Search This Blog

Showing posts with label cybercrime. Show all posts
Showing posts with label cybercrime. Show all posts

Monday, August 1, 2016

Following "Alarming" Report, New York Bans Pokemon Go for Sex Offenders on Parole

So reports Governor Andrew Cuomo's office in this press release:

Governor Andrew M. Cuomo today directed the New York State Department of Corrections and Community Supervision to restrict sex offenders under community supervision from using Pokémon GO and similar games. In an effort to safeguard New York’s children, the Governor also sent a letter to software developer Niantic, Inc. requesting their assistance in prohibiting dangerous sexual predators from playing Pokémon GO.

“Protecting New York’s children is priority number one and, as technology evolves, we must ensure these advances don't become new avenues for dangerous predators to prey on new victims," Governor Cuomo said. "These actions will provide safeguards for the players of these augmented reality games and help take one more tool away from those seeking to do harm to our children." 
At the Governor’s direction, DOCCS has imposed a new condition of parole for sex offenders under community supervision that will prohibit them from downloading, accessing, or otherwise engaging in any Internet enabled gaming activities, including Pokémon GO. The directive will apply to nearly 3,000 Level 1, 2 and 3 sex offenders currently on parole. The Department of Criminal Justice Services will additionally be providing guidance to county probation offices recommending the adoption of this policy. ​
This ban was announced almost immediately after the "Alarming Report by State Senators Jeffrey Klein and Diane Savino Detailing Dangers of Pokémon GO in Exposing New York’s Children to Sex Offenders."  As I noted in a post last Saturday, Senators Klein and Savino's report was indeed alarming -- not because it revealed that the game had actually been subjected to malicious use by sex offenders, but because it revealed the Senators' inability to keep their staff from playing a game in which they capture and battle imaginary creatures.

News outlets report on this ban here, here, and here. Douglas Berman also posts about the ban here and highlights Senator Savino's admission that "there's no evidence to any kids were sexually abused after being lured by the Pokémon app."

It's excellent to see a state government spend so much time and effort combating a problem that has not yet manifested. Additionally, it is fantastic that parole condition prohibits sex offenders on parole from downloading, accessing, or otherwise engaging in "any Internet enabled gaming activities," which would presumably include any game that requires the Internet to play, no matter whether there is any contact or potential contact with other players, both in the real world or cyberspace.

Thursday, August 13, 2015

"Bitcoin's Dark Side Could Get Darker"

That's the title of this interesting article by Tom Simonite over at the MIT Technology review. Simonite outlines a myriad of ways that online, "smart-contract" platforms such as Ethereum may be used to facilitate activities that, at best, are difficult to regulate, and at worst, are criminal.

From the article:

In a paper to be released today, Juels, fellow Cornell professor Elaine Shi, and University of Maryland researcher Ahmed Kosba present several examples of what they call “criminal contracts.” They wrote them to work on the recently launched smart-contract platform Ethereum
One example is a contract offering a cryptocurrency reward for hacking a particular website. Ethereum’s programming language makes it possible for the contract to control the promised funds. It will release them only to someone who provides proof of having carried out the job, in the form of a cryptographically verifiable string added to the defaced site. 
Contracts with a similar design could be used to commission many kinds of crime, say the researchers. Most provocatively, they outline a version designed to arrange the assassination of a public figure. A person wishing to claim the bounty would have to send information such as the time and place of the killing in advance. The contract would pay out after verifying that those details had appeared in several trusted news sources, such as news wires. A similar approach could be used for lesser physical crimes, such as high-profile vandalism.
Admittedly, not all uses of bitcoin and smart-contract platforms are criminal. But many non-criminal uses may still be very difficult to regulate. The article concludes:

“The potential for Ethereum to alter aspects of society is of significant magnitude,” says Wood. “This is something that would provide a technical basis for all sorts of social changes and I find that exciting.” 
For example, Wood says that Ethereum’s software could be used to create a decentralized version of a service such as Uber, connecting people wanting to go somewhere with someone willing to take them, and handling the payments without the need for a company in the middle. Regulators like those harrying Uber in many places around the world would be left with nothing to target. “You can implement any Web service without there being a legal entity behind it,” he says. “The idea of making certain things impossible to legislate against is really interesting.”

Monday, June 22, 2015

Google to Remove Revenge Porn Images from Search Results

From the BBC:

Victims of revenge porn will be able to put in requests to Google to take down content from search results. 
The images will still exist but won't come up on a list when people look for them.
In a blog post the company's Vice President Amit Singhal said it will apply to "nude or sexually explicit images". 
Google has, in the past, resisted attempts for it to take down online content from those search results. 
The update is expected to come in over the next couple of weeks.
Google's announcement regarding these requests can be found here.

Revenge porn occurs when people post nude photos of somebody else online without the pictured person's consent. It is one of many ways the Internet can be used to harass and attack people. Danielle Citron goes into great deal about revenge porn and other forms of online harassment in her excellent book, Hate Crimes in Cyberspace. And just yesterday, John Oliver's "Last Week Tonight" had this segment on online harassment and revenge porn:



I have blogged several times about state laws that prohibit revenge porn and whether they are constitutional. For example, I think that properly tailored laws can prohibit revenge porn without violating the First Amendment. But while laws prohibiting revenge porn may help combat the problem of revenge porn, laws alone are not enough without the involvement of companies like Google.

