skip to main |
skip to sidebar
You may have seen the story from Australia: The New South Wales Supreme Court held, essentially, that cartoons showing Bart, Lisa and Maggie Simpson (along with others?) having sex with each other was child pornography under New South Wales and Australian law. The defendant in the case apparently was convicted of using his computer to access child pornography after the images of the minor Simpsons’ orgy were found on his computer. He appealed to the NSW Supreme Court, arguing, apparently, that he could not be convicted because the child pornography wasn’t “real,” i.e.., its creation did not involve the use of real children. At least that’s how I understand it: The news reports say he appealed arguing that fictional cartoon characters could not be considered “people” within the scope of the child pornography law because the characters “plainly and deliberately” departed from the human form (as well know, at least those of us who watch The Simpsons). The Justice who wrote the opinion for the NSW Supreme Court found that if the images were those of real human beings, “such depictions could never be permitted. . . . Their creation would constitute crimes at the very highest end of the criminal calendar.” He also apparently said that while the primary purpose of the child pornography statutes was to stop the abuse of “real” children, it was also intended to deter the production of other material that could “fuel demand for material that does involve the abuse of children.”Such a conviction simply could not happen in the United States. As I’ve noted before, the U.S. Supreme Court has held that under the First Amendment, U.S. legislators can criminalize the possession, use and distribution of “real” child pornography because its creation involves the victimization of actual children. Back in 1976, as I noted earlier, the Court held that real child pornography could be criminalized even though it is not obscene (adult child porn is, of course, perfectly legal) because it does involve the victimization of children, who either cannot consent to what they’re involved in or whose consent would not be valid if they did. A few years ago, as I’ve noted before, the Supreme Court held that this rationale does not apply to virtual child pornography because no child is harmed in its creation; since virtual child pornography (like real child pornography) is speech, it’s protected by the First Amendment. And since no countervailing circumstances – such as harming a real child – militate against enforcing First Amendment protection in this context, virtual child pornography cannot be criminalized in the United States. The federal statutes that define child pornography specifically exempt cartoons and other depictions from that definition. Section 2256(11) of Title 18 of the U.S. Code says that the definition of child pornography contained in § 2256(8)(B) of Title 18 “does not apply to depictions that are drawings, cartoons, sculptures, or paintings depicting minors or adults.”
Maybe you saw the stories that were getting a fair amount of play a couple of days ago . . . the ones about the European Union’s new five-year plan to target cybercrime?
According to the press release and some other information I found, the plan encompasses conducting “remote searches” of computers. Neither the press release or anything else I can find online explains what, precisely, these “remote searches” would involve. At least one person speculated that it might consist of remotely installing keystroke loggers . . . an updated version of the perhaps apocryphal FBI “Magic Lantern” program. “Magic Lantern” was alternately described as a keystroke logger program or a Trojan horse program. A couple of years ago the German police were using a Trojan horse program – the Federal Trojan – to conduct remote surveillance of computers. That program seems to have targeted terrorists, in particular, . . . but it ended when the German courts held that the practice violated the law.I don’t know WHAT the EU’s “remote searches” initiative will involve. It might involve the use of keystroke loggers or Trojan horse programs . . . or it might simply involve the kind of searches the FBI is conducting courtesy of P2P file-sharing software. I also don’t really know how EU/European law would deal with the permissibility of conducting remote searches of either type, i.e., logger, Trojan or P2P. Since I don’t know what the EU initiative will consist of, or how EU law will deal with it, I decided to do a post analyzing how the first two kinds of remote searches – the use of keystroke loggers and Trojan horse programs – might work under US law. I’m not going to talk about the P2P option because, as I’ve written before, law enforcement’s using P2P software to access files you have opened up for file-sharing is not a “search” under our 4th Amendment. Since it isn’t a search, it doesn’t require that law enforcement obtain a warrant or otherwise comply with the 4th Amendment in conducting such an investigation. Installing a keystroke logger or a Trojan horse program on someone’s computer without their knowledge or consent (no P2P software or anything analogous) definitely would be a search under the 4th Amendment. As I tell my students, courts treat computers – more precisely, computer hard drives – as a closed container, and we have a 4th Amendment expectation of privacy in closed containers. So to install either a logger or a Trojan horse program, law enforcement would have to comply with the requirements of the 4th Amendment by obtaining a search warrant, or, to be more precise, a search and seizure warrant. Search warrants authorize officers to go to a particular place and search for particular evidence; they also authorize the officers to seize that evidence if and when they find it. To be a valid, a search (and seizure) warrant must be based on probable cause (to believe evidence of a particular crime will be found) and must “particularly describe” the place to be searched and the item(s) to be seized. So for a search (and seizure) warrant to remotely install a keystroke logger or a Trojan horse program, officers would have to show probable cause to believe that particular evidence will be found on the computer on which the program is to be installed. For the sake of analysis, we’ll assume that wouldn’t be a problem. The warrant would also have to “particularly describe” the place to be search, which is the computer on which the program is to be installed. So the warrant application, and the warrant, would have to include details that specifically identified the target computer. The description of the item(s) to be seized would probably take the form of describing the type of evidence that is being sought . . . evidence of child pornography, or terrorism, or fraud or whatever crime(s) the officers are investigating. About ten years ago, federal agents got a search warrant to install a keystroke logger on a computer being used by Nicodemus Scarfo, who was suspected of loansharking and illegal gambling. Actually, the agents got a couple of warrants because they did not install the logger program remotely; instead, they made a surreptitious entry into his office and manually installed the program. The program was used, successfully, to obtain the key – the passphrase – for an encrypted file the agents knew was on the computer. (You can find a summary of the facts in the opinion you can read here.) In this case, then, the use of the logger program to search for and seize the evidence was novel, but the process by which the program was installed was not so novel. The agents simply entered the office, accessed the computer and installed the program; entering the office was clearly a search (because you have a reasonable expectation of privacy in your office), as, I assume, was installing and using the logger program (we also have a 4th Amendment expectation of privacy in the keystrokes we type on our computer, at least when we’re using the computer in a private place, like our private office).
As I explained in an earlier post, I believe using the logger was both a search and a seizure, because it seized information about the keystrokes. But the search (and seizure) warrant authorizing the use of the logger program authorized the seizure of the keystrokes, so I think it covered all the bases there. Now let’s analyze the process of remotely installing a logger program or a Trojan horse program for the purpose of searching a suspect’s computer. I see this as presenting several novel issues, one of which goes to the process of installing the program.I think that one won’t prove particularly difficult to deal with. The USA Patriot Act authorized the use of surreptitious searches (something like the keystroke logger installation in the case above) to obtain information. The searches are called “sneak and peek” searches and the warrants authorizing them are called “sneak and peek” (S&P) warrants. The practice of issuing S&P warrants arose prior to the Patriot Act, but it formally brought them into federal law. When S&P searches began being conducted, they were charges on two bases: Unlike traditional searches and seizures pursuant to a warrant, they are conducted in secret; the whole point (as in the Scarfo case) is not to let the suspect know officers have been in his/her/their property looking for evidence. Traditional searches and seizures are conducted in public; the owner(s) of the property are often present when they are conducted, and they are given a copy of the warrant and an inventory of what was taken. None of that is true for S&P searches. Courts upheld S&P searches even though they differ markedly from the kinds of searches the 4th Amendment deals with because they found that these searches comport with constitutional requirements as long as they are conducted pursuant to, and in accordance with, a valid search warrant. So I think the process of installing a logger or Trojan horse program for the purpose of conducting a remote search of a computer could be justified under this same rationale; it would be necessary to include in the warrant a specification of how long the remote search could continue, but otherwise the basic S&P procedure would probably work here, as well. Describing the place to be searched should not, as I noted earlier, be a particular problem, nor should describing the evidence to be seized. I think, as I just noted, that specifying a particular time frame for the conduct of the search would be an essential element of satisfying this aspect of the 4th Amendment . . . because otherwise officers could install a program and let it sit on a computer indefinitely, perhaps gathering evidence of crimes neither they nor the suspect had contemplated when the original warrant was issued. I think the temporal dimension would be critical to satisfying 4th Amendment requirements here. The warrant would have to authorize the seizure of evidence, once found, but that, again, should not be a particular problem. The logger/Trojan program would have to be configured so that it only captured data within the scope of the warrant (though it that were impracticable, and if the data capture went beyond the scope of the warrant, that could presumably be dealt with by simply not letting the government use that evidence for any purpose). As long as the searching and seizing is being conducted automatically, i.e., by the program instead of by a human being, the “plain view” doctrine would not apply. As I’ve noted before, that’s a principle that expands the scope of a legitimate 4th Amendment search. If an officer has a search warrant to search my house for stolen jewels and sees a bag of cocaine (all this is hypothetical) on my coffee table, the officer’s looking at the bag of cocaine is not a search (because he has the right to be where he is) and if looking at it gives him probable cause to believe it’s evidence of a crime, he can seize it. I don’t see how the plain view doctrine can apply to the extent that the remote searches we’re hypothesizing would be conducted by a program, not a person operating the program. Finally, the use of these programs could not be lawfully conducted with only a search warrant if they in any way intercepted communications coming into or being sent from the computer being searched. Intercepting communications constitutes a wiretap, and wiretaps require a special authorization – a Title III order.
