Showing posts with label spyware. Show all posts
Showing posts with label spyware. Show all posts

Tuesday, April 30, 2013

Jury: School principal Weindl not guilty of CP charges; case arose after FBI agent left spyware on son's school laptop

From the Saipan Tribune (2/13/13): Weindl found not guilty:
A federal jury yesterday found former Whispering Palms School principal Thomas Weindl not guilty of charges of accessing child pornography websites using a Public School System-issued laptop.
For those unfamiliar with the case, here is my description from a previous post:
In United States v. Weindl, __ F.Supp __ (D. N.M.I. Nov. 20, 2012), a Northern Mariana Islands federal district court denied suppression of evidence obtained when spyware installed on school-owned laptop (assigned to an FBI agent's son and later used by the principal) sent child pornography (CP) reports (alerts) to the FBI agent - evidence that led to charges against the school principal (two counts of receiving CP and two counts of possession of CP). There are three relevant issues in the case: (1) whether the act of "accidental" failure to remove the spyware resulted in an "inadvertent search" or an intentional one, (2) whether the FBI agent was acting under the color of law when he opened and later investigated the reports he received from the spyware, and (3) whether Weindl had standing to assert a reasonable expectation of privacy in the spyware reports. 
I had a chance to speak via email with Weindl's attorney, David Banes, last night; Banes indicated that he believed the turning point in the case was the testimony of his computer expert. He also mentioned that "we were able to show that the alleged porn sites constantly changed content" making it hard for the prosecution to prove that what Weindl allegedly browsed and viewed (at time A) was the same content when the page was accessed (assumedly by prosecutors) to serve as a basis for the charges (and evidence at the trial) (at time B). Finally, Banes noted that the defense was able to put on convincing evidence that eBlaster reports are not designed to be used as forensic evidence.

My previous posts on the case can be found below:

11/28/2012 - Principal caught with CP when FBI agent returns son's school laptop with spyware still on it; court denies suppression

12/3/2012 - Weindl - FBI agent spyware v. principal attracts attention and misinformation

12/5/2012 - Weindl (FBI agent's spyware vs. principal) - Why the court got it wrong

Jeffrey's differing take can be found here:

12/7/2012 - Weindl: Why the court got it right, and the FBI agent/father shouldn't be viewed as a government agent

Kashmir Hill at Forbes also wrote it up, here:

11/30/12 - An FBI Dad's Misadventures With Spyware Exposed School Principal's Child Porn Searches

Wednesday, December 5, 2012

Weindl (FBI agent's spyware vs. principal) - Why the court got it wrong

In this second post, I will explain my reasons for believing the court's reasoning in Weindl was flawed. The Weindl case, as a quick recap, involved a principal (Weindl) who was caught with child pornography after using a laptop assigned to the son of an FBI agent (Auther); the laptop was returned by Auther with spyware on it. For my original write-up of the facts of the case, see: Principal caught with CP when FBI agent returns son's school laptop with spyware still on it; court denies suppression. I also wrote a quick follow-up post about the coverage and misinformation regarding the case after I wrote about it. That can be found here: Weindl - FBI agent spyware v. principal attracts attention and misinformation.

First, let me address the "smell test." It seems extremely odd that when Auther took the computer to the FBI and asked "fellow agents for advice on how to wipe it clean" they "tried to remove all the files but were unsuccessful." Two things: (1) the FBI investigates a significant number of "cyber" cases using forensics techniques to recover deleted files and search through hard drives, uncover steganography, and analyze complex network traffic. Yet, they can't wipe a hard drive - something that a simple Google search will tell you how to do? Also, (2) Auther paid for and installed the spyware, knew the "hot-keys" to access the information it collected, and set it up to email him reports. Yet, once again, he could not uninstall that program, the most cognizable change he made to a machine he did not own?

In addition, he took it to a computer store to wipe all of the files, with a service order showing "reimage" and "clean out files" as the work to be done. I accept that a local service may not have been aware of the spyware to look for it in the first place, but reimage means just that, start all over again.  And, more interestingly, Auther did not even mention that he installed spyware on the computer to the computer shop. Wouldn't that program be the first thing you would mention when cleaning up a computer?

