close
The Wayback Machine - https://web.archive.org/web/20071017092012/http://information-retrieval.info:80/cybercrime/
Cybercrime Logo

 

Image
 
Image

 NYLS Logo

Image

 

COURSE OUTLINE AND SYLLABUS (Spring 2007):

Cybercrime, Cyberterrorism, and
Digital Law Enforcement:


NYLS CRI150 (Spring 2007) [go to 2006 Syllabus]

Professor K. A. Taipale (bio) (contact)

<cybercrime.advancedstudies.org>

New technologies do not determine human fates,
rather, they alter the spectrum of possibilities within which people act.

(McClintock and Taipale, 1992)

The emergence of modern information-based societies in which the exercise of economic, political, and social power increasingly depends on the opportunities to access, manipulate, and use information and information infrastructure has created opportunities for new crimes and new threats to global security, as well as for new law enforcement and national security responses.

This course explores how a "networked" world has bred new crimes and new responses, and investigates how the computer has become a tool, a target, and a place of criminal activity and national security threats, as well as a mechanism of response. This course addresses such questions as how emerging technologies challenge existing laws and criminal procedures; how nation-states regulate criminal conduct across traditional geographic and political boundaries; what reasonable expectations of privacy are in cyberspace; and how control is shifting from traditional mechanisms of law enforcement to new regulatory regimes, including technology. (See also, Subtext infra).

Specific topics covered include the information environment as crime scene; computer use in traditional crimes like financial fraud, drug trafficking, extortion, securities fraud, and political terrorism; hacking and unauthorized access; identity theft and online fraud; electronic interception, search and seizure, and surveillance; cyberterror; "hactivism"; censorship and free speech; economic espionage; and information warfare.

The casebook for this class is David J. Loundy, COMPUTER CRIME, INFORMATION WARFARE, AND ECONOMIC ESPIONAGE, Carolina Academic Press (2003) (ISBN:0890891109).


Registered Students note:

Login to NYLS LexisNexis Web Course
for updated Syllabus and Reading Assignments.


All original material on this page is copyright the Center for Advanced Studies in Science and Technology Policy © 2003-2007. Permission is granted to reproduce this material in whole or in part for non-commercial purposes, provided it is with proper citation and attribution.

Cite this page as: K. A. Taipale, Cybercrime, Cyberterrorism, and Digital Law Enforcement: Course Oultine and Syllubus (2007) (NYLS CRI150) available at http://cybercrime.advancedstudies.info/.


 

Course Outline

  1. Overview, What is Cybercrime?
  2. Computer Intrusions and Attacks
  3. Computer Viruses, Time Bombs, Trojans, Malicious Code
  4. Online Fraud and Identity Theft; Intellectual Property Theft
  5. Online Vice: Gambling and Pornography (Enforcement Case Study)
  6. Investigating Cybercrime; International Aspects and Jurisdiction
  7. Infrastructure and Information Security; Risk Management
  8. Interception, Search and Seizure, and Surveillance
  9. Information Warfare and Hacktivism
  10. PAPER RESEARCH
  11. The War of Ideas (relevant to 2006 course only)
  12. VoIP: A Case Study
  13. Trade Secret Theft and Economic Espionage
  14. National Security
  15. PAPERS DUE
  16. USEFUL LINKS FOR DEFINING TECHNICAL TERMS
  17. COURSE SUBTEXT AND OPTIONAL BACKGROUND MATERIAL

 


 

I.      Overview, What is Cybercrime?

 

Cybercrime [FN1] (cf. computer crime, electronic crime, information crime, virtual crime) is a term used broadly to describe criminal activity in which computers or computer networks are a tool, a target, or a place of criminal activity. These categories are not exclusive and many activities can be characterized as falling in one or more categories.

Additionally, although the term cybercrime is more properly restricted to describing criminal activity in which the computer or network is a necessary part of the crime, the term is also sometimes used to include traditional crimes in which computers or networks are used to facilitate the illicit activity, or where a computer or network contains stored evidence of a traditional crime.

Examples of cybercrime in which the computer or network is a tool of the criminal activity include "spamming" and certain intellectual property and criminal copyright crimes ("IP piracy"), particularly those facilitated through peer-to-peer networks.

Examples of cybercrime in which the computer or network is a target of criminal activity include unauthorized access (sometimes referred to as "computer trespass," "hacking," or "cracking"), malicious code ("malware"), and denial-of-service ("DoS", see Caroline McCarthy, "Florida man charged in botnet attack on Akamai," N.Y. Times, Oct. 24, 2006) attacks. Attacks on critical infrastructure (cf., CIP), including telecommunications networks and industrial control systems (SCADA), may result in significant real-world damage, implicating cyberterrorism and national security issues. (See GISP Program on Telecommunications and Cybersecurity Policy).

Examples of cybercrime in which the computer or network is a place of criminal activity include theft of service, in particular, telecom fraud (e.g., "phreaking") and certain financial frauds involving electronic transfers (e.g., "salami slicing"). An emerging area is "virtual crime," particularly in online gaming or immersive social network sites where avatars and virtual goods are subject to attack or theft.

Finally, examples of traditional crimes facilitated through the use of computers or networks include Nigerian 419 or other gullibility frauds (e.g., "phishing"), identity theft, child pornography, online gambling, securities fraud, etc. Cyberstalking is an example of a traditional crime -- harassment or stalking -- that has taken a new form when facilitated through computer networks. For an example of the use of computers to facilitate shoplifting, see "As Shoplifters Use High-Tech Scams, Retail Losses Rise," Wall St. J. (Oct. 25, 2006).

Additionally, certain other information crimes, including trade secret theft and economic espionage, are sometimes considered cybercrimes when computers or networks are involved.

Cybercrime in the context of national security may involve hacktivism (online activity intended to influence policy), traditional espionage, or information warfare and related activities. (See GISP Program on Information and Warfare, Information Operations (IO), Information Assurance, and Operational Resilience).

Another way to define cybercrime is simply as criminal activity involving the information technology infrastructure, including illegal access (unauthorized access), illegal interception (by technical means of non-public transmissions of computer data to, from or within a computer system), data interference (unauthorized damaging, deletion, deterioration, alteration or suppression of computer data), systems interference (interfering with the functioning of a computer system by inputting, transmitting, damaging, deleting, deteriorating, altering or suppressing computer data), misuse of devices, forgery (ID theft), and electronic fraud.

Unique Characteristics of Cybercrime.

The global reach of the Internet, the low marginal cost of online activity, and the relative anonymity of users have changed the balance of forces that have previously served to keep in check certain undesirable behaviors in the physical world. These characteristics of "cyberspace" have lowered the cost of perpetrating undesirable behavior by eliminating certain barriers to entry, lowering transaction costs, and reducing the probability of getting caught.

Together, these characteristics make traditional law enforcement strategies, particularly strategies based on identifying and apprehending perpetrators after they commit online crime, both less effective and more expensive.

At the same time, however, other characteristics of cyberspace provide new opportunities to control illegal acts. Unlike in the physical world, in cyberspace certain readily identifiable third parties – Internet service providers, telecommunication providers, and victims themselves – have exclusive or shared technical control over the infrastructure through which most illegal online behavior is carried out. These characteristics provide new opportunities for innovative policy approaches to controlling undesirable behavior, including the use of technical architecture as a regulatory mechanism, the use of novel authorization and surveillance regimes to prevent or deter undesirable activity, and the use of data and activity logging to enhance persistence and recoverability of evidence, among others.

These responses in turn raise new philosophical, social, and Constitutional concerns (or challenge accepted constructs) regarding the relationship between individual and the state, including issues relating to civil liberties, privacy, freedom, and collective security. (See Digital Law Enforcement). (See also, Subtext infra).

Cyber-attacks and attackers.

Cyber-attacks can be malicious or accidental; can involve attacks by other nation states, organized groups, or individuals; and can be motivated by monetary gain, ill-will, political interests, or curiousity. Cyber-attacks can be directed at governments, firms, or individuals. Cyber-attacks can involve the theft or destruction of information; the theft of services or financial assets; or the destruction of hardware or software infrastructure. Cyber-attacks can result in financial loss, business or service interruption, or infrastructure destruction. Cyber-attacks can be aimed directly at disrupting business or government services or can be launched in conjunction with physical attacks in order to magnify effects or prevent effective response. Cyber-attacks for monetary gain or ill-will are generally considered cybercrime; attacks for political interests can be considered hacktivism (if in the nature of political protest) or cyberterrorism (if intended to disrupt or destroy infrastructure or control mechanisms). Cyber-attacks by (or in some cases against) nation states are generally considered a form of information warfare.

Developing effective law enforcement or national security policies, laws, and practices to deal with emerging cyber threats while still protecting traditional civil liberties values as well as technology innovation opportunities is a national priority. (See GISP Program on Law Enforcement and National Security in the Information Age "PLENSIA").

Cybercrime Law.

Another way to think about cybercrime is to distinguish the applicable substantive law, procedural law, and jurisdictional law, and to distinguish between reactive, preemptive, and preventative strategies.

There are two kinds of substantive cybercrime law: computer misuse (covered in parts II and III below) and traditional crime (covered in part IV). Computer misuse crimes generally involve either exceeding the user's privileges (hacking) or denying others their privileges (malware, DoS, etc.). Traditional crimes are those like fraud, threats, pornography, etc. that have a physical world analog but are facilitated through the use of a computer (parts IV and XII).

Procedural cybercrime law also has two distinct aspects (part VII): search and seizure law under the Fourth Amendment, and statutory privacy law. In general, the former -- Fourth Amendment jurisprudence -- governs the retrieval of evidence from individual computers while the latter -- statutory privacy laws -- governs the surveillance of networks or third party computers.

Jurisdictional law is complicated in computer crime because activity can take place in multiple jurisdictions complicating both prosecution and investigation/evidence gathering (part V). Further, the global nature of the information infrastructure blurs the previously clear demarcation between reactive law enforcement policies and preemptive national security strategies (and their respective legal regimes) (parts VII and XIII).

Additionally, because victims themselves, or third parties (like ISPs), control much of the infrastructure in or through which cybercrime takes place, preventative strategies are sometimes in tension with traditional law enforcement approaches (part 6).

Cybercrime can also take on a political dimension, for example, when it is used as a form of warfare between nation states (or against sub-state enemies) or when it is used by individuals or groups as a form of political activism (hacktivism) (part VIII).

 

REQUIRED READING:

Michael Edmund O'Neill, Old Crimes in New Bottles: Sanctioning Cybercrime, 9 Geo. Mason L. Rev 237-288 (2000).

Course Introduction and Part I, Overview, What is Cybercrime? at cybercrime.taipale.info, including sections on:

Also, PLENSIA Program Overview, Program on Law Enforcement and National Security in the Information Age, World Policy Institute (2004).

 

OPTIONAL READING RE REGULATORY MECHANISMS:

Lawrence Lessig, CODE AND OTHER LAWS OF CYBERSPACE, Chapter 7, pp. 85-99 (Basic Books 1999) (ISBN:0465039138) (discussing law, social norms, the market, and architecture as things that regulate).

Neal Kumar Katyal, Architecture as Crime Control, 111 Yale L.J. 1039, 1047 (2002).

Neal Kumar Katyal, Digital Architecture as Crime Control, 112 Yale L.J. 2261  (2003).

K. A. Taipale, Internet and Computer Crime: System Architecture as Crime Control, Center for Advanced Studies (Feb. 2003). Available at SSRN: http://ssrn.com/abstract=706161.

Orin Kerr, Virtual Crime, Virtual Deterrence: A Skeptical View of Self-Help, Architecture, and Civil Liability, 1 J.L. Econ. & Pol'y 197 (Winter 2005).

Susan W. Brenner and Leo L. Clark, Distributed Security: A New Model of Law Enforcement, J. Marshall J. Computer & Info. L. (2005). Available at SSRN: http://ssrn.com/abstract=845085.

 

OTHER BACKGROUND TEXTS:

Ralph D. Clifford, CYBERCRIME: THE INVESTIGATION, PROSECUTION AND DEFENSE OF A COMPUTER-RELATED CRIME (Second Edition 2006) (ISBN:0890897239).

Samuel C. McQuade, III, UNDERSTANDING AND MANAGING CYBERCRIME (2006) (ISBN:020543973X).

Peter Stephenson, INVESTIGATING COMPUTER RELATED CRIME (2000) (ISBN:0849322189).

Joel McNamara, SECRETS OF COMPUTER ESPIONAGE: TACTICS AND COUNTERMEASURES (2003) (ISBN:0764537105).

 

OPTIONAL BACKGROUND READING ON SOCIAL CONSTRUCTION OF LAW:

The Stanford Encyclopedia of Philosophy, entry on "Legal Positivism."

Wikipedia, entry on "Legal Positivism."

See also references in COURSE SUBTEXT, infra.

 

 


 

II.     Computer Intrusions and Attacks

 

What is "computer trespass"? Compare "unauthorized access" with "exceeding scope of authorized access." Explore the relationship between acceptable use policies ("AUP"), terms of service ("TOS"), and criminal law. What are the limits of a "computer crime"? Understanding self-help strategies, honeypots, and strike-back mechanisms. When does use of a publicly-accessible system amount to an intrusion or attack? Denying service by overwhelming system resources ("DoS" and "DDoS")?

 

REQUIRED READING:

CASEBOOK: David J. Loundy, COMPUTER CRIME, INFORMATION WARFARE, AND ECONOMIC ESPIONAGE, Carolina Academic Press (2003) (ISBN:0890891109):

Chapter 2, Computer Intrusions and Attack, pp. 9-53 (CA v. Lawton ["hradware" v. "software"]; WA v. Olson [authorization not conditioned on AUP]; NM v. Rowell [is use of phone system to commit fraud a computer crime?]; NY v. Versaggi "alter program" v. "alter function"]; NY v. Angeles [locks]; Ebay v. Bidder's Edge [exceed conditional access]).

US Department of Justice, CCIPS, Federal Computer Intrusion Laws.

 

STATUTES:

18 U.S.C. § 1029. Fraud and related activity in connection with access devices.

COMPUTER FRAUD AND ABUSE ACT
18 U.S.C. § 1030. Fraud and related activity in connection with computers.

CAN-SPAM ACT
18 U.S.C. § 1037. Fraud and related activity in connection with electronic mail.

 

ADDITIONAL READING:

Hacking:

"Romanian man indicted for hacking into U.S. government computers," Associaated Press (Dec. 1, 2006) ("A Romanian man has been indicted on charges of hacking into more than 150 U.S. government computers, causing disruptions that cost NASA, the Energy Department and the Navy nearly $1.5 million (euro1.1 million). ... The U.S. government alleged Faur was the leader of a hacking group called ''WhiteHat Team,'' whose main goal was to break into U.S. government computers because they are some of the securest machines in the world. ... After the hacking, scientists and engineers had to manually communicate with spacecraft and the computer systems had to be rebuilt.")

URL hacking:

Philip Greenspun's Weblog: "Business schools redefine hacking to "stuff that a 7-year-old could do" (Mar. 8, 2005).

Lisa Trei, "Business school hopefuls who tried to gain access to application files rejected," Stanford Report (Apr. 13, 2005).

Michele Dellio, "Rooting Around Site With Intent?" WIRED News (Oct. 30, 2002).

Here is how the Reuters/Intentia "hack" was done. [LINK]

Declan McCullagh, "Rival behind Schwarzenegger Web flap," CNET News.com (Sep. 12, 2006).