That became an issue in the Scarfo case because the computer had a modem and, as we all know, keystrokes are used to send emails and other communications. The government convinced the judge that the logger program used in the Scarfo case was configured so it shut off when the modem was active, so that overcame the Title III issue. That issue, though, would have to be addressed in future cases involving the use of logger or Trojan horse programs; if the government wanted to obtain communications as well as static data, they would have to get both a search warrant and a Title III order. There’s another huge issue, which I’ve written about before: The use of remote searches directed at computers that are outside the territorial boundaries of the United States. I'll take that up in another post.
As I explained in an earlier post, consent is an exception to the 4th Amendment’s requirement that law enforcement officers get a search warrant before searching your property for evidence of a crime. As an exception, consent eliminates the need to get a warrant. As I also explained, it’s essentially a waiver. I give up my right not to have my property searched.
But as I think I’ve noted before, consent acts like a contract. That is, my consent to search substitutes for a warrant as long as the officer’s search stays within the scope of what I’ve consented to.
So, if officers stop me and say, “Can we search for car for a stolen rifle”? and I say, “yes,”, they can search my car only in places where a rifle can be. My consent to their searching for a rifle defines the scope of my consent, That means they can’t search in the glove compartment, say. And that brief introduction leads us to U.S. v. Richardson, 2008 WL 4761735 (U.S. District Court for the Western District of Pennsylvania 2008). The facts in the opinion are too detailed to describe here, so I’ll just summarize essentially what happened.Law enforcement agents monitoring a website called ILLEGAL.CP, which the court says is “a website that published child pornography,” came to believe that Jamie Richardson had tried to log onto the ILLEGAL.CP site from his home. U.S. v. Richardson, supra. Since they didn’t have the probable cause to get a search warrant for Mr. Richardson’s home computer, three agents decided to go to his house and see if they could get him to consent to a search of the computer. The opinion notes that at least one of them was wearing blue jeans and other civilian clothing, including a jacket that “obscured” his gun “from view.” U.S. v. Richardson, supra. When they got to the house, they knocked on the front door and Richardson answered. They told him they were “looking into” the possible theft of his identity, including the misuse of one or more of his credit cards. U.S. v. Richardson, supra. They explained all this to Mr. Richardson and his wife while they were all sitting at the Richardson’s kitchen table. In its recitation of the facts, the federal judge notes that the “only purpose of the agents in referring to the fact that someone had improperly used” Richardson’s “credit card was to secure his cooperation; and the content of what was told to the Defendant was not false.” U.S. v. Richardson, supra. They never told him that someone using “his bank account, physical address, email address, IP addresses and . . . phone number” had tried to access the ILLEGAL.CP website. U.S. v. Richardson, supra.During the course of this discussion, the Richardsons told the agents that “certain occurrences, including previously unauthorized charges to their `credit cards and bank accounts’ and a previous telephone call from a `telemarketer’ may have resulted in theft of their identities.” U.S. v. Richardson, supra. So they were buying the story the agents were giving them. Richardson would later say he never felt he was a suspect in criminal activity, and the court notes that one of the agents “made an inference to the Richardsons that they were victims of identity theft `thoughout the entire time that [the agents] were there.” U.S. v. Richardson, supra.The agents finally got around to asking about computers in the home. Mr. Richardson apparently told them they had two computers, only one of which worked. U.S. v. Richardson, supra. The agents then asked Mr. Richardson if they could make a mirror image of the hard drive on that computer, and he “orally consented.” U.S. v. Richardson, supra. They left the room and then came back, with a consent to search form, which he signed. U.S. v. Richardson, supra.
During all of this, the agent who taken the lead in the conversation and the effort to get consent, “indicated that the purpose of searching the hard drives was to search `[f]or Internet activity’” but she did not tell “the Richardsons which `violation of law’ she was investigating”. U.S. v. Richardson, supra. She also later admitted that “`I may have used a ruse in the initiation of the interview’ and described her tactic as such: `I explained to him that there was some credit card activity over the Internet and it was his credit card, however, I didn't explain exactly what it was for, what the activity was or the website that was accessed.’” U.S. v. Richardson, supra. I could go on, but it seems pretty clear that Mr. Richardson was consenting to what he thought was a search of his computer for evidence that he’d been the victim of identity theft (when, in fact, he was consenting to its being searched for evidence relating to child pornography). I’ll skip over the detailed facts in the opinion that describe what follow, and just note that they did, in fact, find child pornography on the mirror image they took of the Richardson computer. Richardson moved to suppress the evidence, arguing that the search the agents conducted was outside the scope of what he had consented to.The court agreed: “It is clear that in this instance, a search for [child pornography] images on the hard disc drives was outside of the scope of the Defendant's consent to search.” U.S. v. Richardson, supra.Lieb and the other agents let the vagueness of their reference to `[“llegal”]' credit card activity over the Internet’ permit the Defendant's concern for himself or his wife being a victim of illegal use of their credit card to result in the Defendant's consent to search the two computers for such evidence. . . . However, Lieb's vague description also resulted in the unintended restriction of what one could consider was the objectively reasonable scope of the search.
U.S. v. Richardson, supra. In reaching this conclusion, the court quoted from a Seventh Circuit Court of Appeals decision: “Government agents may not obtain consent to search on the representation that they intend to look only for certain specified items and subsequently use that consent as a license to conduct a general exploratory search.” U.S. v. Dichiarinte, 445 F.2d 126 (7th Cir. 1971). The court held, therefore, that because “the ICE agents searched for matters beyond the scope of the consensual search, the images of child pornography revealed from the forensic examinations of all computer equipment seized or imaged and obtained must be suppressed as being beyond the scope of the oral and written voluntary consent granted by the Defendant.” U.S. v. Richardson, supra.
This post is about a federal identity theft case: U.S. v. Blixt, 2008 WL 5003239 (9th Circuit Court of Appeals 2008). Here, according to the Ninth Circuit, are the facts that resulted in Ms. Blixt’s being charged with identity theft:Blixt began working for Crawford and Company in 1998 in its Helena, Montana office. Crawford is a large international corporation, providing claim adjusting, vocational rehabilitation, and risk management services to its insurance company clients. At the time of the events leading to Blixt's conviction, Timothy Fitzpatrick was the branch manager.
When checks arrived from insurance companies, they were forwarded from the Helena office . . . to Crawford's headquarters in Atlanta via commercial carrier. From 2003 to 2004, it was primarily Blixt's responsibility to forward the packages.
The Helena branch maintained a checking account at Valley Bank, with Fitzpatrick having signature authority. . . . [I]n March, 2003, Blixt began to deposit client payments into the Valley Bank account. Blixt wrote approximately 352 checks from this account for her own personal gain, forging Fitzpatrick's signature on each check. The total amount of the checks was in excess of $150,000.00. . . .