While images of revenge porn may still exist online, Google's promise to exclude them from search results upon request is a significant step towards lessening the impact of these images on victims' lives.

Tuesday, June 2, 2015

Supreme Court Narrowly Decides Online Threats Case, Elonis v. U.S.

At long last, the Supreme Court has issued an opinion in Elonis v. United States. I blogged about the opinion back when the Court granted certiorari in Elonis to answer this question presented:

Whether, consistent with the First Amendment and Virginia v. Black, conviction of threatening another person under 18 U.S.C. § 875(c) requires proof of the defendant's subjective intent to threaten, as required by the Ninth Circuit and the supreme courts of Massachusetts, Rhode Island, and Vermont; or whether it is enough to show that a “reasonable person” would regard the statement as threatening, as held by other federal courts of appeals and state courts of last resort.
Yesterday, the Supreme Court held that the "reasonable person" test is insufficient to support a conviction under 18 U.S.C. § 875(c). The Court did not address what level of intent is required to support a conviction, and the Court did not decide whether the reasonable person test was unconstitutional under the First Amendment.

The Court's opinion is available here. Coverage from Lyle Denniston at SCOTUSBlog is available here.

This high-profile case was eagerly awaited by many legal commentators, but ultimately resulted in a very narrow decision. Eugene Volokh notes the narrowness of the case here, and Orin Kerr argues that this narrowness was a good call.

While the Elonis case involved arguments touching on constitutional law, it is important to note that the Court explicitly avoided addressing First Amendment issues. Accordingly, while coverage noting that the Elonis decision is a victory for free speech may involve technically accurate descriptions of the ruling, readers should keep in mind that the Court did not wade into the question of whether 18 U.S.C. § 875(c) violates the First Amendment -- even if the statute is applied in a manner that asks whether a reasonable person would feel threatened by the statement.

Moreover, while the Court did indeed conclude that a defendant prosecuted under 18 U.S.C. § 875(c) must have a level of intent greater than negligence, it is important to note that this does not mean that a defendant must "intend to threaten" somebody in the conventional sense of the word. Summaries of the opinion claiming that defendants now must truly intend to make a threat, while accurate, may be misleading, since this language suggests that an individual must make a statement with the purpose to threaten somebody.

But the Court did not decide that a statement must be made with the purpose to threaten -- the Court simply held that it is not sufficient that the prosecution prove that a defendant negligently made a statement that would cause a reasonable person to regard the statement as threatening. A defendant may possibly violate 18 U.S.C. § 875(c) if he or she knowingly or recklessly makes a statement that another may feel threatened by. For instance the prosecution may succeed if it proves that a defendant made a statement that he or she knew would cause another to feel threatened, or that the statement would create a substantial risk that somebody else would feel threatened. The Court did not hold that the prosecution must prove that a statement is made with the purpose to threaten another. Readers in the legal community should have no trouble noting that "intent" does not necessarily mean "purpose." But I fear that the wider audience who reads broadly-worded commentary on the decision will be left with an impression that the Court's ruling is far wider than it actually was.

Ultimately, Elonis is a narrow decision, and I suspect that there is a great deal of litigation still to come that will attempt to answer the questions that Elonis leaves open. In the meantime, I hope that commentators and the general public will recognize Elonis for its narrowness rather than criticizing it or praising it for what it is not. Elonis is not a landmark victory for the First Amendment. Nor does it give people carte blanche to threaten others online. Elonis simply prohibits one way of interpreting 18 U.S.C. § 875(c) and leaves questions of free speech and required levels of intent for another day.

Tuesday, March 31, 2015

Silk Road Investigators Charged With Money Laundering and Wire Fraud

From the New York Times:

On the so-called dark web, drug dealing and other illicit sales have thrived in recent years, the authorities have said, through hidden websites like Silk Road and hard-to-trace digital currencies like Bitcoins. 
On Monday, the government charged that in the shadows of an undercover investigation of Silk Road, a notorious black-market site, two federal agents sought to enrich themselves by exploiting the very secrecy that made the site so difficult for law enforcement officials to penetrate. 
The agents, Carl Mark Force IV, who worked for the Drug Enforcement Administration, and Shaun W. Bridges, who worked for the Secret Service, had resigned amid growing scrutiny, and on Monday they were charged with money laundering and wire fraud. Mr. Force was also charged with theft of government property and conflict of interest.
The complaint can be found here. It alleges that in the course of their investigation into the Silk Road site, the agents obtained hundreds of thousands of dollars in bitcoins which they then deposited into their personal accounts.

