Showing posts with label crime. Show all posts
Showing posts with label crime. Show all posts

Tuesday, July 23, 2013

As the Nebuad Litigation Turns.... Mortensen v. Bresnan Communications

The litigation fallout from ISPs partnership with Nebuad continues.  Today's decision is the latest chapter out a lawsuit against a Montana ISP:
In 2008, Bresnan [Defendant ISP] entered into a temporary arrangement with advertising company NebuAd, Inc. Under the arrangement, in exchange for a share of NebuAd's advertising revenue, Bresnan [Defendant ISP] allowed NebuAd to place an appliance in its Billings, Montana, network. The appliance allowed NebuAd to gather information and create profiles of subscribers in order to target them with preference-sensitive advertising. Bresnan contends that it provided specific notice to consumers about the NebuAd trial and allowed individuals to opt out. Under a heading labeled "About Advanced Advertising," the company website provided detailed information about the trial. It also gave a list of thirteen frequently asked questions with corresponding answers that assured customers that no personally identifying information, such as first and last name, physical street address, email address, telephone numbers, or social security numbers would be collected. Plaintiffs contend that this notice was misleading and that consent was never obtained.
Plaintiffs brought suit Defendant ISP for violations of the Electronic Communications Privacy Act (dismissed previously), the Computer Fraud and Abuse Act, Montana state privacy law (dismissed previously), and trespass to chattels. 

Today's decision takes a contortious turn, not on Internet law (my normal beat), but on the Supremacy Clause of the U.S. Constitution and Defendant ISP's choice of law provision in the terms of service.  Today's case involves a Montana subscriber, an ISP doing business in Montana, an action that transpired in Montana, and a claim for a violation of a Montana law.  Pop Quiz: what state's law should apply??

Hint: The ISP is headquartered in New York and incorporated in Delaware.

Hint two:  The terms of service say that the law of New York applies (thus a cause of action based on Montana law would be bupkis).

Hint Three: The terms of service says that all claims shall be submitted to arbitration pursuant to the Federal Arbitration Act.

Okay, that seems unfair.  The case involves a Montana subscriber, an ISP's operations in Montana, and a violation that purportedly transpired in Montana.  Why should New York's law apply?? 

And when its seems this unfair, and when the customer has no choice in the matter, we call this a contract of adhesion, void as a matter of public policy.  That's what the lower court concluded, stating that Montana citizens had a constitutional right to trail by jury and access to the courts. Therefore, Plaintiff's litigation should go forward.

Not so fast, said the appeals court.  You see, there is this federal law called the Federal Arbitration Act, and it strongly favors arbitration. "Any general state-law contract defense, based in unconscionability or otherwise, that has a disproportionate effect on arbitration is displaced by the FAA."  If you are going to say that a contractual provision requiring arbitration is unconscionable because of some Montana law, then that state law is preempted - you lose.

Now comes the twister:  The Federal Arbitration Act just kicked the legs out from Montana saying its citizens have a right to a trail over arbitration.  Okay, what about the choice of law?  Does Montana law or New York law apply?  "Montana uses the Restatement (Second) of Conflict of Laws § 187(2), which finds a choice-of-law provision overcome where 
(1) Montana has a materially greater interest in the transaction than the state whose law was selected by the parties and 
(2) application of the selected state's law would be contrary to Montana's public policy."
Does Montana have a greater interest in this case?  Sure, says the court.  "The contract was received by the consumers in Montana as part of their Welcome Kit, and the contract governed services provided in Montana to Montana residents. The subject matter of the contract and performance of it took place almost entirely in Montana."

But here's the problem.  With the preemption of Montana law by the Federal Arbitration Act, there is no longer a public policy conflict with Montana law.  New York law favors arbitration; Montana law does not - Montana's disfavorance of arbitration got the boot.  Lacking a public policy conflict, the test for overriding a choice-of-law provision in a contract now fails.


Outside of the legal holding and the status of this litigation, the Court provides background on how another Nebuad litigation was resolved:
After NebuAd's temporary arrangement with Bresnan to gather information from the subscribers ended, a class of plaintiffs, including those involved in the present action, brought suit in the United States District Court for the Northern District of California against NebuAd and several Internet service providers who hosted NebuAd appliances, including Bresnan. Bresnan and the other providers moved to dismiss the action for lack of personal jurisdiction and failure to state a claim. The district court granted this motion finding personal jurisdiction lacking. Valentine v. NebuAd, Inc., No. C08-05113 TEH, 2009 WL 8186130, at *3-10 (N.D. Cal. Oct. 6, 2009). NebuAd became the sole defendant in that action and eventually reached a court-approved settlement with the plaintiffs.
According to Wikipedia, "Due to fallout following public and Congressional concern, NebuAd's largest ISP customers have all pulled out. NebuAd closed for business in the UK in August 2008, followed by the US in May 2009. NebuAd UK Ltd was dissolved in February 2010."

Monday, July 08, 2013

ART :: Sunberg, Danielle E., Reining in the Rogue Employee: The Fourth Circuit Limits Employee Liability Under the CFAA (June 27, 2013). American University Law Review

Sunberg, Danielle E., Reining in the Rogue Employee: The Fourth Circuit Limits Employee Liability Under the CFAA (June 27, 2013). American University Law Review, Vol. 62, No. 5, 2013. Available at SSRN: http://ssrn.com/abstract=2286316

Abstract: The Fourth Circuit’s opinion in WEC Carolina Energy LLC v. Miller reflects a growing trend among the courts to adopt a narrow code approach to employee liability under the Computer Fraud and Abuse Act. The case exacerbates the existing circuit split and reinforces the need for reconciling when an employee accesses a computer “without authorization.” While resolution from the judiciary remains remote, Congress is engaged in a lively debate over the proper interpretation of the term “without authorization.” Recent legislative proposals suggest that Congress has united in support of limiting liability for unauthorized access under the CFAA to the circumvention of technological barriers. Support for this restrictive interpretation signifies that until the ambiguity in the law is clarified, future undecided courts should follow in the Fourth Circuit’s footsteps and adopt the code approach to determine employee liability under the CFAA.

Friday, June 14, 2013

Does the Computer Fraud and Abuse Act violate the 10th Amendment to the US Constitution?

US v. Roque, Dist. Court, D. New Jersey 2013

Motion to Dismiss indictment denied.  From the Court Opinion:

Essentially, the Superseding Indictment[1] alleges that Felix Roque, who is the Mayor of West New York, and his son, Joseph Roque, sought, through violations of the Computer Fraud and Abuse Act ("CFAA"), to disable a website critical of Mayor Roque's administration and to harass persons associated with the website. Of course, alleging is not proving, and the defendants are clothed in the presumption of innocence. It would be premature and inappropriate at this stage to consider the truth, or not, of what is alleged. The current motions are directed to the sufficiency of the Indictment and its allegations as a matter of law.

