Showing posts with label wiretap. Show all posts
Showing posts with label wiretap. Show all posts

Monday, August 19, 2013

Must Read: Lawful Hacking: Using Existing Vulnerabilities for Wiretapping on the Internet

Steven M. Bellovin (Columbia), Matt Blaze (Penn), Sandy Clark (Penn), and Susan Landau (Harvard; Sun Microsystems) have posted an incredible paper that was presented at the Privacy Legal Scholars Conference in June 2013. The paper is entitled "Lawful Hacking: Using Existing Vulnerabilities for Wiretapping on the Internet"; I have a general aversion to the term "must read," so my use of that term is indicative of the quality of the content.

 The abstract:
For years, legal wiretapping was straightforward: the officer doing the intercept connected a tape recorder or the like to a single pair of wires. By the 1990s, though, the changing structure of telecommunications — there was no longer just “Ma Bell” to talk to — and new technologies such as ISDN and cellular telephony made executing a wiretap more complicated for law enforcement. Simple technologies would no longer suffice. In response, Congress passed the Communications Assistance for Law Enforcement Act (CALEA), which mandated a standardized lawful intercept interface on all local phone switches. Technology has continued to progress, and in the face of new forms of communication — Skype, voice chat during multi-player online games, many forms of instant messaging, etc.— law enforcement is again experiencing problems. The FBI has called this “Going Dark”: their loss of access to suspects’ communication. According to news reports, they want changes to the wiretap laws to require a CALEA-­like interface in Internet software.  
CALEA, though, has its own issues: it is complex software specifically intended to create a security hole — eavesdropping capability — in the already-­complex environment of a phone switch. It has unfortunately made wiretapping easier for everyone, not just law enforcement. Congress failed to heed experts’ warnings of the danger posed by this mandated vulnerability, but time has proven the experts right. The so-­called “Athens Affair”, where someone used the built-­in lawful intercept mechanism to listen to the cell phone calls of high Greek officials, including the Prime Minister, is but one example. In an earlier work, we showed why extending CALEA to the Internet would create very serious problems, including the security problems it has visited on the phone system. 
In this paper, we explore the viability and implications of an alternative method for addressing law enforcement's need to access communications: legalized hacking of target devices through existing vulnerabilities in end-­user software and platforms. The FBI already uses this approach on a small scale; we expect that its use will increase, especially as centralized wiretapping capabilities become less viable. 
Relying on vulnerabilities and hacking poses a large set of legal and policy questions, some practical and some normative. Among these are: 
• Will it create disincentives to patching?
• Will there be a negative effect on innovation? (Lessons from the so-­called “Crypto Wars” of the 1990s, and, in particular, the debate over export controls on cryptography, are instructive here.)
• Will law enforcement’s participation in vulnerabilities purchasing skew the market?
• Do local and even state law enforcement agencies have the technical sophistication to develop and use exploits? If not, how should this be handled? A larger FBI role?
• Should law enforcement even be participating in a market where many of the sellers and other buyers are themselves criminals?
• What happens if these tools are captured and re-purposed by miscreants?
• Should we sanction otherwise-­illegal network activity to aid law enforcement?
• Is the probability of success from such an approach too low for it to be useful? 
As we will show, though, these issues are indeed challenging. We regard them, on balance, as preferable to adding more complexity and insecurity to online systems.

Thursday, March 28, 2013

Canadian Supreme Court holds that general warrant cannot be used to obtain prospective text messages

If you're interested, be sure to check out a recent Canadian case holding that a general warrant for prospective text messages was improper because the messages were being intercepted, requiring an interception order. The Crown was arguing that obtaining the messages from the phone company was not an interception of real-time communications because they were in a database and could therefore be acquired under the general warrant power. By an American law comparison, the court was essentially holding that interception of future text messages required a wiretap order as opposed to a search warrant or 2703(d) order.

Here's an excerpt from the main opinion (there was also a concurring and a dissenting opinion):
Text messaging is, in essence, an electronic conversation. The only practical difference between text messaging and the traditional voice communications is the transmission process. This distinction should not take text messages outside the protection of private communications to which they are entitled in Part VI. Technical differences inherent in new technology should not determine the scope of protection afforded to private communications....
When Telus copies messages to its computer database, several steps in the transmission process have yet to occur. The production schedule required by the general warrant in this case means that the police likely obtained stored copies of some text messages before they were even received by the intended recipient. Had the police acquired the same private communications directly from the transmission stream, instead of from the stored copies, the Crown concedes that a Part VI authorization would be required. The level of protection should not depend on whether the state acquires a copy of the private communication that is being transmitted or a copy that is in storage by a service provider as part of the communications process.... 
The police gained a substantial advantage by proceeding with a general warrant. They did not need the Attorney General’s request for an authorization; they did not need to show that other investigative procedures had been tried and failed; they did not need to provide any notice to the target individuals; and they did not need to identify which other individuals’ private communications may be acquired in the course of the search....

The general warrant in this case purported to authorize an investigative technique contemplated by a wiretap authorization under Part VI, namely, it allowed the police to obtain prospective production of future private communications from a computer maintained by a service provider as part of its communications process. Because Part VI applied, a general warrant under s. 487.01 was unavailable.
R. v. TELUS Communications Co., No. 34252 (Can. 2013).

Supreme Court of Canada says that wiretap order is required to obtain text messages

Tuesday, March 26, 2013

Good faith exception saves location data obtained after failure to request GPS data in wiretap request

In United States v. Barajas, No. 12-3003 (10th Cir. 2013), the Tenth Circuit refused to suppress evidence over a claim that the failure to request GPS data in a wiretap request prevented its use.

The DEA was investigating alleged drug trafficking and obtained a wiretap order for the defendant's cell phone after showing the court that other methods of surveillance had been unsuccessful. The affidavit, however, did not request GPS or cell site location data, though the actual order of the court did allow law enforcement to acquire it. At trial, the defendant filed a motion to suppress evidence that was acquired as a result of GPS pinging, but the motion was denied.

