Wednesday, October 11, 2006

GPS Tracking and the 4th Amendment: Part 2


Last time I talked about using GPS devices to track vehicles. There' a Supreme Court decision that seems to hold that monitoring such a device in order to track someone’s movements is outside the 4th Amendment, so no warrant is required to do so. We can argue that the decision doesn’t apply to modern GPS technology, of course, but at least there is a decision out there.

The Supreme Court did not decide, when it issued that decision twenty-plus years ago, whether the installation of a tracking device, such as a GPS device, is something that comes within the scope of the 4th Amendment. That issue is now surfacing, as courts try to figure out whether putting a tracking device on someone’s car is either a “search” or a “seizure” under the 4th Amendment.

Putting the device on a vehicle is not, I would submit, a “search” because a search violates a valid 4th Amendment expectation of privacy. The issue that’s coming up in these cases is whether the 4th Amendment is implicated when a tracking device is installed on a “public” area of a vehicle: under a bumper, on the undercarriage, etc. It’s clear that officers cannot go into “private” areas of a vehicle (the trunk, under the hood, inside the passenger compartment, etc.) without having a warrant; that would clearly be a search regardless of whether their motive is to install a tracking device or just to look around (or both). When the devices are installed on areas that are, at least arguably, accessible to the general public, I don’t think we can legitimately characterize the act of installing them as a “search.” After all, what “private” information do the officers obtain by doing so?

I tend to think, though, that the act of installing a tracking device on such a “public” area of a vehicle is a seizure under the 4th Amendment. Seizures occur when agents of the government interfere with someone’s possession and use of their vehicle. Now, when an officer sneaks up to a car at night or at some other time when it is parked and is not being used by the owner and installs a GPS device, there would not seem to be any particular interference with the owner’s possession and use of the property. The owner never even knows what’s happened – that’s the whole point.

But something has definitely happened, and some courts have said that something is a seizure, which means that the installation of a tracking device comes within the 4th Amendment. A Wisconsin district court held, earlier this year, that officers must have reasonable suspicion to believe that a crime is being/has been committed and that the installation of the tracking device will yield evidence of that crime. U.S. v. Garcia, 2006 WL 298704 (W.D. Wisconsin 2006). This court found that reasonable suspicion was enough because “the intrusion caused by the application of the device is minimal. The real intrusion . . . is the 24/7 governmental monitoring that follows.”

(Reasonable suspicion is a lower level of individualized suspicion of probable cause. It basically means that officers can’t just install a tracking device whenever they feel like it in hopes something will turn up. Instead, they must be able to articulate specific facts which supported their belief that installing the device would yield evidence of criminal activity.)

A couple of years ago, a New York court went further. In People v. Lacey, 787 N.Y.S.2d 680 (N.Y. Co. Court 2004), the court held that police must get a warrant, based on probable cause, to install a tracking device”

“Although . . . persons have diminished expectations of privacy in automobiles on public roads and can be visually tracked by the police, it is clear that the mere act of parking a vehicle on a public street does not give law enforcement the unfettered right to tamper with the vehicle by surreptitiously attaching a tracking device without either the owner's consent or without a warrant issued by a Court. . . . Attachment of the GPS requires a physical intrusion into an individual's personal effects . . . . Accordingly, the Court finds that in the absence of exigent circumstances, not here present, the police should have obtained a warrant prior to attaching the GPS to the Mitsubishi.

About a month ago, a New Jersey court held that the 4th Amendment requires police to get a warrant before attaching a GPS tracking device. State v. Scott, 2006 WL 2640221 (N.J. Super. A.D. 2006).

Courts in Washington and Oregon have reached similar conclusions by applying their state constitutions (which can and often do provide more protection than the 4th Amendment). State v. Jackson, 76 P.3d 217 (Washington 2003); State v. Campbell, 759 P.2d 1040 (Oregon 1988). The Jackson court noted, for example, that if “police are not required to obtain a warrant . . . before attaching a GPS device to a citizen's vehicle, then there is no limitation on the State's use of these devices on any person's vehicle, whether criminal activity is suspected or not.”

Other courts have disagreed, basically on the premise that the installation of a GPS tracking device in no way interferes with the vehicle owner’s possession and use of the vehicle. As the Ninth Circuit said in U.S. v. McIver, 186 F.3d 1119 (1999), “McIver did not present any evidence that the placement of the . . . tracking devices deprived him of dominion and control of his Toyota 4Runner, nor did he demonstrate that the presence of these objects caused any damage to the electronic components of the vehicle. Under these circumstances, we hold that no seizure occurred because the officers did not meaningfully interfere with McIver's possessory interest in the Toyota 4Runner.”

I understand that viewpoint, but whenever I think about this issue I come back to the argument a gentleman made earlier this year, when I raised this issue in a conference presentation. He said something to the effect of “the government can’t put a bumper sticker on my car – it’s my car and putting a bumper sticker on it would violate my rights to the ownership of the car. So if they can’t put a bumper sticker on my car, how can they put a GPS device on it?”

Good question.

Sunday, October 08, 2006

GPS Tracking and the 4th Amendment: Part 1


As you may know, police often use GPS devices to monitor the movements of vehicles used by those who are suspected of being involved in criminal activity. The use of these devices is becoming increasingly common because they are so effective.

The devices are usually attached somewhere on the exterior of the vehicle, under a bumper or on the undercarriage, say.


The use of GPS tracking devices is raising 4th Amendment issues, for several reasons. In this post I want to talk about what has been the most common issue: Whether the use of a tracking device is a "search" under the 4th Amendment.

To explain why this is an issue, I need to review what happened in a twenty year old Supreme Court case: In United States v. Knotts, 460 U.S. 276 (1983), the Supreme Court was asked to decide if law enforcement’s using a “beeper” to track the movements of a vehicle was a search under the 4th Amendment. If it was, law enforcement would have had to have gotten a search warrant for the use of the beeper to be constitutional; if it was not, then their using the beeper without getting a warrant did not violate the 4th Amendment.


The “beeper” was a radio transmitter that was placed in a container of chloroform that was sold to a suspect – Armstrong – who was believed to be involved in manufacturing illegal drugs. Armstrong put the container with the beeper in it in his vehicle and officers followed him to see where he was taking it. In following him, they relied both on visual surveillance and on the signals from the beeper; the beeper basically made it easier for them to keep track of Armstrong’s vehicle as he traveled along roads in rural Wisconsin. As its name implies, the beeper merely transmitted an audio signal that became stronger when the officers were closer to Armstrong’s vehicle and weakened as they fell further behind it.


The Supreme Court said the use of the beeper was not a “search” because Armstrong did not have a 4th Amendment expectation of privacy in his movements along public highways. The Knotts Court noted that the “fact that the officers . . . relied not only on visual surveillance, but also on the use of the beeper . . . does not alter the situation. Nothing in the Fourth Amendment prohibited the police from augmenting the sensory faculties bestowed upon them at birth with such enhancement as science and technology afforded them”.

Since Armstrong’s movements were not private, there was no search and the 4th Amendment was not implicated.
Given the Knotts decision, it would seem that law enforcement’s using GPS devices to track vehicles would not be a search within the 4th Amendment . . . which means law enforcement could install a GPS device on a vehicle and monitor it without obtaining a warrant, just as the officers did in Knotts. Some courts, though, are suggesting that Knotts is not dispositive of this issue because of the significant differences between GPS tracking devices and the beeper used in Knotts.

