Friday, March 20, 2009

Robbery

We were talking about online theft in a class, and that led me to think about robbery. Specifically, I started thinking about whether it is possible to commit robbery online.

To understand why that may be an issue, you need to know a little bit about the law of theft: Centuries ago, English common law developed a crime called larceny. Larceny consisted of “taking another’s property from his possession without his consent, even though no force was used.” Lee v. State, 59 Md.App. 28, 474 A.2d 537 (Maryland Court of Appeals 1984). To constitute larceny, the person taking another’s property also had to do with the intent to steal, i.e., with the intention to deprive the rightful owner of the possession and use of his/her property.

As I explained in an earlier post, common law later developed a related crime called “larceny by trick.” It needed the new crime to deal with situations in which I persuade you to give me your property by lying to you (telling you you’re buying a bold mine, say). In that situation, I clearly get your property wrongfully, and I implicitly have the intent to steal (to keep the money for myself, thereby depriving you of its possession and use), but I didn’t take it from you without your consent. We still have the larceny by trick crime though, as I noted in an earlier post, we call it “fraud.” And as I’ve explained in other posts, you can commit fraud online; indeed, cyberspace makes it even easier to commit lots and lots of fraud.

You can clearly commit larceny – or, as we usually refer to it, theft – online. In 1994, Vladimir Levin, a Russian working as a computer programmer for AO Saturn, allegedly hacked into the accounts of Citigroup customers and transferred millions of dollars into accounts controlled by him and his cohorts. That kind of online activity is clearly theft: You’re taking the rightful owner’s property without his/her consent with the intent to steal it; we could arguably have an issue as to whether the property was taken from the owner’s possession, but that element isn’t particularly important in modern theft laws. It’s theft if you steal my car from a parking lot while I’m in a restaurant, for example. The Model Penal Code, which is a basic template of criminal laws, defines theft as unlawfully taking “movable property of another with purpose to deprive him thereof.” Model Penal Code § 223.2. The MPC doesn't require that the property have been taken "from" the owner; it simply requires that you take property you know belongs to someone else to deprive him/her of it (not, for example, to borrow it with the owner's permission.)

I also did a post on a kind of theft that can only occur online: non-zero-sum theft as opposed to the zero-sum theft in my example above. In zero-sum theft, the possession and use of the property is transferred entirely from the rightful owner to the thief, so the owner is completely deprived of the possession and use of the property; in non-zero-sum theft, the thief acquires some quantum of the possession and use of the property. As I noted in an earlier post, copying a company’s password file from one of its database is an example of non-zero-sum theft; the company still has the passwords, but the thief has them, too. And the fact the thief has them deprives the company of some quantum of the value of the passwords; they can still be used, but they can’t be used with any confidence that the accounts they control are secure.

That brings me back to robbery. Common law defined robbery as “the . . . forcible taking from the person of another any goods or money . . . by violence or putting in fear.” State v. Campbell, 41 Del. 342, 22 A.2d 390 (Delaware Supreme Court 1941). Robbery is an aggravated theft crime because it involves using force or violence or the threat of force or violence to induce someone to give up possession of his/her property. Robbery is also defined as larceny committed by violence of intimidation. The Model Penal Code defines it a little differently:
A person is guilty of robbery if, in the course of committing a theft, he:

(a) inflicts serious bodily injury upon another; or
(b) threatens another with or purposely puts him in fear of immediate serious bodily injury; or
(c) commits or threatens immediately to commit any felony of the first or second degree.
Model Penal Code § 222.1(1). The first two options under the Model Penal Code provision retain the common law requirements, but the Model Penal Code adds the third option – committing or threatening to commit a serious felony.

I can’t find any cases dealing with the third option, but the logic is that I can commit robbery by hurting you, by threatening to hurt you or by threatening to hurt someone (rape or murder) or something (arson) you care about. And if you’re wondering why the third option doesn’t constitute extortion (which is actually another kind of theft crime), here’s the reason: In robbery, I use the threat to commit a serious felony against you or something/someone you care about to force you to give me the money or property I’m after against your will; in extortion, the theory is, I use a similar threat, but you give me the property willingly (with your consent). You weigh the options and decide to give in, which makes it extortion not theft.

Let’s get back to robbery. I’m not sure that robbery in the traditional sense – the forcible taking of property from someone by using or threatening violence – can be committed online. As to the first option, I can’t think of a scenario – using current technology – in which you could inflict bodily injury on someone to get them to hand over their property. Since I don’t see how you can inflict serious bodily injury in the online context, I also don’t see how you can use the threat of such injury to commit robbery (at least not, again, using current technology . . . all this might be possible someday).

That brings us to the third, Model Penal Code option: Using the threat to commit a serious felony (e.g., rape, murder, arson) to coerce someone into handing over their property. I can certainly see that part of the dynamic would work online: I can send you a threat to burn your business or home, say, to coerce you to give me your money. The problem I have with taking this scenario to the next step, which is where it would become robbery, is the “immediately” requirement. Remember, robbery consists of using force or the threat of force to take the property or money from the person at that moment; it’s not intended to be a long, drawn-out process, which is what it seems to me it has to be online.

So far, anyway, I’m pretty sure that robbery in the strict legal sense cannot be committed online . . . .

Wednesday, March 18, 2009

Juror Misconduct and Technology

This post is about the that effect technology is having on what is called juror misconduct. As I explain below, juror misconduct is the term that is used to refer to actions by jurors that are at least arguably inconsistent with their role in a criminal trial.

The U.S. Constitution and the Sixth Amendment to the U.S. Constitution create a right to trial by jury in criminal cases.

Article III of the Constitution says, in part, that the “Trial of all Crimes . . . shall be by Jury”. The Sixth Amendment says, also in part, that "In all criminal prosecutions, the accused shall enjoy the right to a speedy and public trial, by an impartial jury of the state and district wherein the crime shall have been committed."

The Seventh Amendment to the Constitution creates a right to jury trial in civil cases, but we’re only concerned with criminal cases.


The Sixth Amendment right to trial by an impartial jury not only means that the jurors are not supposed to be biased, i.e., not supposed to have a reason to lean either toward the prosecution or defense. It also means that they’re to play a very passive role in the trial.

As you’ve no doubt seen on TV and in movies (and maybe in real-life if you’ve ever sat in on a trial), the jurors sit and listen to what goes on until both sides have put on all of their evidence and each side has made its closing argument to the jurors. Before the closing argument, the trial judge will “instruct” the jury on the law; that is, the judge will summarize for the jury the basic law governing their functions (e.g., presumption that the defendant is innocent, prosecution must prove guilty beyond a reasonable doubt) and the specific law governing the crime(s) with which the defendant is charged.

So really what trial jurors do during trial is listen: They listen to the judge, they listen to the lawyers, they listen to the witnesses, and then they go off on their own (retire) to decide whether the prosecution has proven its case or not. Every once in a while, a juror or set of jurors will decide they should take a more active role in the case by, say, conducting their own investigation or experiments or using a dictionary to look up terms they think the judge didn’t define well enough.

The jurors may think they’re doing the right thing by trying to be as meticulous as possible, but in fact they’re violating the requirement that they be impartial. As I noted, the requirement of impartiality means that the jury ONLY decides the case on the basis of evidence that was introduced in court. As a Pennsylvania court explained,
[w]hen jurors conduct their own experiments . . ., the result is the introduction of facts that have not been subject to the rules of evidence or to cross-examination by either party. This is broadly defined as juror misconduct. However, when allegations of misconduct arise, it is the responsibility of the trial court to determine if the misconduct resulted in a reasonable possibility of prejudice.
Pratt v. St. Christopher’s Hospital, 581 Pa. 524, 866 A.2d 313 (Pennsylvania Supreme Court 2000). This was a civil case, but the same principle applies in criminal cases.

