Showing posts with label internet crime. Show all posts
Showing posts with label internet crime. Show all posts

Wednesday, October 30, 2013

Taking judicial notice of Miley Cyrus' twerking: Texas online solicitation statute ruled unconstitutional

Paging Mark Bennett: You were right; the prosecutors were wrong.

In a surprising decision - both for its unanimous outcome and the unlikely reference to Miley Cyrus "twerking" in a Texas judicial opinion - the Court of Criminal Appeals today declared Texas Penal Code §33.021(b), criminalizing online solicitation of a minor, "facially unconstitutional" in a habeas corpus writ styled Ex Parte John Christopher Lo. See their unanimous opinion (pdf) written by Judge Cathy Cochran which ruled that the statute is "overbroad because it prohibits a wide array of constitutionally protected speech and is not narrowly drawn to achieve only the legitimate objective of protecting children from sexual abuse." Bennett had earlier opined:
it is my opin­ion that this statute vio­lates the First Amend­ment by crim­i­nal­iz­ing pro­tected com­mu­ni­ca­tions between adults.

There is no require­ment that the per­son on the other end of the line be a child, or even that the actor believe the per­son on the other end of the line to be a child. So the statute crim­i­nal­izes dirty talk between adults if one of them is pre­tend­ing to be a child — even if the other one knows that the other is just pretending.

Because it reaches con­sti­tu­tion­ally pro­tected speech (for exam­ple, sex­u­ally explicit com­mu­ni­ca­tion between two grown-ups play­ing “naughty teenager” on the inter­net — both could be pros­e­cuted), the Online Solic­i­ta­tion of a Minor statute is over­broad and unconstitutional.
The CCA unanimously agreed, finding that, unlike statutes in other states, Texas' law "prohibits and punishes speech based on its content." The legislation was supposedly crafted to cover those who "engage in conversations over the Internet with the intent of meeting a minor for sexual activities." But the court found that the statute as written "punishes, as a third-degree felony, salacious speech over the internet (but not "dirty talk" spoken face-to-face) and the distribution of sexually explicit materials over the internet (but not the distribution of those same materials hand-to-hand) to a minor as long as the actor has the intent to arounse or gratify anyone's sexual desires. It does not require that the actor ever have any intent to meet the minor for any reason."

The court opined that the overbroad statute would criminalize many common, even historically important artistic works, not to mention ubiquitous images of Miley Cyrus "twerking":
Subsection (b) covers a whole cornucopia of "titillating talk" or "dirty talk." but it also includes sexually explicit literature such as "Lolita," "50 Shades of Grey," "Lady Chatterly's Lover," and Shakespeare's "Troilus and Cressida." It includes sexually explicit television shows, movies, and performances such as "The Tudors," "Rome," "Eyes Wide Shut," "Basic Instinct," Janet Jackson's "Wardrobe Malfunction" during the 2004 Super Bowl, and Miley Cyrus' "twerking" during the 2013 MTV Video Music Awards." It includes sexually explicit art such as "The Rape of the Sabine Women," "Venus De Milo," "the Naked Maja," or Japaneses Shunga. Communications and materials that, in some manner, "relate to" sexual conduct comprise much of the art, literature and entertainment of the world from the time of the Greek myths extolling Zeus's sexual prowess, through the ribald plays of the Renaissance, to today's Hollywood movies and cable TV shows.
The Court did find that there is a "compelling state interest" in prohibiting online solicitation of minors but that the law as written is "not narrowly drawn." Bottom line, said the court, "everything that Section 33.021(b) prohibits and punishes is speech and is either already prohibited by other statutes (such as obscenity, distributing harmful material to minors, solicitation of a minor, or child pornography) or is constitutionally protected." (Emphasis in original.)

Strong stuff. For once, instead of bucking US Supreme Court opinions, the CCA simply applied them and reached a conclusion that closely tracks federal First Amendment case law. Kudos to the court for not dodging the issue.

MORE: See coverage from the Austin Statesman, the Houston Chronicle, and the Volokh Conspiracy.

