Home Computers Connected to the Internet Aren't Private, Court Rules
eweek.com
eweek.com
Just because a home computer might be hacked does not mean that an average user doesn't expect his experience on that computer to be private. Every area of life might be breached by determined intruders and, if that were the test of having a expectation of privacy, then every area of life would flunk it. Your home, your car, your bathroom, your bedroom, you name it. In reality, of course, break-ins, hacks, and other intrusions are the exception and not the rule in the areas we commonly regard as private. If the legal test on protecting privacy were to turn on whether break-ins or hacks were a regular element of the environment (however infrequent), then the exception swallows the rule and privacy is no more. This judge's ruling essentially embraces such logic and is thus wildly out of line with existing law regarding protection against unreasonable searches and seizures.
Also bad judging in reaching the issue gratuitously: the main issue here was whether a particular warrant was misused; it was unnecessary to decide what would have happened without a warrant of any kind. Yet the judge reached to inject his obiter dictum into the analysis as a sort of by-the-by, "here is what I would rule if other issues were before me."
Why such an outcome? As the lawyers say, "hard facts make for bad law." You have a despicable perp doing vile things and the natural instinct is to want to nail him. Just as, conversely, when you have a sympathetic person who has being seriously wronged, the natural instinct is to do what you can to help him get justice. In either case, judges and juries will be more prone than otherwise to engage in results-oriented jurisprudence and will thus try to bend and shape the law to that purpose even if the law objectively says otherwise. This factor may help explain why the judge did what he did. It does not make it right.
Finally, bad judging means, in this case, bad precedent and this decision will surely have pernicious effects until the day comes when its run is ended by a higher court. For this case, that day will surely come. It is a bad decision all around.
So when a judge says there isn't a reasonable expectation of privacy, he/she isn't even being honest with themselves, let alone the entirety of the computer-owning public. This is a bald-faced hand-out to law "enforcement" and has no bearing in reality.
He may not be a member of the computer-owning public. The article refers to him as "Senior U.S. District Judge Henry Coke Morgan Jr.". Senior status is not a title like Senior Engineer[1]. Rather, it means that he is actually semi-retired: He is paid his pension and travel expenses and has discretion over which cases to take. For example, there is one judge that is basically retired and lives on Cape Cod. However, he occasionally holds court down there in order to handle traffic cases for those caught speeding on federal land so that they don't have to go up to Boston. Judges on Senior status often decide to not do sentencing and they pretty much universally decline to hear Child Porn cases.
There is some fraction of Senior Status judges who don't use Outlook or Gmail but rather have their secretaries print their emails, they handwrite the responses, and their secretaries type up their emails and send them.
Considering all of this and the fact that he was born in 1935[2], he may genuinely believe that if he has a home computer that infection with viruses and weird pop-ups is inevitable.
Sources:
[1] a talk given at the Haystack Observatory by the Clerk of Court for the District of Massachusetts
[2] https://en.wikipedia.org/wiki/Henry_Coke_Morgan,_Jr.
---
Edit: Of course, this isn't the majority of judges by any means. Many of them are comfortable writing opinions from their iPad while at an airport. Also, consider Scalia's opinion in Riley v. California, which this opinion would seem to directly contradict (once I can actually find the pdf...)
Turns out the judge, in whose chambers there was a picture of him on an all-American football team in the 1960s, was dumbfounded that a DVD could contain 80,000 emails and about 30,000 other documents. The opposing counsel, equally aged, agreed.
We were literally saved by lunch -- we were able to track down the judges clerk and get her to translate.
Yep, I agree. While I hesitate to participate in age-based discrimination, my gut feeling on this is that he simply isn't qualified to make a ruling about the nature of digital privacy.
Anybody got his secretary's email address? Here are some mailing addresses and phone numbers. It's 7pm in VA right now. http://www.vaed.uscourts.gov/locations/nor.htm
Doesn't this open up for an appeal
Sometimes people on HN complain when security researchers are threatened with prosecution under the CFAA. Well, which is it - is exploiting vulnerabilities more akin to peering through someone's window blinds with unintended gaps, or burglary?
For example, a Florida appeals court recently ruled that peaking through "a gap accidentally left in a window" was violative of the Fourth Amendment.
There's a whole series of window peaking, gate crossing, fielding entering, etc. cases. They tend to turn on the very specific facts of the case, such as whether the police intruded on a private space to look through the window, or whether the occupant sufficiently indicated that the space was private.
No. No it isn't. This ruling does not state that hacking is legal, it says that it isn't a 4th Amendment violation.
As I said in https://news.ycombinator.com/item?id=12016508
>Someone not having a reasonable expectation of privacy in a thing does not mean it is legal to hack their computer.
And there's an explicit legal exemption of hacking for law enforcement in the CFAA.
Judges are supposed to be experts at the law and better at this stuff than "regular normal people". That's why they spend years in law school, and why judges aren't just randomly selected from the general population.
> then ... to justify their rulings
Well, unless justification and judgment aren't pretty much synonym, that's a contradiction? The subconscious decision met by such a judge should be guided by an organic sound understanding of justice. The verbalization of this kind of emotion should only bring up the true reasons of thought, maybe polished and cut short. At least, that would be my lame excuse.
He signed a bunch of documents where he promised to not disclose anything. He was perfectly aware that he was violating those agreements as well as probably both civil and military law.
