Showing posts with label email. Show all posts
Showing posts with label email. Show all posts

Sunday, January 08, 2017

1982 :: Jan. 4 :: US Postal Service Launches ECOM, its Email Service

The time was 1977. The country is in a tailspin. Saturday Night Live is singing carols about killing Gary Gilmore for Christmas. President Carter takes the Oval Office and pardons Vietnam War draft evadersThe Clash releases their debut album. And the USPS is scared.

The USPS has learned about this thing called electronic mail and electronic transactions. It occurs to the USPS that if everyone were to use these electronic thingies, First Class mail would get wiped out and so would all that revenue.
While there is disagreement on how fast EMS and EFT may develop, it seems clear that two-thirds or more of current mainstream could be handled electronically, and that the volume of USPS - delivered mail is likely to peak in the next 10 years. Any decline in the volume of mail has significant implications for future postal rates, USPS service levels, and labor requirements. 
A key policy issue requiring congressional attention is how USPS will participate in the provision of EMS services, both in the near term and in the longer term. If USPS does not attract and keep a sizable share of the so-called Generation II EMS market (electronic input and transmission with hardcopy output) and conventional (especially first-class) mail volume declines, USPS revenues will probably go down, with the likelihood of an unfavorable impact on rates and/or service levels. If USPS does develop a major role in the Generation II EMS market, and if Generation II EMS costs are low enough, the effect on USPS rates and/or service could be favorable. [USPS, p. ix, 1982]
After some careful strategic planning, the USPS launched an attack on email with a classic pincer movement: on the left flank, the USPS initiated its own email service known as E-COM on January 4, 1982; [USPS, p. 3 1982] [USPS 2008] on the right flank, the USPS considered banning all private email service.


E-COM was a simple concept. The USPS would set up a network where a message would originate electronically. It would then be sent to one of a handful of participating postal offices that had terminals, where it would be printed out.
After arriving at the serving Post Office, the messages were processed and sorted by ZIP Code, then printed on letter-size bond paper, folded, and sealed in envelopes printed with a blue E-COM logo. [USPS 2008]
The hard copy of the message would then be delivered to its destination - essentially in the same manner and with the same speed as first class mail. [ECPA 1985 Report p 45] [USPS, p. 3 1982 (stating that the service was initiated January 1982)]

Before E-COM could get off the ground, it was mired in controversy. [CATO[USPS, p. 3 1982] The US Postal Commission, the Department of Justice, the Department of Commerce, private companies, and even the FCC, objected. The first objection was that it was against government policy for a government agency to compete with the private sector. [USPS p. 17 1982] Private commercial email services were nascent and promising, and did not think much of a government monopoly using its government bank role to pay for a competing email service. The FCC said, "we have jurisdiction over all wireline and wireless services. That jurisdiction has been interpreted broadly. And there is no dispute that the transmission of a message over a communications network is communications, under the Communications Act, and under our jurisdiction." "Not only that," the FCC was heard to say, "but its common carriage." The FCC stated:
With respect to the relevant judicial decisions defining the nature of common carriage, we note that none of the parties to this proceeding appears to dispute that ECOM service would constitute a common carrier offering if it were to be provided by an entity other than the Postal Service. We also conclude independently that ECOM is a quasi-public offering of a for-profit service which affords the public an opportunity to transmit messages of its own design and choosing. Based on those judicially defined criteria, we find that, in offering ECOM, the Postal Service is engaging in a common carrier activity.
[In re Request for declaratory ruling and investigation by Graphnet Systems, Inc., concerning the proposed E-COM service, FCC Docket No. 79-6 (Sept 4, 1979)] In other words, before E-COM could get launched, the FCC said, "if you are going to do this, then you are under our jurisdiction, and you are going to have to file a tariff for the offering of your common carriage service." The FCC said that email, whether from the USPS or privately offered, is a form of common carriage - they don't say that anymore.