In . . . 2004, Blixt began sending false accounting information to Crawford's Atlanta office to cover her actions. . . . Using this system, Blixt was able to orchestrate allocation of current funds to old accounts from which Blixt had stolen funds.
In August, 2004, Fitzpatrick was alerted by Valley Bank to `some unusual signatures on checks that were coming into the account.’ Ultimately, Blixt admitted her actions to Fitzpatrick.
U.S. v. Blixt, supra. Blixt was charged with committing (i) mail fraud in violation of 18 U.S. Code § 1341 and aggravated identity theft in violation of 18 U.S. Code § 1828A. The aggravated identity theft statute makes it a crime to, “during and in relation to” committing one of a number of specified federal felonies, knowingly use, “without lawful authority, a means of identification of another”. 18 U.S. Code § 1828A(1). The felony violations specified in § 1828A include mail fraud, so Blixt was charged with knowingly using a means of identification of another “during and in relation to” the commission of mail fraud. Section 1028A defines “means of identification” as “any name or number that may be used . . . to identify a specific individual, including . . . name, social security number, date of birth, . . . driver's license . . . number, . . . passport number, employer or taxpayer identification number”. 18 U.S. Code § 1028A(d)(7). Mail fraud consists of using the mails to execute a scheme to defraud. 18 U.S. Code § 1341. Blixt’s using the mail to send false accounting information to the Atlanta office would qualify as mail fraud because it helped her keep the scheme going when it might otherwise have been discovered earlier. Since the mail fraud statutes makes it a crime to use the mails to “execute” a scheme to defraud, it encompasses conduct other than the conduct actually involved in perpetrating the fraud, i.e., in securing the money or property that is the object of the fraud. Blixt was convicted of both counts and appealed, making a rather interesting but ultimately futile argument in challenging her conviction for the § 1028A offense. She claimed “she did not use another's name, she merely forged a signature, and because a forged signature is not separately identified as a `means of identification’ under § 1028A , her actions did not violate the statute.” U.S. v. Blixt, supra. The Ninth Circuit began its analysis of her argument by noting that[w]hether the use of another's signature constitutes a `means of identification for purposes of the Aggravated Identity Theft statute has not yet been resolved by this or any other circuit. Finding no prior authority on the issue, we hold as a matter of first impression that forging another's signature constitutes the use of that person's name and thus qualifies as a `means of identification’ under 18 U.S.C. § 1028A .
U.S. v. Blixt, supra. Seems that should be obvious, doesn’t it? It is obvious, as a matter of common sense, but courts can’t just rely on common sense. They have to be sure that a term used in the definition of a crime has been defined clearly enough, in the law, that a reasonable person would be able to find out precisely what is, and is not, prohibited. The premise that the law is knowable (reasonably clear) and available (published) is the basic reason why “ignorance of the law is no excuse” when it comes to the commission of crimes. If you can figure out what you’re not supposed to do, then you can’t go ahead and do that and then claim you didn’t actually know it was “wrong.”In analyzing Blixt’s argument, the Ninth Circuit Court of Appeals began noting that there is nothing in the definition of “means of identification” quoted above thatsuggests the use of another's name in the form of a signature is somehow excluded from the definition of “means of identification.”
Were we to find that signatures are categorically not names and thus not included within this definition, we would be disregarding the `settled principle of statutory construction that we must give effect, if possible, to every word of the statute.’ . . . By . . . `any’ to qualify the term `name,’ the statute reflects Congress's intention to construct an expansive definition. . . . Categorically carving out a signature from this definition, although a signature is commonly understood to be the written form of a person's name, would impermissibly narrow the definition of “name” in the statute. Thus, . . . a signature is a name for the purpose of applying the Aggravated Identity Theft statute.
U.S. v. Blixt, supra. Ms. Blixt also had another argument in her arsenal. She claimeda signature is no more than `a series of lines, curves, and squiggles,’ and that no one would be able to decipher Fitzpatrick's name from his signature. However, she does not dispute that Fitzpatrick's signature was meant to be a particularized rendering of his name. Fitzpatrick's signature, however illegible, was thus nothing more than his name written in a particular way and meant to identify him, specifically. Thus, in forging his signature, Blixt indisputably used another person's means of identification for an unauthorized purpose in violation of the Aggravated Identity Theft statute.
U.S. v. Blixt, supra. Finally, Ms. Blixt argued that the signature on a check isthe event that causes a check to be paid, not the name; and that this use of a signature is `not the theft of “personal data” contemplated by Congress when enacting this statute.’ . . . [T]he process used by banks to direct payment on a check in no way affects the legal question of whether forging another's signature constitutes the use of that person's name. More importantly, . . . the legislative history cited by Blixt more strongly supports a conclusion that Blixt's forgery of Fitzgerald's signature constitutes the use of a `means of identification’ because it conforms precisely to the conduct Congress sought to proscribe -- wrongfully obtaining and using Fitzpatrick's signature for her own economic gain.
U.S. v. Blixt. The Ninth Circuit upheld Ms. Blixt’s conviction on the § 1028A charge (and, for other reasons, on the mail fraud charge, as well).So, if you’re contemplating forging someone’s signature to commit mail fraud or any of a variety of other federal felonies, you’re on notice that you’re also contemplating the commission of aggravated identity theft, as well.
This is probably going to be a short post, because it’s about something I know essentially noting about: anti-forensics, or anti-computer forensics.According to Wikipedia, one definition of anti-forensics is that it consists of “`[a]ttempts to negatively affect the existence, amount and/or quality of evidence from a crime scene, or make the analysis and examination of evidence difficult or impossible to conduct.’”
That’s a good general definition, but my specific concern is with computer anti-forensics, which essentially consists of using software and other methods to alter, conceal and/or create computer evidence in such a manner as to frustrate forensic investigators. As the Wikipedia entry notes, anti-computer forensics is divided into several categories, one of which is “data hiding.” The techniques used in data hiding are familiar to most of us, I imagine; encryption and steganography are two kinds of data hiding. According to Wikipedia, another category involves the destruction of digital evidence; file wiping and disk degaussing fall into this category. This post is not about those techniques, for a couple of reasons. One is that they’ve been around for a while, and so are, I think, pretty familiar to most people who work with digital evidence and cybercrime. Another is that they involve putting digital evidence outside the reach of forensic investigators; while that can certainly have a negative impact on a civil or criminal investigation, it is a relatively straightforward process: The evidence either is available or it is not. The remaining category of anti-forensics is the one that interests me. Wikipedia calls this category “trail obfuscation” because it involves the use of techniques that can alter essential characteristics of digital evidence. The use of these techniques is not, as far as I can tell, something that law and lawyers are really familiar with, which could be, or become, a problem. As a recent article in the Sedona Conference Journal noted, anti-forensics could pose a problem for the American legal system (at least) because courts and lawyers currently tend to assume that digital evidence is reliable . . . perhaps even more reliable than other kinds of evidence. In 1999, a Missouri appellate court held that certain records “were uniquely reliable because they were computer-generated rather than the result of human entries.” State v. Dunn, 7 S.W.3d 427 (Missouri Court of Appeals 1999). The Tennessee Supreme Court said something similar a year earlier. State v. Hall, 976 S.W.2d 121 (1998). Though these cases were decided roughly a decade ago, some, including me, think the tendency to assume computer records are particularly reliable still exists, and may even have become more pronounced. The authors of the Sedona Conference Journal article note that the American legal system is, as a result, far too accepting of digital evidence. That might be changing. I found one reported opinion in which the use of anti-forensics was an issue. The case is a civil case, but that isn’t relevant. The issue of interest in the case is not a legal issue but a practical one.The opinion issued in Southern New England Telephone Co. v. Global NAPS, Inc., 251 F.R.D. 81 (U.S. District Court for the District of Connecticut 2008). Southern New England Telephone (SNET) sued Global NAPS about some issue involving misrouted traffic and access charges (civil litigation is not my strong suit). As in most civil suits, particularly complex federal civil suits, the parties engaged in discovery – the mutual disclosure of potentially relevant evidence – for a long time. Discovery seems to have gone on for almost two years, according to the district court’s opinion.In this opinion, the federal district court ruled on SNET’s motion to sanction Global NAPS “for failure to comply with discovery orders.” Southern New England Telephone Co. v. Global NAPS, Inc., supra. The motion was based on a number of allegations about Global NAPS’ lack of cooperation in the discovery process, one of which involved anti-forensics. At one point, SNET hired a forensic analysis company to conduct a “more intensive” forensic analysis of certain of the Global NAPS computers on which evidence relevant to the litigation might be found. The company found that a data-wiping program – Window Washer – had been used to delete files and then overwrite them. Southern New England Telephone Co. v. Global NAPS, Inc., supra. The court noted that whoever had used Window Washer “did not merely use the program in its default mode, but chose the `wash and bleach’ option, which overwrites deleted files.” Southern New England Telephone Co. v. Global NAPS, Inc., supra. That, though, is not what we’re really concerned with here. The forensic analysis company – LECG – also found that true anti-forensics software might have been used on the computer files:In order to determine what, or how many files, have been deleted, LECG relies on `metadata.’ Metadata is a record created for all files containing their name, the date, and where the data is stored on the disk, among other things. Metadata is stored in a database called a Master File Table (`MFT’). Generally, a deleted file maintains its metadata, so it is possible to determine some things about the deleted file even after it has been erased. However, when a deleted file has no metadata, `it is likely that anti-forensics software has been employed by the user to erase the file and clear the MFT data.
