Monday, June 26, 2006

Prosecuting

I live in Dayton, Ohio, and because of that I read the local paper: the Dayton Daily News.

A day or so ago, the DDN had a story on identity theft, a version of which is available online. The hard-copy version was longer than the online one and included a photograph of a local prosecutor. The prosecutor, who will remain nameless here, has headed the fraud unit of the Montgomery County Prosecutor's Office for ten years (or so the DDN says), and I'm sure he is very experienced, very knowledgable about white-collar crime. Indeed, I believe I've heard anecdotal evidence to that effect, though I don't know the man myself.

Most of the hard-copy version of the article seemed to be an Associated Press-style story about identity theft, one with lots and lots of statistics . . . the gist of which is that we really don't have to worry much about identity theft because it's happening in the real-world more than it's happening online. The premise seemed to be that we don't need to worry that much about it because, since it's happening primarily in the real-world, it's nothing new.

Now, I had some problems with that part of the article because it seemed to be saying that online identity theft is not a problem since only a small percentage of identity theft can be attributed to commercial data breaches, that is, to companies' allowingconsumer data to be compromised. I have some reservations about that contention, and I also have some problems with equating online identity theft to compromised commercial databases. The article did not deal much with phishing or the other "personalized" types of identity theft, which I think was a shame. IMHO, it is important to educate people as much as possible about the various kinds of threats that exist online.

But all of that is minor carping on my part -- none of it is what prompted me to write this post. What prompted me to write this post was the role the local fraud prosecutor played in the (much longer hard-copy) version of the article. What was his role, you ask?

You might assume that, as a clearly-experienced and no doubt very-talented fraud prosecutor, his role would be that of a prosecutor who is handling/has handled identity theft cases. Nope -- his role in the article was as victim. It explains how he had his identity stolen.

Now, I find that peculiar, especially given the article's overall tone (don't worry about identity theft, it's nothing new, nothing strange). First of all, I suspect most prosecutors would not fall for real-world fraud schemes -- their experience and expertise would protect them. Here, though, we have not just a run of the mill prosecutor but the head of the local county prosecutor's fraud unit becoming a victim of identity theft. Doesn't that undercut the whole, "don't worry, identity theft is really not anything to be concerned about" tenor of the article?

Second, I found it interesting, given that tenor, that the article did not say anything about how the local prosecutor's office is handling, would handle or hypothetically might handle identity theft cases (whichever applies . . . though my pick would be the last alternative). The article doesn't say anything about that (presumably because I'm right and the last alternative, the hypothetical, is the correct choice) or even tell us if the identity theft who victimized the career prosecutor was ever prosecuted. Continuing it's reassuring tone, it tells us that the identity theft who picked on this prosecutor did so by running up charges on his credit card. The prosecutor noticed the charges, called the credit card company and had the charges removed so, as the article notes, the identity theft "didn't cost him a cent."

Well, that's reassuring, isn't it?

I''m sorry -- I'm venting a bit here and, in so doing, I really, really do not mean to be harsh with the DDN reporter who wrote the article or in any way be disrespectful to the prosecutor. It's just that they hit a nerve, as far as I am concerned.

See, I have spent a lot of time working with state and local law enforcement officers and with local prosecutors. From that experience, I know that cybercrime poses many, many challenges for prosecutors. I have often had police officers tell me they investigated a cybercrime case (one that was local enough it could be prosecuted in their state/county), put a good case together and then took the results of their investigation to a local prosecutor . . . who didn't want to touch the case, because cybercrime cases are "different," complex and time-consuming.

They're "different" because, as I have written about before, the law used to charge the person may be new, may be non-existent (which requires some creative extrapolation on the part of the prosecutor) or may raise difficult constitutional or other issues. They're complex for that reason, too. They're also complex because they can involve difficult issues concerning the intersection of law and technology.

These issues can arise with regard to charges against the defendant If, say, the defendant was an employee of a company and used her legisimate, employee access to its computer system to, say, delete files she was not supposed to delete, copy files she was not supposed to copy or browse through files she was not supposed to see, then the prosecutor will have to figure out what to charge her with. He cannot charge her with gaining "unauthorized access" to (hacking) the system because her employment gave her the right to access part of the system or to access all of the system for certain uses. So the prosecutor will have to figure out if he can legitimately charge her with "exceeding authorized access" (whatever that means) to the system, knowing that her lawyer will no doubt claim that everything she did was authorized. Trying to figure that out takes time (one reason why these cases are also time-consuming) and can be very difficult, especially if one has little or no understanding of computer systems.

If the prosecutor gets over that hurdle, there can be constitutional issues -- Fourth Amendment challenges to how the evidence was gathered -- and digital evidence issues -- challenges to the accuracy of the data being used as evidence against her. All of those issues can raise difficult questions about how law intersects with evolving technology.

So cybercrime cases can be a burden for prosecutors (just as they can be a burden for police officers) . . . which means prosecutors often may not want to deal with them. That is unfortunate. I can understand why prosecutors shy away from these cases, given everything I've just oulined plus the heavy caseloads they already have (involving real-world crimes, which are sometimes regarded as "realer" than cybercrimes).

The problem is that they're not going to go away, they're only going to increase in number, in the extent of the damage they do and in complexity. Not prosecuting these cases is only going to encourage more people to commit cybercrimes.

I remember a conversation I had a year ago with an economic crime detective in a major US city. He told me he keeps "catching" the same cybercrime perpetrators, putting together cases, taking the cases to prosecutors who decline to prosecute. He keeps trying, but is obviously becoming discouraged.

My point here is not to pick on the DDN or on the Dayton prosecutor whose identity was stolen. My point here, insofar as I really have one, is to point out that here, as well as in other areas, we are not doing a good job of dealing with cybercrime. I am not sure what the answer is, since it will take a lot of resources (money, personnel, expertise) to deal with this problem, and counties and parishes and states all do have other priorities. Real-world crimes -- blowing people up, killing them by other means, harming them by other means -- are an obvious and compelling priority.

I guess I just do not understand why we cannot do both.

Tuesday, June 20, 2006

"Toxic immersion"

I just finished Synthetic Worlds: The Business and Culture of Online Games, a book by Edward Castronova (University of Chicago Press, 2005). It raises a number of interesting issues, some of which I may address in future posts.

Today, I want to talk a bit about an issue Castronova raises toward the end of the book: “toxic immersion.” (Synthetic Worlds, page 238). He describes toxic immersion as “losing people to a space that, by any standard of human worth, dignity, and well-being, is not good for them.” Castronova unfortunately does not provide many details on what, precisely, he means by this. He does note that it would consist, at least in part, of having “synthetic worlds” (i.e., virtual realities) “become permanent homes for the conscious self.”

It is already apparent this could happen in various ways. As Castronova points out, the most extreme option is a Matrix scenario in which our bodies are maintained by machines while our minds roam virtual worlds. (Synthetic Worlds, page 238). Another possibility – raised by a British Telecom forecast – is that human consciousness would leave its physical host and migrate into cyberspace, or the version of cyberspace. (2005 BT Technology Timeline). Or there might be a less drastic scenario, one in which we spend much of our time plugged into cyberspace (or the future version . . . ) and the rest interacting with the real, physical world. Or . . . many others.

But I’m really not interested in "how toxic immersion occurs" scenarios. What I found interesting about Castronova’s take on toxic immersion is that he suggests it could justify state intervention to protect people from an experience "that, by any standard . . . is not good for them." (Synthetic Worlds, page 238).

I find this suggestion interesting because it reminds me of something I wondered about a few years ago, and then forgot about, in the press of dealing with other issues, other problems.

It occurred to me, a few years ago, that there could be some very interesting parallels between the way societies might deal with immersion in virtual realities and the way societies currently deal with drugs. Drugs (at least certain drugs) and virtual realities have something in common: They can both take us away from the real, physical world. Drugs do this in various ways: by blurring the edges of the real-world, by blunting our ability to experience the real-world or even, in the case of hallucinogens, transforming our experience of the real-world. Virtual realities go even further; they can take us away -- conceptually, anyway, from the real, physical world.

Historically, many cultures have had no difficulty whatsoever with the real-world-evading and/or -transforming qualities of various drugs. Indeed, some embraced the real-world-transforming qualities of drugs, incorporating drugs into their religious ceremonies. Other cultures, however, have historically rejected the real-world-evading and/or -transforming qualities of various drugs. As we know, this latter view has triumphed over the last century or so, and we live in a world in which access to drugs is carefully controlled and unauthorized access is punished as a crime.