Computer Fraud and Abuse Act

Defendants move to dismiss the Indictment. They assert that the CFAA, at least as applied here, impinges upon the authority of the State of New Jersey to regulate local conduct, and hence violates the Tenth Amendment to the United States Constitution. The Tenth Amendment provides that "powers not delegated to the United States by the Constitution, nor prohibited by it to the States, are reserved to the States respectively, or to the people." U.S. Const, amend. X. The government responds, in essence, that the CFAA is an exercise of a power "delegated to the United States by the Constitution" — specifically, by the Commerce Clause, which grants Congress the power to "regulate Commerce ... among the several States." U.S. CONST, art. I, § 8, cl. 3. See generally Treasurer of N.J. v. U.S. Dep't of Treasury, 684 F.3d 382, 413 (3d Cir. 2012) ("If Congress acts under one of its enumerated powers ... there can be no violation of the Tenth Amendment") (quoting United States v. Parker, 108 F.3d 28, 31 (3d Cir. 1997)).[3]

The CFAA was enacted pursuant to the Commerce Clause power. The CFAA charges here are explicitly tied to "protected computers," defined as computers "used in or affecting interstate or foreign commerce or communication." 18 U.S.C. § 1030(e)(2)(B). The Indictment alleges that each computer in question was a protected computer, i.e., a "computer used in and affecting interstate commerce." E.g., Indictment Count 1, ¶¶ 2(a) 86 (b); Count 2, ¶ 2. If facially adequate, such allegations are sufficient to call for a trial on the merits. See generally Costello v. United States, 350 U.S. 359, 363 (1956); United States v. Vitillo, 490 F.3d 314, 320 (3d Cir. 2007). The Indictment, in other words, need only allege a valid offense; it need not on its face negate the possibility of every application of the statute that might present a Constitutional problem. It is almost tautological that an allegation of interstate commerce, if proven, would establish the required nexus to interstate commerce. And having alleged interstate commerce, the government has taken on the burden of proving it. Nevertheless, because that is something of a legal conclusion, I will entertain briefly the defendants' contention that the allegations factually fall short of what is legally required to support federal jurisdiction. See generally Fed. R. CRIM. P. 12(b)(3)(B); United States v. Panarella, 277 F.3d 678, 685 (3d Cir. 2002) (Rule 12 challenge available "if the specific facts alleged in the charging document fall beyond the scope of the relevant criminal statute").

It is settled that the Commerce Clause power encompasses (1) the use of the channels of interstate commerce; (2) the instrumentalities of interstate commerce, or persons or things in interstate commerce; and (3) activities that substantially affect interstate commerce. See United States v. Lopez, 514 U.S. 549, 558-59 (1995); United States v. Bishop, 66 F.3d 569, 590 (3d Cir. 1995). The Indictment alleges facts and circumstances sufficiently broad to encompass proof of the requisite connection to interstate commerce under category (1) or category (2).

The inherent attributes of the internet, plus the physical locations of the computers in question here, suggest that the defendants used the "channels" or "instrumentalities" of interstate commerce, and that the relevant communications crossed state lines and hence were "in" interstate commerce. See United States v. MacEwan, 445 F.3d 237, 245 (3d Cir. 2006) (concluding that the "Internet is an instrumentality and channel of interstate commerce"); United States v. Trotter, 478 F.3d 918, 921 (8th Cir. 2007). The computers at issue here were all connected to the internet, and were used to communicate over the internet. The government argues, with some force, that the internet is the quintessential "instrumentality" of 21st century commerce. Thus the commerce power that once permitted the government to regulate intrastate activities of railroad cars would permit regulation here, even if the computer communications had been confined to this State. Cf. Southern R. Co. v. United States, 222 U.S. 20 (1911).[4] Even as applied to in-state activity, the CFAA has been upheld as a valid exercise of the Commerce Clause power. See, e.g., Trotter, 478 F.3d at 921; United States v. Mitra, 405 F.3d 492, 496 (7th Cir. 2005) (purely local attack on first-responder network upheld as violation of CFAA because the network operated over the electromagnetic spectrum and was an instrumentality of interstate commerce). Likewise, and in the alternative, the commerce power that once permitted the government to regulate persons and property actually transported across state lines permits regulation of the interstate communications here. Cf. Brooks v. United States, 267 U.S. 432 (1925) (upholding Dyer Act, which prohibits transportation of stolen vehicles across state lines); Hoke v. United States, 227 U.S. 308, 320 (1913) (Mann Act). Actual interstate communications between, for example, computers in New Jersey and "Go Daddy, an Internet Service Provider (ISP') located in Arizona," or "Weebly, a second ISP located in California" (Indictment Count 1, ¶ 1(h)), may demonstrate that the computers were used "in" interstate commerce. See Trotter, 478 F.3d at 921 (citing Mitra, 405 F.3d at 496).

We might hypothesize that the offense conduct involves purely local politics, or that the participants were personally indifferent to the interstate character of the internet or the location of the servers. In general — and certainly at this pretrial stage — I cannot say that this affects the issue. It may be just as true, for example, that a carjacker does not intend to commercially exploit a stolen car, or to drive it across state lines; nevertheless, because carjacking implicates interstate commerce, Congress has the power to prohibit it. See Bishop, 66 F.3d at 590; see also Trotter, 478 F.3d at 922,

Under these principles, I cannot grant defendants' motion to dismiss the Indictment. The allegations of the Indictment encompass a set of facts that, if proven, would make out a violation of the CFAA that would fall within the Commerce Clause power. Even if I accepted the defendants' Tenth Amendment reasoning, see n.3, above, I could not find at this early procedural stage that the government had boxed itself out of proving a valid federal case. The motion to dismiss the Indictment on these grounds is denied.


Monday, December 10, 2012

Safe Web Act extended until 2020

On Dec. 4th, President Obama signed into law HR 6131 extending the Safe Web Act until 2020.  The Safe Web Act was set to expire in 2013.  The Safe Web Act authorizes the Federal Trade Commission to engage in international enforcement efforts and information sharing.  Testifying before Congress in July, the FTC testified that
the agency has conducted more than 100 investigations with international components, such as foreign targets, evidence, or assets, and has filed more than 50 cases involving cross-border aspects since the Act's passage. The FTC has used the Act's provisions in many of these matters, and in related actions brought by other U.S. and foreign enforcement agencies. With these tools, the testimony states, the agency has stopped frauds costing American consumers hundreds of millions of dollars.
As the Internet is a global phenomenon, so is Internet fraud and crime.  In order to keep pace and enable international investigations and forensics, the Safe Web Act was necessary to authorize FTC activity.  Rep. Mary Bono Mack, sponsor of HR 6131, explained the origins of the Safe Web Act:
About a decade ago, the FTC began to highlight the growing problems it encountered in effectively combating Internet scams and fraud directed at American citizens by foreign operators, often times involving organized crime rings. By 2005, an estimated 20 percent of consumer complaints the FTC received involved fraud originating outside of the United States, costing American consumers hundreds of millions of dollars a year. In order to expand its ability to effectively fight online fraud, the FTC sent Congress legislative recommendations in 2005 seeking additional authorities.

