Friday, October 15, 2010

Source Code, Economic Espionage and Transporting Stolen Property

On February 11, 2010, Sergey Aleynikov was indicted on three counts of violating federal criminal law: theft of trade secrets in violation of 18 U.S. Code § 1832(a)(2); transporting stolen property in violation of 18 U.S. Code § 2314; and unauthorized access to a computer system in violation of 18 U.S. Code § 1030(a). U.S. v. Aleynikov, __ F.Supp.2d __, 2010 WL 3489383 (U.S. District Court for the Southern District of New York). He moved to dismiss all three counts, arguing that each was, in its own way, legally inadequate. U.S. v. Aleynikov, supra.


Aleynikov succeeded in getting the third count dismissed, but was unable to persuade the court to dismiss the first two counts. U.S. v. Aleynikov, supra. In this post, I’m going to focus on Aleynikov’s arguments as to the first two counts, the government’s response and the court’s ruling on those issues. I’m not going to address the § 1030 count for two reasons: One is to keep this post relatively short; the other is that I’ve written more about § 1030 crimes than about the crimes at issue in the first two counts. If you’d like to read more about this case, check out the Wikipedia entry on Sergey Aleynikov.


According to this opinion, this is how the case against Aleynikov arose:


Goldman Sachs & Co. is a global financial services firm engaged in high-frequency trading on securities and commodities markets. . . . Aleynikov was a computer programmer employed by Goldman as a Vice President in its Equities Division from May 2007 until June 2009. . . . . [He] was responsible for developing and maintaining some of the computer programs used to operate Goldman's high-frequency trading system. Aleynikov resigned . . . to work for Teza Technologies, LLC. . . . [as] `Executive Vice President, Platform Engineering,’. . . responsible for developing Teza's own high-frequency trading business that would compete with Goldman.


High-frequency trading . . . involves the rapid execution of high volumes of trades in which trading decisions are made by sophisticated computer programs that use complex mathematical formulae known as algorithms. The algorithms use statistical analyses of past trades and current market developments. Goldman used a proprietary system . . . [called] the `Platform,’ to rapidly obtain information on the latest market movements, process that information into a form that can be analyzed by the algorithms, and execute the trading decisions reached by the application of the algorithms to that information. Together, the trading algorithms and Platform comprise Goldman's trading system (the `Trading System’).


Goldman acquired portions of the Platform when it purchased the Hull Trading Company in 1999. . . . . Goldman's computer programmers have developed and modified the computer programs Goldman uses in its Trading System by writing and altering their source code. Goldman has not licensed its Trading System or made it or its components available to the public, and has taken measures to protect [its] source code. . . .

Aleynikov was a member of a team of programmers responsible for developing and improving aspects of the Platform. . . . On his last day of employment at Goldman, Aleynikov copied, compressed, encrypted, and transferred to an outside server in Germany hundreds of thousands of lines of source code for the Trading System. . . . After transferring the source code to the German server, Aleynikov deleted the program he used to encrypt the files. He also deleted his `bash history,’ i.e., the history of his most recent computer commands. . . . [I]n the days that followed, Aleynikov accessed the German server and downloaded the source code to his home computer, and from there to other home computers and to a portable flash drive. . . .


Aleynikov [then] flew to Chicago . . .to meet with Teza. He brought a laptop and the flash drive containing source code for Goldman's Trading System. . . .


U.S. v. Aleynikov, supra.


Based on all this, Count I of the indictment charged Aleynikov with violating 18 U.S. Code § 1832(a)(2), which makes it a crime for one acting with the “intent to convert a trade secret, that is related to or included in a product that is produced for or placed in interstate or foreign commerce, to the economic benefit of anyone other than the owner thereof” to copy, duplicate, deliver, transmit or otherwise convey such information without being authorized to do so. Aleynikov moved to dismiss this count because he argued that it did not allege that the source code for Goldman’s Trading System is


related to or included in a `product’ that is `produced for or placed in interstate and foreign commerce.’ According to Aleynikov, a `product,' as used in [§ 1832(a)] must be a tangible item of personal property distributed to and used by the commercial public. Because Goldman has never licensed or sold the Trading System, and has no intention of doing so, Aleynikov contends that the Trading System is not a `product produced for or placed in' commerce within the meaning of § 1832. [He] does not dispute that the trade secret he allegedly stole is `related to or included in’ the Trading System.


U.S. v. Aleynikov, supra. The government argued that the Trading system is, in fact,


a `product’ . . . that has an `obvious and indisputable connection’ to interstate and foreign commerce. The Government thus agrees with Aleynikov that the trade secret at issue in Count One is the source code, and the relevant `product’ is the Trading System. . . . [T]he Government . . . expects to prove at trial that there are high-frequency trading systems that may be purchased by securities trading firms, and that Goldman maintains computers in the United States and elsewhere in the world that use its Trading System to conduct trading on world markets.


U.S. v. Aleynikov, supra. The judge found, first, that the Economic Espionage Act (EEA), of which § 1832 is a part, doesn’t define the term “product,” which means the court was required to give the term its “`ordinary meaning.” U.S. v. Aleynikov, supra (quoting U.S. v. Santos, 553 U.S. 507 (2008)). The judge found there was no doubt


that the Trading System is a `product’ within the meaning of the EEA. [It] is `comprised of different computer programs’. . . . The only difference between the Trading System and other computer software, like Microsoft Windows, is that Goldman does not presently intend to sell or license the Trading System. This . . .does not, however, render the Trading System any less of a `product’ within the meaning of the EEA.