LECG determined that, out of 93,560 items in the MFT, nearly 20,000 had no metadata, meaning they had likely been erased using anti-forensic software . . . .
Southern New England Telephone Co. v. Global NAPS, Inc., supra.Later in the opinion, the federal judge notes that this, in conjunction with other evidence, convinced her that anti-forensic software had been used to destroy and/or alter files that might have been relevant to the litigation. Southern New England Telephone Co. v. Global NAPS, Inc., supra. Since she found the defendants had “willfully” violated the court’s discovery orders, the federal judge entered a default judgment against them (which means the plaintiff won). Southern New England Telephone Co. v. Global NAPS, Inc., supra.The anti-forensics techniques used in the case were not particularly sophisticated, but I find it interesting because it at least refers to such techniques. I suspect anti-forensics techniques are more likely to become an issue in civil litigation, at least at first, because civil litigants are sometimes able to pour a great deal of resources into the preparation of their cases. When millions (or billions) of dollars are at stake, litigants are likely to be willing to put a lot of money into preparing their cases.I might be right about that, or I might not (it’s happened). It might also be that the issue of anti-forensics assumes, and maintains, greater significance in the context of civil litigation. The use of computer search protocols, for example, seems to be far more prevalent in civil discovery than in criminal forensics. I really don’t know where any of this is going, but that won’t stop me from speculating. It seems to me that anti-forensics has the potential to (i) frustrate the conduct of computer forensic examinations by masking or altering digital evidence and/or (ii) give defense attorneys a new device they can use to try to persuade juries that digital evidence is too mutable to be reliable.
A California Court of Appeals recently decided a case that involved the difference between a completed crime and an attempt to commit that crime. The case is People v. Love, 166 Cal.App.4th 1292, 83 Cal.Rptr.3d 428 (Cal. App. 2008), and here are the facts that gave rise to the issue:[Ms. Love] worked as a receptionist for dentist Hamid N. (Dr. Hamid) during February and March 2005. Rosa D. (Rosa), a patient of Dr. Hamid, noticed on her credit card statement a charge of $91.98 for flowers she had not ordered. An investigator determined that the purchase was made from Dr. Hamid's office computer on Valentine's Day, a date on which defendant worked. Defendant's brother . . . testified that he had asked defendant to order the flowers on his behalf; they were delivered to a woman he was dating. Defendant admitted ordering the flowers in a recorded phone conversation with her mother.
Another patient of Dr. Hamid, Sadiq M., discovered that someone had charged to his credit card a $500 Victoria's Secret gift card without his knowledge or consent. Investigators traced the order, finding it had been placed on March 25, 2005, in Dr. Hamid's name and listed his office address. The credit card company placed a hold on the purchase, preventing the gift card from being issued.
People v. Love, supra. There were other, similar events. Ms. Love was eventually charged with 13 counts of “identity theft-based offenses . . . arising from abuse of her position of trust as a dental receptionist.” People v. Love, supra. We’re only concerned with one of those counts: Count 8, which was based on the March 25, 2005 charge for a Victoria’s Secret gift card. In Count 8, Ms. Love was charged with “fraudulent use of access cards or account information” in violation of California Penal Code § 484g(a): Every person who, with the intent to defraud, . . . uses, for the purpose of obtaining money, goods, services, or anything else of value, an access card or access card account information that has been . . . obtained . . in violation of Section 484e or 484f,. . . is guilty of theft. If the value of all money, goods, services, and other things of value obtained in violation of this section exceeds four hundred dollars ($400) in any consecutive six-month period, then the same shall constitute grand theft.
Sections 484e and 484f criminalize the act of using another person’s access card or access card information without their permission. Another section of the California Penal Code defines “access card” as “any card, plate, code, account number, or other means of account access that can be used . . . to obtain money, goods, services, or any other thing of value, or . . . to initiate a transfer of funds, other than a transfer originated solely by a paper instrument.’” California Penal Code § 484d(2). So, in Count 8 Ms. Love was essentially charged with theft. She claimed she could not be charged with the completed crime of theft because the credit card company put a hold on the purchase: “Defendant contends that, because the credit card company cancelled the order and prevented the Victoria's Secret gift card from being issued pursuant to her use of Sadiq's credit card, her actions amounted to `at best’ an attempted theft under section 484g.” People v. Love, supra. So she’s saying that since she never got the $500 Victoria’s Secret gift card, she did not actually “obtain” money, goods, or “anything else of value” that did not really belong to her and could, at most, be charged with attempting to do so.As I may have noted before, an attempt is what the law calls an inchoate, or incomplete, crime. When you charge someone with attempt, you by definition concede that they did not actually succeed in completing a crime; instead, you are pLovecuting them for trying to commit the crime. Often, attempt charges arise from situations – like this one – in which the would-be perpetrator’s effort to commit a crime is frustrated by outside forces. Even though the would-be perpetrator’s failure to commit the crime is not due to any change of heart on his or her part, we still cannot convict them of committing the crime they were intending to commit. It’s a basic, albeit implicit, premise of criminal law that you can only be convicted of, and punished for, what you actually succeed in doing.To avoid having to let someone like this go scot free, Anglo-American law came up with the idea of prosecuting them for what they actually did . . . for trying to commit a crime (but failing). The charge we use to do that is attempt. As I tell my students, there is no free-standing offense of “attempt.” Instead, you necessarily attempt to commit a real, complete crime: the target crime. An attempt charge is always phrased like this: "Doe attempted to commit [the target crime]." If, therefore, you try to hire a hitman to kill your rich uncle and wind up “hiring” an undercover police officer, you have attempted to solicit the crime of murder and can be prosecuted for that.
(Actually, you could also be charged with attempting to commit murder, on the grounds that you would have been guilty of murder if the person you hired had really been a hitman and had actually killed your rich uncle. If all that happened, you would be guilty as an accomplice to the murder, which means you'd be guilty of murder.) Here, Ms. Love is arguing that she tried to commit theft, but failed. So she’s claiming she can only be convicted of the attempt, which will carry a lesser penalty than actually committing theft. (It’s another premise of criminal law that we can’t punish you as severely for trying and failing to commit a crime as we can if you succeed.)Unfortunately for Ms. Love, this court didn’t buy her argument:Section 484g, subdivision (a). . . may be broken down into two elements: (1) that defendant `use[ ]’ the access card or account information, and (2). . . do so `for the purpose of obtaining money, goods, services, or anything else of value.’ . . .