As summarized by the FTC, the Safe Web Act achieves the following:
  • Broadening Reciprocal Information Sharing. (US SAFE WEB Act §§ 4(a), 6(a)) Allows the FTC to share confidential information in its files in consumer protection matters with foreign law enforcers, subject to appropriate confidentiality assurances. Similar to longstanding SEC, CFTC, and federal banking agency authority. Needed to allow the FTC to share information with foreign agencies to help them halt fraud, deception, spam, spyware and other consumer protection law violations targeting U.S. consumers. Also needed for the FTC to obtain, in return, foreign information required to halt such illegal practices.
  • Expanding Investigative Cooperation. (US SAFE WEB Act § 4(b) (adding FTC Act § 6(j))) Allows the FTC to conduct investigations and discovery to help foreign law enforcers in appropriate cases. Similar to longstanding SEC, CFTC, and federal banking agency authority. Needed to allow the FTC to obtain information for foreign agencies' actions to halt fraud, deception, spam, spyware, and other consumer protection law violations targeting U.S. consumers. Also needed to help the FTC to obtain, in return, foreign investigative assistance in FTC cases.
  • Obtaining More Information from Foreign Sources. (US SAFE WEB Act § 6(b)) Protects information provided by foreign enforcers from public disclosure if confidentiality is a condition of providing it. Similar to longstanding SEC and CFTC authority. Needed because, without it, some foreign law enforcers will not give the FTC information needed to halt fraud, deception, spam, and spyware.
  • Protecting the Confidentiality of FTC Investigations. (US SAFE WEB Act § 7) Safeguards FTC investigations in a defined range of cases by (1) generally protecting recipients of Commission CIDs from possible liability for keeping those CIDs confidential; (2) authorizing the Commission to seek a court order in appropriate cases to preclude notice by the CID recipient to the investigative target for a limited time; and (3) tailoring the mechanisms available to the Commission to seek delay of notification currently required by the Right to Financial Privacy Act ("RFPA") or the Electronic Communications Privacy Act ("ECPA"), to better fit FTC cases. Similar to longstanding RFPA, ECPA, and securities law provisions. Needed to prevent notice to investigative targets that are likely to destroy evidence or to move assets offshore or otherwise conceal them, precluding redress to consumer victims.
  • Protecting Certain Entities Reporting Suspected Violations of Law. (US SAFE WEB Act § 8) Protects a limited category of appropriate entities from liability for voluntary disclosures to the FTC about suspected fraud or deception, or about recovery of assets for consumer redress. Similar to longstanding protections for financial institutions making disclosures of suspected wrongdoing to federal agencies. Needed because liability concerns discourage third-party businesses from alerting the FTC to suspected law violations or recoverable assets.
  • Allowing Information Sharing with Federal Financial and Market Regulators. (US SAFE WEB Act § 10) Adds the FTC to RFPA's list of financial and market regulators allowed to readily share appropriate information. The list already includes the SEC and the CFTC. Needed to help the FTC track proceeds of fraud, deception, or other illegal practices sent through U.S. banks to foreign jurisdictions, so they can be recovered and returned to consumer victims.
  • Confirming the FTC's Remedial Authority in Cross-Border Cases. (US SAFE WEB Act § 3) Expressly confirms: 1) the FTC's authority to redress harm in the United States caused by foreign wrongdoers and harm abroad caused by U.S. wrongdoers; and 2) the availability in cross-border cases of all remedies available to the FTC, including restitution. Needed to avoid spurious challenges to jurisdiction in FTC cases and to encourage the full range of remedies for U.S. consumer victims in foreign courts
  • Enhancing Cooperation Between the FTC and DOJ in Foreign Litigation. (US SAFE WEB Act § 5) Permits the FTC to cooperate with DOJ in using additional staff and financial resources for foreign litigation of FTC matters. Needed because, without additional resources to freeze foreign assets and enforce U.S. court judgments abroad, fraudsters targeting U.S. consumers can more readily use the border as a shield against law enforcement.
  • Clarifying FTC Authority to Make Criminal Referrals. (US SAFE WEB Act § 4(b) (adding FTC Act § 6(k))) Expressly authorizes the FTC to make criminal referrals for prosecution when violations of FTC law also violate U.S. criminal laws. Similar to existing FTC authority to provide information to criminal authorities, a narrow express criminal referral provision in the FTC Act, and an SEC provision. Needed because foreign agencies that address consumer fraud and deception as a criminal (not civil) law enforcement issue would be more willing to share information if FTC has express authority to share information with criminal authorities.
  • Providing for Foreign Staff Exchange Programs. (US SAFE WEB Act § 9) Provides for foreign staff exchange arrangements between the FTC and foreign government authorities, and permits the FTC to accept reimbursement for its costs in these arrangements. Needed to improve international law enforcement cooperation in crossborder matters.
  • Authorizing Expenditure of Funds on Joint Projects. (US SAFE WEB Act § 4(b) (adding FTC Act § 6(l)), 4(c)) Authorizes the FTC to expend appropriated funds, not to exceed $100,000 annually, toward operating expenses and other costs of cooperative cross-border law enforcement projects and bilateral and multilateral meetings. Similar to SEC authority. Needed to allow the FTC to help support valuable international cooperative organizations and projects such as the website or consumer education programs of the International Consumer Protection and Enforcement Network (ICPEN) that foster the FTC's mission.
  • Leveraging FTC's Resources Through Reimbursement, Gift Acceptance, and Voluntary and Uncompensated Services (US SAFE WEB Act § 11) Authorizes the FTC to accept reimbursement for providing assistance to law enforcement agencies in the U.S. or abroad, and to accept gifts and voluntary services in aid of the agency's mission and consistent with ethical constraints. Similar to the authority of numerous regulatory agencies, including the SEC and the CFTC, and of the FTC and DOJ in the antitrust context, to accept reimbursements from foreign counterparts. Needed to assure that in appropriate circumstances a foreign agency bears the costs of FTC efforts on their behalf, and to enable the FTC to employ volunteers as our Canadian counterparts have done successfully for years.

Wednesday, September 14, 2011

Computer Fraud and Abuse Act claim alleged with sufficient particularity

MOBILE MARK, INC. v. PAKOSZ, Dist. Court, ND Illinois 2011

Procedure: Defendant's Motion to Dismiss Plaintiff's Computer Fraud and Abuse Claim is denied

Background: Plaintiff, a designer and seller of commercial antenna products, sued one of its former engineers, Defendants, for violation of the federal Computer Fraud and Abuse Act ("CFAA") and other statutes (this blog focuses on federal internet law).In brief, the amended complaint alleges that, before leaving Plaintiff to work for Hascall-Denke, Pakosz accessed Plaintiff's computer system and copied proprietary information to a laptop that Plaintiff had loaned him. Pakosz allegedly transferred the proprietary data to a number of external storage devices, and then installed and repeatedly ran a "Window Washer" program on the laptop to delete files and other data in order to conceal his activities. According to Plaintiff, Pakosz turned its trade secrets over to Hascall-Denke, which used the information to manufacture knock-off versions of Plaintiff's antennas.
Rule: "To state a civil claim for violation of the CFAA, a plaintiff must allege: 1) dama ge or loss; 2) caused by; 3) a violation of one of the substantive provisions set forth in § 1030(a); and 4) conduct involving one of the factors in § 1030(c)(4)(A)(i)(I)-(V)." Cassetica Software, Inc. v. Computer Sciences Corp., No. 09 C 0003, 2009 WL 1703015, at *3 (N.D. Ill. June 18, 2009)

Analysis:
 
First, defendants object that "Mobile Mark has not alleged any particular file or document that Pakosz allegedly accessed without authorization." They also argue that Mobile Mark has failed to allege that Pakosz lacked permission to copy or transfer files to his Mobile-Mark laptop Defendants are incorrect in assuming that Plaintiff's CFAA claim must be set forth with such particularity. The complaint provides defendants with ample notice of the basis for Mobile Mark's CFAA claim.
 
Defendants also argue that Count II must be dismissed because Mobile Mark has failed to allege that the files on which the claim is based "involved interstate commerce."  The portion of the CFAA on which Plaintiff relies simply does not require any showing that the files at issue had anything to do with interstate commerce
 
Finally, Defendant argues that Plaintiffs fails to allege that it suffered any loss in connection with Pakosz's alleged activity.  Plaintiff asserts that it was forced to perform a forensic computer analysis in order to investigate Pakosz's alleged wrongdoing, and that it lost more than $5,000 due to Pakosz's improper use of its data. Further, Plaintiff alleges that, as a result of defendants' actions, it has suffered a loss of "customers, goodwill, sales, and business opportunities." In short, the allegations in Mobile Mark's complaint are not deficient in any of the respects asserted by defendants.

Speculative Future Losses Insufficient for CFAA Claim

GENERAL SCIENTIFIC CORP. v. SHEERVISION, INC., Dist. Court, ED Michigan 2011

Procedure:  Defendant's Motion to Dismiss Computer Fraud and Abuse Act Claim

Background:"General Scientific Corp. and SheerVision, Inc. both participate in the highly competitive market for surgical loupe products, which includes telemicroscopes, lights, video cameras, and related accessories used by surgeons, dentists, and dental technicians. In 2007, believing that SheerVision had engaged in importation and sale of goods infringing on Plaintiff's patents, Plaintiff initiated an action before the International Trade Commission ("ITC"). The ITC action settled: Plaintiff covenanted not to sue, and SheerVision promised to cease importation and sale of the allegedly infringing goods.