On appeal, the defendant argued "there is no probable cause for GPS pinging because the affidavits did not request GPS data." The Tenth ruled otherwise on that point, but noted that a separate probable cause determination was necessary for the GPS use as was required for the granting of the wiretap order. Ultimately on this point, the court held:
Absent an explanation of how Mr. Barajas's location would reveal information about the workings of the conspiracy—or more accurately, Mr. Barajas himself—we cannot be certain that probable cause exists.
That, of course, is not the end of the analysis. In applying the Leon good faith exception, the court held that while they "would prefer" the GPS data explanation in the affidavit, they will not hold the government to the "substantial nexus" standard for failure to do so. Further, the gap in the affadavit and order "gives [the court] more pause," but it is not clear that it was intentional. Thus, good faith saved the evidence for the government.

The defendant also argued that the wiretap evidence should have been suppressed for lack of necessity, but the court found that the government had met its burden with an explanation on why traditional investigative techniques were not sufficient.

Friday, December 7, 2012

Weindl: Why the court got it right, and the FBI agent/father shouldn't be viewed as a government agent

You'll have to forgive my co-blogger and me for turning our blog into a blog almost entirely about this Weindl case (United States v. Weindl, No. 1:12-CR-00017 (D.N.M.I. 2012), but as you're probably well-aware by now, it's an important case on the issues presented - and one likely to be appealed to the Ninth Circuit after the trial.

It's not often that Justin and I disagree. But in this case, while I find noble his attempt to argue for strengthened privacy rights under the Fourth Amendment, I cannot say that I find his reasoning compelling (see his previous posts here, here, and here). Justin argues that FBI Agent Auther left eBlaster on the computer intentionally because he suspected Weindl of "questionable activities," which apparently means that Auther knew that not only would Weindl fail to return the computer to the proper place, but that he would also watch child pornography on it. Perhaps Auther's training and experience gives him a sixth sense about such things, but it just doesn't seem likely. What is more likely is that he simply thought eBlaster had been deleted (after all, he did try to have all data removed twice), and he returned the computer as he was supposed to have done. Does law enforcement always comply with the Fourth Amendment? No. Does this seem like a case of an agent trying to circumvent the Fourth? Not really.

The issue that Justin and many others are raising and focusing on is the fact that Auther is an FBI agent. Yes, he is that, but he's also a parent, and as a parent, he should have the right to protect his children from content he doesn't think they should be viewing. That was his intent in installing eBlaster on the computer (unless it was an elaborate attempt to catch the principal beginning months before he even knew the computer would be returned). Who cares if he didn't own the computer? The school shouldn't be allowed to give students computers, and then tell parents that they're not allowed to attempt to prevent their children from viewing pornography, learn how to make meth, or whatever else kids do on computers nowadays. If Auther didn't want his son doing illicit activities, and this was the method he chose to make sure that didn't happen, then good for him. The point is that he didn't install it because he worked for the FBI nor did he install it for the purpose of wiretapping or searching Weindl's activities - he did it because he felt it was the best method for protecting his son.

So let's suppose Auther wasn't an FBI agent. "New Auther" is a grocery store manager, a father of three, happily married for 16 years. Semi-religious, and though not entirely opposed to the viewing of pornography, he thinks that his oldest son (in his mid-teens) is too young to be viewing it. He asks a co-worker what he can do, and the co-worker suggests eBlaster. He then downloads it and installs it on the computer where it sends him reports for the next few months. When New Auther is transferred to a grocery store in another state, he asks his computer friend/co-worker to remove all of his son's files. The co-worker is unsuccessful. He takes it to a computer store where they "reimage" it, making him think the computer has received a fresh start, free of eBlaster and everything else. He then returns the laptop to the school's principal, an acquaintance (not buddies, but something above Facebook friends). A couple weeks later, New Auther gets four eBlaster reports showing that the computer is now being used to view child pornography.

Those are essentially the same acts of real Auther, and those are the reports that the court refuses to suppress. After that point, Auther's actions do arguably cross the line into a government search. But those actions of a concerned parent that looked at the e-mails he received - those actions could have come from anyone - FBI agent or not. It is irrelevant that he opened all of the e-mails he received  - even if there were four of them. This was a mistake by someone who happens to also have a full-time job as a government agent, as opposed to a government agent who happens to make a mistake (and even that doesn't always warrant suppression thanks to good faith and other exceptions). This was not the case of Big Brother installing spyware on everyone's computers in order to capture our Internet activity (as if they actually need to go through that much trouble!).

Justin also argues that Weindl "certainly was not doing anything illegal." The computer loan program was a federally funded program to give students laptops for educational purposes. My guess is that under the terms of the grant, each laptop had to be accounted for at all times, and they probably are not allowed to just loan the computers out to anyone. By policy, they were only given to students and were never given to faculty. Anyone - especially the principal of the school - should have known that it went against the terms of the grant for a non-student to take possession of the laptop. My guess is that Weindl is smart enough to know that in taking possession of property purchased with federal government money and choosing to use it for personal purposes (especially viewing child pornography!), he's probably violating some sort of law for that possession.

There is something that my co-blogger and I agree on - I absolutely agree that the installation of eBlaster onto a person's computer without their knowledge and permission is a wiretap, in violation of the federal Wiretap Act. Where Justin and I would differ, however, is whether Auther's actions were intentional (as the Act requires). He thinks Auther intentionally left eBlaster on the computer in order to intercept Weindl's activity. I, however, would likely come down on the other side.

And... done. Are we finished talking about Weindl? Maybe.

Wednesday, December 5, 2012

Weindl (FBI agent's spyware vs. principal) - Why the court got it wrong

In this second post, I will explain my reasons for believing the court's reasoning in Weindl was flawed. The Weindl case, as a quick recap, involved a principal (Weindl) who was caught with child pornography after using a laptop assigned to the son of an FBI agent (Auther); the laptop was returned by Auther with spyware on it. For my original write-up of the facts of the case, see: Principal caught with CP when FBI agent returns son's school laptop with spyware still on it; court denies suppression. I also wrote a quick follow-up post about the coverage and misinformation regarding the case after I wrote about it. That can be found here: Weindl - FBI agent spyware v. principal attracts attention and misinformation.

First, let me address the "smell test." It seems extremely odd that when Auther took the computer to the FBI and asked "fellow agents for advice on how to wipe it clean" they "tried to remove all the files but were unsuccessful." Two things: (1) the FBI investigates a significant number of "cyber" cases using forensics techniques to recover deleted files and search through hard drives, uncover steganography, and analyze complex network traffic. Yet, they can't wipe a hard drive - something that a simple Google search will tell you how to do? Also, (2) Auther paid for and installed the spyware, knew the "hot-keys" to access the information it collected, and set it up to email him reports. Yet, once again, he could not uninstall that program, the most cognizable change he made to a machine he did not own?