The USPS would not accept "no" for an answer, tinkered with its network in order to weasel out of FCC jurisdiction, and launched E-COM in 1982. A message was priced at 26¢ - and for each email message, the USPS was said to lose around $5 [CATO]. They had apparently estimated that the service would be a raging success; it was not and, with the low message volume, the cost per message was rather high. If you used the service, you had to send at minimum 200 messages. [USPS 2008] The service was one directional; if you got an error message, you would receive it in the mail two days later. When the E-COM messages were printed out, it would take two days more to be delivered. And it cost the same as First Class mail.
In fiscal year 1984, 23 million E-COM messages were sent. E-COM service had 1,046 certified customers, 528 of whom were communication carriers. That year, the Postal Rate Commission responded to the Postal Service's 1983 request for a 31-cent rate for the first page by recommending a rate of 52 cents for the first page and 15 cents for the second page of E-COM messages. The Governors of the Postal Service, who decide rates and postal policies but can overrule a Postal Rate Commission decision only by a unanimous vote, rejected the Commission's recommended decision and asked for reconsideration. The Commission responded in June with a recommendation of a 49-cent rate for the first page and 14 cents for the second page. The Governors rejected these rates as well, essentially because they priced E-COM out the market, and recommended that the Postal Service dispose of the E-COM system by sale or lease to a private firm or firms. [USPS 2008]
For some reason, E-COM was a failure (one Senator called it a turkey). On September 3, 1985, three years after service was initiated, USPS terminated the service and tried to sell it off. [Aide p 8] [ECPA Report 1985 p 46] [USPS 2008]

Tuesday, December 27, 2016

⚖ Can You Legally Disclose Illegally Intercepted Communications to the Author of the Communication?

CRIMINAL LAW 101 EXAM (You have 1.5 hours)

QUESTION: Is it a violation of the Wiretap Act to disclose your own email to yourself?

(Stop laughing) (Seriously, you are being graded on this)

FACTS: "The action arises from the [PLAINTIFF and DEFENDANT]'s acrimonious divorce. DEFENDANT accused PLAINTIFF of serial infidelity, so in discovery PLAINTIFF asked DEFENDANT for all documents related to that accusation. DEFENDANT complied and produced copies of incriminating emails between PLAINTIFF and several other women..."

CAUSE OF ACTION: "PLAINTIFF alleges that DEFENDANT violated the Wiretap Act by surreptitiously placing an auto-forwarding 'rule' on his email accounts that automatically forwarded the messages on his email client to her. He also claims that DEFENDANT's divorce lawyer violated the Act by 'disclosing' the intercepted emails in response to his discovery request. The district judge dismissed the suit on the pleadings."

On this final exam, we concern ourselves only with the later action regarding disclosing of emails.

RULE: 18 USC s 511(1)(c) prohibits the disclosure of intercepted communications:
[A]ny person who- (c) intentionally discloses, or endeavors to disclose, to any other person the contents of any wire, oral, or electronic communication, knowing or having reason to know that the information was obtained through the interception of a wire, oral, or electronic communication in violation of this subsection; . . . shall be punished as provided in subsection (4) or shall be subject to suit as provided in subsection (5).
ANALYSIS: Getting past whether this was in fact an interception, is it disclosure? Couple problems, as the court points out:
  • PLAINTIFF "already knew the contents of the intercepted emails."
  • PLAINTIFF "invited their disclosure by requesting them in discovery in the divorce action" - the court suggests that requesting your own emails in discovery is tantamount to "consent" for disclosure of those communications.
  • Then the Court pontificates, "to 'disclose' something means '[t]o make (something) known or public.'... [DEFENDANT's ATTORNEY] did not publicly disclose PLAINTIFF's emails, and their content was hardly unknown to PLAINTIFF. "
CONCLUSION: "[E]ven if the emails were unlawfully intercepted, [DEFENDANT's ATTORNEY] did not unlawfully disclose their content by producing them in response to PLAINTIFF's discovery request."

Nope, it aint a violation of the Wiretap Act to disclose the contents of a communication to the communicator of that communication.

NOTE: 18 USC 2511(1)(c) specifically states anyone who "intentionally discloses, or endeavors to disclose, to any other person the contents of any wire, oral, or electronic communication" has violated the Act. Here we have a play with three actors. We have the communicator, the interceptor, and the "other." PLAINTIFF is the communicator. DEFENDANT is the interceptor. For this tragedy to work, there needs to be one more person. There needs to be the "other" (and DEFENDANT's ATTORNEY counts in this play as DEFENDANT and does not count as "other."). Lacking the "other," the tragedy is incomplete and the cause of action fails.

