Appreciate C L
chapter 3
United States Computer Laws Part I
Introduction In the previous chapter, we examined the history of computer crime over the past several decades. You should now be familiar with how computer crimes have developed and changed, and you should also have a good understanding of common computer crimes. We also introduced you to the different types of computer attacks, so you should have a basic understanding of the methods used by computer criminals. The next step is to study the laws pertinent to computer crimes. In this chapter, we will examine federal legislation and specific court cases that have arisen due to that federal legislation. After reading this chapter, you should have a basic familiarity with federal computer-related laws. In the next chapter we will discuss specific state legislation.
In this chapter we will also relate how these particular laws affect the commission of specific crimes we mentioned in Chapters 1, “Introduction to Computer Crime,’’ and 2, “A History of Computer Crime in America.” It is very important to understand what laws are applicable in a given situation. In addition to pro- viding a summary and analysis of relevant laws in this chapter, we will also pro- vide the text of each law. This will allow the reader to see the actual language of the law in question for themselves. This will be in a separate subsection under each law so that readers who wish to, can skip that section. In some cases, the text of the law is too large to present here in its entirety. If that is the case, then the most relevant portions will be presented. It may seem cumbersome to include
71
such lengthy citations in the text of a book, however it is critical that the reader have a fundamental understanding of these laws. There is one notable exception: The Digital Millennium Copyright Act is simply too large to put within the confines of this chapter. Furthermore, it is complex legislation and omitting part of it is not practical. So instead, none of it is reproduced here.
The Ribicoff Bill The Ribicoff Bill was the first proposal for federal computer-crime legislation in the United States that would specifically prohibit the misuse of computers. The bill was referred to as Federal Computer Systems Protection Act of 1977. While this bill did not pass, it set the stage for future computer-related legislation, and it showed that at least some members of Congress were contemplating the dan- gers of computer crime as early as the 1970s.
In presenting the bill, Senator Ribicoff stated:
“Our committee investigation revealed that the government has been hampered in its ability to prosecute computer crime. The reason is that our laws, primarily as embodied in title 18, have not kept current with the rapidly growing and changing computer technology.
“Consequently, while prosecutors could, and often did, win convictions in crime by computer cases, they were forced to base their charges on laws that were written for purposes other than computer crime. Prosecutors are forced to ‘shoe horn’ their cases into already existing laws, when it is more appropriate for them to have a statute relating directly to computer abuses.”
While that particular bill did not pass and become law, the statement by Senator Ribicoff is still true today. The fact is that legislation is frequently reactive rather than proactive, and it will often be the case that laws will need amending and changing to keep up with more modern crimes.
The Computer Fraud and Abuse Act of 1986 This law is perhaps one of the most fundamental computer-crime laws, and merits careful study by anyone interested in the field of computer crime. The primary reason to consider this legislation as pivotal is that it was the first significant federal legislation designed to provide some protection against computer-based crimes. Prior to this legislation, courts relied on common-law definitions and adaptations of legislation concerning traditional, non-computer crimes in order to prosecute computer crimes.
Chapter 3 ■ United States Computer Laws Part I72
Throughout the 1970s and early 1980s, the frequency and severity of computer crimes increased, as we have seen in the preceding two chapters. In response to this growing problem, the Comprehensive Crime Control Act of 1984 was amended to include provisions to specifically address the unauthorized access and use of computers and computer networks. These provisions made it a felony offense to access classified information in a computer without authorization. They also made it a misdemeanor offense to access financial records in a com- puter system.
However, these amendments were not considered in and of themselves to be adequate. Thus during 1985, both the House and the Senate held hearings on potential computer-crime bills. These hearings eventually culminated in the Computer Fraud and Abuse Act (CFAA)1, enacted by Congress in 1986, which amended 18 U.S.C. § 1030. The original goal of this act was to provide legal protection for computers and computer systems that were in one of the follow- ing categories:
■ Under direct control of some federal entity
■ Part of a financial institution
■ Involved in interstate or foreign commerce
As you can see, this law was aimed at protecting computer systems that came within the federal purview. This act made several activities explicitly criminal. First and foremost was accessing a computer without authorization in order to obtain any of the following types of information:
■ National security information
■ Financial records
■ Information from a consumer reporting agency
■ Information from any department or agency of the United States
This is a crucial piece of legislation. It is true that outside of cyber spying or terrorism, which we will discuss later in this book in Chapter 6, “Organized Crime and Cyber Terrorism,’’ few computer crimes involve the theft of national security information. However, financial records are often the primary target of sophisticated hackers. In fact even today, 25 years after the passage of this law, financial records are a primary target in many computer crimes. This legislation provides the legal framework for prosecuting such crimes at the federal level.
The Computer Fraud and Abuse Act of 1986 73
Also note that obtaining information from a consumer reporting agency or any federal agency or department without authorization is a crime. This element of the act is crucial because those activities are often an element in identity-theft cases. Specifically, one can relate the prohibition of fraudulently obtaining re- cords with financial information to cases of identity theft, phishing, and any attempt to breach a bank or other financial entity’s computer systems.
Beyond those provisions, the act made it a crime to simply access a federal gov- ernment computer without authorization, even if you cause no damage or access any confidential data. Since some hackers attempt to breach the security of target systems as merely an intellectual exercise rather than with a specific criminal intent, this provision of this law is very important. It means that if an individual obtains unauthorized access to any federal or financial-institution computer system, he or she is guilty of a federal crime regardless of what further action the individual may or may not take.
Obviously, some in the hacking community might take exception to this provi- sion. But it is clearly prudent and necessary for two reasons. The first reason is that when a person intrudes on a system, it is entirely possible that he or she might accidentally cause damage, even without any malicious intent on his or her part. The second reason is that it could be the case that a perpetrator is caught before he or she can effect damages or theft of information. If the act of intruding on a system is not a crime in and of itself, then that perpetrator is essentially rewarded for being caught before he or she could complete his or her plan. This is why, for example, breaking and entering is a crime in and of itself, even without the commission of an actual theft.
This law also made it a criminal offense to traffic in information, such as pass- words, that might be used to access computer systems without authorization. This means that compromising passwords and distributing them on the Internet is a federal crime. Some readers may be unaware that there are places on the Internet where individuals do indeed traffic in stolen passwords, stolen credit- card numbers, and utilities that allow one to compromise systems. The black market for information, specifically cyber information, is a growing problem.
Perhaps the broadest-reaching aspect of this act was the portion that made it a crime to:
knowingly cause the transmission of a program, information, code, or command that causes damage or intentionally accessing a computer
Chapter 3 ■ United States Computer Laws Part I74
without authorization, and as a result of such conduct, causes damage that results in:
■ Loss to one or more persons during any one-year period aggregating at least $5,000 in value
■ The modification or impairment, or potential modification or impair- ment, of the medical examination, diagnosis, treatment, or care of one or more individuals.
■ Physical injury to any person
■ A threat to public health or safety
■ Damage affecting a government computer system
This broad-reaching language made virtually all forms of hacking, viruses, denial-of-service attacks, and session hijacking a federal crime. The first clause requires damages of $5,000. Now, obviously, some attacks do not cause direct economic damages. However, one must keep in mind that the cost of repairing the damage (i.e., removing a virus, getting the system functioning normally, etc.) is considered a part of this damage. This means that indirectly, most computer attacks will involve damages. The second area, involving medical records, was expressly designed to provide legal protection to medical-information systems. The next one is far less common, as it is rare that a computer attack involves physical harm. The fourth category is one that deserves some consideration. This essentially means that any computer attack that represents a threat to public health or safety is a crime. This is very broad language and could very readily be applied to any range of computer attacks. A creative prosecuting attorney could certainly expand this into new areas. For example, would a court consider a person who deliberately spread false information via computer systems to have constituted a threat to public safety if said information was actually harmful or caused unnecessary panic? I would suspect that this aspect of the Computer Fraud and Abuse Act will be the subject of future computer decisions.
Of course, the final case is simply criminalizing damage affecting government computer systems. This would include defacing Web sites of government agen- cies. This is particularly important because attacks on government or military systems are often launched against the agencies’ public Web sites. These attacks can cause significant inconvenience for the agency in question, and in some cases
The Computer Fraud and Abuse Act of 1986 75
can lead to disinformation being given to the public via a defaced Web site. It is also true that it is simply easier to compromise a Web server than to intrude into a secure network. The reason for this is that the Web server must, by its very nature, interact with the public. Budding computer criminals often begin by at- tacking Web sites. Once they have honed their skills, they may then attempt to compromise more secure systems. Making the first steps a federal crime gives law enforcement a very useful tool.
The Patriot Act, passed in 2001, further expanded the Computer Fraud and Abuse Act of 1984 by including expanded sentencing:
■ Maximum prison term went from five years to 10 years for the first offense.
■ Maximum prison term went from 10 years to 20 years for the second offense.
■ The previous threshold had been $5,000 in damages; now the threshold could be $5,000 aggregate in damages.
The Identity Theft Enforcement and Restitution Act of 2007 further expanded the Computer Fraud and Abuse Act. The first—and some would say most im- portant—change was the elimination of the requirement for $5,000 in damages. This means that a computer offense may indeed cause no physical damage and still be a prosecutable offense. Next, this act made it a felony to threaten to da- mage a computer, computer system, or steal data. Therefore, merely threatening a computer attack is now a felony. This act also expanded the law, making any hacking of a system or even conspiring to hack a system a felony.
The specific penalties given by the Computer Fraud and Abuse Act are shown in Table 3.1.
Table 3.1 Penalties under the Computer Fraud and Abuse Act
Offense Minimum/Maximum Sentence
Obtaining national security information 10 years/20 years
Trespassing in a government computer 1 year/10 years
Intentional access and damage 1 year/10 years
Intentional access and reckless damage 5 years/20 years
Trafficking in passwords 1 year/10 years
Extortion involving threats to damage computer 5 years/10 years
Chapter 3 ■ United States Computer Laws Part I76
As you can see, this piece of legislation treated computer crimes quite seriously, and provided federal courts the ability to give out significant sentences for computer-based crimes. This particular bill addresses a number of the attacks we discussed in Chapter 2. It could easily apply to virtually all forms of computer attack, provided the target of the attack was within the scope of this legislation.
Amendments to the Legislation While this law was a pivotal piece of legislation when it was originally enacted, it had some weak points. Prior to 1996, this law did not clearly define what a pro- tected computer was. In 1996, the law was amended to define this term. The term “protected computer” now includes any computer used in interstate or foreign commerce, computers of the federal government, and financial institutions. Consider briefly the part concerning “any computer used in interstate or foreign commerce.” In many, if not most cases, this includes virtually any computer involved in Internet commerce. This would include large scale e-commerce sites such as Amazon.com and eBay.com, but also any Web site that is involved in commercial transactions that cross state lines or international boundaries.
Related Cases In January of 1989, Herbert Zinn gained the distinction of being the first person to be convicted under the Computer Fraud and Abuse Act2. If you will recall from Chapter 2, Mr. Zinn had broken into computer systems at the Department of Defense as well as other sensitive systems. Zinn was sentenced to nine months in prison and fined. Many feel he would have received a much harsher sentence except for the fact that he was a minor when he committed his crimes, although he was an adult when charged and convicted.
Another early conviction stemming from the Computer Fraud and Abuse Act was Robert Morris3. Mr. Morris was a Cornell student. He wrote a worm that was designed to be harmless: It simply checked computers to see how many were connected to the Internet. This was in 1988, and there were not so many ma- chines on the Internet as we have today. However, the computer worm’s massive self replication caused losses in productivity on the networks it infected. He re- ceived no jail time, even though the law did allow for jail time. Instead, he re- ceived community service and probation. A few oddities about this case: Robert Morris was the son of the chief scientist at the National Computer Security Center when he committed his crime. He has since gone on to become an as- sociate professor at M.I.T. You should note that some sources mistakenly claim
The Computer Fraud and Abuse Act of 1986 77
Robert Morris was the first person convicted under the Computer Fraud and Abuse Act. This is incorrect, it was Herbert Zinn. However, Robert Morris was a very early conviction under this law, and an important case.
Theofel v. Farey-Jones, in 2003, is a case that illustrates the breadth of the Computer Fraud and Abuse Act. This case began as a civil matter between Alwyn Farey-Jones and Integrated Capital Associates4. Farey-Jones’ attorney sub- poenaed ICA’s Internet service provider, demanding access to e-mails from ICA, and the Internet service provider complied without notifying ICA. Furthermore, the subpoena itself was very broad and included personal e-mails from ICA employees. The ICA employees whose e-mail had been compromised filed a civil lawsuit against Farey-Jones and his attorney, claiming they had violated three federal statutes: the Stored Communications Act, the Computer Fraud and Abuse Act, and the Wiretap Act. The initial court rejected those claims, but the Ninth Circuit Court of Appeals upheld them. The appeals court ruled that “using a civil subpoena which is patently unlawful, bad faith and at least gross negli- gence” to gain access to stored e-mail is a breach of the Computer Fraud and Abuse Act. This case is interesting because it involves the improper use of sub- poenas. Attorneys, as well as law-enforcement officials, must always be wary to ensure that their gathering of evidence is done in a legal and proper manner. If they do not, not only can the evidence be rejected by a court, it can lead to even more legal difficulties, as it did in this case.