"Since early 2010, however, SheerVision has allegedly undertaken to poach members of Plaintiff's sales staff and use their knowledge of Plaintiff's business contacts and practices to compete against Plaintiff in the market for surgical loupe devices, some of which allegedly violate Plaintiff's patents. According to Plaintiff, SheerVision has hired five of Plaintiff's past employees, including Caouette. In particular, Plaintiff alleges that SheerVision and Caouette used a computer issued by Plaintiff and Caouette's access to Plaintiff's email servers to gather sales contacts, customer lists, pricing information, and copyrighted marketing material for use in SheerVision's commercial pursuits.


"Plaintiff filed suit against Defendants on October 6, 2010. Before the Court is a motion by Defendants to dismiss Counts I through V of Plaintiff's complaint or, in the alternative, for a more definite statement as to those same Counts"

Analysis: "Defendants move to dismiss Count III of Plaintiff's complaint, an alleged violation of the Computer Fraud and Abuse Act ("CFAA"), 18 U.S.C. § 1030, on the ground that Plaintiff failed to sufficiently plead the damages required by the CFAA: namely, "loss . . . aggregating at least $5,000 in value." 18 USC § 1030(c)(4)(A)(i)(I)

"The CFAA defines "loss" as "any reasonable cost to any victim, including the cost of responding to an offense, conducting a damage assessment, and restoring the data, program, system, or information to its condition prior to the offense, and any revenue lost, cost incurred, or other consequential damages incurred because of interruption of service." 18 U.S.C. § 1030(e)(11) (emphasis added). Moreover, to be "plausible" under Twombly, Plaintiff must "plead[] factual content that allows the court to draw the reasonable inference that the defendant is liable for the misconduct alleged." Ashcroft v. Iqbal, 129 S. Ct. 1937, 1949 (2009). Count III of Plaintiff's CFAA claim fails under both the statutory definition of "loss" and Twombly.

"First, Plaintiff has failed to allege specific facts suggesting the plausibility of damages required under the CFAA. Plaintiff merely "believes that it will incur" costs exceeding $5,000. (Pl.'s First Am. Compl. ¶ 19.) A mere belief in purported future damages is insufficient to survive a Rule 12(b)(6) motion because a complaint "requires more than labels and conclusions, and a formulaic recitation of the elements of a cause of action will not do." Twombly, 550 U.S. at 555, 127 S. Ct. at 1964-65. Plaintiff has not alleged specific facts suggesting that it incurred at least $5,000 in losses as a result of Defendants' alleged activity.

"Second, to the extent Plaintiff has attempted to bolster its pleading through its Response to Defendants' Motion to Dismiss and the affidavit of Gregory S. Smith, Plaintiff demonstrates a misinterpretation of the "loss" standard under the CFAA, further undermining its claim. The crux of Plaintiff's response rests on the contention that Defendants' conduct has caused at least $5,000 in losses through usurped sales opportunities. (Pl.'s Resp. to Mot. to Dismiss 6-7.) Lost sales and profits per se are not the measure of loss under the CFAA, however. As the statutory language makes clear, "losses" under the CFAA are limited to costs incurred and profits lost as a direct result of interrupted computer service. 18 U.S.C. § 1030(e)(11) (listing applicable types of loss incurred "because of interruption of service"). The CFAA's damage requirement is not concerned with sales lost through the use of the information accessed. See, e.g., Nexans Wires S.A. v. Sark-USA, Inc., 166 Fed. App'x. 559, 562-63 (2d Cir. 2006) ("the plain language of the statute treats lost revenue as a different concept from incurred costs, and permits recovery of the former only where connected to an `interruption in service'"). The CFAA only covers lost revenue if the loss occurred as a result of interrupted service. Id. 

Monday, July 11, 2011

Time Spent Investigating Intrusion Counts Towards $5000 CFAA Damages Threshold

ANIMATORS AT LAW, INC. v. CAPITAL LEGAL SOLUTIONS, LLC Dist Court EDVA May 10, 2011

PROCEDURE: Defendant Motion for Summary Judgment on Grounds Plaintiff Has Failed to Meet $5000 Damage Threshold Required by Computer Fraud and Abuse Act (CFAA)


RULE: "The CFAA prohibits, inter alia, any person from "intentionally accessing] a computer without authorization or exceeding] authorized access, and thereby obtaining]... information from any protected computer." 18 U.S.C. § 1030(a)(2). In addition to setting forth criminal penalties for violations, the statute provides that "[a]ny person who suffers damage or loss by reason of a violation of this section may maintain a civil action against the violator." § 1030(g). To maintain a civil action under the CFAA, however, a plaintiff must show that the alleged violation "caused ... loss ... aggregating at least $5,000 in value." 18 U.S.C. § 1030(c)(4)(A)(i).[11] The CFAA specifies that a qualifying "loss" under the statute
means any reasonable cost to any victim, including [i] the cost of responding to an offense, [ii] conducting a damage assessment, and [iii] restoring the data, program, system, or information to its condition prior to the offense, and [iv] any revenue lost, cost incurred, or other consequential damages incurred because of the interruption of service[.]"
ISSUE: What Losses Count Towards $5000 Threshold 

"The Fourth Circuit in A.V. ex rel. Vanderhye v. iParadigms, LLC, 562 F.3d 630, 646 (4th Cir. 2009), considered the types of damages that may qualify as CFAA losses. There, the defendant operated a plagiarism detection service known as "Turnitin," where students submitted papers for their classes online to Turnitin, and papers were automatically compared with other papers to determine the likelihood of plagiarism. In a suit by students against the defendant for copyright infringement, the defendant counterclaimed that one of the plaintiff students violated the CFAA by submitting papers using another student's user name and password. Upon learning that this student had registered and submitted papers on behalf of another, the defendant became concerned that a technical glitch allowed the intrusion to occur and investigated the matter thoroughly, only to discovery that the plaintiff student had simply used another student's Turnitin user name and password found on the internet. Although the plaintiff student in issue conceded that his use was unauthorized for CFAA purposes, inasmuch as the conduct violated the Turnitin terms of service, he argued that the defendant's time spent investigating the incident did not qualify as a CFAA loss. The district court agreed, dismissing the counterclaim, but the Fourth Circuit reversed, holding that that the definition of"loss" under the CFAA was "broadly worded" and "plainly contemplates ... costs incurred as part of the response to a CFAA violation, including the investigation of an offense." Id. at 645-46. In remanding, the court "expressed] no opinion as to whether... the alleged consequential damages were reasonable, sufficiently proven, or directly causally linked to [the] alleged CFFA violation." Id. at 646.


After iParadigms, the district court in Yessin, 686 F. Supp. 2d 642, further elaborated on the requirements for qualified CFAA losses. The plaintiff in Yessin sought three types of damages for defendant's unauthorized access of plaintiffs email accounts and website: (i) expenses for establishing new email addresses and a new website, (ii) lost "billable time" spent investigating and responding to the offense rather than conducting business, and (iii) lost revenue from failing to win a business opportunity. Id. at 648. Yessin held that "lost revenue damages may qualify as losses under the CFAA when they result from time spent responding to an offense," but further lost revenue or consequential damages—such as the losses associated with a missed business opportunity—are only recoverable if they were "incurred because of interruption of service." Id. at 654 (citing § 1030(e)(11);iParadigms,562 F.3d at 646Nexans Wires S.A. v. Sark-USA, Inc., 166F. App'x 559, 562(2d Cir. 2006) ("[T]he plain language of the statute treats lost revenue as a different concept from incurred costs, and permits recovery of the former only where connected to an `interruption in service.'")). Thus, Yessin held that only the first two types of losses identified by the plaintiff in that case—namely (i) expenses for the new email addresses and website, and (ii) the time spent responding to the offense—were eligible to be considered as losses for CFAA purposes."