In State v. Jackson, 76 P.3d 217 (Wash. 2003), the Washington Supreme Court held that the use of a GPS tracking device is a search under the state’s constitution, which the court interprets as providing more privacy protection than does the 4th Amendment. The Jackson Court explained that the use of a GPS device is much more intrusive than the monitoring of the beeper used in Knotts:


“[W]hen a GPS device is attached to a vehicle, law enforcement officers do not in fact follow the vehicle. Thus, . . . the GPS device does not merely augment the officers' senses, but rather provides a technological substitute for traditional visual tracking. Further, the devices in this case were in place for approximately two and one-half weeks. It is unlikely that the sheriff's department could have successfully maintained uninterrupted 24-hour surveillance throughout this time by following Jackson. Even longer tracking periods might be undertaken, depending upon the circumstances of a case. We perceive a difference between the kind of uninterrupted, 24-hour a day surveillance possible through use of a GPS device, which does not depend upon whether an officer could in fact have maintained visual contact over the tracking period, and an officer's use of binoculars or a flashlight to augment his or her senses.


Other courts are suggesting that the same result may hold under the 4th Amendment, on the premise that the increased sophistication of GPS tracking makes it more intrusive than the use of the beeper at issue in Knotts and therefore should bring it within the scope of the 4th Amendment.

A New York court concluded, for example, that “[a]t this time, more than ever, individuals must be given the constitutional protections necessary to their continued unfettered freedom from a `big brother’ society. . . . [A] person must feel secure that his or her every movement will not be tracked except upon a warrant based on probable cause establishing that such person has been or is about to commit a crime. Technology cannot abrogate our constitutional protections.” People v. Lacey, 787 N.Y.S.2d 680 (N.Y. Co. Ct. 2004).


A federal district court in Maryland noted that the use of GPS technology raises issues that may implicate the 4th Amendment, but concluded it did not have to decide whether this is true because the officers in the case had obtained a warrant before they installed the GPS device on the suspect’s vehicle. United States v. Berry, 300 F.Supp.2d 366 (D. Md. 2004).


It’s likely to be a long time before the Supreme Court addresses this issue if, indeed, it ever does. This means the applicability of the 4th Amendment to GPS tracking will probably remain uncertain, dependant upon whether a court construes GPS technology as indistinguishable from the beeper used in Knotts or as a device the intrusiveness of which takes it out of the Knotts holding. We may also see state courts using state constitutions to impose restrictions on the use of this technology.

The question as to whether GPS tracking constitutes a search within the compass of the 4th Amendment is really just one manifestation of a larger issue: How do we apply constitutional protections -- such as the 4th Amendment -- to evolving technologies? The constitution, and the 4th amendment in particular, were written at a time when the only world was the real, physical world and searches involved law enforcement's kicking down doors and rummaging through closets and other "private" areas.

Technology lets law enforcement officers do what they could not do when the Constitution was drafted. Here, as in other areas, courts need to decide how we reconcile new technologies, new methods, with traditional principles.

Tuesday, October 03, 2006

The 4th Amendment and Copying Data

This is aabout whether the 4th amendment applies to a law officer's copying data. The issues whether copying data is a "search" or a "seizure" under the 4th Amendment. At the moment, it is not clear that copying data is either.

This is an important issue because, if copying data is neither a search nor a seizure, then it is outside the scope of the 4th Amendment . . . which means officers do not need a search (and/or seizure) warrant or an exception to the warrant requirement in order to copy data lawfully.

As I explained in an earlier post, the 4th amendment creates the right to be free from “unreasonable” (a) searches and (b) seizures. Searches violate a reasonable expectation of privacy, while seizures of property violate the owner’s legitimate interest in the possession and use of that property.


I have argued elsewhere that copying data is a seizure – I don’t think it is a a search because you can copy data without scrutinizing its contents; I think such scrutiny is essential for there to be a “search.”

I think the act of copying data is a seizure, though, because “something” clearly happens: The government obtains a copy of data, something it did not have before the copying occurred.

I see this as somewhat analogous to the rule with regard to copying data as theft: In an Oregon case, the defendant was charged with “theft” because he copied a file containing user passwords, a file that belonged to Intel, his employer. The defendant in that case claimed he had not committed “theft” because theft is, and has traditionally been, a zero-sum offense. That is, it consists of taking someone’s property and thereby wholly depriving them of its possession and use. The defendant in this case claimed he had not “deprived” Intel of anything because it still had the file with the passwords in it.

The Oregon court basically finessed his argument, finding there had been a “theft” because Intel had lost something – essentially the exclusive possession and use of the property. (I say finessed because the statute was somewhat problematic, as many theft statutes are – they can reflect history and define theft in terms of taking “tangible property” and/or in terms of completely depriving the owner of the possession and use of the property.)


But let’s get back to seizures: I think copying data has to be defined as either a search or a seizure, because otherwise it’s completely outside the 4th Amendment . . . which would mean, as I noted earlier, that law enforcement agents could copy data without obtaining a warrant or having any other justification under the 4th amendment. I also think, as I explain above, that it is sufficiently analogous to data theft to qualify as a seizure.

What I really want to talk about is a hypothetical (or maybe a real case) that was posed to me at a conference last year. Here it is: Two officers go to John Doe’s home to execute a search warrant for his laptop. The warrant authorizes them to search the home for the laptop and then seize it, bring it back so it can be analyzed forensically. As they arrive at Doe’s home, he drives up. They tell him why they’re there and he agrees to get the laptop and give it to them, which he does. To get the laptop, he goes inside and they follow, with his permission. They see a terabyte server in the room where he goes to get the laptop -- however many terabytes is up to you, but it’s big. They ask Doe if they can make a mirror image of the server, and he agrees. (Now, I’m assuming they don’t actually do this, that they call others to do so, but for simplicity’s sake I’ll just act as if they whip out the necessary equipment and proceed.)

The process of imaging the server begins. It will take, say, 10 hours. About halfway through, Doe says, “You know, I’ve changed my mind. Quit making the copy.” The question posed to me is: What can the officers do? If they stop, they lose what they have already copied; if they keep going, they clearly do so without Doe’s permission, and his consent is their only 4th amendment justification for copying the data.

If copying the data is a search (which I don’t think it is), they clearly have to stop. The rule is that a search authorized by the property owner’s consent is reasonable as long as the consent continues. But once the property owner changes his/her mind and revokes the consent, the search has to stop. So if the copying is a search – just a search, and one that is still in process – then they have to stop.

What if it’s a seizure? The rule is that if the property owner revokes his/her consent to the seizure of property, the revocation is prospective but not retroactive. So, assume that instead of copying data the officers wanted to look for hard copy child pornography and Doe consented. They’re looking for child pornography (searching often precedes seizing, and he’s consented to both, in this version) and pick up photos, videos and other tangible items as they do so – they seize these items pursuant to Doe’s consent. Then he says to stop. They can keep what they have already seized, but can’t keep seizing further items.

If we say that copying data is a seizure, then how do we resolve the scenario above, the one that was posed to me last year? If it’s a seizure, is it a partially-completed one, which would mean the officers imaging the server could keep the data they had copied to the point at which Doe revoked his consent (assuming that is possible)? If we go with that theory, then can they finish the imaging process, on the premise that this is the only way they can keep what they had already seized?

Or do we say this is a seizure that is in process but that has not yet been completed? If we say that, then it seems that Doe’s revocation of his consent would require that the officers stop the imaging process and abort the seizure.

Thursday, September 28, 2006

Mea Culpa (kind of . . . )

I’ve written extensively here and elsewhere (especially) about how we need to use legal rules to hold individuals and entities liable for not taking reasonable efforts to secure their computer systems. The goal, I argue, is to alter our current culture, to create a climate in which we – the individual end-users and the entity intermediate-, originating-, whatever-users – take security seriously and take it as our individual and collective responsibility.

I’ve just had an object lesson in how far we have to go to achieve that . . . a lesson in humility, maybe . . . or maybe just a good, solid dose of early twenty-first century reality.

I’m a professor at a law school, which is part of a university. Like all law schools, ours is a separate operational unit for most purposes, including internal technology. We do, though, rely on the university’s technical staff for certain things, some of which implicate computer security. That’s about all I’m going to say about organizational responsibilities because my purpose here is not to get anyone into trouble – it is, as I said earlier, simply to recount my recent encounter with reality.