The Actual Law (1) knowingly accesses a computer without authorization or exceeds authorized access, and by means of such conduct obtains information that has been de- termined by the United States Government pursuant to an Executive order or statute to require protection against unauthorized disclosure for reasons of na- tional defense or foreign relations, or any restricted data, as defined in paragraph y. of section 11 of the Atomic Energy Act of 1954, with the intent or reason to believe that such information so obtained is to be used to the injury of the United States, or to the advantage of any foreign nation;
(2) intentionally accesses a computer without authorization or exceeds author- ized access, and thereby obtains information contained in a financial record of a financial institution, or of a card issuer as defined in section 1602(n) of title 15, or contained in a file of a consumer reporting agency on a consumer, as such terms are defined in the Fair Credit Reporting Act (15 U.S.C. 1681 et seq.);
Chapter 3 ■ United States Computer Laws Part I78
(3) intentionally, without authorization to access any computer of a department or agency of the United States, accesses such a computer of that department or agency that is exclusively for the use of the Government of the United States or, in the case of a computer not exclusively for such use, is used by or for the Government of the United States and such conduct affects the use of the Gov- ernment’s operation of such computer;
(4) knowingly and with intent to defraud, accesses a Federal interest computer without authorization, or exceeds authorized access, and by means of such con- duct furthers the intended fraud and obtains anything of value, unless the object of the fraud and the thing obtained consists only of the use of the computer; shall be punished as provided in subsection (c) of this section.
(5) intentionally accesses a Federal interest computer without authorization, and by means of one or more instances of such conduct alters, damages, or destroys information in any such Federal interest computer, or prevents authorized use of any such computer or information, and thereby
(A) causes loss to one or more others of a value aggregating $1,000 or more during any one year period; or
(B) modifies or impairs, or potentially modifies or impairs, the medical ex- amination, medical diagnosis, medical treatment, or medical care of one or more individuals; or
(6) knowingly and with intent to defraud traffics (as defined in section 1029) in any password or similar information through which a computer may be accessed without authorization, if
(A) such trafficking affects interstate or foreign commerce; or
(B) such computer is used by or for the Government of the United States;
(b) Whoever attempts to commit an offense under subsection (a) of this section shall be punished as provided in subsection (c) of this section.
(c) The punishment for an offense under subsection (a) or (b) of this section is
(1)(A) a fine under this title or imprisonment for not more than ten years, or both, in the case of an offense under subsection (a)(1) of this section which does not occur after a conviction for another offense under such subsection, or an attempt to commit an offense punishable under this subparagraph; and
The Computer Fraud and Abuse Act of 1986 79
(B) a fine under this title or imprisonment for not more than twenty years, or both, in the case of an offense under subsection (a)(1) of this section which occurs after a conviction for another offense under such subsection, or an at- tempt to commit an offense punishable under this subparagraph; and
(2)(A) a fine under this title or imprisonment for not more than one year, or both, in the case of an offense under subsection (a)(2), (a)(3) or (a)(1) of this section which does not occur after a conviction for another offense under such subsec- tion, or an attempt to commit an offense punishable under this subparagraph; and
(B) a fine under this title or imprisonment for not more than ten years, or both, in the case of an offense under subsection (a)(2), (a)(3) or (a)(6) of this section which occurs after a conviction for another offense under such subsection, or an attempt to commit an offense punishable under this subparagraph; and
(3)(A) a fine under this title or imprisonment for not more than five years, or both, in the case of an offense under subsection (a)(4) or (a)(5) of this section which does not occur after a conviction for another offense under such subsec- tion, or an attempt to commit an offense punishable under this subparagraph; and
(B) a fine under this title or imprisonment for not more than ten years, or both, in the case of an offense under subsection (a)(4) or (a)(5) of this section which occurs after a conviction for another offense under such subsection, or an at- tempt to commit an offense punishable under this subparagraph.
(d) The United States Secret Service shall, in addition to any other agency having such authority, have the authority to investigate offenses under this section. Such authority of the United States Secret Service shall be exercised in accordance with an agreement which shall be entered into by the Secretary of the Treasury and the Attorney General.
(e) As used in this section
(1) the term “computer” means an electronic, magnetic, optical, electrochemical, or other high speed data processing device performing logical, arithmetic, or sto- rage functions, and includes any data storage facility or communications facility directly related to or operating in conjunction with such device, but such term does not include an automated typewriter or typesetter, a portable hand held calculator, or other similar device;
(2) the term “federal interest computer” means a computer
Chapter 3 ■ United States Computer Laws Part I80
(A) exclusively for the use of a financial institution or the United States Gov- ernment, or, in the case of a computer not exclusively for such use, used by or for a financial institution or the United States Government and the conduct con- stituting the offense affects the use of the financial institution’s operation or the Government’s operation of such computer; or
(B) which is one of two or more computers used in committing the offense, not all of which are located in the same State;
(3) the term “State” includes the District of Columbia, the Commonwealth of Puerto Rico, and any other commonwealth, possession or territory of the United States;
(4) the term “financial institution” means
(A) an institution with deposits insured by the Federal Deposit Insurance Corporation;
(B) the Federal Reserve or a member of the Federal Reserve including any Federal Reserve Bank;
(C) a credit union with accounts insured by the National Credit Union Administration;
(D) a member of the Federal home loan bank system and any home loan bank;
(E) any institution of the Farm Credit System under the Farm Credit Act of 1971;
(F) a broker-dealer registered with the Securities and Exchange Commission pursuant to section 15 of the Securities Exchange Act of 1934;
(G) the Securities Investor Protection Corporation;
(H) a branch or agency of a foreign bank (as such terms are defined in paragraphs (1) and (3) of section l (b) of the International Banking Act of 1978); and
(I) an organization operating under section 25 or section 25(a) of the Federal Reserve Act.
(5) the term “financial record” means information derived from any record held by a financial institution pertaining to a customer’s relationship with the fi- nancial institution;
(6) the term “exceeds authorized access” means to access a computer with au- thorization and to use such access to obtain or alter information in the computer that the accesser is not entitled so to obtain or alter; and
The Computer Fraud and Abuse Act of 1986 81
(7) the term “department of the United States” means the legislative or judicial branch of the Government or one of the executive departments enumerated in section 101 of title 5.
(f) This section does not prohibit any lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency of the United States, a State, or a political subdivision of a State, or of an intelligence agency of the United States.
The Electronic Communications Privacy Act of 1986 This piece of legislation is a critical one in regard to computer crimes. One rea- son for this is because it was one of the earliest laws to specifically address com- puter crimes. Prior to this act there were few laws at state or federal levels that specifically addressed computer crime. The most obvious and notable exception is the Computer Fraud and Abuse Act of 1984. The fact that these two laws were enacted within a period of two years marks a turning point in computer crime. Legislative bodies were beginning to take computer crime seriously and to ad- dress those crimes by passing relevant legislation.
A second reason that the Electronic Communications Privacy Act is so im- portant is that it covers how evidence can be gathered. The purpose of the act was to extend federal wiretap laws into the domain of the newer electronic commu- nications medium5. Specifically, it was an amendment to Title III of the Omni- bus Crime Control and Safe Streets Act of 1968, also called the “wiretap statute.” Anyone investigating computer crimes should be familiar with the Electronic Communications Privacy Act and make certain that any investigations are con- ducted in compliance with this act.
As with many laws, this one has been challenged in court. Specifically, the ques- tion has been raised as to whether or not this law applies to e-mail that is stored for transit, such as on an e-mail server. In United States v. Councilman, a United States District Court ruled that e-mail in storage for transit was not protected under this law. The crux of the case was essentially a claim that an e-mail that was found on an e-mail server, rather than on an individual’s computer, was not protected by privacy laws. However in 2005, the United States Court of Appeals for the First Circuit reversed this opinion. In this author’s opinion, that was absolutely the right thing to do. Many computer users are not aware that their e-mail might be on an e-mail server and not simply on their computers. An end user who happens to be a computer novice would have an expectation of privacy
Chapter 3 ■ United States Computer Laws Part I82
in e-mail, and this was what the appellate court found. This means that e-mail on an e-mail server is considered private communication just like phone conversa- tions, and law enforcement officers are under the same burden to seek a warrant for accessing such data.
The Federal Wiretap Statute, as amended by the Electronic Communications Privacy Act, affects the recording of phone conversations. The two statutes (the Federal Wiretap Statute and ECPA) make it illegal to intercept or disclose in- tercepted telephone communications unless certain exceptions apply. The law creates civil and criminal liability for anyone who “intentionally intercepts, en- deavors to intercept, or procures any other person to intercept or endeavor to intercept, any wire, oral or electronic communication.”
There are two exceptions to this law that must be met before one can legally monitor phone calls:
■ The consent exception. This simply means that both parties to a conversation must give consent. If you will recall the last time you called a customer-service phone number, it is likely that an automated voice informed you the call was being recorded, and the person you spoke to may have even asked your consent to record the call.
■ The business extension exemption. This does not mean that a business can monitor and record all employee calls. The business extension exemption can only be claimed for monitoring performed by certain types of equip- ment, and the recording must occur in the ordinary course of business.
With the Electronic Communications Privacy Act, these same guidelines are now extended to e-mail communications, with a few minor adjustments. The most obvious difference is that e-mail is a written message that when sent to a re- cipient is automatically “recorded” by the recipient. The recipient has the e-mail and may choose to keep it or delete it. This is obviously different from a phone conversation where special steps must be taken to record a phone call. This is important for investigators as well as business owners, or anyone who might feel a need to intercept any form of electronic communications.
Related Cases The case of United States v. Councilman, which we briefly mentioned earlier, is important in the history of the Electronic Communications Privacy Act. The
The Electronic Communications Privacy Act of 1986 83
defendant in this case was a vice president of Interloc and Alibris. Interloc was a book service that also provided e-mail accounts to book dealers6. Mr. Councilman had an employee write a program that took all of the e-mails from Amazon.com to these book dealers and copied them to his own e-mail box, which allowed him to intercept literally thousands of e-mails.
The case became interesting because the defendant’s attorneys claimed that since the messages were still on an e-mail server, and had not yet been delivered to the recipient, that this did not constitute a wiretap. The court agreed with the defendant. This has lead to ambiguities regarding the interception of e-mails, when it is legal and when it is not. As we have already stated, the appellate court overturned this decision. This case is also noteworthy because the in- dividual intercepting the e-mails was not a law-enforcement official, but rather a private citizen, and the interception of the e-mails was not part of a criminal investigation.
The Actual Law Section 2511. Interception and disclosure of wire, oral, or electronic commu- nications prohibited
Except as otherwise specifically provided in this chapter any person who in- tentionally intercepts any wire oral or electronic communication; intentionally uses any electronic, mechanical or other device to intercept any oral commu- nication when
(ii) such device transmits communications by radio, or interferes with the transmission of such communication; intentionally discloses . . . the contents of any wire, oral or electronic communication . . . ; or intentionally uses . . . the contents of any wire, oral or electronic communication . . . ; shall be punished as provided in subsection (4) or shall be subject to suit as provided in subsec- tion (5).
(g) It shall not be unlawful under this chapter or chapter 121 of this title for any person -
(i) to intercept or access any electronic communication made through an elec- tronic communication system that is configured so that such electronic com- munication is readily accessible to the general public;
Chapter 3 ■ United States Computer Laws Part I84
(ii) to intercept any radio communication that is transmitted -
by any station for the use of the general public, or that relates to ships, aircraft, vehicles, or persons in distress; by any governmental, law enforcement, civil de- fense, private land mobile, or public safety communications system, including police and fire, readily accessible to the general public; by any station operating on an authorized frequency within the bands allocated to the amateur, citizens band, or general mobile radio services; or by any marine or aeronautical com- munications system;
(iv) to intercept any wire or electronic communication the transmission of which is causing harmful interference to any lawfully operating station or con- sumer electronic equipment, to the extent necessary to identify the source of such interference; or
(v) for other users of the same frequency to intercept any radio communication made through a system that utilizes frequencies monitored by individuals engaged in the provision or the use of such system, if such communication is not scrambled or encrypted. (Paragraph (4)(b)(ii) is where ECPA specifically mentions cellular and cordless telephones, public land mobile radio system and paging services as being prohibited from monitoring, subject to a $500 fine.)