ANALYSIS:  "Here, unlike in Yessin, the costs reported by Animators create a triable issue of fact as to well over $5,000 in qualified CFAA losses. Just as in iParadigms, where the CFAA claimant believed that its system had been compromised and went to great lengths to investigate the intrusion, so, too, did Animators come to suspect that its confidential information had been accessed without authorization by former employees and accordingly, took action to investigate and respond to the incident.[14] To determine whether unauthorized access infact occurred and the extent of such access, Animators had the laptop analyzed by IDS. Although defendants contend that such an extensive analysis was neither reasonably foreseeable nor necessary, a reasonable jury might well disagree and conclude otherwise. "

HOLDING:  Motion for Summary Judgment Dismissed

Monday, November 29, 2010

The Threat from Within - US v Fowler, SDFL 2010

The security vendor-phobe at the head of the conference bangs on the podium with his shoe declaring that “The greatest threat comes from within! (buy our product for your network’s salvation).”

Fear as a marketing strategy can never be underestimated. Particular when the fear is of the misunderstood. Media helps stoke the flames of fear-marketing with stories of fired or disgruntled IT staff who reportedly effectuate their revenge on former employers by bricking systems.

When hyperbolized threats-from-within transform into actual damage, the victim can be left helpless, unable to access crucial IT and unable to have continuity of operation. In today’s case, after being fired, Defendant allegedly changed the passwords of her former employer’s employee’s accounts and changed the password of the firewall. The scorned company contacted an external IT contractor who was able to hack in and open up the employee accounts. The firewall, however, had pretty much become a big expensive paperweight that had to be replaced.

The Defendant was convicted under the Computer Fraud and Abuse Act. Count One, the conviction challenged in this case, was pursuant to 18 U.S.C. § 1030(a)(5)(A):

Whoever... knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer... shall be punished...

The Defendant challenges her conviction and raises two questions of law: (1) Is a computer on the Internet a ‘protected computer’ pursuant to the Computer Fraud and Abuse Act; and (2) can the salaries of employees that rebuild the system be counted as a part of ‘damages.’

What is a ‘protected computer’ under the CFAA? Is it a computer with good virus protection or behind a firewall (even if the firewall has been Bricked?). According to 18 USC § 1030(e)(2)(B),

“the term “protected computer” means a computer— which is used in or affecting interstate or foreign commerce or communication, including a computer located outside the United States that is used in a manner that affects interstate or foreign commerce or communication of the United States;

In other words, a computer on the Internet is a “Protected Computer.” Lots of Courts agree on this point: US v Trotter, No 05-4202 (8th Cir. Feb. 23, 2007) (Non-profit's computers are engaged in interstate communications connect to Internet); U.S. v. Walters, 182 Fed. Appx. 944, 945 (11th Cir. 2006) (stating that the internet is an instrumentality of interstate commerce); US v. Fowler, Case No. 8:10-cr-65-T-24 AEP (MDFL Oct. 25, 2010) (computer connected to Internet is 'protected computer'); Multiven, Inc. v. Cisco Systems, Inc., 2010 WL 2889262, at *3 (N.D. Cal. July 20, 2010) (finding that a computer connected to the internet was a protected computer); National City Bank, N.A. v. Prime Lending, Inc., 2010 WL 2854247, at *4 n.2 (E.D. Wash. July 19, 2010) (stating that "any computer connected to the internet is a protected computer"); Expert Janitorial, LLC v. Williams, 2010 WL 908740, at *8 (E.D. Tenn. Mar. 12, 2010); Dedalus Foundation v. Banach, 2009 WL 3398595, at *2 (S.D.N.Y. Oct. 16, 2009) (noting that courts have "found that computers that access the Internet through programs such as email qualify as protected computers"); Continental Group, Inc. v. KW Property Management, LLC, 622 F. Supp.2d 1357, 1370 (S.D. Fla. 2009) (noting that a connection to the internet affects interstate commerce or communication).

Second, in order to be convicted under this provision, a defendant must have inflicted at least $5000 worth of damage (this was a notorious problem for Clifford Stoll’s who detected a $0.75 accounting discrepancy, and thus could not garner federal attention, even thought the hacker’s breadcrumbs indicated international espionage of highly sensitive military information. See Clifford Stoll, The Cuckoo’s Egg (Pocket 1990) (a great beach vacation read)). According to the Court, the Defendant managed to inflict $27K in damages, which included $11K for the salaries of all of the company’s staff and all of the company’s contractors who had to put the network back together again. The Court noted the following accounting:

  • $3,941.27 amount paid to IT Contractor for responding to and correcting the damage to the computers
  • $2,501.20 amount attributed to CEO's time spent responding to and correcting the damage to the computers
  • $2404 amount attributed to [employee A’s] time spent responding to and correcting the damage to the computers
  • $1,590.68 amount attributed to [employee B’s] time spent responding to and correcting the damage to the computers
  • $730.72 amount attributed to CFO's time spent responding to and correcting the damage to the computers
  • $11,167.87 TOTAL

The Court rejected Defendant’s argument that time spent by salaried employees cannot be considered a loss under the statute, noting substantial precedent to the contrary:

NCMIC Finance Corp. v. Artino, 638 F. Supp.2d 1042, 1065 (S.D. Iowa 2009) (finding that the company's chief information officer's time spent investigating the matter was appropriately considered a loss under the statute); U.S. v. Larsen, 190 Fed. Appx. 552, 553 (9th Cir. 2006)(stating that losses "include[] the time that the victim's salaried employees spend responding to the unauthorized intrusion"); U.S. v. Millot, 433 F.3d 1057, 1061 (8th Cir. 2006)(recognizing that hours spent by employees responding to an intrusion constitute losses under the statute, because their time could have been spent on other duties); U.S. v. Middleton, 231 F.3d 1207, 1214 (9th Cir. 2000)(finding that a salaried employee's time spent responding to an intrusion is a loss under the statute, because "[t]here is no basis to believe that Congress intended the element of `damage' to depend on a victim's choice whether to use hourly employees, outside contractors, or salaried employees to repair the . . . harm to a protected computer").”
Engaging in some simple math, the Court notes that $11,000 damages alleged is greater than the $5000 threshhold required, and therefore denied Defendants Motion to Acquittal.

US v. Fowler, Dist. Court, MD Florida 2010

Wheel of Morality Turn, Turn, Turn; Tell us what lesson we should learn: Humpty Dumpty was Pushed!

[DISCLAIMER]

Tuesday, December 08, 2009

It's Safe to be a Dog on the Internet Again: Lori Drew Prosecution Terminated

"On the Internet, no one knows whether you're a dog." Of course, if you are a dog, and you are fibbing about it, according to the US Attorneys Office out in California you're a felon and should be sent to the dog pound. Fortunately, there's a new dog in town who seems to be howling a different tune.

Bad facts make for bad law. The unfortunate alleged facts of this case involved fibbing about actual identities, playing with a young girl's emotions, and the girl's eventual suicide. As recited by the District Court

The Indictment included the following allegations (not all of which were established by the evidence at trial). Drew entered into a conspiracy in which its members agreed to intentionally access a computer used in interstate commerce without (and/or in excess of) authorization in order to obtain information for the purpose of committing the tortious act of intentional infliction of emotional distress upon Megan Meier. Megan was a 13 year old girl who had been a classmate of Drew’s daughter Sarah. Pursuant to the conspiracy, on or about September 20, 2006, the conspirators registered and set up a profile for a fictitious 16 year old male juvenile named “Josh Evans” on the www.MySpace.com website, and posted a photograph of a boy without that boy’s knowledge or consent. Such conduct violated MySpace’s terms of service. The conspirators contacted Megan through the MySpace network (on which she had her own profile) using the Josh Evans pseudonym and began to flirt with her over a number of days. On or about October 7, 2006, the conspirators had “Josh” inform Megan that he was moving away. On or about October 16, 2006, the conspirators had “Josh” tell Megan that he no longer liked her and that “the world would be a better place without her in it.” Later on that same day, after learning that Megan had killed herself, Drew caused the Josh Evans MySpace account to be deleted.