At home, I have my own laptop, my own software, my own security arrangements, etc. At the law school, I use a law school-provided laptop which runs law school-provided software (via university arrangements) and I access the Internet via the law school’s wired connection, which has firewalls (sometimes very annoying firewalls and filters, I might add) and other security measures. My laptop has antivirus software provided by a major, reputable company, which I will not identity because what happened is not the fault of their product – it is, as is so often true, attributable to human factors.

My laptop antivirus software updates itself, and I routinely run a virus scan on the laptop at least once a week (more, depending on how often and how long I’m there). I ran a virus scan on Monday and came back to find that it had found a Trojan horse program but was unable to do anything with it – couldn’t delete it, couldn’t quarantine it, nada. I found that peculiar, so I went to the tech staff.

They responded promptly, ran the laptop in safe mode, ran the antivirus software, found the Trojan, deleted it. All was good, till the next day, Tuesday, when the Trojan showed up again, same message, same futile efforts by the antivirus software. So, back I go to the tech staff. They weren’t sure what to do, researched the matter, and decided the problem was that running the antivirus software in safe mode didn’t clear the Trojan from the registry (though now that I think about it, why would running the program in safe mode let it do what it could not do in regular mode?), so a very nice tech person did that while I was out teaching a class.

I come in yesterday, and run into the nice tech person in the hall. I’ve really begun to wonder why the antivirus software had such a hard time with the Trojan, so after he tells me they cleaned the registry, the Trojan is really gone and all is good, I ask about that.

I’m told that the program the law school uses (via the university) has had two upgrades in the last year, neither of which made it to my laptop. The effects of the first upgrade were apparently not that dramatic, so we’ll let that one go.

The second upgrade, which was implemented some months (4? 5? 6?) ago left the software on my laptop incapable of updating itself . . . so for some months I have been running a laptop from my office the antivirus software of which was increasingly out of date. Neither the notice that there was an upgrade or the upgrade itself ever percolated down to me . . . which makes me wonder how many other law school users it missed. (Note: This is not intended as an invitation to would-be law school hackers.)


Again, my point here is not to cause trouble for the good people who work in computer security at my law school and at my university.

My point is simply anecdotal . . . simply a personal experience with how completely out of whack our culture is with the need to secure systems . . . and KEEP them secure.

In a completely different context, someone said our grand jury system is “alchemical” in its function . . . by which they meant that we put together a group (12, 16, 23) of people, wave a set of proposed charges (an indictment) at them, which they almost instantaneously approve and we have a criminal case. The point was that nothing really happens, in terms of having the grand jurors actually assess the merits of the indictment – that the process is almost purely symbolic.

I’m beginning to wonder if a lot of the exercise about computer security isn’t alchemical, in the same sense. Effort happens, and that’s supposed to count, somehow.

This is one of those days when, if I were a gambler, I’d definitely be putting my money on the cybercriminals.

Tuesday, September 26, 2006

Can You Hack an Unsecured Computer?

This is a follow-up, in some ways, to my post about holding people criminally liable for not securing their computer systems.

I noticed that Germany is revising their computer crime laws somewhat, and that reminded me of a distinct aspect of the German Criminal Code’s approach to obtaining unauthorized access to computer data. Section 202a of the German Criminal Code makes it a crime to obtain data from a system without authorization if the system was “specially protected against unauthorized access”.

New York has a similar provision. Section 156.04 of the New York Penal Code makes it a crime for someone “knowingly” to use or cause “to be used a computer . . . without authorization and the computer utilized is equipped or programmed with any device or coding system, a function of which is to prevent the unauthorized use of said computer”. This provision has been used to dismiss charges of hacking. In People v. Angeles, 687 N.Y.S.2d 884 (N.Y. City Crim, Ct. 1999), an employee of a NY car service was charged with gaining unauthorized access to data in a computer owned and operated by the car service in violation of section 156.04. He moved to dismiss the charges, pointing out that the computer in question was not password-protected or otherwise “equipped or programmed with any device . . . to prevent the unauthorized use” of the computer. The court agreed, and dismissed the charges.

So, in New York and Germany (and the Netherlands), you can’t hack an unsecured computer.

The purpose in each instance, as I understand it, was to filter unauthorized access cases – to keep police from having to respond if the owner of the computer in effect left the door to the computer wide open. The implicit premise seems to have been, as I think they used to say in an old TV cop show, “take care of yourself out there.”

We don’t do this in the real-world, at least not in MOST of the US (New York is an exception). If I am foolish enough to leave my house with the front door standing wide open and my new laptop sitting on a table just inside the door, my irresponsibility (stupidity?) in no way undermines my right to expect that the police will investigate the crime. We simply do not incorporate victim fault into our criminal law (though we do in tort law). So the police can’t say to me, “sorry, but you shouldn’t have left the door open. We’re not going to waste our time tracking down the perp when you didn’t do anything to prevent the crime.”

Right now, in most of the US the real-world rule applies in the online context . . . which, aside from anything else, creates some difficult conceptual issues when it comes to wireless networks. Unlike my house with the open door – which is a quintessentially passive situation – an unsecured wireless network is “active,” in that it casts a web outside my house and, some would argue, essentially “invites” unauthorized persons to use it. So, there continues to be quite a debate about whether or not it is hacking to free-ride on an unsecured wireless network, i.e., simply to make use of the network to go online.

If we required wireless network owners to secure their systems, then the analysis would be much easier. I think I read that a New York town is doing this. I can’t find the story just now, but I believe I read earlier this year that a New York town adopted an ordinance which required people running wireless networks to secure them. (I think users who did not secure their systems faced a fine in that instance, presumably because the NY statute would already bar charges for unauthorized access to an unsecured wireless network.)

Interesting issue: If you don’t bar the virtual door is it a crime for someone to enter it?

Tuesday, September 19, 2006

Using Your Office Computer to Access Pornography


Last July the Florida Supreme Court announced it was going to reprimand Judge Brandt C. Downey for, among other things, habitually “viewing pornographic websites” on the computer in his chambers. The case is Inquiry Concerning a Judge (Florida Supreme Court SC 05-2228) (July 13, 2006), 2006 WL 1911389.

In its opinion, the Florida Supreme Court also notes that the judge’s “pervasive practice of viewing pornography” from the computer in his chambers “resulted in frequent computer viruses infecting” the computer. This, in turn, meant that courthouse staff had to remove the viruses from his computer.

The opinion notes that “on at least two occasions, courthouse personnel were unwittingly exposed to pornographic images when they reported” to the judge’s chambers to remove viruses from his computer. The opinion also notes that the judge “repeatedly ignored e-mail warnings . . . from court technology staff” which advised him “of the potential risk to the entire computer network due to [his] viewing of certain websites.”

The Florida Supreme Court found that these allegations, if true, violated Canon 1 of the Code of Judicial Conduct. Canon 1 basically says that a judge should maintain and enforce “high standards of conduct” and should personally observe those standards himself or herself. The judge admitted to violating Canon 1, and this violation became part of the basis for his being reprimanded.

I find this case interesting for several reasons, one of which is that what the judge was doing on his office computer is, I suspect, far from unusual in the American workplace. We are given computers to use at work, and I think the line between “their” computer (which is to be used only officially, for company business) and “our” computer tends to blur in our minds . . . so we think nothing of using “their” computer for “our” own purposes.

(Indeed, I am doing that right now – I am writing this blog post on the laptop in my office at the law school where I teach. Writing a blog post is definitely not as far afield from my employment obligations as the judge’s looking at porn in his chambers, but it’s pretty clearly not in my job description, either.)

A lot of this is inevitable. We spend a lot of time at work – are we supposed to be offline for the entire time, or is it reasonable for us to use our work computers (and our work email addresses) for “personal” reasons?