Tuesday, February 3, 2015

Guilty Verdict in San Diego Revenge Porn Case

NBC San Diego has the story here. From the report:

A San Diego man was found guilty Monday of 27 felony counts for creating a so-called revenge porn website, where he posted more than 10,000 sexually explicit photos of women online to extort them for hundreds of dollars each. 
It took a court clerk 20 minutes to read the list of convictions against 28-year-old Kevin Bollaert, guilty of 21 identity theft and 6 extortion counts. A mistrial was declared on one conspiracy count and one identity theft count.
. . .  
The case — the first of its kind, filed by the California attorney general — centered on a now defunct website called YouGotPosted.com, created by Bollaert so ex-husbands and ex-boyfriends could submit embarrassing photos of victims for revenge. The photos also linked to victims’ social media accounts. 
Prosecutors say those who wanted to get the pictures taken down were redirected to another one of Bollaert's sites, ChangeMyReputation.com. There, the victims were charged $300 to $350 to have their photos removed.
I blogged about Bollaert's arrest back in December, 2013.

As the article also notes, California recently passed a law that criminalizes the sharing of sexually explicit photographs taken in the context of a private relationship. The first conviction under that new law was secured in early December.

California's recently-passed revenge porn law is a misdemeanor. But as Bollaert's conviction shows, those who base their businesses on revenge porn may face far more severe penalties from laws that are already on the books. Prosecutions of this nature may not be limited to defendants in California, since most states should have extortion and identity theft prohibitions that may apply to revenge porn websites.

Wednesday, December 3, 2014

The First Conviction Under California's Revenge Porn Law

The Los Angeles City Attorney announced that it has secured a conviction against Noe Iniguez, who posted nude photographs of his ex-girlfriend online. The Huffington Post and Mashable have reports on the story as well.

California's law against revenge porn was enacted in October 2013 and is currently codified at Penal Code 647(j)(4)(A). Originally, the law prohibited certain instances of distributing photos that one had taken of another person. It therefore did not apply to photographs that a victim would take of himself or herself. An amendment that will expand the law to apply to selfies was approved by the governor in September, 2014, and it is my understanding that this change will take effect in 2015.

Here is the current version of the law:
Any person who photographs or records by any means the image of the intimate body part or parts of another identifiable person, under circumstances where the parties agree or understand that the image shall remain private, and the person subsequently distributes the image taken, with the intent to cause serious emotional distress and the depicted person suffers serious emotional distress.
The City Attorney's announcement describes Iniguez's conduct, which seems to be a pretty clear violation of the law:

In December 2013, Iniguez, using an alias, allegedly began posting derogatory comments about his ex-girlfriend on her employer’s Facebook page. In March, 2014 Iniguez allegedly posted a topless photograph of the victim on her employer’s Facebook page which was accompanied by a message that called the victim a “drunk” and a “slut” and encouraged her firing from the company. The victim had previously secured a restraining order against Iniguez in November 2011 after receiving several harassing text messages following the breakup of their four year relationship.
I have noted before that revenge porn laws tend to draw criticism from commentators who argue that these laws violate the First Amendment. Indeed, Mike Masnick at Techdirt raises this point against the California law (though he makes sure to note that Iniguez does indeed sound "horrible").

But I think that California's law does not raise the same First Amendment problems as, say, Arizona's recently-halted attempt to criminalize revenge porn. The California law specifies that the law is limited to images that are shared in private circumstances, and therefore requires prosecutors to establish that the circumstances in which the image was initially taken or shared were private. Moreover, the law requires the prosecution to prove that the defendant specifically intended to "cause serious emotional distress," and that the victim suffered such distress. All of these parts of the law narrow the scope of the revenge porn prohibition and thereby limit the law's impact on speech.

While this is the first conviction under California's revenge porn law, several other cases are about to get underway -- as the California Attorney General has filed charges against several websites that specialize in sharing revenge porn. I blogged about one of those cases back in December when the case was at the arrest stage.

Those who are interested in revenge porn laws should pay attention to California. The upcoming cases should illustrate whether laws against revenge porn can be a reliable tool for punishing deplorable online behavior. And if any of these cases are appealed, I expect that the California Courts of Appeal will need to address the First Amendment implications of laws against revenge porn.

Thursday, July 24, 2014

Criminal Punishment for the Theft of Virtual Items?

From Erica Buist at The Guardian:

All right, own up: did you steal Mike Weatherley's sword on World of Warcraft? If so, you'd better watch out. He's really upset about it. So much so that, as David Cameron's chief adviser on intellectual property, he has asked ministers to consider passing a law that would mean people "who steal online items in video games with a real-world monetary value receive the same sentences as criminals who steal real-world items of the same monetary value".

. . .


"If you've spent £500 building up your armed forces and someone takes them away online, I guess you can feel hard done-by and you want your £500 back," he told Buzzfeed. He also pointed out: "The perception from some people is that if you steal online it's less of a crime than if you steal physically." 
It's hard to argue with his logic. Gamers spend a lot of money on virtual items, and invest time in building armed forces or gigantic warships. These things may be nothing more than a collection of pixels on a screen, but the money isn't virtual, and neither is the time, or the feeling of having been robbed.
Buzzfeed also covers this proposed law.