Regardless of how important an impact the release had he's still a traitor to the US. No number of "privacy is an illusion" rulings will change that.
I presume that capital punishment is an option for traitors which makes getting of the hacking charge a minor thing anyways.
In the case of Snowden, question is if the acts disclosed were illegal.
Snowden's various NSA oaths are supersceded by his oath to uphold and defend the Constitution of the United States. Which he did.
Snowden wasn't acting as a law enforcement officer performing a search of personal information subject to the 4th Amendement, but as a citizen and US Government employee or contractor, having sworn an oath to defend and protect the Constitution, to do so through exercise of his own 1st Amendment free speech rights.
And should be lawful under those grounds.
The opinion is here: https://www.eff.org/files/2016/06/23/matish_suppression_edva.... The discussion of the IP address issue starts at 43, and the discussion of the privacy issue starts at 47.
The first decision is reasonable: no matter how you try to obscure things, an IP address is public information. Some third-party must have your IP address in order for you to receive packets.
The second decision is, of course, unreasonable. Saying you have no expectation of privacy in the contents of your computer because it can get hacked is like saying you have no expectation of privacy in your house because it can get broken into.
I suspect that on appeal, the former decision will stand and the latter will not.
> However, the Court FINDS that any such subjective expectation of privacy - if one even existed in this case - is not objectively reasonable. SA Alfin testified that when a user connects to the Tor network, he or she must disclose his or her real IP address to the first Tor node with which he or she connects. This fact, coupled with the Tor Project's own warning that the first server can see "[t]his IP address is using Tor," destroys any expectation of privacy in a Tor user's IP address.
I strongly disagree with this conclusion: the only logical conclusion one can make is that the defendant didn't have a reasonable expectation of privacy of he or she participating in the Tor network. But Tor doesn't anonymize users by magically hiding IP addresses but by making the actual origin of a request unknowable. Tor users do have a reasonable expectation of privacy of their IP addresses not being disclosed as the actual origin of some communication.
So no, in my opinion the court decision is not reasonable at all. And by the way, I find the analogy of Tor anonymizing users by "masking" IP addresses, problematic, at least.
This is not just bad judging this is bordering onto absurdity.
If my house is a mile off any public road on a private drive, surrounded by trees, I have a different expectation. I might be more comfortable sunbathing nude, etc. being fairly sure that I'm in a private setting.
If I have a computer and it's not on any network, or only on a private network that I fully own, I expect it is private. At least as private as any papers I have in my desk.
If I use that computer to connect to a public network and access public resources, I have less expectation. I know that at minimum, the resources I access will know that I have done so. I know that it's possible for others on the network to see my traffic. I have exposed my computer to the outside world, and with that comes foreseeable risk, just as I take on foreseeable risks when I do anything else in the outside world.
So I think I agree that by using the internet, I have some reduced expectation of privacy. I think I agree that warrantless monitoring of my activities on the network, e.g. tracking IP addresses and what sites I connect to, etc. is probably OK, just as anyone can follow me around in public and see what places I visit without needing a warrant.
I don't think I agree that this extends into actually invading and searching my computer from the network, even though it may be possible to do that. I think this is like arguing that a warrant is not needed to enter my home and read my mail, on the basis that the correspondence was transported over a public network (the postal service). Or to listen to my phone calls because I'm using the public telephone network. So on that point the judge did go too far and I'd expect that to be overturned on appeal.
So I think there is some rational argument here, but that it went too far in its conclusions.
The term "bad judgment" implies a mistake and some good faith, something a diplomatic lawyer like Grellas would likely do by impulse. Not being a lawyer or obligated to diplomacy here, I'd call it a despicable, bad faith maneuver.
Note that the judge cited the Apple-FBI story:
>Tor users likewise cannot reasonably expect to be safe from hackers. Even if Tor users hope that the Tor network will keep certain information private -just as terrorists seem to expect Apple to keep their data private - it is unreasonable not to expect that someone will be able to gain access
Are they just perceived to be less vulnerable?
Android also has a sandbox, but is more permissive about running things outside it: still, by default it's pretty locked down.
Windows is not locked down that way, and most programs will require admin access for installation, at least.
I could be wrong, but if that's the case, it sounds to me like the defendant didn't have a reasonable expectation of privacy. I think of it as sending a letter with no return address. If the letter is addressed to a criminal enterprise, and there is a reasonable expectation that the sender is engaged with said criminal enterprise, to the extent that the FBI can trace that letter back to the sender seems that it would be legal, in my opinion.
However, the TL;DR of this article seems to be that nobody's computer can be expected to be private because everyone's computer can be hacked. I don't think that's what the judge intended with this decision.
I am not so sure.
Yes, the Judge could have ruled defendant's have a reasonable expectation of privacy for devices connected to the internet. And while it may even be true subjectively, I think the Judge did get it right objectively.
A lot of people in this thread, and you to some extent, suggest that this judge's ruling is the non-digital equivalent of saying a person does not have a reasonable expectation on their home because those too can be broken into the same as an internet connected device. Even in your examples you list "your home" and "your car", but as you know, legally, a home and car don't carry the same expectation of privacy from a 4th amendment analysis. Further, just because a internet connected device and home can be broken into that does not make it a good or fair analogy. Internet connected devices can be broken into by anyone, anywhere in the world so long as they have an internet connection, that is not the case with a home. Nor can people protect their digital data with lethal force the same way one might protect their home. The threats to privacy and the privacy protections for an internet device and a physical home are simply not the same.