WiFi Mooching:

"Man Arrested for Hopping on to Home Wi-Fi Network," Networked World (Jul. 8, 2005).

Declan McCullagh, "FAQ: Wi-Fi Mooching and the Law," CNET News.com (Jul. 8, 2005).

Peter Griffiths, "Two cautioned over wireless "piggy-backing," Reuters (Apr. 18, 2007) ("Two people have been arrested and cautioned for using someone else's wireless Internet connection without permission, known as "piggy-backing", British police said on Wednesday.")

Other:

"Employers Empowered By Computer Crime Law Against Departing And Disloyal Employees," FindLaw (Apr. 11, 2006). (malicious deletion as violation of CFAA).

Cybercrime effects:

FBI survey finds 90% of Organizations Face Computer Attack; 64% Incur Financial Loss: Press Release, "New FBI Computer Crime Survey," Federal Bureau of Investigation (Jan. 18, 2006).

Randy Barrett, "Cyber crime is growing more professional, officials say," National Journal's Technology Daily (Jan. 24, 2006) ("Leading industry and government officials Tuesday agreed that cyber criminals are now more professional and primarily focused on stealing money. ... Hackers are working for financial profit and gain -- not fame").

Tom Espiner, "Cybercrime costs us dearly," Cnet News (Mar. 17, 2006). ("Fifty-seven percent of the 600 U.S. businesses surveyed said they are losing more money through cybercrime ... than from conventional crime. ... while 84 percent believed that criminal hacker groups were increasingly replacing lone hackers as the perpetrators of cybercrime.")

Matthew Jones, "Cyber crime becoming more organized," Reuters (Sep. 15, 2006).

CSI/FBI Computer Crime Survey (2006) (download here).

DoS/DDoS:

Caroline McCarthy, "Florida man charged in botnet attack on Akamai," N.Y. Times (Oct. 24, 2006).

Tom Espiner, "U.K. outlaws denial-of-service attacks," CNET News (Nov. 10, 2006).

DOI (denial of insight)

Clint Boulton, "Denial-of-Insight Lurks For Search Engines, Users," Internet News (Nov. 10, 2006).

 [UR-Soros]

OPTIONAL READING:

Orin S. Kerr, Cybercrime's Scope: Interpreting 'Access' and 'Authorization' in Computer Misuse Statutes, 78 N.Y.U. L. Rev. 1596 (Nov. 2003).

 


 

III.     Computer Viruses, Time Bombs, Trojans, Malicious Code

 

Putting the "mal" in malware. What is "malicious" (cf. "inadvertent harm," "knock-on effects," "collateral damage")? What are "damages" from intrusions? When is "bad software" malicious (can negligence = malicious)?

 

REQUIRED READING:

CASEBOOK: David J. Loundy, COMPUTER CRIME, INFORMATION WARFARE, AND ECONOMIC ESPIONAGE, Carolina Academic Press (2003) (ISBN:0890891109):

Chapter 3, Computer Viruses, Time Bombs, Trojans, and Malicious Code," pp. 55-96 (US v. Morris (intended function test); Werner v. Lewis (contract); State v. Corcoran ("delete"); North Texas Imaging ("intent not means of transmission"); Mahru v. CA (own computer and "criminal" cannot turn on breach of contract (?)) ; Shaw v. Toshiba (distribution of bad software).

 

ADDITIONAL CASES:

Shurgard Storage Centers v. Safeguard Self Storage, 119 F. Supp. 1121 (WD Wash. 2000) ("agency theory")

Fugarino v. State of Georgia, 531 S.E.2d 187 (Ga. Ct. App. 2000) ("spite"/motive)

Briggs v. State of Maryland, 704 A.2d 904 (Md. 1998) (malicious password protecting; sys admin is auth; conduct over motive).

EF Cultural Travel v. Explorica, 274 F.3d 577 (1Cir. 2001) (wholesale, "reeks of abuse"; confidentiality agreement)

AOL v. LCGM, 46 F. Supp. 2d 444 (ED Va. 1998) (TOS)

Register.com v. Vario, 126 F. Supp. 2d 238 (SDNY 2000) (because P objects, D's use of robots was without authorization!)

 

STATUTES:

18 U.S.C. § 1029. Fraud and related activity in connection with access devices.

COMPUTER FRAUD AND ABUSE ACT
18 U.S.C. § 1030. Fraud and related activity in connection with computers.

CAN-SPAM ACT
18 U.S.C. § 1037. Fraud and related activity in connection with electronic mail.

18 U.S.C. § 875. EXTORTION and THREATS. Interstate communications.

 

ADDITIONAL CASES:

NEWBERGER v. Florida, 641 So.2d 419 (1994) (what is "modifying").

US v. SABLAN, 92 F.3d 865 (1995) (relationship of "mens rea" to "damages," and how are damages calculated).

US v. MIDDLETON, 231 F.3d 1207 (2000) (Factual Background, pp. 1208-09, Part B. Damages, p. 1213, and Part C. Sufficiency of Evidence, pp. 1213-14).

 

ADDITIONAL READING:

Jon Swartz, "2005 Worst Year for Breaches of Computer Security," USA Today (Dec. 28, 2005).

Brian Krebs, "Cyber Crime Hits the Big Time in 2006: Experts Say 2007 Will Be Even More Treacherous," Washington Post (Dec. 22, 2006).

Press Release, "Man Pleads Guilty to Infecting Thousands of Computers Using Worm Program then Launching them in Denial of Service Attacks," U.S. Dept. of Justice (Dec. 28, 2005).

"FBI Gets Tough on Cyber-Crime," RED HERRING: The Business of Technology (Sep. 26, 2005).

US DOJ Press Release, "Utah Man Sentenced to 24 Months in Prison for Bringing Down Wireless Internet Services" (Dec. 14, 2006) ("A man skilled in the operation of commercial wireless Internet networks was sentenced today for intentionally bringing down wireless Internet services").

"Professionalization":

Jeremy Kirk, "8,500 victims in international data theft," Computerworld (Oct. 24, 2006)

Elise Ackerman, "Hackers' infections slither onto Web sites: ONLINE SECURITY EXPERTS ISSUE WARNINGS ABOUT ORGANIZED INTERNET CRIME EFFORTS," Mercury News/SilliconValley.com (Jan. 3, 2007) ("Computer security experts said 2006 was also the year that hacking stopped being a hobby and became a lucrative profession practiced by an underground of computer developers and software sellers").

Extortion/Ransomware:

"Hackers Attack UK Student's Web Site," Associated Press (Jan. 18, 2006).

Jon Schwartz, "Cybercrooks hold PC data captive," USA Today (Dec. 18, 2006) ("In the latest online scam ["ransomware"], cybercrooks are breaking into the PCs of small businesses and individuals, locking up data and demanding money in return for freeing it").

Linda Deutsch, NY youths in plea deal in MySpace case, Associated Press/USA Today (Feb. 27, 2007) ("Two New York men accused of trying to extort $150,000 from MySpace.com by developing code that tracked visitors pleaded no contest Monday to illegal computer access in a bargain with the prosecution. Two counts of attempted extortion and another illegal computer access count were dropped in the deal, which gave the defendants three years probation. Each had faced up to nearly four years in prison.")

Vectors:

Tom Espiner, "Wikipedia used to spread malicious code," CNET News (Nov. 6, 2006)

Robert McMillan, "Google accidentally sends out Kama Sutra worm," InfoWorld (Nov. 8, 2006).

Robert McMillan, "Storm Trojan floods e-mail boxes," InfoWorld (Jan. 19, 2007) ("Malicious Trojan horse software claiming to provide information on topics like the deadly storms that have battered Europe this week has infected thousands of computers over the past 24 hours. ... These e-mails appear to have been particularly effective because they offer information on a topic that is of intense public interest in Europe right now.")

"Cyber criminals move focus to web: Cyber criminals will increasingly turn their attention to the web and away from e-mail security in 2007" BBC News (Jan. , 2007) ("The internet now represents the easiest way for cyber criminals to gain entry to corporate networks, as more users are accessing unregulated sites, downloading applications and streaming audio/video. ... They are also subtly changing tactics - instead of sending so-called spyware-infected e-mails, they are sending e-mails linking to websites which contain a malicious downloader [Trojan].")

General:

Evan Ratliff, "The Zombie Hunters," The New Yorker (Oct. 10, 2005). 

Matt Hines, "Rootkits, Smarter Hackers Pose Growing Security Threats," eWeek.com (Apr. 17, 2006).

William Jackson, "Eugene Kaspersky | When Criminals Stalk the Internet," Government Computer News (GCN.com) (Apr. 17, 2006).

Brad Stone, A Lively Market, Legal and Not, for Software Bugs, NY Times (Jan. 30, 2007) ("software vulnerabilities — as with stolen credit-card numbers and spammable e-mail addresses — carry real financial value. They are commonly bought, sold and traded online, both by legitimate security companies, which say they are providing a service, and by nefarious hackers and thieves.")

Spam:

"Man Convicted Under Antispam Law," Bloomberg News (Jan. 16, 2007) ("A ... man who defrauded users of AOL by sending e-mail messages requesting credit data became the first defendant found guilty by a jury under [the Can-Spam Act] a 2003 federal law barring Internet ”spam.” ... The statute prohibits sending unsolicited e-mail messages with falsified header, or return address, information. ... [He] operated a so-called phishing scheme that duped AOL subscribers into providing personal and credit information in the belief they were dealing with the company’s billing department. He used the credit card information to make unauthorized purchases.")

Gregg Kelzer, " Spam Volume Jumps 35% In November," Information Week (Dec. 21, 2006) (" The volume of spam surged in November to an average of 85 billion messages a day during two periods ... and the month saw spam tactics that reduced the efficiency of traditional anti-spam filters")

Botnets:

Ryan Naraine, "'Pump-and-Dump' Spam Surge Linked to Russian Bot Herders," eWEEK.com (Nov. 16, 2006) ("The recent surge in e-mail spam hawking penny stocks and penis enlargement pills is the handiwork of Russian hackers running a botnet powered by tens of thousands of hijacked computers. ... the gang functions with a level of sophistication rarely seen in the hacking underworld.")

John Markoff, "Attack of the Zombie Computers Is a Growing Threat, Experts Say," NY Times (Jan. , 2007) ("These systems, called botnets, are being blamed for the huge spike in spam that bedeviled the Internet in recent months, as well as fraud and data theft.")

Joris Evers, Dutch botnet hackers sentenced to time served, CNET News (Jan. 31, 2007) ("... for commandeering millions of computers last year with a Trojan ... used the hijacked systems in a network, popularly called a botnet, to steal credit card numbers and other personal data, and to blackmail online businesses by threatening to take down their Web sites.")

Logic Bomb:

"Prosecutors: New Jersey worker put data-wrecking 'bomb' in computers of drug company," AP (Dec. 19, 2006) ("A computer administrator angry about possibly losing his job planted an electronic ''[logic] bomb'' in the systems of one of the nation's largest prescription drug management companies, prosecutors said Tuesday.")

Associated Press, "Man gets 8 years for computer sabotage," SiliconValley.com (Dec. 13, 2006) ("A former UBS ... systems administrator was sentenced ... to eight years ... for attempting to profit by detonating a "logic bomb" program that ... caused millions of dollars in damage to the brokerage's computer network ... . ... [he] was angry ... because he expected an annual bonus of $50,000 but got $32,500 ... [he] ultimately lost $23,000 he invested in a stock market bet against UBS because the ploy failed to reduce the company's share price. .... . [The day the logic bomb was to go off, he] went to a broker and bought ... "put options" for UBS stock, ... . ... the right to sell shares for a fixed per-share price, so the lower a stock falls the more valuable the option becomes.)

 

OPTIONAL READING

Michael Lee, et al., Electronic Commerce, Hackers, and the Search for Legitimacy: A Regulatory Proposal, 14 Berkeley Tech. L. J. 839 (1999).

Note, "Immunizing the Internet, or: How I Learned To Stop Worrying and Love the Worm," 119 Harvard L. Rev. (Jun. 2006).

 


 

IV.     Online Fraud and Identity Theft; Intellectual Property Theft

 

Distinguish fraud from computer fraud.

Explore how existing practices in identity management lead to identity theft and other frauds. The relationship between identification, identification systems, and security. The "trusted system" paradigm.

Drawing the line between "sharing" and "piracy" in intellectual property crime

 

REQUIRED READING:

CASEBOOK: David J. Loundy, COMPUTER CRIME, INFORMATION WARFARE, AND ECONOMIC ESPIONAGE, Carolina Academic Press (2003) (ISBN:0890891109):

Chapter 7, Online Fraud, pp. 231-282 (NY v. Lipsitz; PA v. Murgallis; MI v. Jemison; Virgin Atlantic consent order; US v. Mullins; CA v. Gentry; SEC v. Cherif), and

Chapter 9, Identity Theft, pp. 335-344 (KS v. Vargas; WI v. Ramirez).

United States v. LaMacchia, 871 F.Supp. 535 (D. Ma. 1994) (distribution for free of pirated software neither "wire fraud" nor "criminal copyright infringement").

 

STATUTES:

IDENTITY THEFT AND ASSUMPTION DETERRENCE ACT of 1998
18 U.S.C. § 1028. Fraud and related activity in connection with identification documents, authentication features, and information.

18 U.S.C. § 1343. Fraud by wire, radio, or television.

NO ELECTRONIC THEFT ("NET") ACT
17 U.S.C. § 506. Criminal Offenses.

DIGITAL MILLENIUM COPYRIGHT ACT ("DMCA")
17 U.S.C. § 1201. Circumvention of copyright protection systems.

 

ADDITIONAL CASES:

Universal City Studios v. Corley, 273 F.3d 429 (2nd. Cir. 2001).

 

GOVERNMENT RESOURCES:

U.S. Department of State, International Financial Scams – Internet Dating, Inheritance, Work Permits, Overpayment, and Money- Laundering (PDF; 655 KB) ("provides full detailed descriptions of the often sophisticated scams reported to U.S. Embassies and Consulates abroad, and includes samples of email messages and offers that have been sent to potential victims. As illustrated by the brochure, the perpetrators often prey on potential victims’ goodwill by fabricating increasingly complicated but believable scenarios.”)

 

ADDITIONAL READING:

Bureau of Justice Statistics, "Identity Theft 2004," U.S. Dept. of Justice (04/06 NCJ 212213) (latest survey statistics from US DOJ).

The Internet Crime Complaint Center, 2005 Internet Fraud Crime Report: January 1, 2005 -- December 31, 2005, National White Collar Crime Center and the Federal Bureau of Investigation (FBI) (IC3 2005 Annual Report PDF).

Press Release, "Six Defendants Plead Guilty in Internet Identity Theft and Credit Card Fraud Conspiracy," U.S. Dept. of Justice, (Nov. 17, 2006).

Press Release, "U.S. Secret Service Operation Firewall Nets 28 Arrests," U.S. Dept. of Homeland Security (Oct. 28, 2004).

Press Release, "President Bush Signs Identity Theft Penalty Enhancement Act," The White House (Jul. 15, 2004).

Alorie Gilbert, "ID theft tops list of fraud complaints,"  CNET News (Jan. 25, 2006)  (Identity theft continues to plague consumers, topping the list of fraud complaints reported to the Federal Trade Commission (FTC) last year.)

Eric Dash, "Ameriprise Says Stolen Laptop Had Data on 230,000 People," N.Y. Times (Jan. 26, 2006).