Likewise, it is clear that the Trading System was `produced for’ interstate commerce. . . . [T]he sole purpose for which Goldman purchased, developed, and modified the computer programs that comprise the Trading System was to engage in interstate and foreign commerce. . . . Goldman's high-frequency trading activity, which is uniquely made possible by the Trading System, undoubtedly qualifies as interstate and foreign commerce. As such, the Trading System was `produced for’ interstate and foreign commerce within the meaning of the EEA.


U.S. v. Aleynikov, supra. She therefore denied Aleynikov’s motion to dismiss Count I. U.S. v. Aleynikov, supra.


Count II charged him with transporting stolen property in violation of 18 U.S. Code § 2314, which makes it a crime to transport, transmit or transfer in interstate or foreign commerce “any goods, wares, merchandise, securities or money, of the value of $5,00 or more” knowing that they have been “stolen, converted or taken by fraud”. Aleynikov argued that the source code he was charged with transporting and transmitting was not “goods, wares, merchandise, securities or money.” U.S. v. Aleynikov, supra. He also argued that § 2314 “only to tangible items, and not to the theft of intangibles, such as the trade secrets embodied in the Trading System's source code.” U.S. v. Aleynikov, supra.


In ruling on Aleynikov’s motion to dismiss this count, the judge noted that while § 2314 does not define “goods, wares [or] merchandise,” the U.S. Court of Appeals for the 2d Circuit has held that these terms are to be interpreted “broadly,” to encompass “`a general and comprehensive designation of such personal property or chattels as are ordinarily a subject of commerce.’” In re Vericker, 446 F.2d 244 (1971) (quoting U.S. v. Seagraves, 265 F.2d 876 (U.S. Court of Appeals for the 3d Circuit 1959)). The judge also noted that courts in the Southern District of New York have held that § 2314 applies to “confidential business information for which a market . . . exists.” U.S. v. Aleynikov, supra. Based on these and other considerations, the judge held that the source code


constitutes `goods' for purposes of § 2314. The source code . . . contains highly confidential trade secrets related to the Trading System. . . . Goldman paid approximately $500 million for components of the Platform when it purchased Hull. In addition, the Government has proffered that the source code would be valuable for any firm seeking to launch, or enhance, a high-frequency trading business. Accordingly, the source code may be viewed as `ordinarily a subject of commerce.’


U.S. v. Aleynikov, supra. The judge also rejected Aleynikov’s argument that § 2314 only applies to “tangible” goods. She found, first, that § 2314 does not distinguish between tangible and intangible goods; she also found that it would be absurd to hold that § 2314 applies to someone who transports hard copy of source code in interstate commerce but not to someone who transports the code in digital form. U.S. v. Aleynikov, supra. She also pointed out that, in an aside, the Supreme Court noted in Dowling v. U.S., 473 U.S. 207 (1985), that for the purposes of applying § 2314 it did not “`matter that the [stolen] item owes a major portion of its value to an intangible component.’” U.S. v. Aleynikov, supra (quoting U.S. v. Dowling with added emphasis).


For these and other reasons, she denied Aleynikov’s motion to dismiss Count II. U.S. v. Aleynikov, supra. So, absent some unexpected development, it looks like the case is going to trial.

Wednesday, October 13, 2010

ShreazaLE and the 4th Amendment

This post is about a recent case in which a defendant who was using peer-to-peer file-sharing software to share images of child pornography. More precisely, it’s about the defendant’s argument that law enforcement’s use of a particular software program – ShreazaLE – violated his rights under the 4th Amendment.


As I’ve explained in several earlier posts, courts have – so far, anyway – consistently held that one who uses P2P file-sharing software to download and/or distribute child pornography (or, presumably, any other contraband) does so at their own risk, as far as becoming the focus of a law enforcement investigation is concerned. As I’ve noted, courts have rejected defendants’ claims that an officer’s using file-sharing software to download child pornography from a defendant’s computer constitutes a “search” under the 4th Amendment, which would mean the officer would have to obtain a search warrant (or be able to invoke a valid exception to the warrant requirement) for the downloading to be lawful under the 4th Amendment.


The case this post is about shares many of the same characteristics as the cases I’ve written about earlier, but has one distinguishing aspect. The case is U.S. v. Gabel, 2010 WL 3927697 (U.S. District Court for the Southern District of Florida 2010), and this is how it arose:


On April 29 [and May 3], 2010, Detective Joe Vella of the Broward County Sheriff's Office discovered an internet user was sharing files over a peer-to-peer (P2P) file-sharing network called Gnutella. All Gnutella peers have a `shared folder’ on their computer. This folder's contents are available for search and download to all other peers logged onto the network at a given time. . . .


On April 29, Vella . . . logged onto Gnutella . . . [and discovered Gabel’s IP address was offering child pornography files for distribution]. . . .
[After confirming that Gabel was offering child pornography,] Vella contacted [Donald] Cannon, who works in the Child Predator Cybercrime Unit of the Florida Attorney General's Office. . . . Cannon had independently determined that Gabel's IP address was sharing . . . images of child pornography and was preparing to obtain a search warrant. . . . Using publically available data, Cannon determined that Gabel's IP address was assigned to Comcast Cable Communications. Cannon subpoenaed from Comcast the physical address where the computer using the IP address was located, which was a residence in Weston, Florida.