Technology has made juror misconduct a more common issue than it used to be. It used to be that to conduct their own investigations jurors had to go to the crime scene or to the library or otherwise take affirmative action in the real-world outside the courtroom. Now, though, they can use the Internet to look up information.

In a Massachusetts case, for example, the defendants were charged with trafficking in cocaine. Commonwealth v. Rodriguez, 63 Mass.App.Ct. 660, 828 N.E.2d 556 (Massachusetts Court of Appeals 2005). After the both sides had produced all their evidence and made their closing arguments, the judge instructed the jury on the law and they began deliberating. After a while the foreperson sent a note to the judge saying it looked like they were deadlocked; the judge told them to keep going, but after a while the foreperson sent out another note. The judge again told them to keep going.

After a while, the foreperson sent the judge a note that said, in part, “`“Your Honor, we have come up against a wall under Chapter 234, Section 26(b)’” of the Massachusetts statutes. Commonwealth v. Rodriguez, supra. That surprised the judge because she hadn't instructed the jurors on that statute; she therefore needed to find out what was going on. The judge told the prosecution and defense lawyers what had happened, and held a hearing on the issue. The judge asked the foreperson “how she had obtained that citation” to the statute. The foreperson said Juror 14 was responsible. The judge brought Juror 14 to the courtroom, asked what had happened and
the juror explained that he had found the citation to the statute when he went `looking on the [I]nternet to see what laws were about jurors and jury duty and how it deals with a hung jury possibly.’ The juror assured the judge he had found only that one statute. He further explained that he had brought it in with him that morning and the jurors `brought it up’ while they were in the jury room. The judge informed the juror that she did not want to know about deliberations and allowed the juror to return to the jury room, but told him not to discuss their conversation.
Commonwealth v. Rodriguez, supra. The defendants moved for a mistrial based on what Juror 14 had done, but the court denied the motion. The defense’s concern was probably that the statute Juror 14 found might have encouraged the jury to convict when it would otherwise not have done so.

The defendants raised the issue on appeal, claiming the trial court should have ordered a mistrial and given them a new chance for an impartial jury. The Massachusetts Court of Appeals agreed with them. It noted that the statute in question
addresses impaneling, sequestering,and discharging jurors and is therefore procedural in nature. As such, it bears no direct relationship to the evidence admitted at trial, to any of the live substantive issues, or to the elements of the offense with which the defendants were charged.

That being said, it was researched by one juror concerned about the deadlock, and its introduction into the deliberations signaled that the jury may have been trying to remove a dissenting juror. The jury's uninstructed consideration of the statute reinforces our conclusion that the verdicts cannot stand.
Commonwealth v. Rodriguez, supra. The Court of Appeals therefore reversed the convictions and set aside the verdicts.

On a less serious note, I’ve found a few cases involving claims of juror misconduct based on texting jurors. In People v. Fulgham, 2008 WL 4147562 (California Court of Appeals 2008), a defendant who was convicted of possessing a controlled substance appealed, arguing in part that his conviction should be reversed because one of the jurors “committed misconduct by text messaging through the trial . . . instead of listening to the testimony.”

Two days into Fulgham’s trial, a juror told the court’s bailiff that Juror 10 was text-messaging during the trial. The bailiff told the court and the next morning the judge brought Juror 10 into court and questioned her outside the presence of the other jurors:

`THE COURT: Ma‘am, . . . it's been brought to the Court's attention . . . that during the course of this trial . . . you had been texting messages on your cell phone?

JUROR [10]: Oh, yeah, I did text message one time. Are we not allowed to do that?

THE COURT: Ma‘am, you are required to pay attention to everything that goes on in here without any distraction of any kind.

JUROR [10]: Okay.

THE COURT: Further, I hope that you have not been texting any type of message in terms of what's been going on with this trial.

JUROR [10]: Oh, no, I haven't. I know that we're not supposed to talk about anything with anyone, so.

THE COURT: All right.
The judge asked the prosecutor and defense attorney if they wanted to question Juror 10, but both declined. On appeal, the Court of Appeals held that the defense attorney’s failure to question the juror “waived any claim of error in the trial court's investigation and decision to retain Juror No. 10.” People v. Fulgham, supra. The court also upheld the judge’s keeping Juror 10 on the jury because she told the “trial court she only sent a text message one time and that it was unrelated to the trial.” People v. Fulgham, supra.

These are simple juror-misconduct-involving-technology cases. Things were much more complicated in the very high profile case of U.S. v. Siegelman, 2007 WL 1821291 (U.S. District Court for the Middle District of Alabama 2007). After Siegelman was convicted, the defense filed a motion with the court asking it to conduct an investigation into the
authenticity of Exhibits 10, 11, 12, 13, and 15 and . . . 23, 24, and 26. As part of that investigation, Defendants would have this Court review data contained on the computer hard drives of computers used by the . . . . Siegelman requests this Court to order Juror 7 and Juror 40 to produce all hard drives, Blackberries, cell phones, or any other device capable of sending email or text messages that they used during the course of this trial. . . . [and] order Juror 7 and Juror 40 to disclose to the Court all internet service providers, email providers, and cell phone companies that provided email, text messaging or cell phone services to them during the trial.
U.S. v. Siegelman, supra. The federal judge denied the motion both because it said it had already conducted an extensive investigation into the jurors’ conduct in the case and because
[n]o court has ever held that a court's obligation to investigate extends that far. The Court does not believe the absence of such legal holdings has anything to do with the law having failed to develop as quickly as technology has evolved. The Court believes sound policy considerations are the reason that the law has not required such fishing expeditions. Such a holding would potentially destroy the jury system in this nation.
U.S. v. Siegelman, supra.

Monday, March 16, 2009

More Absurdity

Last fall, I did a post about a case in which a prosecutor refused to attach images of child pornography to an application for a search warrant because he said he was afraid he’d be prosecuted for “distributing child pornography” if he did. The U.S. Court of Appeals for the Seventh Circuit said this was a very strange thing for the prosecutor to do, since he would be attaching the images to an application being filed with the court as part of the official process of seeking a warrant to search for evidence of a crime. U.S. v. Griesbach, 549 F.3d 654 (7th Cir. 2008).

That prosecutor’s behavior may seem strange, but in a sense it’s the logical outcome of a view that has become increasingly popular and that, as I noted in the post I did last fall, resulted in Congress’ adopting the Adam Walsh Child Protection and Safety Act of 2006, Public Law No. 109-248 § 504, which went into effect on July 27, 2006. As I explained in another post I did last fall, the Act was codified as 18 U.S. Code § 3509(m).

Section 3509(m) says that in federal cases, the court is to deny “any request by the defendant to . . . copy . . . any . . . material that constitutes child pornography”, even when the defense wants the material to have it examined by its own expert witnesses. As I noted in that post, this is important because virtual child pornography – computer generated child pornography – is not a crime. So if a defendant shows that what he or she possessed was child pornography that was created digitally, and did not involve the victimization of real children, then he/she should be acquitted on all charges.

This brings me to a recent case from Tennessee: State v. Allen, 2009 WL 348555 (Tennessee Court of Criminal Appeals 2009). The defendant in the case – Reĺicka Allen – was charged with possessing child pornography a computer technician discovered on Allen’s computer after he took it in to be repaired. State v. Allen, supra. The technician told the computer store manager what he’d found, the manager called the police and Mr. Allen was charged with possessing child pornography. State v. Allen, supra.

Allen filed a motion asking for a copy of the hard drive so that his expert could examine it. The prosecution refused, but offered to let the expert examine the hard drive at the Sheriff's Department. Allen then asked the court to compel the prosecution to give him a copy of the hard drive. The court held a hearing on issue, and Allen’s expert explained why he needed a copy of the hard drive:
Herbert Mack . . .described . . . the . . .programs and viruses by which material can be both deliberately and inadvertently downloaded into a computer and estimated it would take him approximately one week of intensive twelve-to fourteen-hour days to complete an examination of [the] hard drive. He testified he would probably require the assistance of support personnel from his office and, in addition, would need to consult regularly with counsel with respect to whether any sexually explicit files he found on the computer qualified as child pornography. He said that, given the large number of images allegedly contained on the computer, he would not be able to remember the specifics of the information without taking the computer hard drive from the sheriff's department.