Epstein v. Epstein, Court of Appeals, 7th Circuit 2016

Tuesday, November 08, 2016

🚴 NIST Cybersecurity Practice Guide, Special Publication 1800-6: “Domain Name Systems-Based Electronic Mail Security”



Business Challenge

"Email has become the dominant method of electronic communication for both private and public sector organizations, fueled by low costs and fast delivery.  Securing these transactions has been less of a priority, which is one reason why email attacks have increased.
"Whether the goal is authentication of the source of an email message or assurance that the message has not been altered by or disclosed to an unauthorized party, organizations must employ some cryptographic protection mechanism. Economies of scale and a need for uniform security implementation drive most enterprises to rely on mail servers and/or Internet service providers (ISPs) to provide security to all members of an enterprise. Many current server-based email security mechanisms are vulnerable to, and have been defeated by, attacks on the integrity of the cryptographic implementations on which they depend. The consequences of these vulnerabilities frequently involve unauthorized parties being able to read or modify supposedly secure information, or introduce malware to gain access to enterprise systems or information. Protocols exist that are capable of providing needed email security and privacy, but impediments such as unavailability of easily implemented software libraries and operational issues stemming from some software applications have limited adoption of existing security and privacy protocols.

Solution

"This project has resulted in NIST Special Publication 1800-6, “Domain Name Systems-Based Electronic Mail Security,” which illustrates how commercially available technologies can meet an organization’s needs to improve email security and defend against email-based attacks such as phishing and man-in-the-middle types of attacks.
"This draft practice guide describes a proof of concept security platform that demonstrates trustworthy email exchanges across organizational boundaries and includes authentication of mail servers, signing and encryption of email, and binding cryptographic key certificates to the servers.
The goal of this project is to help organizations:
  • Encrypt emails between mail servers
  • Allow individual email users to digitally sign and/or encrypt email messages
  • Allow email users to identify valid email senders as well as send digitally signed messages and validate signatures of received messages
"The example solution uses Domain Name System Security Extension (DNSSEC) protocol to authenticate server addresses and certificates used for Transport Layer Security (TLS) to DNS names.
The project's demonstrated security platform can provide organizations with improved privacy and security protection for users' operations and improved support for implementation and use of the protection technologies. The platform also improves the usability of available DNS security applications and encourages wider implementation of DNSSEC, TLS and S/MIME to protect electronic communications.
NIST SP 1800-6 is in draft form and open for public comment until December 19, 2016. Please share your comments and feedback on this project and its example solution.

Friday, October 09, 2015

:: Email. The modern working world cannot exist without it, but hackers exploit this vital service to steal money and valuable information. The National Institute of Standards and Technology (NIST) is tackling this threat with two new projects. hand on keyboard Credit: ©Fotolia.com NIST is publishing a draft document for comment that provides guidelines to enhance trust in email. And the National Cybersecurity Center of Excellence (NCCoE) is seeking collaborators to provide products and expertise to demonstrate a secure, standards-based email system using commercially available software and other tools. In the early, halcyon days of the Internet, researchers were more interested in sharing information rather than securing it. Now, decades later, securing the world’s most widely used medium for business communication is a full-time job for researchers and IT specialists around the globe. “The two main threats to current email services are phishing and leaking confidential information,” explains computer scientist Scott Rose. In phishing, hackers use forged emails to trick email users to unknowingly provide valuable data such as bank account numbers. In other scams, addressees are lured into clicking on a link that downloads malicious code, which can home in on an organization’s most valuable data like a heat-seeking missile or steal personal information. Hackers can also intercept email messages to learn an organization’s proprietary information, or tamper with the information in the message before it is delivered to the recipient. In the draft Trustworthy Email (NIST Special Publication (SP) 800-177), authors provide an overview of existing technologies and best practices, and they offer deployment guidance to meet federal government security requirements. Emerging protocols to make email security and privacy easier for end users also are described. While there are two basic threats to email, there are multiple ways to exploit both, Rose says. Trustworthy Email suggests solutions to address all common exploits. To reduce the risk of spoofing, for example, the authors suggest that organizations use techniques to authenticate domain names used to send emails, and that employees or members digitally sign email. For confidential email, organizations can encrypt email between sender and receiver or secure the transmission between email servers. Trustworthy Email is written for enterprise email administrators, information security specialists and network managers. The document applies to federal IT systems, but can be used in other organizations. The publication is designed to complement NIST’s earlier document, Guidelines on Electronic Mail Security, NIST SP 800-45 version 2. The authors seek input on the draft document. The deadline for comments on Trustworthy Email, SP 800-177, is November 30, 2015. Please send any questions or comments to sp800-177@nist.gov. At the same time, the NCCoE is seeking collaborators to provide products and technical expertise during a project that will demonstrate a secure email system. The NCCoE’s Domain Name System (DNS) Based Secured Email project will lead to a publicly available NIST Cybersecurity Practice Guide. The guide will explain how to employ and build a platform to meet federal and industry security and privacy requirements using commercially available tools and components. More information is available in a recent white paper. If you are interested in participating, details are provided in Federal Register Notice Document 2015-25304. Letters of interest will be accepted on a first-come, first-served basis. Those selected to participate will enter into a Cooperative Research and Development Agreement with NIST. The NCCoE is a partnership of NIST, the State of Maryland and Maryland's Montgomery County. The center is dedicated to furthering rapid adoption of practical, standards-based cybersecurity solutions for businesses and public organizations using commercially available and open-source technologies.

