Friday, 19 September 2008
Defamation, MySpace and fake profiles
Principal Loses Lawsuit Against Students and Parents Over Fake MySpace Page--Draker v. Schreiber (Eric Goldman - 22 august 2008)
Draker v. Schreiber, 2008 WL 3457023
But it does not mean disciplinary action cannot be taken. See "Judge Says School Can Suspend Student For Fake MySpace Page Of Principal" (19 September 2008)
A change of standard in the law? Sorry have not read yet the case, so can't comment much "UK High Court Recognizes That Defamation Standard Should Be Lowered For Online Forums" (11 August 2008) Judgment is available on the BBC website in PDF format
Cyber-attack: politics
"Georgian president suffers cyberattack" (21 July 2008)
Liability of auction sites
Blocking access to content or removal of
However, that is not really our point. Blocking access or asking content to be removed should go before the courts or at least an impartial body/institution/authority who could hear both sides and decide if the suspicious or litigious content is really illegal. That would save us from unregulated censorship (censorship for printed publications used to be regulated - even if nobody really agreed with the principle of censorship). After all, for movies, whether it's porn or not is the decision for most countries of accreditated bodies; why should it be different on the internet? A question of unpracticability (too much requests)? no study has been made and if nobody tries, we're just then giving up on fair trial's rights. See Thailand and China "Thailand Continues To Try To Mimic China With Internet Censorship" (4 September 2008)
in that sense, the US DMCA takedown notice is more respectful of rights than simple requests: it must meet some important conditions that, if met, compel the ISPs or host to takedown the litigious copyright material. See "But What If A Takedown Notice Isn't Actually A DMCA Takedown?" (22 August 2008) and "Judge Says Copyright Holders Must Consider Fair Use Before Sending DMCA Takedowns" (21 August 2008)
Jurisdiction issues
Absurd? Mr Masnik argues that the stricker laws get to be applied. Not far of the mark if we compare with the case of privacy where the European standards of privacy have overcome the American conception of privacy.
On the other hand, should the most liberal laws get the upper hand? An interesting problem of diversity and unity familiar to the comparatist
"Indian Court Demands Google Hand Over Anonymous Blogger's Identity" (15 August 2008)
Nasa hacker - last episodes
The last episode is first a protest against his extradition (3 september 2008), and the last possible appeal for Mr. McKinnon before the Hight Court. The grounds of appeal is unfitness to stand trial in the US, and thus asking the trial to take place in the UK... which means applying UK laws, not US laws, thus sentencing will be much more favourable. Home office decides
see also: http://www.crime-research.org/news/29.08.2008/3542/ (29 August 2008)
Note that none of the articles seems to give an accurate account of what the US is claimins as damages suffered...
Blocking access - China again
"China Blocks iTunes After Olympic Athletes Download Pro-Tibetan Music" (21 August 2008)
"So About That Plan To Drop The Great Firewall For Olympics Reporters? Yeah, Forget That..." (30 July 2008)
Investigations - finding criminals and new technologies
"GPS Device Data Increasingly Being Used By Police To Determine Where You Were" (3 September 2008)
"German Authorities Raiding Homes To Find Skype Tapping Whistleblower" (18 September 2008)
or the troublesome FBI view on searches "FBI Asks Congress To Ignore The Whole 'Probable Cause' Part Of The 4th Amendment" (22 August 2008) and "DHS: Laptop Border Searches Are Bad... Except When We Do It" (17 September 2008)and our previous posthttp://cybercrimeatessex.blogspot.com/2008/07/cyber-investigations-and-human-rights.html (13 July 2008)
Thursday, 18 September 2008
Laptop searches in the US
Hopefully a Bill is being introduced since then (1 October 2008), the Senators not being kin of the searches "Senators Not Thrilled About Laptop Searches At The Border" (ZDnet.uk, June 2008)
and our previous post
http://cybercrimeatessex.blogspot.com/2008/07/cyber-investigations-and-human-rights.html (13 July 2008)
Cybercrime sanctions = disciplinary action
http://www.crime-research.org/news/10.09.2008/3565/ (10 sept 2008) "Carleton collars hacker"
Theft and security measures - analogies with the past
By the way, the clarity with which Gartner describes the system of authentication is chilling and I still can't understand why it's there and has not been replaced by something better.
Social networking and investigation
and refers back to a post in july 2008 http://cybercrimeatessex.blogspot.com/2008/07/social-networking-privacy-and.html
ISPs and search engines blocking accesss to content
- It's a behaviour not peculiar to criminal law issues, but it is certainly troublesome when it comes to criminal law. Again, ISPs take action before any judgment has been passed, before any court involvement and the like. Such blocking of content by physically removing the materials does not comply with international standards of presumption of innocence; plus it means that the ISPs act as judges, especially if nobody challenges their decision, a route that could be explained for purely financial reasons.
