Showing posts with label 9th Circuit. Show all posts
Showing posts with label 9th Circuit. Show all posts

Thursday, April 10, 2014

Featured Article: The Internet and the Constitution: A Selective Retrospective

The Honorable M. Margaret McKeown of the United States Court of Appeals for the Ninth Circuit has a rather interesting article appearing in volume 9 of the Washington Journal of Law, Technology & Arts.

In her article, The Internet and the Constitution: A Selective Retrospective, Judge McKeown examines the complexities of the Internet and its associated innovations from a legal perspective, from the many jurisdictional and due process challenges, to the implications on the First Amendment and free speech. Judge McKeown's story of "institutional stability in the face of change," however, is one she believes has been lost in the all-to-common narrative: "the Internet is changing all the rules and the system can’t keep up."

I found the entire article fascinating, but for those looking for a cybercrime hook, the article's discussion on “The Fourth Amendment and Privacy,” beginning on page 161, may be of particular interest.

The abstract appears below
Over the last two decades, the Internet and its associated innovations have rapidly altered the way people around the world communicate, distribute and access information, and live their daily lives. Courts have grappled with the legal implications of these changes, often struggling with the contours and characterization of the technology as well as the application of constitutional provisions and principles. Judge M. Margaret McKeown of the United States Court of Appeals for the Ninth Circuit has had a close-up view of many of these Internet-era innovations and the ways the courts have addressed them. In this Article, adapted from her October 2013 Roger L. Shidler Lecture at the University of Washington School of Law, Judge McKeown offers her retrospective thoughts on the ways courts have handled constitutional issues in Internet cases. She also discusses some of the challenges currently facing courts and legislators alike as the U.S. legal system incorporates and accommodates Internet- based technologies and the societal, commercial, governmental, and relational changes they spawn.

Thursday, May 23, 2013

9th Circuit orders hard drive reformatting just in case hard drives contained encrypted files

The Ninth Circuit recently upheld an order allowing the government to reformat the hard drives on a computer before returning them because the drives might have contained encrypted files, and those encrypted files might have violated the defendant's supervised release. (United States v. Spink, No. 12-30068 (9th Cir. 2013)).

The defendant had been accused of violating the terms of his supervised release by use of his computer by possessing images of bestiality or zoophilia (he had previously owned at least 52 such websites). However, it appears as though the computers had either been erased, or the defendant had encrypted files on the computer. As no evidence was apparently found (from the little facts in the opinion), the computers had been ordered to be returned.

However, after the order, the government argued that they should be able to erase the hard drives in case there were files encrypted on the drive that would violate the defendant's release.
The government professed that it could not determine whether the computers' hard drives appeared to be blank because they had been erased or because they contained encrypted information that the government could not access.
The Ninth Circuit affirmed the decision to allow the hard drives to be erased, holding:
If the hard drives have been erased, there is no harm to Spink from the government wiping the hard drives again before it returns the computers. However, if there is encrypted data, Spink presumably has the ability to access those materials, and he has not offered to access the files in the presence of the Probation Office. Moreover, if the hard drives contain encrypted materials, those materials are likely to be the type of materials that Spink is prohibited from possessing under the conditions of his supervised release.
As I've argued many times before, I think the assumption that encryption is only used to do illegal or improper acts is erroneous and a very harmful idea for courts to consider. Does a locked door to your house imply that you are hiding illegal items in your home?

Friday, January 18, 2013

Breaking: In important Fourth Amendment case (Ahrndt), federal district judge GRANTS motion to suppress

We previously wrote about United States v. Ahrndt in a series of posts, after the 9th Circuit remanded the case for further consideration of the defendant's motion to suppress. Yesterday, a federal district court in Oregon granted Ahrndt's motion to suppress evidence (CP) from his iTunes library obtained by his neighbor (and later law enforcement) through an unsecured wireless network. This is a very important development, and we will get further into it in another series of posts.