Section 2512. Manufacture, distribution, possession, and advertising of wire, oral or electronic communication intercepting devices prohibited
(1) Except as otherwise specifically provided in this chapter, any person who intentionally -
(a) sends through the mail, or sends or carries in interstate or foreign commerce, any electronic, mechanical, or other device, knowing or having reason to know that the design of such device renders it primarily useful for the purpose of the surreptitious interception of wire, oral, or electronic communications;
(b) manufactures, assembles, possesses, or sells any electronic, mechanical, or other device, knowing or having reason to know that the design of such device renders it primarily useful for the purpose of the surreptitious interception of wire, oral, or electronic communications, and that such device or any compo- nent thereof has been or will be sent through the mail or transported in interstate or foreign commerce; or
(c) places in any newspaper, magazine, handbill, or other publication or dis- seminates by electronic means any advertisement of -
The Electronic Communications Privacy Act of 1986 85
(i) any electronic, mechanical, or other device knowing or having reason to know that the design of such device renders it primarily useful for the purpose of the surreptitious interception of wire, oral, or electronic communications; or
(ii) any other electronic, mechanical, or other device, where such advertisement promotes the use of such device for the purpose of the surreptitious interception of wire, oral, or electronic communications, knowing the content of the adver- tisement and knowing or having reason to know that such advertisement will be sent through the mail or transported in interstate or foreign commerce, shall be fined under this title or imprisoned not more than five years, or both.
(2) It shall not be unlawful under this section for -
(a) a provider of wire or electronic communication service or an officer, agent, or employee of, or a person under contract with, such a provider, in the normal course of the business of providing that wire or electronic communication ser- vice, or
(b) an officer, agent, or employee of, or a person under contract with, the United States, a State, or a political subdivision thereof, in the normal course of the activities of the United States, a State, or a political subdivision thereof, to send through the mail, send or carry in interstate or foreign commerce, or manu- facture, assemble, possess, or sell any electronic, mechanical, or other device knowing or having reason to know that the design of such device renders it pri- marily useful for the purpose of the surreptitious interception of wire, oral, or electronic communications.
(3) It shall not be unlawful under this section to advertise for sale a device de- scribed in subsection (1) of this section if the advertisement is mailed, sent, or carried in interstate or foreign commerce solely to a domestic provider of wire or electronic communication service or to an agency of the United States, a State, or a political subdivision thereof which is duly authorized to use such device.
Section 2515. Prohibition of use as evidence of intercepted wire or oral communications
Whenever any wire or oral communication has been intercepted, no part of the contents of such communication and no evidence derived therefrom may be re- ceived in evidence in any trial, hearing, or other proceeding in or before any court, grand jury, department, officer, agency, regulatory body, legislative com- mittee, or other authority of the United States, a State, or a political subdivision thereof if the disclosure of that information would be in violation of this chapter.
Chapter 3 ■ United States Computer Laws Part I86
The Communications Decency Act of 1996 This was the first legislative attempt to curtail Internet pornography. The Com- munications Decency Act was actually part of the Telecommunications Act of 1996, specifically title V. One of the main focuses of the act was to reduce chil- dren’s access to pornography7. To quote from the act itself, any person who:
knowingly (A) uses an interactive computer service to send to a specific person or persons under 18 years of age, or (B) uses any interactive com- puter service to display in a manner available to a person under 18 years of age, any comment, request, suggestion, proposal, image, or other commu- nication that, in context, depicts or describes, in terms patently offensive as measured by contemporary community standards, sexual or excretory activities or organs
In July of 1996, a U.S. federal court in New York struck down the portion of the act which was intended to protect children from indecent speech on the grounds that it was too broad8. Almost a year later, on June 26, 1997, the Supreme Court upheld another court’s decision in Reno v. American Civil Liberties Union, thus striking down significant portions of the Communications Decency Act. The court stated that the indecency provisions were an unconstitutional abridgement of the First Amendment right to free speech because they did not permit parents to decide for themselves what material was acceptable for their children. The court also opined that the CDA’s provisions were overly broad in that they ex- tended to non-commercial speech, and did not define “patently offensive,” a term with no prior legal meaning.
In 2003, Congress amended the Communications Decency Act and removed the indecency provisions that the Supreme Court had struck down in Reno v. ACLU. In the case of Nitke v. Gonzales, additional and separate challenges were made to those provisions of the act, but they were rejected by a federal court in New York in 2005. In 2006, the Supreme Court affirmed that New York court’s 2005 deci- sion. What this means for law-enforcement agencies is that the Communications Decency Act, as it was amended in 2003, is current federal law, not the original act that was passed by Congress in 1996.
Section 230 of the Communications Decency Act is particularly important in a law-enforcement context. This section states that “No provider or user of an interactive computer service shall be treated as the publisher or speaker of any
The Communications Decency Act of 1996 87
information provided by another information content provider.” This means that Internet service providers and Web hosting companies cannot be held liable for the content their users may post on their services.
Related Cases The most obvious related case would be the case that struck down significant portions of this act. In the case of Reno v. ACLU, the American Civil Liberties Union sued then attorney general Janet Reno, challenging the constitutionality of this law9. A three-judge federal district court ruled that certain provisions of the Communications Decency Act violate the first amendment of the U.S. Con- stitution. On June 26, 1997, the Supreme Court affirmed that ruling. This is important for the obvious reason that it rendered portions of the law null and void.
The case of Zango Inc. v. Kaspersky Lab10 dealt with the immunity clause in the Communications Decency Act. That clause holds Internet service providers immune from prosecution for activities in which their subscribers may engage that violate the Communications Decency Act. In this case, the issue was whether that immunity applied to the makers of antivirus and anti-spyware programs.
The plaintiff in the case, Zango, Inc., was a company that provided access to a catalog of online videos, games, and music to users who agreed to view adver- tisements while surfing the Internet. Kaspersky’s software classified Zango as adware, a type of malware. Zango sued Kaspersky, seeking an injunction against its blocking activities.
In 2009, the Ninth Federal Circuit Court of Appeals held that Kaspersky was entitled to immunity as a “provider” of an “interactive computer service.” The court concluded that a provider of filtering software or services may not be held liable for any action taken to make its filtering software available “so long as the provider enables access by multiple users to a computer service.”
This case is important not only because the appeals court clarified what a ser- vice provider was, but also because this was an interesting application of the act itself. The protections in the Communications Decency Act were meant to protect Internet service providers from being convicted should one of their subscribers use their service to publish pornography. However, the defendants in this litigation, Kaspersky Labs, utilized the law to defend themselves against
Chapter 3 ■ United States Computer Laws Part I88
a matter not directly related to the provisions of the law. The lesson to be learned here is that the law is not static, but rather malleable. Creative attorneys on either side of any case can often make novel applications of the law to suit their clients’ needs.
The Actual Law Section 223 (47 U.S.C. 223) is amended
(1) by striking subsection (a) and inserting in lieu thereof:
(a) Whoever
(1) in interstate or foreign communications -
(A) by means of a telecommunications device knowingly -
(i) makes, creates, or solicits, and
(ii) initiates the transmission of, any comment, request, suggestion, proposal, image, or other communication which is obscene, lewd, lascivious, filthy, or in- decent, with intent to annoy, abuse, threaten, or harass another person;
(B) by means of a telecommunications device knowingly -
(i) makes, creates, or solicits, and
(ii) initiates the transmission of, any comment, request, suggestion, proposal, image, or other communication which is obscene or indecent, knowing that the recipient of the communication is under 18 years of age, regardless of whether the maker of such communication placed the call or initiated the communication;
(C) makes a telephone call or utilizes a telecommunications device, whether or not conversation or communication ensues, without disclosing his identity and with intent to annoy, abuse, threaten, or harass any person at the called number or who receives the communications;
(D) makes or causes the telephone of another repeatedly or continuously to ring, with intent to harass any person at the called number; or
(E) makes repeated telephone calls or repeatedly initiates communication with a telecommunications device, during which conversation or communication en- sues, solely to harass any person at the called number or who receives the com- munication; or
The Communications Decency Act of 1996 89
(2) knowingly permits any telecommunications facility under his control to be used for any activity prohibited by paragraph (1) with the intent that it be used for such activity,
shall be fined under title 18, United States Code, or imprisoned not more than two years, or both.”; and
(2) by adding at the end the following new subsections:
(d) Whoever -
(1) in interstate or foreign communications knowingly -
(A) uses an interactive computer service to send to a specific person or persons under 18 years of age, or
(B) uses any interactive computer service to display in a manner available to a person under 18 years of age, any comment, request, suggestion, proposal, image, or other communication that, in context, depicts or describes, in terms patently offensive as measured by contemporary community standards, sexual or excretory activities or organs, regardless of whether the user of such service placed the call or initiated the communication; or
(2) knowingly permits any telecommunications facility under such person’s control to be used for an activity prohibited by paragraph (1) with the intent that it be used for such activity, shall be fined under title 18, United States Code, or imprisoned not more than two years, or both.
(e) In addition to any other defenses available by law:
(1) No person shall be held to have violated subsection (a) or (d) solely for providing access or connection to or from a facility, system, or network not under that person’s control, including transmission, downloading, intermediate storage, access software, or other related capabilities that are incidental to pro- viding such access or connection that does not include the creation of the con- tent of the communication.
(2) The defenses provided by paragraph (1) of this subsection shall not be ap- plicable to a person who is a conspirator with an entity actively involved in the creation or knowing distribution of communications that violate this section, or who knowingly advertises the availability of such communications.
(3) The defenses provided in paragraph (1) of this subsection shall not be ap- plicable to a person who provides access or connection to a facility, system, or
Chapter 3 ■ United States Computer Laws Part I90
network engaged in the violation of this section that is owned or controlled by such person.
(4) No employer shall be held liable under this section for the actions of an employee or agent unless the employee’s or agent’s conduct is within the scope of his or her employment or agency and the employer (A) having knowledge of such conduct, authorizes or ratifies such conduct, or (B) recklessly disregards such conduct.
(5) It is a defense to a prosecution under subsection (a)(1)(B) or (d), or under subsection (a)(2) with respect to the use of a facility for an activity under sub- section (a)(1)(B) that a person -
(A) has taken, in good faith, reasonable, effective, and appropriate actions under the circumstances to restrict or prevent access by minors to a communication specified in such subsections, which may involve any appropriate measures to restrict minors from such communications, including any method which is fea- sible under available technology; or
(B) has restricted access to such communication by requiring use of a verified credit card, debit account, adult access code, or adult personal identification number.
(6) The Commission may describe measures which are reasonable, effective, and appropriate to restrict access to prohibited communications under subsection (d). Nothing in this section authorizes the Commission to enforce, or is intended to provide the Commission with the authority to approve, sanction, or permit, the use of such measures. The Commission shall have no enforcement authority over the failure to utilize such measures. The Commission shall not endorse specific products relating to such measures. The use of such measures shall be admitted as evidence of good faith efforts for purposes of paragraph (5) in any action arising under subsection (d). Nothing in this section shall be construed to treat interactive computer services as common carriers or telecommunications carriers.
(f)(1) No cause of action may be brought in any court or administrative agency against any person on account of any activity that is not in violation of any law punishable by criminal or civil penalty, and that the person has taken in good faith to implement a defense authorized under this section or otherwise to re- strict or prevent the transmission of, or access to, a communication specified in this section.
The Communications Decency Act of 1996 91
(2) No State or local government may impose any liability for commercial activities or actions by commercial entities, nonprofit libraries, or institutions of higher education in connection with an activity or action described in subsec- tion (a)(2) or (d) that is inconsistent with the treatment of those activities or actions under this section: Provided, however, That nothing herein shall preclude any State or local government from enacting and enforcing com- plementary oversight, liability, and regulatory systems, procedures, and re- quirements, so long as such systems, procedures, and requirements govern only intrastate services and do not result in the imposition of inconsistent rights, duties or obligations on the provision of interstate services. Nothing in this subsection shall preclude any State or local government from governing conduct not covered by this section.
(g) Nothing in subsection (a), (d), (e), or (f) or in the defenses to prosecution under (a) or (d) shall be construed to affect or limit the application or enforce- ment of any other Federal law.
(h) For purposes of this section -
(1) The use of the term “telecommunications device” in this section -
(A) shall not impose new obligations on broadcasting station licensees and cable operators covered by obscenity and indecency provisions elsewhere in this Act; and
(B) does not include an interactive computer service.
(2) The term “interactive computer service” has the meaning provided in section 230(e)(2).
(3) The term “access software” means software (including client or server soft- ware) or enabling tools that do not create or provide the content of the com- munication but that allow a user to do any one or more of the following:
(A) filter, screen, allow, or disallow content;
(B) pick, choose, analyze, or digest content; or
(C) transmit, receive, display, forward, cache, search, subset, organize, re- organize, or translate content.
(4) The term “institution of higher education” has the meaning provided in section 1201 of the Higher Education Act of 1965 (20 U.S.C. 1141).
