Saturday, July 09, 2016

Case o' The Week: Share? Beware. - Nosal and Shared Passwords as CFFA violations



Share passwords?
You really shouldn’t. Your IT staff will yell at you.
(That, and you’ll go to federal prison).
United States v. Nosal, 2016 WL 3608752 (9th Cir. July 5, 2016), decision available here.

 
The Honorable Judge Margaret McKeown, and the Honorable Chief Judge Sidney Thomas

Players: Decision by Judge McKeown, joined by Chief Judge Thomas (above). Dissent by Judge Reinhardt. Hard fought-appeal by SF counsel Dennis Riordan, Donald Horgan and Ted Sampsell-Jones.

Facts: Nosal left Korn/Ferry, a headhunting company, to start his own firm. Id. at *2. Korn / Ferry had a confidentiality agreement that prohibited password sharing. Id. at *4. Nosal’s accomplices circumvented their revoked accessed credentials, and consensually used an assistant’s password to access Korn / Ferry’s database for information to take to Nosal’s new enterprise. Id. at *2. Nosal was convicted after trial. Id. at *10.

Issue(s): “This is the second time we consider the scope of the Computer Fraud and Abuse Act (“CFAA”), 18 U.S.C. § 1030, with respect to David Nosal. The CFAA imposes criminal penalties on whoever ‘knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value . . . .’ Id. § 1030(a)(4) (emphasis added). Only the first prong of the section is before us in this appeal: knowingly and with intent to defraud accessing a computer ‘without authorization.’” Id. at *1. 

“The question we consider is whether the jury properly convicted Nosal of conspiracy to violate the ‘without authorization’ provision of the CFAA for unauthorized access to, and downloads from, his former employer's database called Searcher. Put simply, we are asked to decide whether the ‘without authorization’ prohibition of the CFAA extends to a former employee whose computer access credentials have been rescinded but who, disregarding the revocation, accesses the computer by other means.” Id. at *2 (footnote omitted). "

Held: “[W] e conclude that ‘without authorization’ is an unambiguous, non-technical term that, given its plain and ordinary meaning, means accessing a protected computer without permission. This definition has a simple corollary: once authorization to access a computer has been affirmatively revoked, the user cannot sidestep the statute by going through the back door and accessing the computer through a third party. Unequivocal revocation of computer access closes both the front door and the back door.” Id. at *1. 

“We . . . . hold that Nosal, a former employee whose computer access credentials were revoked by Korn/Ferry acted ‘without authorization’ in violation of the CFAA when he or his former employee co-conspirators used the login credentials of a current employee to gain access to computer data owned by the former employer and to circumvent the revocation of access.” Id. at *9.

Of Note: Dissenting Judge Reinhardt explains that this holding extends the CFAA to most of us who share passwords. Id. at *19 (Reinhardt, J., dissenting). It is a compelling opinion, that wonders how this extension of the CFAA statute to consensual password sharing can be reconciled with the very real policy concerns of Nosal I. 
  En banc, encore?

How to Use: A (thin) silver lining in this case is reversal and remand on the restitution award, for attorney fees. Id. at *18. Korn / Ferry hired “premier” attorneys, and the opinion insinuates that this private firm did a fair chunk of the USAO’s work. Id. 
  Judge McKeown warns that private attorneys “are not a substitute for the work of the prosecutor, nor do they serve the role of a shadow prosecutor.” Id. An interesting admonishment, for those of us who have endured Silicon’s Valley’s pricest private counsel sitting chummily at the USAO’s table.
                                               
For Further Reading: Professor Kerr has an interesting, albeit somewhat self-promoting, analysis of Nosal II in a Washington Post piece here. 

A very thought-provoking op-ed comes from Harvard Law Professor Noah Feldman, available here





Steven Kalar, Federal Public Defender N.D. Cal. Website at www.ndcalfpd.org


.
.

Labels: , , , , ,

Sunday, October 04, 2015

Case o' The Week: 1,600 Pages, Yet Called "Briefs" - Christensen and Federal Hacking Statute



“Defendants have raised a staggering number of issues on appeal. Their briefs – fourteen in all – totaled over 900 pages.” . . .  “The government is similarly verbose. Its answering brief was nearly 700 pages.” United States v. Christensen, 2015 WL 5010591, at *2 & n.1. (9th Cir. Aug. 25, 2015), decision available here.
  
We’ll skip an issue or two here, and focus on (the winning) one.