That question raises a lot of interesting issues. Some of the things we do with “their” computers while we’re at work don’t hurt anyone or anything, but some of what we do can “harm” the company we work for. The judge was exposing the court’s computer system to viruses. He was not doing this intentionally, but his activity still had that effect. It doesn’t seem as if the court computer system was seriously compromised by the viruses, but the viruses could have interfered with other employees’ ability to use the system, and the court may have incurred expenses in having the viruses removed.

What happened to the judge raises another issue: He was disciplined because the judicial system found that his recreational use of his office computer was not consistent with the standards of behavior we require of judges. What standards, I wonder, do we require of the rest of us?

Do I have an obligation to use my office computer in a way that minimizes its exposure to viruses and other evils? If so, how far does that obligation extend – am I supposed to educate myself about the dangers that lurk online so I can more effectively avoid them? Or is the security of my computer and the system it is linked to purely the concern of our computer staff?

More importantly, perhaps, how am I supposed to know? The judge got into trouble because he was bound by an external set of standards – the Code of Judicial Conduct. What, if anything, is supposed to put the rest of us on notice as to the responsibility, if any, we have to use our office computers in a “responsible” manner?

Friday, September 15, 2006

Hold People Liable for Cybercrime?


This is, I hope, going to be a relative short but provocative post.

Elsewhere, I have analyzed the necessity and viability of holding the “users” of technology --- you and me – criminally liable for not preventing cybercrime, at least under certain conditions and subject to certain constraints.

I am not going to go into detail on what I have written elsewhere; if you want a longer version, you can find it here and here.


As I explain in those and other articles, our current model of law enforcement (police react to a completed crime, investigate, identify and apprehend the perpetrator, who is then prosecuted, convicted and sanctioned . . . which takes him/her out of commission and deters others from following his/her example) is not very effective for cybercrime.

It is not particularly effective for cybercrime because the model assumes territorial crime, that is, it assume that the victim(s) and perpetrator(s) are in some physical proximity when the crime is committed. This, in turn, means that:

  • they’re in the same jurisdiction, the same country, so the country’s laws clearly apply and the country clearly has jurisdiction to prosecute;
  • physical proximity means there is trace evidence at the crime scene (think CSI) and that individuals located in the area of the crime are likely to have seen things that can help identify the perpetrator;
  • the perpetrator may even be known, locally, which helps with identification;
  • once identified, the perpetrator can be apprehended with relative ease.
Cybercrime is different because cyberspace makes it easy for perpetrators to
  • be anonymous or pseudonymous;
  • commit crimes across national borders (maybe across several national borders); and
  • commit crimes on a much larger scale (real-world crime tends to be sequential, cybercrime tends to be simultaneous and cumulative).
Because of its limited resources, country-based law enforcement finds it difficult to deal with cybercrime. That difficulty is exacerbated by the fact that while we can map the contours of real-world crime to some extent (which lets law enforcement allocate resources more effectively), we cannot do that with cybercrime (primarily due to the low level at which it is reported).

So, I argue, we need to move to a model that ALSO emphasizes prevention . . . which is where we come in. Currently there is no legal obligation to secure systems and otherwise frustrate cybercriminals. Currently, criminal law does not take the negligence or recklessness of the victim into account – if I leave my keys in my car and it’s stolen, that’s still a crime. There is no consequence of assumed risk. My negligence in leaving the keys there and creating an opportunity for a car thief has no consequences in criminal law because a crime is not “against” me, it’s “against” the state . . . it’s not personal, it’s a matter of social control.


In the articles I noted above, I argue that we should change this in two basic ways: One deals with crimes in which the person who didn’t secure their system is the only victim; the other deals with crimes in which the perpetrator used computers their owners (A and B, say) had not secured to attack others (C and D, say, to keep it simple).


I argue that we should use a form of assumed risk for the first scenario, the one in which the owner of the system is the only victim. What this could mean (it could be structured in various ways) is that law enforcement would have no obligation to investigate the crime and try to apprehend the perpetrator; they could if they wanted to (because crime is an offense against the state), but they would be free to ignore it if they concluded that the injury was only to the person who, in a sense, allowed it to be inflicted.


We could use a modified version of accomplice liability to address the second scenario – the consequent victimization scenario. Here, A’s and B’s respective negligence resulted in the infliction of “harm” on C and D, who, we are assuming, did nothing wrong. Since A and B contributed to the commission of the crimes against C and D, then could be held criminally liable for facilitating those crimes. It would probably be a low level of criminal liability and a low penalty (maybe only a fine, maybe community service).


The goal in both instances is to change behavior, to bring home to people that there are consequences of not securing their systems. I think the current state of complacence with regard to securing (or not securing) computers is a function of our implicitly assuming that crime is the sole province of the police. (It may also be in part attributable to the fact that people don't see cybercrime as "real" crime . . . not as the kind of crime that warrants alarm systems and burglar bars.)

It did not used to be that way; crime control used to be partially, and even primarily, a civilian, community function. The police-only model of crime control has only been the dominant model for about a hundred and fifty years, since Sir Robert Peel invented the professionalized police force in nineteenth century London.

Maybe it’s time we realized that technology is changing our world and that we can't rely only on old assumptions.


Or maybe I’m completely off base.

Thursday, September 14, 2006

Defamation


Defamation -- or libel -- was a crime at English and, later, American common law.

The justification for making it a crime was that it tended to cause a "breach of the peace" -- which originally meant that the person defamed and the one who made the defamatory statement might get into a duel.

Later, it seemed to mean merely that they might fight or otherwise engage in disruptive behavior.

In 1961, the drafters of the Model Penal Code -- which is the template for criminal law in this country -- decided defamation should not be criminalized. They said it was the most difficult decision they faced in updating and streamlining American criminal law. Their primary reason for not criminalizing defamation is that it was not necessary because anyone injured by defamation could file a civil suit; if the claim was valid, the plaintiff could recover damages, which would be enough to make up for the "harm" caused by the defamation.

The drafters of the Model Penal Code made this decision long before there was an Internet, in a world in which defamation was "published," if at all, by deep-pocket entities: newspapers, magazines, television stations, radio stations and, sometimes, movies. In that world, these mass-media outlets had an incentive to vet -- to filter -- what they published in order to avoid being held civilly liable for defamation.

It's now 45 years later and "publication" has become much more democratic. With the Internet, we can "publish" whatever we want (except for child pornography and a few other outlawed items). This, I think, calls into question the assumption the drafters of the Model Penal Code made in not criminalizing libel.

Since we do not have to rely on a mass-media outlet to "publish" material, the filter editors at newspapers, magazines, TV and radio stations provided is gone. And so is the likelihood that an injured party can recover damages -- most people who post material online are what we in the law call "judgment-proof." That is, you may be able to get a $1,000,000 (or $1,000,000,000) damage award against them, but it's functionally meaningless. They will never be able to pay up.

Maybe I should use a case to illustrate what I mean: A few years ago, Daniel Curzon-Brown, an reportedly an “openly gay” professor at City College in San Francisco, sued Ryan Lathouwers, founder and webmaster of Teacher Review, a site that posted “anonymous comments about . . . faculty members.” Curzon-Brown sued for defamation after he was the subject of “postings that use[d] the word `faggot’ frequently, and allege[d] that he raped and molested students in exchange for better grades.” One posting claimed he had sex with a student in the classroom; another accused him of killing a student. A year later, Curzon-Brown agreed to dismiss the suit and to pay the American Civil Liberties Union [ACLU] $10,000 in attorneys’ fees; the ACLU represented Lathouwers, who could not afford private counsel. According to news stories, had Curzon-Brown not agreed to dismiss, the ACLU would have moved for dismissal on the grounds that Lathouwers was statutorily immune from suit under the Communications Decency Act of 1996, and would have sought $100,000 in attorneys’ fees.