In addition, he took it to a computer store to wipe all of the files, with a service order showing "reimage" and "clean out files" as the work to be done. I accept that a local service may not have been aware of the spyware to look for it in the first place, but reimage means just that, start all over again.  And, more interestingly, Auther did not even mention that he installed spyware on the computer to the computer shop. Wouldn't that program be the first thing you would mention when cleaning up a computer?

Also, the court seemed to be quite deferential to Auther when it accepted the argument that he was more concerned about leaving than investigating the principal. Perhaps that is true, but is it not equally likely that he suspected the principal of questionable activities and, before leaving, wanted to confirm his suspicions? After all, the FBI agent did say that he was aware of the Sandusky case and that what happened at Penn State motivated some of his later actions. That coupled with the two-time failure to remove the spyware smells funny.

But lets assume that all of the facts are true - just as the court did. I find it questionable that the court omitted any discussion regarding the license agreement of eBlaster, which requires you to agree to "use [eBlaster] only on a computer you own," an agreement Auther clearly violated when he installed it on a school-loaned laptop. The court also breezes over the likelihood that Auther violated policies of the school or the PSS laptop loaner program. I point this out because Auther is permitted to walk all over policies and procedures carte blanche, but Weindl's use of the laptop in likely violation of the rules of the loaner program was sufficient to wipe out his expectation of privacy completely. More on that later.

I think one of the most glaring errors of the court is the reasoning that opening the first four emails was not a search and instead was inadvertent conduct not under the color of law.  First, the court found that the search was only the activity of the spyware program collecting the data, and did not include the person on the other end viewing that information. I am not convinced you can draw such a black and white line. The Fourth Amendment (and by proxy the protection of privacy) has been held to protect against the intrusion of the process of a search as well as the discovery of the information it provides. If the latter were not an aim, the Fourth Amendment would never have been extended outside of property notions, as it was in Katz.

Thus, Auther's decision to open an email with a subject line that clearly indicated the email regarded information collected after he had returned the PC should have been held a search. Moreover, knowledge that the email could not regard his own or his son's activity does not make opening the email inadvertent. The definition of inadvertent is: "not focusing the mind on a matter : inattentive." The case indeed indicated that Auther recognized that the emails were providing information they should not have been because he believed the program had been removed and the computer was no longer in his possession. An example is illustrative: If I move into a new house on Royal Avenue on Tuesday, and on Friday I get a package addressed to "our lifelong neighbors on Royal Avenue," opening that package would not be inadvertent. I clearly know that I do not constitute the "neighbor" the package was intended for, since I moved in three days prior. Auther's opening of the email is no different. The subject line contained prima facie evidence that it was not intended for him and arose from improper means. Thus, the only reason he could have to open it would be to pry.

I am willing to concede, however, that one might reasonably argue that opening the first email would be inadvertent. Maybe he wasn't paying attention to the subject line. But, after reading the first, he should have known something was awry. To open the other three emails, after reading the first, would indicate one very important thing: that he was now acting as an officer of the law because of the information the email contained (evidence of someone accessing child pornography). To go back to my example, if I opened the first package without paying particular attention to the address line that said "to our lifelong neighbors on Royal Avenue," it may be reasonable to say I was just careless (or it was inadvertent). However, if inside that box are pictures of a family that I don't know, then when three more packages arrive addressed the same way and similar in appearance, a reasonable person would not open them. They would instead return them to whomever delivered them. Or, in Auther's case, contact the principal or the PSS program and indicate that the spyware he installed without authorization from either the school program or the software author was in fact still installed and had generated an email to him. An interesting question raised by the case is: if the spyware email hadn't contained evidence of CP access, would he have called the school to raise the flag on the spyware? One would think so.

The last significant problem with the case is the court's decision to deny standing to Weindl on the reasonable expectation of privacy issue. The court stated:
Sometimes, people delude themselves into thinking that they have a right to things that don't belong to them. . . . No evidence indicates that Weindl had a right to use, or himself had permission to use, a PSS laptop, even for school-related activities. Auther turned his son's laptop in to Weindl in Weindl's capacity as an agent for the school, not for Weindl's personal use.
Even if Weindl had a subjective (albeit unrealistic) expectation of privacy in the PSS laptop, it was not an expectation that society is prepared to endorse. An expectation of privacy does not become objectively reasonable just because a person hides someone else's property away in his office desk and does not let anyone else use it. A person cannot have a reasonable expectation of privacy in a computer he stole or obtained by fraud. 
The court justifies the last paragraph on two reasonable expectation of privacy cases: one involving a stolen computer (Wong), and one involving a computer obtained by fraud (Caymen). The court then states that "Weindl's case is similar to Wong and Caymen. Weindl misappropriated school property for his own personal use. Whatever expectation of privacy he developed in the contents of the laptop's hard drive and the keystrokes of Internet searches is not a legitimate one that society is prepared to accept. . . . The laptop was not assigned to Weindl and was not his office computer." I find the comparison to Wong and Caymen to be ill-advised. In both cases, the individual had either been convicted, or charged with obtaining the device by illegal means. Weindl did nothing of the sort, here. Additionally, in Caymen, where the defendant obtained the laptop by fraud, the court based its holding on cases from sister circuits regarding stolen cars. There is a theme here: stolen. Weindl did not steal, nor obtain anything by fraud. While he may not have had permission, he certainly was not doing anything illegal.

The Caymen court pointed out that a person who has stolen something lacks the property interests an owner has (the bundle of sticks) that define property ownership. Can the same be said for the laptop, here? Arguably, no. Weindl was permitted to have constructive possession of the laptop - something a thief would never have. Also, if the laptop had been stolen from the FBI agent's son and then recovered, it would likely have been returned to the principal (or someone under his authority). Granted, he lacked other property rights like the right to sell, but to analogize the computer to stolen property is off target.