Chapter 3 ■ United States Computer Laws Part I92
(5) The term “library” means a library eligible for participation in State-based plans for funds under title III of the Library Services and Construction Act (20 U.S.C. 355e et seq.).
No Electronic Theft Act of 1997 What is commonly called the No Electronic Theft Act of 199711, known also as the NET Act, was House Resolution 2265 signed into law by President Clinton on December 16, 1997. The purpose of this law is to provide law enforcement and prosecutors with the tools to fight copyright violations on the Internet. Under this law, electronic copyright infringement can carry a maximum penalty of three years in prison and a $250,000 fine. This law made it a federal crime to reproduce, distribute, or share copies of electronic copyrighted works. This means not only software, but also music, videos, or electronic versions of printed material. Under this law, it is a crime to distribute such copyrighted material, even if the distributor does so without any financial gain.
The law does require that the distribution be willful, and that the retail value of the copyrighted material exceed $1,000. It is important for law enforcement and prosecutors to keep in mind that this law comes with a five-year statute of lim- itations. In other words, the crime must be charged and prosecuted within five years of its commission.
While the distribution of copyrighted material is the key focus of this act and the portion most often discussed in legal circles, it is not the only thing this law did. It also made it a criminal act to:
■ Remove a copyright notice from an electronic product.
■ Knowingly place a false copyright notice (in other words, to claim a copy- right on something someone else already had copyright to).
Furthermore, the NET Act specifically addressed violation of copyrights on live musical or video performances. This means that it is a federal crime to record live performances without permission and then distribute such recordings.
Related Cases The case of United States v. LaMacchia12 involved an M.I.T. student named David LaMacchia. Mr. LaMacchia created and operated electronic bulletin boards on the Internet and encouraged users to upload and download copies of popular
No Electronic Theft Act of 1997 93
copyrighted commercial software. The illegal copying that took place on the bul- letin boards resulted in alleged losses to the copyright owners of more than $1 million. However, LaMacchia himself did not have any financial interest in the copyright violations; he did not have any monetary gain, he merely encouraged the acts and provided a bulletin board. Because of this issue, prosecutors charged him with wire fraud rather than criminal copyright infringement. The court dismissed the indictment, holding that copyright infringement can only be prosecuted under the Copyright Act. This case is important because it demonstrates the care law enforcement and prosecutors must take in charging a client. Sometimes one can creatively apply the law to prosecute a criminal who might not exactly fit into a particular law’s definitions. However, this is always fraught with problems and, as happened in this case, can be completely dismissed by the court.
The Actual Law SEC. 2. CRIMINAL INFRINGEMENT OF COPYRIGHTS.
(a) DEFINITION OF FINANCIAL GAIN. Section 101 of title 17, United States Code, is amended by inserting after the undesignated paragraph relating to the term “display,” the following new paragraph: “The term ‘financial gain’ includes receipt, or expectation of receipt, of anything of value, including the receipt of other copyrighted works.”
(b) CRIMINAL OFFENSES. Section 506(a) of title 17, United States Code, is amended to read as follows:
(a) CRIMINAL INFRINGEMENT. Any person who infringes a copyright will- fully either -
(1) for purposes of commercial advantage or private financial gain, or
(2) by the reproduction or distribution, including by electronic means, during any 180-day period, of 1 or more copies or phonorecords of 1 or more copyrighted works, which have a total retail value of more than $1,000 shall be punished as provided under section 2319 of title 18, United States Code. For purposes of this subsection, evidence of reproduction or distribution of a copyrighted work, by itself, shall not be sufficient to establish willful infringement.
(c) LIMITATION ON CRIMINAL PROCEEDINGS. Section 507(a) of title 17, United States Code, is amended by striking “three” and inserting “5.”
Chapter 3 ■ United States Computer Laws Part I94
(d) CRIMINAL INFRINGEMENT OF A COPYRIGHT. Section 2319 of title 18, United States Code, is amended -
(1) in subsection (a), by striking “subsection (b)” and inserting “subsections (b) and (c)”;
(2) in subsection (b) -
(A) in the matter preceding paragraph (1), by striking “subsection (a) of this section” and inserting “section 506(a)(1) of title 17” and
(B) in paragraph (1) -
(i) by inserting “including by electronic means,” after “if the offense consists of the reproduction or distribution,”; and
(ii) by striking “with a retail value of more than $2,500” and inserting “which have a total retail value of more than $2,500”; and
(3) by redesignating subsection (c) as subsection (e) and inserting after subsec- tion (b) the following:
(c) Any person who commits an offense under section 506(a)(2) of title 17, United States Code
(1) shall be imprisoned not more than 3 years, or fined in the amount set forth in this title, or both, if the offense consists of the reproduction or distribution of 10 or more copies or phonorecords of 1 or more copyrighted works, which have a total retail value of $2,500 or more;
(2) shall be imprisoned not more than 6 years, or fined in the amount set forth in this title, or both, if the offense is a second or subsequent offense under para- graph (1); and
(3) shall be imprisoned not more than 1 year, or fined in the amount set forth in this title, or both, if the offense consists of the reproduction or distribution of 1 or more copies or phonorecords of 1 or more copyrighted works, which have a total retail value of more than $1,000.
(d) (1) During preparation of the pre-sentence report pursuant to Rule 32(c) of the Federal Rules of Criminal Procedure, victims of the offense shall be per- mitted to submit, and the probation officer shall receive, a victim impact state- ment that identifies the victim of the offense and the extent and scope of the
No Electronic Theft Act of 1997 95
injury and loss suffered by the victim, including the estimated economic impact of the offense on that victim.
(2) Persons permitted to submit victim impact statements shall include -
(A) producers and sellers of legitimate works affected by conduct involved in the offense;
(B) holders of intellectual property rights in such works; and
(C) the legal representatives of such producers, sellers, and holders.
(e) UNAUTHORIZED FIXATION AND TRAFFICKING OF LIVE MUSICAL PERFORMANCES -
Section 2319A of title 18, United States Code, is amended -
(1) by redesignating subsections (d) and (e) as subsections (e) and (f), respec- tively; and
(2) by inserting after subsection (c) the following:
(d) VICTIM IMPACT STATEMENT-
(1) During preparation of the pre-sentence report pursuant to Rule 32(c) of the Federal Rules of Criminal Procedure, victims of the offense shall be permitted to submit, and the probation officer shall receive, a victim impact statement that identifies the victim of the offense and the extent and scope of the injury and loss suffered by the victim, including the estimated economic impact of the offense on that victim.
(2) Persons permitted to submit victim impact statements shall include -
(A) producers and sellers of legitimate works affected by conduct involved in the offense;
(B) holders of intellectual property rights in such works; and
(C) the legal representatives of such producers, sellers, and holders.
(f) TRAFFICKING IN COUNTERFEIT GOODS OR SERVICES. Section 2320 of title 18, United States Code, is amended -
(1) by redesignating subsections (d) and (e) as subsections (e) and (f), respec- tively; and
(2) by inserting after subsection (c) the following:
Chapter 3 ■ United States Computer Laws Part I96
(d) (1) During preparation of the pre-sentence report pursuant to Rule 32(c) of the Federal Rules of Criminal Procedure, victims of the offense shall be per- mitted to submit, and the probation officer shall receive, a victim impact state- ment that identifies the victim of the offense and the extent and scope of the injury and loss suffered by the victim, including the estimated economic impact of the offense on that victim.
(2) Persons permitted to submit victim impact statements shall include -
(A) producers and sellers of legitimate goods or services affected by conduct involved in the offense;
(B) holders of intellectual property rights in such goods or services; and
(C) the legal representatives of such producers, sellers, and holders.
Digital Millennium Copyright Act This act, signed into law on October 28, 199813, frequently called the DMCA, focused primarily on methods for circumventing access control. Basically, this law made it illegal to attempt to circumvent copy-protection technologies. Manufacturers of CDs, DVDs, and other media frequently introduce technolo- gical measures that prevent unauthorized copying of the media in order to pro- tect their copyrighted material.
This law did provide protection from prosecution for online providers, includ- ing Internet service providers, if they adhered to certain measures. In other words, an ISP is not liable if one of its customers is using the ISP’s service to violate the DMCA.
In addition to the protections for ISPs and other online providers, the law allows for the Library of Congress to issue specific and explicit exceptions to DCMA. Usually, these exemptions are granted when it is shown that a particular access- control technology has had a significant adverse effect on the ability of individuals to make non-infringing uses of copyrighted works. The specific exemption rules are revised every three years. A proposal for an exemption can be submitted by anyone to the Registrar of Copyrights.
Related Cases In the case of IO Group Inc. v. Veoh Networks Inc.14, IO Group alleged that Veoh was responsible for copyright infringement by allowing videos owned by
Digital Millennium Copyright Act 97
IO Group to be accessed through Veoh’s online service without permission. According to IO Group, this had occurred more than 40,000 times in a period of less than one month. IO Group argued that since Veoh translated the uploaded videos from users to a Flash format that Veoh was a direct violator of the law, not merely an Internet service provider. The IO Group argued that this prevented Veoh from using the DMCA safe harbor provisions granted to Internet service providers whose customers violated the act. However, the court granted Veoh’s motion for summary judgment and held that Veoh was entitled to the protection of the DMCA safe-harbor provisions.
Children’s Internet Protection Act This bill was first introduced into Congress in 1999, and was signed into law on December 21, 200015. The primary purpose of this bill was to require libraries and schools to filter content that children have access to. The law does require that libraries turn off the filter for adult patrons should they request it. The intent is simply to ensure that children are not exposed to pornographic or indecent material on computer systems supplied by the taxpayer.
Schools and libraries subject to CIPA may not receive the discounts offered by the E-rate program unless they certify that they have an Internet safety policy and technology-protection measures in place. An Internet safety policy must include technology-protection measures to block or filter Internet access to pictures that are obscene, child pornography, or harmful to minors (for computers that are accessed by minors).
Schools and libraries must also certify that, as part of their Internet safety policy, they are educating minors about appropriate online behavior, including cyber- bullying awareness and response and interacting with other individuals on social-networking sites and in chat rooms.
Schools subject to CIPA are required to adopt and enforce a policy to monitor online activities of minors. Specifically, schools and libraries subject to CIPA are required to adopt and implement a policy addressing access by minors to in- appropriate matter on the Internet; the safety and security of minors when using electronic mail, chat rooms, and other forms of direct electronic communica- tions; unauthorized access, including so-called “hacking,” and other unlawful activities by minors online; unauthorized disclosure, use, and dissemination
Chapter 3 ■ United States Computer Laws Part I98
of personal information regarding minors; and restricting minors’ access to materials harmful to them.
The Actual Law SEC. 1703. STUDY OF TECHNOLOGY PROTECTION MEASURES.
(a) IN GENERAL. Not later than 18 months after the date of the enactment of this Act, the National Telecommunications and Information Administration shall initiate a notice and comment proceeding for purposes of -
(1) evaluating whether or not currently available technology protection mea- sures, including commercial Internet blocking and filtering software, adequately addresses the needs of educational institutions;
(2) making recommendations on how to foster the development of measures that meet such needs; and
(3) evaluating the development and effectiveness of local Internet safety policies that are currently in operation after community input.
(b) DEFINITIONS. In this section:
(1) TECHNOLOGY PROTECTION MEASURE. The term “technology protec- tion measure” means a specific technology that blocks or filters Internet access to visual depictions that are -
(A) obscene, as that term is defined in section 1460 of title 18, United States Code;
(B) child pornography, as that term is defined in section 2256 of title 18, United States Code; or
(C) harmful to minors.
(2) HARMFUL TO MINORS. The term “harmful to minors” means any picture, image, graphic image file, or other visual depiction that -
(A) taken as a whole and with respect to minors, appeals to a prurient interest in nudity, sex, or excretion;
(B) depicts, describes, or represents, in a patently offensive way with respect to what is suitable for minors, an actual or simulated sexual act or sexual contact, actual or simulated normal or perverted sexual acts, or a lewd exhibition of the genitals; and
Children’s Internet Protection Act 99
(C) taken as a whole, lacks serious literary, artistic, political, or scientific value as to minors.
(3) SEXUAL ACT; SEXUAL CONTACT. The terms “sexual act” and “sexual contact” have the meanings given such terms in section 2246 of title 18, United States Code.
Subtitle A. Federal Funding for Educational Institution Computers
SEC. 1711. LIMITATION ON AVAILABILITY OF CERTAIN FUNDS FOR SCHOOLS.
Title III of the Elementary and Secondary Education Act of 1965 (20 U.S.C. 6801 et seq.) is amended by adding at the end the following:
PART F. LIMITATION ON AVAILABILITY OF CERTAIN FUNDS FOR SCHOOLS.
SEC. 3601. LIMITATION ON AVAILABILITY OF CERTAIN FUNDS FOR SCHOOLS.
(a) INTERNET SAFETY.