It occurred to me, several years ago, that virtual realities can raise many of the same issues as real-world-evading and/or real-world-transforming drugs. Castronova's comments reminded me of my reflections on that issue because he clearly believes a "descent" into virtual reality would justify, as he says, "paternalistic" intervention by the state. Why, I wonder? Why, (I hope) you ask?

When I thought about this several years ago, I speculated that we might see a world in which the use of virtual reality was treated in a fashion analogous to the way we treat the use of (certain) drugs. That is, access to virtual reality would be . . . what? . . . controlled? licensed? monitored? penalized? . . . all for "our own good," as Castronova would have it.

What would justify this? If we reject, as I do, Puritanically-based knee-jerk reactions to any vaguely-hedonistic experience, what remains? The historic arguments for criminalizing drugs (as aggressively articulated by Harry Anslinger, the first U.S. "drug czar," in the 1930's) were that (certain) drugs (i) caused people to become violent, (ii) damaged users' physical health and/or (iii) resulted in their becoming parasites on society because they used drugs instead of working to support themselves and their families. (Alchohol somehow escaped being consigned to the outlawed "drug" category even though many/all of these "justifications" could be applied to it, as well.)

I can see similar arguments' being made with regard to the use of virtual reality, which currently consists primarily of multiple-user online games. When I first thought of that possibility, I was thinking primarily in terms of justifications (ii) and (iii) because I could see people's becoming so immersed in virtual reality that they tended to let other things slide. We are already beginning to see some of this, along with a societal reaction against it. As you may know, there have been a few instances in which people have died apparently as a result of playing online games without taking breaks (for food and sleep?).

These deaths, along with other not-really-identified evils resulting from intensive online gaming, have given rise to concerns about "online game addiction" and produced at least one effort to enact legislation that would limit the amount of time people could spend playing online games. I could be wrong but this looks to me like a first step, maybe a small first step but still a first step, toward what I was speculating about several years ago: treating the use of virtual reality as analogous to drugs, regulating the usage in various ways, maybe even eventually prohibiting usage of virtual reality by all/some segments of the population.

And what about factor (i), Harry Anslinger's favorite: the premise that the use of (drugs) virtual reality makes people violent? Well, I have noted, over the last year or three, articles appearing that link online game playing to increased violence and agression in the real-world. Although research to the contrary has also appeared, it looks to me like the online-games-cause-violence theorists are getting more play in the media. And perception is what counts. Harry Anslinger, for example, got marijuana outlawed by claiming that it caused people to becoming violent, very violent . . . incredible as that may seem today.

So where am I going with all this? I'm not really sure. I'm not saying that virtual reality/online gaming is analogous to (certain) drugs that (presumably) have undesirable effects which are sufficient to warrant their being controlled or outlawed. I'm not saying that at all. What I am suggesting is that there are perceived functional parallels between the two that may well result in virtual reality's being treated in a fashion analogous to the way we treat (certain) drugs.

So, who knows . . . maybe in ten or twenty or thirty or fifty years we will have a "Virtual Reality Control Strategy" and a "War on Virtual Reality."

What an absurd and depressing thought.

Saturday, June 17, 2006

Trojan horse defense

A Trojan horse program is a type of malware, or malicious software. Like other malware, it installs itself surreptitously on a computer; unlike other types of malware, a Trojan horse lets the person who disseminated it remotely control the computer(s) on which it installed itself. The person who controls the Trojan will have complete access to the data on the compromised computer and can copy it, delete it or put new data on the computer.

The last feature is what I want to talk about today. It's given rise to what is called the "Trojan horse defense." A friend and I wrote a law review article analyzing how prosecutors can rebut the defense. (Susan Brenner, Brian Carrier & Jef Henninger, The Trojan Horse Defense in Cybercrime Cases, 21 Santa Clara Computer and High Technology Law Journal 1 (2004)). The article focuses both on legal arguments and technical issues a prosecutor facing the defense can use to rebut it. It goes into a great deal of detail -- today, I want to talk generally about the Trojan horse defense (THD) and some of the issues it raises.

The THD became notorious in 2003, when Aaron Caffrey used in the United Kingdom. Caffrey was charged, basically, with hacking into the Port of Houston computers and causing them to shut down. His defense attorney conceded the attack came from Caffrey's laptop computer, but claimed Caffrey was not responsible for the attack, that he had, in effect, been "framed" by other hackers who installed Trojan horse programs on his laptop and used them to attack the Port of Houston computers. In an effort to rebut this defense, the prosecution pointed out that no trace of Trojan horse programs had been found on the laptop; the defense countered by explaining that the Trojan hourse programs had been "self-erasing" Trojans, so no trace would remain. The jury clearly bought the defense's argument, as it acquitted Caffrey.

This was not the first instance in which the THD had been used in the UK, but the Caffrey case received far more publicity than the earlier instance(s) in which the defense was raised. News stories pointed out that Caffrey's defense raised serious challenges for prosecutors. As one observer noted, the "case suggests that even if no evidence of a computer break-in is unearthed on a suspect's PC, they might still be able to successfully claim that they were not responsible for whatever their computer does, or what is found on its hard drive." And others pointed out that someone could establish the factual basis for such a defense by having Trojan horse programs on their computer.

As we note in the article, the THD is a new version of a very old defense: the SODDI defense (as it is known in the U.S.). SODDI stands for "some other dude did it." When a defendant raises a SODDI defense, he (or she) concedes that a crime was committed but blames someone else for its commission. The SODDI defense is usually not very successful in real-world prosecutions (the O.J. Simpson case is a major exception). When a defendant raises a SODDI defense in a prosecution for a traditional, real-world crime -- like, say, murder or rape -- he claims the crime was committed by an unknown someone else. Jurors tend to be skeptical of claimes like this, especially if, as is usually the case, the prosecution is able to link the defendant to the crime by showing motive, opportunity and/or incriminating evidence that is in his possession or can be traced to him (DNA, fingerprints, etc.). Jurors are skeptical of claims like this because they understand how the real-world works.

The SODDI defense has been much more successful in cybercrime cases because they involve a context which most jurors don't really understand, or understand enough to buy defense claims like Caffrey's contention about being framed by self-erasing Trojan horse programs.

(I'm not a technically trained person, so I cannot opine on the likelihood of self-erasing Trojans. I know people who are technically trained who do not believe they exist. If they do not exist now, I assume they will at some point, so I don't see this as a particularly important issue, at least not for the prosecution.)

In cybercrime cases, the SODDI defense turns the tables on the prosecution: In a criminal case, the prosecution has the burden of proving all the elements of the crime beyond a reasonable doubt and the defense has the burden of proving an affirmative defense by a preponderance of the evidence.
  • The preponderance standard is much lower than the standard the prosecution must meet, but it ensures that the defense cannot present some purely frivolous theory to the jury.
  • Affirmative defenses concede that a crime has been committed by assert there is some reason why the defendant should not be held liable for it, such as that the defendant is insane or that he acted in self-defense.
To get a THD before the jury, the defense must therefore present credible evidence that would let a "reasonable juror" find that the defense had proven that the crime was virtually committed by Some Other Dude, using a Trojan horse. In the Caffrey case, this evidence came in the form of Aaron Caffrey's testimony to the jury; Caffrey, who admitted he was a hacker, acted as his own expert witness, which was particularly important given that no Trojan horse programs were found on this computer

If a Trojan horse program is found on a defendant's computer, that would provide the factual basis for getting the defense to the jury . . . that along with testimony which establishes what a Trojan horse program is and what it does. Once the defense does this, the ball is now in the prosecution's court: The prosecution must rebut the defense, which means it must prove beyond a reasonable doubt that it was the defendant -- not Some Other Dude Using a Trojan Horse -- who committed the crim(s) charged. This is where the difficulty arises.

The prosecution now is obligated to prove a negative: that it was not Some Other Dude Using a Trojan Horse program who hacked the Port of Houston, collected child pornography or committed some other cybercrime. Proving a negative can be difficult, especially in this context.

As opposed to instances in which a defendant raises a SODDI defense in a real-world criminal case, the prosecution cannot rely on the jury's ability to use their common sense to assess the merits of and then reject the defense as implausible because the defense is grounded in what is still, for many, a distinctly "uncommon" context: the virtual environment of computes, hard drives and cyberspace. Some jurors may know nothing about technology, which really gives them no conceptual framework to use in judging the merits of a THD. This, I think, makes them something of a wild card; their decision to go with the prosecution or the defense may be made arbitrarily, a juror's equivalent of flipping a coin.