Lastly, I believe the court was correct, technically, about the application of the Federal Wiretap Act: namely, that suppression is only for wire and aural communications in criminal cases. However, I find it fantastical to argue that placing spyware on an individual's computer isn't wiretapping. That the court had to cite to a 1978 case in support of this part of the holding is a clear illustration of the lack of coverage in this area. I hope that these facts present an opportunity for the 9th Circuit to directly address the issue and clarify that a "wire" communication should include such conduct. (Although maybe it is a legislative task, since to include what could be characterized as "electronic communications" within "wire communications" would arguably construe the civil portion of the law addressing "electronic communications" superfluous, something courts are reticent to do).

I am excited to see how the 9th Circuit handles this case. The facts of Weindl illustrate, as many other technologically centered cases do, the "play in the joints" of the law. And, with respect to the Wiretap Act, reflects the anachronistic nature of some federal statutes as applied to emerging technologies.

Wednesday, November 28, 2012

Principal caught with CP when FBI agent returns son's school laptop with spyware still on it; court denies suppression

This case will be discussed in two posts.

In United States v. Weindl, __ F.Supp __ (D. N.M.I. Nov. 20, 2012), a Northern Mariana Islands federal district court denied suppression of evidence obtained when spyware installed on school-owned laptop (assigned to an FBI agent's son and later used by the principal) sent child pornography (CP) reports (alerts) to the FBI agent - evidence that led to charges against the school principal (two counts of receiving CP and two counts of possession of CP). There are three relevant issues in the case: (1) whether the act of "accidental" failure to remove the spyware resulted in an "inadvertent search" or an intentional one, (2) whether the FBI agent was acting under the color of law when he opened and later investigated the reports he received from the spyware, and (3) whether Weindl had standing to assert a reasonable expectation of privacy in the spyware reports.

I believe this case was wrongly decided on the all three issues. I contacted David Banes, the lawyer for Weindl, and he (not surprisingly) agrees as well. He indicated that his client "fully intend[s]" to appeal this denial of suppression after the case goes to trial (it does not look like the judge will allow a conditional plea).

In this first post, I will give a summary of the case. In the second post, I will argue why the court erred in its holding.

Summary 

The defendant Thomas Weindl ("Weindl") was a school principal at Whispering Palms public school in Saipan, Mariana Islands. The FBI agent whose actions gave rise to this case is Joseph Auther ("Auther"). Auther's eldest son was enrolled at Whispering Palms, and was assigned a laptop during his time there. Auther kept an eye on his son's use of the laptop by purchasing and installing eBlaster on the laptop (without his son's knowledge). eBlaster sent email reports directly to Auther, with keystrokes, internet sites visited, and a plethora of other information. The report in Auther's inbox "would give the subject as 'Report,' followed by the date and time span of covered activity."

Auther was reassigned to a different FBI office in April 2012 and as part of the moving process, returned the laptop to the school, and more specifically, handed it over to Weindl. Auther did not tell Weindl about eBlaster, apparently assuming that it had been removed, but had told Weindl (prior to turning it in) that he would wipe the machine. Auther did in fact attempt to wipe the machine, but failed. The court describes Auther's actions as follows:
The first step Auther took to service the laptop was to bring it into the FBI office and ask fellow agents for advice on how to wipe it clean. They tried to remove all the files but were unsuccessful. Next, . . . Auther asked a local computer store to repair a scratched screen and wipe off all the files on the laptop's hard drive. The store's service order (Ex. 1) lists the work to be done as "Reimage" and the work performed as "Clean out files." Auther did not tell the technician about eBlaster, but he expected that the cleaning would eliminate the program. 
As stated previously, eBlaster was not, in fact, removed. After handing the laptop over, Auther did not receive any emails from eBlaster for over six days. On the seventh day, Auther received four emails from eBlaster indicating someone was using the laptop to access child pornography. The emails had subject lines, as described above, that clearly indicated that they were regarding activity that occurred after Auther turned in the laptop. Auther viewed all four emails, nonetheless. Auther hypothesized that the activity could be from a virus, another student using the laptop, or Weindl himself. He thought of Weindl because the pornography searched for was of young asian children with older adults and Weindl had recently married a Korean woman and now had an 11-year-old stepdaughter.

At this point, Auther did not report the results of the reports to authorities, but instead called Weindl under false pretenses, acting as if he would like to purchase the laptop. Weindl indicated that he had given it back to the school laptop agency (PSS), and that Auther wouldn't be able to buy it. Auther did not indicate that he had received CP reports, or that eBlaster was apparently still on the computer. Auther's reasoning was:
. . .that he did not want to raise concerns in Weindl's mind about who was using the computer or about a possible investigation involving Whispering Palms teachers and students. . . . [H]e was concerned that the Internet activity might mean that a child molester was operating at Whispering Palms. He was aware that a former coach at Pennsylvania State University had just been convicted on child molestation charges, and he was determined not to allow similar conduct to go undetected at Whispering Palms. (emphasis added)
Three days later, instead of handing the case over to the authorities, Auther then proceeded to start an investigation into what was going on with the laptop. Flashing his FBI badge at the offices of the the laptop program agency (PSS), he inquired if the laptop had actually been returned, and found that it hadn't. Auther then inquired with his ISP about the IP address noted in the reports, attempting to find out where the computer was being used. Auther indicated to the court that he may have shown his FBI badge to the ISP. The ISP refused to tell him anything, but he was able to decipher that the computer usage was not from an IP at his house.

On the same day as the trip to PSS and the ISP, Auther received two more emails indicating that the computer was being used to access CP. He decided to drive by the school on his way to report everything to the FBI. He noticed Weindl's car in the parking lot and called Weindl on his cellphone. Auther asked about the laptop and Weindl said he was investigating some "hanky panky" going on at PSS. Auther knew he was lying since PSS did not have the laptop, and grew much more suspicious. He reported what was going on and his suspicion about Weindl to a special agent with the FBI (Ewing). He also asked that child protective services be sent to Weindl's house to check on his 11-year-old stepdaughter.

Over a week later, Ewing and Auther went to Weindl's office to speak with him. During the conversation, Weindl admitted he lied about returning the laptop to PSS and admitted to viewing child pornography. He also confessed that he had taken the laptop out into the jungle and smashed it. He was arrested outside the school a short time later. Prior to trial, Weindl filed a motion to suppress the eBlaster evidence arguing that it was obtained in violation of his Fourth Amendment rights.