Mack expressed concern about working from a `mirror image’ rather than the hard drive itself, testifying that the programs in existence did not create true mirror images:

A. . . . . If what you're going to give me is a mirror image, my concern there is that I'm not getting all of the data that's there.

Q. And why is that? If it's a mirror image wouldn't you just get everything that's in the mirror?

A. No, sir.

Q. Why not?

A. A mirror image is a misnomer, okay. The computer programs that you have right now, okay, are for the purpose of recovering good data. Okay. So if a file has been ordered damaged or erased it's not going to be on the image. . . .

Mack testified that the risk of transmitting inaccurate information was high if defense counsel was dependent upon Mack to tell [him] what he had seen on a . . . disk image. Mack stated that there was an increased risk of disclosing non-discoverable information because the State's expert would be able to determine what tools had been run on Defendant's computer hard drive and what information had been recovered before Defendant was obligated to disclose its expert report. Mack also stated that Defendant would have no choice but to involuntarily disclose information that was not subject to discovery and that Defendant did not intend to use at trial.
State v. Allen, supra.

After the hearing, the trial court issued a protective order requiring the prosecution to give Allen’s expert a copy of the hard drive. The prosecution refused. Allen filed a motion to suppress the evidence, in effect as a sanction for the prosecution’s refusal to comply with the court’s order. State v. Allen, supra. Instead of granting the motion to suppress, the trial court issued a second order requiring the prosecution to give Allen’s expert a copy of the hard drive. State v. Allen, supra.

The prosecution appealed that order to the Tennessee Court of Criminal Appeals, which upheld what the trial court had done: “We find these orders reasonable and appropriate, especially given [Defendant's] computer expert's testimony with respect to the extensive and exhaustive work entailed in his examination of [Defendant's] computer hard drive. Accordingly, we conclude that the trial courts did not err in granting Defendant['s] motion to compel the production of the evidence.” State v. Butler and Allen, 2005 WL 735080 (Tennessee Court of Criminal Appeals 2005).

The prosecution still refused to comply, so Allen filed another motion to suppress the evidence. The state filed a motion saying it could not comply without violating § 3509(m). State v. Allen, supra. The trial court denied the motion because it found that nothing in Tennessee law prevented it from ordering that Allen’s expert be given a copy of the hard drive. The prosecution filed another claiming § 3509(m) prevented it from complying with the order; Allen’s attorney filed a brief pointing out that other courts had found that § 3509(m) doesn’t bind state courts. (It’s a federal statute, after all.)

The state filed a motion asking the court to reconsider and at the hearing on that motion the prosecutor told the trial court he had contacted the local U.S. Attorney’s office and
`disclosed that a copy of the mirror image of the hard drive would be provided to defense counsel and their experts. The State informed the court that defense counsel, any defense expert, as well as court staff and others could be at risk of federal prosecution for possession of child pornography in violation of the Adam Walsh Act if the discovery material was turned over to Defendant.’
State v. Allen, supra. The prosecutor threatened the judge with § 3509(m) to try to get him to deny the request for a copy of the hard drive. After they had an exchange in which the prosecutor pretty much made that clear, the court ordered that the hard drive be suppressed because the defense counsel and expert were “totally chilled from being able to evaluate their own-evaluate the evidence against them.” State v. Allen, supra. The prosecutor then said the judge was effectively dismissing the charges and basically asked the judge to do so formally, so he could appeal the decision. The judge did.

On appeal, the Court of Criminal Appeals held that § 3509(m) “does not apply to proceedings in Tennessee state courts.” State v. Allen, supra. It also noted that it had
been unable to find a single state or federal criminal prosecution of defense counsel anywhere in the country based on counsel's possession of child pornography as part of a state's discovery procedures. We think the likelihood of federal prosecution of defense counsel in this case for possession of child pornography is remote at best and did not justify the suppression of evidence and dismissal of the prosecution of Defendant.
State v. Allen, supra. The Court of Criminal Appeals noted that while it understood the trial court’s frustration with the prosecutor’s “persistent refusal . . . to comply with court orders”, the court should have used its power to hold the prosecutor in contempt to deal with the problem. State v. Allen.

Needless to say, I think things are really getting out of hand when it comes to dealing with child pornography evidence.

Friday, March 13, 2009

Prescriptive rules

I’ve done a couple of posts on the “insider” issue: the problem of defining when someone who is authorized to access a computer system exceeds the permissible bounds of that access and therefore becomes subject to criminal liability.

As I explained in a post I did earlier this year, the problem arises because the crime these “insiders” are prosecuted for is called “exceeding authorized access.”


The problem, as I explained in that and other posts, comes in defining how the “insider” knew that he or she was exceeding the scope of their authorized access. It's a basic premise of criminal law that you can’t be prosecuted for a crime unless you intended to commit the crime (I purposely exceed my authorized access to my employer’s computer system) or at least knew you were committing the crime (I know I’m exceeding my authorized access to my employer’s computer system but I’m going to do it anyway). In other words, you must have been put on notice as to what is permitted and what is not when it comes to using that computer system.

The problem criminal law has had with this crime is one of line-drawing. You have a trusted employee who’s authorized to use the computer system for certain purposes, like an IRS customer service representative who’s authorized to use the system to look up information (tax return filings, refunds, etc.) in order to answer questions from the taxpayers who contact the office. Assume the IRS agent uses the system to look up friends, his fiance’s father and a number of other people; that use is, as a matter of common sense, completely out of bounds. The IRS agent is, in effect, off on a virtual frolic and detour. “Frolic and detour” is a term the law uses to refer to the situation in which an employee briefly abandons carrying out his employer’s business to run an errand or do something else personal; a delivery driver who makes a detour to visit his girlfriend would be an example of frolic and detour.

So in my hypothetical, we all know as a matter of common sense that the IRS agent went on a virtual frolic and detour and, in so doing, exceeded the bounds of his authorized access to the IRS system. But common sense won’t work for the law; the law has to be able to draw a reasonably clear line. So the law has to be able to define what “exceeded authorized access” means with enough precision to put people on notice as to what they can, and cannot, do.

The problem, as I’ve noted before, is that it can be really difficult to do that in practice. I did a post earlier this year about a corporate Vice President who used his employer’s computer system to collect information the VP could use when he went out on his own. As I noted in my post, the court held that the VP did not exceed authorized access to the system because he was allowed to use it to look up the information at issue.

Some, as I may have noted, think the solution to the problem of defining the crime of exceeding authorized access lies in code; they say employers should simply use code to lock people into permissible use zones. If you’re somehow able to get around the limits on your permissible use zones, the efforts you made to do so would inferentially establish your intent, i.e., you knew you were exceeding authorized access and intended to do just that. (And if you weren’t able to get around the limits, there’d be no exceeding authorized access, which I think is the real point.)

The other theory is the contract theory, which I’ve written about before. It’s the one I was referring to above, when I talked about employer policies that tell you what you can and cannot do. The problem with that – as I wrote in a post earlier this year – is that it can be very difficult to come up with workable policies that do this.

I did a post earlier this year suggesting an alternative approach: making it a crime to misuse authorized access instead of exceeding authorized access. I still like that idea but I have a student who’s doing an independent study on this general issue, and as we were discussing the problem last week, I came up with another approach. I’m going to outline that approach and I’d be interested in any comments you might have on it.

We were talking about the central problem in defining the crime of exceeding authorized access: drawing a clear line between what is and is not permissible. My problem with that approach is that it essentially relies on prescriptive rules.