Other jurors may know a little about technology, enough to know what viruses are and to have a general idea of what they can do. As far as the prosecution is concerned, a little knowledge may be a dangerous thing: These jurors may understand enough about technology to be willing to believe that Trojan horses (and other types of malware) can do things they may not be able to do at all, or may not have been able to do given the facts in the case before them.

(I'm not sure where I come out on jurors who know a lot about technology. They might be able to analyze and reject the factual foundation of a shaky/untenable THD or they might over-analyze the evidence presented and so buy into the defense. I guess one reason I am not sure where I come out on these jurors is that I think they are likely to be very scarce in the jury pool.)

Assuming, as I think is reasonable, that the jury is made up of people with little or no knowledge of technology, how does the prosecution rebut the defense's presentation of a THD? It seems that the prosecution will have to dissect the technical basis of the defense to do so; the Caffrey prosecution showed that no Trojan horses were on Caffrey's laptop, and asked the jury to infer from this that it was Caffrey, not a Trojan horse program being used by someone else, who shut down the computers at the Port of Houston.

But if Trojan horses are found on the suspect's computer, the prosecution will have to get into the specifics of technology -- its capabilities and limitations -- to rebut the THD. This, I think, creates real difficulties for prosecutors, because it requires that they be able to explain abtruse, technical concepts and processes to a lay jury in a way laypeople can understand and can use that understanding to conduct a critical assessment of the THD presented to them. That can be a very difficult process; it will require, I think, not only expert witnesses, but the skillful use of graphics -- animations, diagrams, maybe physical exhibits -- that can really let jurors grasp what would have had to occur for the THD to be valid and why that did not occur (establishing, by inference, that the THD defense is invalid). Doing all that can be a huge undertaking for the average prosecutor/prosecutor's office, as it requires time, expertise and the money to pay for the creation of the necessary demonstrative evidence (animations, diagrams, etc.).

For now, I suspect the defense enjoys the advantage with regard to the THD, which is why I am surprised that we have not seen it used more in this country (it still seems be be used, often successfully, in the United Kingdom).

The only American case I know of in which it has been used successfully is an Alabama state tax fraud/tax evasion prosecution against Eugene Pitts, a Hoover, Alabama accountant. Pitts was accused of underreporting income on his tax returns for 1997, 1998 and 1999. He admitted there were errors on his returns for those years, but blamed the errors on a computer virus. Although prosecutors pointed out that the alleged virus did not affect the client tax returns Pitts prepared on the same computer, the jury acquitted him of all charges after deliberating for 3 hours . . . another "Caffrey verdict."

I assume the infrequency with which a THD is used in this country has something to do with the defense bar's familiarity, or unfamiliarty, with technology. Other than that, I cannot imagine why it does not show up more often, especially given the frequency with which the real-world variant of the SODDI defense is used.

Everything I have said in this post has been directed at the prosecution's burden and ability to rebut a THD defense. Everything I have said so far implicitly assumes that the invocation of the defense is frivolous as it was, IMHO, in the Caffrey and Pitts cases. And I think that is likely to be true in many (most?) of the cases in which a THD is used.

It will not, however, be true in every case. As people knowledgeable about computer technology will tell you, a Trojan horse program could easily be used to frame someone for a crime. While it seems exceedingly unlikely ("incredible") that a Trojan horse program could put 15,000 images of child pornography sorted into folders and sub-folders on someone's hard drive without their knowing it, a Trojan horse could be used to frame someone for, fraud, embezzlement or other crimes, even murder.

Think about it: Do you know everything that is on your hard drive . . . every file folder, every file? I can't imagine that you do, given the amount of data most of us acquire. And how many of us ever check to see what, exactly, is on our hard drive? Maybe other people do; I don't (I hope I am not inviting someone to frame me by admitting that . . . ).

The possibility makes me think of the old TV series, The Fugitive. In the TV series (and in the movie), Dr. Richard Kimble is adventitiously framed by the one-armed man who kills Kimble's wife. Kimble's SODDI defense (asserting that the mysterious one-armed man, whom only he saw, killed his wife) fails, and he is convicted of the crime. The same thing could be done, more calculatedly and with far less risk to the framer, by using a Trojan horse program.

Imagine a twenty-first century version of The Fugitive: Kimble's wife becomes ill so he takes her to the hospital, where she dies; the autopsy shows she died of ricin poisoning. As in the series, Kimble and his wife had been fighting; the evidence of marital discord encourages the police to take him seriously as a suspect in her death. Police obtain a search warrant, seize the computer in their home and search it. On its hard drive, they find evidence (downloaded data, evidence of Internet searches) that Kimble researched the toxicity of ricin poisoning and the processes used to extract ricin from castor beans. (They might also find ricin in the house somewhere, maybe in a place Kimble uses.) This would be enough to charge him with his wife's death (absent other contravening facts) and probably enough to convict him (absent a compelling defense).

In this scenario, Kimble could try asserting a THD to disclaim responsibility for the research into ricin poisoning, but the THD would not be as effective here as it could be in a "pure" cybercrime case. Here, a Trojan horse program is being used, in part, to frame someone for a real-world crime, murder. The potential for persuading the jury (correctly, in this instance) that someone used a Trojan horse program to put the ricin data on the computer as part of a larger plot to frame Kimble for his wife's death would be undermined by that fact because the jurors would be likely to concentrate on the real-world aspects of the crime (death, fighting, ricin, opportunity, etc.) and use their common sense (no one said it's infallible) to conclude that he did it.

I could go on, but I hope I've made my point. The Trojan horse defense is a two-edged sword: It can be used by guilty parties seeking to avoid being held liable for what they have done; but it can also be used to frame the innocent.

Tuesday, June 13, 2006

E-hijacking

According to a story posted on FleetOwner late last year, a shipment of computer tapes containing banking records belonging to Citigroup was "e-hijacked" as it was in transit to an Experian credit bureau in Texas.

The tapes were being shipped via UPS but, the story says, were diverted in transit. It says the shipment's electronic manifest was altered while the shipment was in transit, so that the tapes were delivered to an address other than the address for which they were destined. The story also says that the manifest was restored to its original form after the tapes were delivered, to make it appear that standard procedures had been followed. It does not explain how the alteration and mis-delivery were discovered.

A couple of months later, UPS issued a denial, saying that the tapes were not e-hijacked. UPS maintained that the boxes containing the tapes broke open in transit and the contents were "inadvertently thrown away."

I tend to suspect that the original story was true and that the tapes were, in fact, e-hijacked, but I tend to be cynical about these things. And I could be wrong -- it's been known to happen.

If something like this did happen, it would raise some interesting legal issues, so let's assume, for the sake of discussion, that things went as the original story said -- that someone altered the UPS manifest and the tapes were mis-delivered to, say, a warehouse where people responsible for the alteration took delivery of them and then disappeared. It would be quite easy to rent or "borrow" a warehouse for this purpose, I suspect.

Some of the stories about this reported e-hijacking focused on how it was done, on whether it took an army of "outside" hackers to alter the manifest or whether it was done by an "insider" who might or might not have had some outside help. I tend to lean to the "insider" theory, if only because it would be much simpler, much cleaner than having to mount an external attack. If I were doing something like this (which, of course, I would not, but it is always interesting to play crook in one's mind), I would use an insider because I think that would minimize the chance of the alteration's being spotted. If you used outside hackers, their efforts to crack the system and their ultimate success in doing so might be noticed, might call attention to what was going on. I'd definitely go with the insider, myself . . . but that is not what I want to talk about.

Being a lawyer, I am fascinated by what, if any, "crime" our hypothetical e-hijackers would have committed.

The original story assumed that this ehijacking constituted "theft," but I am not so sure. Legally, "theft" consists of taking someone's property with out their consent; theft statutes often note that the thief takes the property with the intent to deprive the owner of its possession and use. We more commonly refer to theft as "stealing."

Here, our (hypothetical) e-hijackers did not take the property from anyone without consent. They (hypothetically) took the tapes from UPS, to which Citigroup had given them for the purposes of shipment; that is what's called a bailment, and it basically means that UPS stands in Citigroup's shoes. So, if our hypothetical hijackers had pulled a "Sopranos"-style hijacking and had men with guns stop the truck, order the driver out, order him to open the cargo area, held him at bay with rifles and then go into the truck and take the boxes with the tapes over his protests, we would have "theft."