U.S. v. Gabel, supra. A judge issued the search warrant Cannon later applied for and it was executed at Gabel’s residence on May 7, 2010. U.S. v. Gabel, supra. The officers found child pornography on Gabel’s computer, and he also confessed to using Limewire to download child pornography. U.S. v. Gabel, supra. On June 8, 2010, Gabel was indicted for violating 18 U.S. Code § 2252 by knowingly accessing and possessing with intent to view child pornography. U.S. v. Gabel, supra.


Gabel then filed a motion to suppress the evidence “gathered during warrantless searches of his computer files”, the evidence found at his home and his confession. U.S. v. Gabel, supra. We’re not concerned with the last two issues, only with the first one.


Gabel’s motion to suppress the evidence Vella downloaded from his computer relied in large part on the software Gabel used to do so:


Vella logged on [to Guntella] using a program called ShreazaLE. . . . a law enforcement enhanced program. . . . ShreazaLE . . . organize[s] data and download[s] files in a manner that screens for child pornography and creates an evidentiary record. . . .


[W]hen a typical Gnutella peer wants to download a song or movie, he will usually do so by downloading from multiple users, which reduces download time. Although individual peers
can download a file solely from one other individual peer, ShreazaLE is automatically set to do so. In this way, law enforcement can confirm that a file containing images of illegal child pornography came from a single source. This assists law enforcement in proving that illegal images of child pornography came from a single source, rather than trying to prove which part of the image came from which source.


The `browse’ or `search’ function on Gnutella clients permits peers to view files being shared from a specific user and allows peers to choose among those files for download. Gnutella makes public to all peers the IP (internet protocol) addresses of all others peers. The IP address is a unique number assigned to everyone who logs onto the internet. It also makes available the `SHA-1’ values of the files available for download. A SHA-1 value, where information is given an arithmetic algorithm, is, in effect, a digital fingerprint specific to each computer file. Thus, while two users might title a file differently, the network is able to identify that the two files are the same for download purposes. Users searching for child pornography frequently search for files under code names, such as `pthc,’ which stands for `pre-teen, hard core.’


Keeping track of SHA-1 value is important to law enforcement investigating child pornography. Using a national database of `child notable’ images, which are images officers from around the country consider to be illegal child pornography in their jurisdiction, law enforcement can scan for files previously identified as containing child pornography without having to download and view them.


[When Vella logged into Gnutella on April 29, 1010 using ShreazaLE, he] saw Gabel's IP address was offering more than 1,000 files for distribution, and was able to determine that they likely contained child notable images because ShreazaLE cross-referenced their SHA-1 values. . . . Vella downloaded more than 100 child notable files from Gabel's shared folder on April 29 and again on May 3 . . .. Vella opened the files to verify they contained images of child pornography. . . .


U.S. v. Gabel, supra.


This brings us back to Gabel’s motion to suppress the images Vella downloaded from his computer. One thing is clear, and the rest isn’t. What’s clear is that Vella, like the other defendants I’ve written about who were charged with using file-sharing software to distribute or download child pornography, based his motion to suppress the downloaded images on the argument that Vella’s accessing his computer and downloading the images constituted a “search” under the 4th Amendment, one that was conducted without a valid search warrant or applicable exception to the warrant. If Gabel’s argument was correct, i.e., if what Vella did constituted a 4th Amendment “search,” the search would have been unlawful because it was not authorized either by a warrant or an exception to the warrant requirement.


As I’ve explained in other posts, the test courts use in deciding whether particular law enforcement conduct constituted a 4th Amendment “search” is the test the Supreme Court enunciated in U.S. v. Katz, 389 U.S. 347 (1967). The Katz Court held that one has a reasonable expectation of privacy in a place if both of two conditions are met: (i) He subjectively believes it is private; and (ii) society accepts his belief that the place is private as objectively reasonable. The Katz Court also noted that whatever someone “knowingly exposes to public view” isn’t private and therefore isn’t protected by the 4th Amendment.


As I’ve noted in earlier posts, other courts have rejected defendants’ claims that law enforcement’s downloading child pornography from their computers was a search when the defendant was using file-sharing software to distribute and/or download images of child pornography. Those courts have held, basically, that the defendant might have subjectively believed the contents of his hard drive were private, but that this isn’t an expectation society is prepared to accept as objectively reasonable. Courts have found that if you know you’re using file-sharing software, you know you’re opening at least some of the contents of your hard drive up to others, which means it’s objectively unreasonable for you to believe those files are “private.”


Here, though, I think Gabel is relying on the fact that Vella used special law enforcement software, software that had some features not found in generic file-sharing software. Not having access to the briefs in the case, I can’t be sure, but at one point in the opinion the federal judge refers to the Supreme Court’s decision in Kyllo v. U.S., 533 U.S. 27 (2001), which, as I explained in an earlier post, held that it is a “search” for officers to use technology that is not in general public use to obtain information from inside a home. I believe Gabel argued that Vella’s using ShreazaLE was a 4th Amendment search under Kyllo because the software was technology that is not in general public use and was employed to obtain information from inside Gabel’s home. I base that belief, in part, on this portion of the opinion:


Gabel [claims] he had a reasonable expectation that only those users logging on the Gnutella network in the usual manner would be able to view his files. Since law enforcement used enhanced programs unavailable to the public, which enabled them to target their search, more easily identify images of child pornography and create a log reflecting Gabel's file-sharing history, Gabel argues that their warrantless search violated the Fourth Amendment.