Law uses two kinds of rules: prescriptive rules (do this) and proscriptive rules (don’t do that). Prescriptive rules tend to be civil in nature; we have lots of regulatory rules that are prescriptive rules. Proscriptive rules tend to be criminal in nature; the structure of a statute that defines a crime is prohibiting certain behavior and/or certain results, such as causing the death of a human being. The distinction between the two types of rules isn’t perfect; categories sometimes blur in law, for various reasons (such as the facts that it’s concerned with practical matters and legislators sometimes are not masters of statutory construction). But it exists, and it’s a good conceptual model for thinking about the exceeding authorized access problem.

I see the contract-line-drawing approach to the problem as relying on prescriptive rules. In this approach, it’s basically up to the employer to develop rules that prescribe what the employee can do and stay within the scope of his or her authorized access to the employer’s computer system. This approach, in other words, puts the risk of error on the employer; if the employer doesn’t get the policy exactly right, it leaves some play, some room, for employees to exploit the computer system in greater or lesser ways for their own purposes. I’m not, of course, saying it’s impossible to develop policies that can define the scope of authorized access with some precision; I’m simply saying I think it can be very difficult, especially with regard to certain types of employment.

That brings me to the alternative approach I came up with when my student and I were discussing this last week. The alternative approach is to put the risk on the employee, not the employer. How could we do that and how would it help solve the problem?

The way we could do that is to make exceeding authorized access a crime – just as we currently do – but alter the way we define the crime. As I noted above and as I’ve noted in other posts, the problem we’re having with defining the crime of exceeding authorized access is the issue of intent. If we can’t draw precise lines between what is and what is not forbidden, then the law did not clearly forbid at least certain types of conduct, which means the person who engages in that conduct cannot be prosecuted because we can’t show that they intended to and/or knew they were exceeding authorized access.

We could address that by making exceeding authorized access a strict liability crime. As Wikipedia explains, strict liability crimes do not require the prosecution to prove intent; all the prosecution has to prove is that the person engaged in the prohibited conduct (i.e., exceeded authorized access). Strict liability crimes put the risk on the person because if they do what’s forbidden, they have no excuse; they can’t say, “I didn’t mean to” or “I didn’t know.” That may seem harsh, and it can be. To mitigate the harshness of holding people criminally liable without requiring intent, the law uses a compromise: We can eliminate intent in a criminal statute but, in exchange, the penalties have to be small, usually just a fine.

Strict liability crimes evolved about a hundred years ago as a way to enforce rules that were being adopted to encourage businesses and others to follow certain standards. There’s a case, for example, in which the CEO of a grocery company was convicted of a strict liability crime after his company let food stored in a warehouse be contaminated by insects and other vermin. The CEO appealed his conviction to the U.S. Supreme Court, arguing that he shouldn’t be held liable because he didn’t know what was happening in the warehouse. (It was a big company with lots of warehouses.)

The Supreme Court upheld the conviction because the crime he was convicted of was what’s called a regulatory offense. Regulatory offenses don’t have individual victims; they’re intended to encourage people to abide by the law in ways that contribute to the greater social good (like ensuring that food isn’t contaminated). As the Supreme Court noted, he best way to go about doing that is to use strict liability; strict liability puts the risk of error on the person who’s responsible for seeing that a rule – a rule the purpose of which is to promote the greater social good – is enforced. If the rule is not enforced, then the person who’s responsible has no excuse; good intentions or a lack of good intentions isn’t relevant. All that matters is the result.

So as my student and I were talking about all this, I came up with the idea of creating an exceeding authorized access crime that’s a strict liability crime. How would we do that? Well, I’m not exactly sure. If we decided this was a good way to go, we’d have to figure out how to structure the crime. I suspect – though I’m not sure (and can be wrong) – that we could come up with a good general definition of what it means to exceed one’s authorized access to a system. We might phrase in terms of using the system only in a fashion appropriate for carrying out your assigned tasks, say, or something similar.

Or maybe it’s a stupid idea. Maybe it wouldn’t do anything to help achieve clarity in this area. I still like my misusing authorized access alternative. What I found (find) intriguing about this notion is the idea of putting the risk on the person who is in the position to exceed authorized access. I really don’t think the prescriptive rules (putting the risk on the employer) is a particularly viable option . . . but, again, I could be way off base.

Wednesday, March 11, 2009

Possession of Identity Theft Tools

Colorado has an unusual statute that makes it a crime to possess identity theft tools. I can’t find a statute like it in any other state.

This is what the statute says:

A person commits possession of identity theft tools if he or she possesses any tools, equipment, computer, computer network, scanner, printer, or other article adapted, designed, or commonly used for committing or facilitating the commission of the offense of identity theft . . . and intends to use the thing possessed, or knows that a person intends to use the thing possessed, in the
commission of the offense of identity theft.
Colorado Revised Statutes § 18-5-905(1).

Possession of identity theft tools is a felony. Colorado Revised Statutes § 18-5-905(2).

Why did Colorado adopt this provision in 2006? I can see the rationale for doing so, I think, but I also doubt the statute is constitutional.

Let’s start with why they adopted it. As I’ve noted before, every state makes it a crime to possess burglar’s tools, i.e., tools that are specially adapted for or commonly used to commit burglary. As I explained in an earlier post, the purpose of this crime is to let law enforcement officers step in and arrest someone they suspect of getting ready to commit burglary before they can actually break into a house or a building.

As I noted in that post, possession of burglar’s tools statutes define an attempt crime. If a police officer on patrol sees someone standing outside a jewelry store equipped with tools that could be used to break into the store, the officer can stop and check things out. If the evidence indicates that yes, the person was getting ready to break into the store then the officer can arrest him for attempted burglary.

The same premise applies if an officer finds someone getting ready to kill someone or kidnap someone or set a building on fire. As long as the evidence and the legitimate inferences from the evidence prove beyond a reasonable doubt that the person had embarked on a course of conduct that was intended to culminate in the commission of a crime (burglary, murder, etc.), they can be charged with and convicted of attempting to commit that crime.

The policy justification for criminalizing attempts is that it lets officers intervene to stop crimes, instead of having to wait until the person breaks into the store or commit murder. Criminalizing attempts – which are by definition incomplete crimes – is also justified on the grounds that the person’s conduct shows they are dangerous, i.e., are willing and eager to commit a crime.

So where does that leave us with the Colorado statue? As I said, I think it’s a specialized burglar’s tools statute. As such, it’s presumably based on the premise I noted above: By making the possession of identity theft tools a crime, this statute would let law enforcement officers arrest someone who has such tools and thereby stop them before they actually commit identity theft.
That seems reasonable, and I don’t have any problem with the rationale of the statute. The problem I have with it goes, as I noted earlier, to its constitutionality.

The U.S. Supreme Court has held that statutes are void for vagueness and therefore unconstitutional when the language of the statute is so unclear that people “of common intelligence must necessarily guess at [their] meaning and differ as to [their] application.” Connally v. General Construction Co., 269 U.S. 385 (1926). Vagueness is particularly objectionable when it comes to criminal statutes, for several reasons.

One reason why vagueness in criminal statues is particularly objectionable is that if you are convicted of violating a criminal statute, you’ll probably be punished with some very severe sanctions (fine, imprisonment, damage to reputation). It’s not fair to impose harsh sanctions on people if they couldn’t understand that something was prohibited.

Another, related reason derives from a basic principle of criminal law: ignorance of the law is no excuse. If I’m prosecuted for murder or theft, I can’t defend myself by saying “I didn’t know it was a crime to (kill people/steal stuff).” The principle that ignorance of the law is no excuse implicitly assumes that (i) the law exists and (ii) is knowable. In other words, it’s not enough just to adopt a statute that makes something a crime; the statute has to make it clear what is, and is not, being criminalized. It’s not fair to hold me liable for violating a statute that was so ambiguous or confusing that I couldn’t figure out what was being criminalized.