That's not what happened. What happened (hypothetically) is that UPS consensually handed the tapes over to our (hypothetical) e-hijackers, not realizing that they were being mis-delivered. (The premise of the original story is that UPS thought it was delivering the tapes to Experian, which was their legitimate destination.) It's not stealing if you voluntarily hand over property to someone who, unbeknownst to you, is not authorized to receive it.

English common law had to deal with this problem many centuries ago: People being charged with theft made a similar argument when what they had done was to trick the victim into giving them property/money -- the twelfth-century version of selling the Brooklyn Bridge. Courts finally recognized that, in fact, this was not theft . . . but they still perceived it as being "wrong." So they created a new kind of crime: larceny-by-trick (or theft-by-trick), which has come down to us as "fraud." Like the thief, the fraudster gets property to which he/she is not legitimately entitled; unlike the thief, the fraudster does not take the property but, instead, convinces the victim to hand it over. So, it seems more likely that our (hypothetical) e-hijackers committed fraud.

Who, though, did they defraud? We said above that since Citigroup gave the tapes to UPS for the purpose of delivering them to Experian, UPS essentially stood in Citigroup's shoes while it had the tapes. That is, UPS effectively represented the "owner" of the property while it was in transit to Experian. Okay, that tells us who the "owner" of the property was at the moment it was (hypothetically) diverted from Experian to the (hypothetical) e-hijackers. But who, precisely, did they defraud? Who did they trick? The deception that, at least hypothetically, resulted in the transfer of possession of the tapes from UPS to the e-hijackers was not directed at a person; it was directed at a computer, more specifically, at the UPS computer which issued/processed the manifest for the shipment. If this story were true, and if, as seems unlikely, the e-hijackers were apprehended, would it be permissible to charge them with fraud based on their having deceived a computer?

Logically, I see no reason why we could not construct such a charge . . . but I suspect that if we did so, the defendants would move to dismiss, arguing that the law is and always has been that "fraud" consists of deceiving a person so that person hands property over to the fraudster. I'm not sure, at this point, that we actually need to revise our fraud laws to encompass this scenario, but I think it is an issue we might want to consider . . . because if e-hijacking really did not occur in this instance, it will.


Monday, June 05, 2006

C3: Cybercrime, cyberterrorism and cyberwarfare

I've written a lot about cybercrime and have done at least one post on cyber terrorism.


Today, I want to talk not about cybercrime or cyberterrorism as such, but about the three categories of online malefaction: cybercrime, cyberterrorism and cyberwarfare.

More specifically, I want to focus on the clear and not-so-clear distinctions between the categories.

Let's begin with some basic definitions:
  • Cybercrime is, essentially, using computer technology to commmit unlawful acts, or crimes. As I explained in an earlier post here, and as I have explained elsewhere, the activity we refer to as cybercrime often consists of nothing more than using a computer to commit a crime that is probably as old, or almost as old, as humanity. So, if someone uses a computer and the Internet to siphon funds from a bank account belonging to someone else, it is simply theft (taking property from someone else without their consent) as far as the law is concerned. There are, however, good reasons to consider the perpetrator's use of computer technology in the commission of this and other technological crimes; aside from anything else, they let the perpetrator commit the crime remotely (the perpetrator is in, say, Brazil, the bank account is in the United States), which can make it difficult for law enforcement to "solve" the crime. Also, the use of computer technology can increase the scale on which crime is committed; so, an online fraudstater using computer technology can defraud many more people in a given space of time than she would be able to do if she had to deal with each of them face-to-face. Cybercrime, like all crime, is committed by civilians whose motives are purely their own. (There is an exception to this, which I will note below.)
  • Cyberterrorism essentially consists of using computer technology to engage in terrorism. Terrorism consists of acts that are committed for political, versus economic, motives. Much of crime is committed for economic reasons, as in the examples I gave above. Terrorism is committed to further certain political goals. It is usually intended to demoralize a civilian population (which differentiates it from warfare, which is not supposed to target civilians), and usually accomplishes that, in the real-world, by destroying property and injuring or killing as many civilians as possible. The 911 attacks on the World Trade Center are a perfect example of real-world terrorism; they were intended to destroy a premier symbol of capitalism and, in so doing, undermine the morale and confidence of U.S. citizens. As I explained in an earlier post, we have not, as yet, seen cyberterrorism, but I am confident we will. I do not think, as I said in my earlier post, that cyberterrorism is an effective way to destroy property and human life on the scale and with the shocking simultaneity one can achieve by using bombs, airplanes and similar real-world methods. I do think, though, that computer technology can be used to erode citizen confidence in the security and stability of the internal systems upon which they rely. As I noted in my earlier post, one way to do this would be to launch sequenced, synchronized attacks shutting down ATM systems and other financial mechanisms in carefully selected cities around the United States. As the attacks progressed from city to city, it would become increasingly apparent that they were not random, were not the product of software bugs, were not otherwise explainabel but were, instead, the product of terrorist activity. Attacks such as these would not inflinct the sheer horror of the 911 attacks, but they could further terrorist goals by creating a climate of insecurity and anger at the government, something analogous to what we saw with the Katrina fiasco. Like terrorism, cyberterrorism is carried out by individuals who are part of a group that is held together by a commitment to a specific political ethos.
  • Cyberwarfare is using computer technology to wage war. The distinguishing characteristic of war is that it is a struggle between nation-states; it is, like all human activity, physically carried out by individuals, but those individuals are acting for a particular nation-state. Like terrorism, warfare tends to result in the destruction of property (often on a massive scale) and in the injury and deaths of individuals (often many, many individuals). Unlike terrorism, war is supposed to be limited to clashes between the aggregations of individuals (armies) who respectively act for the warring nation-states, their armies. Injuring and killing civilians (those who are not serving in one of the combatant nation-states' armies) occurs, but it, like most property damage/destruction, is supposed to be a collateral event. The primary focus of war in general and of particular wars in specific is to "triumph" over the adversarial nation-state(s) (whatever that means in a given context). Inflicting injury/death on civilians and destroying property is not the primary focus of warfare. Cyberwarfare (also known as "information warfare") is a logical consequence of migrating much of human activity into cyberspace. Several years ago, the Department of Defense defined cyberwarfare as "actions taken to achieve information superiority by affecting adversary information, information-based processes, information systems, and computer-based networks while defending one's own" computer systems, information, etc. More simply, cyberwarfare consists of using cyberspace to achieve the same general ends nation-states pursue via the use of conventional military force; that is, the use of cyberspace to achieve certain advantages over a competing nation-state or to prevent a competing nation-state from achieving advantages over another state. As I write this, it is clear that many nation-states are already engaging in cyberwarfare, though on what I think is a relatively small scale. Some countries are training/have already trained "hacker warriors" and are using them to mount attacks on other countries, many of which are developing their own cyberwarfare capabilities. From what I can tell, most of the attacks so far resemble skirmishes rather than full-scale "cyber-battles" (whatever a full-scale cyber-battle would look like . . . . )
That's a pretty concise explanation of what each category comprises and of how each category differs from the others. That, however, is not my primary concern in writing this post. What I really want to focus on is how the use of cyber-techniques to implement any or all of these three types of real-world activity can, for lack of a better word, challenge a government's ability to respond to online-based crime, terrorism and/or warfare.