U.S. v. Gabel, supra. Gabel’s argument didn’t work. The judge didn’t find that this issue fell within the Kyllo holding given the relatively restricted capabilities of the software:


Although the enhanced law enforcement programs Vella and Cannon used allowed them to document and track IP addresses sharing child pornography, at no time before obtaining the subpoena and search warrant did they access information that was unavailable to any other Gnutella peer. Any member of the general public could have logged onto Gnutella and downloaded all of the files which Vella and Cannon downloaded in this case, and they could have determined the IP address sharing those files. Thus, the main difference between the law enforcement enhanced programs and the Gnutella client programs used by the public is that the law enforcement versions automatically document and save publically available information.


U.S. v. Gabel, supra. In denying Gabel’s motion to suppress the downloaded files, the judge also explained that Vella’s use of “enhanced” software


merely permitted law enforcement to more easily organize and classify information that was otherwise available to the public, which aided them in obtaining evidence to support a search warrant. Gabel had no reasonable expectation of privacy in his files. He was, essentially, sharing them with the entire world. Anyone with internet access could have easily downloaded Gnutella client software, logged onto the network and downloaded Gabel's files. The fact law enforcement did so with a device that enabled them to screen for child pornography and collect data for evidentiary purposes does not alter the privacy analysis. . . . The tool used by law enforcement here is no different, from a constitutional perspective, than the myriad special means -- street cameras, radar and canines -- that police legally use every day without prior judicial approval to efficiently gather evidence by accessing public information. These police tools do not generate Fourth Amendment concerns because they do not access anything the public cannot access. Thus, law enforcement's use of an enhanced computer program is the digital equivalent of a pole camera, which is legal and which does not require a warrant or court order.


U.S. v. Gabel, supra.

Sunday, October 10, 2010

Tracking Devices, Abandoned Property and Bailments

You’ve probably seen one of the stories about the California student who found a GPS tracking device on his car.


As the Wired story explains, Yasir Afifi, a U.S. citizen and 20-year old business marketing student at Mission College in Santa Clara, discovered the

the device . . . when he took his car to a local garage for an oil change. When a mechanic at Ali’s Auto Care raised his Ford Lincoln LS on hydraulic lifts, Afifi saw a wire sticking out near the right rear wheel and exhaust.

Garage owner Mazher Khan . . . also saw it. A closer inspection showed it connected to a battery pack and transmitter, which were attached to the car with a magnet. Khan asked Afifi if he wanted the device removed and when Afifi said yes, Khan pulled it easily from the car’s chassis.

As the Wired story also explains, a few days later FBI agents showed up at Afifi’s apartment and told him “`We’re here to recover the device you found on your vehicle. It’s federal property. It’s an expensive piece, and we need it right now.’” According to a story in the San Jose Mercury News, Afifi gave the GPS device to the FBI agent who demanded it . . . so in a sense, the story is over.


As you may have noticed, there was a lot of discussion of the incident online, some of which included comments to the effect that Afifi wasn’t legally obligated to give the tracking device to the FBI because, by putting it on his vehicle, the FBI abandoned any property interest in it. So I decided to do this post on whether the GPS device really was abandoned property and/or whether there was any legal reason why Afifi would have to return it to the FBI.


We’ll start with abandoned property. As the legal encyclopedia American Jurisprudence explains, abandoned property is property as to which the

owner has voluntarily relinquished all right, title, claim, and possession, with the intention of terminating his or her ownership, but without vesting ownership in any other person, and with the intention of not reclaiming any future rights therein. Or, as sometimes stated, the term `abandonment,’ as applied to personal property . . . , means the act of voluntarily and intentionally relinquishing a known right. . . . It involves a relinquishment of possession, and occurs because an owner no longer desires to possess the property.

1 Am. Jur. 2d Abandoned, Lost, and Unclaimed Property § 3 (notes omitted).


I’m sure the FBI had no intention of “voluntarily and intentionally relinquishing” its ownership interest in the GPS device agents attached to Afifi’s vehicle. The FBI only meant for the device to stay in place on his vehicle for a given period of time for the purpose of tracking his movements. That, in turn, cuts against the notion that the FBI abandoned the property. As American Jurisprudence also explains,

[m]ere relinquishment of the possession of a thing is not an abandonment of it in the legal sense of the word, for such an act is not wholly inconsistent with the idea of continuing ownership; the act of abandonment must be an overt act or some failure to act which carries the implication that the owner neither claims nor retains any interest in the subject matter of the abandonment.

1 Am. Jur. 2d Abandoned, Lost, and Unclaimed Property § 7. So if Afifi had found the GPS device in a trash can, that would presumably have given rise to a legitimate inference that the owner had abandoned the property with the intention of relinquishing ownership of it. And as the legal encyclopedia Corpus Juris Secundum explains, abandoned personal property “becomes the property of the person first appropriating it with the intention to possess.” 1 C.J.S. Abandonment § 15. In other words, if Afifi had found the device under circumstances which clearly indicated it had been abandoned, it would have become his property.


The problem with the abandonment theory, of course, is that the device wasn’t found in a trash can. Instead, it was found carefully installed on Afifi’s vehicle, which inferentially suggests that the person(s) who put it there intended to come back for it. The FBI obviously would have had a much stronger argument here if they’d attached a sticker to the device, one that said something like “Property of the FBI – If found, please return.” Such a sticker, as I understand the law of abandoned property, would have put the finder on notice that the property had not, in fact, been abandoned . . . but was something else.


