charges Thrasher with the


class D Felony of harassment . . . in that on or about May 1, 2009, in the County of St. Charles, State of Missouri, the defendant with the purpose to cause emotional distress to D.P., a person who is 17 years of age or younger, and who did thereby cause D.P. emotional distress by anonymously creating personal information of D.P. on Craigslist, and the defendant was 21 years of age or older.


Complaint, State v. Thrasher, OCA # 09-2394 (St. Charles County Circuit Court 2009).


I don’t know why the charge in this case is being referred to – by Fox and other sites – as “cyberbullying.” As the quote above indicates, Thrasher is really charged with felony harassment in violation of § 565.090 of the Missouri Statutes.


Section 565.090 was amended after the Megan Meier case to expand the scope of its prohibitions. The statute was expanded to encompass electronic communications and to add the felony offense with which Ms. Thrasher has been charged. Under the revised statute knowingly communicating with “another person who is . . . seventeen years of age or young” and “without good cause” recklessly frightening, intimidating or causing emotional distress to that person is a class A misdemeanor unless the person doing the communicating is 21 or older . . . as is Ms. Thrasher.


I only have two comments on this case: One is that it aggravates me when conduct like this is referred to as “cyberbullying.” As I noted in an earlier post, if we’re going to use that term I think we need to define it with some precision and, I’d suggest, limits its use to conduct by a juvenile that’s directed at another juvenile. As I noted in that post, I don’t see why we need to use cyberbullying for adult-on-adult or adult-on-almost adult conduct when such conduct can be referred to, and prosecuted as, harassment or stalking.


My other comment is that if I were Thrasher’s defense attorney I’d consider filing a motion to dismiss the charges. As I noted above, the statute Thrasher is charged with predicated liability for harassment on the perpetrator’s (Thrasher’s) “communicating with the victim. I’d argue that Thrasher did not “communicate with” the 17 year old; Thrasher “communicated with” the pool of people who frequent the Casual Encounters section of Craigslist. I’d therefore argue that an essential element of the crime is missing, and the complaint should be dismissed.



Wednesday, August 19, 2009

Sneaking and Peeking

In a post I did last year, I noted that federal law allows the issuance of “sneak and peek” search” warrants. This post examines the use of a “sneak and peek” in a particular cybercrime case. Before I get to that case, though, I need to explain what “sneak and peek” warrants are and how they differ from traditional search warrants.


In the federal system, regular search warrants are governed by Rule 41 of the Federal Rules of Criminal Procedure. Rule 41(b)(1) says that at “the request of a federal law enforcement officer or an attorney for the government” a magistrate judge who has authority to issue warrants in that district can “issue a warrant to search for and seize a person or property located within the district”.


That provision contemplates the kind of searches and seizures officers have historically conducted: They go to a place, search for tangible evidence, seize it if they find it and leave a copy of the executed warrant and a receipt for the items the officers seized with “the person from whose premises” the property was taken. Rule 41(f)(1). (They can also leave the warrant and receipt on the premises if no one was there.)


Rule 41 warrants can be, and are, used to search for and obtain computer evidence. Rule 41(a)(2) defines the “property” that can be seized with such a warrant as including “documents, books, papers, any other tangible objects, and information.” So such a warrant can be used to seize computer hardware and/or data (“information”).


“Sneak and peek” warrants differ from regular Rule 41 warrants not in terms of how they are obtained (the officer still has to file an application for the warrant and an affidavit in support), but in terms of the kind of evidence they’re directed at and certain differences in the execution of the warrant. The PATRIOT Act amended § 3103a of Title 18 of the U.S. Code to accommodate “sneak and peek warrants,” which had been around for a while.


An early “sneak and peek” case is U.S. v. Johns, 851 F.2d 1131 (U.S. Court of Appeals for the Ninth Circuit 1988). In Johns, federal agents applied for a search warrant that would let them “surreptitiously enter” a commercial storage unit “to examine the contents without taking anything”. U.S. v. Johns, supra. They wanted to see what was in the unit but they didn’t want the owner to know law enforcement officers had been there. The court issued the warrant, the agents entered the storage unit and found chemicals used to manufacture methamphetamine, which resulted in Johns being indicted. U.S. v. Johns, supra. He moved to suppress the evidence, arguing that the “sneak and peek” warrant violated the 4th Amendment and Rule 41.