The third reason why vagueness is especially problematic when it comes to criminal statutes is that a vague criminal law can give rise to arbitrary and discriminatory enforcement. That is, such a law gives the people who are responsible for enforcing criminal law a lot of latitude to decide who they want to go after and who they don't. So unprincipled law enforcement officers and prosecutors can use such a statute against people they don't like or want to harass, and let everyone else go.

It looks to me like the Colorado possession of identity theft tools may well be void for vagueness. Vagueness is an issue that has been raised with regard to burglar’s tools, but possession of burglar’s tools statutes have been around long enough – and the kind of tools those statutes address are unambiguous enough – that vagueness really isn’t a viable argument in this context.

I don’t think that’s true here. I think the statute’s making it a crime to possess “any . . . computer, computer network, scanner, printer, or other article adapted . . . or commonly used for committing or facilitating the commission” of identity theft is unconstitutionally vague. How am I supposed to know whether the computer, scanner and printer I use are “commonly used for committing or facilitating” identity theft? What, in other words, makes my possession of these items a crime? How can I tell when my possession of a computer, scanner and printer is legal and when it’s a crime under the Colorado statute?

Maybe I’m missing something. Maybe there’s a class of computers, scanners and printers that are specifically adapted for identity theft and essentially have no other use. If that’s true, then maybe this statute is not unconstitutionally vague. I doubt it, though.


Monday, March 09, 2009

Can You Trust Your Car? - Part 2

A couple of years ago I did a post about a federal case in which the FBI used a car’s integrated telecommunications system to listen in on what people in the vehicle said without their knowing about it.

As I explained in that post, the opinion in that case had nothing to do with the people whose conversations the FBI eavesdropped on, courtesy of the car’s cellular phone system. Instead, it was a civil case: The manufacturer of the car involved was trying really hard not to have to cooperate with the FBI, for what I think are obvious reasons.

Think about it: If you knew the cellular phone system installed in your car as part of a system like OnStar could be used to listen in on your conversations, would you be keen on having a car with such a system? Even if you weren’t planning on using your car to plot criminal activity, you might still find the notion of having someone eavesdrop on you to be unsettling. After all, aren’t cars supposed to be private places?

I found another car eavesdropping case, one that involves the OnStar system (the federal case involved a different system) and deals with a motion to suppress brought by the object of the eavesdropping. The case is State v. Wilson, 2008 WL 2572696 (Court of Appeals of Ohio 2008) and here’s a summary of the facts:
In November or December of 2006, appellant, Gareth Wilson, purchased a used Chevrolet Tahoe equipped with the OnStar system. [He] declined OnStar services. On January 2, 2007, OnStar received an emergency button key press from the Tahoe, as the service had yet to be disabled. The OnStar employee did not receive a response, so the employee contacted the Fairfield County Sheriff's Office and requested emergency assistance be sent to the vehicle's location.

While monitoring the vehicle, the OnStar employee overheard the occupants of the vehicle discussing a possible illegal drug transaction. The employee permitted the Sheriff's dispatcher to listen to the conversation. The dispatcher contacted Deputy Shaun Meloy regarding the OnStar call. Deputy Meloy in turn notified Reynoldsburg Police Officer Joe Vincent who notified Officer James Triplett.

Officer Triplett effectuated a traffic stop of the Tahoe. As Officer Triplett approached the vehicle, he observed furtive movement from [Wilson], the driver. . . . Officer Triplett removed [Wilson] from the vehicle and conducted a search, whereupon marijuana was discovered.
State v. Wilson, supra.

Wilson was charged with trafficking in marijuana, a fourth degree felony under Ohio law. He filed two motions to suppress the marijuana arguing that it was “discovered as a result of a traffic stop predicated on a violation of Ohio's wiretapping and electronic surveillance law, thereby violating his rights against unreasonable search and seizures as protected by the Fourth Amendment to the United States Constitution.” State v. Wilson, supra.

As I explained in an earlier post, the U.S. Supreme Court held – in Katz v. U.S., 389 U.S. 347 (1967) – that we have a 4th Amendment expectation of privacy in the contents of our telephone calls. In other decisions, the Court has held that we have a 4th Amendment expectation of privacy in conversations we hold in private places – like our homes. The government’s surreptitiously listening in on phone calls is known as wiretapping and it’s surreptitiously eavesdropping on face-to-face conversations is known as bugging. Both states and the federal system have statutes that make wiretapping and bugging illegal; the statutes implement the 4th Amendment’s requirements in this respect. (They also, in certain respects, go beyond what the 4th Amendment requires because legislators have on occasion wanted to ensure that we have even more protection in this area.)

Wilson’s motions to suppress therefore raised three issues: Did OnStar eavesdropping violate his rights under the 4th Amendment? If not, did it violate his rights under Ohio’s wiretapping and bugging statute? Finally, was the traffic stop valid?

The Ohio Court of Appeals quickly disposed of the Fourth Amendment issue:
The Fourth Amendment is a restriction against governmental action only. The seizure by a private person is not prohibited by the Fourth Amendment. . . .[T]here is no evidence that any law enforcement officers aided the On Star representative in the monitoring of the conversation. Law enforcement's role was strictly passive in terms of listening to, but not providing the means or controlling the manner of the monitoring. Thus, the Court finds no governmental action in this case and therefore no Fourth Amendment violation.
State v. Wilson, supra.

The court then turned to the Ohio statute. Ohio Revised Code § 2933.52(A) makes it a fourth degree felony to “[i]ntercept . . .or procure another person to intercept . . . a wire, oral or electronic communication.” Since the OnStar system was used to listen in on what people were saying in the car, it didn’t constitute intercepting a wire or electronic communication (wiretapping a phone call or email); instead, it consisted of intercepting an oral communication (bugging a conversation). Wilson argued that what happened to him violated this provision.

The prosecution said what happened to Wilson didn’t violate § 2933.52(A) because it came within an exception created by the next section of the statute. Section 2933.52(B) states that it isn’t a violation of § 2933.52(A) for an “employee . . . of a provider of wire or electronic communication service . . . to intercept, disclose, or use that communication in the normal course of employment while engaged in an activity that is necessary to the rendition of service”. To support its argument, the prosecution offered a transcript of the conversation between the OnStar employee and the Sheriff’s Office dispatcher:
ON STAR OPERATOR: Hi. This is Edwina calling from OnStar Emergency Services. We just had an emergency key press from a vehicle. We're not getting any voice contact at all. They're located on Churchview Drive in Pickering (sic), Ohio. The closest cross street is Finch. The vehicle is at the top of the T at Finch and Churchview Drive. . . .

ON STAR OPERATOR: Great. The vehicle has -- they pressed the button. I cannot get anybody to respond to me whatsoever, so I don't know if it's empty or if somebody is just not able to respond. . . .

ON STAR OPERATOR: Thank you very much for holding. I do have a dispatcher back on line. I will be in the background.

(Inaudible conversation )

ON STAR OPERATOR: Quite an ear full, huh, Dispatch?

SHERIFF'S DISPATCHER: Right. We're monitoring Reynoldsburg Police right now.
State v. Wilson, supra. After the Sheriff’s Dispatcher mentioned the police, the Onstar employee “communicated the following to the vehicle: `ON STAR OPERATOR: This is Edwina with OnStar Emergency Services. Police have dispatched to your location at Spring Run and Reynoldsburg. I will be disconnecting. Please know we are here whenever you need us.’”