(Another circumstance that might have done the same thing was the fact that, as the Wired story notes, someone who apparently knows their GPS devices identified this one as an “Orion Guardian ST820 tracking device made by an electronics company called Cobham, which sells the device only to law enforcement.” If Affifi realized that, then this should have had the same effect as the sticker, i.e., should have put him on notice that the device was not, in fact, abandoned property.)


What else, you ask? Well, I see two logical possibilities, one of which, however factually unlikely it may be, is that the GPS device was lost property. According to Corpus Juris Secundum, lost property is “property which the owner has unwittingly or unintentionally allowed to pass out of his or her possession”. 36A C.J.S. Finding Lost Goods § 1. Since the owner didn’t intend to surrender ownership of the property, the rights of someone who finds it are much less than in the case of abandoned property. As a Maryland court explained, “one who finds lost personal property holds it against all the world except the rightful owner.” Ganter v. Kapiloff, 69 Md. App. 97, 516 A.2d 611 (Maryland Court of Appeals 1986). This court also noted that “[g]enerally, it may be said that the finder of lost property holds it as a bailee for the true owner.” Ganter v. Kapiloff, supra.


That brings to the other logical possibility: bailment. As Wikipedia explains, the term bailment “describes a legal relationship” in which “physical possession of personal property . . . is transferred from one person (the 'bailor') to another person (the 'bailee').” As Wikipedia also noted, a bailment differs “from a contract of sale or a gift of property, as it only involves the transfer of possession and not ownership.” When I check a bag with an airline, that’s a bailment; I’m giving the airline temporary possession of my bag, not ownership of it.


And that brings me to the only case I could find in which the possession of a tracking device became an issue. The case – Aegis Investigative Group v. Metropolitan Government of Nashville and Davidson County, 98 S.W.3d 159 (Tennessee Court of Appeals 2001) arose when the Aegis Investigative Group (“Aegis”) filed a lawsuit in the “the First Circuit Court for Davidson County on October 30, 1998, alleging that employees of the Metropolitan Nashville Davidson County Police Department removed an electronic tracking device from the vehicle of the wife of one of its clients.” Aegis v. Metropolitan Government, supra. The case arose when Aegis,

a private investigating firm, was hired to watch the wife of a Murfreesboro client for information in a divorce action by placing an electronic tracking device on her car. After the wife discovered the device, she came to the Metropolitan Nashville Police Department to have the device removed as part of a stalking . . . . Metro held the device as potential evidence in a stalking and illegal use investigation. . . . No charges were placed against Aegis. Notwithstanding the conclusion of its investigation, Metro did not return the device to [Aegis] for some five (5) months. . . .

Aegis v. Metropolitan Government, supra. Aegis claimed Metro had a duty to return the device, but Metro argued that it did not. Aegis v. Metropolitan Government, supra. In ruling on the issue, the Court of Appeals held that with regard to the device, Metro was “a bailee implied in law, which is commonly referred to as a constructive bailee.” Aegis v. Metropolitan Government, supra. It explained that while bailments usually arise from a

contractual relation. . . . [t]here is also a class of bailments which arise by operation of law. Such a constructive or involuntary bailment arises where the person having possession of a chattel holds it under such circumstances that the law imposes on him the obligation of delivering it to another. . . .

Aegis v. Metropolitan Government, supra. The court also found that in a situation such as this, i.e., when “the bailment is for an indefinite time,” no cause of action for unlawful detention of the property arises unless and until the owner demands its return. Aegis v. Metropolitan Government, supra. Since the court found that Aegis had not demanded the return of the property, it held that Metro “rightfully acquired” possession of the device and had no “duty of care” to deliver it to Aegis absent a demand for its return. Aegis v. Metropolitan Government, supra.


If we apply that reasoning to the Afifi case, then Afifi presumably was a constructive bailor of the device and was, once the FBI demanded it back, legally obligated to return it.


There’s also the other, non-property issue, which occurred to me when I first heard about the story and which, I later discovered, the FBI agent raised when he confronted Afifi demanding the return of the device. The San Jose Mercury News article says the FBI agent told Afifi he’d be arrested for obstructing justice if he didn’t return the device.”


Since the tracking device was being used to gather evidence as part of an investigation into criminal activity, failing to return it (and, even worse, destroying it) could presumably be prosecuted as obstruction of justice . . . as long as Afifi was on notice that it was, in fact, being used by the government for that purpose.

Friday, October 08, 2010

Yelp, Defamation and the Communications Decency Act

This is not a post about cybercrime, as such. It’s a post about a civil suit for defamation. I’m writing about it because I think it raises an interesting issue in regard to online defamation, both civil and criminal.


As I explained in an earlier post, defamation was a crime at English and, later, American common law. As I also explained, the drafters of the Model Penal Code, an influential code of model criminal laws based on U.S. law, chose not to criminalize defamation . . . which they said was the most difficult decision they made in the process of updating and standardizing American criminal law.


Their primary reason for not criminalizing defamation is that it was not necessary because anyone injured by defamation could file a civil suit; if the claim was valid, the plaintiff could recover damages, which would be enough to make up for the "harm" caused by the defamation. As I noted in that post, some U.S. states went ahead and criminalized defamation, but criminal defamation prosecutions still tend to be rare.


I’m writing about the case we’ll get to in a minute because it deals with what I think is an interesting basis for a defamation claim. Defamation, as you probably know, basically consists of publishing a statement or statements that, as Wikipedia says, “may give an individual . . . a negative image.”


