The U.S. Attorney for the Southern District of Texas issued a news release on April 13 announcing an FBI operation to copy and remove malicious web shells from hundreds of vulnerable computersrunning on-premises versions of Microsoft Exchange Server software" The announcement coincided with the partial unsealing of a search warrant.
The legal authority the FBI used for this operation was Rule 41 of the Federal Rules of Criminal Procedure, a rule detailing the requirements and process for issuing search warrants.
Yet its clear from the unsealed search warrant that the primary purpose of the FBIs operation here was to remove malicious code surreptitiously; an admirable goal, but a slippery slope when it comes to the legal basis upon which executed.
The Fourth Amendment guarantees a persons right to be secure in theirhouses, papers, and effects, against unreasonable searches and seizures, and requires that in order for a search to occur in these private spaces, the government must secure a search warrant, issued based upon probable causeparticularly describing the place to be searched, and the persons or things to be seized. Rule 41 basically provides the road map for adhering to these Fourth Amendment requirements, through issuance of that probable cause warrant.
Putting aside the question as to how the government establishes probable cause when the search warrant doesnt provide identifying information about the victims whose servers are to be accessed nor the places to be searched, the point is that Rule 41s purpose is to further investigative evidence gathering, not to disrupt crime nor delete code (which ironically, is evidence in itself).
Its true that Rule 41 was amended in 2016 to allow remote searches and seizures (Section (b)(2)(6)), but the premise of this amendment was to aid investigations that span across more than five federal districtsnot to clean and secure victim computers.
This time the government removed rogue nation-state code; something most agree is dangerous. But what if the next time its Saudi Arabia objecting to their portrayal in a movie? Lets call this Sony Pictures Part 2, after North Koreas infamous 2014 attack on Sony Pictures, because its movie The Interview portrayed Kim Jong Un in a negative light?
What if this time, the FBI decides that Saudi Arabias concerns warrant hacking into private networks to delete all copies of the offending movie, under the premise of stopping a national security threat, a move arguably violative of the 1st Amendment?
Having been a member of both the law enforcement and intelligence communities, Ive seen first hand the motivation that drives people to serve, and the dedication they bring. And while the FBIs heart was in the right place, heart alone doesnt suffice.
In this case, the FBI is knowingly causing the transmission of a program, information, code, or command to intentionally damagedamage having been defined to include deleting information protected computers (in this case, the victims servers), without the authorization of the victims whose systems are being accessed.
In any other context, this would be criminal under Section 1030(a)(5)(A) of the Computer Fraud and Abuse Act (CFAA), which ironically, is one of the very statutes the FBI alleges was violated by the Chinese nation-state group known as Hafnium, at the heart of the threat to Microsoft Exchange Servers. But two wrongs dont make a right. Not even in 2021.
From a practical perspective, if the motivation was to search computers for evidence, in virtually any other case there would be a point where the additional evidence to be gained would be duplicative, and the marginal return too low, to warrant searching additional computers. And that point would be long before searching over 100 victims servers.
Notably, Section 1030(f) of the CFAA states that this section does not prohibit any lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency... But not prohibiting an action is different from lawfully authoriz[ing] one. And with no court having interpreted application of 1030(f), we return to the FBIs need for a route to secure court-authorization, which brings us back to Rule 41.
Interestingly, the FBI used Rule 41 in 2017 when it neutered a virulent botnet called Kelihos. But in that case, the operation involved rerouting victim computers, as opposed to gaining access and clean[ing] them. This newest operation is therefore the next step down the slippery slope that law professors, activists, and defense attorneys love to argue when challenging governmental action.
Yet with the damage done in just the past few months by Solar Winds and the Hafnium hacks alone, we clearly need a fresh approach. And the FBIs solution here is just that. But its a solution without a clear legal basis.
So, whether it means amending the CFAA or passing a new law, one thing is clear: Contorting a long-standing federal procedural rule in a way for which 22 Senators raised concerns back in 2016, concerns precisely about using Rule 41 to clean computerssurely cannot be the right answer.