Perhaps a better way to distinguish a home and internet connect device is to use other precedent as an analogy. A public phone booth (reasonable expectation of privacy) vs speaking on your private cell phone in public (no reasonable expectation of privacy). Trash in your house (reasonable expectation of privacy) and when you put in on the curb for pick up (no expectation of privacy), might be good for saying non-internet connect device (privacy) and internet connected device (no privacy).
So why don't I think it bad decision?
Lets just say if the Judge did rule there is a reasonable expectation on internet connected devices, it wouldn't stop the Gov. They could always hide behind the non-Gov search/seizure argument in future cases. In other words, the Gov could always say they didn't hack a defendant's internet connected device, that a non-Gov actor searched/seized the data and anonymously provided the evidence to the Gov; therefore, the evidence is not subject to 4th amendment protections. Again not something likely to happen in any of these non-digital analogies (i.e. police are not going to claim the person who broke into your home, while breaking into your home seized evidence of your crimes and gave it to the police anonymously).
As much as we would all like to have a reasonable expectation of privacy on our internet connected devices, we don't objectively; therefore, I think the court reached the right decision. Definitely if the security of the devices improves to keep out Gov and non-Gov actors alike (objective expectations), then our reasonable expectations (subjective) and the law can change with it.
I would argue that it's only relatively recently that people have started to associate an internet connected machine with the potential for a lack of privacy.
People have begun to realize that making a secure device is difficult, but that doesn't mean they don't expect some degree of privacy.
Most certainly don't expect that connecting their laptop to Wifi that they control and pay for automatically reduces the privacy of things contained on their laptop, and only on their laptop to zero.
Further, the expectation is that security and privacy is a feature that all (well, most) companies are actively working to improve, and therefore a fluid definition of an expectation of privacy is dangerous, I think.
>People have begun to realize that making a secure device is difficult, but that doesn't mean they don't expect some degree of privacy.
I totally agree and just think a lot of people in the thread don't understand 4th Amendment law and are conflating 4th amendment analysis of reasonable expectation of privacy with the separate right to privacy.
The Judge's ruling is very limited: In a criminal case the Gov can introduce evidence of a crime they collected from a device connected to the internet they obtained without a warrant.
My point is, even if the Judge said the introduction of said evidence violates the 4th Amendment and should be suppressed...legally such a ruling would still be limited and have no effect of the Gov's actual efforts to collect all that data without a warrant. The only practical effect such a ruling would have is that once the Gov has evidence of a crime then they will obtain a narrow search warrant or alternatively (as I mention above) introduce the evidence as collected by a non-Gov 3rd party (not subject to 4th Amendment protections).
>Further, the expectation is that security and privacy is a feature that all (well, most) companies are actively working to improve, and therefore a fluid definition of an expectation of privacy is dangerous, I think.
Yes, fluid definitions can be dangerous, but it can also be the most beautiful and powerful thing about the law. One such example separate but equal being defined constitutional in Plessy v Ferguson, then being redefined as unconstitutional in Brown v Board.
That is certainly a good point, however I guess I'm projecting my bias by presuming that this particular ruling should have skipped over the Plessy v Ferguson equivalent and landed immediately on Brown v Board.
I think a reasonable expectation of privacy should be the goal for everyone manufacturing hardware and developing software, especially as the world gets more and more connected.
The fact that it's not a reasonable expectation for a layman is a black mark on our industry (software and hardware), and is something we should work to change (by actually making secure software).
[Edit:] furthermore the fact that DoJ etc are sitting on zero-days, thus decreasing (by not increasing) the security of our systems is most definitely a negative contribution to this fight.
A home can be broken into by anyone, anywhere in the world so long they communicate that wish to someone who is near and willing to break into peoples home for money.
> Nor can people protect their digital data with lethal force
That's what the legal system is for. They will apply force, lethal in some cases, if a criminal break the law. People no longer need to hire a private army to protect their home.
> the Gov could always say they didn't hack a defendant's internet connected device, that a non-Gov actor searched/seized the data and anonymously provided the evidence
Its a common TV troop in crime shows where the police will break into someones home, and just before doing it, they say into the camera: "when we got here, the door was already open". While its true that the actually police could do this, it is very much illegal, and equally illegal would it be for the police to claim that a non-Gov actor did the break in and provided the evidence anonymously.
This seems like an argument for someone looking over your shoulder when using a mobile device, or a laptop, in a public place.
How do any of those examples have any bearing on someone actually hacking the device? Most devices have policy and counter-measures built-in to specifically prevent any kind of unauthorized access.
For example, every device running the popular operating system Windows has a firewall built-in and activated by default.
It is not apples to apples, but take the trash example.
Case law holds that you have reasonable expectation of privacy in the trash inside your home (i.e. the Gov can not introduce evidence collected from the trash inside your house without obtaining a warrant). Lets call that the non-internet connected device, which AFAIK would still have 4th Amendment protections.
Now lets say you take that trash to the crub, all the sudden case law says you no longer have reasonable expectation of privacy of said trash (i.e. the Gov can collect the trash without a warrant and introduce any evidence of your crime they collect from said trash). This in my analogy would be the internet connected device, this court says no longer has 4th Amendment protections.