The Johns court followed the approach it had taken in U.S. v. Freitas, 800 F.2s 1451 (U.S. Court of Appeals for the Ninth Circuit 1986). The Freitas court, like later courts, found that a “sneak and peek” warrant violated Rule 41 because it didn’t require the agents executing to the warrant leave a copy of the warrant and a receipt for whatever was taken. (Back then, it was usually just visual observation and/or taking photos of whatever was in the place being searched).


The court also found, though, that the provisions of Rule 41 aren’t co-extensive with the requirements of the 4th Amendment; in other words, they’re narrower than the constitutional provision. According to most of the courts who considered “sneak and peek” warrants prior to the PATRIOT Act, the 4th Amendment is broad enough to encompass this kind of search for (and seizure of) intangible evidence. And I think that’s probably true; the 4th Amendment was created to address the traditional kind of searches and seizures but that doesn’t mean it can’t – and shouldn’t – be interpreted to apply to nontraditional searches and seizures.


To eliminate any concerns about the validity of “sneak and peek” warrants, Congress included a provision in the PATRIOT Act – codified as 18 U.S. Code § 3103a – that “specifically allow[s] officers to delay giving notice to the subject of a search if the court issuing the warrant `finds reasonable cause to believe that providing immediate notification of the execution of the warrant may have an adverse result.’” American Civil Liberties Union v. U.S. Dept. of Justice, 265 F.Supp.2d 20 (U.S. District Court for the District of Columbia 2003) (quoting the PATRIOT Act). The statute does require that the “sneak and peek” provide “for the giving of such notice within a reasonable period not to exceed 30 days after the date of its execution, or on a later date certain if the facts of the case justify a longer period of delay.” 18 U.S. Code § 3103a(b)(3).


That, then, is a brief history of “sneak and peek” warrants. As I noted in my prior post, in the Scarfo case, which arose in the 1990s, federal agents used a “sneak and peek” warrant to install a keystroke logger on a suspect’s office computer. So in that case, the focus wasn’t on simply sneaking in and peeking around, but on installing the logger so it would capture keystrokes typed on the keyboard. The purpose was to discover the key for an encrypted file on the computer; agents had used an earlier warrant to obtain a copy of the hard drive, which they searched without finding what they were looking for. The suspected the keystroke logger would record the key needed to access the file and, indeed, it eventually did.


Aside from the Scarfo case, I hadn't really seen any “sneak and peek” cases, at least not any reported cases. Recently, though, I found this one, which I had somehow overlooked: U.S. v. Hernandez, 2007 WL 2915856 (U.S. District Court for the Southern District of Florida 2007).


The case involved a DEA investigation into “Internet pharmacies, wherein customers order controlled substances prescriptions via the Internet”. U.S. v. Hermandez, supra. One of the pharmacies the DEA was investigating was RX Direct, Inc., which was then located in Deerfield, Florida. U.S. v. Hermandez, supra.


I won’t go into all the details of the investigation; I’ll just note that the agents involved made a number of undercover purchases of drugs from RX Direct, Inc. received evidence from citizens who had ordered drugs from the company and conducted an extensive investigation into its general operations. At that point, one of the agents – DEA Agent Richards – submitted an affidavit to a federal magistrate seeking a “sneak and peek” warrant for RX Direct, Inc. In outlining her probable cause for the warrant, she noted that based on her personal experience and that of other experienced agents,


information concerning the operation of Internet pharmacies routinely are stored in computer hardware and computer software. She . . . learned through her investigation that RX Direct dispensed prescription controlled substances pursuant to the electronic transmittal or prescription drug orders. Therefore, she believed that RX Direct stored information on computers which reflected the activity described in the affidavit.

Investigator Richards believed that the computers and computer media which would be found at the Deerfield location of RX Direct `are instrumentalities used to further, and contain evidence of, the dispensation of prescription controlled substances via the Internet where no legitimate physician/patient relationship was established.’