Here is what we wrote, before:

Ninth Circuit remands case involving CP found on an unsecured wireless network - Jeffrey

Examination of the technology involved in Ahrndt - Jeffrey

Ahrndt considerations on remand and cordless ≠ WiFi - Justin

Arhndt's reference to Jones, and what Jones means in the context of wireless networks - Justin

Wednesday, October 10, 2012

Ninth Circuit holds that storing CP in shared folder is distribution, FBI must disclose EP2P software to defendants

In United States v. Budziak, No. 11-10223 (9th Cir. 2012), the Ninth Circuit held that storing child pornography in a shared folder for peer-to-peer networking without proof of distribution can, nonetheless, be considered distribution. The decision echoes that of three other circuits' opinions - United States v. Chiaradio, 684 F.3d 265, 281-82 (1st Cir. 2012); United States v. Shaffer, 472 F.3d 1219, 1223 (10th Cir. 2007); and United States v. Collins, 642 F.3d 654, 656-57 (8th Cir. 2011).

The Ninth held "that the evidence is sufficient to support a conviction for distribution under 18 U.S.C. § 2252(a)(2) when it shows that the defendant maintained child pornography in a shared folder, knew that doing so would allow others to download it, and another person actually downloaded it."

On appeal, the defendant argued that he had disabled sharing in the software, but he had presented no such evidence at trial. The government, however, had presented evidence to the contrary.

Budziak did sufficiently argue that the trial court improperly denied him access to the FBI's EP2P software used to find child pornographer sharers on the Limewire network. As a result, the case was remanded for the district court to determine if discovery could have affected the outcome.

Tuesday, August 14, 2012

Ninth Circuit takes second look at Pineda-Moreno, denies suppression of evidence

The Ninth Circuit has revisited United States v. Pineda-Moreno, No. 08-30385 (9th Cir., Aug. 6, 2012) after remand from the Supreme Court and has upheld the use of GPS evidence in the case due to the Davis good faith rule.

Pineda-Moreno was one of the three leading circuit cases prior to Jones to hold that a GPS device could be used by law enforcement without a search warrant - the Ninth's reasoning was that the installation and use was not a search. After the Supreme Court held the use to be a search in Jones, Pineda-Moreno appealed to the Supreme Court where the conviction was vacated and remanded.

Following the general pattern of such cases, the exclusionary rule does not apply because law enforcement acted on then-binding circuit precedent. The Ninth Circuit had held prior to Pineda-Moreno that "placing an electronic tracking device on the undercarriage of a car was neither a search nor a seizure under the Fourth Amendment." United States v. McIver, 186 F.3d 1119, 1126-27 (9th Cir. 1999).

Tuesday, July 31, 2012

Fourth Circuit adopts narrow reading of the CFAA

We have discussed previously the tension between a wide and narrow reading of the CFAA - see Jeffrey's original take on Nosal Ninth Circuit en banc adopts narrow reading of CFAA, and my analysis of the dissent - Why Nosal’s dissent is surprisingly persuasive.

Well, the Fourth Circuit has sided with the "narrow" camp, in WEC Carolina Energy Solutions v. Miller. Not surprisingly, it is another case of employee disloyalty that has been dressed up to be a federal hacking violation.  Essentially, Miller (or his assistant) downloaded documents while he was still employed and was authorized to access such information and then twenty days after his resignation used allegedly proprietary information (from the downloaded documents) in a presentation to customers for his new employer (a competitor of WEC). WEC eventually lost the contract and sued under the CFAA, alleging that the downloading of the documents was a violation of the CFAA because "'[u]nder WEC's policies they were not permitted to download confidential and proprietary information to a personal computer.' Thus, by doing so, they 'breache[d] their fiduciary duties to WEC' and via that breach, they either (1) lost all authorization to access the confidential information or (2) exceeded their authorization."

The court reviewed the panel decision in Nosal (which was later overturned en banc), and candidly called its interpretation of the CFAA a "non sequitur." Recall that a reading of the CFAA under the Nosal panel's interpretation would essentially criminalize employee violations of acceptable use policies. And lets not forget what the fight is really over - it is the plain text of the CFAA, which defines in pertinent part "exceeds authorized access" as:

to access a computer with authorization and to use such access to obtain or alter information in the computer that the accesser is not entitled so to obtain or alter.

The key word, as I have highlighted, is "so." Nosal defined so as "in that matter." The Fourth Circuit's responded:

To us, defining "so" as "in that manner" only elucidates our earlier conclusion that "exceeds authorized access" refers to obtaining or altering information beyond the limits of the employee's authorized access. It does not address the use of information after access. Indeed, the Ninth Circuit indicated as much in its en banc reversal, when it declined to hold that the interpretation of "so" as "in that manner" necessarily means employees can be liable for use-policy violations.  
The Fourth Circuit thus rejected the wide interpretation of "so," and applying the rule of lenity, held that "Congress has not clearly criminalized obtaining or altering information 'in a manner' that is not authorized. Rather, it has simply criminalized obtaining or altering information that an individual lacked authorization to obtain or alter."