That was the plaintiff’s claim in Reit v. Yelp!, Inc., ___ N.Y.S.2d ___, 2010 WL 3490167 (New York Supreme Court – New York County 2010). Glenn Reit, “a dentist practicing on Third Avenue in Manhattan. . . . sue[d]Yelp!, Inc., the owner and provider of the website Yelp.com, and a `John Doe’ defendant, identified on Yelp.com as Michael S., for defamation”. Reit v. Yelp!, inc., supra. Here is how the court summarized Reit’s claim:


Reit alleges that he and his dental practice have been defamed by Michael S., an anonymous poster on Yelp.com, an interactive website designed to allow the general public to write, post, and view reviews about businesses, including professional ones such as Reit's, as well as restaurants and other establishments. Yelp solicits and sells advertising on its website.


In May of 2009, Yelp.com contained a web page referencing Reit's practice that included ten positive reviews. On May 6, 2009, Michael S. posted a negative, and allegedly defamatory, review about Reit's practice, including statements that his office is `small,’ `old’ and `smelly,’ and `the equipment is old and dirty.’ Reit claims that the number of people who call for appointments has dropped from 10-15 per day to 4-5 per day as a result of this post.


Reit contacted Yelp in an effort to remove the post. Yelp refused. Instead, Reit claims that Yelp removed all the positive postings on Reit's Yelp.com page and retained only the Michael S. posting. Reit alleges upon information and belief that this procedure of removing positive reviews and highlighting negative ones is part of Yelp's business model, used as leverage to coerce businesses and professionals into paying for advertising on Yelp.com.


Reit v. Yelp!, inc., supra. In a footnote the court appended to the second sentence in the last paragraph quoted above, the court explained that


[s]ubsequently, the Michael S. post was removed from the Yelp website, though for a time it was still accessible through the Google.com internet search engine. This has been remedied, and the Michael S. post is no longer available for view on the internet.


Reit v. Yelp!, inc., supra.


Yelp responded by filing a motion to dismiss Reit’s defamation claim on the grounds “that it is immune from liability under 47 U.S. Code § 430, the Federal Communications Decency Act of 1996 (CDA).” Reit v. Yelp!, inc., supra. As I’ve noted in earlier posts, § 230(c)(1) of the CDA immunizes certain parties from liability for content they publish online. As the Reit court explained,


Section 230 of the CDA provides that `[n]o provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider,’ (CDA § 230(c)(1) ), and that `[n]o cause of action may be brought and no liability may be imposed under any State or local law that is inconsistent with this section’ (CDA § 230(e)(3) ).


`Interactive computer service’ is defined as `any information service, system or access software provider that provides or enables computer access by multiple users to a computer server . . . ‘(CDA §230(f)(2)). An `information content provider’ is `any person or entity that is responsible, in whole or in part, for the creation or development of information provided through the internet or any other information computer service’ (CDA §230(f)(3)).


Through the CDA, Congress granted interactive computer services immunity from liability for publishing false or defamatory material so long as the information was provided by another party. Similarly, `lawsuits seeking to hold a service provider liable for its exercise of a publisher's traditional editorial functions -- such as deciding whether to publish, withdraw, postpone or alter content -- are barred’. (Shiamili v. Real Estate Group of New York, Inc., 68 A.D.3d 581, 892 N.Y.S.2d 52 (1st Dept. 2009). . . . However, an internet computer service is liable for its own speech, or when it `develops’ information (Shiamili, supra).


Reit v. Yelp!, inc., supra.


Reit conceded that Yelp! Is an internet computer service, but argued that the CDA did


not immunize it from defamation here because its removal of posts was not editorial, but business related. Specifically, Reit argues that the selective removal of all of his positive reviews was more than the action of an editor `simply selecting material for publication.’ This distinction, Reit argues, makes Yelp an internet content provider.


Reit v. Yelp!, inc., supra.


The New York Supreme Court explained that the situation in this case was analogous to the situation in the Shiamili case, cited above:


In Shiamili, the plaintiff sued an interactive computer service for defamation based on information published on its website. The complaint alleged that the defendants `choose and administer content’ that appears on the website. Shiamili argued that the defendants `engaged in a calculated effort to encourage, keep and promote bad' content on the Web site.’ The First Department held that this allegation does not raise an inference that defendants were information content providers within the meaning of the CDA because `message board postings do not cease to be data provided by another information content provider merely because the construct and operation of the Web site might have some influence on the content of the postings’. . . .


Reit v. Yelp!, inc., supra (quoting Shiamili, supra).


The Supreme Court therefore held as follows:


Here, Yelp is an interactive computer service. The allegedly defamatory content was supplied by a third party information content provider and consisted of a message board posting. That Yelp allegedly uses `bad’ posts in its marketing strategy does not change the nature of the posted data. Moreover, Yelp's selection of the posts it maintains on Yelp.com can be considered the selection of material for publication, an action `quintessentially related to a publisher's role’. Green v. America Online (AOL), 318 F.3d 465, 471 (3d Cir), cert. denied, 5420 U.S. 844 (2003)). Accordingly, Yelp may not be considered an internet content provider, so that Reit's defamation claims are barred by the CDA.


Reit v. Yelp!, inc., supra. The court ordered that Yelp!’s motion to dismiss be granted and the action be dismissed. Reit v. Yelp!, inc., supra.