Also, the court seemed to be quite deferential to Auther when it accepted the argument that he was more concerned about leaving than investigating the principal. Perhaps that is true, but is it not equally likely that he suspected the principal of questionable activities and, before leaving, wanted to confirm his suspicions? After all, the FBI agent did say that he was aware of the Sandusky case and that what happened at Penn State motivated some of his later actions. That coupled with the two-time failure to remove the spyware smells funny.

But lets assume that all of the facts are true - just as the court did. I find it questionable that the court omitted any discussion regarding the license agreement of eBlaster, which requires you to agree to "use [eBlaster] only on a computer you own," an agreement Auther clearly violated when he installed it on a school-loaned laptop. The court also breezes over the likelihood that Auther violated policies of the school or the PSS laptop loaner program. I point this out because Auther is permitted to walk all over policies and procedures carte blanche, but Weindl's use of the laptop in likely violation of the rules of the loaner program was sufficient to wipe out his expectation of privacy completely. More on that later.

I think one of the most glaring errors of the court is the reasoning that opening the first four emails was not a search and instead was inadvertent conduct not under the color of law.  First, the court found that the search was only the activity of the spyware program collecting the data, and did not include the person on the other end viewing that information. I am not convinced you can draw such a black and white line. The Fourth Amendment (and by proxy the protection of privacy) has been held to protect against the intrusion of the process of a search as well as the discovery of the information it provides. If the latter were not an aim, the Fourth Amendment would never have been extended outside of property notions, as it was in Katz.

Thus, Auther's decision to open an email with a subject line that clearly indicated the email regarded information collected after he had returned the PC should have been held a search. Moreover, knowledge that the email could not regard his own or his son's activity does not make opening the email inadvertent. The definition of inadvertent is: "not focusing the mind on a matter : inattentive." The case indeed indicated that Auther recognized that the emails were providing information they should not have been because he believed the program had been removed and the computer was no longer in his possession. An example is illustrative: If I move into a new house on Royal Avenue on Tuesday, and on Friday I get a package addressed to "our lifelong neighbors on Royal Avenue," opening that package would not be inadvertent. I clearly know that I do not constitute the "neighbor" the package was intended for, since I moved in three days prior. Auther's opening of the email is no different. The subject line contained prima facie evidence that it was not intended for him and arose from improper means. Thus, the only reason he could have to open it would be to pry.

I am willing to concede, however, that one might reasonably argue that opening the first email would be inadvertent. Maybe he wasn't paying attention to the subject line. But, after reading the first, he should have known something was awry. To open the other three emails, after reading the first, would indicate one very important thing: that he was now acting as an officer of the law because of the information the email contained (evidence of someone accessing child pornography). To go back to my example, if I opened the first package without paying particular attention to the address line that said "to our lifelong neighbors on Royal Avenue," it may be reasonable to say I was just careless (or it was inadvertent). However, if inside that box are pictures of a family that I don't know, then when three more packages arrive addressed the same way and similar in appearance, a reasonable person would not open them. They would instead return them to whomever delivered them. Or, in Auther's case, contact the principal or the PSS program and indicate that the spyware he installed without authorization from either the school program or the software author was in fact still installed and had generated an email to him. An interesting question raised by the case is: if the spyware email hadn't contained evidence of CP access, would he have called the school to raise the flag on the spyware? One would think so.

The last significant problem with the case is the court's decision to deny standing to Weindl on the reasonable expectation of privacy issue. The court stated:
Sometimes, people delude themselves into thinking that they have a right to things that don't belong to them. . . . No evidence indicates that Weindl had a right to use, or himself had permission to use, a PSS laptop, even for school-related activities. Auther turned his son's laptop in to Weindl in Weindl's capacity as an agent for the school, not for Weindl's personal use.
Even if Weindl had a subjective (albeit unrealistic) expectation of privacy in the PSS laptop, it was not an expectation that society is prepared to endorse. An expectation of privacy does not become objectively reasonable just because a person hides someone else's property away in his office desk and does not let anyone else use it. A person cannot have a reasonable expectation of privacy in a computer he stole or obtained by fraud. 
The court justifies the last paragraph on two reasonable expectation of privacy cases: one involving a stolen computer (Wong), and one involving a computer obtained by fraud (Caymen). The court then states that "Weindl's case is similar to Wong and Caymen. Weindl misappropriated school property for his own personal use. Whatever expectation of privacy he developed in the contents of the laptop's hard drive and the keystrokes of Internet searches is not a legitimate one that society is prepared to accept. . . . The laptop was not assigned to Weindl and was not his office computer." I find the comparison to Wong and Caymen to be ill-advised. In both cases, the individual had either been convicted, or charged with obtaining the device by illegal means. Weindl did nothing of the sort, here. Additionally, in Caymen, where the defendant obtained the laptop by fraud, the court based its holding on cases from sister circuits regarding stolen cars. There is a theme here: stolen. Weindl did not steal, nor obtain anything by fraud. While he may not have had permission, he certainly was not doing anything illegal.