The prosecutor said the OnStar person listened in on what people were saying in the car and shared it with police as part of performing an activity necessary to OnStar service, i.e., ensuring the occupants of the car were safe. Wilson argued that the exception the prosecution was trying to invoke shouldn’t apply because he didn’t have a contract with OnStar. The court disagreed: “It is uncontested that someone other than the OnStar employee initiated the contact as the `panic button’ had been activated. Clearly the occupants of the vehicle initiated the contact and failed to respond to the OnStar employee.” State v. Wilson, supra. So Wilson lost on the second issue. . .

and on the third issue: The court found that the OnStar information gave the officer probable cause to stop the car to be sure everything was okay. It also found that the officer’s observing a “questionable license tag” on the car (I don’t know what that’s about) further supported his reasons for stopping it. So Wilson lost on his motions to suppress. His no contest plea on a lesser charge (which got him 60 days in jail and 5 years of community control) stand.

I’m still waiting for a real 4th Amendment challenge to the use of OnStar . . . a case like the federal case I wrote about before, in which law enforcement officers get the service to let them listen in on conversations in the vehicle. As I explained in that earlier post, it seems to me that should be a 4th Amendment violation . . . though I can also see the argument that you assumed the risk of being eavesdropped on by having the system in your car.

Friday, March 06, 2009

5th Amendment Bummer

Over a year ago, I did a post on the U.S. Magistrate Judge’s decision in the Boucher case.

As I explained in that
post, Sebastien Boucher was crossing the border from Canada into the United States when a Customs inspector flagged his laptop for further inspection. The inspector saw files on the laptop that he believed contained child pornography.

The inspector and an Immigration and Customs Enforcement (ICE) agent looked at more files and then ran into a drive – the Z drive – they couldn’t access. At their request, Boucher opened the Z drive and the agent saw more of what he thought was child pornography. He arrested Boucher, seized the laptop and shut it down. He then got a warrant to search the laptop:

In the course of creating a mirror image of the contents of the laptop, however, the government discovered that it could not find or open the Z drive because it is protected by encryption algorithms from the computer software `Pretty Good Protection,’ which requires a password to obtain access. The government is not able to open the encrypted files without knowing the password. In order to gain access to the Z drive, the government is using an automated system which attempts to guess the password, a process that could take years.
In re Boucher, 2009 WL 424718 (U.S. District Court for the District of Vermont).

As I explained in my last post, the government (a U.S. Department of Justice prosecutor) got a grand jury to subpoena Boucher and order him to produce the password needed to access the Z drive on his laptop. Boucher took the 5th Amendment and refused to comply; he argued that requiring him to produce the password would in effect require him to give testimony that could incriminate him.

As I explained in my earlier post, his argument was based on an aspect of the 5th Amendment privilege against self-incrimination that lets you take the 5th Amendment as the basis for refusing to produce evidence – computer files, a gun, any kind of physical evidence – that can be used to convict you of a crime. As I also explained, the U.S. Magistrate who had to decide whether to enforce the grand jury subpoena agreed with Boucher; the Magistrate said he could claim the 5th Amendment privilege and refuse to give up the encryption key . . . which essentially meant that the evidence on the laptop was beyond the government’s reach.

I was sure the U.S. Department of Justice would appeal the ruling, and it did. Since a U.S. Magistrate issued the ruling, the first step in appealing it was to ask the U.S. District Judge who supervises the Magistrate to decide whether the Magistrate was correct.

As I said last time, I think the U.S. Magistrate got it exactly right. Basically, the government wanted to do the same thing it tried in the Webster Hubbell case: While Hubbell was in jail on other charges, the Department of Justice served him with a grand jury subpoena that ordered him to produce lots of documents to the grand jury. U.S. v. Hubbell, 530 U.S. 27 (2000). Hubbell took the 5th Amendment and refused to produce them, making the same argument Boucher made: that producing the evidence would incriminate him.

To get around Hubbell’s invoking the privilege, the U.S. Department of Justice gave him immunity, which stripped him of his 5th Amendment privilege with regard to what the subpoena ordered him to do, so he produced the documents. Since he produced the documents under a grant of immunity, the government could not use his act of producing them or the contents of the documents against him. But the Department of Justice went through the documents and used what they found in them to charge Hubbell with new crimes. Hubbell moved to dismiss the charges, arguing that the government violated his 5th Amendment privilege; he said the government basically tricked him into producing the documents on the understanding they would not be used against him. Since they were used against him, Hubbell argued that what the Justice Department did violated his 5th Amendment privilege, and the U.S. Supreme Court agreed. It upheld the U.S. District Court’s granting the motion to dismiss the charges, so Hubbell walked. U.S. v. Hubbell, supra.

Boucher relied on the same principle. And like Hubbell, he is (IMHO) entitled to take the 5th Amendment privilege against self-incrimination as the basis for refusing to give the government the password for the Z drive. As I pointed out in my earlier post, the government could give him immunity for the act of producing it, but that would mean they couldn’t use any of the files on the laptop . . . which would make it impossible to prosecute him for the child pornography – if any – found on it. So there'd be no point in proceeding, from the government's perspective.

I suspect the federal prosecutors knew Boucher’s argument was valid . . . which is why they modified the grand jury subpoena before they asked the U.S. District Court Judge to decide whether the U.S. Magistrate’s opinion should stand. Instead of ordering Boucher to produce the Department of Justice had the subpoena modified so that now
it does not . . . seek the password for the encrypted hard drive, but requires Boucher to produce the contents of his encrypted hard drive in an unencrypted format by opening the drive before the grand jury. In oral argument and post-argument submissions, the Government stated that it intends only to require Boucher to provide an unencrypted version of the drive to the grand jury.
In re Boucher (2009), supra. Why did they do this? Well, I still think it doesn’t work, but it gave the prosecution a new argument.

As I explained in my earlier post, the Supreme Court has held that you can take the 5th Amendment when your act of producing evidence tells the government something it doesn’t already know. If you’re telling the government something it doesn’t already know, you’re testifying; if you’re just giving the government something it already knows you have and knows about, you’re not testifying. You’re just handing over physical evidence. The Department of Justice modified the Boucher subpoena to try to bring it within that loophole: handing over physical evidence instead of testifying.

The U.S. District Court Judge bought the argument. The Supreme Court has held that an essential part of telling the government something it doesn’t know (testifying) is authenticating the evidence you hand over. So, say a grand jury subpoenas me and orders me to “produce the gun you used to kill John X.” If I show up and hand over a gun, I’m implicitly testifying that yes, I have the gun and this gun I’m giving you is in fact the gun I used to kill John X. If the subpoena tells me to produce “the Taurus 38 caliber revolver serial # 3810384 you used to kill John X,” then I’m not telling the government anything when I produce the gun. The existence of the gun and the fact I have it and used it to kill John X are a “foregone conclusion.”

Getting back to Boucher, the Justice Department argued that by ordering him to produce an unencrypted version of the Z drive on his laptop, it wasn’t requiring him to testify:
Boucher accessed the Z drive of his laptop at the ICE agent's request. The ICE agent viewed the contents of some of the Z drive's files, and ascertained that they may consist of images or videos of child pornography. The Government thus knows of the existence and location of the Z drive and its files. Again providing access to the unencrypted Z drive “adds little or nothing to the sum total of the Government's information” about the existence and location of files that may contain incriminating information.

Boucher's act of producing an unencrypted version of the Z drive likewise is not necessary to authenticate it. He has already admitted to possession of the computer, and provided the Government with access to the Z drive. The Government has submitted that it can link Boucher with the files on his computer without making use of his production of an unencrypted version of the Z drive, and that it will not use his act of production as evidence of authentication.
In re Boucher (2009), supra. So the U.S. District Court judge denied Boucher’s motion to quash the grand jury subpoena (make it go away) and ordered him “to provide an unencrypted version of the Z drive viewed by the ICE agent” to the grand jury. In re Boucher (2009), supra.

Where does that leave Boucher? He has two choices: comply with the subpoena and give the grand jury an unencrypted (and unaltered) copy of the Z drive; or appeal the U.S. District Judge’s opinion.

