Sunday, April 15, 2012

Case o' The Week: Nosal, No Sale, for Gov't -- - Nosal and the CFAA




Chief Judge Alex Kozinski
"Minds have wandered since the beginning of time and the computer gives employees new ways to procrastinate, by gchatting with friends, playing games, shopping or watching sports highlights. Such activities are routinely prohibited by many computer-use policies, although employees are seldom disciplined for occasional use of work computers for personal purposes. Nevertheless, under the broad interpretation of the CFAA, such minor dalliances would become federal crimes. While it’s unlikely that you’ll be prosecuted for watching Reason.TV on your work computer, you could be. Employers wanting to rid themselves of troublesome employees without following proper procedures could threaten to report them to the FBI unless they quit. Ubiquitous, seldom-prosecuted crimes invite arbitrary and discriminatory enforcement." 

United States v. Nosal, 2012 WL 1176119, *4 (9th Cir. Apr. 10, 2012) (en banc), decision available here.


Players: Important win for appellate gurus Ted Sampsell Jones (argued), and Dennis Riordan. Decision by CJ Kozinski, joined by eight judges. Dissent by Judge Silverman, joined by Judge Tallman.

Facts: Nosal worked for an executive search firm. Id. at *1. He started a competing company, and convinced some of his former colleagues to download confidential files from his old firm, to use in his new one. Id. “The employees were authorized to access the database, but [the executive search firm] had a policy that forbade disclosing confidential information.” Id.

Nosal was indicted on many counts, including violations of the Computer Fraud and Abuse Act (CFAA), 18 USC § 1030. Id. Nosal challenged the CFAA counts, arguing that this wasn’t unauthorized access into a computer (hacking), but (if proved true), was theft of data by folks who had legitimate access to the files.

ND Cal District Judge Marilyn Patel agreed and dismissed the CFAA counts, holding that the CFAA prohibits hackers from accessing computer information without authorization – not theft by employees who are authorized to access the data. Id. A three-judge panel reversed. See generally blog description of three-judge panel decision, here.

The case went en banc.

Issue(s): “Computers have become an indispensable part of our daily lives. We use them for work; we use them for play. Some-times we use them for play at work. Many employers have adopted policies prohibiting the use of work computers for nonbusiness purposes. Does an employee who violates such a policy commit a federal crime? How about someone who violates the terms of service of a social networking website? This depends on how broadly we read the Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030.” Id. at *1 (emphasis added).

Held: “We need not decide today whether Congress could base criminal liability on violations of a company or website’s computer use restrictions. Instead, we hold that the phrase ‘exceeds authorized access’ in the CFAA does not extend to violations of use restrictions. If Congress wants to incorporate misappropriation liability into the CFAA, it must speak more clearly.Id. at *7.

Of Note: Gallons of ink will be spilled on Nosal and its impact on computer crimes – it is a very important case. Putting all that aside, read Nosal simply for the enjoyment of joyful legal writing. CJ Kozinski – a computer geek in judge’s clothing – gets it: the government’s interpretation of the CFAA would have criminalized logging on a work computer and “g-chatting with friends, playing games, shopping or watching sport hightlights.” Id. at *4.


Are you of a libertarian bend, prone to tuning into “Reason.TV” while at work? Id. Do you hit Ebay, while filling out timesheets and CJA vouchers? Id. at *5 &n.8. Visit Hulu and JDate? Id. Netflix and Pandora? Id. Do you describe yourself on Craigslist’s dating site as “talk dark and handsome,” when you’re really “short and homely?” Id. at *5. The Chief has no problem with you getting fired – but he and the Ninth don’t want you prosecuted for a federal crime.

How to Use: Fellow blogger Steve “Rule of Lenity” Sady loves Nosal - and you should too. CJ Kozinski explains that the rule is not only intended only to protect citizens, who need fair notice of criminal laws. Id. The Rule of Lenity also ensures “that Congress will have fair notice of what conduct its law criminalizes. We construe criminal statutes narrowly so that Congress will not unintentionally turn ordinary citizens into criminals.” Id. at *7. Great quotes for the defense bar’s favorite rule of construction.

For Further Reading: Are you making too much of a “simple little case,” bringing cutting-edge challenges on “silly issues” that make prosecutions slow and expensive? You must have been hanging out with Carl Gunn. For three decades Carl has been the government’s gadfly while serving in three Defender offices – you’ll remember him as the rebel who “gunned” for the Marshal’s shackling policy in L.A.. See Howard blog here.
Carlton Gunn

 Carl’s now semi-retired, and is maintaining a very interesting blog in his new private practice life. See "Hanging out with Carl" blog hereHit Carl’s blog for a great essay on challenging “controlled substance” priors in federal court – it is a valuable new site to add to your RSS feed.