The Caymen court pointed out that a person who has stolen something lacks the property interests an owner has (the bundle of sticks) that define property ownership. Can the same be said for the laptop, here? Arguably, no. Weindl was permitted to have constructive possession of the laptop - something a thief would never have. Also, if the laptop had been stolen from the FBI agent's son and then recovered, it would likely have been returned to the principal (or someone under his authority). Granted, he lacked other property rights like the right to sell, but to analogize the computer to stolen property is off target.

Lastly, I believe the court was correct, technically, about the application of the Federal Wiretap Act: namely, that suppression is only for wire and aural communications in criminal cases. However, I find it fantastical to argue that placing spyware on an individual's computer isn't wiretapping. That the court had to cite to a 1978 case in support of this part of the holding is a clear illustration of the lack of coverage in this area. I hope that these facts present an opportunity for the 9th Circuit to directly address the issue and clarify that a "wire" communication should include such conduct. (Although maybe it is a legislative task, since to include what could be characterized as "electronic communications" within "wire communications" would arguably construe the civil portion of the law addressing "electronic communications" superfluous, something courts are reticent to do).

I am excited to see how the 9th Circuit handles this case. The facts of Weindl illustrate, as many other technologically centered cases do, the "play in the joints" of the law. And, with respect to the Wiretap Act, reflects the anachronistic nature of some federal statutes as applied to emerging technologies.

Monday, December 3, 2012

Weindl - FBI agent spyware v. principal attracts attention and misinformation

Since I wrote about United States v. Weindl on November 28th, Principal caught with CP when FBI agent returns son's school laptop with spyware still on it; court denies suppression, the story was picked up by Kashmir Hill at Forbes (by way of Eric Goldman), An FBI Dad's Misadventures With Spyware Exposed School Principal's Child Porn Searches, and from there spread like wildfire to various other sites.

Today, Robert X. Cringely, on his Infoworld blog "Notes from the field" highlighted the story as well - School for scandal: FBI spyware nabs pervy principal. In the story, he states:
When spooks spy on their kids -- and happen to ensnare adults doing things they shouldn't -- isn't that illegal spying? I asked cyber lawyer Jonathan Ezor, Director of the Touro Law Center Institute for Business, Law and Technology in Islip, New York. 
Though Ezor cautioned that he is not a criminal attorney, he says Auther's discovery of Weindl's dark deeds probably falls under the "in plain sight" exception for evidence. If you open the door for the cops and they see a big pile of cocaine sitting on your coffee table, they have every right to break down the door, then seize you and the drugs, no warrant required. 
The more important issue, says Ezor, was what the feds told Weindl when they sat down with him in his office and whether they read him his rights. That might have a greater bearing on whether his Fourth Amendment rights were violated. 
On the other hand, Justin P. Webb of the CyberCrime Review blog says the court was wrong across the board (though he's saving his reasons why for a future blog post).
Two things:

(1) With all due respect to Jonathan Ezor, he clearly did not read the case. As I stated in my write-up, the court expressly dismissed the plain view exception to the warrant requirement. You cannot argue for plain view when you are somewhere you weren't authorized to be. Further, and as the case states specifically, Weindl was not read his rights" when [the the two FBI agents] sat down with him in his office." Most importantly: the significant implications of the case, which Weindl's attorney assured me will reach the the 9th Circuit, do not revolve around the interrogation, but the search.

(2) Cringely is correct to note that I believe the Weindl opinion was wrong across the board. While my post on that issue is not up yet, it will be within 48 hours.



