Showing posts with label computer access. Show all posts
Showing posts with label computer access. Show all posts

Tuesday, January 19, 2016

A search of a computer for “communications” includes photographs.

In a recent case in Massachusetts a court ruled that a search warrant issued for a computer (in this case an iPhone) properly included a search for photographs. The search in this case arose out of a shooting on a city street between two men. The police obtained information that the defendant, believed to be one of the two men involved in the shooting, had received threatening telephone calls and texts on his cell phone. As a result, they obtained a search warrant for the cell phone which included “saved and deleted photographs” on the iPhone. The police found incriminating photographs on the cell phone.

The court found that photographs can constitute communications. The defendant admitted this point so the court did not discuss the point. A famous quote says that “apicture is worth a thousand words.” This point is proven every minute as people attach photographs and video to texts and emails. They post pictures and video in social media. Video cameras constantly provide information over the internet. I can't imagine a good faith argument to dispute the fact that photographs are communicative. Once the argument is made that a photograph can constitute communications then it seems inevitable that a search warrant for communications should include photographs.

Many people think that a search of a cell phone occurs by a police officer manually searching the phone to look for texts, emails, photographs, etc. While this can occur, that is not how the police searched in this case. The police used a Universal Forensic Extraction Device (UFED) to access the device and to extract the information. A UFED bypasses the password lockout feature of the cellphone and allows a targeted search of the device. It can search all areas of the physical phone as well as all cloud based accounts accessed by the telephone. As the search is targeted the police didn't receive a copy of all information on the phone and its services but only such data as the UFED found responsive to the targeted search. A properly targeted search prevents the police from browsing the entire phone and obtaining information outside the scope of the search warrant. A UFED search based on permissions granted by a search warrant should be permitted.

Police routinely search cellphones in arrests on serious crimes. There are many restrictions on the ability of police to search phones. If you have been arrested and the police seized your cellphone or computer you should consult a lawyer to analyze the method, scope, and reasons for the search. Failure to act promptly can result in improperly seized evidence used to obtain a conviction.



Saturday, March 28, 2015

Death and Facebook. The Legacy Feature.

A friend of mine died and his wife posted his death and funeral arrangements on his Facebook page. In this era of social media, Facebook is a natural and expected forum to notify friends and relatives of such information. Unfortunately, use of his Facebook account was unauthorized by Facebook and constituted criminal behaviour under both Massachusetts and Federal law. At the time of his death, his wife had no other way to use his Facebook account to provide notice. Since that time, Facebook has changed its policies and now has a Legacy feature for memorization of Facebook pages after death.

Facebook's Terms of Service states: “You will not share your password let anyone else access your account, or do anything else that might jeopardize the security of your account.” In other words, the only authorized user of a Facebook page is the registered owner. There is no exception for family members after death. Authorization is important because both Massachusetts and Federal law make it a crime for any person who is not an authorized user to access a computer. Since using Facebook means that a user accesses Facebook's computer, any person who is not authorized by Facebook and uses another person's account is committing a crime. Massachusetts General Laws chapter 266, section120F punishes unauthorized computer access by up to thirty days in jail and a one thousand dollar fine. United States Code Title 18Section 1030 punishes unauthorized computer access by up to twenty years in prison and fines. Permission to use a Facebook account by the registered owner of the account is still a crime because Facebook doesn't allow such permission. A widow posting information about her husband's death is unauthorized and a criminal act.

Facebook has recognized people's desires to use Facebook accounts after death and has created a new feature called Legacy. During a person's life, they can designate a person as a “Legacy Contact.” This person will have limited rights to access a Facebook account after a person dies. The Legacy Contact can post a final message and Memorialize the account. Memorialization freezes the account, indicates that the owner died and may allow others to share memories on the account.

Every individual with a Facebook account should consider a legacy contact. This should become part of estate planning and become just as routine as writing a will or making pre-death funeral arrangements. Unauthorized computer access can have serious criminal consequences. A lawyer can help understand how to avoid violating the law and still enjoy social media.



Sunday, June 16, 2013

Unauthorized access to email results in verdict of $325K.

In the past, I have blogged about unauthorized access to social media and email accounts in the context of divorce. http://massfamilylawblog.blogspot.com/2012/12/can-you-spy-on-your-spouse-with.html and http://massfamilylawblog.blogspot.com/2012/10/spying-on-spouse.html. The danger of such spying is shown by a recent case of unauthorized access which resulted in a verdict of damages of $325,000.00.

In the case of Cheng v. Romo, (Civil Action No. 11–10007–DJC. U.S. Dist.Ct. MA) a civil lawsuit was filed under the federal Stored Communications Act 18 U.S.C. § 2701, et
seq. and the Massachusetts Privacy Act Mass. Gen. L. c. 214, § 1B. Cheng and Romo were doctors who worked together. Their employer did not provide email addresses so they used their private emails for work purposes. Cheng gave Romo his email password so she could access some documents that Cheng had received relating to their work. Romo used the password on several occasions at the time that Cheng gave her the password. For over four years, Romo did not access Cheng's email. However, when Romo was having problems with the empolyer and was contemplating leaving the company, she again accessed Romo's email account. When she accessed the email at this time, she did it for the purpose of obtaining information to help her in potential litigation and negotiations with the employer. Romo's access of the email was discovered when her lawyer produced emails from Cheng's account. A lawsuit followed for damages for the unauthorized access of the email account.

The facts of this case raised questions about interpretation of the Stored Communications Act. Once authorization is given for an email account, can it be limited? Does it have to be limited by express words? Can it be limited by the context of the grant of permission?

Based on jury verdict, it appears that a use exceeding authorization constitutes an unathorized use under the statute. Furthermore, the context can establish the scope of permission. In this case, permission was granted to access an email account for performing work and obtaining information necessary for performing a job function. When the account was accessed four years later, the purpose was to obtain information to harm the owner of the email account and the employer. This was not a proper purpose.

Unless there is a written document establishing the scope of authorization for another's email account, the scope of any authorization should be limited to access for the benefit of the account holder. Any intentional access to obtain information to the detriment of the account holder should be considered unauthorized. I consider intent as the critical element. If a person, in good faith, uses another's email account and happens across harmful information, that access would still be authorized. It is only when the intent is to cause harm that such access should be considered in violation of the computer access and privacy laws.

Applying the lessons of this case to my previous blog articles, I conclude that spying on a spouse or other by accessing their email violates these laws even if the password was freely given. This is true even if a shared computer is used or a computer that is owned by the person spying. Using the internet to spy on another or harm another can be very risky as this $325,000.00 verdict shows.

Before trying to harm someone by using their email or other accounts, you should consult a lawyer who can advise you on the law as it applies to your specific facts.