Arshad Mohammed, "Record Fine for Data Breach ChoicePoint Case Spotlighted ID Theft," Wash. Post (Jan. 27, 2006).

Katie Hafner, "Seeing Fakes, Angry Traders Confront EBay," N.Y. Times (Jan. 29, 2006).

Associated Press, "Fighting Web Credit-Card Fraud," MIT Tech. Rev. (Apr. 17, 2006) (illustrating the need for non-repudiation in online transactions).

Anita Ramasastry, "Debit Card Debacles: Why Consumers Need to Worry About the Recent, Massive Wave of Debit Card Fraud, And What Legal and Technological Protections Can Prevent Future Harm," FindLaw (Mar. 29, 2006).

Anita Ramasastry, "Risky Business? How Multinationals' Outsourcing Involving Customer Data Can Lead to Identity Theft and Other Fraud," FindLaw (Jul. 10, 2006).

Munir Kotadia, "Fighting fraud by baiting phishers," CNET News (Mar. 31, 2006) (using info ops -- "dilution" -- against phishers.)

Tom Zeller, Jr. "A Sinister Web Entraps Victims of Cyberstalkers," N..Y. Times (Apr. 17, 2006) (cyberstalking and "identity theft for revenge").

"Consumers Lose $8 Billion to Online Fraud," consumeraffairs.com (Aug. 8, 2006)

Byron Acohido and Jon Swartz, Cybercrime flourishes in online hacker forums, USA Today (Oct. 11, 2006).

"Online brokerage account scams worry SEC," CNET News (Reuters) (Oct. 13, 2006).

Floyd Norris, "S.E.C. Says Russian Trader Used Stolen Online Passwords," N.Y. Times (Dec. 20, 2006) ("A Russian trader ... found a simpler way to pump and dump stocks. The ... the trader ... used the Internet to steal passwords of account holders at online brokerage firms. ... [He] would buy, through his own account, shares in a thinly traded company. Immediately after that, he would use the accounts of victims to buy large quantities of the stock, driving up the price. He would then sell his shares into that demand.)

Will Knight, "One in 10 snared by fake 'phishing' messages," New Scientist News Service (Oct. 20, 2006) ("One in 10 internet users may be lured into handing over sensitive personal information such as a credit card number, by fraudulent "phishing" emails, research suggests").

Ellen Nakashima, "Hackers Zero in on Online Stock Accounts," Wash. Post A:01 (Oct. 24, 2006). ("'Although these schemes cleverly combine aspects of securities fraud, identity theft and hacking, what they really boil down to is outright thievery,' said John Reed Stark, chief of the Internet enforcement office at the Securities and Exchange Commission.")

Tom Zeller, Jr., "3 Americans Arrested by F.B.I. in Identity Thefts," N.Y. Times (November 3, 2006) ("The proliferation and sale of stolen consumer data on the international black market, particularly through online forums, has been a nagging problem for law enforcement, given the restrictions in national legal systems.")

Brian Krebs, "FBI Tightens Net Around Identity Theft Operations," Wash. Post (Nov. 3, 2006) ("The FBI is cracking down on an international identity theft operation that involves the trading of social security numbers; the sale of stolen credit card account information ["carding"]; and phishing, the practice of using e-mail to trick consumers into handing over personal information").

Jenn Abelson,"TJX breach snares over 200,000 cards in region," Boston Globe (Jan. 25, 2007).

Ellen Nakashima, "Hack, Pump, and Dump", Washington Post (Jan. 26, 2007) ("... a wave of techno-criminals who meld computer hacking with identity theft to create nightmares for legitimate investors ... hacked into four online trading accounts of unsuspecting investors, selling off their holdings in higher-valued companies to purchase shares [in penny stocks in which they owned shares, when the stock prices went up they dumped their shares] ... The SEC is not saying how [the] ring obtained the user names and passwords on the investors' accounts. Typically, authorities said, hackers use keystroke monitoring software placed on a public computer, or they purchase personal data, such as stolen Social Security and credit card numbers, from criminal enterprises.")

"Online banking fraud 'up 8,000%'" BBC News (Dec. 13, 2006) ("the UK has seen an 8,000% increase in fake internet banking scams in the past two years).

Dawn Kawamoto, "FBI warns of twist in extortion phishing scam," CNET News (Jan. 12, 2007) ("FBI officials are warning users of a new phishing scam that plays off a recent round of bogus extortion threats.")

Enid Burns, Consumers Open One in Six Phishing Messages, ClickZ Stats (Feb. 5, 2007) ("As many as 59 million phishing e-mail messages are sent each day, and up to 10 million of those may be opened by consumers. A study released by Iconix finds one in four phishing messages are opened. Divided into eight categories, spoofed or phished messages had open rates ranging from 1 in 4 to 1 in 10. Fake social-network-related messages maintained 24.9 percent open rates. Other categories, including as e-cards (17.1 percent); payment (16.2 percent); financial (15.5 percent); auction (14.7 percent); information (12.9 percent); retail (12.1 percent); and dating (9.5 percent), had lower open rates.")

 

Intellectual Property Crime:

US DOJ, Computer Crime & Intellectual Property Section, "Prosecuting Intellectual Property Crimes" (Third Edition Sep. 2006).

Mark Hachman, "Update: At Least 25 Million Americans Pirate Movies," ExtremeTech.com (Jan. 25, 2007) ("Roughly 25 million Americans -- or 18 percent of the U.S. online population -- have illegally downloaded a full-length movie, a study released Wednesday asserts.") (Is this study credible?).

 

OPTIONAL READING:

Lynn M. Lopucki, Did Privacy Cause Identity Theft? 54 Hastings L. J. 1277 (2003).

F. Gregory Lastowka and Dan Hunter, Virtual Crimes, 49 N.Y.L. Sch. L. Rev. 293 (2004/2005).

K. A. Taipale, Presentation: Science and Technology: Identity Theft: Policy Implications at The Heritage Foundation, Washington, DC, Nov. 2, 2005. [presentation slides] (arguing that privacy and existing business models enable identity theft).

K. A. Taipale, Presentation: Technical and Policy Challenges: Implications for Evolving Business Models at the 16th Annual Economic Crimes Institute Conference, Tysons Corner, VA, Oct. 24, 2005. [presentation slides] (suggesting use of identity registrars to mitigate identity theft).

K. A. Taipale, Technology, Security and Privacy: The Fear of Frankenstein, the Mythology of Privacy, and the Lessons of King Ludd, 7 Yale J. L. & Tech. 123, 154-162; 9 Intl. J. Comm. L. & Pol'y 8 (Dec. 2004) (excerpt pp. 154-162, download article for footnotes):

A. TECHNOLOGIES OF IDENTIFICATION

Identification technologies or systems serve to authenticate data attribution – that is, they provide confidence that a particular piece of data (an attribute) or collection of data (an identity) correlates with a specified entity (an individual or other object).147

Authentication generally serves as the first step in one or both of two kinds of security applications or strategies – authorization and/or accountability.148 Authorization (or permission) is the process of deciding what an identified individual is permitted (or not permitted) to do within a system (including whether they are allowed access in the first place). For example, an individual may be authorized to enter a secure zone, may be denied access to board a plane, or may be given access to a computer system but constrained from accessing certain services or information. Accountability, on the other hand, is the process of associating a consequence to the individual for any actions that they may take within the system, for example, by recording identifying information prior to entry into a system, or by monitoring, recording or logging activity within the system, to allow for subsequent tracking or sanction. Both authorization and accountability serve to ensure that rules governing behavior within a system are obeyed.149

From a political point of view, authorization based on access control strategies are generally associated with totalitarian systems (i.e., the default state of these systems is that all users are suspect, the chosen receive permission) and accountability strategies are associated with freedom (i.e., the default state is that all users are presumed innocent, only those who have already done something wrong are sanctioned).150 Unfortunately, accountability strategies are not very effective against suicidal attackers or situations with catastrophic outcomes, and, thus, give rise to the difficult policy choices facing a free society in taking a preemptive, rather than traditional reactive law enforcement, approach to terrorism.

In any identification system, there are generally three forms of authentication that can occur:

• Entity authentication is the process of establishing confidence that an identifier, for example, a name, number or symbol, refers to a specific entity (an individual, place or thing),151

• Identity authentication is the process of establishing confidence that an identifier refers to an identity (a collection of data related to an entity),152 and

• Attribute authentication is the process of establishing confidence that an attribute (a property associated with an entity, for example, a physical descriptor or a role, etc.) applies to a specific entity.153

Individuals (or other entities) may have multiple identifiers, even within the same systems, for example, name, social security number, driver’s license number, etc. and may have one or more aliases for each identifier.154 Note that the greater the uniqueness of any particular identifier, the greater the confidence that it applies to a particular individual or entity.155

In addition, individuals or entities may also have multiple identities – that is, multiple discrete sets of related data defining, for example, a particular role. Any particular individual might have identities relating to different roles, for example, as a family member, as a work professional, or as a community participant, each of which may or may not share attributes or identifiers.

Entity resolution is the technical process whereby different identifiers or different identities are resolved (attributed) to the same entity or individual usually through analysis of shared attributes. Technical methods for entity resolution of individuals – that is, confirming that multiple discrete sets of related data (i.e., different “identities”) actually belong to the same individual – have achieved high success rates and for some applications are a “solved problem.”156 However, entity resolution of places (or objects) has not been satisfactorily automated as yet.157 Some form of entity resolution (or other data normalization) is generally required for automated analysis, particularly in systems based on anonymization and pseudonymization described below.158

Identity verification can be achieved through tokens (something you have), passwords (something you know), or a data match (something you are).159 The highest level of confidence combines all three, for example, a token (ID card), requiring a password (PIN), and that contains a data match (for example, a biometric identifier).160

Confidence in identification depends not only on the technologies of identification but on the integrity of the process of enrollment (the issuing and maintaining of tokens, passwords and the data to be matched), as well as the process of verification (confirming or verifying identity).161 Even technologies of identification with very low error rates for matching (for example, certain biometrics) can be compromised if the enrolment process is corrupted or if the measurement process is fooled.162

Identification technologies can also be classified as participatory, where the person to be identified either cooperates or engages with the system knowingly, or passive, where the individual is not required to actively participate in the identification process. Examples of the former are the use of ID cards, fingerprint or iris scanners, and passwords, examples of the latter are face and gait recognition (and other so-called recognition-at-a-distance technologies), DNA sniffers, and the like. Passive identification can be either overt or surreptitious.163 Each of these characteristics has obvious security and privacy implications.164

Authentication (that is, identification) in a security system is only the first step and does not provide security against a particular threat on its own. After identity is authenticated it must be used for some security purpose – either by authorizing the individual to do or not do something,165 or by logging or tracking identifying data in some fashion to provide for later accountability. Thus, any identification system is only as good as the watch list or other criteria against which the authenticated identity is compared for authorization166 or the deterrent effectiveness of the sanction for accountability.167

1. IDENTIFICATION SYSTEMS AND SECURITY

Identification based security is always somewhat vulnerable because of what is known as the trusted systems problem.168 With few exceptions, “secure” systems need to be penetrated – under authorized circumstances by trusted people.169 Unfortunately, there is inherently no way to prove trust, the best that any identification system can do is confirm not-yet-proven-untrustworthy status, i.e. confirm that a particular individual is not on a watch list for example.170

This essentially creates three classes of users of any system based only on identification, those confirmed as untrustworthy and denied access (and there may be false positives), those deemed not-untrustworthy who are in-fact trustworthy and are allowed access (good guys), and those deemed not-untrustworthy who are in-fact untrustworthy but have not yet been identified as such and may be mistakenly allowed access (false negatives).

Therefore, any system of identification needs to be part of a larger security system that recognizes, and compensates for, this problem. So, for example, a system for screening passengers (like CAPPS II or its successor, “Secure Flight”)171 should be combined with random searching of non-flagged passengers to provide layered security.172

Another general problem in security systems is balancing security with usability or functionality.173 Authentication imposes friction or overhead on a system and can interfere with its usefulness. In the context of the ‘war on terrorism’ security systems based on authentication that impose too high a cost on functionality risk undermining the very system for which protection is sought.174 Thus, for example, too high a burden in terms of physical intrusion or time spent in airport security screening lines can undermine the air transportation system. Inefficient port security can fail in two ways – terrorists can gain entrance or legitimate commerce can be impeded to the point that it interferes with trade. Denying access to immigrants or visa-applicants deprives the economy of needed talent. This issue is beyond the scope of this article except, however, as it relates to privacy concerns. To the extent that any security system imposes privacy costs on users out of proportion to the perceived threat, it risks undermining the confidence and support that is required from existing users for systems to function or for systems to attract new users – i.e., the capital and talent it needs for proper functioning or further development.

2. PRIVACY CONCERNS

Identification systems can either enhance or intrude upon privacy depending on their use and context.175 Identification systems can enhance privacy when they are used to secure data or to protect identity, for example, by ensuring that an individual is indeed the authorized user of a credit card or a particular computer network, or is permitted access to certain information. Identification systems can also provide convenience, for example, by allowing personalized services to be delivered.176

On the other hand, identification systems can be intrusive of privacy and their use can be self-proliferating. Proliferation occurs when the prevalence of a security paradigm premised on fully mediated access becomes the norm.177 For example, once ID checks are common for boarding airplanes or entering government buildings, they become acceptable (or required) for lesser uses – for example, prior to boarding trains or buses, or entering stores, etc.

Additionally, identification systems themselves tend to increase the collection of personal data, for example, by creating additional transaction records at the time and place of authentication, and may also expose personal information to additional disclosure at multiple points during the operation of the system or subsequently.178 Availability of these transaction records may also allow for linkages and profiling, and the ability to create digital dossiers, not otherwise possible.179

Also, as noted above, the use of identification or authentication systems in conjunction with access control strategies may challenge traditional notions of freedom. In particular, access control strategies may impact on individual autonomy, including freedom of speech (denying access to information or communication systems),180 freedom to travel or peaceably assemble (by denying access to particular modes of transport),181 and freedom to petition the government (by denying access to government buildings or other resources).

Certain privacy impacts cannot be eliminated as they are inherent in the act of authentication, which requires the revelation and confirmation of some ‘identifying’ information to function, however, identification and authentication systems can be designed to minimize these privacy impacts and maximize security gains.182 Further, identification should not be required where it does not provide a security gain. Thus, for example, a distinction should be drawn between systems or occasions when an identifier is required for security and situations where only authentication is required.183

In addition, even where identification or authentication strategies are appropriate, they should be designed so as to neither require more personal information than is necessary for the particular security application (and even then in proportion to the threat) nor generate additional transaction records beyond what is required for the particular security purpose.184

Pseudonymization strategies, discussed infra, based on certificated authorizations from trusted third parties, selective disclosure of identifying information, and escrowed identity, can be designed to protect identity privacy but still meet legitimate law enforcement and security needs.

 


 

V.      Online Vice: Gambling and Pornography; Child Exploitation

 

The global reach of the Internet makes direct enforcement of local "morality" laws difficult, often leading to control strategies premised on sanctioning secondary enabling activity or third parties, in particular financial intermediaries and internet service providers.

In addition, the lack of "physicality" challenges regulatory regimes based on isolating undesirable activity to certain geographically determined areas (Las Vegas/Atlantic City, red-light/porn districts) and determining tolerance by reference to local community standards.