Wednesday, November 28, 2012

Principal caught with CP when FBI agent returns son's school laptop with spyware still on it; court denies suppression

This case will be discussed in two posts.

In United States v. Weindl, __ F.Supp __ (D. N.M.I. Nov. 20, 2012), a Northern Mariana Islands federal district court denied suppression of evidence obtained when spyware installed on school-owned laptop (assigned to an FBI agent's son and later used by the principal) sent child pornography (CP) reports (alerts) to the FBI agent - evidence that led to charges against the school principal (two counts of receiving CP and two counts of possession of CP). There are three relevant issues in the case: (1) whether the act of "accidental" failure to remove the spyware resulted in an "inadvertent search" or an intentional one, (2) whether the FBI agent was acting under the color of law when he opened and later investigated the reports he received from the spyware, and (3) whether Weindl had standing to assert a reasonable expectation of privacy in the spyware reports.

I believe this case was wrongly decided on the all three issues. I contacted David Banes, the lawyer for Weindl, and he (not surprisingly) agrees as well. He indicated that his client "fully intend[s]" to appeal this denial of suppression after the case goes to trial (it does not look like the judge will allow a conditional plea).

In this first post, I will give a summary of the case. In the second post, I will argue why the court erred in its holding.

Summary 

The defendant Thomas Weindl ("Weindl") was a school principal at Whispering Palms public school in Saipan, Mariana Islands. The FBI agent whose actions gave rise to this case is Joseph Auther ("Auther"). Auther's eldest son was enrolled at Whispering Palms, and was assigned a laptop during his time there. Auther kept an eye on his son's use of the laptop by purchasing and installing eBlaster on the laptop (without his son's knowledge). eBlaster sent email reports directly to Auther, with keystrokes, internet sites visited, and a plethora of other information. The report in Auther's inbox "would give the subject as 'Report,' followed by the date and time span of covered activity."

Auther was reassigned to a different FBI office in April 2012 and as part of the moving process, returned the laptop to the school, and more specifically, handed it over to Weindl. Auther did not tell Weindl about eBlaster, apparently assuming that it had been removed, but had told Weindl (prior to turning it in) that he would wipe the machine. Auther did in fact attempt to wipe the machine, but failed. The court describes Auther's actions as follows:
The first step Auther took to service the laptop was to bring it into the FBI office and ask fellow agents for advice on how to wipe it clean. They tried to remove all the files but were unsuccessful. Next, . . . Auther asked a local computer store to repair a scratched screen and wipe off all the files on the laptop's hard drive. The store's service order (Ex. 1) lists the work to be done as "Reimage" and the work performed as "Clean out files." Auther did not tell the technician about eBlaster, but he expected that the cleaning would eliminate the program. 
As stated previously, eBlaster was not, in fact, removed. After handing the laptop over, Auther did not receive any emails from eBlaster for over six days. On the seventh day, Auther received four emails from eBlaster indicating someone was using the laptop to access child pornography. The emails had subject lines, as described above, that clearly indicated that they were regarding activity that occurred after Auther turned in the laptop. Auther viewed all four emails, nonetheless. Auther hypothesized that the activity could be from a virus, another student using the laptop, or Weindl himself. He thought of Weindl because the pornography searched for was of young asian children with older adults and Weindl had recently married a Korean woman and now had an 11-year-old stepdaughter.

At this point, Auther did not report the results of the reports to authorities, but instead called Weindl under false pretenses, acting as if he would like to purchase the laptop. Weindl indicated that he had given it back to the school laptop agency (PSS), and that Auther wouldn't be able to buy it. Auther did not indicate that he had received CP reports, or that eBlaster was apparently still on the computer. Auther's reasoning was:
. . .that he did not want to raise concerns in Weindl's mind about who was using the computer or about a possible investigation involving Whispering Palms teachers and students. . . . [H]e was concerned that the Internet activity might mean that a child molester was operating at Whispering Palms. He was aware that a former coach at Pennsylvania State University had just been convicted on child molestation charges, and he was determined not to allow similar conduct to go undetected at Whispering Palms. (emphasis added)
Three days later, instead of handing the case over to the authorities, Auther then proceeded to start an investigation into what was going on with the laptop. Flashing his FBI badge at the offices of the the laptop program agency (PSS), he inquired if the laptop had actually been returned, and found that it hadn't. Auther then inquired with his ISP about the IP address noted in the reports, attempting to find out where the computer was being used. Auther indicated to the court that he may have shown his FBI badge to the ISP. The ISP refused to tell him anything, but he was able to decipher that the computer usage was not from an IP at his house.