The evidence at trial satisfied the first element of section 484g, subdivision (a)-defendant `use[d]’ the card. Merriam-Webster's New Collegiate Dictionary defines `use’ in such a context as `to put into action or service: avail oneself of: employ. . . . Defendant `use[d]’ or `put into . . . service’ Sadiq's access card information by entering it into an Internet Web page to place an order. The conduct described by the plain language of the statute is completed regardless of whether the object is obtained. . . .
The evidence also satisfied the second element that defendant's `use[ ]’ was `for the purpose of obtaining money, goods, services, or anything else of value.’ The obvious and undisputed purpose behind entering Sadiq's access card information into the Internet was to acquire the Victoria's Secret gift card.
Because the evidence established both elements described plainly in section 484g, subdivision (a), we find there was sufficient evidence to convict defendant of the completed offense.
People v. Love, supra. Ms. Love lost because the crime defined by this statute is itself a type of inchoate crime. That is, it criminalizes PART of the conduct involved in actually carrying out a type of theft. One of the things we have seen in modern criminal law (especially in the United States) is a tendency to divide crimes up into parts, so that you can be charged for (and convicted of) each part. The implicit premise of this statute is that you (a) commit one crime by using the card for the purpose of obtaining money, goods, etc. and (b) commit another crime if you go further and actually obtain those items. So statutes like this are at once free-standing attempt provisions (that is, they don't require a target crime, as such) and provisions that can increase the liability imposed for what is, in effect, theft.
I’ve done a couple of posts on the rules that govern Customs searches of laptops travelers are carrying into or out of the United States. In those posts, I explained that the rules evolved to deal with luggage and other “containers.”
As I also explained, the traditional rule – in the U.S. and elsewhere – is that Customs agents can search us and whatever we carry as we enter into or leave the country.
The premise is that the sovereign has the right to know what is coming into and out of the country. The default target of the border search rule is contraband: child pornography, drugs and other items the possession of which is illegal in and of itself. But it can also encompass other items – such as terrorist materials, weapons, etc. Whatever a traveler is carrying that is illegal to possess can be seized in a border search. I did a presentation last week at which we talked about a related issue I did a post on: your ability to take the 5th Amendment privilege against self-incrimination and refuse to give up encryption key so border agents can access the contents of your encrypted laptop computer. As I explained there, a Vermont federal court judge held that the act of producing the encryption key constitutes incriminating “testimony” within the compass of the 5th Amendment privilege. If that decision is upheld on appeal (and I’m assuming it is being appealed), then it means you can effectively put the contents of your hard drive beyond the reach of Customs agents (unless and until they’re given encryption-cracking software or can send laptops off somewhere to have the encryption cracked, but we’ll get back to that). At the presentation last week, someone who seems knowledgeable said Customs agents are seizing encrypted laptops and not giving them back. According to this gentleman, the legal basis for their doing this is a rule that lets Customs agents seize locked luggage you refuse to open. I found that possibility interesting on several levels.For one thing, I wasn’t sure Customs agents can, and have, seized luggage under this theory. I assumed they simply got the bag or luggage or other container open, somehow (which nearly happened to me in Brussels a few years ago when the zipper of a nearly new bag jammed the night before I left . . . but a very clever Customs agent managed to get it to work where I had been unable to). I checked the federal regulations governing what Customs agents are authorized to do, and found two pertinent provisions. Section 148.21 of title 19 of the Code of Federal Regulations provides as follows:A Customs officer has the right to open and examine all baggage, compartments and vehicles brought into the United States . . . . To the extent practical, the owner or his agent shall be asked to open the baggage, compartment or vehicle first. If the owner or his agent is unavailable or refuses to open the baggage, compartment, or vehicle, it shall be opened by the Customs officer.
A similar provision appears in §1462 of Title 19 of the Code of Federal Regulations:If such owner, agent, or other person shall fail to comply with his demand, the officer shall retain such trunk, traveling bag, sack, valise, or other container or closed vehicle, and open the same, and, as soon thereafter as may be practicable, examine the contents, and if any article subject to duty or any article the importation of which is prohibited is found therein, the whole contents and the container or vehicle shall be subject to forfeiture.
So the regulations explicitly authorize a Customs officer to open luggage or another container if the owner refuses to do so. Customs officers can simply break into the bag or container, which means they will be able to determine what’s inside. Having done so, they can either give the mutilated bag back to its owner (who may or may not be going on his or her way, depending on what they find inside) or seize the bag and its contents for forfeiture.
Other regulations provide for the “summary forfeiture” of illegal drugs; that simply means they’ll be taken and deemed forfeitable property. See 19 Code of Federal Regulations § 162.45a. In other instances, the government has to serve notice and follow certain procedures to forfeit the property; this option applies when the property is not contraband (illegal in itself) but is subject to forfeiture for some other reason. 19 Code of Federal Regulations § 162.49. Okay, let’s get back to laptops. If someone is crossing the border with an unencrypted laptop, a Customs officer can simply boot it up and look through the files himself. It’s analogous to an unlocked suitcase.If someone is crossing the border with a laptop the hard drive of which is encrypted, then things become more interesting. If the owner of the laptop refuses to either use the key to give the Customs agent access to its contents or give the key to the agent so he can access it himself, that refusal should trigger the application of the provisions quoted above.
In other words, it would authorize the Customs agent to “open the container” himself . . . except he can’t, as things stand now. If the Vermont federal judge’s decision stands, then the owner of the laptop can cite the 5th Amendment privilege against self-incrimination as his or her basis for refusing to give up the encryption key as long as he or she can show that doing so would not only be “testimony,” it would be “incriminating” testimony. (To be able to take the 5th, you also have to be “compelled” to give testimony that incriminates you, but we’ll assume that can be satisfied here; in the Vermont case, the laptop owner was subpoenaed by a federal grand jury, so compulsion was not a problem.)If we assume the owner of the laptop can, in fact, take the 5th and refuse to give up the encryption, then we seem to be at an impasse not contemplated by the drafters of the federal regulations governing what Customs agents can do at the border. They can’t search the encrypted hard drive, and if they can’t search it, they can’t seize the laptop for forfeiture because they won’t know what, if any, illegal items it contains. According to the gentleman who raised this issue at my presentation, Customs agents confronted with this impasse are simply seizing encrypted laptops . . . which seem to disappear indefinitely. I have heard some rumors about encrypted laptops being seized, but I have no personal knowledge of that nor do I have any authoritative sources to cite on that. But for the sake of analysis, let’s assume this is, in fact, happening.If it is happening, is it legal? I don’t see how it can be. If the laptops are seized to be held until Customs agents have the ability to crack their encryption and access their contents, it seems to me that is an illegal forfeiture of the property. That is, it seems to me the government is in effect depriving you of your property for good; forfeiture, of course, is a formal or informal process by which the government takes property away from the owner . . . permanently. Here, the government’s seizure of an encrypted laptop is not technically that kind of forfeiture because it is not inevitably a permanent seizure of the property; the premise is that the property is being seized until the government can open it. The provisions I quoted above implicitly authorize that kind of a seizure, although at a much lower level. That is, a Customs officer could seize, say, a really secure metal (titanium) briefcase intending to open it later, when he gets the necessary tools and/or assistance. That kind of seizure, though, differs in a significant respect from the kind of seizure we’re hypothesizing and analyzing here.
In this seizure of an encrypted laptop, there is no certainty that the laptop will be returned to its owner because the owner has no way of knowing when, or if, Customs agents will be able to crack its encryption and access its contents. In the luggage seizure scenario, the person knows they will at some point get their bag back, along with any non-contraband and/or otherwise non-illegal items it contained. In the encrypted laptop scenario, the owner may never get the laptop back, or may get it back at such a distant point in time that it has ceased to be of any use. (We also have the related issue of the seizure of the laptop’s depriving its owner of the possession and use of the data it contains.)As I said, I don’t know if any of this is really happening, but if it is, it seems to me it could be challenged as constituting an illegal forfeiture.