(1) IN GENERAL. No funds made available under this title to a local educational agency for an elementary or secondary school that does not receive services at discount rates under section 254(h)(5) of the Communications Act of 1934, as added by section 1721 of Children’s Internet Protection Act, may be used to purchase computers used to access the Internet, or to pay for direct costs asso- ciated with accessing the Internet, for such school unless the school, school board, local educational agency, or other authority with responsibility for ad- ministration of such school both -
(A)(i) has in place a policy of Internet safety for minors that includes the op- eration of a technology protection measure with respect to any of its computers with Internet access that protects against access through such computers to vi- sual depictions that are -
(I) obscene;
(II) child pornography; or
(III) harmful to minors; and
Chapter 3 ■ United States Computer Laws Part I100
(ii) is enforcing the operation of such technology protection measure during any use of such computers by minors; and
(B)(i) has in place a policy of Internet safety that includes the operation of a technology protection measure with respect to any of its computers with Inter- net access that protects against access through such computers to visual depic- tions that are -
(I) obscene; or
(II) child pornography; and
(ii) is enforcing the operation of such technology protection measure during any use of such computers.
(2) TIMING AND APPLICABILITY OF IMPLEMENTATION.
(A) IN GENERAL. The local educational agency with responsibility for a school covered by paragraph (1) shall certify the compliance of such school with the requirements of paragraph (1) as part of the application process for the next program funding year under this Act following the effective date of this section, and for each subsequent program funding year thereafter.
(B) PROCESS.
(i) SCHOOLS WITH INTERNET SAFETY POLICIES AND TECHNOLOGY PROTECTION MEASURES IN PLACE. A local educational agency with respon- sibility for a school covered by paragraph (1) that has in place an Internet safety policy meeting the requirements of paragraph (1) shall certify its compliance with paragraph (1) during each annual program application cycle under this Act.
(ii) SCHOOLS WITHOUT INTERNET SAFETY POLICIES AND TECHNOL- OGY PROTECTION MEASURES IN PLACE. A local educational agency with responsibility for a school covered by paragraph (1) that does not have in place an Internet safety policy meeting the requirements of paragraph (1) -
(I) for the first program year after the effective date of this section in which the local educational agency is applying for funds for such school under this Act, shall certify that it is undertaking such actions, including any necessary pro- curement procedures, to put in place an Internet safety policy that meets such requirements; and
Children’s Internet Protection Act 101
(II) for the second program year after the effective date of this section in which the local educational agency is applying for funds for such school under this Act, shall certify that such school is in compliance with such requirements.
Any school covered by paragraph (1) for which the local educational agency concerned is unable to certify compliance with such requirements in such second program year shall be ineligible for all funding under this title for such second program year and all subsequent program years until such time as such school comes into compliance with such requirements.
(iii) WAIVERS. Any school subject to a certification under clause (ii)(II ) for which the local educational agency concerned cannot make the certification otherwise required by that clause may seek a waiver of that clause if State or local procurement rules or regulations or competitive bidding requirements prevent the making of the certification otherwise required by that clause. The local edu- cational agency concerned shall notify the Secretary of the applicability of that clause to the school. Such notice shall certify that the school will be brought into compliance with the requirements in paragraph (1) before the start of the third program year after the effective date of this section in which the school is ap- plying for funds under this title.
(3) DISABLING DURING CERTAIN USE. An administrator, supervisor, or person authorized by the responsible authority under paragraph (1) may disable the technology protection measure concerned to enable access for bona fide re- search or other lawful purposes.
(4) NONCOMPLIANCE.
(A) USE OF GENERAL EDUCATION PROVISIONS ACT REMEDIES. When- ever the Secretary has reason to believe that any recipient of funds under this title is failing to comply substantially with the requirements of this subsection, the Secretary may -
(i) withhold further payments to the recipient under this title,
(ii) issue a complaint to compel compliance of the recipient through a cease and desist order, or
(iii) enter into a compliance agreement with a recipient to bring it into com- pliance with such requirements, in same manner as the Secretary is authorized to
Chapter 3 ■ United States Computer Laws Part I102
take such actions under sections 455, 456, and 457, respectively, of the General Education Provisions Act (20 U.S.C. 1234d).
(B) RECOVERY OF FUNDS PROHIBITED. The actions authorized by sub- paragraph (A) are the exclusive remedies available with respect to the failure of a school to comply substantially with a provision of this subsection, and the Secretary shall not seek a recovery of funds from the recipient for such failure.
(C) RECOMMENCEMENT OF PAYMENTS. Whenever the Secretary de- termines (whether by certification or other appropriate evidence) that a recipient of funds who is subject to the withholding of payments under subparagraph (A) (i) has cured the failure providing the basis for the withholding of payments, the Secretary shall cease the withholding of payments to the recipient under that subparagraph.
(5) DEFINITIONS. In this section:
(A) COMPUTER. The term “computer” includes any hardware, software, or other technology attached or connected to, installed in, or otherwise used in connection with a computer.
(B) ACCESS TO INTERNET. An computer shall be considered to have access to the Internet if such computer is equipped with a modem or is connected to a computer network which has access to the Internet.
(C) ACQUISITION OR OPERATION. An elementary or secondary school shall be considered to have received funds under this title for the acquisition or op- eration of any computer if such funds are used in any manner, directly or in- directly -
(i) to purchase, lease, or otherwise acquire or obtain the use of such computer; or
(ii) to obtain services, supplies, software, or other actions or materials to sup- port, or in connection with, the operation of such computer.
(D) MINOR. The term “minor” means an individual who has not attained the age of 17.
(E) CHILD PORNOGRAPHY. The term “child pornography” has the meaning given such term in section 2256 of title 18, United States Code.
Children’s Internet Protection Act 103
(F) HARMFUL TO MINORS. The term “harmful to minors” means any picture, image, graphic image file, or other visual depiction that -
(i) taken as a whole and with respect to minors, appeals to a prurient interest in nudity, sex, or excretion;
(ii) depicts, describes, or represents, in a patently offensive way with respect to what is suitable for minors, an actual or simulated sexual act or sexual contact, actual or simulated normal or perverted sexual acts, or a lewd exhibition of the genitals; and
(iii) taken as a whole, lacks serious literary, artistic, political, or scientific value as to minors.
(G) OBSCENE. The term “obscene” has the meaning given such term in section 1460 of title 18, United States Code.
(H) SEXUAL ACT; SEXUAL CONTACT. The terms “sexual act” and “sexual contact” have the meanings given such terms in section 2246 of title 18, United States Code.
(b) EFFECTIVE DATE. This section shall take effect 120 days after the date of the enactment of the Children’s Internet Protection Act.
(c) SEPARABILITY. If any provision of this section is held invalid, the remainder of this section shall not be affected thereby.
CAN-SPAM Act of 2003 The CAN-SPAM Act of 200316 was pivotal because it was the first law con- cerning the transmission of commercial e-mail. However, critics have claimed the law has too many loopholes. For example, one does not need permission before sending e-mail, which means unsolicited e-mail—what most people consider spam—is not prohibited. It also means mass e-mailings for political, religious, or ideological purposes that do not represent a commercial interest are exempt.
The only requirement is that the sender must provide a method whereby the receiver can opt out, and that method cannot require the receiver to pay a fee to opt out.
The law defines commercial e-mail as “any electronic mail message the primary purpose of which is the commercial advertisement or promotion of a commercial
Chapter 3 ■ United States Computer Laws Part I104
product or service (including content on an Internet Web site operated for a commercial purpose).” This means mass mailings that have no commercial pur- pose are not covered by this law.
All commercial e-mail is required to offer ways for the recipient to opt out. Those methods must meet the following guidelines:
■ A visible and operable unsubscribe mechanism is present in all e-mails.
■ Consumer opt-out requests are honored within 10 days.
■ Opt-out lists, also known as suppression lists, can only used for compliance purposes, not to be sold to other vendors/senders
There are also restrictions on how the sender can acquire the recipient’s e-mail address and how the sender can actually transmit the e-mail. Those requirements are as follows:
■ A message cannot be sent through an open relay.
■ A message cannot be sent to a harvested e-mail address.
■ A message cannot contain a false header.
Perhaps the most controversial portion of this law is the fact that it supersedes all other state and local ordinances. To quote from the law itself:
This chapter supersedes any statute, regulation, or rule of a State or political subdivision of a State that expressly regulates the use of electronic mail to send commercial messages, except to the extent that any such statute, reg- ulation, or rule prohibits falsity or deception in any portion of a commer- cial electronic mail message or information attached thereto.
Related Cases On February 16, 2004, Anthony Greco, 18, of Cheektowaga, New York was the first person to be arrested under the CAN-SPAM Act of 2003, a charge to which he pleaded guilty. Mr. Greco allegedly sent more than 1.5 million messages promoting mortgage refinancing and adult pornography to MySpace users in October and November 200417. The final disposition of his case is unknown.
On September 27, 2004, Nicholas Tombros pleaded guilty to charges and became the first person to be convicted under the CAN-SPAM Act of 200318. Note that
CAN-SPAM Act of 2003 105
Anthony Greco was the first person arrested, but Mr. Tombros was the first convicted. Mr. Tombros was sentenced in July 2007 to three years of probation, six months of house arrest, and a fine $10,000.
The Actual Law SECTION 3. DEFINITIONS.
In this Act:
(1) AFFIRMATIVE CONSENT. The term “affirmative consent,” when used with respect to a commercial electronic mail message, means that -
(A) the recipient expressly consented to receive the message, either in response to a clear and conspicuous request for such consent or at the recipient’s own in- itiative; and
(B) if the message is from a party other than the party to which the recipient communicated such consent, the recipient was given clear and conspicuous no- tice at the time the consent was communicated that the recipient’s electronic mail address could be transferred to such other party for the purpose of initiating commercial electronic mail messages.
(2) Commercial electronic mail message -
(A) IN GENERAL. The term “commercial electronic mail message” means any electronic mail message the primary purpose of which is the commercial adver- tisement or promotion of a commercial product or service (including content on an Internet Web site operated for a commercial purpose).
(B) TRANSACTIONAL OR RELATIONSHIP MESSAGES. The term “commer- cial electronic mail message” does not include a transactional or relationship message.
(C) REGULATIONS REGARDING PRIMARY PURPOSE. Not later than 12 months after the date of the enactment of this Act, the Commission shall issue regulations pursuant to section 13 defining the relevant criteria to facilitate the determination of the primary purpose of an electronic mail message.
(D) REFERENCE TO COMPANY OR WEB SITE. The inclusion of a reference to a commercial entity or a link to the Web site of a commercial entity in an elec- tronic mail message does not, by itself, cause such message to be treated as a commercial electronic mail message for purposes of this Act if the contents or
Chapter 3 ■ United States Computer Laws Part I106
circumstances of the message indicate a primary purpose other than commercial advertisement or promotion of a commercial product or service.
(3) COMMISSION. The term “Commission” means the Federal Trade Commission.
(4) DOMAIN NAME. The term “domain name” means any alphanumeric des- ignation which is registered with or assigned by any domain name registrar, domain name registry, or other domain name registration authority as part of an electronic address on the Internet.
(5) ELECTRONIC MAIL ADDRESS. The term “electronic mail address” means a destination, commonly expressed as a string of characters, consisting of a unique user name or mailbox (commonly referred to as the “local part”) and a reference to an Internet domain (commonly referred to as the “domain part”), whether or not displayed, to which an electronic mail message can be sent or delivered.
(6) ELECTRONIC MAIL MESSAGE. The term “electronic mail message” means a message sent to a unique electronic mail address.
(7) FTC ACT. The term “FTC Act” means the Federal Trade Commission Act (15 U.S.C. 41 et seq.).
(8) HEADER INFORMATION. The term “header information” means the source, destination, and routing information attached to an electronic mail message, including the originating domain name and originating electronic mail address, and any other information that appears in the line identifying, or pur- porting to identify, a person initiating the message.
(9) INITIATE. The term “initiate,” when used with respect to a commercial electronic mail message, means to originate or transmit such message or to procure the origination or transmission of such message, but shall not include actions that constitute routine conveyance of such message. For purposes of this paragraph, more than one person may be considered to have initiated a message.
(10) INTERNET. The term “Internet” has the meaning given that term in the Internet Tax Freedom Act (47 U.S.C. 151 nt).
(11) INTERNET ACCESS SERVICE. The term “Internet access service” has the meaning given that term in section 231(e)(4) of the Communications Act of 1934 (47 U.S.C. 231(e)(4)).
CAN-SPAM Act of 2003 107
(12) PROCURE. The term “procure,” when used with respect to the initiation of a commercial electronic mail message, means intentionally to pay or provide other consideration to, or induce, another person to initiate such a message on one’s behalf.
(13) PROTECTED COMPUTER. The term “protected computer” has the meaning given that term in section 1030(e)(2)(B) of title 18, United States Code.