On the same day as the trip to PSS and the ISP, Auther received two more emails indicating that the computer was being used to access CP. He decided to drive by the school on his way to report everything to the FBI. He noticed Weindl's car in the parking lot and called Weindl on his cellphone. Auther asked about the laptop and Weindl said he was investigating some "hanky panky" going on at PSS. Auther knew he was lying since PSS did not have the laptop, and grew much more suspicious. He reported what was going on and his suspicion about Weindl to a special agent with the FBI (Ewing). He also asked that child protective services be sent to Weindl's house to check on his 11-year-old stepdaughter.

Over a week later, Ewing and Auther went to Weindl's office to speak with him. During the conversation, Weindl admitted he lied about returning the laptop to PSS and admitted to viewing child pornography. He also confessed that he had taken the laptop out into the jungle and smashed it. He was arrested outside the school a short time later. Prior to trial, Weindl filed a motion to suppress the eBlaster evidence arguing that it was obtained in violation of his Fourth Amendment rights.

The court, in denying suppression of the eBlaster evidence, began by declaring that to have a Fourth Amendment violation, there needed to be state action and standing (a reasonable expectation of privacy). Addressing the state action portion, the court laid out the standard relating to an off-duty officer - whether Auther was acting under color of state law, where his actions "in some way related 'to the performance of his official duties'" or "pursuant to [a] government or police goal." The court held that when Auther installed eBlaster he was acting as a private citizen, and not as an FBI agent. Despite the circumstances changing when Auther returned the laptop (that Auther wasn't acting as a concerned parent anymore), the court held that it was an inadvertent search not under color of state law because Auther did not intentionally leave eBlaster on the computer.

In reaching that result, the court was not persuaded by Weindl's argument that even if the presence of eBlaster was inadvertent, Auther opening and reading the eBlaster reports turned something inadvertent into intentional. The court reasoned that "[t]he search was the gathering of information by eBlaster, not the viewing of the contents." The court also dismissed the argument that "the initial eBlaster reports come under the Fourth Amendment via the two-part test for private-party searches."

So, to clarifiy, the original four emails from eBlaster sent to Auther, and him viewing them, were not the "product of a search conducted under color of state law."

The court did find a search, however, relating to the two eBlaster reports Auther received after he called Weindl to inquire about the laptop. The court stated:
By that time, Auther knew that someone may have been viewing illicit material on the laptop. He suspected Weindl even before he called him. When he did call, he hid his real concern about the laptop's usage behind a pretense that he was interested in purchasing the computer. After the call, he did not uninstall or disable eBlaster, even though as a private citizen he was under no obligation to continue monitoring an unknown person's offensive Internet activities. He did not immediately call his colleagues at the FBI and hand the investigation over to them — conduct that might have indicated Auther wanted to maintain a separation between his private self and his public persona as a law enforcement officer. . . . [instead] Auther continued his investigation into the child pornography website searches. . . . At the PSS offices, he showed his FBI badge. At the Internet service provider, he relied on the fact that he was known to be an FBI agent to seek information about IP addresses. The totality of the circumstances shows that at this point, Auther's actions were related to his official duties and in pursuit of a police goal. Although a formal FBI investigation had not been opened yet, Auther was now acting under color of law.
The court dismissed the government's argument to the contrary, that "even if Auther's conduct constituted state action, his discovery of the illicit Internet activity through eBlaster e-mails was accidental and therefore does not come under the Fourth Amendment." The court stated that precedent was clear that to have inadvertent discovery through plain-view doctrine, the police had to be somewhere they were justified to be. However, here, "Auther, . . . had no legitimate justification to intrude on anyone's conduct on the school laptop once it was no longer on loan to his son. Moreover, the incriminating evidence did not drop out while he was straightening the icons on the computer's desktop but came into view because of intentional spying on the keyboard and hard drive."