If he turns over the drive, he may be prosecuted for, and convicted of, possessing child pornography. If he appeals, he might win; I think he would have a good shot at winning because I don’t buy the government’s position that producing an unencrypted version of the drive isn’t testimony within the 5th Amendment privilege. The issue isn’t producing the password; the issue is producing the drive and the contents of the drive.

The problem for Boucher is that since the U.S. District Judge has held that he can’t invoke the 5th Amendment, he’ll be held in contempt if he does not provide the grand jury with unencrypted version of the Z drive by the date specified on the subpoena. That means he’ll be held in civil contempt. As I explain to my students, when you’re held in civil contempt for failure to comply with a grand jury subpoena, you sit in jail until you are either willing to comply or can persuade a Court of Appeals to hold that you can, in fact, invoke the 5th Amendment and refuse to comply with the subpoena. Getting a case to and through the Court of Appeals could take a year, or two, at least (it took over a year for the government to get the U.S. District Court Judge to review the Magistrate’s order).

Selfishly, I hope Boucher takes the issue to the Court of Appeals because I think the 5th Amendment should protect encrypted files and I’d like to see that issue resolved. But I don’t have to sit in jail for a long time to see that happen.

Tuesday, March 03, 2009

Cyberbullying

As I may have mentioned, I’m working on a law review article about cyberbullying with a law student (she’s the expert on education law, about which I know nothing). Like most law review articles, it’s long and complicated so I can’t describe our analysis in detail in a blog post.

I can, though, outline one of the issues we’re dealing with: defining cyberbullying. I haven’t really paid much attention to cyberbullying over the last couple of years, when it began to become a widely reported and talked about phenomenon. My assumption is that it’s more properly dealt with by educational institutions than by the criminal justice system.

(As an example of what, IMHO, is a gross misuse of criminal law, did you see the story about the student who was arrested for disorderly conduct after she refused to quit texting in class? I don’t know why the police had to get involved in that.

Aside from what I see as the unnecessary and unfortunate consequences that would result if the student winds up with a criminal conviction on her record, I’d think that having students arrested in class for conduct other than harming or threatening to harm teachers or students would disrupt the whole environment . . . but, then, what do I know.)


Getting back to my point, one of the things I’ve noted over the last year, roughly, is that cyberbullying became an increasingly elastic concept. It expanded from a term that referred to students using communications technology (email, websites, texting, etc.) to bully each other to a term that also encompassed adult bullying. Last December, for example, Wired had a story about a Chinese man who became the target of a “virtual lynching” by cyber-vigilantes after his wife committed suicide. According to the story, she killed herself because she believed he was having an affair (as he was, it turned out). The headline is “Man Receives Compensation for Cyberbullying,” and the story uses that term to describe what happened to him.

I found that odd because when I think of bullying, I think of schools. I know the term bully is not specifically limited to schools, but I associate it with schools – especially in the online context – because when adults do things to other adults we generally refer to that as a type of crime, e.g., stalking, harassment, defamation, invasion of privacy, etc.

When the law student and I began to develop what we were going to say in our article, I suggested we start by defining cyberbullying more precisely. We did research and talked about it and we came up with a basic premise that would structure how we would define the phenomenon we were going to deal with in the article. The article analyzes the necessity and propriety of using criminal law to address cyberbullying; so for the article to be coherent and useful, we had to define cyberbullying with some precision.

We decided there were two ways to look at it: The first is to regard it as a generic phenomenon; if we take this path, then what happened to the Chinese gentleman and other adults and children can be characterized as cyberbullying. The problem we (mostly me) (had) with that approach is that I don’t see why it makes sense to lump adult and student conduct together in the category of cyberbullying; as I noted above, we use criminal law to address adult-on-adult conduct that involves the victimization of one person by another, at least when that victimization inflicts a harm criminal law takes cognizance of. So I really didn’t see the point of using cyberbullying to refer to what happened to the Chinese man, and other similarly situated adults; seems to me that kind of conduct is best approached as a crime (stalking, harassment, etc.).

The more we looked at it, the more we decided that cyberbullying should be defined as a context-specific phenomenon, with the context being an educational environment. We considered limiting it to the first 12 grades, since that seems to be where most of what is characterized as cyberbullying occurs, but we decided to make it a generic educational context.

The purpose was to at least create the possibility of analyzing cyberbullying at the undergraduate and graduate levels. As a layperson, I tend to assume that bullying, whether cyber or real-world, is more likely to occur in the first 12 grades than at the undergraduate and graduate levels; I base that assumption on the premise that as people mature, they are much less likely to engage in the kind of bullying I assume we all either experienced or observed (or, for some of us, engaged in) when we were in one of the first 12 grades. I’m not saying bullying doesn’t happen at the undergrad or grad levels; I’m just saying it seems to me that it is less likely to be a big problem there (but, again, I could be completely wrong . . . education is not my specialty, either).


So, getting back to our definition. As I said, we decided to define cyberbullying as a context-specific phenomenon . . . as a phenomenon unique to an educational context. We did that because it seems that a significant “harm” inflicted by cyberbullying is its impact on the educational process, especially in the first 12 grades. We also defined it that way because the focus of the paper is on analyzing whether the criminal law needs to create a new crime specifically targeting cyberbullying. If existing criminal law can address the harms inflicted by cyberbullying, the we don’t need a new, cyberbullying crime; to the extent that existing law can’t address the harms inflicted by cyberbulling, then we may need to create a new crime.

Having defined cyberbullying, we created a taxonomy: student-on-student cyberbullying; student-on-teacher cyberbullying; teacher-on-student cyberbullyiing; and teacher-on-teacher cyberbullying. We explained we’re not going to deal with the last two categories because we have an adult perpetrator; our premise is when an adult is the perpetrator of cyberbullying, the use of the criminal law is presumptively more appropriate than when the perpetrator is a student (especially a student in the first 12 grades). A subsidiary premise is that when an adult is the perpetrator, we can probably use existing crimes to prosecute the adult for what he or she did.

We haven’t found any cases that involve teacher-on-student or teacher-on-teacher cyberbullying, but we’re pretty confident they’ll arise. My student is developing hypotheticals to demonstrate how both types of cyberbullying could arise, so we can analyze how criminal law can be used to address both.

I don’t have an example of these types of cyberbullying, but I do have what I find to be a pretty peculiar case that involves an adult engaging in what a news story describes as cyberbullying. Maybe you saw the story, which appeared last month: A North Carolina mother (we’ll call her Mom X) had a daughter (J) who had been part of a circle of girls (teens or preteens, the story say) who were all friends. For some reason, J was kicked out of the group of friends, which aggravated Mom X.

Mom X allegedly used J’s login information to go online and contact the other girls; posing as J, Mom X invited the other girls to join her in a webcam chat. When they did, the story says she yelled at them and insisted they become friends with J again. The story says at least some of the girls who were involved in the webcam chat were very upset about it, to the point that they were crying. Some of the parents called the police who were, when the story appeared, investigating to see if a crime had been committed.


Would this be adult-on-student(s) cyberbullying under our taxonomy? No, it wouldn’t because the adult isn’t affiliated with the school system . . . isn’t a teacher or a principal (or any other adult who’d work for a school, like, say a guidance counselor). Under our definition and our taxonomy, this isn’t cyberbullying; it is, if anything, an adult harassing some children. It really wouldn’t qualify as criminal harassment; as I explained in an earlier post, harassment and stalking both require a course of conduct, i.e., several distinct acts of harassment or stalking. Here, there was only one incident, so I don’t think this woman could (or should) be charged with stalking or harassment.

There are civil causes of action – like the one for intentional infliction of emotional distress – that parents of the girls whom Mom X yelled at could use if they wanted to sue her . . . but I think that would be a very bad idea. It would just drag the girls (J and the one(s) whose parents were suing) into court and aggravate everything; it would also probably really wreck J’s standing with those girls and the others at her school.