 

GAMBLING LAW

WIRE WAGER ACT 18 U.S.C. §1084:

(a) Whoever being engaged in the business of betting or wagering knowingly uses a wire communication facility for the transmission in interstate or foreign commerce of bets or wagers or information assisting in the placing of bets or wagers on any sporting event or contest, or for the transmission of a wire communication which entitles the recipient to receive money or credit as a result of bets or wagers, or for information assisting in the placing of bets or wagers, shall be fined under this title or imprisoned not more than two years, or both.

 

UNLAWFUL INTERNET GAMBLING ENFORCEMENT ACT OF 2006

(enacted as Title VIII of the Security and Accountability For Every Port Act of 2006 or SAFE Port Act, Pub. L. 109-347): 

31 USC §5363 (§802 of the SAFE Act). Prohibition on acceptance of any financial instrument for unlawful Internet gambling.

No person engaged in the business of betting or wagering may knowingly accept, in connection with the participation of another person in unlawful Internet gambling--

(1) credit, or the proceeds of credit, extended to or on behalf of such other person (including credit extended through the use of a credit card);

(2) an electronic fund transfer, or funds transmitted by or through a money transmitting business, or the proceeds of an electronic fund transfer or money transmitting service, from or on behalf of such other person;

(3) any check, draft, or similar instrument which is drawn by or on behalf of such other person and is drawn on or payable at or through any financial institution; or

(4) the proceeds of any other form of financial transaction, as the Secretary and the Board of Governors of the Federal Reserve System may jointly prescribe by regulation, which involves a financial institution as a payor or financial intermediary on behalf of or for the benefit of such other person.

 

AIDING AND ABETTING 18 U.S.C. §2(a):

Whoever commits an offense against the United States or aids, abets, counsels, commands, induces or procures its commission, is punishable as a principal.

 

ANALYSIS/DISCUSSION OF LEGISLATION:

Unlawful Internet Gambling Funding Prohibition Act and The Internet Gambling Licensing and Regulation Commission Act (First Session On H.R. 21 And H.R. 1223), Hearing Before The Subcommittee On Crime, Terrorism, and Homeland Security of the Committee on the Judiciary, U.S. House of Representatives, 108th Congress (Apr. 29, 2003).

Nelson Rose, Professor of Law, Whittier Law School, Costa Mesa, CA “The Unlawful Internet Gambling Enforcement Act of 2006 Analyzed” (2006).

Congressional Research Service, “Internet Gambling: Two Approaches in the 109th Congress,” RS22418 (Oct. 2, 2006).

CASES:

US v. COHEN, 260 F.3d 68 (2001) (operator of an Antigua-based sports betting website convicted under Wire Wager Act, 18 U.S.C. 1084).

NEWS:

Jacob Sullum, Abetting Betting: Is Talking about Online Gambling Illegal? Reason Online (Apr. 9, 2004) ("[DOJ sent] a letter to media trade groups warning that their members could be breaking the law by accepting ads for gambling sites. ... a grand jury in St. Louis that is issuing subpoenas to companies that do business with the online gambling industry.")

AP, "Internet Gambling Execs Arrested: Founders Of Online Payment Processing Company Neteller Charged With Laundering Billions Of Dollars," CBSnews.com (Jan. 16, 2007) ("[They] were charged in connection with the creation and operation of an Internet payment services company that facilitated the transfer to billions of dollars of illegal gambling proceeds from U.S. citizens to the owners of overseas Internet gambling companies. ... the company acknowledged when it went public that U.S. law prohibits people from promoting certain forms of gambling, including Internet gambling, and transmitting funds that are known to have been derived from criminal activity ... [and] conceded in the company's offering documents that they were risking prosecution by the U.S. government.").

Andrew Sorkin, "Gambling Subpoenas On Wall St.," NY Times (Jan. 22, 2007) (" The Justice Department has issued subpoenas to at least four Wall Street investment banks as part of a widening investigation into the multibillion-dollar online gambling industry .... The subpoenas were issued to firms that had underwritten the initial public offerings of some of the most popular online gambling sites that operate abroad.").

Roy Mark, "Antigua Takes Upper Gambling Hand Over U.S.," InternetNews.com (Jan. 26, 2007) ("... Antigua has won its latest long-shot effort to force the U.S. to open its market to offshore gambling, according to a confidential report issued by the World Trade Organization (WTO).")

 

PORNOGRAPHY

 

To a large extent, the legal tension between online "pornography" legislation and Constitutional challenges in court cases turns on whether there is (or the court imagines?) a viable technical "less restrictive alternative." Note that "when plaintiffs challenge a content-based speech restriction, the Government has the burden to prove that the proposed alternatives will not be as effective as the challenged statute." Ashcroft v. ACLU, 542 U.S. 656 (2004). Query: How does one decide yesterday's cases based on presumptions about tomorrow's technology?

CASES

Ginsberg v. New York (1968) ("sale to minors"); F.C.C. v. Pacifica Foundation (1978) ("broadcast exception"); Renton v. Playtime Theaters, Inc. (1986) ("zoning").

MILLER v. CALIFORNIA, 413 U.S. 15 (1973) (Miller Test - community standards; "lacks serious literary, artistic, political, or scientific value").

NEW YORK v. FERBER, 458 U.S. 747 (1982) (child pornography can be banned even if it doesn't meet Miller test for obscene).

RENO v. ACLU, 521 U.S. 844 (1997) (see First Amendment Center resources) (Communications Decency Act of 1996 unconstitutional because it was not narrowly tailored to serve a compelling governmental interest and because less restrictive alternatives were available).

ASHCROFT v. FREE SPEECH COALITION, 535 U.S. 234 (2002) (LII) ("By prohibiting child pornography that does not depict an actual child ["virtual porn"], the statute goes beyon [Ferber], which distinguishes child pornography from other sexually explicit speech because of the State's interest in protecting the children exploited by the production process.")

ASHCROFT v ACLU, 542 U.S. 656 (2004) (LII) (upholding injunction preventing enforcement of the Child Online Protection Act (COPA), 47 U.S. C. §231, which, among other things, imposes a $50,000 fine and 6 months in prison for the knowing posting, for “commercial purposes,” of World Wide Web content that is “harmful to minors,” but provides an affirmative defense to commercial Web speakers who restrict access to prohibited materials by “requiring use of a credit card” or “any other reasonable measures that are feasible under available technology,” §231(c)(1). ... "respondents propose that blocking and filtering software is a less restrictive alternative, and the Government had not shown it would be likely to disprove that contention at trial. Filters impose selective restrictions on speech at the receiving end, not universal restrictions at the source.")

U.S. v. AMERICAN LIBRARY ASSOC., 539 U.S. 194 (2003) (LII) (upholding Children’s Internet Protection Act (CIPA), which forbids public libraries to receive federal assistance for Internet access unless they install software to block obscene or pornographic images and to prevent minors from accessing material harmful to them).

 

STATUTES

Communications Decency Act of 1996 (Title V of the Telecommunications Act of 1996).

Child Online Protection Act (COPA) of 1998 (47 U.S.C. 231). (Cf. Children's Online Privacy Protection Act of 1998 (COPPA) 16 USC 6501-6506)

Children's Internet Protection Act (CIPA) of 2000 Children’s Internet Protection Act (CIPA), Pub. L. No. 106-551, Div. B., Tit. XVII, 114 Stat. 2763A-335 (2000).

Child Protection and Obscenity Enforcement Act of 1988 (Pub. L. 100–690, title VII, subtitle N (§7501 et seq.), Nov. 18, 1988, 102 Stat. 4485, 18 U.S.C. § 2251 et seq.) (enforced through "2257 Regs" guidelines, 28 CFR 75)

 

NEWS ARTICLES

Brian Krebs, Substitute Teacher Faces Jail Time Over Spyware, Security Fix: Brian Krebs on Computer Security, washingtonpost.com (Jan. 25, 2007) ("A ... substitute teacher ... is facing prison time following her conviction for endangering students by exposing them to pornographic material displayed on a classroom computer ... [a] computer expert ... testified for the defense that the images were the result of incessant pop-up ads served by spyware on the classroom computer.")

Brian Krebs, Missed Software Upgrade Blamed for Conn. Porn Case, Security Fix: Brian Krebs on Computer Security, washingtonpost.com (Jan. 25, 2007) ("the school district's information technology supervisor says the whole mess [see previous article] might never have happened had he renewed the school's license for its content filtering software")

Teacher's porn conviction sparks tech debate, CNN.com (Feb. 13, 2007) ("[Teacher] convicted last month of exposing seventh-grade students to pornography on her classroom computer ... contended the images were inadvertently thrust onto the screen by pornographers' unseen spyware and adware programs. Prosecutors dispute that.")

Associated Press, Austrian Officials Uncover Major Child-Porn Ring, Wall Street Journal (Feb. 7, 2007) ("Austrian authorities ... have busted a major international child-pornography ring involving more than 2,360 suspects from 77 countries who paid to view videos depicting infants and young children being sexually abused. ... videos ... included images that showed "the worst kind of child sexual abuse. ... Girls could be seen being raped, and you could also hear screams," ... No suspects were yet in custody, but Austrian authorities said they were sharing their information with law enforcement in other countries in hopes that suspects could be investigated and charged.")

 

CHILD EXPLOITATION

 

CASES:

US v Poehlman, 217 F.3d 692 (2000) ("Mark Poehlman, a cross-dresser and foot-fetishist, sought the company of like-minded adults on the Internet. What he found, instead, were federal agents looking to catch child molesters. We consider whether the government's actions amount to entrapment.")

OTHER:

Dru Stevenson, Entrapment by Numbers, 16 U. Fla. J.L. & Pub. Policy 1 (2005).

Martin G. Weinberg, et al., COVER STORY: INTERNET SEXUAL ENTRAPMENT: THE USES & MISUSES OF 18 U.S.C. 2423(B), 26 Champion 12 (Aug. 2002).

NEWS:

Carl S. Kaplan, Court Says Agents Went Too Far in Online Sting, Cyber Law Journal (2000)

"Four-fold increase in serious child abuse on Web," Reuters (Apr. 17, 2007) ("Images of child abuse posted and sold online are rapidly becoming more graphic and more sadistic and involving younger children.")

[MORE TO COME]

 


 

VI.     Investigating Cybercrime; International Aspects and Jurisdiction

 

Digital Evidence and Computer Forensics.

The computer as "witness" [more to come].

Digital Evidence is electronic records -- that is, any data that is recorded or preserved on any medium in or by a computer system or similar device and that can be read or perceived by a person or computer system, including by display, printout or other output -- that may be evidence of a crime.

Computer Forensics is the scientific examination and analysis of data held on, or retrieved from, computer storage media in such a way that the electronic record can be used in a court of law.

See related material at Interception, Search and Seizure, and Surveillance, below in part VII.

International Aspects and Jurisdiction.

The emergence of a global information society facilitates and enhances opportunities for transnational cyber- and other crime. The divergence between global information flows and nation-state regulatory jurisdiction leads to "regulatory arbitrage" where inconsistent and incompatible regulatory regimes result in "flag of convenience" forum shopping that can lead to the lowest- (in the case of crime) or highest- (in the case of government control over civil liberties) common denominator regime asserting jurisdiction. Where does cybercrime take place and who can or should have jurisdiction? How can cybercrime across jurisdictional lines be prevented, controlled, mitigated, or responded to?

The cross-jurisdictional nature of computer network activity complicates both prosecution and investigation of cybercrime.

 

REQUIRED READING:

CASEBOOK: David J. Loundy, COMPUTER CRIME, INFORMATION WARFARE, AND ECONOMIC ESPIONAGE, Carolina Academic Press (2003) (ISBN:0890891109):

Chapter 17, International Aspects of Computer Crime, pp. 685-736 (Susan W. Brenner, Transnational Evidence Gathering).

Russel Smith, "Investigating Cybercrime: barriers and solutions," Australian Institute of Criminology (Sep. 11, 2003).

Council of Europe (CoE) Convention on Cybercrime (ETS No.-185, Nov. 2001).

Council of Europe Convention on Cybercrime, Frequently Asked Questions and Answers, US DOJ CCIPS (Update as of Nov. 10, 2003).

Fact Sheet, "Council of Europe Convention on Cybercrime," U.S. Dept. of State (Sep. 29, 2006).

Declan McCullagh, "Senate ratifies controversial cybercrime treaty," CNET News (Aug. 4, 2006).

"U.S. Becomes Party to Council of Europe Convention on Cybercrime," BeSpacific (Sep. 29, 2006).

 

Digital Evidence, Computer Forensics, Investigations (more to come):

Declan McCullagh, "Feds offer cybercrime tips to local cops," Cnet News (Jan. 16, 2007) ("The department's Office of Justice Programs on Tuesday published what amounts to a manual for tech-challenged gumshoes, covering everything from how to track suspects through an Internet Relay Chat network to targeting copyright thieves on peer-to-peer networks.") [download PDF manual]

 

ADDITIONAL READING:

Press Release, "Six Defendants Plead Guilty in Internet Identity Theft and Credit Card Fraud Conspiracy," U. S. Dept. of Justice (Nov. 17, 2006).

Tom Zeller, Jr. "US Arrests 7 on Charges of Credit Data Trading," N.Y. Times (Mar. 29, 2006).

Tom Zeller, Jr. "LINK BY LINK; Countless Dens of Uncatchable Thieves," N.Y. Times (Apr. 3, 2006) (In the transnational, Internet-driven market for stolen financial and consumer data, some thieves are simply easier to nab than others. And while Russians and Eastern Europeans have become the top bananas in the stolen data trade, the English-speaking -- particularly American -- players are really the lowest-hanging fruit.)

CASSELL BRYAN-LOW, "How Legal Codes Can Hinder Hacker Cases: Prosecutions of Virus Writers Find Complex Issues, Soft Penalties -- but Laws May Stiffen," Wall Street Journal (Jan. 17, 2007) ("The problems [in trying hacker cases] lie in both building cases and securing stiff sentences, say legal and security experts. Prosecutors can have a hard time explaining the complex crimes to the courts. It often is difficult for law enforcers to quantify the damage caused by a virus that infects computer networks. And judges often hand down light sentences to the culprits, who typically are young, first-time offenders, among other factors.")

U.S. Dept. of Justice, Computer Crime Guidance.

 

OPTIONAL READING:

Susan W. Brenner and Bert-Jaap Koops, Approaches to Cybercrime Jurisdiction, 4 J. of High Tech. L. 1 (2004).

 

OPTIONAL BACKGROUND READING:

Jack Goldsmith & Tim Wu, WHO CONTROLS THE INTERNET: Illusions of a Boderless World (Oxford 2006) (ISBN:0195152662).

James A. Lewis, CYBERSECURITY (CSIS 2003) (ISBN:0892064269).

 


 

VII.    Infrastructure and Information Security; Risk Management

 

REQUIRED READING:

CASEBOOK: David J. Loundy, COMPUTER CRIME, INFORMATION WARFARE, AND ECONOMIC ESPIONAGE, Carolina Academic Press (2003) (ISBN:0890891109):

Chapter 10, Employees, Policies, and Risk Management, pp. 345-370 (social engineering; risk management),

Chapter 11, Infrastructure Security, pp. 371-400 (Presidential Decision Directive PDD 63), and

Chapter 12, Technical Means of Protecting Information, pp. 401-448 (AZ v. Moran; NIST; Ziff Davis; cryptography; biometrics).

 

STATUTES:

Federal Information Security Management Act of 2002 ("FISMA").

Digigtal Millenium Copyright Act ("DMCA") (anti-circumvention provisions)
17 U.S.C. § 1201. Circumvention of copyright protection systems.

