Is the law’s arm long enough?

Feature
Nov 29, 200412 mins

Even though Congress continues to propose laws to defeat spyware and spammers, it seems law enforcement’s hands are still essentially tied.

The legal framework for battling cybercrime rests on surprisingly few federal laws.

While enforcement officials and other experts seem largely satisfied with these statutes, new laws are in the works to combat increasingly sophisticated criminals. Also, the distinction between pure cybercrime – defined as a computer-based attack on computers, networks and data – and traditional crime such as fraud and theft continues to blur, further complicating the legal challenges.


Main index: Profiling cybercrime: Network threats and defense strategies


One critical part of the legal framework is only now starting to get more systematic attention: the procedural rules that regulate investigations and evidence gathering – and protect civil rights.

The main federal cybercrime laws traditionally have been the Computer Fraud and Abuse Act and the Electronic Communications Privacy Act. They form the foundation of digital law enforcement by defining and criminalizing unauthorized access to computers and the interception of electronic communications.

But many prosecutions involve these cybercrime laws coupled with traditional laws, such as those against mail and wire fraud, or in the case of the Federal Trade Commission, unfair and deceptive practices under the FTC Act.

Consider a number of recent federal cases, which show the range of cybercrime actions and federal priorities:

•  Six men were indicted on charges, based on the Computer Fraud and Abuse Act as well as money laundering and conspiracy, in Los Angeles for allegedly hacking into the online ordering system of Ingram Micro and fraudulently ordering more than $10 million worth of computer gear to be shipped to locations in Romania and the U.S.

•  Capping a 4-year-old case, a federal judge ruled that two companies and their principals were guilty of unfair and deceptive practices under the FTC Act for billing people for accessing Internet pornography sites that in fact were never accessed at all. The defendants, both now at large, have been ordered to repay nearly $18 million in phone charges.

•  Operation Web-Snare, a joint effort by the Department of Justice and investigators from federal, state and local agencies, involved more than 150 separate investigations into a range of crimes covered by various cybercrime laws, including: criminal spamphishing, spoofed or hijacked accounts, international re-shipping schemes, cyber extortion, auction fraud, and credit card fraud, identity theft and hacking.

•  A former employee of Varian Semiconductor was charged under the Computer Fraud and Abuse Act with one count of intentionally damaging a protected computer when he hacked into a Varian server from his Indiana home and deleted the source code for a major new e-commerce application.

•  A Florida man was charged with illegal access to servers at Acxiom, which manages personal, financial and corporate data, and downloading an estimated 8.2G bytes from an FTP server between April 2002 and August 2003. The charges were based in part on the Computer Fraud and Abuse Act.

These cases show that the distinction between cybercrime and traditional crime is blurring.

Criminals “don’t care about definitions, they just keep figuring out ways to make more money more surreptitiously,” says Paul Luehr, vice president with Stroz Friedberg and a former federal attorney who oversaw cyber investigations for the U.S. Attorney’s office in Minnesota for four years. Spammers who used to just pitch Viagra are now soliciting for names, addresses and credit card information to perpetrate fraud, and hacking into mail servers and Web servers to hide their tracks, Luehr says.

The CAN-SPAM lesson

The federal response to spamming is a good example of how the legal code is adapting and being enforced. Before the 2003 passage of the CAN-SPAM Act, law enforcement agencies used a range of existing statutes, including provisions of the Computer Fraud and Abuse Act and the wire fraud statute to prosecute spamming. But as Assistant FBI Director Jana Monroe testified in Congress earlier this year, existing statutes didn’t directly address a range of specific spamming actions, such as using widely available “open proxies” to bounce e-mail traffic through intermediary computers with the intent to hide the true location of the sender.

“Because of this, many investigators and prosecutors viewed cases based primarily on the sending of spam as unlikely to result in successful investigations and prosecutions,” she testified. But CAN-SPAM criminalizes a range of spamming activities so that spammers now face criminal penalties. That’s especially important because spamming now is seen as a favored means to start or run a wide array of frauds.