The court, in denying suppression of the eBlaster evidence, began by declaring that to have a Fourth Amendment violation, there needed to be state action and standing (a reasonable expectation of privacy). Addressing the state action portion, the court laid out the standard relating to an off-duty officer - whether Auther was acting under color of state law, where his actions "in some way related 'to the performance of his official duties'" or "pursuant to [a] government or police goal." The court held that when Auther installed eBlaster he was acting as a private citizen, and not as an FBI agent. Despite the circumstances changing when Auther returned the laptop (that Auther wasn't acting as a concerned parent anymore), the court held that it was an inadvertent search not under color of state law because Auther did not intentionally leave eBlaster on the computer.

In reaching that result, the court was not persuaded by Weindl's argument that even if the presence of eBlaster was inadvertent, Auther opening and reading the eBlaster reports turned something inadvertent into intentional. The court reasoned that "[t]he search was the gathering of information by eBlaster, not the viewing of the contents." The court also dismissed the argument that "the initial eBlaster reports come under the Fourth Amendment via the two-part test for private-party searches."

So, to clarifiy, the original four emails from eBlaster sent to Auther, and him viewing them, were not the "product of a search conducted under color of state law."

The court did find a search, however, relating to the two eBlaster reports Auther received after he called Weindl to inquire about the laptop. The court stated:
By that time, Auther knew that someone may have been viewing illicit material on the laptop. He suspected Weindl even before he called him. When he did call, he hid his real concern about the laptop's usage behind a pretense that he was interested in purchasing the computer. After the call, he did not uninstall or disable eBlaster, even though as a private citizen he was under no obligation to continue monitoring an unknown person's offensive Internet activities. He did not immediately call his colleagues at the FBI and hand the investigation over to them — conduct that might have indicated Auther wanted to maintain a separation between his private self and his public persona as a law enforcement officer. . . . [instead] Auther continued his investigation into the child pornography website searches. . . . At the PSS offices, he showed his FBI badge. At the Internet service provider, he relied on the fact that he was known to be an FBI agent to seek information about IP addresses. The totality of the circumstances shows that at this point, Auther's actions were related to his official duties and in pursuit of a police goal. Although a formal FBI investigation had not been opened yet, Auther was now acting under color of law.
The court dismissed the government's argument to the contrary, that "even if Auther's conduct constituted state action, his discovery of the illicit Internet activity through eBlaster e-mails was accidental and therefore does not come under the Fourth Amendment." The court stated that precedent was clear that to have inadvertent discovery through plain-view doctrine, the police had to be somewhere they were justified to be. However, here, "Auther, . . . had no legitimate justification to intrude on anyone's conduct on the school laptop once it was no longer on loan to his son. Moreover, the incriminating evidence did not drop out while he was straightening the icons on the computer's desktop but came into view because of intentional spying on the keyboard and hard drive."

Addressing the argument that a violation of the federal Wiretap Act occurred, the court noted that under the criminal portion of the Act, "suppression motions are authorized only with respect to the contents of wire and oral — not electronic — communications."  The court laid out that the definition of "[a] wire communication is 'any aural transfer' involving wire or like connections between the point of origin and point of reception." 18 U.S.C. § 2510(1). And that, "an 'aural transfer' is 'a transfer containing the human voice' at some point in transmission of the communication." 18 U.S.C. § 2510(18). Thus, the court held that there was "no evidence that the transmission of information from the school laptop to Auther via eBlaster entailed hearing a human voice. Therefore, the evidence that Weindl seeks to suppress is not the product of a wire communication."

Finally, the court noted that to suppress the two eBlaster reports the arrived after Auther called Weindl under false pretenses, Weindl must have Fourth Amendment standing; that he had a subjective expectation of privacy regarding his actions on the laptop, and that his expectation was objectively reasonable. The court held that Weindl did not have standing. The court refused to accept the argument that Weindl had a property interest in the laptop. But, the court stated, the Fourth Amendment isn't solely grounded in property (note: don't tell that to Scalia), but also in privacy expectations.

Weindl argued, in that vein, that he had a legitimate expectation of privacy in the laptop because: he was the sole user, there were no warnings that his use would not be private (or that monitoring occured), he used the laptop in his own, locked office, when he was not using the laptop, he placed it in a desk drawer, and he never gave anyone else permission to use it. Not buying this argument, the court explained:

Sometimes, people delude themselves into thinking that they have a right to things that don't belong to them. . . . No evidence indicates that Weindl had a right to use, or himself had permission to use, a PSS laptop, even for school-related activities. Auther turned his son's laptop in to Weindl in Weindl's capacity as an agent for the school, not for Weindl's personal use.
Even if Weindl had a subjective (albeit unrealistic) expectation of privacy in the PSS laptop, it was not an expectation that society is prepared to endorse. An expectation of privacy does not become objectively reasonable just because a person hides someone else's property away in his office desk and does not let anyone else use it. A person cannot have a reasonable expectation of privacy in a computer he stole or obtained by fraud. See United States v. Wong, 334 F.3d 831, 839 (9th Cir. 2003) (stolen laptop); United States v. Caymen, 404 F.3d 1196, 1201 (9th Cir. 2005) (fraudulently obtained laptop). . . .
Weindl's case is similar to Wong and Caymen. Weindl misappropriated school property for his own personal use. Whatever expectation of privacy he developed in the contents of the laptop's hard drive and the keystrokes of Internet searches is not a legitimate one that society is prepared to accept. . . . The laptop was not assigned to Weindl and was not his office computer. For these reasons, Weindl lacks standing to claim a Fourth Amendment violation with respect to the eBlaster reports. (emphasis added)
Accordingly, the court held that none of the eBlaster reports should be suppressed, because the first four were not part of a search under color of state law and the last two were searches, but Weindl lacked standing (a reasonable expectation of privacy) to challenge them.

The next post on this case will focus on the court's analysis and explain what I believe the correct holding should have been.

(There is an additional issue in this case regarding the interrogation of Weindl that occurred in his office (after it was determined that he had looked at the CP), specifically: whether the conversation constituted a custodial interrogation requiring Miranda rights. The court held that part of the interrogation could stand, and part had to go. I believe this issue was wrongly decided as well (the entire conversation should have been tossed). However, I'm not going to address it because it is tangential to the main issue (and actually goes away if the computer evidence is suppressed because it would be fruit of the poisonous tree)). 