U.S. v. Hernandez, supra. Agent Richards reported that the owner of RX Direct had said he intended to move RX Direct to a new location, and it was not clear if the records would be relocated, as well. She then asked that the warrant be a “sneak and peek” warrant:


[B]ecause there is an ongoing undercover investigation of the subjects of this investigation, it would be detrimental to the investigation for an overt search warrant to be executed during normal business hours at this time. The overt execution of a search warrant at this time may result in endangering the life or physical safety of the CS; may result in the subjects . . . fleeing from prosecution before the investigation is complete; may result in the subjects destroying or tampering with evidence at as yet unidentified locations; and would likely seriously jeopardize the potential success of the undercover investigation by alerting the subjects to the existence of law enforcement scrutiny.


U.S. v. Hernandez, supra. Richards asked “permission to execute the warrant in a surreptitious fashion after the close of business and continuing during the hours of 10:00 p.m. and 6:00 a.m. so that the owners/operators of RX Direct would be unaware of the execution”. The court issued the warrant and allowed the agents to delay providing notice of the execution of the warrant for 30 days. U.S. v. Hernandez, supra. When they executed the warrant, the agents copied the data on the company’s hard drives.


The investigation continued, and eventually resulted in the indictment of individuals involved with RX Direct, Inc. One of them moved to suppress evidence, arguing that the “sneak and peek” warrant was invalid because it authorized the agents to copy data. He said “with most `sneak and peek’ warrants, no evidence is seized.” U.S. v. Hernandez, supra. I’m not sure that’s literally true: As I noted earlier, prior to the PATRIOT Act, officers executing “sneak and peek” warrants would go into a place -- a home or office or storage unit – and look around . . . and often to take photography or videotape what they saw. When they photographed and videotaped what they saw, they were in a sense “seizing” evidence, though not in the tangible, literal sense.


As I noted above, Rule 41 allows officers executing a search warrant – which includes a “sneak and peek” warrant – to seize “information.” I’d argue that even in the non-computer “sneak and peek” warrant cases the officers were, at least in a sense “seizing” information. In other words, they came away knowing something they didn’t prior to the search; we could say their simply learning that information was a seizure of evidence, but that might be a little difficult to defend. It seems to me, though, that if they recorded what they saw, they did in fact “seize” evidence in the form of information.


The Hernandez court quickly dismissed the argument about seizing evidence: “[T]he defendant cites no case which precludes the copying of records during the execution of a search warrant”. I suspect there is no case like that because copying documents has traditionally been part of executing warrants for paper records. I’m not sure if this “sneak and peek” warrant specifically authorized copying the data, which I think would probably have been a good idea. In denying the motion to suppress, the court also noted that the government was not planning to introduce evidence derived from the copying of the hard drives during the execution of the “sneak and peek” warrant at trial, so there was “no basis to suppress any evidence as the result of the copying of the computer hard drives.”

Monday, August 17, 2009

Miranda and the Fifth Amendment Bummer

This is a follow-up to a comment on a post I did earlier this year.


More precisely, this is a follow-up to Jeremy R. Fishman’s comment on my 5th Amendment Bummer post.


In that post, which updated an earlier post on the Boucher case, I explained that a federal judge had held that Boucher couldn't take the 5th Amendment privilege against self-incrimination as the basis for refusing to surrender the key needed to access his encrypted hard drive.


In his comment, Jeremy raised the issue of Boucher’s being “in custody” which, as I noted in a reply comment, gets us into a different standard – the Miranda rules. Since it’s only logical to assume Miranda comes up when someone is being detained by law enforcement and is asked to do something, I thought I’d do a post parsing the extent to which the Miranda rules do, and do not, apply in this situation.


I can’t find any cases in which Miranda’s applicability to a Boucher-style scenario has come up, so I’m going to use a hypothetical to analyze the issues. We’ll essentially assume the facts in the Boucher case: John Doe arrives at the O-Hare airport on a flight from London; as he goes through Customs, he’s flagged for secondary (more intensive) screening. Doe’s carrying a laptop. The Customs officer takes the laptop and turns it on; it boots up, and the officer tries to examine the contents of the laptop, but can only see part of the files it contains. As in the Boucher case, part of the hard drive has been partitioned as Drive Z; the partitioned drive is encrypted, so the Customs officer can’t access the files it contains.