One result is that the Internet Crime Complaint Center (IC3), a joint effort by the FBI and the National White Collar Crime Center, has revamped its SLAM-Spam program. The IC3 is refining its databases, sharing data, and educating and training federal and state agencies. This outreach program covers such topics as anti-spam techniques spammers used, tactics to investigate spam schemes and the tools available to them via CAN-SPAM.

Where the law has not kept pace is in the area of the procedural rules that law enforcement must follow in investigating cybercrimes. These rules traditionally restrict the scope of police searches, what evidence can be considered and how investigations are regulated. But applying these rules, based on traditional crimes and investigations, to cybercrimes leads to unexpected results, according to Orin Kerr, a law professor at George Washington University Law School. Kerr is a former federal prosecutor and author of the Justice Department’s manual outlining procedures for searching and seizing digital evidence. An upcoming issue of Columbia Law Review will publish his paper, “Digital Evidence and the New Criminal Procedure.”

The dynamics of investigating a cybercrime, such as a hack into a bank’s computers, are very different from investigating a traditional “physical” crime, such as a bank robbery at gunpoint, Kerr says. “There’s a bad fit between the traditional rules [of evidence and procedure] and the new facts of computer crime,” he says.

The doctrine of rules and laws that have grown up around Fourth Amendment proscriptions against unreasonable search and seizure, and the Fifth Amendment’s against self-incrimination, today offer little protection to wide-ranging, almost entirely unregulated electronic searches and evidence gathering, Kerr says.

That is starting to change. Provisions of the Electronic Communications Privacy (ECP) Act imposed statutory limitations on how the government can obtain information from ISPs.

The USA PATRIOT Act (an acronym for Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism) of 2001 later amended the ECP Act to create two classes of electronic surveillance, one for data related to dialing, routing and addressing of communications, the other for the contents of those communications. The latter now are classed as more private than the former. As a result, police must meet a higher standard before obtaining a search warrant for such information.

Kerr expects Congress will tackle these issues more systematically next year as it debates provisions of the USA PATRIOT Act due to expire at the end of 2005.

The main proposed change to the Computer Fraud and Abuse Act pending before Congress is to extend this law to cover spyware. Sometimes spyware is used for harmless applications such as pop-up ads or software updates, but increasingly these programs are used to change settings and launch computer attacks such as spam or viruses.

In the final days before Congress adjourned in advance of the presidential election, several anti-spyware measures were passed.

The House approved H.R. 4661, the Internet Spyware (I-SPY) Prevention Act of 2004, which was hailed by high-tech industry groups including the Business Software Alliance (BSA) and the Center for Democracy and Technology. The I-SPY Act imposes criminal penalties on individuals who access another person’s computer with spyware and use that program to harm a person or cause damage to a computer.

Meanwhile, the House passed H.R. 2929, the Safeguard Against Privacy Invasions (SPY) Act, which calls for the FTC to oversee online software distribution. In late September, a similar measure called the SPYBLOCK Act passed the Senate Committee on Commerce, Science and Transportation. Like SPY, SPYBLOCK would regulate advertising delivered via interactive software and spyware designed to hijack end users’ computers for malicious purposes.

Trade groups favor I-SPY Act

Industry trade groups including the Information Technology Association of America (ITAA) prefer the I-SPY Act over the other bills because it takes a more targeted approach to setting criminal penalties on spyware.

ITAA worries that the SPY Act and the SPYBLOCK Act would regulate legitimate advertising and software update notices in addition to spyware. ITAA President Harris Miller said in a statement that overly broad anti-spyware legislation “could leave consumers unaware of the latest software updates and unable to make use of the most convenient way to upgrade their applications.”

Another piece of pending cybercrime legislation is the Anti-Phishing Act of 2004. Phishing is a type of identity theft scam by which individuals are enticed to provide confidential information such as credit card numbers through spoofed e-mails, which appear to come from a legitimate source such as a bank or e-commerce Web site.

The Anti-Phishing Act makes it illegal to knowingly send out spoofed e-mail that links to sham Web sites with the intention of committing a crime. This act also makes it illegal to knowingly create a Web site that pretends to be legitimate but actually intends to collect information for a criminal purpose. It includes provisions to protect Web sites that are parodies or offer political commentary.