These unfortunate facts led to a large public emotional outcry and pressure for prosecution.

Lacking a specific law that the defendant violated, the US attorney distorted the Computer Fraud and Abuse Act. The Computer Fraud and Abuse Act was designed to smack hackers who gain unauthorized access to computers and networks. CFAA prosecutions involve individuals who break through computer security or who go beyond signs that say "None Shall Pass."

According to the prosecutor, Defendant violated the CFAA, not through hacking, not through cracking, not by defeating a security system. No, defendant violated the CFAA by violating MySpace's terms of service. Defendant (a) lied about Defendant's age, (b) lied about defendant's name and (c) uploaded without permission a picture of someone else. By violating the TOS, prosecutor argued, Defendant had never actually gained permissive use of the computer system. Therefore, Defendant's use of MySpace was unauthorized and constituted a criminal violation of the Computer Fraud and Abuse Act.

The prosecutor's argument was met by a backlash of individuals and experts who claimed that, based on the prosecutors argument, anyone who has violated a terms of service of any site in any way was a criminal. Use a pseudonym, you're a criminal. Lie about your age, you're a criminal. Upload a fake address, you're a criminal. Indeed, many of the actions individuals regularly take in order to protect their identity and privacy would equally make them a criminal.

After a drawn-out legal proceeding, the district court finally agreed. The US Attorney's crow barring of the CFAA to meet the facts of this case would have produced bad law. In the words of the court,

Treating a violation of a website's terms of service, without more, to be sufficient to constitute “intentionally access[ing] a computer without authorization or exceed[ing] authorized access” would result in transforming section 1030(a)(2)(C) into an overwhelmingly overbroad enactment that would convert a multitude of otherwise innocent Internet users into misdemeanant criminals. . . .

One need only look to the MSTOS terms of service to see the expansive and elaborate scope of such provisions whose breach engenders the potential for criminal prosecution. Obvious examples of such breadth would include: 1) the lonely-heart who submits intentionally inaccurate data about his or her age, height and/or physical appearance, which contravenes the MSTOS prohibition against providing “information that you know is false or misleading”; 2) the student who posts candid photographs of classmates without their permission, which breaches the MSTOS provision covering “a photograph of another person that you have posted without that person's consent”; and/or 3) the exasperated parent who sends out a group message to neighborhood friends entreating them to purchase his or her daughter's girl scout cookies, which transgresses the MSTOS rule against “advertising to, or solicitation of, any Member to buy or sell any products or services through the Services.” However, one need not consider hypotheticals to demonstrate the problem. In this case, Megan (who was then 13 years old) had her own profile on MySpace, which was in clear violation of the MSTOS which requires that users be “14 years of age or older.”No one would seriously suggest that Megan's conduct was criminal or should be subject to criminal prosecution.

. . . . .

In sum, if any conscious breach of a website's terms of service is held to be sufficient by itself to constitute intentionally accessing a computer without authorization or in excess of authorization, the result will be that section 1030(a)(2)(C) becomes a law “that affords too much discretion to the police and too little notice to citizens who wish to use the [Internet].”

On August 28, 2009, with the above opinion, the District Court dismissed the US Attorney's prosecution. On November 20, 2009, the US Attorney's Office filed papers with the 9th Circuit Court of Appeals indicating it will not appeal its case against Lori Drew.

Perhaps, now that we have a more technologically sophisticated administration that can appreciate how this prosecution would have led to bad implications, the US Attorney thought better of its prosecution. In the words of Prof. Orin Kerr, "The case should have never been filed, and it was a stretch from the beginning."

This doesn't change the unfortunate facts of this case; but it avoids a potentially unfortunate legal precedent.

Wednesday, October 29, 2008

The New-Old Internet Services Child Explotation Reporting Requirement

Title V is where Sen. McCain's SAFE Act was assimilated into Biden's Protect Act. This language was not part of the Biden bill, and did not go through Congressional hearings. The Center for Democracy and Technology commented on the inclusion of this provision by stating

Among the most problematic provisions in S.519 – which was never publicly debated by any committee–is the outsourcing of significant law enforcement investigative functions to the National Center for Missing & Exploited Children (NCMEC), which as a non-governmental entity operates outside of the core constitutional and legal protections that govern (or should govern) our criminal justice system (such as the 4th Amendment, the Privacy Act, the Freedom of Information Act, etc.). Although NCMEC makes valuable contributions in the child safety arena, the growing trend in Congress to outsource law enforcement functions to a nominally private group—without any serious oversight or procedural protections— takes us down a dangerous path. [CDT]
Before exploring what Title V does, note first that Internet services already have a reporting obligation. In 1998, Congress passed the Child Protection and Sexual Predator Punishment Act which, in part, requires Internet services which become aware of child pornography to report this information to the National Center for Missing and Exploited Children. Note that this does not require Internet services to go out and affirmatively police their systems. It only states that when Internet services gain actual knowledge, then action must be taken. 42 U.S.C. § 13032(e)
Reports can be made to

The Cyber Tip Line
National Center for Missing and Exploited Children
www.cybertipline.com
1-800-843-5678

It's not immediately apparent what is the new McCain SAFE Act Provisions bring to the table, so to elucidate, here is a side-by-side, comparing the new legislation to the old statute (it's a bit of a hack job but the language parallels pretty well. Old language is on the left in Green. New language is on the right; new and different language is highlighted in red) - well it was suppose to be a side-by-side but Glogger is refusing to render it correctly, so let's try a different way - the Cybertelecom website will have this as a side-by-side:

  • Definitions

    • Old Language 42 USC 13032

      • (a) Definitions In this section—

        (1) the term “electronic communication service” has the meaning given the term in section 2510 of title 18 ; and

        (2) the term “remote computing service” has the meaning given the term in section 2711 of title 18 .

    • New Language 18 USC 2258A

      • n/a

  • Who has the Duty

    • Old Language 42 USC 13032

      • (b) Requirements (1) Duty to report.— Whoever, while engaged in providing an electronic communication service or a remote computing service to the public, through a facility or means of interstate or foreign commerce,

    • New Language 18 USC 2258A

      • (a) Duty To Report- (1) IN GENERAL- Whoever, while engaged in providing an electronic communication service or a remote computing service to the public through a facility or means of interstate or foreign commerce,

  • What triggers the Duty

    • Old Language 42 USC 13032

      • obtains knowledge of facts or circumstances

        from which a violation of section 2251 , 2251A , 2252 , 2252A , 2252B , or 2260 of title 18 , involving child pornography (as defined in section 2256 of that title), or a violation of section 1466A of that title, is apparent,

        shall, as soon as reasonably possible, . . . . .


    • New Language 18 USC 2258A

      • obtains actual knowledge of any facts or circumstances

        described in paragraph (2)

        shall, as soon as reasonably possible--

        . . . . .

        `(2) FACTS OR CIRCUMSTANCES- The facts or circumstances described in this paragraph are any facts or circumstances from which there is an apparent violation of--

        `(A) section 2251, 2251A, 2252, 2252A, 2252B, or 2260 that involves child pornography; or

        `(B) section 1466A.

  • Monitoring

    • Old Language 42 USC 13032

      • (e) Monitoring not required Nothing in this section may be construed to require a provider of electronic communication services or remote computing services to engage in the monitoring of any user, subscriber, or customer of that provider, or the content of any communication of any such person.

    • New Language 18 USC 2258A

      • `(f) Protection of Privacy- Nothing in this section shall be construed to require an electronic communication service provider or a remote computing service provider to--

        `(1) monitor any user, subscriber, or customer of that provider;

        `(2) monitor the content of any communication of any person described in paragraph (1); or

        `(3) affirmatively seek facts or circumstances described in sections (a) and (b).