Monday, October 8, 2012

Wiretap Act and sniffing Wi-Fi - new Michigan Law Review note

The newest issue of the Michigan Law Review has arrived, and within it is a very interesting note on the intersection of the federal wiretap act and wi-fi sniffing. It's a topic we have touched upon here a few times, and I think the article does a good job of highlighting the uncertainty in the area. Indeed, that word is used in the abstract. The article, by Mani Potnuru, can be reached here: Limits of the Federal Wiretap Act’s Ability to Protect Against Wi-Fi Sniffing, and the abstract is below:
Adoption of Wi-Fi wireless technology continues to see explosive growth. However, many users still operate their home Wi-Fi networks in unsecured mode or use publicly available unsecured Wi-Fi networks, thus exposing their communications to the dangers of "packet sniffing," a technique used for eavesdropping on a network. Some have argued that communications over unsecured Wi-Fi networks are "readily accessible to the general public" and that such communications are therefore excluded from the broad protections of the Federal Wiretap Act against intentional interception of electronic communications.
This Note examines the Federal Wiretap Act and argues that the current Act's treatment of Wi-Fi sniffing might protect unsecured Wi-Fi communications under some circumstances, but that any such protections are incidental, unsystematic, and uncertain. This Note further argues that the current statute's "readily accessible to the general public" language should be interpreted in a way that addresses concerns about Wi-Fi sniffing and users' expectations of privacy. Users' current expectations stem from their limited understanding of the underlying Wi-Fi technology and the accompanying security risks and, more importantly, from the fact that private communications cannot be intercepted without specialized tools and knowledge not readily available to the general public. Finally, this Note advocates for amending the Federal Wiretap Act to remove uncertainty regarding protections against Wi-Fi sniffing. Clear protections against Wi-Fi sniffing would avoid the private and social cost of data theft resulting from sniffing and could close the gap between users' theoretical ability to protect themselves by using security mechanisms and their reduced practical ability to take any such protective measures.

Wednesday, September 5, 2012

Federal court addresses applicability of Wiretap Act to wireless network packet sniffing, holds data is "publicly available"

An Illinois federal district court recently analyzed the Wiretap Act as it applies to packet sniffing and held that "the interception of communications sent over unencrypted Wi-Fi networks" does not violate the statute. In re Innovatio IP Ventures, LLC Patent Litigation, No. 11 C 9308 (N.D. Ill. 2012).

The plaintiff, Innovatio IP Ventures, LLC, brought suit against multiple companies for various patent infringement claims concerning the use of wireless Internet technology in the defendants' businesses (such a hotels and coffee shops). Innovatio sent technicians to defendants' businesses in order to collect information about the infringement. The packets they intercepted contained data about the network as well as "e-mails, pictures, videos, passwords, financial information, private documents" and other data transmitted by network users. Innovatio sought a preliminary ruling on the admissibility of the data.

After a discussion of how packets are transmitted in a wireless network and the meaning of the word "intercept" in the Wiretap Act, the court determined that the proper "question is not ... whether the networks are "readily available to the general public," but instead whether the network is configured in such a way so that the electronic communications sent over the network are readily available." The Wiretap Act provides an exception if the communications are publicly available (18 U.S.C. § 2511(g)(i)). The court concluded that the communications themselves are readily available because they are "open to such interference from anyone with the right equipment" - equipment available for a couple hundred dollars and the right open source software.

The court concluded:
Any tension between that conclusion and the public's expectation of privacy is the product of the law's constant struggle to keep up with changing technology. Five or ten years ago, sniffing technology might have been more difficult to obtain, and the court's conclusion might have been different. But it is not the court's job to update the law to provide protection for consumers against ever changing technology. Only Congress, after balancing any competing policy interests, can play that role.... Unless and until Congress chooses to amend the Wiretap Act, the interception of communications sent over unencrypted Wi-Fi networks is permissible.
An argument had also been made that the interception violated Pen Registers and Trap and Trace, but the court found that the argument was not properly briefed and declined to apply the statute. Thus, the court found the evidence to be admissible.

Tuesday, September 4, 2012

Lawyer removed as counsel, alleged to have encouraged client to install spyware to aid custody/divorce proceeding

In Zang v. Zang, 2012 U.S. Dist. LEXIS 123383 (S.D. Ohio, August 30, 2012), the defendant's motion to disqualify plaintiff's counsel was granted due to Donald Roberts, the lawyer of the plaintiff (and former lawyer/brother-in-law of the defendant), allegedly being involved in encouraging the defendant to install spyware to aid in custody and divorce proceedings. The plaintiff (wife) in this matter is "asserting claims under the federal Wiretap Act, 18 U.S.C. § 2510 et seq., together with state law claims for invasion of privacy, conspiracy to commit invasion of privacy, and violations of the Ohio wiretap statute."

The facts as summarized by the court:
According to Mr. Zang, he confided in Roberts [the lawyer] that he suspected Ms. Zang of infidelity. Mr. Zang alleges that Roberts advised him to install a program called "Web Watcher" on the computer in the marital home, that Roberts assured him that he recommended this program to his other domestic relations clients, and that Roberts even suggested stores where Mr. Zang could find the software. After this conversation, Mr. Zang claims that he paid Roberts one dollar "as a retainer for his legal services." Mr. Zang then purchased and installed the Web Watcher program. 
Quite a strange set of facts, seeing as the attorney who was disqualified was the brother-in-law of the defendant, yet is now retained by Ms. Zang (plaintiff). Not surprisingly, Roberts (the attorney) denies ever being paid a $1 retainer by the defendant and offering such advice. Mr. Zang argues otherwise. (Side note: If the facts are true, Roberts will likely enjoy some time in front of the Ohio State Bar.)

To determine whether to disqualify Roberts, the court analyzed the rules of professional conduct in Ohio and held that because he would likely be called as a witness in the case and that his testimony was certainly material, and likely necessary, he could not be retained.