The Communications Decency Act “overrides the traditional treatment of publishers. . . . ‘such as newspapers, magazines or television and radio stations, all of which may be held liable for publishing . . . obscene or defamatory material written or prepared by others.’” Concerned about lawsuits inhibiting free speech online, Congress added Section 230(c)(1) to title 47 of the U.S. Code. It provides that “[n]o provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider.”

The effect of this provision is to immunize those who, like Lathouwers, post content that is provided by another, such as the individuals who submitted the postings about Curzon-Brown. At least one court has found that the immunity applies even though the operator of the site “exercises some editorial control over the anonymous postings.” A case argued a week ago before the California Supreme Court asks the court to find that the immunity conferred by this section does not apply, in least when certain conditions are met. Reports of the oral arguments in the case suggest, though, that this court will not inclined to do so (as, I would submit, it cannot under the federal statute).

The amount and variety of material that is posted online continues to generate efforts to hold someone civilly liable for what the object of a posting believes is false (maybe maliciously false) information. Todd Hollis, for example, is a lawyer in Pittsburgh. He is suing Dontdatehimgirl.com after three anonymous women posted distinctly unflattering comments about his allged behavior in his relationships with them. The site operator, of course, is relying on the provision quoted above -- the CDA section that immunizes the operator of a website, like dontdatehimgirl.com, which merely posts comments published by others.

I could give a number of other examples, some involving respectable websites, others involving more suspect conduct (like a man's pretending to be his former boss and posting an ad in her name -- using her home address, phone number and email address -- on a site where bored wives seek "sexual adventure" with other men). There's really no point, though, because the issues are exactly the same: Someone claims to have been defamed by what was posted online and wants redress (revenge). They can sue the poster (if they can identify him or her, a problem Todd Hollis apparently has in his dontdatehimgirl.com case), but he or she probably won't have enough money to pay the plaintiff's attorney fees. And they can't sue the site operator.

So what disincentive do we have to keep people from defaming others online? It doesn't seem we really have one, at least not unless the poster (i) identifies himself or herself, (ii) is in the same jurisdiction as the victim (which makes suing a much more viable option) and (iii) has enough money to pay a substantial damage award (or at least pay the plaintiff's attorney's fees if he/she wins).This is leading some to call for re-criminalizing defamation. If we were to do that, we would have to be very careful in how we defined criminal online defamation, because of the First Amendment, if nothing else.

Another factor the drafters of the Model Penal Code cited in not criminalizing libel is that defamation -- most of it, anyway -- inflicts a low-level of "harm." They specifically said that the use of the criminal sanction would not be appropriate for those who merely spread "gossip" and rumors. Maybe that factor still applies -- maybe we just have to toughen up and deal with having things that were said behind our backs broadcast to the world . . . . Or maybe not . . . ?

Sunday, September 03, 2006

Child pornography: real and pseudo

As I assume everyone knows, the possession, distribution and/or creation of child pornography is a crime in the U.S. and in many other countries, including the United Kingdom.

I want to talk generally about the criminalization of child pornography, why we have it, what it encompasses, what it does not encompass, etc., but I want to begin with a recent case from the UK.

Stafford Sven Tudor-Miles of Easton, Middlesbrough in the UK, recently pled guilty to (a) five counts of attempting to make indecent pseudo-photographs of children and (b) one count of possessing indecent pseudo-photographs of children.

What did he really do? What he did, and please don’t ask me why, was to scan “photographs of adult porn stars into his computer and used sophisticated digital equipment to reduce the size of their breasts.” I assume the photos had the porn stars engaged in some of their professional activity.


Tudor-Miles’ attorney argued that no crime had been committed because the pictures were really those of adult women. That defense apparently did not work. According to the story in the TimesOnline, under the UK’s “Protection of Children Act 1978, as amended by the Criminal Justice and Public Order Act 1994, a pseudophotograph of a child is defined as an image, whether made by computer graphics or otherwise, which appears to be that of a child.” And UK law treats such an image “as showing a child even if some of the physical characteristics are those of an adult.”

Let’s talk for a minute about how this case would be handled under US law, and then we’ll analyze the result.

Our First Amendment protects speech, except in certain, very limited instances. The Supreme Court recognized, in New York v. Ferber, 458 U.S. 761 (1978), that child pornography is speech within the compass of the First Amendment, but held it can be criminalized for two reasons: One is that children are harmed – physically and emotionally – in the creation of child pornography. The other is that the child pornography is a permanent record of the “harms” inflicted on the children, and this record can remain in essentially permanent circulation. The Supreme Court found that the infliction of these two “harms” overrode First Amendment considerations.

(I often analogize this to the concept of a snuff film. If anyone were idiotic enough to make a First Amendment argument to support the creation and possession of a snuff film, the argument would fail because of the “harm” – the death of a human being – involved in creating the film.)

The Ferber Court was talking about “real” child pornography – child pornography involving the use of “real” children. Computer technology is making it possible, at some level, to create “virtual” child pornography – either by morphing existing images of adults, as Tudor-Miles did, or by using CGI to create the images from scratch. Now, computer technology still is far from the point at which a CGI image is indistinguishable from that of a real person, or a real child, but you can create a good simulacrum.

In 2002, in Ashcroft v. Free Speech Coalition, 535 U.S. 234, the Supreme Court struck down the federal statute that criminalized virtual child pornography. More specifically, the statute made it a crime to create, possess and/or distribute any image “that is, or appears to be, of a child engaging in sexually explicit conduct.” Since “real” children are not involved in the creation of virtual child pornography, the government could not rely on Ferber.

Instead, it said there are two other reasons why virtual child pornography should not be protected by the First Amendment (and can therefore be criminalized): One is that it “whets the appetites” of pedophiles. The other is that pedophiles use child pornography to seduce children into sexual activity. The Supreme Court rejected both.

As to the “whets the appetite” argument, it found this claim was too broad. As the Court noted, the “mere tendency of speech to encourage unlawful acts is not a sufficient reason for banning it.” If that were true, we’d have no Grand Theft Auto, no slasher flicks, no “caper” movies, none of that.

As to the premise that pedophiles use child pornography to seduce children, the Court found that equally unpersuasive. It noted that other things – “cartoons, video games, and candy” – would be at least as effective for this purpose, but we do not ban them. The Court concluded that the government cannot “ban speech fit for adults simply because it may fall into the hands of children.”

Congress quickly adopted another statute, which pretty much does the same thing as the one the Court struck down, but it has not, to my knowledge, been challenged as yet. I think the new statute is unconstitutional for the same reasons the first one was.

Which brings me back to the issue I wanted to raise: Is there any reason to criminalize virtual child pornography, i.e., pornography that appears to involve children engaging in sexual activity but really does not?

Child pornography is by definition not obscene. We have other statutes (which are also, I think, constitutionally problematic) that ban obscene material. Child pornography is material that is not obscene, that would be mere pornography if it involved adults. It has been criminalized for the reasons given in Ferber.

Why, if at all, does it make sense to prosecute and incarcerate Tudor-Miles for making fake child pornography? Why, if at all, would it make sense to prosecute someone who used next-generation computer technology to create what seems to be child pornography but is really just the depiction of activity by computer-generated images?

There’s a case from Canada, that went all the way to the Canadian Supreme Court, which involved “textual child pornography.” Canadian police seized a CD from the home office of a fellow; on it were stories he had written that featured children engaged in sexual activities (with, I believe, adults). He was prosecuted for possessing the stories, ones he had written and that he had not distributed. The Canadian Supreme Court held, basically, that the charge was improper, because nothing “real” was involved – the stories were, as the court said, mere fantasies, the products of his imagination.

So, is virtual child pornography mere fantasy and, as such, something the law should not condem? Or is there a good reason to go after people like Tudor-Miles?

Wednesday, August 23, 2006

Encrypted Hard Drives and the Constitution


I spoke to a group a few months ago about how Customs Officers’ can search the hard drives of laptops carried by one coming into the US or leaving the US.