A recent case from North Carolina highlights the role mens rea – or intent – plays in a criminal prosecution. The case is State v. Ramos, 2008 WL 4906318 (N.C. App. 2008), and here, according to the court, are the facts that resulted in charges against being filed against Ms. Ramos:Defendant was hired as a community outreach coordinator by the Latin American Resource Center (`LARC’) on 15 May 2005. Her supervisor was LARC's director and founder, Aura Camacho-Maas. . . .
One of [her] responsibilities was to write grant proposals. . . . One . . . was supposed to be completed by 1 August. . . . On 1 August, the proposal was not complete, and defendant and Camacho-Maas had to work until midnight to get the proposal done.
Camacho-Maas assigned defendant a second proposal. . . [It] required [her] to access computer files related to LARC's teacher apprenticeship program (`TAP’). When . . . the proposal was still not completed, Camacho-Maas and defendant . . . had to work on the grant proposal together.
Camacho-Maas told defendant she was being terminated because she was unable to do the work required for her position. When Camacho-Maas asked defendant for her keys . . . defendant refused to hand them over until she received her paycheck. Camacho-Maas explained . . . she would receive her paycheck at the end of the month, and defendant left the building. Camacho-Maas . . . told the receptionist defendant had been terminated and was not to enter the building without Camacho-Maas being present. . . .
[A short time later,] Camacho-Maas realized the receptionist and defendant were . . . coming out of defendant's office. Camacho-Maas . . . went into defendant's office, sat down at defendant's computer, and discovered the TAP files were missing from LARC's server. Camacho-Maas had seen the TAP files on the server earlier that day. . . . Only LARC employees have access to the TAP files, and Camacho-Maas had not authorized anyone to move or remove the TAP files. Camacho-Maas called the police. . . .
State v. Ramos, supra. When the detective assigned to the case met with Ms. Ramos, she admitted she hadcopied files onto her flash drive. Detective Williams asked defendant to accompany him to the police station so he could copy the contents of the flash drive. A member of the Raleigh Police Department's cybercrimes unit found approximately 304 LARC files on defendant's flash drive, 80% of which were TAP files that were `either deleted or deleted and overwritten.’
State v. Ramos, supra. Ms. Ramos was charged with damaging a computer in violation of a North Carolina statute: “It is unlawful to willfully and without authorization alter, damage, or destroy a computer, computer program, computer system, computer network, or any part thereof.” North Carolina Statutes § 14-455(a). At her trial on the charge, the court gave the jury this instruction on what was required to find her guilty of the charge:The defendant, Geraldine Lewis Ramos, has been charged with the misdemeanor of damaging a compute [sic] system or computer network, or any part thereof.
For you to find the defendant guilty of this offense the State must prove two things:
First, that the defendant damaged a computer system or computer network or any part thereof by deleting a file or files from the computer system or computer network.
Second, that the defendant did so without authorization. A person is without authorization when although the person has the consent or permission of owner [sic] to access a computer system or computer network the person does so in a manner which exceeds the consent or permission.
If you find from the evidence beyond a reasonable doubt that on or about August the 15th, 2005 the defendant, without authorization, damaged a computer system or computer network, it would appeal [sic] your duty to return a verdict of guilty.
State v. Ramos, supra. She was convicted and appealed, arguing that the instruction was insufficient because it didn’t tell the jury they had to find she acted “willfully” in order to convict her. State v. Ramos, supra. The prosecution argued that there was no error because the court instructed the jury they had to find that she acted “without authorization.” According to the prosecution, “without authorization” and “willfully” are synonymous. State v. Ramos, supra. The North Carolina Court of Appeals did not agree:Our General Assembly defined `authorization for purposes of computer-related crimes . . . as meaning `having the consent or permission of the owner, or of the person licensed or authorized by the owner to grant consent . . . to access a computer, computer system, or computer network in a manner not exceeding the consent. . . `[W]ilful’ . . . means the wrongful doing of an act without justification or excuse, or the commission of an act purposely and deliberately in violation of law.’ . . . One may act `without authorization,’ but still not act willfully. For example, a person who accidentally deletes files is not acting willfully, but has deleted the files without authorization.
State v. Ramos, supra. The issue of willfulness was essential in deciding whether Ms. Ramos was guilty of the charge because, as she explained, she believed Camacho-Maas had authorized herto delete files amounting to her own work. Defendant testified that, at the time of her termination, defendant told Camacho-Maas, `since my work is no good I guess you won't mind if I take my work off computer [sic].’ According to defendant, Camacho-Maas responded, `. . . that the work was not good, and it was no consequence.’ Defendant testified that Camacho-Maas followed defendant into her office while defendant was deleting the files. Defendant testified Camacho-Maas “didn't say anything, but she knew what I was doing at that time, reason [sic] I walked back down to the room.” Defendant claimed that the only files that she deleted were:
[t]he . . . research that I had done for the curriculum. I deleted part of the grant which was the grant that I had written. I think that was about three, three files, but it was not the TAP file.
TAP file was in the server. It was a server and, in order for, to go into the server. She had already worked in the server, so I could not [sic] to go into the TAP file.
State v. Ramos, supra. From this, the North Carolina Court of Appeals held it was error for the trial court not to have instructed the jury on the issue of willfulness:Based on this testimony, the jury could reasonably find that defendant intended only to delete files she believed -- according to the State, incorrectly -- Camacho-Maas had consented to her deleting. . . . A jury could further find, based on defendant's testimony that she did not intend to delete the TAP files and did not believe she could enter the TAP files while Camacho-Maas was working on them, that any deletion of the files was accidental. Thus, the record contains evidence that would allow a jury to find that she deleted files without authorization, but not willfully. The trial court's failure to include willfulness in its instructions cannot, therefore, be deemed harmless error.
State v. Ramos, supra. Personally, I cannot understand why the trial court did not instruct the jury on willfulness. It is a basic, historic principle of criminal law that you cannot be convicted of a crime unless you acted with the mens rea – the criminal intent – required for the commission of that crime.
On November 3, I wrote about a decision in which a court held that the use of EnCase forensic software was a search under the 4th Amendment. This post is about a related but slightly different issue: whether the use of password-protection on computer files establishes a 4th Amendment expectation of privacy in those files.As I explained in an earlier post, the 4th Amendment gives us a right to be free from “unreasonable” searches and seizures. As I also explained there, a “search” violates a reasonable expectation of privacy in a place or a thing. If something isn’t private, then it isn’t a search for law enforcement officers to explore it.A case I’ve mentioned before – U.S. v. Andrus, 483 F.3d 711 (10th Cir. 2007) – dealt with whether the use of password-protection on files establishes a reasonable expectation of privacy in those files. In the Andrus case, a father consented to the search of his son’s laptop. The laptop files were password-protected; since the father didn’t know the son’s password, he couldn’t have accessed the files.
So the issue was whether his consent to the search of the files – which an investigator accessed by using EnCase to bypass the operating system – was valid. As I explained in an earlier post,, consent to search can be valid in either of two ways: the person has actual authority to consent to the search (he owns the laptop or uses a laptop owned by someone else); or the police officers reasonably, but mistakenly, believed the person had authority to consent. Since the father wasn’t able to access the computer himself, he didn’t have actual authority to consent to the search. So the issue was whether the police reasonably believed he had authority to consent to the search. As I explained in the earlier post, to have a reasonable expectation of privacy in a thing, you have to have a subjective expectation of privacy that society is prepared to regard as objectively reasonable. As the Andrus court noted, theinquiry into whether the owner of a highly personal object has indicated a subjective expectation of privacy traditionally focuses on whether the subject suitcase, footlocker, or other container is physically locked. . . . Determining whether a computer is `locked,’ or whether a reasonable officer should know a computer may be locked, presents a challenge distinct from that associated with other types of closed containers. Unlike footlockers or suitcases, where the presence of a locking device is generally apparent by looking at the item, a `lock’ on the data within a computer is not apparent from a visual inspection of the outside of the computer, especially when the computer is in the `off’ position prior to the search.