"Will YouTube Ban Videos Of Putting Your Head In The Sand Next?" http://www.techdirt.com/articles/20080917/1401402295.shtml (17 septembre 2008)
"Thousands Of Anti-Scientology Videos Taken Down From YouTube Via DMCA Takedowns" (8 september 2008) http://www.techdirt.com/articles/20080908/0221022195.shtml
"Google Taking Down Private Videos For Copyright Infringement?" http://www.techdirt.com/articles/20080904/0301492164.shtml (8 September 2008)
- The dangers underlined above appear in the following case. A grandfather posting on windows live the images of his family, with no possible access by outsiders, was ordered to withdraw some photographs within 48 hours or the site would be shut down. Having no clue of what the problem was, he went to see which pictures were so problematic and it was his grandson taking the bath with his dad, so obviously child naked with adult (male - because if female, I am pretty sure the host would not have raised an eyebrow). Had the case been refered to the court, the ISP/host would have lost: impossibility to prove the mens rea of putting child porn images (the family context with restricted access to family members whose identity can be easily verified); impossibility for the pictures to be found constituting child porn given that the adult was not engaging in any indecent act.
- and at the end, I think this is an infringement on privacy which is too great not to be noticed
Wednesday, 17 September 2008
Tracking down hackers
Overall, the article highlights the main difficulty of cybercrime: tracking down the authors.
Comp. with "Cybercrime expert to educate MSU engineers on "Gen Next Terror" "(23 September 2008)
See in comparison "Second TJX hacker pleads guilty" (24 Septembre 2008) and the track for Palin's hacker which seems quite disproportionate in comparison with more damaging cybercrimes that just this one, "FBI Closing In On Palin Hacker " (22 September 2008)
"FBI on the trail of hackers after Palin's emails made public" (The Guardian, 19 September 2008)
and for statistics by DOJ (US) in september 2008
Hackers and their skills for policing purposes
"New Zealand Hacker Released As Police, Judge, Prosecutors All Praise His Mad Hacking Skillz"(16 July 2008)
as the charge was dropped "NZ teenage hacker charges dropped " (BBC, 16 July 2008)
see also my post of 14 March 2008
Saturday, 30 August 2008
Criminal responsiblity for lack of security features?
http://www.techdirt.com/articles/20080825/2320012094.shtml (26 August 2008)
In the same line of thought is the comment of a Nigerian official who points out that victims of 419 scams should be held responsible "Nigerian Official Blames The Victims Of Nigerian 419 Advance Fee Scams" http://www.techdirt.com/articles/20080822/0315012062.shtml (22 August 2008)
And earlier, "Banks slip through virus loophole" (TheGuardian, 12 June 208): "A quiet rule change allows British banks to refuse to compensate the victims of online fraud if they do not have "up-to-date" anti-virus protection, says Danny Bradbury"
Hacking - insiders
http://news.bbc.co.uk/2/hi/uk_news/england/hereford/worcs/7585098.stm
- The employee does not work for Lloyds anymore. Has disciplinary action been taken? Concerning criminal proceedings, the behaviour falls under the CMAct 1990, for the employee modified computer data without authorisation
- Althought there has been no harm here (just a change of password without taking money or the like), the facts illustrate that crime can be generated from the inside. Security policies must be stronger to avoid this type of situation, despite a survey stating that insider crimes diminish "Insiders No Longer The Biggest Threat To Computer Networks" (TechDirt, 17 June 2008)
Scams -Nigeria and the challenge of cybercrime
http://www.crime-research.org/news/27.08.2008/3537/ (27 August 2008)
although one can validly argue that victims are now really fools to fall for 419 scams after all the publicity surronding them for the past few years. http://www.techdirt.com/articles/20080822/0315012062.shtml (22 August 2008) "Nigerian Official Blames The Victims Of Nigerian 419 Advance Fee Scams"
Friday, 29 August 2008
Hacking (Nasa hacker) - jurisdiction and policies
Three things here interest me:
- First, Mr McKinnon's admission that he hacked but to find documents on UFOs. In strict terms of criminal law, his motive (UFOs, pure fun, or terrorism) bears no influence on the existing offence. Mens rea, the mental component of an offence, discards motives which cannot be its component. Motives may come into play later, as an excuse (insanity for example) or justification. This is why the Asperger's syndrome argument becomes important as a ground for an excuse (constraint? barely insanity in today's understanding of the defence)
- Second, the procedural aspect of the case. 95% of criminal cases end up in a plea; plea bargaining is supposed to be a transaction between two parties and a minimum of fairness is supposed to exist, rules of the Supreme Court. But the conception of fairness is relative, especially in the eyes of Europeans: American fairness in relation to plea bargaining is not often perceived, rightly or wrongly, as fairness in the sense of ENglish law or European Human Rights. Pressures are great to accept the plea and not to do so is taking a huge risk.
- It is unclear what has been the attitude of the authorities. Pressure was claimed to have been exercised. Mistatements were supposedly made about the extent of the hack and its threat...
Overall, let's hope one thing: that Mr McKinnon's misapprehensions of his original actions does not cost him more than it is necessary. He should not be sanctioned for the symbol that some may want to see of him in the fight against cybercrime; he should be sanctioned for his actions only, not for political or policies reasons. He hacked into the computers; this is an offence. If hacking into governmental networks is an aggravating circomstance, fine; it is not, then he should be left alone.
"US: tackling cyber-crime" (22 August 2008)
http://news.zdnet.co.uk/security/0,1000000189,39475039,00.htm (28 August 2008)
http://www.crime-research.org/news/29.08.2008/3542/ (29 August 2008)
Earlier, "Nasa hacker to fight US extradition on Monday" (ZDNet.uk, 13 June 2008)
Crime in virtual world
http://news.zdnet.co.uk/security/0,1000000189,39466789,00.htm