Let’s assume that when the Customs officer looked at the files on the unencrypted part of the hard drive he developed reasonable suspicion to believe that Drive Z contained child pornography. Reasonable suspicion, as Wikipedia explains, is a lower standard than probable cause; reasonable suspicion lets the Customs officer detain John Doe for a reasonable period of time while the officer tries to confirm, or disconfirm, his belief that Doe’s laptop contains child pornography.


If the officer had probable cause to believe the laptop contained child pornography, he could (i) arrest Doe and/or (ii) get a warrant to search the contents of the laptop. I’m not assuming probable cause because I don’t think the circumstances outlined above can support probable cause and because probable cause wouldn’t alter the Miranda analysis we’re about to pursue.


As long as Doe is in “custody” – as long as he is either under arrest or his freedom of movement has been restrained in a fashion analogous to an arrest – he is entitled to the protections of Miranda. As Wikipedia explains, that means the officer must give Doe the Miranda warnings (right to remain silent, right to have an attorney present during any questioning, right to have an attorney appointed) and find out if Doe wants to waive the rights or invoke them. If Doe invokes the right to silence and/or the right to an attorney, the officer cannot ask him any questions; if Doe waives one and invokes the other right, the officer still cannot ask him any questions; the officer can only question Doe if Doe waives both the right to remain silent and the right to an attorney. Since the Miranda rules apply regardless of whether Doe has been arrested or is only being detained while the officer tries to determine if there is child pornography on the laptop, it doesn’t matter whether the officer has probable cause or not.


Probable cause is only relevant insofar as the officer might want to obtain a warrant to search the laptop. As I noted in my posts on the Boucher case, getting a warrant in this situation won’t help the officer pursue the child pornography inquiry because Drive Z is encrypted and law enforcement officers currently have no way of breaking encryption.


So, the Customs officer has reasonable suspicion to believe Doe is carrying a laptop that contains child pornography; as I’ve noted before, and as I assume everyone already knows, child pornography is contraband, i.e., is illegal in and of itself. Possession of child pornography is therefore a crime. The issue is whether Doe has child pornography on his laptop; the only way the officer can resolve that issue is by gaining access to the contents of Drive Z, and the only way he can gain access to the contents of Drive Z is by getting Doe to give him the encryption key for Drive Z.


In the Boucher case, the government did what I suspect it will typically do in cases like this: have a grand jury issue a subpoena to the person (Boucher or Doe) that orders him to surrender the encryption key to the grand jury. I suspect the government will use this procedure because, as I noted in my Boucher posts, a grand jury can compel someone to comply with its demands by locking them up until they do.


Law enforcement officers can’t do that. They can only ask the suspect to give them the encryption key, which brings us back to the alternative scenario we’re analyzing. If you recall where we were, the Customs officer has reasonable suspicion to believe there is child pornography on the laptop; the reasonable suspicion lets the Customs officer detain Doe for a “reasonable” period of time while the officer tries to (i) develop the probable cause he needs to arrest Doe and seize the laptop or (ii) decide he was wrong about the laptop’s containing child pornography.


The Customs officer has detained Doe, which means he’s in custody for the purpose of the Miranda rules. That means, as I noted earlier, that if the officer wants to ask Doe about the laptop, the encryption key or anything else (other than, say, if he wants a drink of water or to use a bathroom) he must (i) give Doe the Miranda warnings and (ii) get a valid waiver of the rights to silence and counsel from Doe. More precisely, under the Miranda rules, the officer cannot “interrogate” Doe unless he does both of these things. If he interrogates Doe without doing both of these things, he violates Miranda.


The Supreme Court has defined Miranda interrogation as words or actions by the police office that he should know are reasonably likely to elicit an incriminating response from the suspect. Rhode Island v. Innis, 446 U.S. 291 (1980). We’ll make the interrogation analysis really simple here; we’ll assume the Customs officer asks Doe to give him the encryption key for Drive Z. Asking someone a direct question constitutes interrogation under the Innis standard, so we have to decide what the consequences of the officer’s asking this question are, under Miranda.