I agree that some aspects of online theft are similar to theft in the real world. Many online items are purchased with real money. Thieves can steal these goods under the pretense of exchanging or trading items, but then leaving upon receipt of the valuable goods. This entry in a World of Warcraft forum is an example of such a fraudulent transaction. Law students studying for the bar should recognize this as something resembling the quirky crime of larceny by trick.

But there are crucial differences between the theft of physical items or money and the theft of virtual goods in an online environment. Blizzard, the company that makes many of these online games, warns players of these online scams, but also says that they will "assist where possible" when a scam can be verified. And as the players in the earlier forum mention, if there is a chat record that details the fraudulent transaction, the player can usually receive another copy of their virtual good, and the person who stole the good will probably be banned.

If somebody can receive an identical copy of their stolen good once it is stolen, and if offenders face effective exile from the online world in which the theft takes place, I am not sure that prosecuting online thieves would be a constructive undertaking. It makes sense to criminalize online theft that results in the loss of money from a person's bank account (say in instances of identity theft). But when the theft deprives somebody of a virtual item that can be replaced with an identical item without cost to the website, the theft, while fraudulent, does not seem to cause enough harm to warrant criminal prosecution.

Monday, July 14, 2014

Greenberg on "Crypto-Anarchists" Cody Wilson and Amir Taaki

At Wired, Andy Greenberg has an excellent article on "crypto-anarchists" Cody Wilson and Amir Taaki. Wilson and Taaki are involved in projects like Dark Wallet that would make digital currencies like Bitcoins hard, or impossible, to trace. Wilson is the person behind Defense Distributed, the company that made the first gun entirely out of 3D printed parts. The article describes how Taaki and Wilson got involved with their endeavors and details their projects and goals.

From the article:

Dark Wallet also offers what it calls “stealth addresses” that allow a user to receive bitcoins at an encrypted address, where only he or she can retrieve them using a private key. When a coin passes through either a CoinJoin transaction or a stealth address, it becomes vastly more difficult to track, making taxation, regulation, and prosecution virtually impossible. “We want a bitcoin that laughs at the regulatory pageantry,” Wilson says. “We’re going to permanently problematize bitcoin’s reputation.”
. . . 
“Everywhere there’s a computer, there would be the promise of a gun,” [Wilson] told me when we first spoke in 2012. “I see a world where contraband will pass underground through the data cables to be printed in our homes as the drones move overhead. I see a kind of poetry there. I dream of this very weird future and I’d like to be a part of it.”
Wilson and Taaki pursue a vision of a world where people have "tools that make illegal behavior so commonplace and technically trivial that the law ceases to be relevant." People who agree with this vision embrace technologies like Bitcoins and 3D printers because these technologies upset existing legal regimes and therefore resist traditional regulation.

The interest in circumventing laws with new technology is not restricted to idealists like Wilson and Taaki. The article points out that groups promoting terrorism have specifically identified Dark Wallet as a useful tool for funneling illegal funds. Digital currencies like Bitcoins are increasingly used for illegal activities such as the sale of drugs and child pornography.

Wilson and Taaki's ideal of undermining traditional laws illustrates why governments need to develop regulations for emerging technologies, or adapt existing regulatory schemes to apply to new technology. Law has often lagged behind technological advances, but the need to bring law up to speed gains new urgency when those behind the development of technology are actively seeking to bypass regulations.

Additionally, this article illustrates the particular importance of legal scholarship that tries to answer questions about regulating new technology. Not only will this scholarship tend to be novel, but it will be useful, since legal scholarship on bitcoins, 3D printing, and other emerging technologies will be the first arena where legal questions about these new technologies are presented and answered.

Tuesday, June 17, 2014

Second Circuit Holds That Fourth Amendment Limits Government's Retention of Computer Files

So holds the court today in United States v. Ganias. In this case, Stavros Ganias, an accountant for two companies, IPM and American Boiler, whom the IRS suspected of theft and other crimes. 

In November, 2003, Army investigators obtained a search warrant to search Ganias's accounting business. The agents carrying out the search did not take the computers, but they copied the hard drives of each of Ganias's computers. The court noted that the files copied included information beyond the scope of the warrant, which was limited to files related to the "financial and accounting operations of [IPM] and American Boiler . . . ."

In 2004, the IRS began to suspect that Ganias was misreporting his own income. After further investigations revealed Ganias was misreporting the income of his clients, in February, 2006, the IRS sought to obtain Ganias's personal files that were contained in the data seized in 2003. After Ganias did not reply, the government obtained a new warrant and searched the files it had seized in 2003. The court emphasized that the government had retained these files for two and a half years since the initial seizure.

The Second Circuit concluded that this 2006 search of the files violated Ganias's Fourth Amendment rights. From the court's analysis:

[W]e consider a more limited question: whether the Fourth Amendment permits officials executing a warrant for the seizure of particular data on a computer to seize and indefinitely retain every file on that computer for use in future criminal investigations. We hold that it does not.  
If the 2003 warrant authorized the Government to retain all the data on Ganias's computers on the off-chance the information would become relevant to a subsequent criminal investigation, it would be the equivalent of a general warrant. The Government's retention of copies of Ganias's personal computer records for two-and-a-half years deprived him of exclusive control over those files for an unreasonable amount of time. This combination of circumstances enabled the Government to possess indefinitely personal records of Ganias that were beyond the scope of the warrant while it looked for other evidence to give it probable cause to search the files. This was a meaningful interference with Ganias's possessory rights in those files and constituted a seizure within the meaning of the Fourth Amendment.