Email. The modern working world cannot exist without it, but hackers exploit this vital service to steal money and valuable information. The National Institute of Standards and Technology (NIST) is tackling this threat with two new projects.
NIST is publishing a draft document for comment that provides guidelines to enhance trust in email. And the National Cybersecurity Center of Excellence (NCCoE) is seeking collaborators to provide products and expertise to demonstrate a secure, standards-based email system using commercially available software and other tools. In the early, halcyon days of the Internet, researchers were more interested in sharing information rather than securing it. Now, decades later, securing the world’s most widely used medium for business communication is a full-time job for researchers and IT specialists around the globe. “The two main threats to current email services are phishing and leaking confidential information,” explains computer scientist Scott Rose. In phishing, hackers use forged emails to trick email users to unknowingly provide valuable data such as bank account numbers. In other scams, addressees are lured into clicking on a link that downloads malicious code, which can home in on an organization’s most valuable data like a heat-seeking missile or steal personal information. Hackers can also intercept email messages to learn an organization’s proprietary information, or tamper with the information in the message before it is delivered to the recipient. In the draft Trustworthy Email (NIST Special Publication (SP) 800-177), authors provide an overview of existing technologies and best practices, and they offer deployment guidance to meet federal government security requirements. Emerging protocols to make email security and privacy easier for end users also are described. While there are two basic threats to email, there are multiple ways to exploit both, Rose says. Trustworthy Email suggests solutions to address all common exploits. To reduce the risk of spoofing, for example, the authors suggest that organizations use techniques to authenticate domain names used to send emails, and that employees or members digitally sign email. For confidential email, organizations can encrypt email between sender and receiver or secure the transmission between email servers. Trustworthy Email is written for enterprise email administrators, information security specialists and network managers. The document applies to federal IT systems, but can be used in other organizations. The publication is designed to complement NIST’s earlier document, Guidelines on Electronic Mail Security, NIST SP 800-45 version 2. The authors seek input on the draft document. The deadline for comments on Trustworthy Email, SP 800-177, is November 30, 2015. Please send any questions or comments to sp800-177@nist.gov. At the same time, the NCCoE is seeking collaborators to provide products and technical expertise during a project that will demonstrate a secure email system. The NCCoE’s Domain Name System (DNS) Based Secured Email project will lead to a publicly available NIST Cybersecurity Practice Guide. The guide will explain how to employ and build a platform to meet federal and industry security and privacy requirements using commercially available tools and components. More information is available in a recent white paper. If you are interested in participating, details are provided in Federal Register Notice Document 2015-25304. Letters of interest will be accepted on a first-come, first-served basis. Those selected to participate will enter into a Cooperative Research and Development Agreement with NIST. The NCCoE is a partnership of NIST, the State of Maryland and Maryland's Montgomery County. The center is dedicated to furthering rapid adoption of practical, standards-based cybersecurity solutions for businesses and public organizations using commercially available and open-source technologies.

