Blogs > The Law Blogger

The Law Blogger is a law-related blog that informs and discusses current matters of legal interest to readers of The Oakland Press and to consumers of legal services in the community. We hope readers will  find it entertaining but also informative. The Law Blogger does not, however, impart legal advice, as only attorneys are licensed to provide legal counsel.
For more information email: tflynn@clarkstonlegal.com

Monday, March 7, 2016

Privacy vs National Security: Apple Strikes Back

The San Bernardino shooting has taught us that, if you are a terrorist intent on communicating with your comrades-in-arms, the devices you select for such communication, data transmission and storage will be manufactured by Apple. This is largely because the NSA, FBI, Homeland Security or other law enforcement agencies cannot reach the data contained in the device without it self-destructing.

The battle between privacy -more specifically, encryption- and national security has been playing out at least since Edward Snowden drew attention to the issue with his leaks back in 2013. Apple has drawn a line-in-the-sand on the San Bernardino shooting case, which is puzzling at first considering that the device in question was supplied by the county government and also considering Apple's track record of cooperation in other criminal investigations.

Walter Isaacson's 2011 authorized biography of Apple founder Steve Jobs sets a detailed stage for the privacy vs security debate that the December California terrorist shooting has brought onto center stage within the national security context. By now, it is a matter of technological and intellectual history that Jobs and co-founder Steve Wozniak had fundamental differences on the critical issue of the software architecture to be designed and implemented for their wonderful computing machines.

Jobs favored, and prevailed, on the use of closed-source software for Apple devices, shunning Wozniak's preferred open-source approach; the approach utilized by Microsoft's Bill Gates. Now, as a result of these 1980s macro-planning decisions, Apple products are rarely afflicted with computer viruses like Microsoft products and hardware.

In addition, it turns out that the closed source approach is far superior from a privacy and data integrity standpoint. For example, if someone other than the owner attempts to infiltrate the data -to hack into the data- then the data stored on an Apple device will be destroyed.

This is the problem currently facing the FBI in the California shooting case. They have sought and have been granted injunctive relief from the United States District Court for California's Central District, Eastern Division.

In the introduction to Apple's motion to set aside the injunction, the tech giant's heavy-weight lawyers from Gibson, Dunn & Crutcher state their client's position on the matter:
Apple is committed to data security. Encryption provides Apple with the strongest means available to ensure the safety and privacy of its customers against threats known and unknown. For several years iPhones have featured hardware and software based encryption of their password-protected contents.These protections safeguard the encryption keys contained on the device with a passcode designated by the user during setup. This passcode immediately becomes entangled with the iPhone's Unique ID ["UID"] which is permanently assigned to that one device during the manufacturing process. The iPhone's UID is neither accessible to other parts of the operating system nor known to Apple. These protections are designed to prevent anyone without the passcode from accessing encrypted data on iPhones.
Cyber-attackers intent upon gaining unauthorized access to a device could break a user-created passcode, if given enough chances to guess and the ability to test passwords rapidly by automated means. To prevent such "brute-force" attempts to determine the passcode, iPhones running the iOS 8 or higher include a variety of safeguards. For one, Apple uses a "large iteration count" to slow attempts to access an iPhone, ensuring that it would take years to try all combinations of a six-character alphanumeric passcode. Finally, Apple includes a setting that -if activated- automatically deletes encrypted data after ten consecutive incorrect attempts to enter the passcode. This combination of security features features protects users from attackers or if, for example, the user loses the device.
Apple does not believe the federal government's assurances that it is just this one device; just this one time. Apple knows there will be another time with another one of its devices.

Also, the world's most valuable company is concerned about the precedent this case would set if it is forced by the feds to create software to access a user's private data, even when that user is a murderous terrorist. Apple asserts such an injunction would fundamentally compromise the privacy of its users; an unacceptable scenario for the corporation.

For its part, the USDOJ advanced a traditional and fundamental point: companies -and for that matter, citizens- cannot select which laws it will honor and which it will violate. In addition, they characterize this case as a particularly dangerous one which could lead to more deaths if not aggressively pursued.

A hearing on Apple's motion is currently scheduled for March 22, 2016, in Riverside, CA. Stay tuned for further developments in this important privacy rights case.

Post #526

www.clarkstonlegal.com
info@clarkstonlegal.com





Labels: , , , , , , , , ,

Thursday, January 16, 2014

Privacy and a Tale of Two Courts

The Federal Bench.  Judge Richard J. Leon serves on the bench of the United States District Court in the District of Colombia; Judge William Pauley III serves on the bench of the United States District Court in Manhattan.  These judges have issued opinions in two cases that impugn tactics employed by our National Security Agency that were brought to light last summer by the now-expatriated Edward Snowden.