The court then addressed the government's arguments for the constitutionality of keeping the information. Following its dismissal of each argument, the court concluded:

Because the Government has demonstrated no legal basis for retaining the non-responsive documents, its retention and subsequent search of those documents were unconstitutional. The Fourth Amendment was intended to prevent the Government from entering individuals' homes and indiscriminately seizing all their papers in the hopes of discovering evidence about previously unknown crimes. . . . Yet this is exactly what the Government claims it may do when it executes a warrant calling for the seizure of particular electronic data relevant to a different crime. Perhaps the "wholesale removal" of intermingled computer records is permissible where off-site sorting is necessary and reasonable, . . . but this accommodation does not somehow authorize the Government to retain all non-responsive documents indefinitely, for possible use in future criminal investigations. (citations omitted).
Notably, this case involves the seizure and retention of personal computer files that were beyond the scope of the initial warrant. The court does not explicitly address situations where files that are within the scope of the original warrant are held for a long period of time, and end up being relevant in another case against the defendant. And the court's repeated reliance in its arguments on the non-responsive nature of the computer files means that this case could be distinguished from situations where responsive files are seized and retained.

The logic of the opinion, however, lends itself to situations where law enforcement officers seize files that are within the scope of a warrant. Even if officers have a warrant to seize particular files, by retaining electronic copies of the files, the officers could probably be characterized as depriving the defendant of "exclusive control over those files," to use the Second Circuit's language. And if interference with this exclusive control for an unreasonable amount of time causes the government's conduct to amount to a search, there seems to be no reason why the Fourth Amendment wouldn't apply to any information the government copies and retains.

Monday, June 16, 2014

In United States v. Elonis, The Supreme Court Will Address the Complex Issue of Online Threats

Last September, I blogged about the Third Circuit case, United States v. Elonis, where the Third Circuit upheld Anthony Elonis' conviction under 18 U.S.C. § 875(c) making it a crime to "transmit in interstate or foreign commerce any communication containing any threat to kidnap any person or any threat to injure the person of another." In that post, I suggested that it was unlikely that the Court would take up Elonis' case.

I was wrong. Today, the Supreme Court announced that it will hear the case.

The Wall Street Journal Law Blog reports on the Court's announcement and summarizes the details of Elonis' conduct:
After his wife obtained a protection-from-abuse order, defendant Anthony Elonis took to Facebook and wrote on his page, "Fold up your PFA and put it in your pocket Is it thick enough to stop a bullet?" 
In another post, Mr. Elonis wrote, "Enough elementary schools in a ten mile radius to initiate the most heinous school shooting ever imagined." And after an FBI agent visited his residence, Mr. Elonis said that law-enforcement officers should bring an explosives expert on their next visit, "Cause little did y'all know, I was strapped wit' a bomb."
SCOTUSBlog's page on the case is available here, and it includes the text of the issue the Supreme Court will examine:

Whether, consistent with the First Amendment and Virginia v. Black, conviction of threatening another person under 18 U.S.C. § 875(c) requires proof of the defendant's subjective intent to threaten, as required by the Ninth Circuit and the supreme courts of Massachusetts, Rhode Island, and Vermont; or whether it is enough to show that a “reasonable person” would regard the statement as threatening, as held by other federal courts of appeals and state courts of last resort.
While the requirement that a defendant simply hold a subjective intent to threaten somebody is accepted by most courts as sufficient for conviction under this statute, the cases that have most recently challenged the subjective approach involve statements made over the Internet. In Elonis, the defendant was convicted for statements made on his Facebook page. In another case, Jeffries v. United States, which I blogged about
here and here, the Sixth Circuit held that the defendant, Franklin Jeffries, violated the threat statute when he posted a video to Youtube where he sang about killing the judge overseeing his custody dispute. The Supreme Court rejected Jeffries' petition for certiorari last October.

Wednesday, May 7, 2014

NSA's Failure to Monitor Minecraft Leads to Inevitable International Digital Terrorism

A while ago, I blogged about some classified documents released by Snowden that revealed that agents with the National Security Agency (NSA) had infiltrated World of Warcraft and Second Life. The agents set up characters and interacted with other users in an effort to uncover terrorism plots.

While the agents did not find any criminal activity, one could (perhaps sarcastically) argue that users are probably less likely to engage in virtual terrorism in World of Warcraft. While entire virtual cities have been destroyed in the past, I am aware of no similar destruction since news broke about the NSA's surveillance.