 

DIRECTIVES:

Presidential Decision Directive (PDD 63) Critical Infrastructure Protection (May 1998)

Executive Order 13231 Critical Infrastructure Protection in the Information Age (Oct. 16, 2001)

 

GOVERNMENT REPORTS:

Government Accounting Office (GAO-07-39) CRITICAL INFRASTRUCTURE PROTECTION Progress Coordinating Government and Private Sector Efforts Varies by Sectors’ Characteristics (October 2006) (plans for protecting the nation’s critical information technology networks and systems are focused on developing resiliency and quick recovery rather than on safeguarding against every type of threat).

Government Accounting Office (GAO-05-434) CRITICAL INFRASTRUCTURE PROTECTION Department of Homeland Security Faces Challenges in Fulfilling Cybersecurity Responsibilities (May 2005).

Government Accounting Office (GAO-04-354) CRITICAL INFRASTRUCTURE PROTECTION Challenges and Efforts to Secure Control Systems (Mar. 2004).

Congressional Reporting Service (CRS RL32114) Computer Attack and Cyber Terrorism: Vulnerabilities and Policy Issues for Congress (Oct. 17, 2003).

 

ADDITIONAL READING:

National Strategy to Secure Cyberspace (Feb. 2003).

National Infrastructure Advisory Council (DHS) Website.

Heather Greenfield, "Agencies close to satisfying cybersecurity law," GOVEXEC.com (Nov. 2, 2006) ("The White House Office of Management and Budget predicts that the percentage of federal systems complying with a 2004 law [FISMA] requiring agencies to identify cyber risks and develop ways to combat them will be up next year.")

Jason Miller, "What are good security metrics?" Gov. Comp. News (Nov. 2, 2006) ("Paller [the research director of the SANS Institute] said that Congress and the administration pay too much attention to how agencies meet certain aspects of the Federal Information Security Management Act. He said the number of systems certified and accredited, awareness training, configuration management and annual testing don’t go far enough to ensure agency IT systems are secure.")

Bruce Schneier, "Quickest Patch Ever," WIRED (Sept. 7, 2006) ("If you really want to see Microsoft scramble to patch a hole in its software, don't look to vulnerabilities that impact countless Internet Explorer users or give intruders control of thousands of Windows machines. Just crack Redmond's DRM.")

Mary Mosquera, "Commerce uses encryption to help steel notebooks, GCN.com (Jan. 22, 2007) ("With thefts of notebook PCs a leading cause of data breaches, the Commerce Department is encrypting its mobile hard drives to lock up files and data." (Query: should there be a presumption of negligence for unencrypted data?)

Brad Stone, A Lively Market, Legal and Not, for Software Bugs, NY Times (Jan. 30, 2007) ("software vulnerabilities — as with stolen credit-card numbers and spammable e-mail addresses — carry real financial value. They are commonly bought, sold and traded online, both by legitimate security companies, which say they are providing a service, and by nefarious hackers and thieves.")

Ellen Messmer, U.S. cyber counterattack: Bomb 'em one way or the other, NetworkWorld (Feb. 2, 2007) ("If the United States found itself under a major cyberattack aimed at undermining the nation’s critical information infrastructure, the Department of Defense is prepared, based on the authority of the president, to launch a cyber counterattack or an actual bombing of an attack source.")

Anne Broache, Data breach bills resurface in Congress, CNET News (Feb. 6, 2007) ("Concealing security breaches in which personal consumer information may have been swiped could carry prison time under a pair of sweeping proposals that resurfaced Tuesday in Congress.")

 

OPTIONAL READING ON RISK:

Cass R. Sunstein, Terrorism and Probability Neglect, 26 JOURNAL OF RISK AND UNCERTAINTY 121 (2003), reprinted in THE RISKS OF TERRORISM (W. Kip Viscusi ed. 2003) .

Cass R. Sunstein, Probability Neglect: Emotions, Worst Cases, and Law, U. Chicago L. & Econ., Olin Working Paper No. 138. (November 2001) available at http://ssrn.com/abstract=292149.

Cass R. Sunstein, RISK AND REASON (Cambridge 2002) (ISBN:0521016258).

Much of Sunstein’s work in this area builds on that of Amos Tversky and Daniel Kahneman. See generally Amos Tversky & Daniel Kahneman, Judgment under Uncertainty: Heuristics and Biases, 185 SCIENCE 1124 (1974); JUDGMENT UNDER UNCERTAINTY: HEURISTICS AND BIASES, (Daniel Kahneman, Paul Slovac & Amos Tversky, eds., 1982).

K. A. Taipale, Technology, Security and Privacy: The Fear of Frankenstein, the Mythology of Privacy, and the Lessons of King Ludd, 7 Yale J. L. & Tech. 123, 133-136; 9 Intl. J. Comm. L. & Pol'y 8 (Dec. 2004) (excerpt pp. 133-136).

 

OPTIONAL READING ON SECURITY:

NIST Information Security Handbook: A Guide for Managers, Nov. 7, 2006. (Download PDF) ("NIST Special Publication 800-100, Information Security Handbook: A Guide for Managers. The purpose of this publication is to inform members of the information security management team [agency heads, chief information officers (CIO), senior agency information security officers (SAISO), and security managers] about various aspects of information security that they will be expected to implement and oversee in their respective organizations.")

Dan Geer, "The Shrinking Perimeter of Defense: Making the Case for Data-Level Risk Management" (2004).

Dan Geer, "Securing the Point of Use: The New Foundation for Data Security" (2005).

Dan Geer, et al., "Cyber Insecurity: The Cost of Monopoly" (2005).

Dan Geer, schmoocon presentation 13i06 (2006) [slides] [text].

Bruce Schneier, Crypto-Gram, http://www.schneier.com/crypto-gram.html.

Bruce Schneier, BEYOND FEAR (2004) (ISBN:0387026207).

Bruse Schneier, SECRETS & LIES: DIGITAL SECURITY IN A NETWORKED WORLD (2000) (ISBN:0471453803).

Anthony H. Cordesman, CYBER-THREATS, INFORMATION WARFARE, AND CRITICAL INFRASTRUCTURE PROTECTION: DEFENDING THE US HOMELAND (2002) (ISBN:0275974235).

Hal Varian, "Managing Online Security Risks," N.Y. Times (Jun. 1, 2000).

Ross Anderson, "Economics and Security Resources Page," Univ. of Cambridge (see, in particular, "Why Information Security is Hard - An Economic Perspective")

Bruce Schneier, "Information Security and Externalities," Schneier on Security Weblog (Jan. 18, 2007) ("Information security is not a technological problem. It is an economics problem. And the way to improve information security is to fix the economics problem.")

 

OPTIONAL READING ON BIOMETRICS

National Research Council of the National Academies, Summary of a Workshop on the Technology, Policy, and Cultural Dimensions of Biometric Systems (2006) (Whither Biometrics?)

K. A. Taipale, Presentation: Technology, Policy, and Cultural Dimensions of Biometric Systems: Information Sharing, Biometric Systems: Workshop, National Academy of Sciences (2005). [slides]

 


 

VIII.   Interception, Search and Seizure, and Surveillance

 

Digital Law Enforcement.

New information technologies can improve efficiencies in law enforcement and national security information. Advanced sensing, collection, information sharing, and data analysis technologies (including data mining) can improve allocation of law enforcement and national security resources to more effective uses.

Such developments, however, are challenging to political and legal systems, and social expectations, that are at least partially based on protecting certain civil liberties and individual freedoms by maintaining privacy through the “practical obscurity” of inefficient information access technologies and procedures.  On the one hand there is a need to "connect the dots" through improved information sharing and analysis to provide for collective security or effective law enforcement and on the other hand the notion of individual liberty in free society is at least partially built on keeping the power to easily "connect the dots" out of the control of government agencies by maintaining or imposing inefficiencies in information sharing through a system of checks and balances, due process, and technical constraints.

 

REQUIRED READING:

CASEBOOK: David J. Loundy, COMPUTER CRIME, INFORMATION WARFARE, AND ECONOMIC ESPIONAGE, Carolina Academic Press (2003) (ISBN:0890891109):

Chapter 5, Interception of Electronic Communications, pp. 131-158 (Steve Jackson Games v. U.S. Secret Service), and

Chapter 6, Search and Seizure, pp. 159-230 (Katz v. US; Kyllo v. US; US v. Gorshkov; US v. Scarfo; Trulock v. Freeh).

US v COUNCILMAN (2005) ("stored communications")
http://www.ca1.uscourts.gov/pdf.opinions/03-1383EB-01A.pdf

 

ADDITIONAL CASES:

Katz v. United States, 389 U.S. 347 (1967) (FindLaw) (extending warrant requirement to wiretaps and overruling Olmstead v. United States, 277 U.S. 438 (1928).

Smith v. Maryland, 442 U.S. 735 (1979) (FindLaw) (use of "pen register" not a "search," therefore, does not require warrant).

[cf. Trudi Gilfillian, "Internet subpoena invalid, appeals court says," PressofAtlanticCity.com (Jan. 23, 2007) (NJ appeals court holds "defendant had a reasonable expectation of privacy in her ISP account information" under state constitution).]

US v Miller, 425 U.S. 435 (1976) (FindLaw) (no legally recognized expectations of privacy in records of accounts held by bank).

Kyllo v. US, 533 U.S. 27 (2001) (use of a thermal imaging device to monitor the radiation of heat from a person's home was a "search" requiring a warrant).

 

STATUTES:

ELECTRONIC COMMUNICATIONS PRIVACY ACT (ECPA)
18 U.S.C. § 2701, et seq.

THE WIRETAP ACT (Title III)
18 U.S.C. § 2510, et seq.

Pen Register / Trap and Trace
18 U.S.C. § 3121, et seq.

FOREIGN INTELLIGENCE SURVEILLANCE ACT (FISA)
50 USC §1801 et seq.

U.S. Constitution, Fourth Amendment.

 

GOVERNMENT DOCUMENTS

U.S. DOJ, Computer Crime & Intellectual Property Section, Electronic Evidence and Search & Seizure (including Search & Seizure Manual).

 

DATA RETENTION:

Anne Broache, "Politicos mull data retention by Web hosts, registrars," CNET News (Sep. 26, 2006).

Declan McCullagh, "FBI director wants ISPs to track users," CNET News (Oct. 17, 2006).

Jo Best, "EU data retention directive gets final nod," CNET News (Feb. 22, 2006).

DIRECTIVE 2006/24/EC OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 15 March 2006 (on the retention of data generated or processed in connection with the provision of publicly available electronic communications services or of public communications networks and amending) (Directive 2002/58/EC) [download PDF].

Anne Broache, "Attorney general to talk data retention with new Congress," CNET News (Jan. 18, 2007) ("The Bush administration plans to approach Congress again this year about the possibility of new rules requiring Internet service providers to retain information about their subscribers for a certain period of time.")

Declan McCullagh, GOP revives ISP-tracking legislation, CNET News (Feb. 6, 2007) ("All Internet service providers would need to track their customers' online activities to aid police in future investigations under legislation introduced Tuesday as part of a Republican "law and order agenda.")

Victoria Shannon, Proposed legislation called a threat to Internet users' privacy, Int'l. Herald Tribune (Feb. 14, 2007) ("European governments are preparing legislation to require companies to keep detailed data about people's Internet and phone use that goes beyond what the countries will be required to do under a European Union directive").

 

ELECTRONIC DISCOVERY

FindLaw.com Electronic Discovery Resource Page http://technology.findlaw.com/electronic-discovery/

 

PRE-CRIME

Minority Report (20th Century Fox 2002) ("pre-cogs" predict who will commit murder in the future allowing for their preemptive arrest).

Data mining:

Charles Piller & Eric Lichtblau, FBI Plans to Fight Terror With High-Tech Arsenal, L.A. Times, July 29, 2002, at A1 ("By Sept. 11, 2011, the FBI hopes to use artificial-intelligence software to predict acts of terrorism the way the telepathic precogs in the movie Minority Report foresee murders before they take place.").

Emily Singer, Computer model forecasts crime sprees, (Aug. 17, 2003) ("Computer forecasts that predict where and when crimes will happen by analysing past patterns should help police channel resources where they are needed most. The technique, now under trial in the US, could be available for routine use within a year.")

The Privacy Implications of Government Data Mining Programs, Hearing Before the U.S. Senate Committee on the Judiciary (Jan. 10, 2007).

Brain scanning:

"Brain Fingerprinting" Testing Ruled Admissible in Court ("Iowa ... Court ... ruled [in 2001] that "Brain Fingerprinting" testing is admissible in court. ... The test showed that the record stored in [defendant's] brain did not match the crime scene and did match the alibi. ... In a "Brain Fingerprinting" test, words, pictures or sounds describing salient features of a crime are presented by a computer, along with other, irrelevant information, that would be equally plausible for an innocent subject. Items are chosen that would be known only to the perpetrator and to investigators, but not to the public or to an innocent suspect. ... When a subject recognizes something as significant in the current context, the brain emits a specific brain response [the "P300" spike]. If the record of the crime is stored in the subject's brain, this response appears when the subject recognizes the correct, relevant items. If not, then the response is absent.").

Ian Sample, The brain scan that can read people's intentions, The Guardian (Feb. 9, 2007) ("A team of ... neuroscientists has developed a powerful technique that allows them to look deep inside a person's brain and read their intentions before they act. ... to probe people's minds and eavesdrop on their thoughts, and raises serious ethical issues over how brain-reading technology may be used in the future. ... they may be able to spot people who plan to commit crimes before they break the law.")

Steve Silberman, Don't Even Think About Lying: How brain scans are reinventing the science of lie detection, WIRED 14.01 (Jan. 2006) ("Functional magnetic resonance imaging [fMRI] enables researchers to create maps of the brain's networks in action as they process thoughts, sensations, memories, and motor commands. ... fMRI is also poised to transform the security industry, the judicial system, and our fundamental notions of privacy ... using the technology to analyze the cognitive differences between truth and lies.")

Lie detection:

R. Colin Johnson, Lie-detector glasses offer peek at future of security, EE Times (Jan. 16 , 2004) ("... a lie detector small enough to fit in the eyeglasses of law enforcement officers, and its inventors say it can tell whether a passenger is a terrorist by analyzing his answer to that simple question in real-time.")

Carrie Lock, Deception Detection: Psychologists try to learn how to spot a liar, Science News (Jul. 31, 2004).

NICK McDERMOTT, Telephone lie detector claims to catch fibbers, Daily Mail (Dec. 18, 2006) ("A new telephone lie detector system promises to pick up on tell-tale signs of stress in a caller's voice whenever they tell a fib. Available for free, the Kishkish lie detector can be easily downloaded from the web and used by those who make phone calls over the internet.")

Scientists: A good lie detector is hard to find, PHYSORG.com (Feb. 12, 2007) ("n the not-too-distant future, police may request a warrant to search your brain.")

HONEYPOTS:

Dr. Ian Walden & Anne Flanagan, Honeypots: A Sticky Legal Landscape? 29 Rutgers Computer & Tech. L.J. 317 (2002).

 

ADDITIONAL READING ON SEARCH & SEIZURE:

Orin Kerr, Searches and Seizures in a Digital World, 119 Harvard L. Rev. (2005).

Orin Kerr, Search Warrants in an Era of Digital Evidence, 75 Miss. L. J. 85 (2005).