Friday, September 30, 2011

US Postal Service Versus Email: The Historic Grudge Match of the Ages

So apparently rumor has it that the USPS' new marketing strategy is to waste money on a bunch of ads trying to convince America that email is unsafe.  Hum.  Mr. Peabody, let's turn to the Wayback Machine and travel to the far and weird past:

The time is 1977. The country is in a tailspin. Saturday Night Live is singing carols about killing Gary Gilmore for Christmas . President Carter takes the Oval Office, and pardons Vietnam War draft evaders . The Clash releases their debut album. And the USPS is scared.

The USPS has learned about this thing called electronic mail and electronic transactions. It occurs to the USPS that if everyone were to use these electronic thingies, First Class mail would get wiped out and so would all that revenue. After some careful strategic planning, the USPS launched an attack on email with a classic pincer movement: on the left flank, the USPS initiated its own email service known as E-COM ; on the rank flank, the USPS considered banning all private email service.

E-COM was a simple concept. The USPS would set up a network where a message would originate electronically. It would then be sent to one of a handful of participating postal offices that had terminals, where it would be printed out. The hard copy of the message would then be delivered to its destination - essentially in the same manner and with the same speed as first class mail. USPS launched this service in 1981.

Before E-COM could get off the ground, however, it was mired in controversy. The US Postal Commission, the Department of Justice, private companies, and even the FCC, objected. The first objection was that it was against government policy for a government agency to compete with the private sector. Private commercial email services were nascent and promising, and did not think much of a government monopoly using its government bankrole to pay for a competing email service. The FCC made a particularly interesting objection. The FCC said, "we have jurisdiction over all wireline and wireless services. That jurisdiction has been interpreted broadly. And there is no dispute that the transmission of a message over a communications network is communications, under the Communications Act, and under our jurisdiction." "Not only that," the FCC was heard to say, "but its common carriage." The FCC stated:
With respect to the relevant judicial decisions defining the nature of common carriage, we note that none of the parties to this proceeding appears to dispute that ECOM service would constitute a common carrier offering if it were to be provided by an entity other than the Postal Service. We also conclude independently that ECOM is a quasi-public offering of a for-profit service which affords the public an opportunity to transmit messages of its own design and choosing. Based on those judicially defined criteria, we find that, in offering ECOM, the Postal Service is engaging in a common carrier activity.
In re Request for declaratory ruling and investigation by Graphnet Systems, Inc., concerning the proposed E-COM service, FCC Docket No. 79-6 (Sept 4, 1979).

In other words, before E-COM could get launched, the FCC said, "if you are going to do this, then you are under our jurisdiction, and you are going to have to file a tariff for the offering of your common carriage service" (The FCC doesnt say that email is common carriage any more).

Well, the USPS would not accept "no" for an answer, tinkered with its network in order to weasel out of FCC jurisdiction, and launched E-COM in 1981. A message was priced at 26¢ - and for each email message, the USPS was said to lose around $5. They had apparently estimated that the service would be a raging success; it was not and, with the low message volume, the cost per message was rather high. And by the way, if you used the service you had to send at minimum 200 messages. The service was one directional; if you got an error message, you would receive it in the mail two days later. When the E-COM messages were printed out, it would take two days more to be delivered. And it cost the same as First Class mail.

For some reason, E-COM was a failure (one Senator called it a turkey). Three years after service was initiated, USPS terminated the service and tried to sell it off.

Friday, July 08, 2011

ECPA Claim Dismissed: No Showing Def Was Connected to 3rd Party Who May Have Illegally Intercepted Email, Or That Def Knew Email May Have Been Illegally Intercepted

ZINNA v. Cook, Court of Appeals, 10th Circuit 2011:  In ECPA cause of Action, Def Motion for Summary Judgment granted where Pltf failed to provide evidence that 

  • Def had any association with third party who may have illegally intercepted the email
  • Def had any knowledge that email may have been illegally intercepted when Def disclosed the email

Facts: "Plaintiff Michael L. Zinna brought this action under the civil damages provision of the Federal Wiretap Act, 18 U.S.C. § 2520(a), claiming defendants conspired to intercept, disclose, or use certain electronic communications he had made. He alleged emails he sent to friends and associates on June 14, 2006, were intercepted by a third party and acquired by defendants, who posted information taken from them to an internet web site (ColoradoWackoExposed.com [no longer resolves]) later that evening in an effort to discredit him. The district court granted summary judgment for defendants, holding that Mr. Zinna failed to present evidence sufficient to create a triable issue that defendants either played a role in the alleged illegal interception or had knowledge of it when contents of the emails were posted on the internet. Mr. Zinna timely filed this appeal. As explained below, we affirm for substantially the reasons stated by the district court."