AND MORE: Mark Bennett, the attorney who argued the case before the CCA, now has two blog posts up about it:
FOLLOWUP: What happens to people convicted under now-unconstitutional online solicitation statute?

Tuesday, April 23, 2013

Corporate welfare alert: Don't criminalize internet terms-of-service violations

There's a bill up in the House Criminal Jurisprudence today, HB 1064 by Luna Hernandez, which would criminalize accessing an open wi-fi connection without express permission - the new crime would be a Class B misdemeanor, normally, and a state jail felony if the open wi-fi belongs to a government entity. The Senate companion was amended in a way that's equally disturbing, SB 249 by Patrick, is over from the upper chamber and has been amended in ways that apply the same penalties for accessing any computer network in violations of " a contractual agreement," which in practice means a company's "terms of service" agreement.

These terms-of-service agreements have become a joke and criminalizing their violation would create a bevy of pointless prosecutions. A body of contract law already exists; there's no need to use criminal law to bolster it, especially when these "contracts" are so problematic. How many times have you agreed to a site's "terms of service" with just a click of a button that says "Agree" without reading the voluminous, small-print legalese that accompanies it? Everybody has; nobody reads those things.

In 2010, just to reinforce that point, a British gaming firm began satirically including in their "terms of service agreements" language that declared users agreed to literally sell their souls. The agreement read:
By placing an order via this Web site on the first day of the fourth month of the year 2010 Anno Domini, you agree to grant Us a non transferable option to claim, for now and for ever more, your immortal soul. Should We wish to exercise this option, you agree to surrender your immortal soul, and any claim you may have on it, within 5 (five) working days of receiving written notification from gamesation.co.uk or one of its duly authorised minions.
Some 7,500 people clicked "Agree" before the company revealed the joke and removed the language. Reported Fox News, "The terms of service were updated on April Fool's Day as a gag, but the retailer did so to make a very real point: No one reads the online terms and conditions of shopping, and companies are free to insert whatever language they want into the documents." That's precisely why criminalizing violations of terms of service is bad public policy.

As filed, Hernandez's bill that's up today criminalizes those who access someone else's computer network to "obtain a benefit." which would include accessing someone's open wi-fi network. As Grits wrote when the Senate bill was heard, 'Since accessing the internet for free is a benefit and effective consent is defined in the penal code as 'consent by a person legally authorized to act for the owner,' on its face accessing someone's wi-fi without their express permission would be a crime. Personally, I consider leaving wi-fi unsecured simply common courtesy, though internet service providers would like to restrict it for their own commercial benefit. As far as I'm concerned, criminalizing a neighbor using my wi-fi is akin to criminalizing their reading by my porch light. People can always restrict access if it bothers them." This bill is less about protection of the public and more about using law enforcement as corporate welfare to enforce terms-of-service agreements with wireless internet providers.

This is a bad bill. Too many unintended consequences would arise from the House version and the Senate version, which explicitly criminalizes terms of service violations, improperly uses criminal law to enforce private contracts. The legislation is a classic case of overcriminalization, usurping civil and contract law by imposing criminal penalties, including jail time, and shifting the enforcement burden onto the justice system. Both the House and Senate versions and should be roundly rejected.

Friday, September 30, 2011

Police bone up on social media, high-tech crime investigations

After Grits' recent post about Austin PD's ill-conceived "wardriving" strategy to seek out and map open wifi connections - which was shut down by APD Chief Art Acevedo - I learned that the detective in charge of the department's Digital Analysis Response Team (DART) is the president of the Austin High Tech Crime Investigators Association, which will hold a two-day training late next month. (See details here.) One 3.5 hour session pertains to "Wifi Investigations and Exploits," which seems on point with the wardriving tactic, as well as other seminars on various aspects of high-tech forensics and investigations. Since these are topics I know little about, I signed up for the $130 event - thanks to Grits readers' generous contributions - so here in a month or so perhaps we'll have a bit more insight into the goals and methods behind such approaches and a better sense of what's going on in the field with police departments, high-tech investigations and digital forensics.