In my last post I talked about how the border search exception to the Fourth Amendment's warrant requirement lets (apparently, anyway – so far every federal court to address the issue has upheld the application of the exception in this context) the officers do this, and why.

After I did my presentation on that issue to the group, one of the people in the audience came up to me, quite agitated.

He said he handles computer security (in some capacity, I didn’t quite get the context) for a company, the executives of which often travel into and out of the country carrying laptops. He said the laptop hard drives have proprietary information on them, and are therefore encrypted. He was concerned about a Customs Officer’s wanting to see the files on the laptop.


At first, I am afraid I did not take the question that seriously – I told him (which I think is true) that the executives probably are not likely to have their laptops searched (but that was before the recent UK airline bombing plot, so who knows now).

That was a bad answer because it, of course, leaves open the possibility that they might have the laptop hard drives searched. And he, very reasonably, was not happy with that answer, so he pressed for a better one. He made it clear that the concept of giving the officer the encryption key was simply not an option because of the very sensitive nature of the information on the laptops. So we chatted about all this for a bit, and I finally told him his should probably come up with a procedure for this scenario, decide how they would handle it if it arose.


Let’s take the scenario he presented and parse out the options and the applicable law. The Customs Officers have a Fourth Amendment right to search “containers” (which, as I said before, includes a hard drive) when someone is entering or about to leave the country. I’ve run this scenario by prosecutors and based on their reaction and how I analyze the law, it looks to me like the scenario can have three basic resolutions:
  1. The laptop owner gives the Customs Officer the encryption key and the officer searches the laptop’s hard drive for contraband (data within the scope of a border search);
  2. the laptop owner refuses to give the Customs Officer the encryption key, says he/she has decided not to travel that day and walks away with the laptop (the prosecutors I’ve discussed this with say it would work, so we’ll assume it will, at least for now); and
  3. the laptop owner refuses to give the Customs Officer the encryption key and insists on traveling with it, citing some constitutional rule.
The first two options are self-resolving, so let’s focus on the third one.

The problem we have here is that the Fourth Amendment really does not apply to the act of refusing to hand over the encryption key.


(Ironically, it would apply if the laptop owner gives up the encryption key, because this would be consenting either to the “seizure” of the key or to letting the agent “search” it. Or it could be considered to be a waiver of the Fifth Amendment issue we’ll get to in just a moment.)


See, the Fourth Amendment only applies when government agents (like the Customs Officer) DO something . . . like taking your laptop away from you or breaking down your front door to go in and seize it or turning it on and looking through the unencrypted files against your objection. The Fourth Amendment does not apply when, as is the case here, you refuse to do something the government wants you to do and they try to make you do it.


The Fifth Amendment applies, in a very limited way, if and when the government wants you to do a very specific thing: give “testimony” that “incriminates” you.

There is a major difference between the Fifth Amendment and Miranda, which gives you a right to silence and to counsel; the Fifth Amendment, which is supposedly the foundation of Miranda, gives you neither of those things. To qualify for Miranda, you have to be in “custody,” i.e., the police have to have restrained your freedom of movement so you cannot just walk away. Since we’re assuming you can walk away, Miranda won’t apply; the Fifth Amendment is the only option.


The Fifth Amendment only applies, though, if you are “compelled” to give testimony. Being “compelled” is synonymous with being subpoenaed by a court or a grand jury and being ordered to testify; if you won’t, you, a la Judith Miller in Plamegate, will be locked up until you do. That’s being “compelled.”


That brings us to the first problem with trying to use the Fifth Amendment to refuse to give up the encryption key but still travel. It doesn’t seem that you can show you’re being “compelled” to do anything – if you can walk away (as in option #2), then you are not being compelled and the Fifth Amendment is off the table. And there probably are no other constitutional provisions that might apply.


Just for the sake of argument, let’s change things a bit: The laptop belongs to John Doe. He refuses to provide the encryption key when the Customs Officers ask for it and starts to walk away. They say he can go but tell him they’re keeping the laptop because they have probable cause to believe there’s contraband (child porn, say) in it because they have been “tipped” to that by a confidential informant. That should let them hold onto it under another Fourth Amendment exception (exigent circumstances – holding onto the laptop to prevent Doe from destroying the evidence on it) while they get a warrant to search it.


They get the warrant, but find they cannot search the files because the hard drive is encrypted. They call Doe and ask for the key and he says he won’t provide it. They can’t make him do this, so they go to a federal prosecutor who gets a grand jury to subpoena Doe. He appears before the grand jury, is asked for the encryption key, invokes his Fifth Amendment privilege and refuses to provide it.


Can he get away with that? Or will a judge find he cannot claim the Fifth Amendment privilege and lock him up until he gives up the key?


Good question, one that is not resolved.
To claim the Fifth, Doe has to be compelled (being threatened with being locked up works) to give “testimony” that “incriminates” him. Incriminates means the evidence can be used to convict him of a crime; you can’t claim the Fifth because evidence would embarrass you or hurt your business or implicate someone else in a crime. It has to implicate you in a crime.

So, purposes of analysis, we’ll say Doe can show the answer would incriminate him.
Is giving up an encryption key “testimony?” You might think it is, but it’s not that easy.

The Supreme Court has held that “testimony” is a communication; "testimony" therefore does not encompass physical evidence such as blood, hair or even handwriting. You cannot take the Fifth Amendment to refuse to provide samples of your handwriting because the Supreme Court has held that you’re just providing samples of physical evidence – how you shape letters, how much force you exert, etc. (You can’t be put under oath and compelled to write answers to questions asked you because the answers would be communications, or testimony.)


In 1988, in Doe v. United States, 487 U.S. 201), the Supreme Court held that someone cannot take the Fifth and refuse to sign a “compelled consent” because signing the consent form does not constitute “testimony.” The compelled consents (an oxymoron?) were (and are, I assume) used to get into “secret” bank accounts in places like the Cayman Islands.

The person (Doe in this case) was subpoenaed by a grand jury and told to sign a form that gave blanket consent to the bearer (FBI agents) to gain access to any and all bank accounts in his name. A number of people claimed they should not have to do this, that this was “testifying” against themselves (and could leave to the discovery of incriminating evidence). The Supreme Court said it was not testimony, it was just physical evidence – the same rationale as the Court applies to handwriting.


In the Doe case, the Court noted, in effect, that someone (i) cannot invoke the Fifth Amendment and refuse to hand over the key to a “strongbox” or a safe deposit box but (ii) but may be able to take the Fifth and refuse to “reveal the combination to his wall safe – by word or deed.” It depends on whether you are simply handing over physical evidence (like blood or handwriting) or whether you are “being forced to express the contents of your mind” by communicating.

So, basically, whether one use the Fifth Amendment privilege against self-incrimination as the basis for refusing to give up an encryption key depends on whether doing that is more analogous to handing over a key to a safe deposit box or to giving up the combination to a wall safe. (I think the Court was assuming the person had memorized the combination, btw.)


(Oh, and Miranda? Pretty much the same analysis, in that it only applies to “testimony,” to communications. The issue here, as I noted earlier, is “custody.” If the agents took Doe into custody and would not let him leave, then they would have to give him the Miranda warnings and honor his invocation of the right to silence or counsel if he did, invoke, either.)

Sunday, August 20, 2006

TSA Copying Hard Drives? 4th Amendment Issues?


I'm hearing the TSA is copying the hard drives from laptops (some, I assume, not all) that are taken through airport screening.

I'm hearing they're using a pretty simple process, to expedite the copying (which, if true, dealt with my initial disbelief that this is happening -- the problem of how much time it would take to do a true mirror image of many/some of the laptops people bring with them to their flights).

What I'm hearing comes from people I think are credible sources, so I'm going to assume it's true, at least for now.