The court went on to clearly reject the Seventh Circuit's interpretation of the CFAA as a "cessation-of-agency theory," in Citrin.  Namely, that the Seventh Circuit's interpretation is deficient because:

Such a rule would mean that any employee who checked the latest Facebook posting or sporting event scores in contravention of his employer's use policy would be subject to the instantaneous cessation of his agency and, as a result, would be left without any authorization to access his employer's computer systems.
The Fourth Circuit stated that in drafting the CFAA, Congress did not intend to legislate on the agency relationship and did not intend "the imposition of criminal penalties for such a frolic."

As Orin Kerr reported on the Volokh Conspiracy, subsequent to this decision the DOJ asked for an extension of time to file the petition for certiorari for the Nosal decision. That seems like a no-brainer to me. The government will need to craft an argument to sidestep this landmine, and I'm not sure they'll be able to do it.

I am highly persuaded by Judge Floyd's reasoning, and I absolutely agree that Congress never intended any interaction between agency theory and the CFAA. I agree because any other interpretation is illogical.  Congress was legislating computer intrusions (a.k.a. hacking) in 1986 (26 years ago) -and its intent in legislating the act is borne out by the record; it is further clarified when one considers documents such as the Hacker Manifesto (published Jan. 1986) which was all about breaking into systems, not use violations. Recall 1986 technology:



1986 wasn't the land of the "internets," the Googlemaker, or the MyFaceTube - it was a completely different technological standpoint. Which just reinforces a point I keep making - that the CFAA is anachronistic and should be revised; however, until it is, it should not be used as the sword of enforcement for violations of every and any use policy an entity can dream up.  Such an interpretation is not borne out by the text, the history, the intent, nor does it comport with the real function that the law was enacted to serve.

Wednesday, April 11, 2012

Ninth Circuit en banc adopts narrow reading of CFAA

In United States v. Nosal, 676 F.3d 854 (9th Cir. 2012), the Ninth Circuit adopted a narrow reading of the Computer Fraud and Abuse Act, finding that violating an employer computer policy or a website's terms of service is not a violation of federal law.

Nosal quit his job and soon thereafter encouraged his former coworkers to send him confidential information from the company. The employees had access to the database but were not allowed to disclose the information. Nosal was charged under the CFAA "for aiding and abetting the ... employees in 'exceed[ing their] authorized access' with intent to defraud," and he filed a motion to dismiss, arguing that the statute doesn't cover this type of act. The district court agreed and dismissed most of the charges (United States v. Nosal, 2010 WL 934257 (N.D. Cal. 2010)). A Ninth Circuit panel reversed, finding that an employee does violate the CFAA by violating an employer's restrictions (Nosal, 642 F.3d 781 (2011)). The Ninth Circuit reviewed the decision en banc.

In Judge Kozinski's opinion, he acknowledged that the CFAA was written "to address the growing problem of computer hacking" and found that an argument that "exceeds authorized access" applied to hacking as well is "perfectly plausible." The court emphasized that to interpret the statute as encompassing policy violations would  mean that "millions of unsuspecting individuals would find that they are engaging in criminal conduct." Further, "minds have wandered since the beginning of time and the computer gives employees new ways to procrastinate." The result being that a prohibition of Facebook use at work could land someone in prison for breaking the rule if the broad interpretation were adopted. "[S]udoku enthusiasts should stick to the printed puzzles, because visiting www.dailysudoku.com from their work computers might give them more than enough time to hone their sudoku skills behind bars."

Likewise, a broad reading would also criminalize letting a friend check your e-mail or providing inaccurate or misleading information on a dating website as those acts likely violate the service's terms. "[D]escribing yourself as “tall, dark and handsome,” when you’re actually short and homely, will earn you a handsome orange jumpsuit."

The Ninth Circuit's decision is contrary to decisions of other circuits - United States v. Rodriguez, 628 F.3d 1258 (11th Cir. 2010);  United States v.  John, 597 F.3d 263 (5th Cir. 2010); Int’l Airport Ctrs., LLC v. Citrin, 440 F.3d 418 (7th Cir. 2006). The Ninth wrote that "[t]hese courts looked only at the culpable behavior of the defendants before them, and failed to consider the effect on millions of ordinary citizens. We therefore respectfully decline to follow our sister circuits and urge them to reconsider instead."