Addressing the argument that a violation of the federal Wiretap Act occurred, the court noted that under the criminal portion of the Act, "suppression motions are authorized only with respect to the contents of wire and oral — not electronic — communications."  The court laid out that the definition of "[a] wire communication is 'any aural transfer' involving wire or like connections between the point of origin and point of reception." 18 U.S.C. § 2510(1). And that, "an 'aural transfer' is 'a transfer containing the human voice' at some point in transmission of the communication." 18 U.S.C. § 2510(18). Thus, the court held that there was "no evidence that the transmission of information from the school laptop to Auther via eBlaster entailed hearing a human voice. Therefore, the evidence that Weindl seeks to suppress is not the product of a wire communication."

Finally, the court noted that to suppress the two eBlaster reports the arrived after Auther called Weindl under false pretenses, Weindl must have Fourth Amendment standing; that he had a subjective expectation of privacy regarding his actions on the laptop, and that his expectation was objectively reasonable. The court held that Weindl did not have standing. The court refused to accept the argument that Weindl had a property interest in the laptop. But, the court stated, the Fourth Amendment isn't solely grounded in property (note: don't tell that to Scalia), but also in privacy expectations.

Weindl argued, in that vein, that he had a legitimate expectation of privacy in the laptop because: he was the sole user, there were no warnings that his use would not be private (or that monitoring occured), he used the laptop in his own, locked office, when he was not using the laptop, he placed it in a desk drawer, and he never gave anyone else permission to use it. Not buying this argument, the court explained:

Sometimes, people delude themselves into thinking that they have a right to things that don't belong to them. . . . No evidence indicates that Weindl had a right to use, or himself had permission to use, a PSS laptop, even for school-related activities. Auther turned his son's laptop in to Weindl in Weindl's capacity as an agent for the school, not for Weindl's personal use.
Even if Weindl had a subjective (albeit unrealistic) expectation of privacy in the PSS laptop, it was not an expectation that society is prepared to endorse. An expectation of privacy does not become objectively reasonable just because a person hides someone else's property away in his office desk and does not let anyone else use it. A person cannot have a reasonable expectation of privacy in a computer he stole or obtained by fraud. See United States v. Wong, 334 F.3d 831, 839 (9th Cir. 2003) (stolen laptop); United States v. Caymen, 404 F.3d 1196, 1201 (9th Cir. 2005) (fraudulently obtained laptop). . . .
Weindl's case is similar to Wong and Caymen. Weindl misappropriated school property for his own personal use. Whatever expectation of privacy he developed in the contents of the laptop's hard drive and the keystrokes of Internet searches is not a legitimate one that society is prepared to accept. . . . The laptop was not assigned to Weindl and was not his office computer. For these reasons, Weindl lacks standing to claim a Fourth Amendment violation with respect to the eBlaster reports. (emphasis added)
Accordingly, the court held that none of the eBlaster reports should be suppressed, because the first four were not part of a search under color of state law and the last two were searches, but Weindl lacked standing (a reasonable expectation of privacy) to challenge them.

The next post on this case will focus on the court's analysis and explain what I believe the correct holding should have been.

(There is an additional issue in this case regarding the interrogation of Weindl that occurred in his office (after it was determined that he had looked at the CP), specifically: whether the conversation constituted a custodial interrogation requiring Miranda rights. The court held that part of the interrogation could stand, and part had to go. I believe this issue was wrongly decided as well (the entire conversation should have been tossed). However, I'm not going to address it because it is tangential to the main issue (and actually goes away if the computer evidence is suppressed because it would be fruit of the poisonous tree)). 















Friday, October 5, 2012

FTC decision puts spy software manufacturers on notice

The Federal Trade Commission recently settled with several companies regarding software that allowed the companies to spy on the computer's users by capturing screenshots, logging keystrokes, and taking pictures through the computer's webcam. The software was used by rent-to-own companies to track buyers when they became delinquent on payments. In addition to the rent-to-own companies, the FTC complaint also included the software manufacturer, Designware.

The software, PC Rental Agent, was installed on an estimated 420,000 computers in the United States, Canada, and Australia and marketed exclusively to businesses who rent computer equipment. The manufacturer recommended that companies notify customers of the software, but it was not required, and users could not detect the software's presence on their own.