That brings to the issues which I have been asked about, namely, how can they do this? Isn't this a violation of the constitution? Don't we have a right to privacy in the contents of our laptop data?


Briefly, the answer to the last question is "yes," and the answer to the second question is, I'm afraid, "no."

And that brings us to the first question: How can they do this?
The only constitutional provision that would be implicated is the Fourth Amendment, which protects us from "unreasonable searches and seizures." "Reasonable searches and seizures" are ok. Searches are "reasonable" if they are conducted pursuant to a search warrant OR if they fall within an exception to the warrant requirement.

The TSA agents definitely do not have a search warrant. They must, therefore, be relying on either of two exceptions to the Fourth Amendment's warrant requirement.


One possibility is the border search exception. The border search exception is one of the oldest 4th Amendment exceptions. It lets officers/agents search you, your bags, all that without a warrant AND without probable cause or reasonable suspicion (as you can see from the opinion quoted below). The premise is that governments have the right to control what comes into/out of their border. We are probably all familiar with this in the context of customs searches of luggage when someone comes into (or goes out of -- the exception applies both way) the United States.


I started noting federal court decisions on the appliability of the border search exception to laptops a few years ago. I suspect the issue had never come up until then. The early (2-3 years ago) arguments on this tried to say something courts have found credible in other contexts: That a laptop is a "container," like luggage, but it is a much more complex container than luggage, can contain so much information it should be treated differently . . . basically as a container+.

That argument has worked elsewhere but has failed miserably in the border search context. Courts have done what the 9th Circuit does in the case quoted below, said a laptop is a container like any other container and can be searched by customs agents as such.


I can't find law on TSA searches, but I suspect that the same basic rationale is being applied here OR that these searches are based on another exception, the administrative search exception, which supports DUI checkpoints and airport screening generally.

The "administrative search" exception (which some think is about to swallow the Fourth Amendment) lets the government conduct searches and/or seizures without a search warrant when it is acting for a purpose other than the enforcement of criminal law.
So DUI checkpoints are (the Supreme Court has said) NOT about catching people who are driving drunk just so they can be prosecuted; the checkpoints are, instead, about ensuring safety on our highways by discouraging drunk driving.

The same thing holds for airport screening: When we go through the metal detectors and have our luggage screened it's not because the agents are trying to gather evidence to be used to convict us -- each of us -- of a crime. It is, instead, for a different, administrative purpose -- air travel.


Now, I wonder how and why checking the contents of someone's hard drive contributes to that administrative function. If and when this comes up in court, it seems to me that the person whose laptop hard drive was searched can argue that the search was unreasonable in scope, i.e., that copying and seachng the data on someone's hard drive is not sufficiently related to maintaining airport security to bring it within the scope of the adminstrative search exception.


One more point: Copying someone's hard drive is, I think, a "seizure" not a "search." Searches violate privacy, while seizures violate possessory interests. Since they don't actually "read" the files when they make the copy, there is no compromise of privacy, no "search." I'd say, though, that there is definitely an interference with possessory interests because (a) the laptop is taken away and "held" while the copy is made and (b) the government "takes" the copy, which means you no longer have exclusive possession and control of the data on the hard drive.


Ninth Circuit border search exception case:


First, we address whether the forensic analysis of Romm's laptop falls under the border search exception to the warrant requirement. We review the legality of a border search de novo. United States v. Okafor, 285 F.3d 842, 845 (9th Cir.2002). Under the border search exception, the government may conduct routine searches of persons entering the United States without probable cause, reasonable suspicion, or a warrant. See United States v. Montoya de Hernandez, 473 U.S. 531, 538, 105 S.Ct. 3304, 87 L.Ed.2d 381 (1985).


For Fourth Amendment purposes, an international airport terminal is the "functional equivalent" of a border. See Okafor, 285 F.3d at 845 (citing Almeida-Sanchez v. United States, 413 U.S. 266, 272-73, 93 S.Ct. 2535, 37 L.Ed.2d 596 (1973)). Thus, passengers deplaning from an international flight are subject to routine border searches. . . .


We assume for the sake of argument that a person who, like Romm, is detained abroad has no opportunity to obtain foreign contraband. Even so, the border search doctrine is not limited to those cases where the searching officers have reason to suspect the entrant may be carrying foreign contraband. Instead, " 'searches made at the border ... are reasonable simply by virtue of the fact that they occur at the border.' " United States v. Flores-Montano, 541 U.S. 149, 152- 53, 124 S.Ct. 1582, 158 L.Ed.2d 311 (2004) (quoting United States v. Ramsey, 431 U.S. 606, 616, 97 S.Ct. 1972, 52 L.Ed.2d 617 (1977)). Thus, the routine border search of Romm's laptop was reasonable, regardless whether Romm obtained foreign contraband in Canada or was under "official restraint."


United States v. Romm, --- F.3d ----, 2006 WL 2042827 (Ninth Circuit Court of Appeals, July 24, 2006).

Friday, August 18, 2006

NSA Surveillance Held Unconstitutional


As everyone probably knows by now, Anna Diggs Taylor, a federal judge in Detroit has held that the NSA surveillance program is unconstitutional and therefore unenforceable. See ACLU v. NSA, U.S. District Court - Eastern District of Michigan).

The implementation of the decision has been stayed, to give the Department of Justice time to appeal the ruling. (I hope it’s an expedited appeal.)

The judge held that the program violates the First Amendment, as well as the Fourth Amendment (and is illegal for other reasons, as well, including the separation of powers doctrine). I don’t even want to try to summarize the entire decision here, as you can read it online if you are so inclined.

Instead, I want to comment briefly on her Fourth Amendment analysis . . . which was also brief. After tracing the history and purpose of the Fourth Amendment – which is to preserve privacy against government intrusions, especially in our homes and other important enclaves -- she concluded that the NSA wiretapping program has “obviously” been implemented “in violation of the Fourth Amendment.”

At the end of her opinion, she explains that none of the justifications the Administration has offered for the current surveillance program – e.g., that the threat of terrorism makes it impracticable to apply for and get wiretapping warrants – have any merit. As she said, the government’s argument as to “the need for speed and agility is . . . weightless.”


She also found that the program has been implemented in violation of the FISA (Foreign Intelligence Surveillance Act) statutes, which impose special requirements when federal agents are investigating terrorism and related activities (versus plain old “crime”). And she found that it violates Title III, a set of statutes which Congress adopted in 1968 to implement the Katz decision, the one I mentioned in an earlier post; Katz is important in this context because in Katz the Supreme Court held that wiretapping the content of phone conversations is a “search” under the Fourth Amendment, and so cannot constitutionally be done unless the government gets a search warrant beforehand.


I think Judge Taylor’s opinion is very well-reasoned and reaches the correct result. No one can argue against the need to prevent terrorism, but the government cannot use the threat of terrorism to bypass constitutional procedures that were created to guarantee us certain fundamental rights. If we allow that, we effectively surrender those rights.

Wednesday, August 16, 2006

Cybercrime treaty: criticisms

Earlier this month, the Senate finally ratified the Council of Europe's Convention on Cybercrime. Since the United States signed the Convention almost five years ago, this means it has now gone into effect for this country (along with other countries that have ratified it).

As I noted in an earlier post, it took the U.S. a surprising long time (almost five years) to ratify the Convention on Cybercrime. The amount of time it took was surprising given (a) that we helped write it and very much lobbied for its adoption and (b) that because we helped write it, we do not need to adopt any new legislation to implement the treaty. The delay was due to concerns that have been expressed by EFF, EPIC and the ACLU, among others.


Basically, these concerns center on three issues, each of which I am going to address, briefly, in this post. I’m going to address them in the order they crop up in the Convention.