Monday, April 9, 2012

Ninth Circuit remands case involving CP found on an unsecured wireless network

This is the first of a four-part series from Cybercrime Review on the Ninth Circuit's Ahrndt decision and the important legal issues concerning wireless networks.

In United States v. Ahrndt, 2012 U.S. App. LEXIS 6976 (9th Cir. 2012), the Ninth Circuit reversed and remanded the denial of Ahrndt's motion to suppress evidence obtained from his unsecured wireless network. The court found the record was missing important facts necessary to reach the conclusion that Ahrndt had no reasonable expectation of privacy in files shared on his wireless network. The court identified several questions that should be addressed on remand.

Ahrndt's neighbor's computer allegedly connected to his unsecured wireless network without her permission. She then opened iTunes and saw that someone on the network was sharing media files - some of which appeared to be child pornography. She contacted law enforcement, and they asked her to show them the images (she had not opened them in her private search but did so at the officer's request). A search warrant was then obtained for police to access the network so as to ascertain the IP address. They were then able to track the account to Ahrndt, and a second warrant was obtained to search his home. At trial, Ahrndt argued for suppression of all evidence, suggesting the initial viewing violated the Fourth Amendment, and evidence found later was fruit of the poisonous tree.

The issue, as determined by the trial court, was "whether the Fourth Amendment provides a reasonable, subjective expectation of privacy in the contents of a shared iTunes library on a personal computer connected to an unsecured home wireless network." United States v. Ahrndt, 2010 U.S. Dist. LEXIS 7821 (D. Or. 2010).

Ahrndt "argued that a wireless network should be given no less protection than a hardwired network under the Fourth Amendment," but the court found that "different communications hardware and technologies carry different reasonable expectations of privacy. As an example, the Eighth Circuit has held that wireless phones are distinct from wired phones in terms of privacy. The court then found that wireless phones and wireless networks should be treated equally because "they transmit data over radio waves." The judge concluded:
As a result of the ease and frequency with which people use others' wireless networks, I conclude that society recognizes a lower expectation of privacy in information broadcast via an unsecured wireless network router than in information transmitted through a hardwired network or password-protected network. Society's recognition of a lower expectation of privacy in unsecured wireless networks, however, does not alone eliminate defendant's right to privacy under the Fourth Amendment. In order to hold that defendant had no right to privacy, it is also necessary to find that society would not recognize as reasonable an expectation of privacy in the contents of a shared iTunes library available for streaming on an unsecured wireless network.
The court then found that no reasonable expectation of privacy existed in the shared iTunes files. The government argued that the sharing was similar to peer-to-peer file sharing, but Ahrndt said it was akin to "having a conversation behind a closed, but unlocked door." The trial court disagreed, finding that
[w]hen a person shares files on LimeWire, it is like leaving one's documents in a box marked "free" on a busy city street. When a person shares files on iTunes over an unsecured wireless network, it is like leaving one's documents in a box marked "take a look" at the end of a cul-de-sac. I conclude that iTunes' lesser reach and limit on file distribution does not render it unlike LimeWire in terms of its user's reasonable expectation of privacy.
An argument that the iTunes files were protected under the ECPA was also struck down "because the wireless network and iTunes software were configured so that the general public could access them."

Finally, Ahrndt had no subjective expectation of privacy because he should have been aware that his wireless network was unsecured and his iTunes files were shared. He worked for Hewlett-Packard, had "an intermediate level of computer knowledge," and should have known how to protect his network or turn off iTunes sharing.

The questions identified by the Ninth Circuit to be answered on remand are:
• As a technical matter, is sharing files over a wireless network accurately characterized as a "broadcast" of the contents of those files, such that JH's computer simply intercepted Ahrndt's images outside Ahrndt's home? Or, alternatively, did the act of connecting to Ahrndt's network, accessing his library and opening the image involve sending wireless signals into Ahrndt's home to communicate with his router and computer? 
• Did Ahrndt intentionally enable sharing of his files over his wireless network? If not, did he know or should he have known that others could access his files by connecting to his wireless network? 
• Was the image in "Dad's LimeWire Tunes" library that JH and McCullough opened accessible over the Internet by Limewire users at the time JH and McCullough accessed the files, or at any time prior? 
Please visit Cybercrime Review for more coverage of the Ahrndt decision in the coming days as we discuss the legal arguments, the technological issues, and other peculiarities with this decision.