Analysis:

  • RULE "Defendants could potentially be liable either for conspiring with [email interceptor] beforehand to intercept the emails or by conspiring to acquire the emails for the purpose of illegally disclosing and/or using them. See Thompson v. Delaney, 970 F.2d 744, 748-50 (10th Cir. 1992) (assessing claims of conspiracy to intercept and conspiracy to use or disclose in violation of Federal Wiretap Act)
  • HOLDINGNo competent evidence in the record ties defendants to the alleged interceptor, much less to show they conspired with him to engage in the illegal interception.
  • RULE: Def could be liable for disclosure of emails that they knew were illegally intercepted.  "liability for use or disclosure of the contents of an intercepted communication requires both intentional conduct and knowledge that the information was obtained through the interception of a[n] . . . electronic communication in violation of [the statute]." Thompson, 970 F.2d at 748 (emphasis added and quotation omitted).
  • HOLDING: Plaintiff has "not cited to any evidence in the record sufficient to support a reasonable inference that defendants knew the material posted on the web site derived from an illegal interception of email."


Tuesday, October 12, 2010

In Which We Learn That an Email Stored on a Laptop is not in "Electronic Storage"

What is it about former-boyfriends or girlfriends and hacking into the ex's email account? There is a growing litany of caselaw developing in this area (would make a good law review article somebody!).

Today we review Thompson v. Kaczmarek, No. 2:10-cv-479 (Sept. 30, 2010). In the words of the court, the relationship between the Plaintiff and the Defendant "deteriorated." Defendant got her hands on Plaintiff's laptop and "became intent on embarrassing [Plaintiff] in revenge." Defendant allegedly turned over the alleged laptop to nefarious dudes with the skill to hack into the hard drive and retrieve allegedly embarrassing emails. Plaintiff sued them all.

As per normal, we are particularly interested in the causes of action based on federal law; in this case Plaintiff claimed that Defendants violated the Stored Communications Act (SCA).

I always struggle with the SCA and ECPA –doesn’t the SCA apply to email somehow magically in transit – and once you have downloaded the email to your own machine, whatever happens to that email is of no concern of ECPA/SCA? If accessing stuff on the Plaintiff's machine caused some type of consternation, wouldn’t that be more of a Computer Fraud and Abuse Act claim?

Let's go to the video tape and find out.

Before the Court is Defendant's Rule 12(b)(6) Motion to Dismiss for failure to state an SCA claim upon which relief can be granted. "[T]he question before the Court is whether the unauthorized access of previously received electronic mail messages ("e-mail") that had been downloaded by the recipient and saved to the hard drive of his personal laptop computer violates the Stored Communications Act." For purposes of this motion, Defendants assume "that Plaintiff did not provide them with authority to access the data saved to the laptop hard drive." The problem, Defendants argue, is that even if the access were unauthorized, this is not a situation covered by the SCA.

The relevant portion of the SCA 18 U.S.C. § 2701 states

whoever—

(1) intentionally accesses without authorization a facility through which an electronic communication service is provided; or

(2) intentionally exceeds an authorization to access that facility;

and thereby obtains, alters, or prevents authorized access to a wire or electronic communication while it is in electronic storage in such system shall be punished as provided in subsection (b) of this section.

Once an email has been downloaded and saved to a person's laptop, the electronic communication (the email) is no longer in electronic storage at the electronic communications service.

Okay, a few definitions.