Judge Pauley's decision gives the NSA a pass to continue gathering evidence despite the effect on our collective or our individual rights to privacy; Judge Leon's decision reigns the NSA in on their tactics.

What the NSA is Doing.  Legal expert and law blogger Johnathan Turley put it bluntly and accurately in his recent post analyzing Judge Pauley's recent privacy decision in ACLU vs Clapper.  He characterizes these cases as challenging the NSA from collecting, "telephony meta-data from almost every phone call or any other electronic communication you'd care name in this country in the seemingly limitless war on terror."

Since Edward Snowden, the former NSA contractor, dropped the bomb on the world last summer that NSA was tracking not only cell phone meta-data, but emails and all other forms of electronic data, it has become common knowledge that anything anyone does on-line or electronically, anywhere in the world, can and is being stored.  And if your electronic fingerprints are being stored, they can be tracked by the NSA.

The SCOTUS Precedent.  Turley has a point; it was not 9/11 that began the erosion of our rights to electronic privacy, it was the 1979 SCOTUS decision in Smith vs Maryland.  In that case, the SCOTUS ruled that individuals do not have a reasonable expectation of privacy in the details  of our telephone calls, [i.e. call points, call destinations, time of calls, etc.] and that law enforcement can obtain this data from third parties like the telephone company.

Judge Pauley's Opinion.  This case is ACLU vs Clapper.  The opinion cites to the Smith vs Maryland precedent to basically grant NSA a pass to continue collecting our meta-data because none of us really can reasonably maintain an expectation of privacy in anything we do electronically, at least in the form and manner of a communication.  So the 4th Amendment lost out in this case; the question is, did we?

Judge Leon's Opinion.  The other case is Klayman vs Obama where Judge Leon took a stand for privacy by enjoining the federal government from further data collection of the two named individuals and their cell phone calls and other electronic transmissions.  Then, he promptly stayed his injunction to provide the feds the opportunity to appeal his ruling.  See, this is what happens in federal court in the District.

Two cases involving government snooping with disparate results.  One or both of these cases will grind onward in the appellate courts as the notion of privacy in our post-modern world continues to evolve.

www.clarkstonlegal.com
info@clarkstonlegal.com




Labels: , ,

Sunday, September 15, 2013

Declassification of Foreign Intelligence Surveillance Court Opinions

By:  Timothy P. Flynn

Well, you had to see this one coming.  Something just does not seem right when a federal court adjudicates in secret, even if done under the provisions of the Patriot Act.

When Edward Snowden released a cashe of classified national security-related information earlier this summer, many in the legal blogosphere began to take note, and the Federal Intelligence Surveillance Court [FISC] was suddenly in the spotlight.

Much of the Snowden-generated furor involved government tracking and storage of email and cell phone transmissions; data, big and raw.  Here is our take on the issue in this post.

Thanks to the ACLU of Washtington, D.C., the FISC is again in the spotlight on a motion, brought pursuant to the Freedom of Information Act, to release certain opinions of the secret court which deal directly with the constitutionality of the court.  Opinions deciding the FISC's own constitutionality; now there is an interesting method of judicial review.

Here is the FISC Opinion, authored by Judge Dennis Saylor, ordering the federal government and the ACLU to submit a list of constitutional-threshold FISC opinions and a proposed declassification process by which the opinions can be submitted to the judge that authored the opinion for the author's judicial consideration as to whether they should be publicized.

Sound complicated?  Well, at least it is some progress toward openness.  The government list of opinions deemed suitable for publication and a proposed declassification procedure are due by October 4th.

The ACLU's filing sought publication of the FISC opinions directly from the stealth court itself, rather than as a component of separate litigation.  As noted in Judge Saylor's opinion, a similar request was lodged in 2011 by the ACLU in federal court in Manhattan which continues to be litigated.

When they are finally made public, these opinions will be very interesting.  We here at the Law Blogger cannot wait to see how the FISC passed muster on itself.

www.clarkstonlegal.com
info@clarkstonlegal.com

Labels: , , , , , ,

Sunday, July 7, 2013

The Foreign Intelligence Surveillance Court

By: Timothy P. Flynn

A secret court; something very offensive to our Democracy.  Even as lawyers, we here at the Law Blogger had never heard of such a stealth tribunal until Edward Snowden blew the whistle on one of its rulings [i.e. the FISA Court's "classified" order to turn over all of Verizon's phone tracing data to the NSA].