You could put a lock on your trash can that you remotely unlock only when the trash man gets there, but the case law says you lost expectation of privacy when the trash hit your curb (i.e. the internet connection) its not a matter of the ongoing defensive measures you took to maintain privacy. Moreover, if I shredded documents evidencing my crime that I then put on the curb, I do not regain my expectation of privacy (4th Amendment protections) because I took defensive measures to avoid anyone being able to read the documents.
By taking the trash to the curb, or throwing away your hard drive, you signal that you no longer care about said trash/data. You probably still care about the data on the device that you haven’t yet decided to throw away. The point is you can review how much of the data, if any, that you’re throwing away, you don’t care about. Someone hacking your device doesn’t give you the opportunity to make this consideration.
To continue with your analogy, hacking a device that someone still owns is exactly like breaking into someone’s house to go through their trash. The internet connection is just a medium by which the break-in occurs.
My experience is that the average person today assumes their devices are not secure and any information they have is accessible to the government without warrants.
I guess I expect my privacy/security in most cases, but I'm aware of the realities and try to prepare for that privacy/security to be violated.
That alone, if it is the force behind the judge's opinion/ruling, makes it invalid, right? Facts? Or do they have no place in a modern US courtroom?
Because burglars regularly break into people's homes or cars doesn't make them subject to warrant-free search. If the FBI wants to run code on my CPU in my private home without my permission, they should have a warrant, just as they'd need one to manipulate other objects in my home without my consent.
"In today's digital world, it appears to be a virtual certainty that computers accessing the Internet can—and eventually will—be hacked."
To apply to houses:
"In today's mechanized world, it appears to be a virtual certainty that houses connected to the earth can—and eventually will—be broken into."
Thus, warrants need not apply for search and seizure in houses. QED.
Or rather "... houses with doors can —and eventually will—be broken into."
And of course, do not speak at home (or do not expect any privacy).
I guess the answer is "sometimes, it's complicated"...
This may be all BS. But it's advice I've heard more than once.
Home windows? If it is visible from a place where a normal person going about their normal activities can see, then no warrant.
For example, if someone walks up your walk to your stoop and there are windows that can been seen through from there, then no warrant. If they have to step off your walkway, walk around the side of your house, scramble through your bushes and pull themselves up to peer through, then a warrant would be required.
The point of mentioning "accessing the internet" is it's a lot easier for the hacker to scale up their wrongdoing with ease. It's much simpler to put a virus of some sort (say, a fake download button on a media sharing site) and reach a large audience, than it is to break into the homes of a similarly large group of people.
Where I primarily disagree with the judgment is that this notion makes it a "virtual certainty" that hacking occurs for any given person. Smart browsing habits, and general computer literacy, can make the odds decrease to near zero.
I suppose the analogy would be that just because Microsoft has the power to remotely upgrade your windows 10 install (and potentially install any back-door), that should not violate your expectation of privacy.
His argument is essentially that if your house is connected to a road, then there is no expectation of privacy.
I expect the ruling, or at least that absurd part of it, will be overturned or superseded. But the counter argument (for future cases) would be that running through a physical firewall is not a direct connection to the internet (silly as it is to make the argument).
Edit: I've gone through most of the relevant sections. Most of the ruling is reasonable, the section this article and the EFF are complaining about is less supported by precedent.
The actual legal argument says that hacking is common enough that people don't have a reasonable expectation of privacy, then there's this paragraph:
>Although this Court recently noted in dicta that the possibility of hacking "is not enough to defeat an individual's reasonable expectation of privacy" because it is illegal, see United States v. Darby, No. 2:16-cr-36, ECF No. 31 at 10-11 (E.D. Va. June 3, 2016), this Court stresses that child pornography often resembles an international crime. Similarly, much hacking occurs by foreign nations where the governments condone or participate in hacking. Child pornography is not just a national issue; it is an international issue, and at least a portion of the pornography in this case arrived from foreign sources through the World Wide Web
This seems to be the weakest part. It's saying that hacking can't be the basis for a lack of expectation of privacy, but that since some countries allow hacking, it's legal there, and if you're accessing stuff from other countries you no longer have the expectation of privacy.
The heinousness of the crime does not justify giving up or overriding Constitutional freedoms. Never. Not ever.
And if anyone is in place to protect us from that level of overreach, it's a judge. I cannot believe he's pulling a "won't someone think of the children!" in justifying (and creating some janky circular logic) this ruling.
The scariest precedent here is the level of crime dictating the flexibility of constitutionality.
And all of this doesn’t matter anyway, because of how packet routing works. No one accessing the Internet can be reasonably expected to have any control over how their packets are routed on the network. You only control the next hop[2].
See for example: http://allthingsd.com/20131120/how-somebody-forced-the-world...
So I would agree to the extent that there can be no expectation of privacy for any unencrypted traffic. However, that’s just one type of hacking – snooping.
As for actual hacking – that is someone breaking into your system – this system has to be running on something, some sort of device. This device has to be physically located somewhere.
If an Elbonian comes to US and breaks into your house is it okay because in their country there are no lock on the doors, just a lot of mud, so breaking is not a crime? This is the logic here, as I see it.
What it ultimately comes down to is the US government wants to have it both ways. They want to be able to extradite people that hack into devices located in the US, but they want you to have no expectation of privacy when they are the ones doing the hacking.