(14) RECIPIENT. The term “recipient,” when used with respect to a commercial electronic mail message, means an authorized user of the electronic mail address to which the message was sent or delivered. If a recipient of a commercial elec- tronic mail message has one or more electronic mail addresses in addition to the address to which the message was sent or delivered, the recipient shall be treated as a separate recipient with respect to each such address. If an electronic mail address is reassigned to a new user, the new user shall not be treated as a recipient of any commercial electronic mail message sent or delivered to that address be- fore it was reassigned.
(15) ROUTINE CONVEYANCE. The term “routine conveyance” means the transmission, routing, relaying, handling, or storing, through an automatic technical process, of an electronic mail message for which another person has identified the recipients or provided the recipient addresses.
(16) SENDER -
(A) IN GENERAL. Except as provided in subparagraph (B), the term “sender,” when used with respect to a commercial electronic mail message, means a person who initiates such a message and whose product, service, or Internet Web site is advertised or promoted by the message.
(B) SEPARATE LINES OF BUSINESS OR DIVISIONS. If an entity operates through separate lines of business or divisions and holds itself out to the re- cipient throughout the message as that particular line of business or division rather than as the entity of which such line of business or division is a part, then the line of business or the division shall be treated as the sender of such message for purposes of this Act.
(17) Transactional or relationship message -
(A) IN GENERAL. The term “transactional or relationship message” means an electronic mail message the primary purpose of which is -
Chapter 3 ■ United States Computer Laws Part I108
(i) to facilitate, complete, or confirm a commercial transaction that the recipient has previously agreed to enter into with the sender;
(ii) to provide warranty information, product recall information, or safety or security information with respect to a commercial product or service used or purchased by the recipient;
(iii) to provide -
(I) notification concerning a change in the terms or features of;
(II) notification of a change in the recipient’s standing or status with respect to; or
(III) at regular periodic intervals, account balance information or other type of account statement with respect to a subscription, membership, account, loan, or comparable ongoing commercial relationship involving the ongoing purchase or use by the recipient of products or services offered by the sender;
(iv) to provide information directly related to an employment relationship or related benefit plan in which the recipient is currently involved, participating, or enrolled; or
(v) to deliver goods or services, including product updates or upgrades, that the recipient is entitled to receive under the terms of a transaction that the recipient has previously agreed to enter into with the sender.
(B) MODIFICATION OF DEFINITION. The Commission by regulation pur- suant to section 13 may modify the definition in subparagraph (A) to expand or contract the categories of messages that are treated as transactional or relation- ship messages for purposes of this Act to the extent that such modification is necessary to accommodate changes in electronic mail technology or practices and accomplish the purposes of this Act.
SECTION 4. PROHIBITION AGAINST PREDATORY AND ABUSIVE COM- MERCIAL E-MAIL.
(a) OFFENSE -
(1) IN GENERAL. Chapter 47 of title 18, United States Code, is amended by adding at the end the following new section:
Sec. 1037. Fraud and related activity in connection with electronic mail
CAN-SPAM Act of 2003 109
(a) IN GENERAL. Whoever, in or affecting interstate or foreign commerce, knowingly -
(1) accesses a protected computer without authorization, and intentionally in- itiates the transmission of multiple commercial electronic mail messages from or through such computer,
(2) uses a protected computer to relay or retransmit multiple commercial elec- tronic mail messages, with the intent to deceive or mislead recipients, or any Internet access service, as to the origin of such messages,
(3) materially falsifies header information in multiple commercial electronic mail messages and intentionally initiates the transmission of such messages,
(4) registers, using information that materially falsifies the identity of the actual registrant, for five or more electronic mail accounts or online user accounts or two or more domain names, and intentionally initiates the transmission of multiple commercial electronic mail messages from any combination of such accounts or domain names, or
(5) falsely represents oneself to be the registrant or the legitimate successor in interest to the registrant of five or more Internet Protocol addresses, and in- tentionally initiates the transmission of multiple commercial electronic mail messages from such addresses, or conspires to do so, shall be punished as pro- vided in subsection (b).
(b) PENALTIES. The punishment for an offense under subsection (a) is -
(1) a fine under this title, imprisonment for not more than five years, or both, if -
(A) the offense is committed in furtherance of any felony under the laws of the United States or of any State; or
(B) the defendant has previously been convicted under this section or section 1030, or under the law of any State for conduct involving the transmission of multiple commercial electronic mail messages or unauthorized access to a computer system;
(2) a fine under this title, imprisonment for not more than three years, or both, if -
(A) the offense is an offense under subsection (a)(1);
(B) the offense is an offense under subsection (a)(4) and involved 20 or more falsified electronic mail or online user account registrations, or 10 or more fal- sified domain name registrations;
Chapter 3 ■ United States Computer Laws Part I110
(C) the volume of electronic mail messages transmitted in furtherance of the offense exceeded 2,500 during any 24-hour period, 25,000 during any 30-day period, or 250,000 during any one-year period;
(D) the offense caused loss to one or more persons aggregating $5,000 or more in value during any one-year period;
(E) as a result of the offense any individual committing the offense obtained anything of value aggregating $5,000 or more during any one-year period; or
(F) the offense was undertaken by the defendant in concert with three or more other persons with respect to whom the defendant occupied a position of orga- nizer or leader; and
(3) a fine under this title or imprisonment for not more than one year, or both, in any other case.
(c) FORFEITURE -
(1) IN GENERAL. The court, in imposing sentence on a person who is convicted of an offense under this section, shall order that the defendant forfeit to the United States -
(A) any property, real or personal, constituting or traceable to gross proceeds obtained from such offense; and
(B) any equipment, software, or other technology used or intended to be used to commit or to facilitate the commission of such offense.
(2) PROCEDURES. The procedures set forth in section 413 of the Controlled Substances Act (21 U.S.C. 853), other than subsection (d) of that section, and in Rule 32.2 of the Federal Rules of Criminal Procedure, shall apply to all stages of a criminal forfeiture proceeding under this section.
(d) DEFINITIONS. In this section:
(1) LOSS. The term “loss” has the meaning given that term in section 1030(e) of this title.
(2) MATERIALLY. For purposes of paragraphs (3) and (4) of subsection (a), header information or registration information is materially falsified if it is al- tered or concealed in a manner that would impair the ability of a recipient of the message, an Internet access service processing the message on behalf of a re- cipient, a person alleging a violation of this section, or a law enforcement agency
CAN-SPAM Act of 2003 111
to identify, locate, or respond to a person who initiated the electronic mail message or to investigate the alleged violation.
(3) MULTIPLE. The term “multiple” means more than 100 electronic mail messages during a 24-hour period, more than 1,000 electronic mail messages during a 30-day period, or more than 10,000 electronic mail messages during a one-year period.
(4) OTHER TERMS. Any other term has the meaning given that term by section 3 of the CAN-SPAM Act of 2003.
(2) CONFORMING AMENDMENT. The chapter analysis for chapter 47 of title 18, United States Code, is amended by adding at the end the following:
Sec. 1037. Fraud and related activity in connection with electronic mail.
(b) UNITED STATES SENTENCING COMMISSION -
(1) DIRECTIVE. Pursuant to its authority under section 994(p) of title 28, United States Code, and in accordance with this section, the United States Sen- tencing Commission shall review and, as appropriate, amend the sentencing guidelines and policy statements to provide appropriate penalties for violations of section 1037 of title 18, United States Code, as added by this section, and other offenses that may be facilitated by the sending of large quantities of unsolicited electronic mail.
(2) REQUIREMENTS. In carrying out this subsection, the Sentencing Com- mission shall consider providing sentencing enhancements for -
(A) those convicted under section 1037 of title 18, United States Code, who -
(i) obtained electronic mail addresses through improper means, including -
(I) harvesting electronic mail addresses of the users of a Web site, proprietary service, or other online public forum operated by another person, without the authorization of such person; and
(II) randomly generating electronic mail addresses by computer; or
(ii) knew that the commercial electronic mail messages involved in the offense contained or advertised an Internet domain for which the registrant of the do- main had provided false registration information; and
Chapter 3 ■ United States Computer Laws Part I112
(B) those convicted of other offenses, including offenses involving fraud, identity theft, obscenity, child pornography, and the sexual exploitation of children, if such offenses involved the sending of large quantities of electronic mail.
(c) SENSE OF CONGRESS. It is the sense of Congress that -
(1) Spam has become the method of choice for those who distribute porno- graphy, perpetrate fraudulent schemes, and introduce viruses, worms, and Tro- jan horses into personal and business computer systems; and
(2) the Department of Justice should use all existing law enforcement tools to investigate and prosecute those who send bulk commercial e-mail to facilitate the commission of Federal crimes, including the tools contained in chapters 47 and 63 of title 18, United States Code (relating to fraud and false statements); chapter 71 of title 18, United States Code (relating to obscenity); chapter 110 of title 18, United States Code (relating to the sexual exploitation of children); and chapter 95 of title 18, United States Code (relating to racketeering), as appropriate.
SECTION 5. OTHER PROTECTIONS FOR USERS OF COMMERCIAL ELEC- TRONIC MAIL.
(a) REQUIREMENTS FOR TRANSMISSION OF MESSAGES -
(1) PROHIBITION OF FALSE OR MISLEADING TRANSMISSION IN- FORMATION. It is unlawful for any person to initiate the transmission, to a protected computer, of a commercial electronic mail message, or a transactional or relationship message, that contains, or is accompanied by, header information that is materially false or materially misleading. For purposes of this paragraph -
(A) header information that is technically accurate but includes an originating electronic mail address, domain name, or Internet Protocol address the access to which for purposes of initiating the message was obtained by means of false or fraudulent pretenses or representations shall be considered materially misleading;
(B) a “from” line (the line identifying or purporting to identify a person initiat- ing the message) that accurately identifies any person who initiated the message shall not be considered materially false or materially misleading; and
(C) header information shall be considered materially misleading if it fails to identify accurately a protected computer used to initiate the message because the
CAN-SPAM Act of 2003 113
person initiating the message knowingly uses another protected computer to relay or retransmit the message for purposes of disguising its origin.
(2) PROHIBITION OF DECEPTIVE SUBJECT HEADINGS. It is unlawful for any person to initiate the transmission to a protected computer of a commercial electronic mail message if such person has actual knowledge, or knowledge fairly implied on the basis of objective circumstances, that a subject heading of the message would be likely to mislead a recipient, acting reasonably under the cir- cumstances, about a material fact regarding the contents or subject matter of the message (consistent with the criteria used in enforcement of section 5 of the Federal Trade Commission Act (15 U.S.C. 45)).
(3) Inclusion of return address or comparable mechanism in commercial elec- tronic mail -
(A) IN GENERAL. It is unlawful for any person to initiate the transmission to a protected computer of a commercial electronic mail message that does not contain a functioning return electronic mail address or other Internet-based mechanism, clearly and conspicuously displayed, that -
(i) a recipient may use to submit, in a manner specified in the message, a reply electronic mail message or other form of Internet-based communica- tion requesting not to receive future commercial electronic mail messages from that sender at the electronic mail address where the message was re- ceived; and
(ii) remains capable of receiving such messages or communications for no less than 30 days after the transmission of the original message.
(B) MORE DETAILED OPTIONS POSSIBLE. The person initiating a commer- cial electronic mail message may comply with subparagraph (A)(i) by providing the recipient a list or menu from which the recipient may choose the specific types of commercial electronic mail messages the recipient wants to receive or does not want to receive from the sender, if the list or menu includes an option under which the recipient may choose not to receive any commercial electronic mail messages from the sender.
(C) TEMPORARY INABILITY TO RECEIVE MESSAGES OR PROCESS RE- QUESTS. A return electronic mail address or other mechanism does not fail to satisfy the requirements of subparagraph (A) if it is unexpectedly and tempora- rily unable to receive messages or process requests due to a technical problem
Chapter 3 ■ United States Computer Laws Part I114
beyond the control of the sender if the problem is corrected within a reasonable time period.
(4) PROHIBITION OF TRANSMISSION OF COMMERCIAL ELECTRONIC MAIL AFTER OBJECTION -
(A) IN GENERAL. If a recipient makes a request using a mechanism provided pursuant to paragraph (3) not to receive some or any commercial electronic mail messages from such sender, then it is unlawful -
(i) for the sender to initiate the transmission to the recipient, more than 10 business days after the receipt of such request, of a commercial electronic mail message that falls within the scope of the request;
(ii) for any person acting on behalf of the sender to initiate the transmission to the recipient, more than 10 business days after the receipt of such request, of a commercial electronic mail message with actual knowledge, or knowledge fairly implied on the basis of objective circumstances, that such message falls within the scope of the request;
(iii) for any person acting on behalf of the sender to assist in initiating the transmission to the recipient, through the provision or selection of addresses to which the message will be sent, of a commercial electronic mail message with actual knowledge, or knowledge fairly implied on the basis of objective circum- stances, that such message would violate clause (i) or (ii); or
(iv) for the sender, or any other person who knows that the recipient has made such a request, to sell, lease, exchange, or otherwise transfer or release the elec- tronic mail address of the recipient (including through any transaction or other transfer involving mailing lists bearing the electronic mail address of the re- cipient) for any purpose other than compliance with this Act or other provision of law.