In the real-world, we know who deals with what:
  • Law enforcement officers (in the U.S. local police, state police and, sometimes, federal agents) deal with crime.
  • Law enforcement officers plus, perhaps, specialized law enforcement officers (the FBI in the U.S., specialized police units in other countries) deal with terrorism. Usually, you tend to see a mix of "regular" and "specialized" police responding to terrorism because the local police are likely to be the first responders to a terrorist incident . . . as we saw with the 911 attacks on the World Trade Center. There, the NY police and fire departments were the first to deal with the attacks, though the FBI and related federal agencies quickly became involved, as well.
  • The military deals exclusively with warfare.
That's a tidy division of responsibilty, one that has been with us for at least a century and a half. It assumes, of course, that we can tell the difference between (i) crime, (ii) terrorism and (iii) war.
  • It's generally not difficult to do that when we are dealing with real-world activity: Crime is pretty easy to spot, especially since much of it tends to be one-on-one crime, e.g., one person robs another, one person kills another, etc. And crime falls into identifiable categories: theft, robbery, rape, murder, fraud, arson, etc.
  • Real-world terrorism is generally easy to spot, even though it involves activity that can also fall within the definition of crime, i.e., harming/killing people and destroying property. Real-world terrorism is usually easy to distinguish from crime because (i) it is irrational and (ii) the scale on which it is committed vastly exceeds what one usually encounters with crime.
  • Take the attacks on the World Trade Center, for example: They are irrational in the sense that they produced no financial gains (unlike, say, bombing party of one of the WTC towers and using that to rob a bank or a jewelry store, say). Much of crime, as I have said before, is committed for financial gain.
  • There are, however, crimes that are not committed for financial gain; in any city in the U.S. (or elsewhere) one can read daily about murders that were committed for no rational reason, for no purpose relating to financial gain or the achievement of other rational ends (like ridding oneself of an unwanted spouse). But those crimes tend to be limited in scale, and tend to involve people who know each other. Husbands kill wives, wives kill husbands, employees "go postal" and kill people in their workplace. In crimes such as these, there is a link, a factual nexus between the perpetrator and the victims. They also tend to be limited in scale: The perpetrator kills only the person(s) he/she knows and is angry/frustrated with.
  • In real-world terrorism, the activity is not rational -- why would anyone fly a plane into the World Trade Center? There is no ostensibly rational motive; the motivations of the Al Qaeda members who actually did that are, of course, quite rational if one accepts the ideological premises from which they operate. To the uninitiated, however, the conduct seems irrational. So, there is a clue that we are dealing with terrorism . . . just as the apparent irrationality of the conduct is clear when a suicide bomber blows up himself/herself and whoever happens to be in the area. That second factor is another differentiating factor, another clue, that we are dealing with terrorism in the real-world: The scale is inexact -- there is no clear link between the act and the result; the suicide bomber blows up some random number of people, none of whom he/she knows, none of whom he/she has any personal grudge against.
  • I could go on, but I think (hope) my point is clear -- it is relatively easy to identify terrorism in the real-world.
  • Finally, it is very easy to identify warfare in the real-world. When the Japanese bombed Pearl Harbor or when the U.S. began bombing in Iraq in 2003, no one who heard about/witnessed the attacks could have the slightest doubt that this was warfare . . . not crime, not terrorism. Both were conducted by specialized cadres of individuals associated with the attacking nation-state, all of whom wore distinctive attire and distinctive insignia.
Now, think about how these activities manifest themselves in the cyber-world. it will, in some instances, be relatively easy to identify the type of activity at issue. This is true, generally, for cybercrime: Most of the emails send out to implement 419 and other fraud scams, for example, are the result of activity by cybercriminals (or aspiring cybercriminals). Like fraudsters in the real-world, they are trying to enrich themselves by convincing deluded victims to send them money or transfer other property to them.

Even here, though, the categorization does not always hold: Al Qaeda and other terrorist groups have been known to use online fraud (especially credit card fraud) as a way to raise money for their terrorist activity. If terrorists are engaging in what would otherwise be cybercrime, is the activity still cybercrime or does it become cyberterrorism? I'd say it's still cybercrime because while it is being perpetrated by those who style themselves as terrorist, it is, at bottom, still just fraud.

I want, though, to focus on the problem I noted above: the challenge of initially identifying what type of cyberactivity is at issue and ensuring that the proper agencies/personnel respond to it.

Imagine, say, that a series of sequenced attacks occur on financial systems scattered around the U.S. We will simplify the example by assuming that each of the attacks takes the same form. (It would, of course, be relatively easy to structure the attacks so they differ in varying degrees.)

So, keeping things simple, let us assume that all/many/most ATM machines are taken off line (i) in Des Moines on April 1; (ii) in Portland on April 2; (iii) in Reno on April 3; (iv) in Cincinnati on April 5; (v) in Nashville on April 6; (vi) in Miami on April 7; and so on. The scenario might involve keeping the ATMs offline or it might involve shutting them down, bringing them back up and then shutting them down again (which I think might be more effective). This basis pattern could be coupled with other attacks on banking systems . . . online banking might be shut down, data might be scrambled, etc. etc.

Take that basic scenario: Who would respond (initially -- we'll get to escalating responses in a minute)? The local police would respond. It would presumably be regarded as a cybercrime -- maybe the stereotypical teenage hacker shutting down the system for fun, maybe a prelude to an extortion effort by professional hackers.

Assume, now, that the attack is not a cybercrime, that it is being perpetrated by those "hacker warriors" I mentioned earlier -- cyberwarriors trained and recruited by a nation-state, one that is hostile to the U.S. and that is using cyberspace in an effort to gain certain tactical advantages. Here, the tactical advantage might be an initial step toward destabilizing the financial system in the U.S.

How long would it take for us to realize we were under such an attack? How long would it take for us to realize that this was cyberwarfare, not cybercrime? How would that realization come to pass . . . if at all?

For that realization to occur, someone, somehow would have to be able to see the big picture, would have to know that these attacks were occuring, would have to see the sequencing in the attacks, would have to know about the similarity in the attacks. How would that come to pass?

What if the local police in each of the cities in which an attack occurred simply believed it was a cybercrime? What if the local police, assisted, maybe, by the state police, sought to deal with it on their own? I think this is the most likely scenario, at least for a considerable period of time.

I hope, but doubt, that we have procedures, personnel, and data-gathering processes in place that allow us to track incidents such as these at a global level . . . that, in other words, let us (one or more of us, official one or more of us, somewhere) grasp what is occuring on a larger scale.

Otherwise, we could become the target of cyberwarfare and not even know it. In the 1970s there was, I think, a slogan -- something like "What if they gave a war and no one came?" Maybe the slogan for the 21st century should be something like "What if they started a war and we didn't know it until they won?"



Saturday, May 27, 2006

Hate

I find it interesting, and instructive, that hate, or, more precisely, hate speech, is an issue that divides cultures as otherwise similar as the United States and Europe.

The image to the right is an example of hate speech, albeit a very old example of hate speech. It is a book (The Way to Victory of Germanicism over Judaism) written by a Wilhelm Marr, a German, and published in 1879. According to one source, Marr "coined the term `anti-Semitism' as a euphenism for the German Judenhaas, or `Jew-hate.'" The same source tells us that Marr's work "was a major link in the evolving chain of German racism that erupted into genocide during the Nazi era."

What, you ask, do hate and a nineteenth century purveyor of racism and hatred have to do with cybercrime in the twenty-first century? On the one hand, not much; on the other hand, maybe quite a lot, at least as the basis of an object lesson.

As I explained in a post last month ("Treaty"), the gaps and inconsistencies that currently exist in national cybercrime law provide a weakness, a vulnerability, cybercriminals can exploit to frustrate investigations and avoid prosecution. Those who are knowledgeable about cybercrime agree that this is a critical issue we must resolve if we are to deal effectively with cybercrime. The difficulty lies in how we resolve it.

One way would be to declare cyberspace to be its "own" jurisdiction -- to make it a "country" that exists separate and apart from the distinct territorial spaces that respectively comprise the nations of the world. This approach would then provide cyberspace with its own set of unitary laws and its own law enforcement agencies; some suggest the United Nations could take over the enforcement role. But while cyberspace might, and I emphasize might, someday become a distinct, sovereign nation, we are a long, long way from that. My sense is that none of the governments of the world are anywhere near ready to cede control of the activities their citizens conduct online to an external entity, regardless of its sovereign status.

So, that approach is not going to work any time in the foreseeable future. The other approach, as I explained in my previous post
("Treaty") is to see that countries of the world harmonize their laws so that (i) there are no gaps in criminalizing, say, hacking or the dissemination of malware and (ii) the laws of each country allow its law enforcement officers to assist officers from other countries in their investigations of cybercrime. This is, as I explained in my earlier post ("Treaty"), the goal of a treaty drafted under the auspices of the Council of Europe: the Convention on Cybercrime. In my earlier post I explained why I have some reservations about the extent to which the Convention on Cybercrime will succeed in harmonizing national cybercrime laws. That is not what I want to talk about today.

Let's go back to Wilhelm Marr and his anti-Semitic publications. The Convention on Cybercrime was drafted by representatives from the Council of Europe and from four other, non-Council of Europe countries: the United States; Canada; Japan and South Africa. See Council of Europe, Explanatory Report for the Convention on Cybercrime para. 304. When the Convention was being drafted, some of the European representatives wanted to include a provision requiring parties to the Convention to criminalize the use of computer technology to disseminate "hate speech," or the kind of "racist propaganda" Marr disseminated via the printing press. See Council of Europe, Explanatory Report for the Protocol to the Convention on Cybercrime para. 4. The rationale was that "
international communication networks like the Internet provide certain persons with modern and powerful means to support racism and xenophobia and enables them to disseminate easily and widely expressions containing such ideas. In order to investigate and prosecute such persons, international co-operation is vital." Council of Europe, Explanatory Report for the Protocol to the Convention on Cybercrime para. 3. The United States, which played an influential role in drafting of the Convention, made it clear that if such a provision was included, the United States would not be able to ratify the Convention. See Council of Europe, Explanatory Report for the Protocol to the Convention on Cybercrime para. 4.