[1] https://en.wikipedia.org/wiki/Provider-independent_address_s...
If they came to the US they would be subject to US jurisdiction. Hackers from other countries aren't, at least not always.
Edit: I mean prosecution. Jurisdiction applies whenever there are effects in the US, see link below.
("No Soldier shall, in time of peace be quartered in any house, without the consent of the Owner, nor in time of war, but in a manner to be prescribed by law.")
Now every last amendment from the Bill of Rights has been discarded.
Thanks for that. A good reminder that we need to think that every time we read anything like this. Just asking a simple question, "Did they get this right?" and even taking a minute to read through to the actual primary source.
"Thus, hacking resembles the broken blinds in Carter. 525 U.S. at 85. Just as Justice Breyer wrote in concurrence that a police officer who peers through broken blinds does not violate anyone's Fourth Amendment rights, jd. at 103 (Breyer, J., concurring), FBI agents who exploit a vulnerability in an online network do not violate the Fourth Amendment. Just as the area into which the officer in Carter peered - an apartment - usually is afforded Fourth Amendment protection, a computer afforded Fourth Amendment protection in other circumstances is not protected from Government actors who take advantage of an easily broken system to peer into a user's computer. People who traverse the Internet ordinarily understand the risk associated with doing so. Thus, the deployment of the NIT to capture identifying information found on Defendant's computer does not represent a search under the Fourth Amendment, and no warrant was needed."
The section of interest starts on page 47 of the linked Opinion and Order. http://mobile.eweek.com/security/home-computers-connected-to...
"But whether the Constitution really be one thing, or another, this much
is certain - that it has either authorized such a government as we have
had, or has been powerless to prevent it. In either case it is unfit to exist.”
-- Lysander Spooner, No TreasonIt is axiomatic that the present we now know inevitably followed from the history that preceded it. When you look at the U.S. federal government that now exists, it must have assumed its current form either by design of the Constitution, or contrary to that design. In case of the latter, the Constitution was entirely unable to prevent the government that it established from evolving into a form contrary to its design. Maybe the process was slowed somewhat. We cannot know for certain.
Therefore, if you dislike the current form of US federal government, it is nonsensical to idolize the Constitution, or any other causally-related fact of history. History gave us the present. If you do not like the present, and wish the future to be different, do not repeat the mistakes of the past. Whether history could have given us another present is irrelevant, because it did not.
In the end, whenever a living human fights with a document, the human will emerge victorious, and the document will become confetti. The Constitution is nothing without a living human to be its champion.
Spooner was criticizing the actual form of our current Constitution. GP was making an appeal to the Constitution and the judicial system's ignoring of it. I agree with Spooner that a Constitution such as ours is completely powerless to prevent individual judges from rewriting every time it fits their fancy.
We've basically had an ongoing Constitutional Convention in the federal courts since the founding -- without the consent of the people.
https://www.eff.org/deeplinks/2016/06/making-sense-troubling...
https://www.eff.org/deeplinks/2016/06/federal-court-fourth-a...
It is very concerning indeed, but will hopefully not be a precedent. At least if common sense and a basic level of constitutional competence prevails.
Rule 41 is a huge concern---as mentioned in the EFF posts---and risks decisions like this becoming commonplace. As the EFF mentions, it also encourages forum shopping: finding a court lax on fourth amendment issues, in this case.
rough translation: "The right to confidentiality and integrity on IT systems"
google translate link: https://translate.google.com/translate?hl=de&sl=de&tl=en&u=h...
As far as I remember the CCC wrote an expertise in the ruling and mentioned computerized implants. That was the point were the judges understood that there should be an expectation of privacy on home computers.
The CFAA does not depend on any expectation of privacy, only authorized usage.
Expectation of privacy defines the bounds of a search. Police searches are not permitted to conduct otherwise illegal activity Just because they are searching.
https://www.law.cornell.edu/uscode/text/18/1030
>(f) This section does not prohibit any lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency of the United States, a State, or a political subdivision of a State, or of an intelligence agency of the United States.
So something can't be illegal for the police to do for the sole reason that it violates the CFAA. If it violates something else, I suppose CFAA charges can be added on, though.
Obviously, this will be struck down..
But it does raise the question what do we do when a judge refuses to understand basic law concepts? Can we than fire the judge?
This was a federal district judge, who under the U.S. Constitution (Article III) has life tenure and can't be fired; he can be removed from office only if impeached by the House of Representatives and convicted by the Senate after a trial.
The chief judge of the district could cut this judge's case load to zero [0]. In this case, though, (A) that's very unlikely to happen, and (B) the judge would still stay on full salary.
[0] EDIT: This sort of happened, for example, to (now-former) federal district judge Sam Kent in Galveston after he was accused of "inappropriate touching" of female court employees. See http://www.chron.com/news/houston-texas/article/Criminal-cas... Kent later pled guilty to a felony charge of making false statements to investigators; he tried to retire from the bench so as to keep his pension, but that pissed off the House judiciary committee, which pushed through articles of impeachment, which caused Kent to resign. He served not quite three years in prison. See http://bigbendnow.com/2011/08/disgraced-former-judge-complet... and https://en.wikipedia.org/wiki/Samuel_B._Kent
Instead of firing him, I think he should be teached. This judgement should be used as example of bad judgment.
Did you mean taught (something) or impeached?