(B) SUBSEQUENT AFFIRMATIVE CONSENT. A prohibition in subparagraph (A) does not apply if there is affirmative consent by the recipient subsequent to the request under subparagraph (A).
(5) INCLUSION OF IDENTIFIER, OPT-OUT, AND PHYSICAL ADDRESS IN COMMERCIAL ELECTRONIC MAIL. (A) It is unlawful for any person to in- itiate the transmission of any commercial electronic mail message to a protected computer unless the message provides -
CAN-SPAM Act of 2003 115
(i) clear and conspicuous identification that the message is an advertisement or solicitation;
(ii) clear and conspicuous notice of the opportunity under paragraph (3) to de- cline to receive further commercial electronic mail messages from the sen- der; and
(iii) a valid physical postal address of the sender.
(B) Subparagraph (A)(i) does not apply to the transmission of a commercial electronic mail message if the recipient has given prior affirmative consent to receipt of the message.
(6) MATERIALLY. For purposes of paragraph (1), the term “materially,” when used with respect to false or misleading header information, includes the alteration or concealment of header information in a manner that would impair the ability of an Internet access service processing the message on be- half of a recipient, a person alleging a violation of this section, or a law en- forcement agency to identify, locate, or respond to a person who initiated the electronic mail message or to investigate the alleged violation, or the ability of a recipient of the message to respond to a person who initiated the electronic message.
(b) Aggravated Violations Relating to Commercial Electronic Mail -
(1) Address harvesting and dictionary attacks -
(A) IN GENERAL. It is unlawful for any person to initiate the transmission, to a protected computer, of a commercial electronic mail message that is unlawful under subsection (a), or to assist in the origination of such message through the provision or selection of addresses to which the message will be transmitted, if such person had actual knowledge, or knowledge fairly implied on the basis of objective circumstances, that -
(i) the electronic mail address of the recipient was obtained using an automated means from an Internet Web site or proprietary online service operated by an- other person, and such Web site or online service included, at the time the ad- dress was obtained, a notice stating that the operator of such Web site or online service will not give, sell, or otherwise transfer addresses maintained by such Web site or online service to any other party for the purposes of initiating, or enabling others to initiate, electronic mail messages; or
Chapter 3 ■ United States Computer Laws Part I116
(ii) the electronic mail address of the recipient was obtained using an automated means that generates possible electronic mail addresses by combining names, letters, or numbers into numerous permutations.
(B) DISCLAIMER. Nothing in this paragraph creates an ownership or proprie- tary interest in such electronic mail addresses.
(2) AUTOMATED CREATION OF MULTIPLE ELECTRONIC MAIL AC- COUNTS. It is unlawful for any person to use scripts or other automated means to register for multiple electronic mail accounts or online user accounts from which to transmit to a protected computer, or enable another person to transmit to a protected computer, a commercial electronic mail message that is unlawful under subsection (a).
(3) RELAY OR RETRANSMISSION THROUGH UNAUTHORIZED ACCESS. It is unlawful for any person knowingly to relay or retransmit a commercial elec- tronic mail message that is unlawful under subsection (a) from a protected com- puter or computer network that such person has accessed without authorization.
(c) SUPPLEMENTARY RULEMAKING AUTHORITY. The Commission shall by regulation, pursuant to section 13 -
(1) modify the 10-business-day period under subsection (a)(4)(A) or subsection (a)(4)(B), or both, if the Commission determines that a different period would be more reasonable after taking into account -
(A) the purposes of subsection (a);
(B) the interests of recipients of commercial electronic mail; and
(C) the burdens imposed on senders of lawful commercial electronic mail; and
(2) specify additional activities or practices to which subsection (b) applies if the Commission determines that those activities or practices are contributing sub- stantially to the proliferation of commercial electronic mail messages that are unlawful under subsection (a).
(d) REQUIREMENT TO PLACE WARNING LABELS ON COMMERCIAL ELECTRONIC MAIL CONTAINING SEXUALLY ORIENTED MATERIAL -
(1) IN GENERAL. No person may initiate in or affecting interstate commerce the transmission, to a protected computer, of any commercial electronic mail message that includes sexually oriented material and -
CAN-SPAM Act of 2003 117
(A) fail to include in subject heading for the electronic mail message the marks or notices prescribed by the Commission under this subsection; or
(B) fail to provide that the matter in the message that is initially viewable to the recipient, when the message is opened by any recipient and absent any further actions by the recipient, includes only -
(i) to the extent required or authorized pursuant to paragraph (2), any such marks or notices;
(ii) the information required to be included in the message pursuant to subsec- tion (a)(5); and
(iii) instructions on how to access, or a mechanism to access, the sexually or- iented material.
(2) PRIOR AFFIRMATIVE CONSENT. Paragraph (1) does not apply to the transmission of an electronic mail message if the recipient has given prior affir- mative consent to receipt of the message.
(3) PRESCRIPTION OF MARKS AND NOTICES. Not later than 120 days after the date of the enactment of this Act, the Commission in consultation with the Attor- ney General shall prescribe clearly identifiable marks or notices to be included in or associated with commercial electronic mail that contains sexually oriented material, in order to inform the recipient of that fact and to facilitate filtering of such elec- tronic mail. The Commission shall publish in the Federal Register and provide notice to the public of the marks or notices prescribed under this paragraph.
(4) DEFINITION. In this subsection, the term “sexually oriented material” means any material that depicts sexually explicit conduct (as that term is defined in section 2256 of title 18, United States Code), unless the depiction constitutes a small and insignificant part of the whole, the remainder of which is not primarily devoted to sexual matters.
(5) PENALTY. Whoever knowingly violates paragraph (1) shall be fined under title 18, United States Code, or imprisoned not more than five years, or both.
SECTION 6. BUSINESSES KNOWINGLY PROMOTED BY ELECTRONIC MAIL WITH FALSE OR MISLEADING TRANSMISSION INFORMATION.
(a) IN GENERAL. It is unlawful for a person to promote, or allow the promotion of, that person’s trade or business, or goods, products, property, or services sold, offered for sale, leased or offered for lease, or otherwise made available through
Chapter 3 ■ United States Computer Laws Part I118
that trade or business, in a commercial electronic mail message the transmission of which is in violation of section 5(a)(1) if that person -
(1) knows, or should have known in the ordinary course of that person’s trade or business, that the goods, products, property, or services sold, offered for sale, leased or offered for lease, or otherwise made available through that trade or business were being promoted in such a message;
(2) received or expected to receive an economic benefit from such promo- tion; and
(3) took no reasonable action -
(A) to prevent the transmission; or
(B) to detect the transmission and report it to the Commission.
(b) Limited Enforcement Against Third Parties -
(1) IN GENERAL. Except as provided in paragraph (2), a person (hereinafter referred to as the “third party”) that provides goods, products, property, or ser- vices to another person that violates subsection (a) shall not be held liable for such violation.
(2) EXCEPTION. Liability for a violation of subsection (a) shall be imputed to a third party that provides goods, products, property, or services to another per- son that violates subsection (a) if that third party -
(A) owns, or has a greater than 50 percent ownership or economic interest in, the trade or business of the person that violated subsection (a); or
(B)(i) has actual knowledge that goods, products, property, or services are pro- moted in a commercial electronic mail message the transmission of which is in violation of section 5(a)(1); and
(ii) receives, or expects to receive, an economic benefit from such promotion.
(c) EXCLUSIVE ENFORCEMENT BY FTC. Subsections (f) and (g) of section 7 do not apply to violations of this section.
(d) SAVINGS PROVISION. Except as provided in section 7(f)(8), nothing in this section may be construed to limit or prevent any action that may be taken under this Act with respect to any violation of any other section of this Act.
SECTION 7. ENFORCEMENT GENERALLY.
CAN-SPAM Act of 2003 119
(a) VIOLATION IS UNFAIR OR DECEPTIVE ACT OR PRACTICE. Except as provided in subsection (b), this Act shall be enforced by the Commission as if the violation of this Act were an unfair or deceptive act or practice proscribed under section 18(a)(1)(B) of the Federal Trade Commission Act (15 U.S.C. 57a(a)(1)(B)).
(b) ENFORCEMENT BY CERTAIN OTHER AGENCIES. Compliance with this Act shall be enforced -
(1) under section 8 of the Federal Deposit Insurance Act (12 U.S.C. 1818), in the case of -
(A) national banks, and Federal branches and Federal agencies of foreign banks, by the Office of the Comptroller of the Currency;
(B) member banks of the Federal Reserve System (other than national banks), branches and agencies of foreign banks (other than Federal branches, Federal agencies, and insured State branches of foreign banks), commercial lending companies owned or controlled by foreign banks, organizations operating under section 25 or 25A of the Federal Reserve Act (12 U.S.C. 601 and 611), and bank holding companies, by the Board;
(C) banks insured by the Federal Deposit Insurance Corporation (other than members of the Federal Reserve System) and insured State branches of foreign banks, by the Board of Directors of the Federal Deposit Insurance Corpora- tion; and
(D) savings associations the deposits of which are insured by the Federal Deposit Insurance Corporation, by the Director of the Office of Thrift Supervision;
(2) under the Federal Credit Union Act (12 U.S.C. 1751 et seq.) by the Board of the National Credit Union Administration with respect to any Federally insured credit union;
(3) under the Securities Exchange Act of 1934 (15 U.S.C. 78a et seq.) by the Securities and Exchange Commission with respect to any broker or dealer;
(4) under the Investment Company Act of 1940 (15 U.S.C. 80a-1 et seq.) by the Securities and Exchange Commission with respect to investment companies;
(5) under the Investment Advisers Act of 1940 (15 U.S.C. 80b-1 et seq.) by the Securities and Exchange Commission with respect to investment advisers regis- tered under that Act;
Chapter 3 ■ United States Computer Laws Part I120
(6) under State insurance law in the case of any person engaged in providing insurance, by the applicable State insurance authority of the State in which the person is domiciled, subject to section 104 of the Gramm-Bliley-Leach Act (15 U.S.C. 6701), except that in any State in which the State insurance authority elects not to exercise this power, the enforcement authority pursuant to this Act shall be exercised by the Commission in accordance with subsection (a);
(7) under part A of subtitle VII of title 49, United States Code, by the Secretary of Transportation with respect to any air carrier or foreign air carrier subject to that part;
(8) under the Packers and Stockyards Act, 1921 (7 U.S.C. 181 et seq.) (except as provided in section 406 of that Act (7 U.S.C. 226, 227)), by the Secretary of Agriculture with respect to any activities subject to that Act;
(9) under the Farm Credit Act of 1971 (12 U.S.C. 2001 et seq.) by the Farm Credit Administration with respect to any Federal land bank, Federal land bank association, Federal intermediate credit bank, or production credit associa- tion; and
(10) under the Communications Act of 1934 (47 U.S.C. 151 et seq.) by the Fed- eral Communications Commission with respect to any person subject to the provisions of that Act.
(c) EXERCISE OF CERTAIN POWERS. For the purpose of the exercise by any agency referred to in subsection (b) of its powers under any Act referred to in that subsection, a violation of this Act is deemed to be a violation of a Federal Trade Commission trade regulation rule. In addition to its powers under any provision of law specifically referred to in subsection (b), each of the agencies referred to in that subsection may exercise, for the purpose of enforcing com- pliance with any requirement imposed under this Act, any other authority con- ferred on it by law.
(d) ACTIONS BY THE COMMISSION. The Commission shall prevent any person from violating this Act in the same manner, by the same means, and with the same jurisdiction, powers, and duties as though all applicable terms and provisions of the Federal Trade Commission Act (15 U.S.C. 41 et seq.) were incorporated into and made a part of this Act. Any entity that violates any pro- vision of that subtitle is subject to the penalties and entitled to the privileges and immunities provided in the Federal Trade Commission Act in the same manner,
CAN-SPAM Act of 2003 121
by the same means, and with the same jurisdiction, power, and duties as though all applicable terms and provisions of the Federal Trade Commission Act were incorporated into and made a part of that subtitle.
(e) AVAILABILITY OF CEASE-AND-DESIST ORDERS AND INJUNCTIVE RELIEF WITHOUT SHOWING OF KNOWLEDGE. Notwithstanding any other provision of this Act, in any proceeding or action pursuant to subsection (a), (b), (c), or (d) of this section to enforce compliance, through an order to cease and desist or an injunction, with section 5(a)(1)(C), section 5(a)(2), clause (ii), (iii), or (iv) of section 5(a)(4)(A), section 5(b)(1)(A), or section 5(b)(3), neither the Commission nor the Federal Communications Commission shall be required to allege or prove the state of mind required by such section or subparagraph.