The provision was therefore not included in the Convention on Cybercrime, but it later became part of an addendum to the Convention: the "
Additional Protocol to the Convention on Cybercrime, Concerning the Criminalisation of Acts of a Racist and Xenophobic Nature Committed through Computer Systems" [hereinafter, "Protocol"]. The Protocol essentially requires the nations that sign and ratify it to adopt laws criminalizing the use of computer technology to disseminate "racist and xenophobic" material. Racist and xenophobic material is defined as "any written material, any image or any other representation of ideas or theories, which advocates, promotes or incites hatred, discrimination or violence, against any individual or group of individuals, based on race, colour, descent or national or ethnic origin, as well as religion if used as a pretext for any of these factors." Protocol, Article 2(1).

This brings us back to Wilhelm Marr. The Protocol is specifically designed to prevent the Internet's being used to disseminate ideas such as those Marr put forth in the book noted above and other, similar efforts.

The notion of outlawing racist or hate speech is far from new. The German Penal Code has for years made it a crime to distribute "propaganda" that glorifies or otherwise supports Nazi ideals or the ideals of any other organization that has been declared to be unconstitutional by the German Federal Constitutional Court. German Penal Code Section 86. Other countries have similar laws, though they may differ somewhat in terms of the precise nature of the speech they prohibit.

The United States has never criminalized hate speech and almost certainly could not do so.. The First Amendment states that Congress cannot adopt any law "
abridging the freedom of speech, or of the press". We can, as I have explained elsewhere, criminalize a few, very narrow categories of speech, but those are exceptional circumstances. We cannot outlaw hate speech (the Protocol's racist or xenophobic speech) because doing so would be criminalizing "pure" speech, not, say, the act of victimizing a child to create child pornography and then publishing that material on the web on in print. Child pornography is speech, but it is also something more; it is speech that memoralizes the victimization of a human being, of a child. We can, therefore, constitutionally criminalize child pornography because we are outlawing the infliction of physical and emotional "harms" on a person to create a particular category of speech, not "speech," as such.

I'm writing about this topic today because I'm writing a paper on a related topic (defamation online) and in the course of my research I discovered a provision that was proposed for inclusion in the Model Penal Code. The
Model Penal Code was published in 1962, the product of many years of effort by members of the American Law Institute. It was intended to reform the then-existing state of criminal law in the United States. At that time, our criminal law was based on traditional English common law and was, as a result, antiquated in many respects. The drafters of the Model Penal Code wanted to update our criminal law by simplifying arcane and unnecessarily complicated rules that had evolved over the centures and by addressing issues that had not been a concern at common law. The therefore published a set of model laws -- the Model Penal Code -- that were intended to act as guides primarily for state legislatures, though the Model Penal Code has also had some influence on federal criminal law.

What I found interesting is that in an early draft the authors of the Model Penal Code proposed creating a new crime: "fomenting group hatred." It consisted of disseminating "any derogatory falsehood, with knowledge of the falsity" for the purpose of "fomenting hatred" against "any racial, national, or religious group". I find the provision interesting because it reminds me of the language in the Protocol to the Convention on Cybercrime.

Unlike the Protocol to the Convention on Cybercrime, however, the provision on "fomenting group" hatred" was never adopted . . . by the drafters of the Model Penal Code or by any U.S. state. In the commentary for the proposed provision, the drafters of the Model Penal Code explain why, at this point in time, anyway, they believed it could survive First Amendment challenges. They seem to have changed their minds later, though, and so did not include it in the final version of the Model Penal Code. As far as I can tell, it has gone unremarked and unnoticed ever since.

I mention the provision not because I believe it should have been included in the Model Penal Code. I think it should not because, unlike those who crafted it, I think it clearly could not survive First Amendment challenges. It would criminalize speech, pure speech . . . speech many would find to be hateful, repulsive and with no redeeming social value. The fundamental premise of our First Amendment, however, is that we, in the United States, do not criminalize speech because we do not like it, because it makes us uncomfortable, because it distresses others to the point that it can legitimately be characterized as inflicting a psychic assault on them. As a society, we believe in the "marketplace of ideas," the notion that the best ideas, the best beliefs, will triumph in a free, transparent discourse encompassing all views, however marginal they may seem.

That perspective makes sense to me . . . perhaps because it is the "right" perspective, or perhaps because I am an American and, as such, grew up with the notion that this is how things should be. I know other countries view hate speech differently. I have tried very hard to understand the premise that, for example, hate speech constitutes an assault, a psychic assault of the type I noted above. I have tried to understand the premise that hate-speech-as-psychic-assault is indistinguishable from the physical assaults every society criminalizes . . and I have failed. I am afraid I cannot, and never will be able to, see an equivalence between words -- mere words, mere speech -- and a physical attack on someone.

And that brings me back to the point of this post: The fact that Americans and Europeans (many Europeans, anyway) can view hate speech so differently illustrates the difficulties we will face, I think, in attempting to harmonize national penal laws so they consistently, and globally, address the problem of cybercrime. Law, especially criminal law, is inextricably bound up with culture, which is and will remain -- at least for the foreseeable future -- a parochial phenomenon, a product of local history and experience. I suspect the parochial nature of our national cultures is one reason why no one wants to "internationalize" cyberspace -- to turn it into a separate legal "place." We fear the loss of control, the loss of identity that would ensue.

It will be interesting to see how we work out the difficulties involved in retaining our national cultures while harmonizing our national penal laws to address cybercrime.


Tuesday, May 23, 2006

Fusion centers

Amidst all the furor (justified, I'd say) over the NSA's surveillance of Americans' phone calls, a new measure is being introduced in law enforcement . . . one that, I think, should give rise to concerns analogous to those produced by the NSA's activities.

I refer to "fusion centers," which seem to be a relatively recent development. You can read more about them here, on the U.S. Department of Justice's website. You can also find the newly issued guidelines for fusion centers on this site.

The guidelines will explain what a fusion center is. Basically, it is being cast as a new tool in our battle against terrorism, though it is clear that fusion centers will focus on criminal activity, as well.

What does a fusion center do? What is the point of a fusion center, you ask?

Well, a fusion center is designed to do one thing: aggregate and analyze information. The purpose, according to the USDOJ site, is to establish a "collaborative process to improve intelligence sharing and, ultimately, increase the ability to detect, prevent, and solve crimes while safeguarding our homeland."

What's wrong with that, you ask? Well, I'm not necessarily saying there is anything wrong with it (I'm not saying there isn't either . . . I'm just ruminating, at the moment). What I find particularly interesting at this point is time is that the NSA activities are receiving a lot of attention and generating a lot of furor, while fusion centers seem to have remained totally under the radar even though they have been in existence for at least 3 years.

What, precisely do they do, you ask? They will apparently do many things, but their central function, it seems, is to collect data from public and private sources and "blend" the data together to create "meaningful and actionable intelligence and information." The guidelines and other sources I have found on fusion centers emphasize that they will compile information from both traditional law enforcement sources and from the private sector.

Some of what I have read about fusion centers indicates that they are intended to address extant jurisdictional gaps that undercut law enforcement's ability to share information. So, you might have a fusion center in a state (Texas has one, as does Maryland, Massachusetts and, I believe, 25 other states, with more states preparing to jump on the bandwagon) which would ensure that law enforcement information gathered by, say, the Sheriff's Office in County A was available to law enforcement officers in the other counties in the state. That seems umproblematic. They might also share this information outside the state, with law enforcement officers in other states and with federal agencies. That, too, seems unproblematic.

What I find interesting is the notion of bringing the private sector into the mix. Doing that takes the concept of a fusion center beyond that of simply compiling and sharing a law enforcement data set (or a series of law enforcement data sets) into something . . . different, something that is more reminiscent of what the NSA has been doing. The guidelines for fusion centers don't really tell me how and why the private sector will participate in this.

The two really go together. Start with how: Will private sector entities become part of these fusion centers, so that their data sets automatically become part of the fusion center's data set? Or will the private sectors only provide data that is/could be relevant to particular inquiries?