The court concluded:
Regardless whether reliance on the advice of counsel is a complete defense to a civil action brought under the wiretap statutes, this issue is relevant to any consideration of damages in this case. Both the federal and Ohio wiretap statutes provide for punitive damages in "appropriate" cases. 18 U.S.C. § 2520(b) and Ohio Rev. Code § 2933.65(A). Specifically, section§ [sic] 2520(b)(2) of the federal Wiretap Act "expressly permits the award of punitive damages when the aggrieved party demonstrates that a wanton, reckless or malicious violation of the Act has occurred." Smoot v. United Transp. Union, 246 F.3d 633, 647 (6th Cir. 2001) (internal quotes omitted). Thus, any evidence tending to show that Mr. Zang believed he was acting lawfully may be pertinent to the determination of whether he acted with the sufficient state of mind to make the award of punitive damages appropriate. Besides Mr. Zang, Roberts may be the only other witness who has personal knowledge on this point.
Stay tuned...

Monday, July 30, 2012

Tennessee district court awards man $20,000 in wiretap violation suit against his ex-wife

In November, I wrote a post about the Tennessee case of Klumb v. Goan, involving a man suing his ex-wife under the federal Wiretap Act after she installed spyware on his computers. Last week, a federal district court ruled in favor of the husband, awarding him $10,000 in statutory damages and $10,000 in punitive damages. Klumb v. Goan, 2012 U.S. Dist. LEXIS 100836 (E.D. Tenn. 2012).

Prior to the marriage, the soon-to-be wife purchased eBlaster, a common spyware application. The program records all keystrokes and websites visited, takes screenshots, and sends all of that data to a designated e-mail address. It also intercepts all incoming e-mails and forwards them to the designated e-mail address. Shortly after the marriage began, the wife installed eBlaster on the husband's work computer.

Some time later, while the husband was in rehab, the office administrator discovered what the wife had done after she attempted to print an e-mail she had intercepted using eBlaster. When the husband returned from rehab, the administrator notified him about the software and the wife having tried to print the e-mail. (Via a subpoena duces tecum, the husband later received a copy of all eBlaster reports received by the wife.)

The couple separated, and it was at that time that the husband discovered that the couple's prenup (designed to protect his interest in the family business), which had been drafted by the wife (an attorney), had inserted a null and void clause for adultery into her copy of the prenup, though his copy - they one they went through line by line - did not contain the clause.

While going through the e-mails on the computer and comparing them to those intercepted by the wife, it was determined that several of them had multiple versions. Ultimately, the court held that evidence showed the wife had modified the e-mails to add language so that it appeared he was having an affair. It was also discovered that a document that the wife sought to enter as a modification to the prenup (giving her 75% of assets in the event of the husband's infidelity), had also had two versions. After the husband signed one, she inserted a substitution page with the infidelity clause without his knowledge.

At trial, the wife argued that no wiretap had occurred because eBlaster did not "intercept" the communications. However, the court applied the "router switching analysis," finding that "a wiretap occurs when spyware automatically routes a copy of an email, which is sent through the internet, back through the internet to a third party's email address when the intended recipient opens the email for the first time." The court found "ample evidence" to show that a wiretap had occurred.

The wife also argued that she had consent because (1) the couple had agreed to monitor their son's computer usage, and (2) the software would prevent the leak of trade secrets to competitors. However, the court did not buy this argument for multiple reasons, including the fact that when the husband learned of the eBlaster usage and confronted his wife, she denied having knowledge of the software's existence.

As such, the court ordered statutory damages of $10,000, punitive damages of $10,000, and attorney's fees and costs.

Wednesday, May 23, 2012

NY district court allows wiretap evidence over multiple objections from defendant

In United States v. Kazarian, 2012 U.S. Dist. LEXIS 70050 (S.D.N.Y. 2012), the court denied the suppression of wiretap evidence over arguments that probable cause did not exist, the necessity requirement was not established, and minimization was not followed.

The defendant allegedly worked to defraud Medicare of over $100 million and sought to suppress evidence from wiretaps (among other searches), arguing that probable cause did not exist and the applications did not show necessity for a wiretap. The court first found that probable cause existed, and then addressed the necessity requirement.

Under the Wiretap Act, allowance for a wiretap requires law enforcement to "demonstrate that 'normal investigative procedures have been tried and have failed or reasonably appear to be unlikely to succeed if tried or to be too dangerous.'" 18 U.S.C. § 2518(1)(c). Wiretaps should not be used routinely "as the initial step in criminal investigation," but law enforcement need not exhaust all other means.

The defendant claimed that "little to no investigation was done" prior to the wiretapping and that the language for showing necessity was essentially boilerplate. However, the court held that using such boilerplate language does not alone make it invalid and found that the wiretapping was reasonably believed to be more effective than other methods of investigation.

The court, in a detailed analysis, also held that the government sufficiently followed the minimization requirement which requires the wiretap to "be conducted in such a way as to minimize the interception of communications not" related to the investigation. 18 U.S.C. § 2518(5).

Sunday, January 15, 2012

Appellate court addresses multiple issues in CP case

A recent Eleventh Circuit case presents a myriad of issues. In United States v. Cray, the defendant appealed his convictions of receipt and possession of child pornography. 450 Fed. Appx. 923 (11th Cir. 2012). He had subscribed to a website providing child pornography for $79.99 per month, and law enforcement tracked his actions on the site back to his ISP account. Among his arguments for reversal were:
  • An argument that obtaining his IP subscriber information was a violation of the Wiretap Act, and thus suppression of the information was warranted. As the court noted, there is no suppression remedy under the Wiretap Act. (Also, obtaining such information is clearly not a wiretap under ECPA.)
  • An expert witness should not have been allowed to testify that "Cray personally operated his laptop to access a child pornography website while in Dover, Delaware." The court found this testimony to be reliable and appropriate although the expert was not personally aware of the act.
  • Admission of testimony concerning geographic location of IP addresses was not inadmissible hearsay under plain error review.
  • Presentation of videos from the child pornography website to the jury was appropriate despite the fact that the videos were not located on the defendant's computer. They were relevant to show the defendant's "intent to receive and access ... child pornography" and to prove they "were actually child pornography."
  • Summary chart matching "filenames found in [defendant's] laptop registry with files accessed on the Website by a subscriber using Cray's name and information" were appropriate for presentation to the jury because the information had already been established, defendant had opportunity to cross-examine, and the court provided limiting instructions to the jury.
Therefore, the trial court decision was affirmed.