"The SCA defines electronic storage as either a) 'any temporary, intermediate storage of a wire or electronic communication incidental to the electronic transmission thereof', and b) 'any storage of such communication by an electronic communications service for purposes of backup protection of such communication.' 18 U.S.C. § 2510(17); see also 18 U.S.C. § 2711(1) (providing that terms defined in § 2510 apply to Title II of ECPA)." The SCA is anticipating the brief, temporary, temporal storage that is involved in electronic, store-and-forward communications. It is when the email is stored on the email server. It is when the email is stored in transit. It is not after it has been received, read, and saved. It is not when the email is on Plaintiff's laptop.

Next, “'electronic communications system' means any wire, radio, electromagnetic, photooptical or photoelectronic facilities for the transmission of wire or electronic communications, and any computer facilities or related electronic equipment for the electronic storage of such communications." 18 U.S.C. § 2510(14). In other word, this is a service in the business of communications – not an end user. Even if Plaintiff wants to claim that the act of backing up his email makes him a "facility," it does not, concludes the court, make him an "electronic communications service."

Defendants' Motion to Dismiss Plaintiff's SCA Cause of Action is granted.

This time the allegedly hacking romantic ex-partner wins. See Global Policy Partners, Inc. v. Yessin, (EDVa Nov. 24, 2009) where the hacking-ex-partner loses. Plaintiff did not apparently raise a Computer Fraud and Abuse Act cause of action. Would the outcome have been different under the CFAA?

[Disclaimer]

Monday, May 19, 2008

What Arlington Public Schools Get Wrong About Email Privacy

Someone in Arlington Public School has woken up to the fact that email is a marvelously insecure way of communicating. Email is an application that moves a text file from one computer to another. A text file requires no special application to be read. It’s kind of like sending a postcard, and anyone who handles the postcard can read the postcard. Worst yet, everyone who handles the postcard can retain a copy of the postcard. Worst yet, anyone who receives the postcard can forward it on to 50 over their closest friends. Not very private or secure.

APS handles a lot of messages between parents, teachers, students, and administrators. A good bit of those messages personal content and sensitive information.

[Paragraph One] + [Paragraph Two] = An APS Disclaimer:

"This communication was sent via the Arlington Public Schools mail system. Please be advised that email is not a secure form of communication. There should be no expectation of right to privacy in anything sent via electronic mail."

Excuse me? Did you just say I have no right to privacy?!?

Let’s go back to the chalk board. Simple because something is technically insecure does not mean that it is legally insecure. Just because I leave an apple out on a table does not mean that the government can legally swipe it.

The APS disclaimer uses two legal terms of art: “Expectation of Privacy” and “Rights.” An “Expectation of Privacy” and our Rights come from the US Constitution, and specifically here the 4th Amendment. You will recall from public school social studies that the 4th Amended states,

The right of the people to be secure in their persons, houses, papers, an effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.

This right has been elaborated in wiretap law and the Electronic Communications Privacy Act (ECPA), which have developed the concept of an “Expectation of Privacy.” Where one has an Expectation of Privacy, the 4th Amendment dictates that the government must have proper authority to search and seize our communications. ECPA specifically sets forth the subpoenas and warrants the government needs in order to access and read our email.

Add all this up: we have a Constitutional Expectation of Privacy in email, protected by the 4th Amendment. It does not matter that it is woefully technically insecure. This is an Expectation of Privacy as against the government, and the government – this time APS – cannot take that away from us.

In other words, five years down the road, when FBI Agent Fox Mulder believes my kid is an alien, Agent Mulder may not simply go through APS email records related to my child. The emails may be insecure - but Mulder is barred by the Constitution from search and seizure without proper authority.

The US Supreme Court has time and again articulated the fundamental nature of privacy to our American experience:

The makers of our constitution undertook to secure conditions favorable to the pursuit of happiness... They sought to protect Americans in their beliefs, their thoughts, their emotions and their sensations. They conferred, as against the government, the right to be let alone – the most comprehensive of the rights and the right most valued by civilized men. – Justice Louis D Brandeis

APS gets it wrong. I would never put any sensitive information in an email; but that does not mean I don’t have an Expectation of Privacy in email or that the government can read it lacking proper authority.