Orin Kerr, A User's Guide to the Stored Communications Act, and a Legislator's Guide to Amending It, Geo. Wash. L. Rev. (2004).

Ceter for Democracy and Technology (CDT) Report: Digital Search and Seizure [PDF].

Ceter for Democracy and Technology (CDT) Press Release: Digital Technology Makes Surveillance Easier; Stronger Laws Needed, Report Finds, Feb. 22, 2006.

 

ADDITIONAL READING ON SURVEILLANCE AND DATAVEILLANCE (excerpts):

K. A. Taipale, "The Ear of Dionysus: Rethinking Foreign Intelligence Surveillance," 9 Yale J. L. & Tech. (forthcoming Spring 2007).

Kim Taipale, The Privacy Implications of Government Data Mining Programs, Testimony before the U.S. Senate Committee on the Judiciary, Washington, DC (Jan. 10, 2007). [PDF]

K. A. Taipale, Whispering Wires and Warrantless Wiretaps: Data Mining and Foreign Intelligence Surveillance, N.Y.U. Rev. L. & Sec., No. VII Supl. on L. & Sec. The NSA and the War on Terror (Spring 2006). [PDF]

K. A. Taipale, Written Testimony on Foreign Intelligence Surveillance Act Modernization Before the House Permanent Select Committee on Intelligence (HPSCI), United States House of Representatives, Jul. 19, 2006.

K. A. Taipale, The Trusted Systems Problem: Security Envelopes, Statistical Threat Analysis, and the Presumption of Innocence, Homeland Security—Trends and Controversies, IEEE Intelligent Systems, Vol. 20 No. 5, pp. 80–82 (Sep./Oct. 2005). [Also available here from IEEE.]

K. A. Taipale, Technology, Security and Privacy: The Fear of Frankenstein, the Mythology of Privacy, and the Lessons of King Ludd, 7 Yale J. L. & Tech. 123 ; 9 Intl. J. Comm. L. & Pol'y 8 (Dec. 2004).

K. A. Taipale, Data Mining and Domestic Security: Connecting the Dots to Make Sense of Data, 5 Colum. Sci. & Tech. L. Rev. 2 (Dec. 2003), excerpt from 57-67 (download article for footnotes):

3. Privacy concerns relating to Information Technology and Domestic Security

Distilled to a simple taxonomy, the significant privacy concerns voiced in opposition to the technologies with which this Article is concerned are primarily two: those that arise from the aggregation (or integration) of data and those that arise from the automated analysis of data that may not be based on any individualized suspicion. [238] The former might be called the "database" problem, [239] and the latter the "mining" problem. [240] The former is implicated in subject-based inquiries that access distributed databases to find more information about a particular subject, and the latter is implicated in the use of pattern-matching inquiries, in which profiles or models are run against data to identify unknown individuals. [241]

Additional concerns are that the technology will not work for the intended purpose (providing either a false sense of security by generating false negatives or imposing civil liberties costs on too many innocent people by generating false positives), [242] that the technology is subject to potential abuse, or that it will be vulnerable to attack. [243]

B. Data Aggregation: The Demise of "Practical Obscurity"

The efficiencies inherent in data aggregation itself cannot be denied; indeed, it is these efficiencies that provide the impetus for developing and employing data aggregation technologies in the first place. [244] Nor can the impact of this efficiency on privacy be denied. [245] New technologies that provide easy access to distributed data and efficiency in processing are obviously challenging to a system that is at least partially based on protecting certain rights by insisting on inefficiencies. On the one hand there is a need to "connect the dots" and on the other hand the notion of a free society is at least partially built on keeping the power to "connect the dots" out of the control any one actor, particularly the central government. [246] Making access to data easier and more efficient (in a sense, lowering the transaction cost of data use) magnifies and enhances government power.247

Interestingly, the Supreme Court addressed the issue of data aggregation almost 15 years ago, albeit in contrapose to the problem at hand. In Department of Justice v. Reporters Committee for Freedom of Press,248 the court held that raw FBI criminal data (in this case, a "rap sheet") that was officially part of the public record did not have to be disclosed to a reporter's Freedom of Information Act request because the aggregation of public records in one place negated the "practical obscurity" that protected those records in the world of distributed paper records.

Justice John Paul Stevens opined: "[T]here is a vast difference between the public records that might be found after a diligent search of courthouse files, county archives and local police stations throughout the country and a computerized summary located in a single clearinghouse of information."249 Thus, in weighing the relative rights of two private parties – the free press rights of the reporter and the privacy rights of the individual – the Court held that the interest in privacy expectations created by inefficiencies in data acquisition was a recognized and protectable interest.

The question that has not been definitively determined as yet is whether that same analysis, when applied to government aggregation or integration of previously discrete, distributed sources of information – each which it may have the perfect legal right to access individually – is itself problematic under the Fourth Amendment's right to be free from "unreasonable" search.250 This issue becomes particularly heightened when combined with the concern expressed below regarding queries that are not based on individualized suspicion. However, for purposes of developing guiding principles for technology development this question does not need to be settled, it is sufficient to recognize that the concern raised by data aggregation is legitimate and to suggest technology development and implementation strategies to mitigate the impact. Thus, the relevant question for subject-driven inquiries becomes to what extent technical efficiencies are to be allowed. Here, the critical juncture is the determination of subject. In other words, based on the identity of the subject and the purpose of the inquiry, what is the permissible scope of query – to what data can the query be directed and what standard of association must be met by any automated processing. A separate, but related, question is what consequences are triggered from the result – the more draconian the potential consequences, the higher the burden for use.

For example, a subject-based inquiry that seeks additional information about a known terrorist – already lawfully subject to investigation – and their associations or activities is fundamentally different than an inquiry to confirm identity of an air traveler and check against a "threat-list" triggered only by the making of a travel reservation. However, the policy issues involved do not turn so much on what kind of technology or even what methodology is to be used, but rather on what the standard for initial query ought to be and how that relates to what data should or should not be accessible and for what ultimate purpose.

The point here is not to minimize the privacy concerns but to isolate the issues so that technical and procedural protections can be built in. In the context of data aggregation and subject-based queries, rule-based processing, which can allow for incremental (rather than all-or-nothing) access to distributed data (and differential processing of such data) are part of the technical solution.251 Rule-based processing allows the incorporation into the technology itself of policy judgments as to how, when, where, and for what purpose, particular information can be accessed.

C. Data Analysis: The "Non-particularized" Search

As noted earlier, a significant concern for privacy advocates in connection with data mining is that the search for previously unknown information may not be based on individualized or particular suspicion.252 Rather, the data itself may be mined in order to discover certain patterns or relationships,253 and then the pattern may be matched against new data to identify additional subjects for further processing. For those opposed to the use of these technologies this amounts to a search "led by investigators with no clear idea how to identify real terrorist threats"255 "put[ting] the government in the business of maintaining constant surveillance on millions of people"256 – "a sharp departure from the principle that you have the right to be left alone unless your government has just cause."257 Pattern-matching, it is contended, "investigate[s] everyone, and most people who are investigated are innocent."258

Although much of the concern behind these criticisms is legitimate, there are technical and procedural subtleties missing from the critics' analysis. First, as described above, a distinction must be drawn between the development of descriptive and predictive models (data mining in the narrow sense), which may employ undirected data mining techniques to model normative behavior, and their subsequent application to new data to find additional like occurrences or deviations (pattern-matching).259

Unlike in commercial applications, pattern development for domestic security or intelligence purposes usually involves analyzing actual (or hypothesized) terrorists or terrorist activity in order to discern whether there are identifying characteristics that can reveal a descriptive or predictive pattern that can then be used to identify other terrorists or related events.260 To the extent that computational "data mining" is used to automate the task of extracting patterns, the data to be analyzed generally still relates to particular terrorists, terrorist activities, or related analogs – the intent of data mining is to uncover connections that may not be obvious from manual observation.261 The popular conception that vast amounts of information relating to innocent subjects is mined with no idea as to what the investigator is looking for, on the hope of uncovering "suspicious patterns," is generally false.262

But, such generalized undirected data mining of information relating to innocent individuals may indeed be employed in counter-terrorism in certain narrow applications to develop normative models. These models can then be used to contrast against terrorist patterns in order to identify potential terrorists from a general population by subsequently using deviation analysis (that is, to look for "suspicious patterns"). However, although individual data of innocent persons may be processed during such model development, it is not unequivocal that there is a significant privacy impact if such analysis is restricted to developing aggregate categories of "normal" patterns in order to find deviations in future pattern-matches any more than there is from any other statistical analysis of "personal data" that is analyzed or reported in the aggregate, for example social science analysis of census data or medical studies statistically reporting aggregations based on individual cases. Since no individual identifying information (nor any corresponding personal data) is returned to the analyst during the automated development of the model (and there is no scrutiny by any human of any individually identifiable data), it is difficult to discern the privacy implications of the data analysis itself unless privacy is conflated with absolute secrecy. 263

On the other hand, pattern-matching queries, in which descriptive or predictive models (whether mined from real data relating to terrorists or derived from hypothetical scenarios) are run against new data in order to identify unknown subjects or activities for further investigation, may directly implicate the issue of the non-particularized search.264 However, by developing technologies that use selective revelation (that is, techniques that separate transactional data from identity or otherwise reveal information incrementally) these concerns can be significantly reduced by maintaining anonymity, which in turn protects autonomy – that is, the ability to freely act within the rules of the polity without being surveilled.265

Pattern-matching is not inherently a surveillance technology. No individual dossier is created and no individual is scrutinized for suspicious behavior. No person or behavior is individually observed or surveilled by the automated analysis itself.266 To the extent that valid behavioral or transactional profiles are developed,267 a search for matching behaviors is undertaken. Once matching behaviors are identified, there may be a Fourth Amendment (and due process) issue regarding whether the suspicion is sufficiently reasonable to "particularize" the search – that is, to connect the behavior with identity.268

This exposes a particular interesting (and generally accepted) misconception in popular notions of "privacy" and data mining, particularly as it relates to autonomy, pattern-matching, and non-particularized search. Although it is contended that pattern- matching "alters the way government investigations typically occur,"269 it is unclear that this is so. For example:

Usually the government has some form of particularized suspicion, a factual basis to believe that a particular person may have engaged in illegal conduct. Particularized suspicion keeps the government's profound investigative powers in check preventing widespread surveillance and snooping into the lives and affairs of all citizens. Computer matches, Priscilla Regan contends, investigate everyone, and most people who are investigated are innocent.270

But how is pattern-matching in a database any different than observing behavior in public? A simple example may illustrate the point. Suppose that a police officer observes an individual running on a public street wearing a mask. Due process requires that the officer comply with certain standards of reasonable suspicion and other procedures before taking additional action, not that he close his eyes. If stopping and questioning an individual who is running in the street wearing a mask is reasonable (it may or may not be in the particular circumstance), then why is questioning or investigating someone whose electronic trail indicates a reasonable suspicion of terrorist activity presumptively not? More importantly, does observing the running suspect somehow invade the privacy of the others on the street who are also observed but not questioned?

Obviously, the answer turns on whether one considers the particular database the equivalent of the public street. But that highlights the paradox: to the extent that the question is whether the particular form of data (street observation or database) is subject to expectations of privacy, we are squarely within the traditional Fourth Amendment jurisprudence.271 Thus, there is no general non-particularized suspicion problem – only the same issue encountered before, that is, is the pattern-matching "reasonable" in the particular context of its use. And that question is related to its efficacy, the point of the research and development at issue.272

Others, however, argue that there is no protection from "anonymized" data because even if the "authorities had to get a warrant . . . to access our information and discover our identity . . . all the bad effects from [surveillance] would be felt" because "it will always be possible that our innocent activities will coincide with" a pattern being matched and "we would no longer be free." However, that argument raises the issue of false positives (that is, innocent people identified by the model) and not that of non- particularized search.273 To argue that transactional data should be absolutely secret – as opposed to anonymous and subject to traditional notions of due process – is not only to privilege privacy as an absolute, it is to extend its reach far beyond existing interests in maintaining individual autonomy for legitimate purposes. Prohibiting pattern-matching queries is more akin to hiding footprints than protecting the disclosure of shoe purchases.274

Although the separate issue of false positives is not an insignificant problem (and is addressed in the following subsection), it is qualitatively and quantitatively different than claiming that "everybody is being investigated" through pattern-matching. In reality only the electronic footprints of transactions and activities are being scrutinized – to the extent that there are suspicious footprints there may or may not be consequences to the individual who left them, and there are technical means to make those consequences conform to existing Fourth Amendment or statutory due process procedures.275 The primary policy issues involved in applying these technologies then are determining what confidence interval for the technology and methodology are required to meet the "reasonableness" test, and what procedural protections are imposed between their application and any consequence to the individual.276

In any case, this Article argues that the use of selective revelation technologies can mitigate the non-particularized suspicion concerns by permitting the imposition of judicial due process between the observed behavior and the act of revealing identity.277 The automated analysis of potentially relevant transactional data while shielding the exposure of individual identity to a generalized search protects privacy by maintaining anonymity, which in turn preserves autonomy.278 Rather than minimizing concerns relating to non-particularized suspicion, this Article suggests that traditional due process protection can be built into both the technology and its implementation policy by using selective revelation. Under selective revelation, pattern-matching would not lead directly to individual identity without being subjected to the appropriate legal standards. Where matching provides information that is in itself sufficient to meet investigative, reasonable suspicion, or probable cause standards – where the observed match "particularizes" the suspicion279 sufficiently (that is, reasonably under the circumstances in conformity with Fourth Amendment requirements) – the relevant procedural protection – subpoena, warrant, or court order – can be applied depending on the specific context before identity is revealed or acted upon.280 Enforcement of these protections would follow the traditional means – pattern-matches determined to be unreasonable would be subject to the exclusionary rule, administrative proceedings, or civil redress.281 Additionally, in cases of pattern-matching that leads to "adverse, non-punitive collateral civil consequences" (for example, watch-listing) additional administrative procedures requiring notice, time limits, and other due process protections can be devised, including an individual right to appeal adverse administrative review to federal court for de novo review.282

 

OPTIONAL BACKGROUND REFERENCES:

Phillip A. Hubbart, MAKING SENSE OF SEARCH AND SEIZURE LAW: A Fourth Amendment Handbook (Carolina Academic Press 2005) (ISBN:1594600635).

Wayne LaFave, SEARCH AND SEIZURE (4th ed. 2004).

O.M. Dickerson, Writs of Assistance as a Cause of the Revolution, in THE ERA OF THE AMERICAN REVOLUTION (Richard Morris ed. 1939).

 

ALSO RELATED:

Kim Taipale and Kate Martin, director of the Center for National Security Studies, debate the NSA surveillance programs on WHHY Radio Times, National Public Radio (NPR) (May 16, 2006).

Kim Taipale and Marc Rotenberg, director of the Electronic Privacy Information Center (EPIC), discussed the role of technology in government surveillance efforts in The Wall Street Journal Online (May 16, 2006). Their exchange is linked here.

 

RECOMMENDED MOVIE:

BRAZIL (MCA-Universal 1985) (Terry Gilliam, dir.) (ASIN:0780022181).

 


 

IX.    Information Warfare, Cyberterrorism, and Hacktivism

 

Information is an instrument of national and global power. As such, control over its use, its protection, and its manipulation, are national and global security issues. (See GISP Program on Information and Warfare).