But in places where the NSA has not announced a presence, virtual terrorism remains. The BBC reports:

A virtual replica of Denmark created to help educate children has been disrupted by "cyber vandals". 
Small portions of it were blown up, despite a ban by its creators, the Danish Geodata Agency (DGA), on the use of "dynamite". 
Large US flags were erected at the starting area, as well as red, white and blue "America" signs. 
. . . 
Buildings were destroyed using virtual dynamite - the use of which had been banned on the Danish server - after users discovered it could be detonated when hidden in mining carts.

It is unclear at this early stage whether this incident will affect international relations. Thanks to the brave efforts of Minecraft users, the damage is being repaired and war will hopefully be avoided:

"It was the players who cleaned up the damage, replacing it with green grass and flowers the following morning," said [Chris] Hammeken, [chief press officer at the Danish Geodata Agency].
Privacy advocates may scoff at the NSA's surveillance of the digital worlds of Minecraft and World of Warcraft, but this incident reveals that in the absence of government surveillance, meticulously constructed buildings and landscapes may be wantonly destroyed. If that doesn't justify the forfeiture of online privacy, I'm not sure what does.

Friday, March 21, 2014

"MtGox Finds 200,000 Missing Bitcoins in Old Wallet"

That is the title of this BBC report:
The firm said it found the bitcoins - worth around $116m (£70m) - in an old digital wallet from 2011. 
That brings the total number of bitcoins the firm lost down to 650,000 from 850,000. 
MtGox, formerly the world's largest bitcoin exchange, filed for bankruptcy in February, after it said it lost thousands of bitcoins to hackers. 
"MtGox had certain old-format wallets which were used in the past and which, MtGox thought, no longer held any bitcoins," said Mt Gox chief executive Mark Karpeles in the filing
However, "on March 7, 2014, MtGox confirmed that an old-format wallet which was used prior to June 2011 held a balance of approximately 200,000 bitcoins," he said.
This is a bit of good news for MtGox's creditors, who previously were facing the prospect that almost all of MtGox's bitcoins had been stolen. But it casts even more doubt on how MtGox was running its business, since MtGox was apparently able to lose track of 200,000 bitcoins. This, on top of earlier revelations that MtGox continued to allow bitcoin trades when it knew that it did not have enough bitcoins to give back to their customers, makes MtGox a cautionary tale of just how much can go wrong in the world of bitcoin exchanges.

Tuesday, March 18, 2014

UCLA Moot Court Program Hosts Cybercrime Competition and Symposium: "Edward Snowden: Patriot or Traitor?"

One of the many hats that I wear at UCLA Law is that of being a problem developer for the UCLA Cybercrime Moot Court Competition. The competition took place this previous weekend, and twelve teams from nine schools competed. The University of Michigan came out on top, and UCLA was the runner-up. I had the opportunity to keep time for several rounds, and I thought that the competitors did an excellent job dealing with the problem (which consisted of a Computer Fraud and Abuse Act issue based closely on the upcoming United States v. Aurenheimer case, and an invented Fourth Amendment issue concerning police searches of unsecured wireless networks).

This year marked the first time that the UCLA Moot Court program hosted a symposium in conjunction with the tournament. The topic of the symposium was Edward Snowden: Patriot or Traitor? Five panelists debated this question. Stewart Baker of Steptoe & Johnson and Judge James Carr, a federal judge from the Northern District of Ohio (and former Chief Judge of the Foreign Intelligence Surveillance Court) argued Snowden was a traitor (although Baker made it immediately apparent that he was more comfortable with the claim that Snowden was a non-patriot, but not necessarily a traitor). Snowden's attorney, Jesslyn Radack, and Trevor Timm, the founder of the Freedom of the Press Foundation argued that Snowden was a patriot. And the Snowden family's attorney, Bruce Fein, argued that Snowden was neither a patriot nor a traitor.

A recording of the full debate is available here.

Wednesday, March 12, 2014

New Snowden Documents on NSA Use of Botnets

The Intercept reports:

Top-secret documents reveal that the National Security Agency is dramatically expanding its ability to covertly hack into computers on a mass scale by using automated systems that reduce the level of human oversight in the process. 
The classified files – provided previously by NSA whistleblower Edward Snowden – contain new details about groundbreaking surveillance technology the agency has developed to infect potentially millions of computers worldwide with malware “implants.” The clandestine initiative enables the NSA to break into targeted computers and to siphon out data from foreign Internet and phone networks. 
. . . 
In some cases the NSA has masqueraded as a fake Facebook server, using the social media site as a launching pad to infect a target’s computer and exfiltrate files from a hard drive. In others, it has sent out spam emails laced with the malware, which can be tailored to covertly record audio from a computer’s microphone and take snapshots with its webcam. The hacking systems have also enabled the NSA to launch cyberattacks by corrupting and disrupting file downloads or denying access to websites. 
The implants being deployed were once reserved for a few hundred hard-to-reach targets, whose communications could not be monitored through traditional wiretaps. But the documents analyzed by The Intercept show how the NSA has aggressively accelerated its hacking initiatives in the past decade by computerizing some processes previously handled by humans. The automated system – codenamed TURBINE – is designed to “allow the current implant network to scale to large size (millions of implants) by creating a system that does automated control implants by groups instead of individually.”
Wired also highlights that the NSA has been hijacking private botnets as part of its overall scheme. The NSA document describing that program is available here, but, as Wired admits, it is pretty short on the details and the purpose of the program. What the document does indicate is that the NSA has successfully taken over the command-and-control functions of several botnets and effectively controls 140,000 computers as a result of this approach.