Also pending before the Senate is ratification of the Council of Europe’s Convention on Cybercrime, which is supposed to make it easier to investigate and prosecute computer-related crime that originates in another country. The U.S. is one of 38 nations that has signed the treaty, but the Senate has not ratified it. A year ago, President Bush urged the Senate to ratify the treaty, calling it the “only multilateral treaty to address the problems of computer-related crime and electronic evidence gathering.”

“We’ve been staunch advocates of” the treaty, says Robert Cresanti, vice president for public policy with the BSA, a trade group representing MicrosoftCiscoIBM and other leading network vendors. “We think it’s perfect to get harmonization of these cybercrimes so we don’t have these havens where people can commit cybercrime. We’d like to see broad adoption of the treaty.”

“It’s important that we work together with other countries,” says Ari Schwartz, associate director of the Center for Democracy and Technology, a Washington, D.C., advocacy group. “We’ve seen a lot of the more major cybercrime cases falling apart because of the lack of cooperation by Taiwan or China or the Phillipines or the former Soviet Union.”

Despite these Congressional efforts to pass new cybercrime laws, observers say the problem today is not that there are holes in existing laws but that federal, state and local law enforcement agencies lack the resources to pursue the growing number of cases.

The Computer Fraud and Abuse Act is pretty effective, Schwartz says. “Law enforcement has been able to bring many cases under that act. The problem is tracking down the criminals,” he says.

“The hard part is the police work,” he adds. “The laws are there. It’s good that we’re extending them and making them more clear for cases like spyware. But the hard part is doing the investigation and bringing it to prosecution.”

BSA also is pushing for more funding for federal law enforcement efforts geared toward cybercrime.

“While there are significant laws on the books, there are not sufficient enforcement resources available,” Cresanti says. “When people find themselves a victim of cybercrime, they have a difficult time accessing law enforcement and bringing forth a claim. . . . In my opinion, it fundamentally comes down to the enforcement resources on the ground.”

That’s one reason BSA supports the Justice Department in its bid to get more resources to battle international piracy. BSA says it supports the creation of “additional Computer Hacking and Intellectual Property Units (CHIP UNITS) to prosecute crimes and work with industry on preventative measures. Enhanced criminal enforcement resources would be a significant step in the right direction.”

For several years, BSA has supported the idea of increasing the funding for the Justice Department’s CHIP UNITS by $10 million per year. These units “are enormously effective in prosecuting crimes, but they often can’t get the attention of investigators,” Cresanti says. “The flow of prosecutions is being hampered by a lack of resources for the investigators.”

Key federal cybercrime laws
Computer Fraud and Abuse Act: The foundation of many later laws, it defines what is illegal access to a computer and criminalizes activities such as hacking and malicious code such as viruses and worms.
National Information Infrastructure Act: Modifies the CFAA to make it illegal even to view information on a computer without authorization.
Electronic Communications Privacy Act: Amends the federal wiretap law, making it illegal to intercept stored or transmitted communications without authorization.
Communicaitons Assistance for Law Enforcement Act: Requires ISPs to add capabilities that let law enforcement agencies conduct, after obtaining a warrant, electronic surveillance of specific individuals.
Cyber Security Act and Homeland Security Act: Increases penalties set out in the Computer Fraud and Abuse Act, reduces the privacy of certain data held by ISPs, making it easier for government agencies to gain access to that data.
CAN-SPAM Act: Imposes limitations and penalties on Internet transmission of unsolicited, commercial e-mail.
john_cox

I cover wireless networking and mobile computing, especially for the enterprise; topics include (and these are specific to wireless/mobile): security, network management, mobile device management, smartphones and tablets, mobile operating systems (iOS, Windows Phone, BlackBerry OS and BlackBerry 10), BYOD (bring your own device), Wi-Fi and wireless LANs (WLANs), mobile carrier services for enterprise/business customers, mobile applications including software development and HTML 5, mobile browsers, etc; primary beat companies are Apple, Microsoft for Windows Phone and tablet/mobile Windows 8, and RIM. Preferred contact mode: email.

More from this author