(f) Enforcement by States -
(1) CIVIL ACTION. In any case in which the attorney general of a State, or an official or agency of a State, has reason to believe that an interest of the residents of that State has been or is threatened or adversely affected by any person who violates paragraph (1) or (2) of section 5(a), who violates section 5(d), or who engages in a pattern or practice that violates paragraph (3), (4), or (5) of section 5(a), of this Act, the attorney general, official, or agency of the State, as parens patriae, may bring a civil action on behalf of the residents of the State in a district court of the United States of appropriate jurisdiction -
(A) to enjoin further violation of section 5 of this Act by the defendant; or
(B) to obtain damages on behalf of residents of the State, in an amount equal to the greater of -
(i) the actual monetary loss suffered by such residents; or
(ii) the amount determined under paragraph (3).
Identity Theft Enforcement and Restitution Act of 2008 This act was actually an extension of the 1984 Computer Fraud and Abuse Act19. It was written in response to the growing threat of identity theft and the per- ceived inadequacy of existing laws. One of its most important provisions was to allow prosecution of computer fraud offenses for conduct not involving an in- terstate or foreign communication. This meant that purely domestic incidents occurring completely within one state were now prosecutable under federal law.
Chapter 3 ■ United States Computer Laws Part I122
Beyond that important provision, this act expanded the definition of cyber ex- tortion to include threats to damage computer systems or steal data.
Another important aspect of this legislation was that it expanded identity-theft laws to organizations. Prior to this, only natural persons could legally be con- sidered victims of identity theft. Under this act, organizations can also legally be considered victims of identity theft and fraud. This law also made it a criminal offense to conspire to commit computer fraud.
The Actual Law SEC. 2. CRIMINAL RESTITUTION.
Section 3663(b) of title 18, United States Code, is amended -
(1) in paragraph (4), by striking “; and” and inserting a semicolon;
(2) in paragraph (5), by striking the period at the end and inserting “; and”; and
(3) by adding at the end the following:
(6) in the case of an offense under sections 1028(a)(7) or 1028A(a) of this title, pay an amount equal to the value of the time reasonably spent by the victim in an attempt to remediate the intended or actual harm incurred by the victim from the offense.
SEC. 3. PREDICATE OFFENSES FOR AGGRAVATED IDENTITY THEFT AND MISUSE OF IDENTIFYING INFORMATION OF ORGANIZATIONS.
(a) Identity Theft. Section 1028 of title 18, United States Code, is amended -
(1) in subsection (a)(7), by inserting “(including an organization as defined in section 18 of this title)” after “person”; and
(2) in subsection (d)(7), by inserting “or other person” after “specific individual.”
(b) Aggravated Identity Theft. Section 1028A of title 18, United States Code, is amended -
(1) in subsection (a)(1), by inserting “(including an organization as defined in section 18 of this title)” after “person”; and
(2) in subsection (c) -
(A) in the matter preceding paragraph (1), by inserting “, or a conspiracy to commit such a felony violation,” after “any offense that is a felony violation”;
Identity Theft Enforcement and Restitution Act of 2008 123
(B) by redesignating -
(i) paragraph (11) as paragraph (14);
(ii) paragraphs (8) through (10) as paragraphs (10) through (12), respec- tively; and
(iii) paragraphs (1) through (7) as paragraphs (2) through (8), respectively;
(C) by inserting prior to paragraph (2), as so redesignated, the following:
(1) section 513 (relating to making, uttering, or possessing counterfeited securities);
(D) by inserting after paragraph (8), as so redesignated, the following:
(9) section 1708 (relating to mail theft);
(E) in paragraph (12), as so redesignated, by striking “; or” and inserting a semicolon; and
(F) by inserting after paragraph (12), as so redesignated, the following:
(13) section 7201, 7206, or 7207 of title 26 (relating to tax fraud); or.
SEC. 4. ENSURING JURISDICTION OVER THE THEFT OF SENSITIVE IDENTITY INFORMATION.
Section 1030(a)(2)(C) of title 18, United States Code, is amended by striking “if the conduct involved an interstate or foreign communication.”
SEC. 5. MALICIOUS SPYWARE, HACKING AND KEYLOGGERS.
(a) In General. Section 1030 of title 18, United States Code, is amended -
(1) in subsection (a)(5) -
(A) by striking subparagraph (B); and
(B) in subparagraph (A) -
(i) by striking “(A)(i) knowingly” and inserting “(A) knowingly”;
(ii) by redesignating clauses (ii) and (iii) as subparagraphs (B) and (C), respec- tively; and
(iii) in subparagraph (C), as so redesignated -
(I) by inserting “and loss” after “damage”; and
Chapter 3 ■ United States Computer Laws Part I124
(II) by striking “; and” and inserting a period;
(2) in subsection (c) -
(A) in paragraph (2)(A), by striking “(a)(5)(A)(iii),”;
(B) in paragraph (3)(B), by striking “(a)(5)(A)(iii),”;
(C) by amending paragraph (4) to read as follows:
(4)(A) except as provided in subparagraphs (E) and (F), a fine under this title, imprisonment for not more than five years, or both, in the case of -
(i) an offense under subsection (a)(5)(B), which does not occur after a convic- tion for another offense under this section, if the offense caused (or, in the case of an attempted offense, would, if completed, have caused) -
(I) loss to one or more persons during any one-year period (and, for purposes of an investigation, prosecution, or other proceeding brought by the United States only, loss resulting from a related course of conduct affecting one or more other protected computers) aggregating at least $5,000 in value;
(II) the modification or impairment, or potential modification or impairment, of the medical examination, diagnosis, treatment, or care of one or more individuals;
(III) physical injury to any person;
(IV ) a threat to public health or safety;
(V ) damage affecting a computer used by or for an entity of the United States Government in furtherance of the administration of justice, national defense, or national security; or
(VI) damage affecting 10 or more protected computers during any one-year period; or
(ii) an attempt to commit an offense punishable under this subparagraph;
(B) except as provided in subparagraphs (E) and (F), a fine under this title, imprisonment for not more than 10 years, or both, in the case of -
(i) an offense under subsection (a)(5)(A), which does not occur after a convic- tion for another offense under this section, if the offense caused (or, in the case of an attempted offense, would, if completed, have caused) a harm provided in subclauses (I) through (VI) of subparagraph (A)(i); or
Identity Theft Enforcement and Restitution Act of 2008 125
(ii) an attempt to commit an offense punishable under this subparagraph;
(C) except as provided in subparagraphs (E) and (F), a fine under this title, imprisonment for not more than 20 years, or both, in the case of -
(i) an offense or an attempt to commit an offense under subparagraphs (A) or (B) of subsection (a)(5) that occurs after a conviction for another offense under this section; or
(ii) an attempt to commit an offense punishable under this subparagraph;
(D) a fine under this title, imprisonment for not more than 10 years, or both, in the case of -
(i) an offense or an attempt to commit an offense under subsection (a)(5)(C) that occurs after a conviction for another offense under this section; or
(ii) an attempt to commit an offense punishable under this subparagraph;
(E) if the offender attempts to cause or knowingly or recklessly causes serious bodily injury from conduct in violation of subsection (a)(5)(A), a fine under this title, imprisonment for not more than 20 years, or both;
(F) if the offender attempts to cause or knowingly or recklessly causes death from conduct in violation of subsection (a)(5)(A), a fine under this title, imprison- ment for any term of years or for life, or both; or
(G) a fine under this title, imprisonment for not more than one year, or both, for -
(i) any other offense under subsection (a)(5); or
(ii) an attempt to commit an offense punishable under this subparagraph; and
(D) by striking paragraph (5); and
(3) in subsection (g) -
(A) in the second sentence, by striking “in clauses (i), (ii), (iii), (iv), or (v) of subsection (a)(5)(B)” and inserting “in subclauses (I), (II), (III), (IV ), or (V ) of subsection (c)(4)(A)(i)”; and
(B) in the third sentence, by striking “subsection (a)(5)(B)(i)” and inserting “subsection (c)(4)(A)(i)(I ).”
(b) Conforming Changes. Section 2332b(g)(5)(B)(i) of title 18, United States Code, is amended by striking “1030(a)(5)(A)(i) resulting in damage as defined
Chapter 3 ■ United States Computer Laws Part I126
in 1030(a)(5)(B)(ii) through (v)” and inserting “1030(a)(5)(A) resulting in da- mage as defined in 1030(c)(4)(A)(i)(II ) through (VI).”
SEC. 6. CYBER-EXTORTION.
Section 1030(a)(7) of title 18, United States Code, is amended to read as follows:
(7) with intent to extort from any person any money or other thing of value, transmits in interstate or foreign commerce any communication containing any -
(A) threat to cause damage to a protected computer;
(B) threat to obtain information from a protected computer without author- ization or in excess of authorization or to impair the confidentiality of information obtained from a protected computer without authorization or by exceeding authorized access; or
(C) demand or request for money or other thing of value in relation to damage to a protected computer, where such damage was caused to facilitate the extortion.
SEC. 7. CONSPIRACY TO COMMIT CYBER-CRIMES.
Section 1030(b) of title 18, United States Code, is amended by inserting “con- spires to commit or” after “Whoever.”
SEC. 8. USE OF FULL INTERSTATE AND FOREIGN COMMERCE POWER FOR CRIMINAL PENALTIES.
Section 1030(e)(2)(B) of title 18, United States Code, is amended by inserting “or affecting” after “which is used in.”
Conclusion Since 1984, the United States federal government has enacted several laws in an effort to fight computer-based crimes. Most recently, issues of identity theft have become a target of legislation. It is critical that the person interested in computer-crime investigation be familiar with these federal laws. While not all crimes will be investigated and prosecuted under federal jurisdiction, many will. And in many cases, state laws have been modeled after one or more of these federal statutes. That means that a fundamental understanding of the key pieces of federal legislation will provide the framework for understanding computer crime laws, even at the state level. In Chapter 4, “United States Computer Laws Part II,” we will examine those state laws.
Conclusion 127
Endnotes 1 U.S. Department of Justice. Computer Fraud and Abuse Act. http://www.
usdoj.gov/criminal/cybercrime/ccmanual/01ccma.html 2 Answers.com. Computer Fraud and Abuse Act. http://www.answers.com/
topic/computer-fraud-and-abuse-act 3 Answers.com. The Morris Worm. http://www.answers.com/topic/morris-
computer-worm 4 FindLaw.com http://caselaw.lp.findlaw.com/data2/circs/9th/0215742p.pdf 5 Computer Professionals for Social Responsibility. Electronic Communica-
tions Privacy Act of 1986. http://cpsr.org/issues/privacy/ecpa86/ 6 The Catholic University of America. Electronic Communications Privacy Act
of 1986 (ECPA). http://counsel.cua.edu/FEDLAW/Ecpa.htm 7 Federal Communications Commission. The Communications Decency Act.
http://www.fcc.gov/Reports/tcom1996.txt 8 The Center for Democracy and Technology. The Communications Decency
Act. http://www.cdt.org/speech/cda/ 9 Cornell Law School. RENO, ATTORNEY GENERAL OF THE UNITED
STATES, et al. v. AMERICAN CIVIL LIBERTIES UNION et al. http://www. law.cornell.edu/supct/html/96-511.ZS.html
10 California Courts. Zango v. Kaspersky Labs. http://www.ca9.uscourts.gov/ datastore/opinions/2009/06/25/07-35800.pdf
11 United States Copyright Office. No Electronic Theft Act of 1997. http://www. copyright.gov/docs/2265_stat.html
12 Kent State Law School. The United States v. David LaMacchia. http://www. kentlaw.edu/faculty/rstaudt/classes/oldclasses/internetlaw/casebook/us_v_ lamacchia.html
13 The United States Copyright Office. The Digital Millennium Copyright Act. http://www.copyright.gov/legislation/dmca.pdf
14 Law.com. “DMCA: A Safe Harbor for Video Sharing?” http://www.law.com/ jsp/legaltechnology/pubArticleLT.jsp?id=1202425323100
Chapter 3 ■ United States Computer Laws Part I128
15 Federal Communications Commission. Children’s Internet Protection Act. http://www.fcc.gov/cgb/consumerfacts/cipa.html
16 Federal Trade Commission. The CAN-SPAM Act: Requirements for Com- mercial E-mailers. http://www.ftc.gov/bcp/edu/pubs/business/ecommerce/ bus61.shtm
17 The U.K. Register. “NY Teen Charged Over IM Spam Attack.” http://www. theregister.co.uk/2005/02/22/spim_arrest/print.html
18 Federal Bureau of Investigation. The Case of the Not-So-Friendly Neighbor- hood Spammer. http://www.fbi.gov/page2/nov04/warspammer111004.htm
19 Open Congress. H.R. 6060. http://www.opencongress.org/bill/110-h6060/show
Endnotes 129