In their complaint, the FTC argued that the software's "collection and disclosure to third parties of private and confidential information about consumers, including both those who rented the computer and
those who are merely using it, causes or is likely to cause substantial harm to consumers." As the manufacturer provided the means for the rental companies to engage in "unfair acts or practices," they had violated the FTC Act. It is the mission of the FTC "[t]o prevent business practices that are anticompetitive, deceptive, or unfair to consumers."

The settlement between Designware and the FTC prohibits the company from continuing to license or sell the software. This order is what one of this blog's readers calls the "biggest unfairness decision in the history of the FTC" because it extends beyond a direct business practice but also to the licensing of software the FTC deems "unfair."

Software manufacturers have been creating similar spying software for a long time, and this decision is likely to have put them on notice that the FTC's tolerance for the genre is soon to end. Of course, the FTC's authority would only extend to a business that is using the software to track consumers; thus, consumer or business-to-employee use would not be under their authority. However, the creation of software that is sold to a business in order to track a consumer could bring the creator under the wrath of the FTC.

Designware, which did not admit fault in the settlement, has filed for bankruptcy. The filing lists the Florida and California AG's offices as creditors, suggesting those offices may be considering further legal action.

Related Links:
Agreement
Complaint
News Release

Tuesday, September 4, 2012

Lawyer removed as counsel, alleged to have encouraged client to install spyware to aid custody/divorce proceeding

In Zang v. Zang, 2012 U.S. Dist. LEXIS 123383 (S.D. Ohio, August 30, 2012), the defendant's motion to disqualify plaintiff's counsel was granted due to Donald Roberts, the lawyer of the plaintiff (and former lawyer/brother-in-law of the defendant), allegedly being involved in encouraging the defendant to install spyware to aid in custody and divorce proceedings. The plaintiff (wife) in this matter is "asserting claims under the federal Wiretap Act, 18 U.S.C. § 2510 et seq., together with state law claims for invasion of privacy, conspiracy to commit invasion of privacy, and violations of the Ohio wiretap statute."

The facts as summarized by the court:
According to Mr. Zang, he confided in Roberts [the lawyer] that he suspected Ms. Zang of infidelity. Mr. Zang alleges that Roberts advised him to install a program called "Web Watcher" on the computer in the marital home, that Roberts assured him that he recommended this program to his other domestic relations clients, and that Roberts even suggested stores where Mr. Zang could find the software. After this conversation, Mr. Zang claims that he paid Roberts one dollar "as a retainer for his legal services." Mr. Zang then purchased and installed the Web Watcher program. 
Quite a strange set of facts, seeing as the attorney who was disqualified was the brother-in-law of the defendant, yet is now retained by Ms. Zang (plaintiff). Not surprisingly, Roberts (the attorney) denies ever being paid a $1 retainer by the defendant and offering such advice. Mr. Zang argues otherwise. (Side note: If the facts are true, Roberts will likely enjoy some time in front of the Ohio State Bar.)

To determine whether to disqualify Roberts, the court analyzed the rules of professional conduct in Ohio and held that because he would likely be called as a witness in the case and that his testimony was certainly material, and likely necessary, he could not be retained.

The court concluded:
Regardless whether reliance on the advice of counsel is a complete defense to a civil action brought under the wiretap statutes, this issue is relevant to any consideration of damages in this case. Both the federal and Ohio wiretap statutes provide for punitive damages in "appropriate" cases. 18 U.S.C. § 2520(b) and Ohio Rev. Code § 2933.65(A). Specifically, section§ [sic] 2520(b)(2) of the federal Wiretap Act "expressly permits the award of punitive damages when the aggrieved party demonstrates that a wanton, reckless or malicious violation of the Act has occurred." Smoot v. United Transp. Union, 246 F.3d 633, 647 (6th Cir. 2001) (internal quotes omitted). Thus, any evidence tending to show that Mr. Zang believed he was acting lawfully may be pertinent to the determination of whether he acted with the sufficient state of mind to make the award of punitive damages appropriate. Besides Mr. Zang, Roberts may be the only other witness who has personal knowledge on this point.
Stay tuned...