This column does not necessarily reflect the opinion of The Bureau of National Affairs, Inc. or its owners.
Write for Us: Author Guidelines
Joel Schwarz is director at MBL Technologies and serves as the firms privacy and data protection lead. He is an adjunct professor at Albany Law School and previously served as the civil liberties and privacy officer for the National Counterterrorism Center, and was a cybercrime prosecutor for the Justice Department and the New York Attorney Generals Office.
See the rest here:
The FBI's New Malware Eradication Service Is on Thin Legal Ice - Bloomberg Law
- Protections for e-data clear Senate committee [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Quinn: Supreme Court should clarify Fourth Amendment rights in the digital age [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Fourth amendment | Wex Legal Dictionary / Encyclopedia ... [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Fourth Amendment to the United States Constitution ... [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- The Fourth Amendment is destroyed by the Roberts led Supreme Court. - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Court may let cops search smartphones [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- Supreme Court to hear case on police searches of cellphones [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- Fourth Amendment in the digital age: Supreme Court to decide if police can search cellphones without a warrant [Last Updated On: April 30th, 2014] [Originally Added On: April 30th, 2014]
- What Scalia knows about illegal searches [Last Updated On: April 30th, 2014] [Originally Added On: April 30th, 2014]
- Should police be allowed to search your smartphone - Video [Last Updated On: April 30th, 2014] [Originally Added On: April 30th, 2014]
- Fourth Amendment to the United States Constitution - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Rand Paul Third Party Records Should Get Fourth Amendment Protection O'Reilly Factor 6 11 2013 - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- The Shaky Legal Foundation of NSA Surveillance on Americans [Last Updated On: May 2nd, 2014] [Originally Added On: May 2nd, 2014]
- Pennsylvania Supreme Court rules police don't need warrants to search cars [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Local police: Updated vehicle-search law still requires probable cause [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Liberal Supreme Court Justice Comes To The Defense Of Scalia [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Gerald Celente - Trends In The News - America's Spiritual Death - (1/20/14) - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- Smartphones and the Fourth Amendment - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- Fourth Amendment Searches And Seizures - Video [Last Updated On: May 5th, 2014] [Originally Added On: May 5th, 2014]
- Fourth Amendment Defined & Explained - Law [Last Updated On: May 6th, 2014] [Originally Added On: May 6th, 2014]
- Enforcement Techniques For Violations Of The Fourth Amendment - Video [Last Updated On: May 6th, 2014] [Originally Added On: May 6th, 2014]
- I-Team: Do police seek search warrant friendly judges? [Last Updated On: May 7th, 2014] [Originally Added On: May 7th, 2014]
- Is Big Brother Listening? Applying the Fourth Amendment in an Electronic Age - Video [Last Updated On: May 9th, 2014] [Originally Added On: May 9th, 2014]
- It Costs Less to Care [Last Updated On: May 10th, 2014] [Originally Added On: May 10th, 2014]
- The Fourth Amendment - Video [Last Updated On: May 10th, 2014] [Originally Added On: May 10th, 2014]
- Magistrate waxes poetic while rejecting Gmail search request [Last Updated On: May 11th, 2014] [Originally Added On: May 11th, 2014]
- License reader lawsuit can be heard, appeals court rules [Last Updated On: May 15th, 2014] [Originally Added On: May 15th, 2014]
- Seize the Rojo - Video [Last Updated On: May 16th, 2014] [Originally Added On: May 16th, 2014]