As I noted in an earlier post, at least one court has held that immunity under CDA § 230(c)(1) applies in criminal, as well as civil, proceedings . . . so a defendant in a criminal defamation act could presumably use the statute as the basis of a motion to dismiss the charge(s) against him/her/it.

Thursday, October 07, 2010

Computer Virus = New Trial

This isn’t a post. It’s basically a report on a brief Memorandum Opinion issued by the Texas Court of Appeals on September 22, 2010.


Here’s the Memorandum Opinion in its entirety (with the Court Reporter’s name redacted):


On June 7, 2010, _____________, court reporter for the 33rd District Court, San Saba County, filed an affidavit in this Court stating that all copies of the reporter's record in this cause have either been deleted or destroyed by a computer virus, that attempts have been made to recover the record from ______'s computer, and that these attempts have been unsuccessful. We then abated this appeal to allow the trial court to determine whether the reporter's record can be replaced by agreement of the parties. See Texas Rules of Appellate Procedure 6(f)(4).


On August 23, 2010, we received a supplemental record containing the trial court's findings that the reporter's record cannot be replaced by agreement of the parties. Because the lost or destroyed record contains the entirety of the appellant's trial, we conclude that the lost record is necessary to resolution of this appeal. See Texas Rules of Appellate Procedure 34.6(f)(3). As a result, the appellant is entitled to a new trial. See Texas Rules of Appellate Procedure 34.6(f)(3). We reverse the judgment of conviction and remand this cause for a new trial.


As this online article explains, the


function of the appellate court is limited to a review of the trial record sent up from the lower court and the briefs filed by the appellant and appellee. . . . The trial record, sometimes called the record proper, must show the pleadings that initiated the case, the complete transcript (in cases of jury trial) of lower court proceedings, the verdict, and the entry of the final judgment or order. The appellant must clearly demonstrate that the grounds for review had been raised and unsuccessfully decided upon at the trial level and, therefore, prejudicial error exists to warrant the reversal of the decision of the lower court.


So . . . no record, no appeal.


I’m absolutely positive this was inadvertent . . . but it raises an interesting logical possibility: using malware to sabotage a court record and thereby gain a new trial. I really doubt that’ll ever happen, but it’s a thought.


Facebook and MySpace Privacy

I’ve so far been unable to find any cases in which a court has addressed whether someone has a 4th Amendment expectation of privacy in content loaded onto a MySpace or Facebook page.


I have, though, found a recent New York state case in which a court addressed the issue of whether content on MySpace or Facebook is private in a more generic sense. So while it’s a civil case and doesn’t address any 4th Amendment issues, I decided to go ahead and do a post on it.


The case is Romano v. Steelcase, Inc., ___ N.Y.S.2d ___, 2010 WL 3703242 (New York Supreme Court – Suffolk County 2010), and I actually know nothing about how it arose or what the specific causes of action at issue are. All I know is that Kathleen Romano sued Steelcase, Inc. claiming, at least in part, that she “sustained permanent injuries as a result” of an “incident,” which I assume involved Steelcase and/or its products. Romano v. Steelcase, Inc., supra. According to the opinion, Romano also alleged that because of the “injuries” she sustained as a result of the “incident,” she “can no longer participate in certain activities or that these injuries have effected her enjoyment of life.” Romano v. Steelcase, Inc., supra.


Steelcase obviously needs to negate some or all of Romano’s claims of permanent injuries and consequent detrimental impact on her ability to participate in certain activities and/or her enjoyment of life. In any civil lawsuit, including this one, the parties engage in “discovery.” As Wikipedia explains, in U.S. law, discovery


is the pre-trial phase in a lawsuit in which each party through the law of civil procedure can request documents and other evidence from other parties and can compel the production of evidence by using a subpoena or through other discovery devices, such as requests for production of documents, and depositions.


While it was investigating Romano’s claims, Steelcase learned that she had Facebook and Myspace pages. Romano v. Steelcase, Inc., supra. Steelcase may, or may not, have, asked her for the ability to access the pages; I can’t tell exactly what happened from the only opinion I have. But I know Steelcase sought the court’s help in gaining access to this information. At the beginning of the opinion, the judge notes that


Defendant Steelcase moves this Court for an Order granting [Steelcase] access to [Romano’s] current and historical Facebook and MySpace pages and accounts, including all deleted pages and related information upon the grounds that [Romano] has placed certain information on these social networking sites which are believed to be inconsistent with her claims in this action concerning the extent and nature of her injuries, especially her claims for loss of enjoyment of life.


Romano v. Steelcase, Inc., supra. Steelcase believed “that a review of the public portions of Plaintiff's MySpace and Facebook pages” would reveal that “she has an active lifestyle and has traveled to Florida and Pennsylvania during the time period she claims that her injuries prohibited such activity.” Romano v. Steelcase, Inc., supra. The motion for this order, then, came after Steelcase


sought to question [Romano] at her deposition regarding her MySpace and Facebook accounts, to no avail and following those depositions, served [her] with a Notice for Discovery & Inspection requesting, inter alia, `authorizations to obtain full access to and copies of [her] current and historical records/information on her Facebook and MySpace accounts.’ [Romano] has refused to provide the requested authorizations.


Romano v. Steelcase, Inc., supra. So Steelcase asked the court to order her to comply.