That takes us to why: Why would private sector entities become involved in this endeavor. Will they be selling data to the fusion centers, in the same way private data aggregators currently sell data to federal and state law enforcement agencies? Will they voluntarily (why?) become part of the fusion centers, collaborators in the process, and contribute the data they hold as part of their oblibation as constituents of the fusion center? Or will they only contribute data in response to whatever legal devices (National Security letters, administrative subpoenas, other subpoenas or court orders) the fusion centers may employ to require them to do so?

Lots of questions. No answers yet. More to come, at some point, when I know more.



Thursday, May 18, 2006

Cyberterrorism


According to a recent article, intelligence "chatter" indicates that criminals, terrorists or both (they can work together) may be contemplating cyberattacks that would, for example, target physical infrastructure capabilities such as power grids or institutions such as hospitals.

I've been interested in cyberterrorism for years. A friend and I published an article on it (In Defense of Cyberterrorism), in which we analyzed some of the scenarios that appear in the article I noted above, along with others. So I thought this would be a good time to opine about cyberterrorism -- Brenner on cyberterrorism, as it were.

There are two diametrically opposed schools of thought among computer security professionals, law enforcement officers, lawyers and others who think about cyberterrorism.

One is the FUD (fear, uncertainty and doubt) school: Those who take this view believe cyberterrorism is a myth. They argue that our computer systems are robust enough to resist any attempt to compromise them from the outside (more on this in a minute). Some claim that computer security firms hype the notion of cyberterrorism in order to frighten businesses and other entities into buying their services, services the companies say are essential to preserve computer systems from online analogues of the 911 attacks on the World Trade Center. Others who take this view suggest that government agencies do something similar, i.e., exaggerate the threat of cyberterrorism to maximize their funding.

The other school of thought is the Digital Pearl Harbor school: Those who take this view believe cyberterrorism represents a threat that is not merely analogous to the attacks on the World Trade Center, but that may pose a threat comparable to the Japanese attacks on Pearl Harbor. They contend that outside attackers could shut down power grids, disrupt communications and/or other essential services, cripple our economy and wreak various other kinds of havoc.

Before I proceed with Brenner-on-cyberterrorism, I want to note a caveat: Both schools tend to focus on "outside" threats, i.e., on terrorists who, working alone or in association with hired hackers, mount an external assault on domestic computer systems in an effort to shut them down, corrupt their operations or otherwise interfere with their proper functioning. This is the "purest," most obvious cyberterrorism scenario; it tracks much of what we have seen with cybercrime (hacking, cracking, viruses, etc. -- all external attacks). Since this is the primary focus of these two competing schools of thought, I am going to limit my comments to this scenario.

Before I proceed to those comments, however, I want to point out that there is another, actually more frightening cyberterrorism scenario: the "inside" threat. In this version, the terrorists plant someone inside a domestic operation -- a power company, a hospital, a financial institution, whatever seems a likely target. The "mole" may be in place for some time; there may, in fact, be multiple "moles," each located in a strategic position. These "moles" are in a position to have legitimate access to the computer systems which will be used in the attack. They are a virtual Fifth Column, seemingly trusted insiders who are actually rogue operatives. I fear that focusing too much on the external threat will lead us to underestimate the potential harms that can result from this inside threat.

But I digress. Time for Brenner-on-cyberterrorism.

I agree and disagree with both schools. I think the Digital Pearl Harbor conceptualization of cyberterrorism is simplistic and misses the point: I believe computer technology can be used effectively by terrorists, but not to achieve the same effects they accomplish with bombs and hijacked airplanes. I do not believe any cyberterrorist attack could ever have the visceral, awful impact of seeing those planes fly into the World Trade Center. That was a classic, perhaps the classic terrorist attack, because it not only produced the demoralizing effects associated with realizing that we can be physically attacked, it also showed how implements and incidents of everyday life can be turned against us. The mundane became awful -- we identified with the people in the WTC and with the people in the airplanes. And, unlike terrorist attacks in which we view the carnage after it has been inflicted, we were able to monitor the infliction of much of the carnage as it happened . . . which exacerbated our helplessness and horror.

I think cyberterrorism can have a similar impact insofar, and only insofar, as it disrupts the ordinary. I doubt, seriously, whether cyberterrorism could ever product (forgive me) the body count associated with the WTC or the Bali attacks, but I do not think that is the point of cyberterrorism. I think cyberterrorism is more about mind games than it is about carnage.

I think cyberterrorism could be used very effectively to undermine our sense of security, physical and/or financial. Take a simple example: Assume that ATM machines began to malfunction . . . first in Chicago, then in Seattle, then in Miami, then in Atlanta, then in Oklahoma City, then in Portland, then . . . . and on and on and on. The malfunctioning occurs in each city sequentially; perhaps it last basically the same period of time in each city . . . all of which makes it very clear that this is no accident. It seems to me that would be a dreadfully marvelous cyberterrorist mind game: We would not know if we could trust ATM's and, perhaps, the financial institutions that provide them.

Cyberterrorism to me is undermining our sense of security . . . undermining our trust in the things we take for granted. It could take more dramatic forms, such as shutting down power to the northeast states in January; that might, as I have been told, well result in many deaths. That would certainly be demoralizing. But a focused attack like that, and like the WTC, actually, I think, restricts the demoralizing effects of the attack. I can feel sorry for the people in the NE states, and I can fear that something similar might happen to me, but the harm, the carnage, is limited in scope.

If cyberterrorists were to mount something like my hypothetical ATM attacks, then follow that or combine that with other, similar attacks, it would have a very interesting effect, I think, on all of us. We would not confront carnage; we would confront the reality that our world was out of control.




Monday, May 15, 2006

NSA monitoring of telephone calls

A lot has been written about whether the NSA monitoring of the phone numbers Americans call is unconstitutional or otherwise illegal.

As I have explained elsewhere, monitoring of the numbers we call (and the addresses to which we send emails) is not unconstitutional but should be unconstitutional.

I analyze this issue in The Fourth Amendment in an Era of Ubiquitous Technology, an article I presented at a Fourth Amendment symposium last year. The bottom line is that the Supreme Court inexplicably got all this wrong almost 30 years ago, when it held that the Fourth Amendment does not apply to the use of a pen register to track the numbers dialed from a telephone, even a telephone in someone's home. The Court held, basically, that because we know the phone company gathers this information, we have no right to expect that it will not be given to police.

As many recognized at the time, the decision was wrong when it was issued. The Justices who signed on to the decision concluded that we know we are exposing "private" information to the phone company and, in so doing, assume the risk that it will voluntarily share this information with law enforcement. The Justices who dissented, notably Justice Marshall, pointed out the fallacy in this conclusion: The notion that we assume a risk is based on the premise that we have a choice -- here, to share or not to share this information with the phone company.

As Justice Marshall pointed out, we really have no choice. Our only options are (i) to use technology and run the risk that information about our use will be shared with the government or (ii) to become a Unibomber-style Luddite who does not use telephones . . . or email and other technologies, because the decision applies to any information we share with third-parties.

History is vindicating Justice Marshall and the other dissenters. Unfortunately, I fear it will be a very long time before the Supreme Court re-considers this issue (and, one hopes, gets it right this time).

Saturday, May 13, 2006

Virtual property, virtual crime

When property law -- civil and criminal-- evolved, "property" consisted only of tangible items like the land the farm depicted in this photograph occupied, the farm buildings and their contents.

This zero-sum conceptualization of property (i.e., property as real, tangible "things," animate and inanimate) prevailed essentially unchallenged until twentieth-century technologies began to make intangible property a socially and legally significant commodity.

The notion of intangible property was not entirely new. In Europe, the principle that one could hold an ownership interest in an intangible such as the ideas recorded in a printed volume of text or the principles underlying a new mechanical or other invention originated in the fifteenth century, the product, I would argue, of a new technology: the printing press. While one could always use handwriting to record ideas and mechanical principles, printing introduced a new possibility; one could produce many, many copies of such a record, copies that could be distributed throughout the country, throughout the Continent and even beyond.

The concept of intangible property -- specifically, the law of copyright and patents -- evolved to give the "owner" of original ideas some way to control the dissemination and use of those ideas. Controlling dissemination and use had become important because the ideas themselves now had "value;" they could be sold directly (books and, eventually, other works of art/entertainment) or could be used to produce revenue (inventions such as the automobile, telephone, etc.).

The law of copyright, patent and related intellectual property doctrines is now well-established (some, including me, would say too well established with regard to statutes like the DMCA). I am not particularly interested in that law or in the activities it is designed to protect.