Ben Franklin had some thoughts on this as documented here:
https://en.wikipedia.org/wiki/Retention_election#U.S._states...
It's state judges (in some states) who are elected. This was a federal district judge; they're appointed for life by the president with the advice and consent of the Senate.
But the ruling won't hold, because it is dumb and bad.
The judge in this case at least seems to understand where the others did not that the IP Address had to be obtained by questionable means.
But decision reads: "The Court notes, however, that perhaps malware is a better description for the program through which the provider of the pornography attempted to conceal its distribution of contraband over the Internet than for the efforts of the Government to uncover the pornography."
The conclusion is that Tor is more malware than the FBI spyware.
I am not entirely dissuaded by govt's logic re expectation of privacy. Most porn/torrent sites do attempt to install spyware/malware. Everyone knows this. Whether the govt should be doing this is another matter entirely.
I am more distressed by the fact that this judge is allowing the FBI to use this tool and not allowing defendant access to its source code in discovery. This is unacceptable.
[0]: [pdf] http://www.steptoe.com/assets/attachments/4903.pdf
-Couldnt agree more
http://www.usatoday.com/story/news/2015/01/19/police-radar-s...
The IP not being secret is supported by precedent from other cases, it seems reasonable that if the government can trace it back without hacking the computer it should be fine.
The keywords are "exploit a vulnerability". In that sense, I'm inclined to agree with the judge.
Put another way, are broken blinds all that different from an unsecured (though attempting to be secured) network?
The counter might be: using an exploit of any kind is akin to first breaking the blinds yourself.
The same is not true of broken computer security, where usually the owner believes that the security feature does its job.
I'd say a better analogy would be a lock. The owner believes that the lock works and will keep people out. The fact that the lock can be picked doesn't mean everyone should expect their locks to be useless, nor does it allow the police to pick a lock to get into someone's house without a warrant.
Exploiting a vulnerability is more like using a bump key or picking the lock on the door. Would it be weird if the cops could pick the locks on your door without a warrant (you know they're all crap locks because hardly anyone knows the difference).
>This section does not prohibit any lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency of the United States, a State, or a political subdivision of a State, or of an intelligence agency of the United States
kicking a door to your apartment at 3 in the morning and sending the dogs in is also exploiting a weak vulnerable door.
Basically the FBI puts cameras on utility poles to look into suspects yards. Because a human could also climb a pole, it doesn't need a warrant.
Brilliant. Finally we can do away with all the stupid laws we have. Private residences are also not immune from invasion. In fact, even a 9-year old child could easily throw a rock through a window, reach in and unlock it, open it up and do whatever they please. The fridge is not locked with a secure method so they can have whatever they want from there--there's no reasonable expecation of it being immune from invasion and theft, so why should it be illegal? This judge is a genius. In fact, this judge is showing us how important it is to do away with silly laws. No one is immune to being punched, kicked, stabbed or shot, and in fact it is quite easy for someone to do that as a matter of fact, if they certainly decide to do so, so we can finally do away with all those ridiculous laws pertaining to assault, rape and murder as well. Another great day for us. We're making progress in America!
While the judge's statement and ruling seem to defy both logic and precedent, this didn't start here, and it doesn't stop here. The government and FBI in particular have long been trying to approach and establish the notion that it's okay for the "good guys" to hack, and not okay for the "bad guys" to hack. This ruling doesn't establish that, but will people in favor of this ruling draw the logical conclusion and say what used to be criminal hacking is no longer a crime, that an online bank has no expectation of privacy and it's being hacked and the money stolen is inevitabile? Would this same judge throw out a case of criminal hacking? I doubt it.
When I read about decisions like this, I often wonder if judges are purposefully making these nonsensical rulings so that the higher courts are forced to take the cases and make valid decisions. Though, I'm still undecided as to why this might be; perhaps the judge isn't up to the task of making a complicated ruling, some personal bias that favors one side of the law, or wishing to look good in front of the Feds in hopes that he or she can move up in the court system.
So... hack the government freely now? "You were the idiots that connected the system to the web... you should have no expectation of privacy."
Put a more insane way: "Your doors were unlocked therefore invading your home was not a crime."
This will have to be struck down to preserve our democracy I would think. Insanity.
Total aside: DoJ is really dropping the ball and will have to decide whether they want to prosecute hackers or enable their own hacking. Can't really support both.
Although, they run the risk of their gambit being discovered, the devices removes, and losing the shipment.
The judge had found, by tighter reasoning, that law enforcement didn't violate the Fourth Amendment in using their tools to find the defendants IP. Then, having gone through that, for no obvious reason, goes on to decide that no one has an expectation of privacy on their personal computers because computers are so full of security holes and hackers are so sophisticated these days that, essentially everyone has 'broken blinds' that anyone else in the world can see through on what would ordinarily be considered a private space.
It boggles the mind.
Up to that point the judge basically says "The defendant decided to go somewhere questionable and do something illegal -- since the FBI was watching, controlling, in fact that questionable place that was more or less public but dedicated to illegal activity, they had every reason to collect information because of probable cause".
Great! Perfect! There is a lot of precedent. I'm reminded of when the FBI took over a biker bar that was known to be a nexus of drug trade and bugged the place and wired it for surveillance and put people who went there and were seen doing illegal things under surveillance themselves. From what I understand, it was a fruitful endeavor. But this is like they did that then decided since the road that connects to that bar also connected to houses that could be seen from the street, any of those houses can be searched. It's insane.