If the officer asks Doe this question (i) without giving Doe the Miranda warning or (ii) after he has given the warnings and Doe has invoked his rights to silence and/or an attorney, the officer has violated the Miranda rules. If the officer asks the question after he has given Doe his Miranda rights and after Doe waived both the right to silence and the right to an attorney, then asking the question doesn’t violate Miranda.


Let’s consider what happens if the officer violates the Miranda rules by asking Doe for the encryption key and Doe answers the question, i.e., gives the officer the encryption key. (Asking the question without giving the warnings and getting a waiver would still violate Miranda, but we wouldn’t have any evidence to suppress.) In other words, Doe says something like, "OK, I'll give you the key to my hard drive. The key is ______________." (We're assuming, for the purposes of analysis, that Doe has committed the key to memory; I think the analysis will be pretty much the same even if he has to retrieve a key he's written down or is stored in something.)


In U.S. v. Patane, 542 U.S. 630 (2004), the U.S. Supreme Court held that a violation of Miranda (i) requires the suppression of statements (testimony) made by the suspect but (ii) does not require the suppression of physical evidence law enforcement obtains as a result of the suspect’s statements. In the Patane case, and in a number of other cases, the Court explained that the Miranda rules are not constitutional rules themselves and are not co-extensive with the 5th Amendment privilege against self-incrimination; they are, instead, a fabrication, a set of prophylactic rules the U.S. Supreme Court created to control what police officers can do when they are interrogating a suspect. In the Patane case, and other cases, the Court has held that the policy which justified imposing the Miranda rules on police interrogations does not require the suppression of evidence other than statements elicited in violation of the Miranda rules.


Where does that leave us? Well, to some extent it brings us back to the 5th Amendment analysis I applied in my Boucher posts. What happens if Doe answers the question and gives the officer his encryption key? Is the encryption key a statement (“testimony”) that must be suppressed because the officer violated Miranda? Or is it physical evidence the officer obtains as the result of a statement that violated Miranda? In other words, can the prosecution argue that (i) it can’t use the statements Doe made in the course of giving the encryption key to the Customs officer but (ii) can use the key itself because it is physical evidence, not testimony?


If the prosecution were to make such an argument, I strongly suspect that Doe’s attorney would respond with an argument along the lines of the act-of-producing-evidence-as-testimony analysis I outlined in my Boucher posts. That is, I suspect Doe’s attorney would argue that it is impossible to sever Doe’s statements from his act of giving the government the encryption key because both constitute “testimony” under the Fisher analysis I outlined in my Boucher posts.


If you look at the 5th Amendment bummer post, you’ll see what I mean; the U.S. Supreme Court has held that in certain circumstances the act of producing physical evidence to the government is itself “testimony” that is protected by the 5th Amendment privilege against self-incrimination; and since the fabricated Miranda rules are somehow based on the 5th Amendment privilege, I think the act-of-producing-evidence-as-testimony principle has to apply in a Miranda analysis as well as under a 5th Amendment analysis. If I’m right, then we pretty much have the same issues to resolve regardless of whether the Customs officer interrogates Doe in violation of Miranda or whether Doe is subpoenaed by a grand jury.


If, of course, Doe gives the Customs officer the encryption key after having been given the Miranda warnings and voluntarily waiving his rights to silence and to an attorney, then he’s probably out of luck.

Sunday, August 16, 2009

Hacking a Heart - Updated

Last year, I did a post that dealt with what could be a new way to commit murder.


In it, I explained that researchers were able to use wireless signals to turn off a pacemaker.


I also explained that if someone used this technology to shut off a pacemaker for the purpose of killing the person who had it, the person who shut down the pacemaker could be prosecuted for murder under existing law. In other words, the essence of murder (or any homicide crime) is that you cause the death of another human being; we don’t concern ourselves particularly with how you caused the death, though, of course, that has to be proved at trial for the prosecution to obtain a conviction.


Looks like hacking a heart just got a lot easier. When I did the post last year, the technology used to shut off the pacemaker was expensive and could only be used if you were pretty close to the person who had the pacemaker.