Thursday, September 20, 2007

26¢ Emails – Regulated by the FCC

Have your received the email alerts about the FCC charging a modem tax? Or about the US Postal Service starting to charge for stamps for email? These are of course hoaxes. One great hoax I remember had to do with a member of Congress Schnell (German for “Fast”) who introduced a legislative proposal 602P (legislative proposals are either “S” for Senate or “HR” for House of Representatives – there’s no “P”) proposing a 5¢ email tax. According the official USPS website,

Some rumors refuse to die-no matter how many times they have been put to rest. . . The fictional Congressman Schnell is making the Internet chat room circuit again, proposing a 5-cents surcharge on e-mail messages. This was a hoax when it first circulated several years ago, and is still a hoax today. There is no Congressman Schnell, and there has never been a Bill 602P. In addition, the USPS has already said it would not support this type of legislation.

And if you don’t believe the USPS, then you should believe the Dept of Energy (after all, they are charge of nuclear power).

Of course, the punch line is that the fee was not 5¢, it was 26¢! And it wasn’t proposed by Schnell - it was proposed by the US Postal Service itself.

Time to use the Way-Back Machine. The time is 1977. The country is in a tailspin. Saturday Night Live is singing carols about killing Gary Gilmore for Christmas. President Carter takes the Oval Office, and pardons Vietnam War draft evaders. The Clash releases their debut album. And the USPS is scared.

The USPS has learned about this thing called electronic mail and electronic transactions. It occurs to the USPS that if everyone were to use these electronic thingies, First Class mail would get wiped out and so would all that revenue. After some careful strategic planning, the USPS launched an attack on email with a classic pincer movement: on the left flank, the USPS initiated its own email service known as E-COM; on the rank flank, the USPS considered banning all private email service.

E-COM was a simple concept. The USPS would set up a network where a message would originate electronically. It would then be sent to one of a handful of participating postal offices that had terminals, where it would be printed out. The hard copy of the message would then be delivered to its destination – essentially in the same manner and with the same speed as first class mail. USPS launched this service in 1981.

Before E-COM could get off the ground, however, it was mired in controversy. The US Postal Commission, the Department of Justice, private companies, and even the FCC, objected. The first objection was that it was against government policy for a government agency to compete with the private sector. Private commercial email services were nascent and promising, and did not think much of a government monopoly using its government bankrole to pay for a competing email service. The FCC made a particularly interesting objection. The FCC said, “we have jurisdiction over all wireline and wireless services. That jurisdiction has been interpreted broadly. And there is no dispute that the transmission of a message over a communications network is communications, under the Communications Act, and under our jurisdiction.” “Not only that,” the FCC was heard to say, “but its common carriage.” Using an actual quote, the FCC stated:

With respect to the relevant judicial decisions defining the nature of common carriage, we note that none of the parties to this proceeding appears to dispute that ECOM service would constitute a common carrier offering if it were to be provided by an entity other than the Postal Service. [Oh really?!?!?!] We also conclude independently that ECOM is a quasi-public offering of a for-profit service which affords the public an opportunity to transmit messages of its own design and choosing. Based on those judicially defined criteria, we find that, in offering ECOM, the Postal Service is engaging in a common carrier activity.

In re Request for declaratory ruling and investigation by Graphnet Systems, Inc., concerning the proposed E-COM service, FCC Docket No. 79-6 (Sept 4, 1979).

In other words, before E-COM could get launched, the FCC said, “if you are going to do this, then you are under our jurisdiction, and you are going to have to file a tariff for the offering of your common carriage service” (do you hear that?!? The FCC said that email, whether from the USPS or privately offered, is a form of common carriage – they don’t say that anymore).

Well, the USPS would not accept “no” for an answer, tinkered with its network in order to weasel out of FCC jurisdiction, and launched E-COM in 1981. A message was priced at 26¢ - and for each email message, the USPS was said to lose around $5. They had apparently estimated that the service would be a raging success; it was not and, with the low message volume, the cost per message was rather high. And by the way, if you used the service you had to send at minimum 200 messages. The service was one directional; if you got an error message, you would receive it in the mail two days later. When the E-COM messages were printed out, it would take two days more to be delivered. And it cost the same as First Class mail.

For some reason, E-COM was a failure (one Senator called it a turkey). Three years after service was initiated, USPS terminated the service and tried to sell it off.

Some what’s the punch line? Congressman Schnell was going to undercut the USPS offering by 21¢ - and deliver you messages two day faster! Vote Schnell!

[Disclaimer]