U.S. v. Andrus, supra. The Andrus court explained that in deciding whether someone has apparent authority to consent to a search of a computer, courts have looked at the officers’ “knowledge about password protection as an indication of whether a computer is ‘locked’ in the way a footlocker would be.” U.S. v. Andrus, supra.
As the Andrus court noted, another federal court held that apparent authority did not exist when “a live-in girlfriend . . . told police she and her boyfriend shared the household computer but had separate password-protected files that were inaccessible to the other.” U.S. v. Andrus, supra. Since the police were on notice that she couldn’t access the files, they couldn’t have reasonably believed she had the authority to consent to a search of the files.In the Andrus case, the officers knew Andrus’ (91-year-old) father owned the house where both lived and paid the Time Warner bills for Road Runner service to the house. The court noted that the father didn’t tell them he didn’t use the computer (though there was some evidence he’d told them he didn’t know how to use it). The real issue, though, was on whom the burden of clarifying the status of password-protection on the computer fell:Andrus argues his . . .password protection indicated his computer was `locked’ to third parties, a fact the officers would have known had they asked . . . [his father] prior to searching the computer. Under our case law, however, officers are not obligated to ask questions unless the circumstances are ambiguous. In essence, by suggesting the onus was on the officers to ask about password protection prior to searching the computer, despite the absence of any indication that [his father’s] access to the computer was limited by a password, Andrus necessarily submits there is inherent ambiguity whenever police want to search a household computer and a third party has not affirmatively provided information about . . . password protection. Andrus' argument presupposes, however, that password protection of home computers is so common that a reasonable officer ought to know password protection is likely.
U.S. v. Andrus, supra. The court noted Andrus had not offered “any evidence to demonstrate a high incidence of password protection among home computer users.” It therefore held that the father had apparent authority to consent to the search. There was a dissent. The dissenting judge noted that the majority of the judges had conceded that is password protection were `shown to be commonplace, law enforcement's use of forensic software like EnCase . . . may well be subject to question.’ . . . But the fact that a computer password `lock’ may not be immediately visible does not render it unlocked. . . . [U]nlike the locked file cabinet, computers have no handle to pull. But, like the padlocked footlocker, computers do exhibit outward signs of password protection: they display boot password screens, username/password log-in screens, and/or screen-saver reactivation passwords.
U.S. v. Andrus (dissenting opinion). The dissent found that the “burden on law enforcement” to ascertain whether or not a computer is password protected is “minimal,” requiring only a “simple question or two”. Accordingly, . . . given the case law indicating the importance of computer password protection, the common knowledge about the prevalence of password usage, and the design of EnCase or similar password bypass mechanisms, the Fourth Amendment . . . mandate[s] that in consent-based, warrantless computer searches, law enforcement personnel inquire or otherwise check for the presence of password protection and, if a password is present, inquire about the consenter's knowledge of that password and joint access to the computer.
U.S. v. Andrus (dissenting opinion). I tend to agree with the dissent. It seems to me police don’t have to ask about password-protection if they only intend to turn the computer on and look through its contents; doing that simply gives them access to files ANYONE could examine on the computer. If, though, they intend to use EnCase “or similar password bypass” software, it seems to me the burden should be on them to find out if, in so doing, they’re about to override passwords that have been installed to establish a heightened expectation of privacy. In other words, if the officers know that the techniques they’re using COULD bypass passwords or other privacy-protection measures, then the onus is on them to determine whether those measures have, in fact, been installed on the computer. If so, it seems to me they cannot use these techniques unless they obtain a search warrant specifically authorizing them to do this.
Last year I did a post in which I speculated on whether we really need corporate identity theft statutes (among other things). As you may know, most identity theft (and identity fraud) statutes make it a crime to steal a real person’s – a human being’s – identity. I think they take this approach because the theft of the identities of real human beings has been the problem the law and other aspects of our societies have been dealing with since it became apparent that you can misappropriate what statutes usually refer to as “personal identifying information.” Most, if not all, of the identity theft/fraud statutes do not explicitly say they only apply to individuals, but they achieve that effect by defining “personal identifying information” as things like Social Security numbers, birth dates, mother’s maiden name, driver’s license numbers, etc. In the earlier post, I talked about a case in which a paralegal effectively stole the identity of a law firm, a corporate entity. Since she was charged with grand larceny, the issue of identity theft did not (and presumably could not have) come up.After I wrote that post, the Georgia Court of Appeals decided a case involving corporate identity theft. The case is Lee v. State, 283 Ga. App. 826, 642 S.E.2d 876 (2007) and here are the facts:Lee used to work for Snelling Personnel Services, a company that provides temporary workers for businesses. Lee had received payroll checks from Snelling and had kept in contact with the company to update his file, most recently in August 2004. On December 6, 2004, someone using the fictitious name of James Strobridge ordered 500 Snelling payroll checks from NEBS Business Forms in Massachusetts. The order was placed from Lee's cellular telephone and the address to which the checks were to be shipped is Lee's home address of 17 Mikell Street in Statesboro.
Four days later, on December 10, a second call was made from Lee's telephone to NEBS, inquiring about the status of the order. That same day, the shipment of the 500 payroll checks to be delivered to Lee's house arrived in Statesboro. The delivery driver, however, recognized that the Mikell Street address is a private residence and he knew that Snelling's office is actually located on South Zetterower Avenue; so he delivered the shipment to the business office on South Zetterower.
No one at Snelling had ordered the checks, which contain the number of a Snelling bank account that, on average, carries an $80,000 balance. Snelling's branch manager called the police. Upon discovering that the fraudulent order had been placed from Lee's phone and was to be sent to his address, the police arrested Lee.
Lee v. State, supra.Lee was charged with identity fraud under Georgia Code § 16-9-121. At the time, this statute read as follows:A person commits the offense of identity fraud when without the authorization or permission of a person with the intent unlawfully to appropriate resources of or cause physical harm to that person, or of any other person, to his or her own use or to the use of a third party he or she:
(1) Obtains or records identifying information of a person which would assist in accessing the resources of that person or any other person; or
(2) Accesses or attempts to access the resources of a person through the use of identifying information.
The language in the opinion is a little murky, but I gather that Lee argued he could not be guilty of identity fraud because, as I noted earlier, the crime is normally considered to be committed only when someone misappropriates the identity of a real person. Here, the identity that was stolen was that of a corporation – Snelling. I think Lee must have made this argument because the Georgia Court of Appeals explained thatthe applicable definition of `person’ for all of Title 16 is found in [Georgia Code] § 16-1-3(12), which states that: `”‘Person’ means an individual, a public or private corporation, an incorporated association, government, government agency, partnership, or unincorporated association.”’ Accordingly, Snelling is a `person’ under the identity fraud statute, and there is sufficient evidence from which a rational trier of fact could have found beyond a reasonable doubt that Lee is guilty of identity fraud in that he attempted to access Snelling's resources through the use of its bank account information and the fraudulent payroll checks.
Lee v. State, supra. The court therefore affirmed his conviction.I actually think that’s a good outcome. Lee could probably also have been charged with fraud, but it seems to me that identity fraud (or identity theft) really captures what he did: He misappropriated and misused Snelling’s “Identifying information.” In a footnote the court noted that under Georgia Code § 16-9-120(4)(D) and (E), “the term `identifying information’ as used in the identity fraud statute includes checking and savings account numbers.” Lee v. State, supra.Since I actually this is a good outcome, I’m mystified by the fact that it won’t work anymore, at least not in Georgia. Effective May 24, 2007, the Georgia legislature changed the state’s identity theft statute so it now reads as follows:(a) A person commits the offense of identity fraud when he or she willfully and fraudulently:
(1) Without authorization or consent, uses or possesses with intent to fraudulently use, identifying information concerning an individual;
(2) Uses identifying information of an individual under 18 years old over whom he or she exercises custodial authority;
(3) Uses or possesses with intent to fraudulently use, identifying information concerning a deceased individual;
(4) Creates, uses, or possesses with intent to fraudulently use, any counterfeit or fictitious identifying information concerning a fictitious individual with intent to use such . . . information for the purpose of committing or facilitating . . . a crime or fraud on another person; or
(5) Without authorization or consent, creates, uses, or possesses with intent to fraudulently use, any counterfeit or fictitious identifying information concerning a real individual with intent to use such . . . information for the purpose of committing or facilitating the commission of a crime or fraud on another person.