We need to turn it around: draconian punishments for "law enforcement" members who violate the constitution, and protections for individuals who tinker, probe, or explore without malicious actions/intent.
Good luck getting that budget passed.
While the the slippery slope is not a valid argument it is always interesting to think about how precedent like this could spiral out of control.
It is so beautifully vague, it an extremely common prosecutorial tool.
I would love to see it overturned, but that seems incredibly unlikely.
The criterion should be open and clear: "Does the government need to get on your internet connected PC (or mail, or whatever else)? Is that beneficial to society?".
Whether you expect your mail or PC or whatever to be private or read by others is beyond the point.
Even whether it's publicly visible should be beside the point (the same way that whether you have your door open or not, nobody has the right to just get into your house without your consent).
E.g. one's public moves (location in time) is public knowledge too, but a society should be able to decide that it's illegal for the government (or even companies and individuals) to aggregate that information about a person, or even more so all citizens.
Even if some third parties still have it, your location data on your telco's servers (period) is something very different than your location data on an advertiser's servers or your location data on some government agency servers.
If I walk down a street in a bad neighborhood, I may or may not "expect" to be mugged, but regardless of what I expect, or what anyone placing bets on me expects, I have the RIGHT not to be mugged.
Edit: In other words, mugging is a crime and unreasonable searches & seizures are crimes.
Know what else gets me about this "expectations" bit - it's ass-backwards. Like "hacking happens a lot, therefore hacking is okay." Well, armed robbery happens a lot, therefore that judge has no reasonable expectation of not being robbed at gunpoint - it's totally fine everybody!
For that matter, the child porn they're trying to stop happens a lot. If you're going to be consistent you now have to say no child has a reasonable expectation of not being exploited.
The law is not a weather vane that swings depending on whichever way people want to break it!
- Celebrities have no expectation of privacy on their cell phones (including photos)? - Home security systems offer no expectation of privacy (they are remotely connected)? - There is no expectation of security with the IoT?
Computers connected to the Internet are all part of these things.
What other things would this impact?
IPv4 LANs vs IPv6 LANs.
To me, a first criterion of computer security of an operating system is that it be able to run any software at all, including software that tries to be malicious, and connect to any communications at all, all quite safely.
Does meeting this criterion really have to be too difficult?
With this criterion met, the judge will be wrong.
While I have no sympathy for the defendants in this case, computing is important and so is secure computing.
What people should always remember is that statute or no statute, expectation of privacy or not, precedent or no precedent...
The jury system needs to be thoroughly re-educated in their rights to nullification. If we use these precedents to arrest child abuse criminals today and ten years from now it becomes used to quell dissent the jury's who sit for these trials MUST know their power to nullify the trial/law being charged...
From wiki..."The jury in effect nullifies a law that it believes is either immoral or wrongly applied to the defendant whose fate they are charged with deciding."
— H. L. Mencken
--separate thought--
I actually haven't thought much about the legality of the Feds running JS on a visitor's computer. I never had any issues with it, even being a complete psycho-libertarian in the extreme. I understand the wording of this particular ruling is distasteful but ignoring that does running JS on a visitor's computer need a warrant?
I'm still pondering it but it seems similar to the Feds busting a store that was a front for selling drugs and then tracking everyone that went in that store.*
The analogy isn't perfect because in the computer case they are actually planting a "bug" in private property (assuming our personal computers are still considered private). Whereas in the drug case the Feds could simply follow these people to their homes and then they know their address.
The analogy can be made better if the Feds put a tracking device inside the drugs that the visitors to the "drug store" purchased. These people then are carrying the tracker into their own home, unbeknownst to them. Similarly the web surfers accessing the compromised site are downloading a tracking script onto their computer without realizing.
My intuition tells me that we want the Feds to need to get a warrant to deliver JS to visitors of a child porn site but not to get a warrant for each individual visitor.
I would be quite interested to hear people's thoughts.
* The use of this fictional scenario does in no way imply my support of the U.S. government's policies on the legality of drugs nor imply recognition of said government's ability to determine this for individuals. :-p
It is funny to me to have to think about the physical location of a server that I am accessing being important. Like my fate depending on whether I was routed to a server in Georgia vs. Kentucky, something I absolutely do not think about whilst navigating the internet.
Basically, the only people they ended up busting were people who for some reason decided it was a good idea to download and run an executable being served by their favorite CP site on the "darknet".
VPN can secure the tunnel, still you can be tracked to IP/MAC quickly. Same to P2P network such as torrent etc.
My take is that when you go surfing, considering the device you used for surfing just like your home mailbox, home address, phone number etc, those are pretty much public info that anyone can find out who you are if they are interested in you.
Nothing I see talks about the contents of the computer, so in the real world this would be the equivalent of the police tailing you after a crime to find out your home address so they can subsequently get a warrant to search said property.
If it's truly this limited, than I don't have a problem with it.
I actually think privacy is dead anyway for all practical purposes, but twisted logic reasoning always irks me...
Most "hacking" today is actually downloading some malicious code, which then takes over the computer system. It's like saying, "Hey, come into my house and go through my stuff. But, only take what you want after you've looked through it."