Image of the Honorable Chief Judge Alex Kozinski from https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_ktMUCFReOnm3MpnUnrk30W8hRqg140moDlb0ZlNyrM3Bw7C0S5QME1x9G60pxR4q8vsaUDQQ8UZKLmlSUgrqr32btiKTLjQMCZAPrTitXCNKtjeY3rMNdPjo9qqhfrzkXFO5lw/s1600/judge+alex+kozinski.jpg


"Reason TV" logo from http://www.reason.tv/


Steven Kalar, Senior Litigator N.D. Cal. FPD. Website at www.ndcalfpd.org

.


.

Labels: , , , , , ,

Sunday, May 08, 2011

Case o' The Week: NSFW - Nosal and "Unauthorized" Access to an Employer's Computer

A slow week in the Ninth let's us reach back a bit to discuss an interesting, albeit disappointing, decision on the Computer Fraud and Abuse Act ("CFAA.") United States v. Nosal, 2011 WL 1585600 (9th Cir. Apr. 28, 2011), decision available here.

A warning, first: after
Nosal, do NOT click here if you're viewing this on a work computer - quite possibly a federal crime, to do so .
Link

Players: Decision by Judge Trott, hard-fought appeal by ND Cal appellate guru Dennis Riordan.

Facts: Nosal worked for a headhunter firm. When he left, he signed a non-compete agreement. Id. Despite this agreement, Nosal recruited three of the firm’s employees for his new, competing business: those employees allegedly transferred information from the old firm’s computer database to Nosal. Id. at *2.

The old firm had significant security measures on their computers: passwords, confidentiality stamps on all reports, and warnings against unauthorized access. Id. at *2.

Nosal and one of his accomplices were charged federally with violations of 18 USC § 1030(a)(4), the Computer Fraud and Abuse Act. Id. District Judge Marilyn H. Patel dismissed five counts on the defendant’s motion, concluding after the Ninth’s recent decision in LVRC Holdings v. Brekka that the CFAA only applied to hacking a computer (or directories) where the employee did not otherwise have no access. Id. at *3. The government took an interlocutory appeal. Id. at *1.

Issue(s): “The government contends . . . that Brekka counsels in favor of its interpretation of the statute – that an employee exceeds authorized access when he or she obtains information from the computer and uses it for a purpose that violates the employer’s restrictions on the use of that information.” Id. at *1.

Held: “Although we are mindful of the concerns raised by defense counsel regarding the criminalization of violations of an employer’s computer use policy, we are persuaded that the specific intent and causation requirements of § 1030(a)(4) sufficiently protect against criminal prosecution those employees whose only violation of employer policy is the use of the company computer for personal – but innocuous – reason.” Id. at *1. Brekka held that a person accesses a computer without authorization ‘when the person has not received permission to use the computer for any purpose.’ 581 F.3d at 1135. Today, we clarify that under the CFAA, an employee accesses a computer in excess of his or her authorization when that access violates the employer’s access restrictions, which may include restrictions on the employee’s use of the computer or of the information contained in that computer.' Therefore, we REVERSE the district court’s decision . . . .” Id. at *8.

Of Note: With all respect to the majority, dissenting Judge Tena Campbell – a visiting D.J. from Utah – has the better argument. Id. at *8. She persuasively argues that the key phrase relied upon by the majority – “exceeds authorized access” has much broader meaning (without an intent requirement) in other parts of the same statute, making the majority’s decision unconstitutionally vague. Id. Congress meant this statute for hacking, she explains, and she worries (with reason) that the majority’s decision makes any unauthorized action on a employer’s computer a federal crime. Id. at *9-*10. (How many millions of apparent federal criminals were checking their brackets during March Madness this year, one wonders). Judge Campbell also doesn’t buy Judge Trott’s heavy reliance on one word in the statute, (“so”) to salvage the government’s interpretation. Id. at *10.

Worth noting that in another recent case (which just went en banc), a great dissent by a visiting district judge caught the Ninth’s eye: the majority decision will hopefully soon be corrected. See United States v. Leal-Felix, 625 F.3d 1148, 1151 (9th Cir. 2010) (Bennett, D.J, dissenting). Here’s hoping that Judge Campbell is as persuasive a visitor as Judge Bennett, and that Nosal gets some much-deserved en banc scrutiny.

How to Use: As noted above, Nosal’s novel holding deserves en banc review, and a PFR seems likely. Preserve pretrial challenges to § 1030(a)(4) charges – Nosal will hopefully not be the last word on this statute.

For Further Reading: Who was Nosal’s attorney? Joe Russoniello, at one point – ring a bell? (Picture left). For more on the Nosal saga, and why the ND Cal USAO is still in the case, see blog here.


Image of the March Madness brackets (obtained while at a home computer), from http://www.betvega.com/march-madness-printable-bracket/

Image of (former) United States Attorney / (former) David Nosal defense counsel, David Nosal, from http://informant.kalwnews.org/2010/08/web-extra-extended-interview-with-joe-russoniello/



Steven Kalar, Senior Litigator N.D. Cal. FPD. Website at www.ndcalfpd.org

.

Labels: , , ,