Georgia Code § 16-9-121 (as revised). As you can see from the definition of "person" quoted above, the law regards an "individual" as a human being, i.e., not as a corporate or other artificial legal entity. I wonder why the Georgia legislature changed the statute. The original version could be used to prosecute identity theft/fraud directed at an individual; its advantage what that it could also be used to prosecute the kind of corporate identity theft at issue in the Lee case. Since I can’t find an explanation in the legislative history of the act that revised the statute, or anywhere else, I guess I’ll just have to wonder. Maybe the Georgia legislature decided we should NOT criminalize corporate identity theft/fraud. I really can’t imagine why, though.
A few months ago I did a post on a case from Wisconsin: State v. Baron, 2008 WL 2201778 (Wisconsin Court of Appeals).
As I explained in that post, the issue in the case was whether the defendant had committed defamation or identity theft. He was prosecuted for identity theft, but the facts of the case seemed more to establish defamation than identity theft.
As I explained in that post, the defendant in the Baron case gained access to his boss’ computer without being authorized to do so and used that access to forward embarrassing emails. When he forwarded the emails, he was pretending to be his boss. State v. Baron, supra. He later told he sent the emails so people could see that his boss really wasn’t “golden.” State v. Baron, supra. Whether the charge against Baron was identity theft or defamation was crucial. As I explained earlier, we have a First Amendment right to criticize the conduct of public officials. Baron’s boss qualified as a public official. Therefore, if what he did was really defamation, he had a valid First Amendment defense, which would result in the case’s being dismissed. If what he did was identity theft, then the First Amendment would presumably not be a defense.The Wisconsin Court of Appeals held it was identity theft, not defamation. The court found that because the identity theft statute made it a crime, among other things, to use another person’s personal identifying information to “harm” their reputation, it was an identity theft statute, not a defamation statute. Essentially, the court held that the use of another person’s identity was an element that served to differentiate this crime from defamation. In defamation, you publish comments that can, or do, damage someone’s reputation, but don’t use their identity to do so. At the time, I said I thought the Wisconsin Court of Appeals was right, but there’s been a development that is making me re-think that: the Wisconsin Supreme Court agreed to review the Court of Appeals’ decision. I got an email from someone asking me why I thought the Wisconsin Supreme Court has done this . . . since it seemed, at least at first glance, that the Court of Appeals’ decision was correct. That email made me think about the Court of Appeals’ decision again. That court said the charge against Baron was identity theft because while it encompasses causing harm to someone’s reputation, the fact you use someone else’s identity to do so differentiates it from defamation. Now I’m not sure if I agree with that.The reason you have a First Amendment defense to a charge of defaming a public official is because being the recipient of such criticism is part of their job. It’s also because such criticism is a valid, important part of our society; we need to be able to criticize what public officials do, if only to keep them honest. It doesn’t matter, as far as the applicability of the First Amendment defense is concerned, that Baron allegedly used his boss’ name when he sent the emails. The Supreme Court has held that the First Amendment right to free speech includes the right to speak anonymously (concealing your identity) and pseudonymously (using a different identity). This only makes sense, especially in the context of criticizing public officials; it can help reduce the possibility of retaliation by an unscrupulous public official. The problem I see here is that, assuming the facts alleged in the opinion (and set out in the earlier post) are correct, Baron didn’t use an alias to criticize his boss’ conduct in office. We’ll assume, for the sake of analysis, that his forwarding the emails in question constituted First Amendment-protected criticism of his boss. Even if that is true, it seems to me that what he allegedly did falls outside the scope of the First Amendment defense because he didn’t just exercise his right to pseudonymously criticize a public official; he did that, but to do so he used another person’s identity in a way he must have known would harm his reputation. Causing harm to someone’s reputation is defamation. Does incorporating a defamation offense into an identity theft offense statute transform it into identity theft (only)? I’m not sure. I checked the statute Baron is being prosecuted under. Until 2003, it was a regular identity theft statute; by that I mean it made it a crime to use someone else’s personal identifying information to fraudulently obtain money or goods or services of other things of value. Wisconsin Statutes section 943.201(2)(c). In 2003 the Wisconsin legislature passed an act that added the “harm the reputation” provision to the statute.That made me wonder why they did that. I couldn’t find any of what the law calls legislative history (reports of debates during the legislative process or setting out the reasons for adopting a particular bill), so I’m pretty much on my own here. The “harm the reputation” provision is, as far as I can tell, unique. I’m working on a law review article on another topic, and I spent the day reviewing identity theft statutes in the various states. I didn’t see any that have a provision like this; they all define identity theft (a) the way Wisconsin used to do (only) or (b) by making it a crime to use someone’s personal identifying information to commit a crime or (c) by combining (a) and (b). I didn’t see any that include what is really a defamation alternative.Now, a few states criminalize defamation, so if there are states with identity theft statutes that fall into the (b) or (c) categories, one could argue that the statutes at least implicitly encompass committing identity theft in order to commit the crime of defamation. I wasn’t working on that, so I didn’t check. Even if such statutes exist, I don’t think they resolve what we’re dealing with here for two reasons: One is that criminal defamation is almost never prosecuted; the other is that criminal defamation is almost always a misdemeanor. Neither of those is a legal, doctrinal reason for differentiating those statutes from what Wisconsin has done, but they at least, I think, support an argument that these hypothetical state statutes were not meant to encompass the use of identity theft to commit defamation. So we’re back to why Wisconsin does this . . . did this on purpose back in 2003. I wonder if this was, in fact, a way of penalizing defamation.In a law review article I published last year, I analyzed whether we should begin criminalizing defamation in order to address the expanded latitude the Internet gives us to use words and images to inflict emotional “harm” on each other. In writing it, I used news stories I found about two Wisconsin cases in which people used the Internet to defame others in particularly nasty ways. In both instances, the perpetrator pretended to be the victim in order to carry out the defamation. One of them pretended to be his former boss (bad to be a boss, it seems) and went onto a website for married women looking to have sex with other men. He posted an entry in her name, using her address, etc. . . . which apparently caused her a lot of embarrassment and a fair amount of fear (that the people who were responding to the ad might show up at her house).At the time, a Wisconsin prosecutor said something like “people are being hurt in new and different ways.” As I recall, either he or a legislator called for the criminalization of defamation. I checked the Wisconsin statutes and found that the state has a criminal defamation statute that makes it a crime to defame someone in their “business or occupation”. Wis. Stat. Ann. § 941.01. That’s not a general defamation statute; consequently, it couldn’t have been used to prosecute the two cases I used in that law review article.So, that leads me to wonder – and this is speculation, nothing more – if the “harm the reputation” alternative was added to the identity theft statute as a way of criminalizing more general defamation. In the Baron case, the Court of Appeals’ decision says he was also charged with criminal defamation, but the state voluntarily dismissed those charges, no doubt because of the First Amendment defense I outlined earlier. (It might also have been because the information in the emails he forwarded was true, and truth is a defense under the Wisconsin defamation statute.) The more I think about this case, the more I think that’s all he really did. I’m not sure. I’m certainly not an expert on Wisconsin law. But I wonder if the Wisconsin Supreme Court took the case because they, too, wonder if Baron is being prosecuted for nothing more than defamation while being denied the right to present a First Amendment defense. I guess we’ll find out, probably next year.