The first issue is the “misuse of devices” issue. Article 5 of the Convention requires countries that sign and ratify it to criminalize “the production, sale, procurement for use, import, distribution or otherwise making available of” either (i) “a device, including a computer program, designed or adapted primarily for the purpose of committing any of the offences established in accordance with” Articles 2-5 of the Convention or (ii) “a computer password, access code, or similar data by which the whole or any part of a computer system is capable of being accessed.” A separate provision makes the possession of such items a crime. Articles 2-5 require parties to criminalize, basically, unauthorized access and unauthorized access with damage to a system or the data it contains. All of the provisions of Article 5 require that the item be possessed, imported, distributed, etc., with the intent that it be used in the commission of one of these crimes.

Those who are concerned about this argue that the provision sweeps too broadly, that it could be used to prosecute researchers or simply the average citizen who happens to be in possession of an item encompassed by Article 5. The drafters of the Convention and the U.S. Department of Justice respond that these “innocents” do not need to be concerned because the provision requires not simply possession/distribution/etc. but also that the person have engaged in this conduct with the intent to facilitate the commission of a crime. I think that is a very good point. My concern, there, would be that intent is often inferred in cases like this (which are essentially aiding and abetting cases), and inferences of intent can be expansive and sometimes problematic.

The second issue, which I will only summarize because it would take a LONG time to go through all of its aspects, is that the provisions of the Convention which provide for cooperation among law enforcement officers of various countries (i) threaten privacy and (ii) sweep too broadly. As to (i) I will only say that the Convention clearly reflects the current state of our Fourth Amendment law, which is good and not-so-good. The basic Fourth Amendment requirements are fine in most respects but, I think, inadequate in others (especially when it comes to obtaining traffic data, i.e., non-content data involved in the transmission of email and other electronic communications).

As to (ii), the concern lies with Article 14 which says, essentially, that the provisions establishing mechanisms for reciprocal law enforcement cooperation apply when police are investigating (a) crimes defined under the Convention; (b) “other criminal offences committed by means of a computer system;” and (c) “the collection of evidence in electronic form of a criminal offence.” They therefore can apply to the investigation of ANY crime as long as a computer was involved in its commission. On the one hand, I can see law enforcement’s position: If police are investigating a crime and digital evidence is involved, why should it matter if the crime can be technically defined as a “cybercrime?” Shouldn’t they be able to proceed anyway? On the other hand, I can see the critics’ issue. This is, after all, styles as a “cybercrime” convention, so it seems logical, at least, that it should be limited to cybercrimes, i.e., crimes in which the computer plays a central role in the commission of the offense.

Now to the third issue, which is probably the source of most criticism of the Convention. The argument here is that the procedural provisions facilitating cooperation among law enforcement do not require “double criminality.” As I noted in an earlier post, extradition treaties – treaties that let the U.S. hand Perpetrator X over to Brazil to be prosecuted for a crime committed in that country – require “double criminality,” i.e., require that the act have been a crime in both countries. The premise is that to do otherwise would be unfair. There has, for example, been a gentleman in Nebraska who has for years been putting up pro-Nazi websites. It is a crime to create such a website in Germany, and over the years German authorities asked U.S. authorities to turn this guy over to them for prosecution. U.S. authorities properly refused to do so, because what he is doing is protected speech under our First Amendment. We can’t turn him over to be prosecuted for what he is lawfully doing here.

Critics of the Convention argue that it does not have a “double criminality” provision that acts as a restraint on its law enforcement cooperation measures, and I would agree . . . no such provision is explicitly included in the Convention. (It is in Article 24, which governs extradition.) I do not think, though, that this is a major problem because Article 15 says that each party to the Convention must:

ensure that the establishment, implementation and application of the powers and procedures provided for in this Section are subject to conditions and safeguards provided for under its domestic law, which shall provide for the adequate protection of human rights and liberties, including rights arising pursuant to obligations it has undertaken under the 1950 Council of Europe Convention for the Protection of Human Rights and Fundamental Freedoms, the 1966 United Nations International Covenant on Civil and Political Rights, and other applicable international human rights instruments, and which shall incorporate the principle of proportionality.

As far as the U.S. is concerned, this imports our Bill of Rights, which guarantees due process which should, aside from anything else, prevent our law enforcement processes from being used to persecute dissidents in other countries. There’s also the fact that if someone in the U.S. is being investigated by a country for being a political dissident, and U.S. authorities assist with the investigation, that person cannot be extradited from the U.S. (even under the Convention) because it requires double criminality for extradition.

There are other issues that arise under the Convention, and maybe I’ll post on them later.

Bottom line: it’s far from perfect but it is, I believe, far from being as horrendous as some claim.

Sunday, August 06, 2006

Computer car theft


You may have heard about this. Several stories appeared earlier this summer about thieves using laptops to steal cars equipped with keyless entry and ignition systems.

According to some of these stories, David Beckham, the British soccer star, has had two BMW X5’s stolen from him this year. In each case, the thieves used the laptop technique to take the cars. The second theft apparently occurred while Beckham and his sons were eating at a restaurant in Madrid.


This is a good example of how beneficial technology can be compromised for criminal purposes. As one reporter explained, “decrypting one 40-bit code sequence can not only disengage the security system and unlock the doors, it can also start the car. . . . The owner of the code is now the true owner of the car.” I’ve read that thieves can also disable tracking systems – GPS systems – that are intended to make it easier to find stolen vehicles.


As far as I know, this is only happening in Europe, where it is becoming more common. It probably won’t take long, though, for it to migrate here to the U.S.

The process of compromising the vehicle’s entry and ignition systems apparently takes about 20 minutes, and I gather the thieves need to have the vehicle parked in a relatively out of the way place . . . since people might be suspicious if they walked by and saw a laptop hooked up to a parked car.


Does this kind of theft raise any new legal issues?
I really don’t think it does, at least not in terms of the theft of the vehicle. All the thieves are doing, after all, is stealing a car, and car theft has been criminalized in this country and abroad for many, many years.

I think our existing car theft statutes would easily encompass this kind of activity. Take Alaska’s car theft state, for example. Alaska Statutes section 11.46.360(a) It makes it a crime (a felony) if “having no right to do so . . . [a] person drives, tows away, or takes the car, truck, motorcycle, motor home, bus, aircraft, or watercraft of another”. Most car theft statutes will be structured similarly.

The essence of the crime lies in taking a vehicle that belongs to someone else; the method one uses to accomplish that is irrelevant. So it really doesn’t matter whether the thief uses a Slim Jim or a laptop.


It seems to me, though, that a prosecutor could also add a “hacking” charge.

As I explained in an earlier post, in terms of criminal law “hacking” consists of gaining access to computer system without being authorized to do so. As I also noted in response to a comment on that post, we have aggravated hacking (or cracking) statutes that make it a more serious crime to hack a system and cause “damage” by, say, copying or destroying data.
It looks to me like the laptop car thief “hacks” the car’s computer system.

As I explained in that earlier post, our law doesn’t do a particularly good job of defining “access” in the context of “hacking,” but I think a prosecutor could make a good argument that a laptop car thief does gain “access” to the car’s computer system. As I noted earlier, one of the phrases used to define “access” is “communicate with,” as in “communicating with” a computer system. Another phrase used for this purpose is “make use of,” again as in “making use of” a computer system.


If you buy that analysis, then it seems laptop car thieves can be charged both with car theft and with hacking the car’s computer system. Now, they might argue that hacking the car’s computer system was merely part of the process of stealing the vehicle, so they should not be charged with both crimes. I suspect that argument would not work.

One of the defining traits of modern American criminal law (anyway) is that prosecutors tend to carve a course of conduct up into multiple offenses, a technique courts generally support. The premise – in this instance – would be that the thief really did commit two distinct and severable crimes: (i) hacked the car’s computer system; and (ii) stole the car. A prosecutor who wanted to charge such a thief with both crimes could point out that he could have stopped with (i) but, instead, chose to proceed with the “second” crime, the theft.


Legal issues aside, this is another example of how technology we adopt to make our lives easier can have unforeseen, unfortunate consequences.