Thursday, March 6, 2014

Class Action Lawsuit Against Mt. Gox Likely

News in the world of bitcoins has been dominated by the collapse of Mt. Gox, the world's largest bitcoin exchange. Investors' bitcoins that were stored with Mt. Gox were apparently stolen by hackers, resulting in the loss of $460 million. Wired has a thorough account of the hack, and the events leading up to the collapse.

Like many hacks on bitcoin exchanges, this story has drawn the attention of news outlets across the world, and has prompted some bitcoin critics to announce the death of the currency. Bitcoin enthusiasts are quick to respond that the currency is resilient and will survive this crisis. I am inclined to agree with this view, since bitcoins have survived previous hacks of exchanges, and attempts by governments to restrict the currency.

But Mt. Gox's collapse and bankruptcy is an event worth noting and continuing to follow, especially in light of the potential for lawsuits against the exchange. The Telegraph reports that hundreds of Mt. Gox customers are seeking to launch a class action lawsuit against the exchange. And the New York Times reports on the difficulty of embarking on such a lawsuit, given the immaterial and evasive nature of bitcoins as assets.

The collapse of Mt. Gox will almost certainly lead to litigation. It will be interesting to see how this litigation proceeds, and whether the plaintiffs have any success in recovering their assets.

Tuesday, February 25, 2014

Smolen et al. on Cyber Insurance

Miriam Smolen, Adrian Azer, and Katrina Johnson have a helpful article at the National Law Review where they discuss the differences between insurance policies that cover commercial general liability and policies that specifically cover risks of cyber-attack or sabotage. They write:

Most companies typically have traditional insurance policies that may cover cyber risks, including commercial general liability (CGL) coverage. CGL policies generally cover the company against liability for claims alleging “bodily injury” and/or “property damage” and also against liability for claims alleging “personal injury” and/or “advertising liability.” Insurers typically argue that “cyber” risks are not intended to be covered under CGL policies, but insureds have had some success in pursuing coverage for cyber risks. Insurers have begun to constrict CGL policy language in an effort to preclude coverage for losses arising from data breaches. In order to specifically cover the risks associated with cyber breaches, and to protect the company’s balance sheet, companies are looking toward cybersecurity insurance.
Smolen et al. go on to describe the types of coverage that cybersecurity policies typically provide. Policies may cover first party costs of investigating breaches and repairing systems, and there are also third-party policies that can protect companies from the costs of lawsuits due to any breaches that intrude on the private information of third-parties who deal with the insured.

Smolen et al. conclude by urging companies to purchase cyber insurance policies in light of insurance companies' narrowing of their commercial general liability policies. In light of today's increasing number and severity of cyber attacks, and the increasing amount of corporate and customer information that is stored in clouds and computers, companies would do well to heed this advice.

Friday, February 14, 2014

Will the Silk Road 2 Bitcoin Hack Give Rise to Negligence Lawsuits and Would this Litigation Succeed?

The BBC reports:

The anonymous online marketplace Silk Road 2 says it has been hacked resulting in the loss of all its customers' bitcoins. 
An administrator for the site said hackers had manipulated computer code enabling them to withdraw $2.7m (£1.6m) worth of the virtual currency.
It follows similar attacks on two exchanges that trade in bitcoins earlier in the week. 
Silk Road 2 is known for selling drugs and other illegal items. 
The site is only accessible through Tor, a network that allows users to browse anonymously online. The virtual currency Bitcoin is often used in transactions as it also grants users a degree of anonymity.
This incident may be particularly interesting to watch because of the notable degree of ineptitude demonstrated by the website's administrator, known (ironically) as Defcon. Defcon should have known that the website was vulnerable to this type of hack because an earlier, similar attack on the Slovenia-based bitcoin exchange firm, Bitstamp, occurred only a few days earlier. That hack made international news, with the BBC reporting about the attack and its underlying mechanics here.

Defcon himself admitted that he should have been taking more precautions:

"I should have taken MtGox and Bitstamp's lead and disabled withdrawals as soon as the malleability issue was reported. I was slow to respond and too sceptical of the possible issue at hand," he said in the forum posting. 
In an article for CoinDesk, a news site for digital currency, Danny Bradbury an expert on Silk Road, said that bitcoin-based sites should put "bitcoins under management in cold storage (ie stored offline) so that they could not be stolen by online attackers." 
Defcon said that all its customers' bitcoins were being stored online because of planned relaunches of some of the site's features. 
"In retrospect this was incredibly foolish, and I take full responsibility for this decision."
Several Silk Road 2 users suspect that Defcon or other website administrators may have been involved in the hack, which Defcon denies.