Monday, July 30, 2012

Tennessee district court awards man $20,000 in wiretap violation suit against his ex-wife

In November, I wrote a post about the Tennessee case of Klumb v. Goan, involving a man suing his ex-wife under the federal Wiretap Act after she installed spyware on his computers. Last week, a federal district court ruled in favor of the husband, awarding him $10,000 in statutory damages and $10,000 in punitive damages. Klumb v. Goan, 2012 U.S. Dist. LEXIS 100836 (E.D. Tenn. 2012).

Prior to the marriage, the soon-to-be wife purchased eBlaster, a common spyware application. The program records all keystrokes and websites visited, takes screenshots, and sends all of that data to a designated e-mail address. It also intercepts all incoming e-mails and forwards them to the designated e-mail address. Shortly after the marriage began, the wife installed eBlaster on the husband's work computer.

Some time later, while the husband was in rehab, the office administrator discovered what the wife had done after she attempted to print an e-mail she had intercepted using eBlaster. When the husband returned from rehab, the administrator notified him about the software and the wife having tried to print the e-mail. (Via a subpoena duces tecum, the husband later received a copy of all eBlaster reports received by the wife.)

The couple separated, and it was at that time that the husband discovered that the couple's prenup (designed to protect his interest in the family business), which had been drafted by the wife (an attorney), had inserted a null and void clause for adultery into her copy of the prenup, though his copy - they one they went through line by line - did not contain the clause.

While going through the e-mails on the computer and comparing them to those intercepted by the wife, it was determined that several of them had multiple versions. Ultimately, the court held that evidence showed the wife had modified the e-mails to add language so that it appeared he was having an affair. It was also discovered that a document that the wife sought to enter as a modification to the prenup (giving her 75% of assets in the event of the husband's infidelity), had also had two versions. After the husband signed one, she inserted a substitution page with the infidelity clause without his knowledge.

At trial, the wife argued that no wiretap had occurred because eBlaster did not "intercept" the communications. However, the court applied the "router switching analysis," finding that "a wiretap occurs when spyware automatically routes a copy of an email, which is sent through the internet, back through the internet to a third party's email address when the intended recipient opens the email for the first time." The court found "ample evidence" to show that a wiretap had occurred.

The wife also argued that she had consent because (1) the couple had agreed to monitor their son's computer usage, and (2) the software would prevent the leak of trade secrets to competitors. However, the court did not buy this argument for multiple reasons, including the fact that when the husband learned of the eBlaster usage and confronted his wife, she denied having knowledge of the software's existence.

As such, the court ordered statutory damages of $10,000, punitive damages of $10,000, and attorney's fees and costs.

Thursday, January 5, 2012

Malware steals credit card info, hides charges in online banking

As Mashable reports, new malware can steal your credit card information when you make purchases online, and after using it for fraudulent purposes, it can also hide those charges from your bank statement when you check your account online. Sounds like some pretty advanced stuff. Here's the video for slightly more info (apologizes for the embedded commercial).

Monday, November 7, 2011

Divorce, Spyware, and Wiretaps, oh my!

Well, it happened again. A Tennessee woman used "spyware" to investigate her husband's online activities. The court says that it allowed her "to intercept his incoming and outgoing e-mail and to monitor his activities on the internet" and ultimately denied wife's 12(b)(6) and summary judgment motions on the issue of a Wiretap Act violation.

The short opinion released by the court in Klumb v. Goan, 2011 U.S. Dist. LEXIS 127880 (E.D. Tenn. 2011), leaves much to be desired with regard to the facts of the case. However, based on what the court says, it seems as if the function that allowed her to "intercept" e-mail was either a keylogger or just a saved password. Here's what the plaintiff alleged:
"[He] first developed suspicions about Goan's installation of unauthorized internet spy software in November 2007 when he compared hard copies of his original email communications to an email recipient to later emails to that same recipient, and discovered that the original email communications had been intercepted, tampered with, and resent to the original recipient by Goan."
It seems to me like this was probably a Gmail account or something similar where it shows the entire e-mail conversation together. She obviously forwarded all of the e-mails to her own account, leaving the forwarded e-mails connected (since Gmail doesn't easily let you delete a specific e-mail without deleting the entire conversation).