As we’re going to point out in the article, not everything needs to be a crime . . . or even a civil suit, for that matter. People in the real-world have, for as long as humans have lived in social groupings, done things to hurt each other’s feelings in varying ways and varying degrees. It isn’t nice, we don’t like it and we want to hit back when it happens. Hitting back physically isn’t a good idea at all; nor, in many instances, is using the law to hit back indirectly.

Freud supposedly said, “sometimes a cigar is just a cigar.” To paraphrase, “sometimes a jerk is just a jerk.”

Monday, March 02, 2009

Standing

As Wikipedia explains, in law standing is the “ability of a party to demonstrate to the court sufficient connection to and harm from the law or action challenged to support that party's participation in the case.”

The term has a specific meaning in the context of Fourth Amendment law. As a U.S. District Court explained,
[a] person seeking to exclude evidence allegedly obtained in violation of the Fourth Amendment must have standing to challenge the illegal conduct that led to the discovery of the evidence. `[T]o say that a party lacks fourth amendment standing is to say that his reasonable expectation of privacy has not been infringed. . . .’
U.S. v. King, 560 F.Supp.2d 906 (U.S. District Court for the Northern District of California 2008) (quoting U.S. v. Taketa, 923 F.2d 665 (9th Circuit Court of Appeals 1991)).

To establish that he has standing to bring a Fourth Amendment challenge, the person who wants to bring the challenge must prove that he had a reasonable expectation of privacy in the place searched or the item seized. U.S. v. King, supra. As I explained in an earlier post, to have a reasonable expectation of privacy in a place or thing, someone must show (i) that he subjectively (personally) believed the place/thing was private and (ii) his belief is one society (objectively) is prepared to accept as reasonable. In that earlier post I gave an example of how this test works in practice.

This post is about a rather unusual Fourth Amendment standing case. The case is U.S. v. King which I quoted earlier. Here – taken from the opinion in U.S. v. King -- is a summary of the facts that led to the Fourth Amendment challenge:

San Francisco Police Sergeant Eastman was investigating Craigslist advertisements for prostitution. He scheduled a “date” at a Quality Inn with a woman named “Stacy,” who said she was 19. The sergeant took other detectives with him when he went to meet “Stacy.” When they got to the Quality Inn, the sergeant called “Stacy” to say he was there; two other detectives checked with the desk clerk, who said “Stacy” was in Room 318. As the officers approached Room 318, they saw a man leaving and suspected he was “a pimp or customer.” When they asked his name, it (King) proved to be the name of the person who rented Room 318; this confirmed their suspicion that he was a pimp.

Two detectives went to Room 318 and knocked on the door. A female who resembled the photo of “Stacy” in the Craigslist ad opened the door. When they saw her, the detectives suspected she was a minor, probably 14 or 15. They entered the room, apparently to conduct what’s known as a protective sweep -- a brief check for people who could threaten officer safety. After they did the protective sweep, the detectives asked Mr. King to come into Room 318; after he came in, one of the detectives blocked to doorway “to prevent entry or exit”.

Sergeant Eastman came to the Room, where he and another detective began to ask “Stacy” how old she was. She said that she was 19 and that King was her “`boyfriend.’” The officers began a series of efforts designed to find out who “Stacy” was and how old she was. As they did that, Sergeant Eastman saw “a laptop computer in plain view on a table.” He “found the laptop significant because prostitutes who work out of hotels often use their laptops to post their ads on Craigslist.” He asked “Stacy” if she used it to post her ads, and she said she did. Sergeant Eastman asked her if the laptop was hers, and she said “yes.” When an officer asked if he could search the laptop, “Stacy” agreed. He found “pictures consistent with those” in the Craigslist ads. The detectives also searched bags in the room, apparently with “Stacy’s” permission. They “found documents related to prostitution activities and a digital camera.”

The officers arrested King and took him to the police station. After booking him, they released him “pursuant to California Penal Code § 849(b)(1), which permits police to release a person who has been subjected to a warrantless arrest when the officer is `satisfied there are insufficient grounds for making a criminal complaint against the person arrested.’” After he was released, King came back to the station and asked for the laptop, saying it was his. Eastman refused to return it because it contained child pornography. Two months later, a San Francisco officer brought all this to the attention of an FBI agent; the resulting investigation showed that “Stacy” “engaged in prostitution at the age of fourteen with King as her pimp.” Based on what they’d found, officers got a warrant and searched King’s home, where they found “a rifle, sexually explicit photos, ammunition, and a digital camera.” As a result, King was indicted for violating 18 U.S. Code § 1591 (sex trafficking of children) and 18 U.S. Code § 2425 (use of interstate facilities to transmit information about a minor).

King moved to suppress the evidence the officers found in the hotel room and the laptop. U.S. v. King, supra. The government argued that he didn’t have standing to challenge the use of the evidence because he didn’t have standing; that is, the government said King didn’t have a reasonable expectation of privacy in Room 318 of the Quality Inn and/or in the laptop.

The court’s opinion doesn’t outline the government’s argument in detail, but I suspect it went like this: “Stacy” was staying in the hotel room and testified at the suppression hearing that she owned the laptop; since she had access to the room and owned the laptop, she could consent to a search of either or both. (As I explained in an earlier post, the authority to consent to a search is based on access to the property to be searched.) Her ability to consent to a search of both defeated King’s claim that he had a reasonable expectation of privacy in either or both, which meant he didn’t have standing to challenge the methods the police used to search both the laptop and the hotel room. U.S. v. King, supra.


The federal district court rather summarily rejected the government’s argument:
The constitution's prohibition against unreasonable searches and seizures extends to protect the legitimate expectation of privacy of the occupant of a hotel. . . .The fact the room was registered in King's name and that King had not yet checked out is sufficient to establish that King had an expectation of privacy in the hotel room. . . .

Individuals generally possess a reasonable expectation of privacy in their personal computers. . . .`Stacy’ testified that she purchased the laptop, but a defendant who lacks an ownership interest may still have standing to challenge a search upon a showing of `joint control’ or `common authority’ over the property searched. . . . “Stacy” conceded she considered the computer to belong to both she and King, and King has proffered evidence that he shared the computer with “Stacy”, had her permission to use it, used it when he wanted to, and considered the computer as belonging to both he and `Stacy’. Because the government has not rebutted that King used the computer as if it were his own, the Court finds that King exercised joint control over the laptop and that he therefore may challenge the government's search of the computer.
U.S. v. King, supra.

Like many defendants raising a Fourth Amendment issue, King won some and lost some. The court first considered whether the search of the laptop was constitutional:
The question . . . is whether `Stacy’ actually consented to the search. Det. Olsen testified that “Stacy” gave permission to look at the computer. `Stacy’ testified she did not recall giving the officers permission to look at her computer, but did not directly contradict Det. Olsen's testimony. To overcome the government's evidence, King must present some evidence that creates a triable issue as to whether “Stacy” gave consent to search the laptop. An equivocal statement that `Stacy’ cannot recall whether she gave consent is insufficient. Accordingly, the motion to suppress is denied as to the laptop.
U.S. v. King, supra.

The court then considered the search of the bags that produced the digital camera and the documents noted above. It found that because the government could not prove the camera and documents the officers seized were in “Stacy’s’ bags, instead of in one of the bags belonging to King, the government had not met its burden of proving that the items were discovered pursuant to a valid consent search.

“Stacy” may have shared the hotel room and laptop with King (which gave her the authority to consent to a search of either or both), but she apparently did not have access to his bags. If she did not have access to his bags, then she did not have authority to consent to the bags; since the officers did not have a search warrant, their only Fourth Amendment justification for searching King’s bags was consent, which didn’t work. So the court granted King’s motion to suppress the digital camera (and its contents) and the documents the officers found in Room 318.