Actually, the FISA Court has been around since the 1978 passage of the Foreign Intelligence Surveillance Act.  Following the September 11th terrorist attacks on our country back in 2001, FISA has been repeatedly amended, primarily through the Patriot Act.

Not surprisingly, since 9/11, FISA has expanded steadily along with the powers of the FISA Court.  The Bush Administration based its warrantless wiretapping practice on FISA; the Obama Administration, to the surprise of many of its supporters, has not only continued the program, but expanded the scope of electronic surveillance to apparently everyone in America.

The Edward Snowden case has shined a light on the 11-member FISA Court.  What that light has shown is that the secret court has evolved from providing quick case-by-case rulings on electronic surveillance scenarios, to building a body of "classified" constitutional decisions that are now hefting the weight of judicial precedent; all without a scintilla of public scrutiny.

We here at the Law Blogger would like to know:  who is on this secret court?  What decisions are they making that may affect our right to privacy?  And do we even still have a right to privacy while connected to the internet or connected to a cell phone?

The FISA Court's recent classified decisions have become so constitutionally significant that a recent NYT article compares the secret court to a "parallel Supreme Court".

One example of the shrouded jurisprudence emanating from the FISA Court is the application of the "special needs" exception to the warrant requirement of the 4th Amendment in terrorism cases.  Normally, law enforcement cannot conduct a search or seizure of a person without a warrant based on probable cause.

In 1989, SCOTUS created the "special needs" exception to the 4th Amendment's warrant requirement in the context of public transportation.  SCOTUS ruled that public railway workers could be drug-tested by the government without a warrant on the basis that the minimal privacy intrusion of the worker was superseded by the need for public transportation safety.

Apply this logic to the modern terrorism cases, and any matter that evokes our "national security" opens the door for the FISA Court to invoke the "special needs" exception.  This fast-expanding exception is now poised to swallow the 4th Amendment's warrant requirement whole.

Although we do not get to read the secret court's decisions, from which there is a very limited and rarely used appeal process, we are told -via the NYT- that a sturdy pillar of jurisprudence and precedent has arisen from the FISA Court: the collection of Metadata does not offend the 4th Amendment.

Well, ok, if the Star Chamber says so.  But we here at the Law Blogger thought that ours was an adversarial justice system characterized by thesis, antithesis, and synthesis.

Post Script: October 15, 2013 - The FISA has given the green light in several of its recent cases for the NSA to continue to collect cell phone use data on U.S. Citizens.  We wonder if our emails are also subject to NSA scrutiny...

www.clarkstonlegal.com


Labels: , , , , , , , ,

Monday, June 24, 2013

National Security vs Individual Privacy in the Big Data Era

By:  Timothy P. Flynn

This post is about the rights of a now famous arrest warrant fugitive, and about each of our rights to maintain private electronic data.

The Fourth Amendment to the United States Constitution guarantees rights to all private citizens:
...to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.
This important amendment arose, in part, as a response to abuses of power during the American Revolution associated with the reviled "writ of assistance"; a general search warrant that allowed the King's soldiers to toss your home with or without reason.

Fast forward to the 21st Century, which opened with unprecedented foreign terrorist attacks on our soil, and we see that our "papers and effects" have been digitized.  Most of us now have fairly robust electronic profiles as opposed to actual "papers and effects".

Now, 13-years into the e-Century, and a dozen years after the fateful 9/11 attacks on New York and Washington, the federal government wants, and apparently gets, direct access to the Big Data of our private lives.  This access has been granted in the name of national security and is backed by the Patriot Act, and other powerful national security-based federal laws.

The extradition and federal prosecution of  Edward Snowden will test these opposing concepts of liberty and national security in the digital age.  Like the cases of Julian Assange and Aaron Swartz, Snowden's revelations about the federal government's snooping is becoming a digital clarion call.

Snowden, a former NSA contractor, made some significant disclosures about what the NSA has been doing, to the Guardian newspaper in London earlier in the month.  The feds have been hunting him with an international arrest warrant ever since for violations of the Espionage Act.

Apparently, Mr. Snowden is now on the move, internationally, as in Jason Bourne style.  Only this is real, not fiction.  Once the United States has Mr. Snowden either extradited or rendered back to the US, he will face criminal charges in federal court in Virginia for leaking the NSA's digital secrets to the media.

Since its inception in 1917 up to the current administration, Presidents have only charged 3 individuals with violating the Espionage Act.  President Obama has prosecuted 6 individuals under the Act.

What does this tell us about the balance between our rights to have our data secure from the prying eyes of the government, and the governments duty to protect our shores from invasion?  Can both interests be served simultaneously?

www.clarkstonlegal.com
info@clarkstonlegal.com

Labels: , , , , , , ,