The court began its ruling on Steelcase’s motion by noting that under § 3101 of New York’s Civil Practice Law and Rules, “there shall be full disclosure of all non-privileged matter which is material and necessary to the defense or prosecution of an action.” Romano v. Steelcase, Inc., supra. The court explained that the “material and necessary” standard “is to be interpreted liberally requiring disclosure of `any facts bearing on the controversy which will assist preparation for trial by sharpening the issues and reducing delay and prolixity’”. Romano v. Steelcase, Inc., supra. The court noted that each civil


discovery request is to be decided on a case-by-case basis keeping in mind the strong public policy in favor of open disclosure. . . . If the information sought is sufficiently related to the issues in litigation so as to make the effort to obtain it in preparation for trial reasonable, then discovery should be permitted. . . . It is immaterial that the information sought may not be admissible at trial as `pretrial discovery extends not only to proof that is admissible but also to matters that may lead to the disclosure of admissible proof’. . . .


Romano v. Steelcase, Inc., supra (quoting Twenty Four Hour Fuel Oil Corp. v. Hunter Ambulance, Inc., 226 A.D.2d 175, 640 N.Y.S.2d 114 (New York Appellate Division 1996)). Finally, the court noted that


Plaintiffs who place their physical condition in controversy, may not shield from disclosure material which is necessary to the defense of the action. . . . Accordingly, in an action seeking damages for personal injuries, discovery is generally permitted with respect to materials that may be relevant both to the issue of damages and the extent of a plaintiff's injury . . . including a plaintiff's claim for loss of enjoyment of life. . . .


Romano v. Steelcase, Inc., supra. In ruling on Steelcase’s motion, the court began by explaining that Facebook and Myspace are both


social networking sites where people can share information about their personal lives, including posting photographs and sharing information about what they are doing or thinking. Indeed, Facebook policy states that `it helps you share information with your friends and people around you,’ and that `Facebook is about sharing information with others.’ Likewise, MySpace is a `social networking service that allows Members to create unique personal profiles online in order to find and communicate with old and news friends;’ and, is self-described as an `online community’ where `you can share photos, journals and interests with your growing network of mutual friends,’ and, as a `global lifestyle portal that reaches millions of people around the world.’ Both sites allow the user to set privacy levels to control with whom they share their information.


Romano v. Steelcase, Inc., supra. The judge then explained that the information Steelcase sought regarding Romano’s Facebook and MySpace accounts was both


material and necessary to the defense of this action and/or could lead to admissible evidence. . . . [I]t appears that [Romano’s] public profile page on Facebook shows her smiling happily in a photograph outside . . . her home despite her claim that she has sustained permanent injuries and is largely confined to her house and bed. [Given] that the public portions of [Romano’s] social networking sites contain material that is contrary to her claims . . . , there is a reasonable likelihood that the private portions of her sites may contain further evidence such as information with regard to her activities and enjoyment of life, all of which are material and relevant to the defense of this action. . . .


Romano v. Steelcase, Inc., supra. The judge noted that although there were no New York cases addressing the issues raised by Steelcase’s motion, there were “instructive cases” from other jurisdictions. Romano v. Steelcase, Inc., supra. A Colorado judge granted a defendant’s request for access to the content on the plaintiffs’ Facebook, Myspace and Meetup.com pages and a Canadian court reached the same conclusion in a case involving a plaintiff whose claims of injuries sustained in an automobile accident were similar to those at issue in the Romano case. Romano v. Steelcase, Inc., supra.


The Canadian court noted that “it is reasonable to infer from the social networking purpose of Facebook, that even if a person only maintains a private profile with the public profile merely listing their name, that relevant information exists on their limited-access private pages”. Romano v. Steelcase, Inc., supra. The Canadian court also commented that to permit a party


claiming very substantial damages for loss of enjoyment of life to hide behind self-set privacy controls on a website, the primary purpose of which is to enable people to share information about how they lead their social lives, risks depriving the opposite party of access to material that may be relevant to ensuring a fair trial.


Romano v. Steelcase, Inc., supra (quoting Leduc v. Roman, 2009 CarswellOnt 843 (February 20, 2009)). The judge therefore granted Steelcase’s motion because he found that to deny Steelcase access to the information it sought would “condone [Romano’s] attempt to hide relevant information behind self-requested privacy settings.” Romano v. Steelcase, Inc., supra.



And in his closing comments, the judge explained that because neither Facebook nor MySpace “guarantee complete privacy, [Romano] has no legitimate reasonable expectation of privacy. . . . MySpace warns users . . . that their profiles and MySpace forums are public spaces and Facebook's privacy policy” explains that when someone posts information on Facebook, “this information may become publicly available.” Romano v. Steelcase, Inc., supra. The judge found that when Romano created her accounts, she consented


to the fact that her personal information would be shared with others, notwithstanding her privacy settings. . . . Since [Romano] knew her information may become publicly available, she cannot now claim she had a reasonable expectation of privacy. As recently set forth by commentators regarding privacy and social networking sites, given the millions of users, `. . . privacy is no longer grounded in reasonable expectations, but rather in . . . wishful thinking.’


Romano v. Steelcase, Inc., supra (quoting Dana L. Flemming & Joseph M. Herlihy, What Happens when the College Rumor Mill Goes Online?, Boston Bar Journal (January/February 2009)).


Since this is a civil discovery case, this court’s holding and comments regarding expectations of privacy in sites like Facebook and MySpace doesn’t constitute any kind of precedent as to 4th Amendment privacy . . . but the logical and rationale might be used to argue that there is no 4th Amendment expectation of privacy in social networking sites.