I can only attend such events because of generous support of Grits contributors, so to those who give monthly or have donated to the blog in the past, thank you: My goal is for y'all to get a better blog product in return by using contributions to pay for learning opportunities like this one. If I had to cover such things out of my own pocket, it just couldn't happen.

Relatedly, see the Dallas Observer's coverage of the "SMILE" conference in Dallas this week where police departments are learning to use social media for both publicity and investigations. Grits had an item previewing the SMILE conference back in August.

MORE: Scott D from the Crime Analyst's blog is at the SMILE conference and has posts here and here from the event.

NUTHER THOUGHT: I'd like to know what if any discussion took place at the conference regarding recent murders by Mexican drug cartels of social media users who exposed or criticized organized crime gangs online. Perhaps Scott D can tell us if the subject came up.

Wednesday, September 21, 2011

More risk than reward from Austin PD compiling list of open wifi connections

UPDATE (9/22): I fowarded this post to Austin Police Chief Art Acevedo and, after a brief back and forth via email, this morning he writes to say the department has canceled today's planned "Operation Wardrive." Wrote Acevedo, "I nixed it already, good intentions to educate, but not best for public perception. A very enthusiastic group of folks trying to combat cyber crime came up with the idea without flying it up the flag pole. Please let folks know that there are people that can and will use unsecured home networks for unsavory and illegal activity."

Thanks, Chief, for accepting feedback and acting on it instead of reacting defensively, and for doing so in a timely manner. Perhaps next time the DART unit should run their plans "up the flag pole" before launching dicey mass surveillance schemes without probable cause, if only to save the embarrassment of having to backtrack after announcing plans to the media.

Certainly readers should check to make sure the default password has been changed on their routers and be sure to use a firewall, especially when using open networks outside the home. But average folks needn't be frightened into closing off access to your home wifi by Chicken Little-style scare tactics. As computer security expert Bruce Schneier has written, running an open wifi connection is "basic politeness. Providing internet access to guests is kind of like providing heat and electricity, or a hot cup of tea." Common courtesy should never trigger a police investigation, even under the pretense of a public education project.
-------------------
Original post: The Austin PD is undertaking a bizarre scheme called "Operation Wardrive" to "find open wireless internet connections in the city." Reported KVUE-TV, "The APD Digital Analysis Response Team, or DART, will hold "Operation Wardrive" Thursday, Sept. 22.  DART unit members will make contact with residents who have open wireless connections and teach them the importance of securing them."

According to KVUE, "APD says wireless devices will be used to find the open networks. They say most manufacturers of wireless routers ship their devices with the wireless network unsecured by default, which leaves people at risk. They warn that internet users who  fail to secure their network are at risk of someone else using it or hacking into personal information."

This strikes me as a very strange task for police to undertake. Asks one of my techie friends, "Has Austin run out of crime? Do APD officers patrol neighborhoods checking for open windows and doors? (Actually using your neighbor's wifi is more like reading by their porch light.)"

This is less about protection of the public and more about using law enforcement as corporate welfare to enforce terms-of-service agreements with wireless internet providers. But APD is not a party to the contract with my ISP and I fail to understand why it's any of their business if my wifi connection is open or not. Want to educate folks that they need to change the password on their routers? Fine. Purchase advertising. But don't go creating a master list of open wifi connections and start hassling customers who've done nothing wrong.

Which brings us to a big unintended consequence from this ill-considered scheme. Because this activity is not (remotely) part of an actual criminal investigation, the list of open wifi connections APD generates as well as all associated data will be a public record under the Texas Public Information Act. Simply compiling that list - which will be available to anyone as soon as somebody files an open records request and posts the results online - makes the types of malicious activities APD is concerned about more likely, not less. Bad idea.

Even if this is a well-intentioned effort and not just water carrying for the ISPs, I don't think our friends at Austin PD have fully thought this tactic through.

MORE: From EFF-Austin, where advocates published a detailed open records request filed today with APD about "Operation Wardrive."