  • Duty

    • Old Language 42 USC 13032

      • make a report of such facts or circumstances

    • New Language 18 USC 2258A

      • `(A) provide. . .

        `(B) make a report of such facts or circumstances

  • To Whom

    • Old Language 42 USC 13032

      • to the Cyber Tip Line at the National Center for Missing and Exploited Children,

    • New Language 18 USC 2258A

      • to the CyberTipline of the National Center for Missing and Exploited Children, or any successor to the CyberTipline operated by such center,

        to the CyberTipline, or any successor to the CyberTipline operated by such center.

  • What must be reported

    • Old Language 42 USC 13032

      • (d) Limitation of information or material required in report A report under subsection (b)(1) of this section may include additional information or material developed by an electronic communication service or remote computing service, except that the Federal Government may not require the production of such information or material in that report.

    • New Language 18 USC 2258A

      • the mailing address, telephone number, facsimile number, electronic mail address of, and individual point of contact for, such electronic communication service provider or remote computing service provider; and

        . . .

        `(b) Contents of Report- To the extent the information is within the custody or control of an electronic communication service provider or a remote computing service provider, the facts and circumstances included in each report under subsection (a)(1) may include the following information:

        `(1) INFORMATION ABOUT THE INVOLVED INDIVIDUAL- Information relating to the identity of any individual who appears to have violated a Federal law described in subsection (a)(2), which may, to the extent reasonably practicable, include the electronic mail address, Internet Protocol address, uniform resource locator, or any other identifying information, including self-reported identifying information.

        `(2) HISTORICAL REFERENCE- Information relating to when and how a customer or subscriber of an electronic communication service or a remote computing service uploaded, transmitted, or received apparent child pornography or when and how apparent child pornography was reported to, or discovered by the electronic communication service provider or remote computing service provider, including a date and time stamp and time zone.

        `(3) GEOGRAPHIC LOCATION INFORMATION-

        `(A) IN GENERAL- Information relating to the geographic location of the involved individual or website, which may include the Internet Protocol address or verified billing address, or, if not reasonably available, at least 1 form of geographic identifying information, including area code or zip code.

        `(B) INCLUSION- The information described in subparagraph (A) may also include any geographic information provided to the electronic communication service or remote computing service by the customer or subscriber.

        `(4) IMAGES OF APPARENT CHILD PORNOGRAPHY- Any image of apparent child pornography relating to the incident such report is regarding.

        `(5) COMPLETE COMMUNICATION- The complete communication containing any image of apparent child pornography, including--

        `(A) any data or information regarding the transmission of the communication; and

        `(B) any images, data, or other digital files contained in, or attached to, the communication.

  • Disclosure to Law Enforcement

    • Old Language 42 USC 13032

      • which shall forward that report to a law enforcement agency or agencies designated by the Attorney General. . . .

        (3) In addition to forwarding such reports to those agencies designated in subsection (b)(2) of this section, the National Center for Missing and Exploited Children is authorized to forward any such report to an appropriate official of a state or subdivision of a state for the purpose of enforcing state criminal law.

        . . . . .

        (f) Conditions of disclosure of information contained within report

        (1) In general No law enforcement agency that receives a report under subsection (b)(1) of this section shall disclose any information contained in that report, except that disclosure of such information may be made—

        (A) to an attorney for the government for use in the performance of the official duties of the attorney;

        (B) to such officers and employees of the law enforcement agency, as may be necessary in the performance of their investigative and recordkeeping functions;

        (C) to such other government personnel (including personnel of a State or subdivision of a State) as are determined to be necessary by an attorney for the government to assist the attorney in the performance of the official duties of the attorney in enforcing Federal criminal law; or

        (D) where the report discloses a violation of State criminal law, to an appropriate official of a State or subdivision of a State for the purpose of enforcing such State law.

        (2) Definitions In this subsection, the terms “attorney for the government” and “State” have the meanings given those terms in Rule 54 of the Federal Rules of Criminal Procedure.

    • New Language 18 USC 2258A

      • `(c) Forwarding of Report to Law Enforcement-

        `(1) IN GENERAL- The National Center for Missing and Exploited Children shall forward each report made under subsection (a)(1) to any appropriate law enforcement agency designated by the Attorney General under subsection (d)(2).

        `(2) STATE AND LOCAL LAW ENFORCEMENT- The National Center for Missing and Exploited Children may forward any report made under subsection (a)(1) to an appropriate law enforcement official of a State or political subdivision of a State for the purpose of enforcing State criminal law.

        `(3) FOREIGN LAW ENFORCEMENT-

        `(A) IN GENERAL- The National Center for Missing and Exploited Children may forward any report made under subsection (a)(1) to any appropriate foreign law enforcement agency designated by the Attorney General under subsection (d)(3), subject to the conditions established by the Attorney General under subsection (d)(3).

        `(B) TRANSMITTAL TO DESIGNATED FEDERAL AGENCIES- If the National Center for Missing and Exploited Children forwards a report to a foreign law enforcement agency under subparagraph (A), the National Center for Missing and Exploited Children shall concurrently provide a copy of the report and the identity of the foreign law enforcement agency to--

        `(i) the Attorney General; or

        `(ii) the Federal law enforcement agency or agencies designated by the Attorney General under subsection (d)(2).

        . . . . .

        `(g) Conditions of Disclosure Information Contained Within Report-

        `(1) IN GENERAL- Except as provided in paragraph (2), a law enforcement agency that receives a report under subsection (c) shall not disclose any information contained in that report.

        `(2) PERMITTED DISCLOSURES BY LAW ENFORCEMENT-

        `(A) IN GENERAL- A law enforcement agency may disclose information in a report received under subsection (c)--

        `(i) to an attorney for the government for use in the performance of the official duties of that attorney;

        `(ii) to such officers and employees of that law enforcement agency, as may be necessary in the performance of their investigative and recordkeeping functions;

        `(iii) to such other government personnel (including personnel of a State or subdivision of a State) as are determined to be necessary by an attorney for the government to assist the attorney in the performance of the official duties of the attorney in enforcing Federal criminal law;

        `(iv) if the report discloses a violation of State criminal law, to an appropriate official of a State or subdivision of a State for the purpose of enforcing such State law;

        `(v) to a defendant in a criminal case or the attorney for that defendant, subject to the terms and limitations under section 3509(m) or a similar State law, to the extent the information relates to a criminal charge pending against that defendant;

        `(vi) subject to subparagraph (B), to an electronic communication service provider or remote computing provider if necessary to facilitate response to legal process issued in connection to a criminal investigation, prosecution, or post-conviction remedy relating to that report; and

        `(vii) as ordered by a court upon a showing of good cause and pursuant to any protective orders or other conditions that the court may impose.

        . . . . .

        `(B) LIMITATIONS-

        `(i) LIMITATIONS ON FURTHER DISCLOSURE- The electronic communication service provider or remote computing service provider shall be prohibited from disclosing the contents of a report provided under subparagraph (A)(vi) to any person, except as necessary to respond to the legal process.

        `(ii) EFFECT- Nothing in subparagraph (A)(vi) authorizes a law enforcement agency to provide child pornography images to an electronic communications service provider or a remote computing service.

        `(3) PERMITTED DISCLOSURES BY THE NATIONAL CENTER FOR MISSING AND EXPLOITED CHILDREN- The National Center for Missing and Exploited Children may disclose information received in a report under subsection (a) only--

        `(A) to any Federal law enforcement agency designated by the Attorney General under subsection (d)(2);

        `(B) to any State, local, or tribal law enforcement agency involved in the investigation of child pornography, child exploitation, kidnapping, or enticement crimes;

        `(C) to any foreign law enforcement agency designated by the Attorney General under subsection (d)(3); and

        `(D) to an electronic communication service provider or remote computing service provider as described in section 2258C.