 

REQUIRED READING:

CASEBOOK: David J. Loundy, COMPUTER CRIME, INFORMATION WARFARE, AND ECONOMIC ESPIONAGE, Carolina Academic Press (2003) (ISBN:0890891109) read:

Chapter 13, Hacktivism, pp. 449-478 (Dorothy E. Denning).

Congressional Research Service (CRS), "Computer Attack and Cyber Terrorism: Vulnerabilities and Policy Issues for Congress," Oct. 17, 2003) (Persistent computer security vulnerabilities may expose U.S. critical infrastructure and government computer systems to possible cyber attack by terrorists, possibly affecting the economy or other areas of national security. This report discusses possible cyber capabilities of terrorists and sponsoring nations, describes how computer security vulnerabilities might be exploited through a cyber terror attack, and raises some potential issues for Congress.)

James Lewis, "Assessing the Risks of Cyber Terrorism, Cyber War and Other Cyber Threats," Center for Strategic and International Studies (CSIS) (Dec. 2002) ("Unless a cyber terror event can be designed to attract as much media attention as a physical terror event, the Internet maybe better utilized byterrorist organizations as a tool for surveillance and espionage, rather than for cyber terrorism.")

 

ADDITIONAL READING:

K. A. Taipale, "Seeking Symmetry in Fourth Generation Warfare: Information Operations in the War of Ideas," presented at the Bantle-INSCT Symposium: "Challenges in the Struggle Against Violent Extremism: Winning the War of Ideas" at the Maxwell School, Syracuse University, Mar. 29-30, 2006.

K. A. Taipale, "Information as Warfare: Disrupting Terrorist Networks" presented at the Yale Information Society Project 2005 conference, "The Global Flow of Information," at the Yale Law School on Apr. 1-3, 2005.

K. A. Taipale, "Deconstructing Information Warfare" presented to the Committee on Policy Consequences and Legal/Ethical Implications of Offensive Information Warfare, The National Academies, Washington, DC, Oct. 30, 2006.

 

Offense/Defense:

Patience Wait, "Defense domain, civilian awareness," GCN (Jan. 22, 2007).

Ellen Messmer, U.S. cyber counterattack: Bomb 'em one way or the other, NetworkWorld (Feb. 2, 2007) ("If the United States found itself under a major cyberattack aimed at undermining the nation’s critical information infrastructure, the Department of Defense is prepared, based on the authority of the president, to launch a cyber counterattack or an actual bombing of an attack source.")

 

Political Hacktivism:

Patrick Houston, "Hackers protest embassy bombing," ZDnet News (May 9, 1999).

"Hackers hit government Web sites after China embassy bombing," CNN.com (May 11, 1999).

Heather Greenfield, "Bloggers Coordinate 'Google Bombs' To Sway Voters," Nat. J. TechDaily (Oct. 24, 2006).

Tom Zeller, Jr., "A New Campaign Tactic: Manipulating Google Data," N.Y. Times (Oct. 25, 2006).

 

Terrorist Use of Internet/Material support prosecutions:

Steve Coll and Susan B. Glasser, "Terrorists Turn to the Web as Base of Operations," Wash. Post (Aug. 7, 2005).

Jon Swartz, "Terrorists' use of Internet spreads," USA Today (Feb. 20, 2005).

Declan McCullagh, Webmaster indicted for terror support, CNET News (Aug. 29, 2002) ("A federal grand jury has indicted the founder of the StopAmerica.org Web site on charges of aiding al-Qaida terrorists").

Ben Charney, Webmaster held on terror charges, CNET News (Aug. 6, 2004) ("The publisher of two pro-jihad Web sites has been arrested in London on suspicion of terrorism-related activities ... was remanded in custody by a London magistrates court on Friday on a U.S. extradition warrant. American authorities are seeking to try Ahmad on five federal charges, including material support of terrorism and prohibited support of the Taliban ... is accused of raising money for Islamic militants through two American-based Web sites that he operated).

Maureen O'Hagan, A terrorism case that went awry, Seattle Times (Nov. 22, 2004) ("Al-Hussayen was charged under a clause [in the PATRIOT Act] that expanded the definition of "material support" to include those who provide "expert advice or assistance" to terrorists' cause. He was the first person ever to be charged under that provision, ... . The contention was that al-Hussayen used his expert skills as Webmaster, so that made him a terrorist.")

Declan McCullagh, U.K. Webmaster accused of aiding terrorists, CNET News (Jul. 20, 2006) ("The arrest .... came at the request of the U.S. government, which released a 14-page indictment (click for PDF) accusing him of selling books, videotapes, audio cassettes, and CD-ROMs that glorified "violent jihad in Chechnya, Bosnia, Afghanistan" and funneling money to groups that were deemed illegal by the federal government").

BOOK REVIEW: Robert F. Worth, TheirSpace, N.Y. Times (Jun. 25, 2006) review of Gabriel Weimann, TERROR ON THE INTERNET (2007). ("Al Qaeda now views the Internet not only as an essential recruitment tool and means of communication with volunteers, but as a virtual training camp. No more need for Afghanistan: would-be terrorists can download manuals and videotapes that show them how to make explosive vests, car bombs, chemical weapons and poisons, and a library of tips on how to use them all effectively. The danger is not just theoretical. There is evidence that some of the newest terrorists were recruited and sometimes trained this way.")

Sebastian Rotella, "A World Wide Web of terrorist plotting," L. A. Times (Apr. 16, 2007) ("The Internet has become a virtual operations center replacing the Al Qaeda bases in Afghanistan and Bosnia.")

 

China and Information Warfare:

Frank Tiboni, "Chinese military targeting DOD tech," FCW.com (July 19, 2005) ("The People’s Liberation Army has likely established information warfare units to develop viruses to attack enemy computer systems and networks, and tactics to protect friendly computer systems and networks.")

Josh Rogin, "DOD: China fielding cyberattack units," FCW.com (May 25, 2006) ("The Chinese People’s Liberation Army (PLA) is developing information warfare ... units and ... is developing the ability to launch pre-emptive attacks against enemy computer networks in a crisis.")

Josh Rogin, "Network attack disables Naval War College," FCW.com (Nov. 30, 2006) ("Chinese attacks on DOD systems are far more widespread than is publicly known ... but almost all attacks remain classified. The problem is thousands of times bigger than what you hear.”) Updated "China is suspected of hacking into Navy site," FCW.com (Dec. 4, 2006).

Josh Rogin, "China a major cyberthreat, commission warns," FCW.com (Dec. 1, 2006) ("China’s cyberwarfare strategy has switched from a defensive to an offensive posture, with the goal of attacking enemy networks and denying adversaries access to information, said the U.S.-China Economic and Security Review Commission (USCC) in its annual report, released Nov. 16. Chinese strategy focuses on U.S. systems that perform command and control or deliver precision weapons, the report states.")

US DOJ Press Release, "Former Chinese National Charged with Stealing Military Application Trade Secrets from Silicon Valley Firm to Benefit Governments of Thailand, Malaysia, and China," (Dec. 14, 2006) ("Third Foreign Economic Espionage Indictment in the United States Since the Enactment of Economic Espionage Act of 1996; Source Code Used for Military Combat Simulation and Banned for Export Without License").

US DOJ Press Release, "Two Men Plead Guilty to Stealing Trade Secrets from Silicon Valley Companies to Benefit China" (Dec. 14, 2006) ("First Conviction in the Country for Foreign Economic Espionage").

 

STATUTES:

USA PATRIOT ACT - Material Support
18 U.S.C. § 2339A. Providing material support to terrorists.
18 U.S.C. § 2339B. Providing material support or resources to designated foreign terrorist organizations.

U.S. Constitution, First Amendment.

U.K. Prevention of Terrorism Bill 2005 (control orders).

 

ADDITIONAL BACKGROUND READING (Selections):

Winn Schwartau, INFORMATION WARFARE (1996) (ISBN:1560251328).

Dorothy Denning, INFORMATION WARFARE AND SECURITY (Addison-Wesley 1998) (ISBN:0201433036).

John Arquilla and David Ronfeldt, NETWORKS AND NETWARS: The Future of Terror, Crime, and Militancy (RAND 2001) (ISBN:0833030302).

Gregory J. Rattray, STRATEGIC WARFARE IN CYBERSPACE (MIT Press 2001) (ISBN:0262182092).

Anthony H. Cordesman, CYBER-THREATS, INFORMATION WARFARE, AND CRITICAL INFRASTRUCTURE PROTECTION: DEFENDING THE US HOMELAND (2002) (ISBN:0275974235).

Leigh Armistead, INFORMATION OPERATIONS (Jt. Forces Staff College and the NSA 2004) (ISBN:1574886991).

DOD REPORT TO CONGRESS: Military Power of the People’s Republic of China (2006), pp 35-36:

Exploiting Information Warfare

The PLA [Peoples Liberation Army] considers active offense to be the most important requirement for information warfare to destroy or disrupt an adversary’s capability to receive and process data.  Launched mainly by remote combat and covert methods, the PLA could employ information warfare preemptively to gain the initiative in a crisis. 

Specified information warfare objectives include the targeting and destruction of an enemy’s command system, shortening the duration of war, minimizing casualties on both sides, enhancing operational efficiency, reducing effects on domestic populations and gaining support from the international community.

The PLA’s information warfare practices also reflect investment in electronic countermeasures and defenses against electronic attack (e.g., electronic and infrared decoys, angle reflectors, and false target generators.)

Computer Network Operations.  China’s computer network operations (CNO) include computer network attack, computer network defense, and computer network exploitation.   The PLA sees CNO as critical to seize the initiative and achieve “electromagnetic dominance” early in a conflict, and as a force multiplier.  Although there is no evidence of a formal Chinese CNO doctrine, PLA theorists have coined the term “Integrated Network Electronic Warfare” to outline the integrated use of electronic warfare, CNO, and limited kinetic strikes against key C4 nodes to disrupt the enemy’s battlefield network information systems.  The PLA has established information warfare units to develop viruses to attack enemy computer systems and networks, and tactics and measures to protect friendly computer systems and networks.  The PLA has increased the role of CNO in its military exercises.  For example, exercises in 2005 began to incorporate offensive operations, primarily in first strikes against enemy networks.

 


 

X.      PAPER RESEARCH

 

SUGGESTED READING:

Eugene Volokh, Writing a Student Article, 48 J. Legal Educ. 247 (1998).

Eugene Volokh, ACADEMIC LEGAL WRITING: Law Review Articles, Student Notes, Seminar Papers, and Getting on Law Review, Second Edition (Foundation Press 2004) (ISBN:158778792X)

 


 

XI.     The War of Ideas (this section relates to 2006 course only)

 

REQUIRED READING:

George Packer, "KNOWING THE ENEMY: Can social scientists redefine the “war on terror”? The New Yorker (Dec. 18, 2006)

K. A. Taipale, "Seeking Symmetry in Fourth Generation Warfare: Information Operations in the War of Ideas," to be presented at the Bantle-Institute for National Security and Counterterrorism (INSCT) Symposium: "Challenges in the Struggle Against Violent Extremism: Winning the War of Ideas" at Syracuse University, Syracuse, NY, Mar. 29-30, 2006.

K. A. Taipale, "Information as Warfare: Disrupting Terrorist Networks" presented at the Yale Information Society Project 2005 conference, "The Global Flow of Information," at the Yale Law School on Apr. 1-3, 2005.

K. A. Taipale, "Transnational Intelligence and Surveillance: Security Envelopes, Trusted Systems, and the Panoptic Global Security State," draft prepared for presentation at the 'Beyond Terror: A New Security Agenda' Conference Watson Institute for International Studies, Brown University, Providence, RI, Jun. 3-4, 2005.

 

STATUTES:

USA PATRIOT ACT - Material Support
18 U.S.C. § 2339A. Providing material support to terrorists.
18 U.S.C. § 2339B. Providing material support or resources to designated foreign terrorist organizations.

U.S. Constitution, First Amendment

U.K. Prevention of Terrorism Bill 2005 (control orders)

 

ADDITIONAL READING:

Combating Terrorism Center (CTC) at West Point, Stealing Al-Qa'ida's Playbook (2006).

Combating Terrorism Center (CTC) at West Point, Harmony and Disharmony: Exploiting Al-Qa'ida's Organizational Vulnerabilities (2006).

 


 

XII.    VoIP: A Case Study

 

REQUIRED READING:

Declan McCullough, "Feds' wiretapping rules challenged in court," CNET news.com (Jan. 27, 2006).

Federal Communications Commission (FCC): CALEA Information http://www.fcc.gov/calea/

Center for Democracy and Technology: CALEA Information Page http://www.cdt.org/digi_tele/

Douglas Carlson, et al., CALEA: An Update and Open Discussion of the Legal, Technical, and Policy Issues Regarding This Controversial New Regulation (2006) [abstract].

Kevin Poulsen, Bill Would Clean Up Caller ID, Wired News (Apr. 6, 2006) (legislation to outlaw the use of caller ID spoofing techniques).

 

STATUTES:

Communications Assistance for Law Enforcement Act of 1994 (CALEA), Pub. L. No. 103-414, 108 Stat. 4279
47 U.S.C. §§ 1001-1010. Interception of Digital Communications.
47 U.S.C. § 1021. Telecommunications Carrier Compliance Payments.

 

ADDITIONAL READING:

Brief for Petitioners, American Council of Education v. Federal Communications Commission (FCC) (Jan. 26, 2006), available at http://www.educause.edu/ir/library/pdf/EPO0601.pdf

 


 

XIII.  Trade Secret Theft and Economic Espionage

 

REQUIRED READING:

CASEBOOK: David J. Loundy, COMPUTER CRIME, INFORMATION WARFARE, AND ECONOMIC ESPIONAGE, Carolina Academic Press (2003) (ISBN:0890891109) read:

Chapter 14, Trade Secret Theft, pp. 479-542 (US v. Farraj, Stampede v. May, Ford v. Lane, Rockwell v. DEV, VMI v. Autodesk, Pepsico v. Redmond, Earthweb v. Schlack), and

Chapter 15, Economic Espionage, pp. 543-590 (EEA 1996, US v. Krumrei, US v. Hsu / US v. Ho, US v. Martin).

 

STATUTES:

TRADE SECRETS ACT
18 U.S.C. § 1832. Theft of trade secrets.

ECONOMIC ESPIONAGE ACT
18 U.S.C. § 1831. Economic Espionage.

TELEPHONE RECORDS AND PRIVACY PROTECTION ACT of 2006 (making it illegal to use a false identity or other fraudulent means - "pretexting" - to gain access to an individual's phone records).

 

ADDITIONAL READING:

USDOJ Computer Crime and Intellectual Property Section (CCIPS), Economic Espionage Act Information.

John R. Wilke, "Two Silicon Valley Cases Raise Fears of Chinese Espionage," Wall St. J. (Jan. 15, 2003).

Melinda Liu, "High-Tech Hunger, The Goal: Make China a technology powerhouse-critics say by any means necessary. Inside Beijing's '863 program,'" Newsweek Intl. (Jan. 16, 2006).

Rachel Conrad, "Judge to hear motions in Silicon Valley economic espionage case," AP (Oct. 19, 2003).

Rachel Conrad, "Judge considers dismissal in Silicon Valley espionage case," AP (Oct. 21, 2003).

Rachel Conrad, "Economic Espionage Case to Go To Trial," AP (Nov. 10, 2003).

Compare "Hacker 'illwill' gets 2 year prison term," CNN.com (Jan. 30, 2006) with Keven Poulsen, "Microsoft Tricks Hacker into Jail," Wired News (Jan. 27, 2006).