Sunday, January 1, 2012

Ninth Circuit finds standing to challenge government's alleged communications dragnet

In a lawsuit alleging "widespread warrantless eavesdropping" in violation of the Foreign Intelligence Surveillance Act, the Electronic Communications Privacy Act, and the Stored Communications Act, the Ninth Circuit has reversed and remanded the lower court dismissal on standing grounds. Jewel v. NSA, 673 F.3d 902 (2011).

The suit, backed by the Electronic Frontier Foundation, alleged "that the government[] operated a "dragnet collection" of communications records by 'continuously soliciting and obtaining the disclosure of all information in AT&T's major databases.'" The district court dismissed the compliant, finding that Jewel's complaint failed by not "specifically linking any of the plaintiffs to the alleged surveillance activities."

Of course, the issue is whether Jewel could demonstrate a "sufficiently concrete and specific injury" in order to have standing. The court found that the complaint "described in detail the ... equipment used ... at the particular AT&T facility" and that she "alleged with particularity that her communications were part of the dragnet."

RELATED CASE: The Ninth Circuit also decided, in a separate opinion, that § 802 of the Foreign Intelligence Surveillance Act, which immunizes telecommunications companies from cooperating with the government's investigations, is constitutional. In re NSA Telcoms. Records Litig., 2011 U.S. App. LEXIS 25949 (2011).

Friday, December 16, 2011

Court applies exception provision of federal Wiretap Act

In a recent wiretapping case, the court made a brought up an important Wiretap Act provision that should be clarified. The plaintiff learned that his conversation with a J.P. Morgan Chase Bank employee had been recorded by the company. The court holds that under the federal Wiretap Act, the plaintiff cannot state a claim. "The statute prohibits an interception that is 'for the purpose of committing any criminal or tortious act in violation of the Constitution or laws of the United States or of any State.' 18 U.S.C. § 2511(2)(d). Courts have interpreted this provision to require that the 'interceptor intend to commit a crime or tort independent of the act of recording itself.' Caro v. Weintraub, 618 F.3d 94 (2d Cir. 2010).

While the court is correct in its analysis, it is important to mention that Caro and the Wiretap Act both state this requirement only "where [the wiretapper] is a party to the communication or where one of the parties to the communication has given prior consent to such interception." 18 U.S.C. § 2511(2)(d). Thus, if a party to the conversation records it for the purpose of committing a crime or tort, they have also violated the federal Wiretap Act.

The case is Berk v. J.P. Morgan Chase Bank, N.A., 2011 U.S. Dist. LEXIS 143510 (E.D. Pa. 2011).

Monday, November 28, 2011

Wired.com explains how Big Brother is watching you

Wired.com recently published an article titled "9 Reasons Wired Readers Should Wear Tinfoil Hats" which hypothesized the many ways in which the government tracks us electronically. The post explains how the government [probably] uses wiretapping, tracking devices, border search, fake cell phone towers, government malware, and more. Some of it is simply written to entertain conspiracy theorists, but it is interesting to ponder nonetheless.

It's a little more hypothetical than I'd usually post, but the best part of the article is the graphic (at right) showing how long cell phone companies keep text messages, call records, and Internet activity.

Just last week, confidential guidelines were released detailing how long Facebook, Microsoft, and AOL keep IP logs and data.

RELATED NEWS: NPR released a story detailing how LAPD has a new computer program that predicts the location of future crimes based on past crime patterns. "[C]rime, especially property crime, happens in predictable waves."

Friday, November 18, 2011

Company alleges SCA, Wiretap, and CFAA claims against former VP

In Exec. Sec. Mgmt. v. Dahl, 2011 U.S. Dist. LEXIS 132538 (C.D. Cal. 2011), The APEX Group (an event security firm) alleges that former employees (one was a VP and board member) made misrepresentations that caused them to lose a contract with the PGA. The ten claims include violations of the SCA, Wiretap Act, and the CFAA. The defendants moved for summary judgment.

The SCA claim is the most interesting. Apex argues two violations - unauthorized access to e-mail and deletion of information on Apex laptops. The latter argument was struck down because defendants had not "accessed a facility," among other issues. However, defendants argue that they were administrators of the Apex e-mail accounts. The issue at hand is whether they, as administrators "with authorization to access the facility, ... accesse[d] unauthorized information." Thus, summary judgment was denied on the e-mail issue.

The Wiretap Act claim appears to be based on defendants setting up their cell phones to download e-mails from accounts not their own through a POP3 account. The court denied this to be "interception" under the statute because the e-mails were not "halt[ed]"; they simply read "emails not intended for their eyes."

With the CFAA claim, Apex argues that defendants used an "erasure program" to delete information from company computers. To satisfy the mandatory $5,000 damage requirement, they argue that this violation ultimately caused the PGA to terminate its relationship with Apex at a cost of over $118,000. As noted here, CFAA damages can be hard to demonstrate, but the court decided to send both arguments to the jury.

This case has nothing extremely profound in it (though the VP being the e-mail administrator presents an interesting question). But if you are interested in learning the basics of these three statutes, Judge Snyder does an excellent job of explaining how these claims work.

Monday, November 7, 2011

Divorce, Spyware, and Wiretaps, oh my!

Well, it happened again. A Tennessee woman used "spyware" to investigate her husband's online activities. The court says that it allowed her "to intercept his incoming and outgoing e-mail and to monitor his activities on the internet" and ultimately denied wife's 12(b)(6) and summary judgment motions on the issue of a Wiretap Act violation.

The short opinion released by the court in Klumb v. Goan, 2011 U.S. Dist. LEXIS 127880 (E.D. Tenn. 2011), leaves much to be desired with regard to the facts of the case. However, based on what the court says, it seems as if the function that allowed her to "intercept" e-mail was either a keylogger or just a saved password. Here's what the plaintiff alleged:
"[He] first developed suspicions about Goan's installation of unauthorized internet spy software in November 2007 when he compared hard copies of his original email communications to an email recipient to later emails to that same recipient, and discovered that the original email communications had been intercepted, tampered with, and resent to the original recipient by Goan."
It seems to me like this was probably a Gmail account or something similar where it shows the entire e-mail conversation together. She obviously forwarded all of the e-mails to her own account, leaving the forwarded e-mails connected (since Gmail doesn't easily let you delete a specific e-mail without deleting the entire conversation).