  • Penalty for Failure to Report

    • Old Language 42 USC 13032

      • (4) Failure to report.— A provider of electronic communication services or remote computing services described in paragraph (1) who knowingly and willfully fails to make a report under that paragraph shall be fined—

        (A) in the case of an initial failure to make a report, not more than $50,000; and

        (B) in the case of any second or subsequent failure to make a report, not more than $100,000.

    • New Language 18 USC 2258A

      • `(e) Failure To Report- An electronic communication service provider or remote computing service provider that knowingly and willfully fails to make a report required under subsection (a)(1) shall be fined--

        `(1) in the case of an initial knowing and willful failure to make a report, not more than $150,000; and

        `(2) in the case of any second or subsequent knowing and willful failure to make a report, not more than $300,000.

  • Designation of Agent

    • Old Language 42 USC 13032

      • (2) Designation of agencies.— Not later than 180 days after October 30, 1998, the Attorney General shall designate the law enforcement agency or agencies to which a report shall be forwarded under paragraph (1).

    • New Language 18 USC 2258A


      • `(d) Attorney General Responsibilities-

        `(1) IN GENERAL- The Attorney General shall enforce this section.

        `(2) DESIGNATION OF FEDERAL AGENCIES- The Attorney General shall designate promptly the Federal law enforcement agency or agencies to which a report shall be forwarded under subsection (c)(1).

        `(3) DESIGNATION OF FOREIGN AGENCIES- The Attorney General shall promptly--

        `(A) in consultation with the Secretary of State, designate the foreign law enforcement agencies to which a report may be forwarded under subsection (c)(3);

        `(B) establish the conditions under which such a report may be forwarded to such agencies; and

        `(C) develop a process for foreign law enforcement agencies to request assistance from Federal law enforcement agencies in obtaining evidence related to a report referred under subsection (c)(3).

        `(4) REPORTING DESIGNATED FOREIGN AGENCIES- The Attorney General shall maintain and make available to the Department of State, the National Center for Missing and Exploited Children, electronic communication service providers, remote computing service providers, the Committee on the Judiciary of the Senate, and the Committee on the Judiciary of the House of Representatives a list of the foreign law enforcement agencies designated under paragraph (3).

        `(5) SENSE OF CONGRESS REGARDING DESIGNATION OF FOREIGN AGENCIES- It is the sense of Congress that--

        `(A) combating the international manufacturing, possession, and trade in online child pornography requires cooperation with competent, qualified, and appropriately trained foreign law enforcement agencies; and

        `(B) the Attorney General, in cooperation with the Secretary of State, should make a substantial effort to expand the list of foreign agencies designated under paragraph (3).

  • Notification to Internet Service

    • Old Language 42 USC 13032

      • n/a

    • New Language 18 USC 2258A

      • `(6) NOTIFICATION TO PROVIDERS- If an electronic communication service provider or remote computing service provider notifies the National Center for Missing and Exploited Children that the electronic communication service provider or remote computing service provider is making a report under this section as the result of a request by a foreign law enforcement agency, the National Center for Missing and Exploited Children shall--

        `(A) if the Center forwards the report to the requesting foreign law enforcement agency or another agency in the same country designated by the Attorney General under paragraph (3), notify the electronic communication service provider or remote computing service provider of--

        `(i) the identity of the foreign law enforcement agency to which the report was forwarded; and

        `(ii) the date on which the report was forwarded; or

        `(B) notify the electronic communication service provider or remote computing service provider if the Center declines to forward the report because the Center, in consultation with the Attorney General, determines that no law enforcement agency in the foreign country has been designated by the Attorney General under paragraph (3).

  • Preservation of Records

    • Old Language 42 USC 13032

      • n/a

    • New Language 18 USC 2258A

      • `(h) Preservation-

        `(1) IN GENERAL- For the purposes of this section, the notification to an electronic communication service provider or a remote computing service provider by the CyberTipline of receipt of a report under subsection (a)(1) shall be treated as a request to preserve, as if such request was made pursuant to section 2703(f).

        `(2) PRESERVATION OF REPORT- Pursuant to paragraph (1), an electronic communication service provider or a remote computing service shall preserve the contents of the report provided pursuant to subsection (b) for 90 days after such notification by the CyberTipline.

        `(3) PRESERVATION OF COMMINGLED IMAGES- Pursuant to paragraph (1), an electronic communication service provider or a remote computing service shall preserve any images, data, or other digital files that are commingled or interspersed among the images of apparent child pornography within a particular communication or user-created folder or directory.

        `(4) PROTECTION OF PRESERVED MATERIALS- An electronic communications service or remote computing service preserving materials under this section shall maintain the materials in a secure location and take appropriate steps to limit access by agents or employees of the service to the materials to that access necessary to comply with the requirements of this subsection.

        `(5) AUTHORITIES AND DUTIES NOT AFFECTED- Nothing in this section shall be construed as replacing, amending, or otherwise interfering with the authorities and duties under section 2703.


  • Liability Limitation

    • Old Language 42 USC 13032

      • (c) Civil liability No provider or user of an electronic communication service or a remote computing service to the public shall be held liable on account of any action taken in good faith to comply with or pursuant to this section.

    • New Language 18 USC 2258A

      • `SEC. 2258B. LIMITED LIABILITY FOR ELECTRONIC COMMUNICATION SERVICE PROVIDERS, REMOTE COMPUTING SERVICE PROVIDERS, OR DOMAIN NAME REGISTRAR.

        `(a) In General- Except as provided in subsection (b), a civil claim or criminal charge against an electronic communication service provider, a remote computing service provider, or domain name registrar, including any director, officer, employee, or agent of such electronic communication service provider, remote computing service provider, or domain name registrar arising from the performance of the reporting or preservation responsibilities of such electronic communication service provider, remote computing service provider, or domain name registrar under this section, section 2258A, or section 2258C may not be brought in any Federal or State court.

        `(b) Intentional, Reckless, or Other Misconduct- Subsection (a) shall not apply to a claim if the electronic communication service provider, remote computing service provider, or domain name registrar, or a director, officer, employee, or agent of that electronic communication service provider, remote computing service provider, or domain name registrar--

        `(1) engaged in intentional misconduct; or

        `(2) acted, or failed to act--

        `(A) with actual malice;

        `(B) with reckless disregard to a substantial risk of causing physical injury without legal justification; or

        `(C) for a purpose unrelated to the performance of any responsibility or function under this section, sections 2258A, 2258C, 2702, or 2703.

        `(c) Minimizing Access- An electronic communication service provider, a remote computing service provider, and domain name registrar shall--

        `(1) minimize the number of employees that are provided access to any image provided under section 2258A or 2258C; and

        `(2) ensure that any such image is permanently destroyed, upon a request from a law enforcement agency to destroy the image.

This comparison was necessary because it was not immediately clear what McCain's SAFE Act brings to the table - and after creating the side-by-side, its still not clear (Congress did impose a long desired record retention requirement - See Record Retention).

Why did Congress felt it necessary to create an entirely new law to address this issue? Understand, the new law does not replace the old. BOTH the new law and the old law now are on the books - and one could in theory be found to have violated both statutes and suffer both penalties. And as far as I can tell from the side-by-side, the new SAFE Act is merely an elaboration and tweaking of the old law - at times the language in the two different statutes is all but plagiarized. I really would be interested to hear from those that might have insight on this legislative maneuver.

Second, I know that CDT complains about the new outsourced role of the National Center for Missing & Exploited Children - but as can be seen, the role is not new. The role of the National Center for Missing & Exploited Children is all but identical under both the old and new statutes - receive, aggregate, and forward information to law enforcement. There may or may not be an objection to this outsourcing, but the role of the National Center for Missing & Exploited Children is not new.