Sunday, January 1, 2012

Ninth Circuit finds standing to challenge government's alleged communications dragnet

In a lawsuit alleging "widespread warrantless eavesdropping" in violation of the Foreign Intelligence Surveillance Act, the Electronic Communications Privacy Act, and the Stored Communications Act, the Ninth Circuit has reversed and remanded the lower court dismissal on standing grounds. Jewel v. NSA, 673 F.3d 902 (2011).

The suit, backed by the Electronic Frontier Foundation, alleged "that the government[] operated a "dragnet collection" of communications records by 'continuously soliciting and obtaining the disclosure of all information in AT&T's major databases.'" The district court dismissed the compliant, finding that Jewel's complaint failed by not "specifically linking any of the plaintiffs to the alleged surveillance activities."

Of course, the issue is whether Jewel could demonstrate a "sufficiently concrete and specific injury" in order to have standing. The court found that the complaint "described in detail the ... equipment used ... at the particular AT&T facility" and that she "alleged with particularity that her communications were part of the dragnet."

RELATED CASE: The Ninth Circuit also decided, in a separate opinion, that § 802 of the Foreign Intelligence Surveillance Act, which immunizes telecommunications companies from cooperating with the government's investigations, is constitutional. In re NSA Telcoms. Records Litig., 2011 U.S. App. LEXIS 25949 (2011).

Wednesday, November 9, 2011

Warrant in CP case may have violated Fourth Amendment

Imagine this set of facts: Law enforcement receives a tip of a website containing child pornography. Yahoo e-mail account qek9pj8z9ec@yahoo.com is the suspect, and the IP address used to create the account is provided. Detectives connect the account with Nicole Chism living in Washington (but the account registration says she lives in Chile). Her credit card was used to pay for hosting of the website. The IP addresses used to create and access the account were tracked to two other people - both living in Washington, but hundreds of miles from Chism's home. Based on this information, detectives believed they had probable cause to believe Nicole's husband committed the crime.

Nicole's husband, Todd, was arrested, and his home and office were searched for child pornography. He was never charged with a crime and subsequently argued that his Fourth Amendment rights were violated. As you might imagine, the Chisms' credit card had been stolen. No evidence connected Todd to the images except for the hosting payment. The affidavit also alleged that the credit card was used to purchase images of child pornography, but no evidence existed for that claim. Further, it never mentioned the other IP addresses, connected Todd to Nicole's credit card, or mentioned that the account was registered to Nicole in Chile.

As a result, the Ninth Circuit reversed the district court's grant of summary judgment, finding that a substantial showing of the officers' reckless or intentional disregard for the trust existed, their false statements and omissions were material, and the officers are not entitled to qualified immunity upon remand. The case is Chism v. Washington, 661 F.3d 380 (9th Cir. 2011).

Friday, October 28, 2011

Verb tense distinctions in exploitation statute

In a recent Ninth Circuit case, United States v. Williams, 659 F.3d 1223 (2011) a defendant made a rather pointless, yet clever, argument. Williams was seeking to show that an individual must personally produce child pornography in order to be convicted of advertising for distribution.

Under the federal sexual exploitation of children statute, 18 U.S.C.A. § 2251, "[a]ny person who ... knowingly makes, prints, or publishes ... any notice or advertisement seeking or offering (A) to receive, exchange, buy [etc.] ... any visual depiction, if the production ... involves the use of a minor engaging in sexually explicit conduct ... shall be punished.... § 2251(d)(1).

Williams's argument was on the verb tense. Since the statute uses the word "involves" rather than "involved", Congress intended for the statute to require the defendant to have actually produced it, rather than to have received it and redistribute the images. Of course, the court produced sufficient explanation for striking down such an argument, but it was clever.

Tuesday, October 4, 2011

SCA's protections apply to foreign citizens

Just a quick rule: According to a recent ruling by the Ninth Circuit, the SCA's application to "all persons ... means any person, including foreign citizens." A party was trying to obtain Hotmail e-mails from an Australian citizen, but Microsoft objected, arguing that the SCA prevents it. (Suzlon Energy Ltd. v. Microsoft Corp., 2011 U.S. App. LEXIS 20018 (9th Cir. 2011)).