That apparently isn’t true anymore. According to this story, a woman recently received a pacemaker that has a wireless connection to the Internet. The story says she’s the first American to receive such a pacemaker, implies that people in elsewhere have them; I couldn’t, though, find any mention of whether that’s true or not . . . and it’s not relevant to my point, anyway.


The story says her doctor can use the Internet to monitor her pacemaker. It also says that the pacemaker sends information to the doctor at least once a day and will alert him if things start to go wrong with it. All of that information travels over the Internet, which presumably means it can be hacked. I didn’t see any mention of encrypting the date in this story, but maybe they’re doing that. I hope so.



Friday, August 14, 2009

Lack of Expert Witness in Child Pornography Case


This post is about a federal judge’s ruling on a habeas petition filed by Luis Rodriguez, who was convicted of receiving and possessing child pornography in violation of federal law. As Wikipedia explains, the writ of habeas corpus is “a civil . . . proceeding in which a court inquires as to the legitimacy of a prisoner’s custody.” Someone like Rodriguez, who has been convicted of a crime, can use a habeas petition to challenge the conviction.


And that is precisely what Rodriguez did. He moved for a new trial, relying on the “declaration of an expert witness, David R. Penrod. . . . According to Mr. Penrod, there is no evidence that Mr. Rodriguez `downloaded,’ `possessed,’ or `saw’ the thumbnail images containing child pornography on Mr. Rodriguez’s computer.” U.S. v. Rodriguez, 2009 WL 1809975 (U.S. District Court for the Eastern District of California 2009). Here’s an excerpt from the declaration:


Microsoft Windows Internet Explorer automatically downloads all thumbnail graphic image files found on every website visited by the user into the user's Internet History cache. This download occurs without the knowledge of the user. All graphic images on every visited website are downloaded, including images not seen by the user, which can amount to thousands of images.

There are twelve-thousand thirty-eight . . . thumbnail images containing pornography in the Internet History cache within Mr. Rodriguez's User Profile. These files were automatically downloaded by Internet explorer without the knowledge of Mr. Rodriguez. In other words, they were not downloaded by Mr. Rodriguez. . . . [T]he government claims that fifty-one of these thumbnail images contain child pornography and that somehow Mr. Rodriguez `possessed’ them. . . . There is no evidence . . . to prove that Mr. Rodriguez ever viewed any of these images. . . . There is simply no means available to prove a user `saw' a particular thumbnail image.

U.S. v. Rodriguez, supra. Penrod also said “`at least two (2) other users, both of who have separate User Profiles on Mr. Rodriguez's work computer and containers in the recycle Bin, downloaded and accessed . . child pornography.’” U.S. v. Rodriguez, supra.


Rodriguez based his habeas petition on the claim that he received ineffective assistance of counsel because his attorney did not utilize a computer forensics expert in preparing for trial. To support his claim, he relied on Penrod’s declaration and on a declaration from a private investigator who interviewed Rodriguez’s trial counsel after he had been convicted. According to the private investigator’s declaration, Rodriguez’s trial lawyer said he believed it wasn’t necessary to use a defense computer forensics expert; the lawyer also told the private investigator he though that if he’d asked to for an expert, one would have been provided. U.S. v. Rodriquez, supra.


In ruling on the ineffective assistance of counsel claim, the federal judge assigned to Rodriguez’s case began by noting that in evaluating such a claim a court must consider two factors: One is “whether the counsel's performance fell below an objective standard of reasonableness considering all of the circumstances”; the other is whether the party seeking a new trial “has affirmatively proven prejudice.” Strickland v. Washington, 466 U.S. 668, 687 (1984).

As to the first Strickland factor, Mr. Rodriguez argues that his trial counsel's failure to call expert witnesses in the instant case, `where the prosecution's case hinged almost exclusively on expert testimony . . .constituted `per se ineffective assistance of counsel.’. . . [T]he government argues that the trial counsel's decision not to retain experts and present expert testimony at trial was `a decision well within trial counsel's discretion.’

Rodriguez argues that the second Strickland factor is satisfied, because had his trial counsel retained a computer expert witness, the outcome would have been different. The government argues that Mr. Rodriguez cannot succeed on his ineffective assistance of counsel claim, because there was abundant evidence upon which the jury could have based its verdict, even if expert testimony had been presented.