Players: Decision by Judge Clifton, joined by Judges Fisher and Chief D.J. Christensen. NorCal’s own CJA Counsel Steven Gruel on the briefs (among others).

Facts: Private investigator Anthony Pellicano (above) illegally tapped calls for his clients. Id. at *2. He paid Turner, a phone employee, to grab needed data. Id. He paid LAPD Officer Arneson, to search confidential police databases for information about targets. Id. Along with other defendants, Turner and Arneson were charged with a bevy of wiretapping and RICO crimes and convicted after trial. Id. at *1. 

Specifically, Turner was convicted of aiding and abetting computer fraud under the Computer Fraud and Abuse Act (“CFAA”). Arneson was convicted of unauthorized computer access of US agency information. Id. at *11.

Issue(s): Was the jury erroneously instructed that it was a crime if Turner and Arneson accessed computers with authorization, but used that access to obtain data beyond that authorization. Id. at *12.  

Held: “Following the convictions, this court decided United States v. Nosal, 676 F.3d 854 (9th Cir. 2012) (en banc). Nosal held the term “exceeds authorized access,” an element of both offenses under the CFAA, to be ‘limited to violation of restrictions on access to information, and not restrictions on its use. Id. at 864. Based on Nosal, we vacate the convictions under the CFAA.” Id. at 11 (emphasis in original). 

“The jury instructions defining both computer fraud and unauthorized computer access of United States agency information were plainly erroneous under Nosal. The error was prejudicial. We therefore vacate Turner’s conviction for aiding and abetting computer fraud, Arnerson’s convictions for computer fraud and unauthorized computer access, and Pellicano’s convictions for aiding and abetting both computer fraud and unauthorized computer access.” Id. at *13.

Of Note: One of (many, many) issues in this appeal was the alleged targeting and ultimate dismissal of a juror in one of the trials involved. Id. at *50 (Christensen, Chief D.J, concurring in part and dissenting in part). Judge Christensen (D. Montana) pens a particularly compelling dissent, strongly suggesting that the juror was targeted for questioning (and excused) not because on his ability to follow the law, because of his (pro-defense) views of the merits of the case. Id. 

This thoughtful dissent on juror independence – and the majority’s counterpoint on jury nullification – is buried in a long opinion, but is an important issue. As Chief Judge Christensen explains, the issue bears directly on the “Sixth Amendment right to a unanimous and impartial jury.” Id. at *53. Worth wading through a long decision to get to this most-troubling dispute.

How to Use: Trying to save Arneson’s conviction (the cop), the government argued that Nosal doesn’t limit criminal liability for access of government information – state and federal laws prevent such access. Id. at *12. The Ninth isn’t buying it. “Congress has created other statutes under which a government employee who abuses his database privileges may be punished, but it did not intend to expand the scope of the federal anti-hacking statute.” Id. 

This Christensen holding is a good Nosal brush-back for the government: the CFAA is an anti-hacking statute, not a general computer crimes catch-all. The sharp lines drawn by the Ninth are handy to have, when facing expansive theories of criminal liability under the CFAA.
                                               
For Further Reading: In a doubly sad day for the Ninth Circuit and the Central District of California, Circuit Judge Harry Pregerson, and his son, District Judge Dean Pregerson have both announced their intention to take senior status this winter. See article here 

The year will bring many more celebrations and reflections on both of their careers – a well-earned transition for both, but a big loss for us all.





Steven Kalar, Federal Public Defender, Northern District of California. Website at www.ndcalfpd.org

.

Labels: , , , , , , ,

Sunday, April 15, 2012

Case o' The Week: Nosal, No Sale, for Gov't -- - Nosal and the CFAA




Chief Judge Alex Kozinski
"Minds have wandered since the beginning of time and the computer gives employees new ways to procrastinate, by gchatting with friends, playing games, shopping or watching sports highlights. Such activities are routinely prohibited by many computer-use policies, although employees are seldom disciplined for occasional use of work computers for personal purposes. Nevertheless, under the broad interpretation of the CFAA, such minor dalliances would become federal crimes. While it’s unlikely that you’ll be prosecuted for watching Reason.TV on your work computer, you could be. Employers wanting to rid themselves of troublesome employees without following proper procedures could threaten to report them to the FBI unless they quit. Ubiquitous, seldom-prosecuted crimes invite arbitrary and discriminatory enforcement." 

United States v. Nosal, 2012 WL 1176119, *4 (9th Cir. Apr. 10, 2012) (en banc), decision available here.