That'll be the next argument made by the government for a ruling. IANAL, but as scary [and wrong!] as it is, it seems logical.
That's basically the impression I'm getting here. If we're going to base expectation of privacy on whether or not it's possible to break into something, then it's reasonable to assume that this applies to one's own home and that the Fourth Amendment is officially dead in the eyes of this judge.
Note that they aren't saying it's legal for a regular person to hack, only that hacking doesn't produce 4th Amendment violations.
Rejecting the Rule Of Law is dangerous. If the government doesn't respect the laws - including their spirit - then why should the people? You might have notice the recent rise populism. Many people are tired of an oligarchy that only vaguely follows the law that is supposed to be "of the people, for the people and by the people". Rulings like this and other events that don't even pretend to respect the Constitution are interpreted as proof that democracy has already failed.
Brexit, the drama in the recent primaries, and other forms of "trumpism"[1] are examples of the growing blowback. Do you really want to support the path towards more civil unrest and other types of instability?
I'm not talking about a technical reading of the law that takes into account modern legal theories and precedent. This is about the perception that a lot of people have that the social contract has failed. As Blyth said (see my previous [1]), "The Hamptons is not a defensible position".
Because eventually, every thought every human ever has will be on the internet, and at THAT point, humanity will have evolved into the Borg.
Might as well get in line to get your smartphone implant installed and welcome the future.
If the judgement applies to all computers connected to the internet that means one can hack into any system legally because the target has no privacy expectations.
"Sorry, you need a warrant."
"But, it's this type of crime."
"Oh, in that case go right ahead."
In what way is that even valid? The "type of crime" determines whether you need or warrant or not?
A judge in Rhode Island rules that people should have no expectation of owning their belongings while they are outside of apartments, because no person on the street 'is immune from robbery'."
In other words, can the average user expect privacy on their home always-connected machine? I mean this as a technical, not legislative, question.
If true, then why is entering any device connected to the Internet a crime?
"You put your computer on the network, BigCorp, you should have no expectation of privacy. The case against Mr. LeetHaxx0r is dismissed."
Orwell was an optimist.
Sweet.
If you can not expect privacy on your Home Computer, you can not expect privacy in your home. End of story.
A "Home Computer" was a computer intended for use in the home, while a "Personal Computer" was a computer intended for use by a single person.
Home Computers were also Personal Computers, but the reverse wasn't true: many Personal Computers were intended for business use. If everyone at a company had a computer in their cubicle, those computers were Personal Computers, but not Home Computers.
This distinction used to be important because Home Computers and business PCs were separate markets, and the machines were as different as you could imagine. They were made by different companies, used different CPU and bus architectures, and ran different operating systems. For example, in the 8-bit era, business PCs all used Zilog Z80 CPUs on the S-100 bus, were made by a legion of white-box manufacturers, and all ran the CP/M operating system, while Home Computers were made by names such as Commodore, Atari, Tandy, and Apple, typically had MOS 6502 processors (except Tandy, who used the Z80 but not on the S-100 bus), and ran barebones operating systems developed in house, which were little more than BASIC REPLs with some disk I/O features added.
Nowadays almost nobody bothers making the distinction. Yeah, sure, the big companies have separate "home" and "business" product lines, but they're all going to be x86 machines running Windows, and you can get both from the same company (see: Dell's Inspiron and OptiPlex lines), so people don't really make a distinction anymore, and seeing someone use a phrase like "Home Computer" in the 21st century feels like an anachronism.
When the IBM PC came out, it and the legion of clones took over the business PC market and replaced the S-100 CP/M market almost overnight. So when "PC" is just used to refer to business PCs and the IBM-compatible DOS/x86 platform completely and thoroughly dominates the business PC market... than naturally the term "PC" will come to be synonymous with that platform.
If not, doesn't this only apply to home routers?
As a long-time IT Guy who has grown tired and disgusted with GOV's fascist, class-war behavior, with this court decision I say to them:
Bring. It. The. FSCK. On.
While maintaining an air-gapped rig is a PITA, I can do that.
While conducting my Connected Life via a live image, removable-media-based system is a PITA, I can do that as well.
While good encryption slathered on everything is annoying, it is doable.
BTW, GOV... As long as you are connected to a network, you have no reasonable expectation of privacy;
Expect your thoughts and beliefs laid bare; your plans to be known by others sooner, rather than later; your secrets to be learned by all;
You want to see what Cyber Warfare _truly_ looks like?
You can't handle the truth.
The only real option you have left is using a typewriter with a one-time pad in a sound isolated room with a sheet over your head. And even then what you type isn't anonymous, it's just encrypted to withstand everything up to, but not including, some government agent holding a wrench (insert xkcd comic here)
At a superficial level, I think I would notice extra chips/wiring/HD showing up on a naked Mo-board.
Going further, as you wish to approach this in pseudo-apsolutist terms, GOV would simply choke on any effort to go _that_ far. Be it the Hardware Effort or the Software/Data Collection and Processing Effort (times many many millions), they would gag on The Spew. Yes, no encryption protects data for ever, blah blah. Good Encryption and other impediments just makes persuit/enforcement not worth the effort [insert THX-1138 reference and every real-world example of governments failing to absolutely control their populace here].
And since I am willing to talk in Absolute Terms, GOV is lousy at math. They may know something about Social Psychology, Propaganda, et al, but the Citizenry has both the guns and the numbers.