U.S. v. Rodriguez, supra.


The federal judge explained that he could consider the factors in reverse order: “Since it is necessary to prove prejudice, any deficiency that does not result in prejudice must necessarily fail.” U.S. v. Rodriguez, supra. The judge found Rodriguez could not “show that there is a reasonable probability that but for counsel's unprofessional errors the result of the proceeding would have been different.” U.S. v. Rodriguez, supra.

The government presented abundant evidence upon which the jury could have based its verdicts, including: Mr. Rodriguez worked in a laboratory and worked on a computer that had multiple users. Other users, but never Mr. Rodriguez, complained about continual pop-up images of pornography on the work computer. When the information technology specialist at the work site attempted to solve the problem, he discovered images of naked children and contacted law enforcement. When a law enforcement officer questioned Mr. Rodriguez, he appeared nervous and evasive, and he claimed not to remember his password.
Mr. Rodriguez also stated that he never shared his password with anyone. Mr. Rodriguez denied he had a working computer at his residence. Even though Mr. Rodriguez's supervisor told the law enforcement officer that Mr. Rodriguez rarely went home for lunch, Mr. Rodriguez ended the interview and went home before his normal lunch hour. Once home, Mr. Rodriguez removed the hard drive from his computer and broke several compact discs, some labeled `teen’ or apparently `preteen.’ He placed handwritten URLs of pornography website into vehicles on the property. He placed a large amount of stories detailing incest and sexual activities between adults and children into a barrel and started to burn them.
The government contended that Mr. Rodriguez also placed sexually explicit images of children into the same burning barrel and attempted to destroy that evidence, as well. All other employees who had access to the computer on which the child pornography was stored testified under oath at trial and denied looking at or downloading any pornography. Most of those witnesses complained about images of pornography that kept appearing on the computer. The pornographic images were located in a folder with Mr. Rodriguez's initials-LCR-and were organized in specific folders. One folder was labeled `Young Teens.’ Moreover, the internet activity of the person logged in under the username `LCR’ with the unique password assigned to Mr. Rodriguez demonstrated that person would access a website related to one of the insects on which Mr. Rodriguez helped to research and then minutes later that person would place an image into the `Young Teens’ folder.

U.S. v. Rodriguez, supra.


The judge found that Rodriguez could not show the jury would have reached a different verdict “even if a computer forensics expert . . .had testified at trial.” U.S. v. Rodriguez, supra. He noted that Penrod “opined” that there were

three (3) possible interpretations of this evidence [that others had access to the work computer]:

1) That two other persons downloaded pornography onto the work computer in addition to Mr. Rodriguez;

2) That Mr. Rodriguez downloaded all of the pornography and was able to access other User Profiles to do so;

3) Those other users, not Mr. Rodriguez, downloaded all or some of the pornography and were able to access Mr. Rodriguez's User Profile to do so.

U.S. v. Rodriguez, supra. The judge didn’t find that this helped Rodriguez’s argument:

Penrod suggests by his own analysis that in two of three scenarios, Rodriguez is the person responsible for putting the child pornography into folders on the work computer. Moreover, the government points out several inconsistencies in Penrod's declaration and provides evidence by declaration that contradict [his] assertions. In addition, Penrod's opinion does not address the evidence supporting Rodriguez's possession of child pornography at his home. . . . [T]he only scenario in which Penrod suggests Rodriguez to be not guilty of the charges is contradicted by Rodriguez's own statement that he never shared his computer password. For these reasons, Rodriguez's expert witness testimony presents no unequivocal evidence that would have caused a different result. The evidence presented at trial supported the jury verdict, even if computer forensics expert Penrod had testified at trial.

U.S. v. Rodriguez, supra. The court therefore denied Rodriguez’s habeas petition.


Since the U.S. Court of Appeals for the Ninth Circuit had already rejected his arguments – in a direct appeal from his conviction – that the evidence should have been suppressed and he should be given a new trial, this put an end to Rodriguez’s options for challenging his conviction. After he was convicted in 2006, the court sentenced him to serve 135 months in federal prison, which I assume is what he is still doing.