Even if Defcon was not maliciously involved in the hack, it seems that his administration of the website was notably foolish. The failure to halt withdrawals in light of widespread reports on Bitcoin security breaches and the storing of all customers' Bitcoins online both contributed to the success of this hack. These failures, combined with Defcon's admission that he should have taken additional precautions, set the stage for a substantial negligence lawsuit against Defcon and Silk Road 2.

As far as I am aware, there have not been many similar negligence lawsuits against Bitcoin exchanges. I am aware of one lawsuit that is pending in California against the Bitcoin exchange, Bitcoinica, following the loss of thousands of Bitcoins following a hack on the exchange. The complaint in that case is available here. And at The Verge, Adrianne Jeffries reports on obstacles that case may face here. Jeffries also reports on another lawsuit against Bitcoin exchange Tradehill, but that lawsuit apparently has proceeded to arbitration.

While the Bitcoinica lawsuit is in its early stages, potential problems with that lawsuit highlight issues that may arise in a lawsuit against Silk Road 2. From Jeffries:

The plaintiffs may face some challenges. The question of jurisdiction is not addressed, and although some of the plaintiffs live in San Francisco, Bitcoinica is now based in the UK. The suit also hopes to pull in up to 100 defendants. "Bitcoinica is an entity of unknown form and origin," says the complaint, which names three defendants and "Does 1 through 100." A representative for Intersango declined to comment. The lawyer for the plaintiffs declined to comment because his lead client could not immediately be reached.
Similar problems may arise in a lawsuit against Silk Road 2. Bitcoin exchanges operate in a world of anonymity, and it may be difficult for plaintiffs to determine the true identity and location of website administrators like Defcon.

It will be interesting to see if any lawsuits result from this recent hack. Because the facts are very favorable for a negligence lawsuit, and because millions of dollars were lost as a result of this hack, I think that there is a high possibility of legal action. If lawsuits occur, this will be a good opportunity to see how the plaintiffs and courts address the obstacles of the defendants' anonymity.

Sunday, January 19, 2014

A Fridge That Sends Spam


A fridge has been discovered sending out spam after a web attack managed to compromise smart gadgets.
The fridge was one of more than 100,000 devices used to take part in the spam campaign.

Uncovered by security firm Proofpoint the attack compromised computers, home routers, media PCs and smart TV sets.

The attack is believed to be one of the first to exploit the lax security on devices that are part of the "internet of things".
This news follows quite soon after my previous post where I mentioned Peter Bright's op-ed in Ars Technical where he warned that these types of security breaches would likely result from poor security in household appliances that are connected to the internet.

This fridge incident lends support to Bright's point, and indicates that developments in internet connectivity will bring concerns about computer security and privacy to many more areas of life beyond phone and computer use.

Thursday, January 16, 2014

The Second Amendment Implications of Regulating 3-D Printed Firearms

Earlier, I posted about proposed California legislation that would require people to apply for serial numbers when making a firearm and affix this number in some way to the firearm. In that post, I concluded that the law would probably apply to 3-D printed firearms and I agreed with Josh Blackman's commentary that parts of the proposed statute seemed vague.

Towards the end of that post, I reiterated my view that the law will need to adapt to regulate 3-D printed firearms. 3-D printing technology is developing, with blueprints for home-printed firearms appearing on popular printing websites, and printed, metal firearms arriving on the scene. I noted that regulations on 3-D printed firearms could have Second Amendment implications, and in this post I seek to explore these implications.

While 3-D printing technology is still in a relatively early stage of development, I am not the first person to address the constitutionality of regulations on 3-D printed firearms. Peter Jensen-Haxel has written on the subject in the Golden Gate University Law Review. The full citation for his comment is: Peter Jensen-Haxel, 3D Printers, Obsolete Firearm Supply Controls, and the Right to Build Self-Defense Weapons Under Heller, 42 Golden Gate U. L. Rev. 447 (2012).

Jensen-Haxel correctly points out that the Supreme Court's decision in District of Columbia v. Heller established that individuals have a right to bear arms. While Heller struck down a firearm restriction because it prohibited the possession of usable handguns in the home, Jensen-Haxel is also probably correct to conclude that the ruling likely extends to the ability to procure a handgun. After all, if individuals are completely restricted purchasing or acquiring a handgun, they are effectively prohibited from possessing a handgun in the home. This seems to be the logic that was underlying the opinion of the Northern District of Illinois when it struck down Chicago's ban on acquiring firearms within city limits in Illinois Association of Firearm Retailers v. Chicago. If there is a Second Amendment right to acquire a firearm, restrictions on 3-D printers may implicate the Second Amendment, since 3-D printing is one way that people may acquire firearms.

But it is important to note that while the Second Amendment may indeed be implicated by restrictions on 3-D printing, it does not follow that these restrictions would violate the Second Amendment. Rights enumerated in the Constitution and its amendments are rarely recognized as conferring an absolute restriction on the government. As I have mentioned previously, courts have interpreted Heller as conferring some protection to the right to bear arms, but not unlimited protection. While the Supreme Court has not established a standard of review for Second Amendment cases, the lower courts typically uphold laws that restrict firearm possession if that laws pass intermediate scrutiny, meaning that the laws are substantially tailored to achieve important government interests.