What I am becoming interested in, and am writing about today, is a broader notion of intangible property -- something I will call "virtual property" to distinguish it from the more traditional types of intangible property to which we, and the law, are accustomed. Unlike these traditional types of intangible property, "virtual property" has not been incorporated into the law, civil or criminal. I want to speculate about how criminal law should deal with "virtual property."

The first thing I need to do is to define "virtual property," which is not easy. I cannot simply define it as property that exists only in digital form, because this would encompass a great deal of conventional intangible property that is protected by the patents, copyrights or other intellectual property law doctrines which I find uninteresting. But while I cannot base my definition entirely upon this asepct of "virtual property, I can incoporate it into my definition of "virtual property."

The first component of my definition, therefore, is that "virtual property" exists only in digital form. It differs from conventional intangible property, I think, in that its value derives entirely, or almost entirely, from activities that are conducted in the virtual world of cyberspace. As I noted above, the value of conventional intangible property lies in activities conducted in the real-world: We buy a book (printed or on tape) to read (listen to) it in the real-world; the same is true of music; and the same is true of the myriad of inventions (cars, refrigerators, TV's, hair-dryers, elevators, etc.) that have altered the way we conduct our lives in the real-world.

(I know stories and music can crossover from the real-world to the virtual world of cyberspace, but I am using rather broad strokes in this analysis . . . product of its being my first cut at the topic plus space limitations that do not let me use footnotes for lengthy asides.)

The ultimate example of "virtual property" as I define it is property that exists and is utilized in an online environment, such as a massively multiplayer online game or a virtual world like Second Life. Unlike stories (books, movies) or music, this type of intangible property is not transportable; it has value only within the online context. If this "virtual property" could be transported to the real, physical world, it would be meaningless; it would have no use and therefore no value.

So, we now have the notion of a specialized type of intangible property; property that only exists and has value in the context of online activities. From a legal perspective, this notion gives rise to two issues: (1) Do we recognize ownership and other traditional property rights in this "virtual property"? and (2) If so, how do we deal with those who infringe upon these property rights?

The first issue has been analyzed by scholars who specialize in civil property law, about which I know very little (what I vaguely recall from my first year Property class, plus buying a house). I will leave that issue to them. Basically, though, I believe -- and many agree -- there is no reason why we cannot recognize property rights in what I am defining as "virtual property" just as we recognize rights in tangible, real-world property and in conventional intangible property.

I think this recognition is already well on its way; a couple of weeks ago, Business Week had a story on entrepreneurs who earn money (good money) by selling goods that exist and are useful only within the confines of Second Life. These and other "virtual property" entrepreneurs operate on the assumption that they "own" the goods they sell, just as real-world entrepreneurs own what they purvey. And the legal validity of that assumption has been upheld in court; a couple of years ago, for example, a Chinese court held that a gamer "owned" the "virtual property" he had amassed while playing the online game Hongyue.

So I think we can justifiably assume the law protects/will protect ownership interests in "virtual" property just as it does in tangible and conventional intangible property. This first step is not conceptually difficult because it basically requires recognizing, and enforcing, contractual rights among people who are engaging in legitimate activities and are, therefore, likely to be obey the dictates of the law. We see this in the Chinese case I noted above.

The difficulty arises, as it always does, with the outlaws . . . with the people who reject legitimate activity and contumaciously violate contractual and other rights. How do we deal with those who steal or destroy "virtual property"? Do we make this a real-world crime and assign real-world law enforcement officers to apprehend the perpetrators, who are then, presumably, sanctioned in the real-world?

This has been done. Last year, Japanese police arrested a Chinese exchange student who was suspected of participating in "onine mugging" and theft that targeted gamers playing Lineage II. As far as I can tell, the Chinese student was arrested for theft -- for using bots to "run virtual stick-ups" in the game. This seems to be very unusual, though. The Hong Kong Police seem to have a special unit that deals with "virtual property" thefts in online games, but this is clearly the exception. My sense is that most law enforcement agencies would not see this type of theft as a matter they should pursue. I think there are several reasons for this.

One is, I suspect, the unstated but prevalent assumption that, after all, "it's just a game" and an online one at that. I think this assumption undercuts the possibility that law enforcement officers (and, no doubt, legislators and others involved in the articulation and enforcement of the law) will take online theft of "virtual property" seriously in two ways:
  • It reflects the view that the gamer-victims assumed the risk of being victimized by playing the game; many online games, after all, routinely feature various forms of mayhem and other antisocial activity. I imagine law enforcers would tend to see this as an anticipated consequence of participating in an optional endeavor and, as such, something that is not their responsibility; they would probably not regard this as "real crime." ("Real crime" being a phenomenon unique to the real, physical world in which our participation and the risks it engenders are distinctly not optional.) It is not, in other words, serious crime in the way real-world crime.
  • It reflects the view that "virtual property" is not really property (i) because it does not "really" exist (i.e., exists only online, not in the real, physical world) and/or (ii) because its value, if any, is unstable and therefore insignificant. (In a tragic case last year, a Shanghai gamer reported the theft of a virtual sword he used in Legends of Mir 3 to police, who said there was nothing they could do because the sword was not real property.)
Another reason law enforcement officers (and law-makers) are not inclined to take online crimes involving "virtual property" seriously is an issue I have written about before: There are simply not enough law enforcement resources to deal with cybercrime in any of its incarnations; police therfore tend to triage -- to prioritize the application of the resources that are available to online crimes. This prioritization emphasizes (i) crimes that "harm" individuals, such as cyberstalking, luring children for sexual encounters and child pornography; and (ii) crimes that target "real" property, such as identity theft, extorting money from businesses and the misappropriation of intellectual property.

Yet another reason may be that, as many have suggested, law enforcers and law-makers tend to see this as a matter that should be handled internally, by the operator of the game or those who participate in it. This does happen and can take either of two forms.
  • One is vigilantism: When law enforcement does not intervene, gamers have been known to take the law into their own hands. Earlier this year, for example, South Korean Lineage players were massacring Chinese players because they believed Chinese players were stealing "virtual property" from Korean players. (And, on another note, some citizens of Second Life crucified a game player who had been repreatedly killing other players.)
  • The other approach is initiated by the operator of the game, and reflects the emergence of customary norms online. Some games, for example, banish griefers (disruptive players) from the game.
Many who have examined the problem of online crime believe "internal" solutions such as these are the appropriate way to deal with online crimes that target "virtual property." Those who take this position tend to assume, I think, that there will always be a clear, radical distinction between "online life" and "real life." They tend to regard "online life" as more analogous to a hobby than to "real life." They therefore conclude that it would be unreasonable to extrapolate the laws and institutions we use to structure "real life" to the unreal, transient, less-than-serious life online.

I think they are wrong. I think we will see -- are in fact already seeing -- the distinction between "online life" and "real life" blur. I think this is evident in the Business Week article I mentioned earlier, the one that focuses on the entrepreneurs in Second Life. We will, for the foreseeable future, continue to live physically in the "real," empirical world, but I think more and more of our activities -- "serious" activities as well as activities some may dismiss as frivolous -- will migrate online.

The production of physical goods and the achievement of physical tasks (e.g., building houses and roads) will necessarily occur primarily in the empirical world. Other endeavors, however, can migrate substantially online; individuals, companies and agencies that provide services can operate substantially online. (Think of what this would do to alleviate the problems we currently experience with commuting to real-world working spaces and the pollution that causes). We will eventually inhabit both the offline and worlds, moving back and forth between them routinely and unconsciously. Earlier this year, a conference was held simultaneously at a site in Cambridge and in the virtual environs of Second Life. And this month the BBC held a virtual music festival that took place simultaneously in the real-world and in Second life.

I'm on the brink of digressing into another topic. What I really want to say is that the "internal" solutions I outlined above are a viable way of dealing with transgressions against "virtual property" as long as it remains a specialized, "lesser" species of property. Entrepreneurs like those described in the Business Week article noted above are already using commerce based upon "virtual property" to support themselves and their families. The trade in "virtual property" does, concedely, seem to be little more than a cottage industry at this point, but it will certainly grow. As it grows, "virtual property" will become more common, will come to play a greater role in our economies (the fused economies that derive from our simultaneously inhabiting the "real" and "virtual" worlds) and will markedly increase in value.

As "virtual property" moves into the mainstream and ceases to be a specialized, "lesser" species of property, we will no longer be able to rely on boutique measures like the internal solutions outlined above to protect it. We will, I believe, have to incorporate it into our legal system, just as we have incorporated the conventional intangible property I mentioned earlier.