Players: Important win for appellate gurus Ted Sampsell Jones (argued), and Dennis Riordan. Decision by CJ Kozinski, joined by eight judges. Dissent by Judge Silverman, joined by Judge Tallman.

Facts: Nosal worked for an executive search firm. Id. at *1. He started a competing company, and convinced some of his former colleagues to download confidential files from his old firm, to use in his new one. Id. “The employees were authorized to access the database, but [the executive search firm] had a policy that forbade disclosing confidential information.” Id.

Nosal was indicted on many counts, including violations of the Computer Fraud and Abuse Act (CFAA), 18 USC § 1030. Id. Nosal challenged the CFAA counts, arguing that this wasn’t unauthorized access into a computer (hacking), but (if proved true), was theft of data by folks who had legitimate access to the files.

ND Cal District Judge Marilyn Patel agreed and dismissed the CFAA counts, holding that the CFAA prohibits hackers from accessing computer information without authorization – not theft by employees who are authorized to access the data. Id. A three-judge panel reversed. See generally blog description of three-judge panel decision, here.

The case went en banc.

Issue(s): “Computers have become an indispensable part of our daily lives. We use them for work; we use them for play. Some-times we use them for play at work. Many employers have adopted policies prohibiting the use of work computers for nonbusiness purposes. Does an employee who violates such a policy commit a federal crime? How about someone who violates the terms of service of a social networking website? This depends on how broadly we read the Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030.” Id. at *1 (emphasis added).

Held: “We need not decide today whether Congress could base criminal liability on violations of a company or website’s computer use restrictions. Instead, we hold that the phrase ‘exceeds authorized access’ in the CFAA does not extend to violations of use restrictions. If Congress wants to incorporate misappropriation liability into the CFAA, it must speak more clearly.Id. at *7.

Of Note: Gallons of ink will be spilled on Nosal and its impact on computer crimes – it is a very important case. Putting all that aside, read Nosal simply for the enjoyment of joyful legal writing. CJ Kozinski – a computer geek in judge’s clothing – gets it: the government’s interpretation of the CFAA would have criminalized logging on a work computer and “g-chatting with friends, playing games, shopping or watching sport hightlights.” Id. at *4.


Are you of a libertarian bend, prone to tuning into “Reason.TV” while at work? Id. Do you hit Ebay, while filling out timesheets and CJA vouchers? Id. at *5 &n.8. Visit Hulu and JDate? Id. Netflix and Pandora? Id. Do you describe yourself on Craigslist’s dating site as “talk dark and handsome,” when you’re really “short and homely?” Id. at *5. The Chief has no problem with you getting fired – but he and the Ninth don’t want you prosecuted for a federal crime.

How to Use: Fellow blogger Steve “Rule of Lenity” Sady loves Nosal - and you should too. CJ Kozinski explains that the rule is not only intended only to protect citizens, who need fair notice of criminal laws. Id. The Rule of Lenity also ensures “that Congress will have fair notice of what conduct its law criminalizes. We construe criminal statutes narrowly so that Congress will not unintentionally turn ordinary citizens into criminals.” Id. at *7. Great quotes for the defense bar’s favorite rule of construction.

For Further Reading: Are you making too much of a “simple little case,” bringing cutting-edge challenges on “silly issues” that make prosecutions slow and expensive? You must have been hanging out with Carl Gunn. For three decades Carl has been the government’s gadfly while serving in three Defender offices – you’ll remember him as the rebel who “gunned” for the Marshal’s shackling policy in L.A.. See Howard blog here.
Carlton Gunn

 Carl’s now semi-retired, and is maintaining a very interesting blog in his new private practice life. See "Hanging out with Carl" blog hereHit Carl’s blog for a great essay on challenging “controlled substance” priors in federal court – it is a valuable new site to add to your RSS feed.



Image of the Honorable Chief Judge Alex Kozinski from https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_ktMUCFReOnm3MpnUnrk30W8hRqg140moDlb0ZlNyrM3Bw7C0S5QME1x9G60pxR4q8vsaUDQQ8UZKLmlSUgrqr32btiKTLjQMCZAPrTitXCNKtjeY3rMNdPjo9qqhfrzkXFO5lw/s1600/judge+alex+kozinski.jpg


"Reason TV" logo from http://www.reason.tv/


Steven Kalar, Senior Litigator N.D. Cal. FPD. Website at www.ndcalfpd.org

.


.

Labels: , , , , , ,