Bill Gertz, "Enemies," Wash. Times (Sep. 18, 2006).

"Bugging the Boardroom," BBC News (Sep. 5, 2006).

David A. Kaplan, "Intrigue in High Places," Newsweek (Sept. 5, 2006) (To catch a leaker, investigators working for Hewlett-Packard acquired the home-phone records of its board of directors through pretexting).

Jordan Robertson, "HP Spy Probe Investigator Pleads Guilty," AP (Jan. 12, 2007) ("Federal prosecutors scored their first victory in the investigation of Hewlett-Packard's ill-fated boardroom spying probe ... when a low-level private investigator pleaded guilty to identity theft and conspiracy charges.")

US DOJ Press Release, "Former Chinese National Charged with Stealing Military Application Trade Secrets from Silicon Valley Firm to Benefit Governments of Thailand, Malaysia, and China," (Dec. 14, 2006) ("Third Foreign Economic Espionage Indictment in the United States Since the Enactment of Economic Espionage Act of 1996; Source Code Used for Military Combat Simulation and Banned for Export Without License").

US DOJ Press Release, "Two Men Plead Guilty to Stealing Trade Secrets from Silicon Valley Companies to Benefit China" (Dec. 14, 2006) ("First Conviction in the Country for Foreign Economic Espionage").

 

OPTIONAL BACKGROUND READING:

Hedieh Nasheri, ECONOMIC ESPIONAGE AND INDUSTRIAL SPYING (Cambridge Univ. Press 2005) (ISBN:0521543711).

 


 

XIV.   National Security

 

REQUIRED READING:

CASEBOOK: David J. Loundy, COMPUTER CRIME, INFORMATION WARFARE, AND ECONOMIC ESPIONAGE, Carolina Academic Press (2003) (ISBN:0890891109) read:

Chapter 16, National Security, pp. 591-684 (Snepp v. US, US v. HEINE, PHILLIPPI v. CIA, US v. MEGAHEY, In re All Matters Submitted to the FISC)

In re Sealed Cases, U.S. FISC of Review, 310 F.3d 717 (2002) (reversing In re All Matters Submitted to the FISA Court, 218 F. Supp. 2d 611 (U.S. FISC 2002) in the assigned text).

K. A. Taipale, Commentary (with James Jay Carafano), "Fixing Foreign Intelligence Surveillance," Wash. Times (Jan. 24, 2006).

K. A. Taipale, Whispering Wires and Warrantless Wiretaps: Data Mining and Foreign Intelligence Surveillance, N.Y.U. Rev. L. & Sec. No. VII, Suppl. Bull. on L. & Sec. (Jun. 2006).

K. A. Taipale, Written Testimony on Foreign Intelligence Surveillance Act Modernization Before the House Permanent Select Committee on Intelligence (HPSCI), U.S. House of Representatives, July 19, 2006.

ACLU v. NSA, (ED-Mich Aug. 17, 2006) (ruling that the NSA Terorist Surveillance Program was unconstitutional and illegal) (District Court ruling PDF) (On October 4, 2006, a unanimous three-judge panel of the Sixth Circuit Court of Appeals stayed the District Court's ruling while the the government's appeal is considered by the Court of Appeals, "Court Allows Warrantless Wiretapping During Appeal," AP (Oct. 5, 2006): "In the three-paragraph ruling, judges said that they balanced the likelihood an appeal would succeed, the potential damage to both sides, and the public interest.").

Kim Taipale, The Privacy Implications of Government Data Mining Programs, Testimony before the U.S. Senate Committee on the Judiciary, Washington, DC (Jan. 10, 2007). [PDF]

K. A. Taipale, "The Ear of Dionysus: Rethinking Foreign Intelligence Surveillance," 9 Yale J. L. & Tech. (forthcoming Spring 2007). 

 

STATUTES:

THE NATIONAL SECURITY ACT OF 1947
50 U.S.C. § 402

Presidential Decision Directive (PDD) 62, Combating Terrorism (22 May 1998)

FOREIGN INTELLIGENCE SURVEILLANCE ACT (FISA),
50 U.S.C. § 1801, et seq.

TITLE 18 > PART I > CHAPTER 37. ESPIONAGE AND CENSORSHIP
18 U.S.C. §§ 792-799.

18 U.S.C. § 798. Disclosure of classified information.

 

ADDITIONAL READING:

Foreign Intelligence Surveillance:

James Risen and Eric Lichtblau, "Bush Lets U.S. Spy on Callers Without Courts," N.Y. Times (Dec. 16, 2005).

Eric Lichtblau and James Risen, "Domestic Surveillance: The Program; Spy Agency Mined Vast Data Trove, Officials Report," N.Y. Times (Dec. 24, 2005).

Wikipedia Entry: NSA_warrantless_surveillance_controversy

Clayton, Mark, "US plans massive data sweep", The Christian Science Monitor (Feb. 09, 2006).

Shane Harris, "TIA Lives On," Nat'l J. TechDaily (Feb. 23, 2006).

Shane Harris, "NSA spy program hinges on state-of-the-art technology," Nat'l J. (Jan. 20, 2006).

Shane Harris, "NSA program broader than previously described," Nat'l J. (Mar. 17, 2006).

Shane Harris, "FISA's Failings," Nat'l J. (Apr. 8, 2006), republished as "Internet devices threaten NSA's ability to gather intelligence legally," GOVEXEC.com (Apr. 10, 2006).

Dan Eggen and Dafna Linzer, "Judge Rules Against Wiretaps," Wash. Post (Aug. 18, 2006).

Lara Jakes Jordan, "Outsiders To Monitor Wiretap Plan," AP (Jan. 17, 2007) ("Attorney General Alberto Gonzales said [authority to monitor and approve the NSA surveillance] has been given to the Foreign Intelligence Surveillance Court. ... 'As a result ... , any electronic surveillance that was occurring as part of the Terrorist Surveillance Program will now be conducted subject to the approval of the Foreign Intelligence Surveillance Court ... . According, ... the President has determined not to reauthorize the Terrorist Surveillance Program when the current authorization expires.')

Dan Eggen, "Court Will Oversee Wiretap Program," Washington Post (Jan. 18, 2007).

Eric Lichtblau and David Johnston, "Court to Oversee U.S. Wiretapping in Terror Cases," N.Y. Times (Jan. 18, 2007).

Dan Eggen, "Dismissal of Lawsuit Against Warrantless Wiretaps Sought," Washington Post (Jan. 25, 2007) ("A lawsuit challenging the legality of the National Security Agency's warrantless surveillance program should be thrown out because the government is now conducting the wiretaps under the authority of a secret intelligence court, according to court papers filed by the Justice Department yesterday.")

"Justice Wants Spying Lawsuit Dropped," Associated Press (Jan. 26, 2007) ("The ... administration sought ... to drop its appeal of a federal court ruling that concluded the government's domestic spying program is unconstitutional, saying the entire issue is moot since the surveillance now is monitored by a secret court.")

Disclosure of national security secrets:

Eric Lichtblau and James Risen, "Bank Data Sifted in Secret by U.S. to Block Terror," N.Y. Times (Jun. 23, 2006) (disclosing details of a secret but legal program to monitor terrorist financing).

Byron Calame, "Banking Data: A Mea Culpa," N.Y. Times (Oct. 22, 2006) (public editor of the Times withdraws his support for the decisiobn to publish details of the secret SWIFT monitoring program)

 

SEE ALSO:

Anthony H. Cordesman, CYBER-THREATS, INFORMATION WARFARE, AND CRITICAL INFRASTRUCTURE PROTECTION: DEFENDING THE US HOMELAND (2002) (ISBN:0275974235).

Markle Task Force on National Security in the Information Age, "Mobilizing Information To Prevent Terrorism: Accelerating Development Of A Trusted Information Sharing Environment," THIRD REPORT (2006).

Markle Task Force on National Security in the Information Age, "Creating a Trusted Network for Homeland Security," SECOND REPORT (Dec. 2003).

Markle Task Force on National Security in the Information Age, "Protecting America's Freedom in the Information Age," FIRST REPORT (Oct. 2002).

 

ALSO RELATED:

Kim Taipale and Kate Martin, director of the Center for National Security Studies, debate the NSA surveillance programs on WHHY Radio Times, National Public Radio (NPR) (May 16, 2006). [Listen to the show via RealAudio or Streaming MP3] (1 hr.)

Kim Taipale and Marc Rotenberg, director of the Electronic Privacy Information Center (EPIC), discussed the role of technology in government surveillance efforts in the Wall St. J. Online (May 16, 2006). Their exchange is linked here.

BACKGROUND READING:

Cliff Stoll, THE CUCKOO'S EGG (1989) (ISBN:0743411463).

 


 

XV.    PAPERS DUE [tbd] BY 5:00PM.

 


 

SUMMER VACATION

 


 

Registered Students note:

Login to NYLS LexisNexis Web Course
for updated Syllabus and Reading Assignments.

 


 

USEFUL LINKS:

Although this course does not require a technical background, we discuss technology and technical matters. Definitions for technical terms can be found at:

www.webopedia.com
www.techencyclopedia.com
www.whatis.com

 


 

SUBTEXT AND ADDITIONAL BACKGROUND FOR THE COURSE:

The subtext of this course is how the emergence of advanced information societies challenges certain existing theories of criminal justice and the underlying constructs of social control and individual freedom.

In particular, this course recognizes and examines how technology is helping accelerate the ongoing transformation of modern information-based societies from a notional Beccarian model of criminal justice based on punishment and deterrence of deviant individuals after they commit criminal acts to a Foucauldian (or Deleuzian) model of general social compliance through ubiquitous preventative surveillance and control through systems constraints.

In this emergent model, security is not achieved primarily by policing through arrest and prosecution but by risk management through surveillance, information exchange, auditing, communication, and classification.

Suggested optional background reading includes:

Cesare Beccaria, ON CRIME AND PUNISHMENT (1764) (ISBN:0915145979) (the Enlightment and criminal law reform).

Jeremy Bentham, THE PANOPTICON LETTERS (1787) (setting out a plan of construction and management for prisons and other institutional buildings in which the central authority can observe all prisoners without the prisoners being able to tell if they are being observed or not. Control is then maintained through the mental uncertainty that in itself becomes a crucial instrument of discipline). See also, Jeremy Bentham, An Introduction to the Principles of Morals and Legislation (The Collected Works of Jeremy Bentham) (ISBN:0198205163).

John Austin, THE PROVIDENCE OF JURISPRUDENCE DETERMINED (1832) (ISBN:0521447569) ("positive laws" versus moral principles).

Franz Kafka, THE TRIAL (1925) (ISBN:0805209999) (Joseph K. is arrested, tried and executed for an unspecified crime) (subtext examines the clash of traditional law based on morality with modern law based on rules).

B. Traven, DAS TOTENSCHIFF (1926); THE DEATH SHIP (tr. 1934) (ISBN:1556521103) (Kafkaesque journey of American sailor who has lost his identity papers):

Official: “You ought to have some papers to show who you are.”
Protagonist: “I do not need any papers. I know who I am.”
Official: “Maybe so. But others are also interested in who you are.”

George Orwell, NINETEEN EIGHTY-FOUR (1949) (ISBN:0899663680) (depicts a totalitarian society of the future, ruled by an omnipotent dictator called Big Brother. In this society, called Oceania, people’s thoughts and actions are continuously monitored.  The term Big Brother has subsequently been used to refer to any ruler or government that invades the privacy of its citizens).

Jacques Ellul, THE TECHNOLOGICAL SOCIETY (1964) (ISBN:0394703901) (postulating that human activity has been technicized -- rendered efficient -- and, thus, diminished in the process).

John Rawls, A THEORY OF JUSTICE (1971) (ISBN:0674000781) (justice as fairness, "veil of ignorance", the liberty principle, and the difference principle) (See also, Rawls, JUSTICE AS FAIRNESS: A Restatement (2001) (ISBN:0674005112).

Michel Foucault, DISCIPLINE AND PUNISH: THE BIRTH OF THE PRISON (1975) (ISBN:0679752552) (arguing that the abolition of torture and the emergence of the modern penitentiary have shifted the focus of punishment from the prisoner's body to his soul. Foucault invokes Bentham's panopticon as metaphor for the whole of modern "disciplinary" societies in which control is maintained through pervasive inclinations to observe and normalize).

David Burnham, THE RISE OF THE COMPUTER STATE (1983) (ISBN:0394514378) (early examiniation of the consequences of a modern computerized state in which information is easily aggregated and maintained by large bureaucracies).

BRAZIL (MCA-Universal 1985) (Terry Gilliam, dir.) (ASIN:0780022181) (Kafka meets Monty Python in a complex story reflecting on industrialization, terrorism, government control and bureaucracy, and technology gone wrong. A minor bureaucrat in a retro-future dystopia overcome by bureaucratic inefficiency tries to correct an administrative error and himself becomes an enemy of the state):

Protagonist: “Do you want to see my papers?”
Official: “No need, sir”
Protagonist: “But I could be anyone.”
Official: “No you couldn’t, sir, this is [the Ministry of] Information Retrieval.”

Gilles Deleuze, Postscript on Control Societies, L'Autre Journal, No. 1 (May 1990) (tranlated and reprinted in CTRL [SPACE] infra).

David Lyon, THE ELECTRONIC EYE (1994) (ISBN:0816625158) (how electronic surveillance orders society).

David Brin, THE TRANSPARENT SOCIETY (1998) (ISBN:0738201448) (arguing for "reciprical transparency," not secrecy, to counter ubiquitous surveillance technology).

Stephen M. Feldman, AMERICAN LEGAL THOUGHT FROM PREMODERNISM TO POSTMODERNISM (2000) (ISBN:0195109678) (tracing the evolution of American legal thought).

MINORITY REPORT (20th Century Fox 2002) (Steven Spielberg, dir.) (ASIN:B00005JL78) ("precogs" predict who will commit murder in the future thus allowing for their preemptive arrest).

CTRL [SPACE]: RHETORIC OF SURVEILLANCE FROM BENTHAM TO BIG BROTHER (Thomas Y. Levin, et al., eds., MIT Press, 2002) (ISBN:0262621657) (CTRL [SPACE] is a catalog of surveillance art, containing images and essays relating to surveillance. The catalog includes essays by philosophers Michel Foucault (The Eye of Power: A Conversation with Jean-Pierre Barou and Michelle Perrot), Paul Virilio (The Visual Crash), Jean Baudrillard (Telemorphosis), Gilles Deleuze (Postscript on Control Societies), Victor Burgin, and Slavoj Zizek, among others. CTRL [SPACE] also includes images from many well-known, and lesser known, Western artists in the emerging genre of surveillance art, including Sophie Calle, Diller + Scofidio, Dan Graham, Pierre Huyghe, Michael Klier, Rem Koolhaas, Bruce Nauman, Yoko Ono, Thomas Ruff, Julia Scher, Andy Warhol and Peter Weibel, among others.)

David Lyon, SURVEILLANCE AS SOCIAL SORTING (2003) (ISBN:0415278732) (the politics and ethics of categorization; surveillance as a means of creating and maintaining social differences by verifying identitties and assessing risk).

Wendy Hui Kyong Chun, CONTROL AND FREEDOM (2006) (ISBN:0262033321) (exploring the paradoxical narratives of control and freedom in a networked world).

 

 


[FN1] Parts of this introduction previously posted to Wikipedia:Cybercrime.

 

 

Image

 NYLS Logo

Image
 
Image Image
Image
Image