- NSA Spying Has a Disproportionate Effect on Immigrants [Last Updated On: May 17th, 2014] [Originally Added On: May 17th, 2014]
- Motorists sue Aurora, police in 2012 traffic stop after bank robbery [Last Updated On: May 17th, 2014] [Originally Added On: May 17th, 2014]
- Judge Says NSA Phone Surveillance Likely Unconstitutional - Video [Last Updated On: May 21st, 2014] [Originally Added On: May 21st, 2014]
- New York Attorney Heath D. Harte Releases a Statement on Fourth Amendment Rights [Last Updated On: May 22nd, 2014] [Originally Added On: May 22nd, 2014]
- Bangor Area School District teachers vote no to random drug [Last Updated On: May 24th, 2014] [Originally Added On: May 24th, 2014]
- The Fourth Amendment Rights - Video [Last Updated On: May 24th, 2014] [Originally Added On: May 24th, 2014]
- I Don't Care About The Contitution, Take Your Fourth Amendment And Shove It The Hills Hotel - Video [Last Updated On: May 27th, 2014] [Originally Added On: May 27th, 2014]
- Lonestar1776 at Illegal Checkpoint 80 Miles Inside Border - Standing UP & Pushing Back! pt 2/2 - Video [Last Updated On: September 1st, 2014] [Originally Added On: September 1st, 2014]
- Suit charges Daytona Beach's rental inspection program violates civil rights [Last Updated On: September 2nd, 2014] [Originally Added On: September 2nd, 2014]
- 4th Amendment - Laws.com [Last Updated On: September 6th, 2014] [Originally Added On: September 6th, 2014]
- YOU CAN ARREST ME NOW (cops refuse) - Video [Last Updated On: September 6th, 2014] [Originally Added On: September 6th, 2014]
- The Feds Explain How They Seized The Silk Road Servers [Last Updated On: September 8th, 2014] [Originally Added On: September 8th, 2014]
- Defence asks judge in NYC to toss out bulk of evidence in Silk Road case as illegally obtained [Last Updated On: September 9th, 2014] [Originally Added On: September 9th, 2014]
- Volokh Conspiracy: Does obtaining leaked data from a misconfigured website violate the CFAA? [Last Updated On: September 9th, 2014] [Originally Added On: September 9th, 2014]
- Family of a mentally ill woman files lawsuit against San Mateo Co. after deadly shooting [Last Updated On: September 10th, 2014] [Originally Added On: September 10th, 2014]
- Minnesota Supreme Court upholds airport drug case decision [Last Updated On: September 12th, 2014] [Originally Added On: September 12th, 2014]
- Law Talk - Obamacare Rollout; Fourth Amendment, NSA Spying Stop & Frisk DUI Check Points lta041 - Video [Last Updated On: September 12th, 2014] [Originally Added On: September 12th, 2014]
- Volokh Conspiracy: The posse comitatus case and changing views of the exclusionary rule [Last Updated On: September 15th, 2014] [Originally Added On: September 15th, 2014]
- Guest: Why the privacy of a public employees cellphone matters [Last Updated On: September 16th, 2014] [Originally Added On: September 16th, 2014]
- Volokh Conspiracy: Apples dangerous game [Last Updated On: September 19th, 2014] [Originally Added On: September 19th, 2014]
- Judge expounds on privacy rights [Last Updated On: September 20th, 2014] [Originally Added On: September 20th, 2014]
- Great privacy essay: Fourth Amendment Doctrine in the Era of Total Surveillance [Last Updated On: September 20th, 2014] [Originally Added On: September 20th, 2014]
- The Fourth Amendment By Maison Erdman - Video [Last Updated On: September 20th, 2014] [Originally Added On: September 20th, 2014]
- Volokh Conspiracy: When administrative inspections of businesses turn into massive armed police raids [Last Updated On: September 22nd, 2014] [Originally Added On: September 22nd, 2014]
- The chilling loophole that lets police stop, question and search you for no good reason [Last Updated On: September 23rd, 2014] [Originally Added On: September 23rd, 2014]
- E.O. 12333: End-Running the Fourth Amendment | The Dissenter [Last Updated On: September 25th, 2014] [Originally Added On: September 25th, 2014]
- Fourth Amendment: The History Behind "Unreasonable ... [Last Updated On: September 25th, 2014] [Originally Added On: September 25th, 2014]
- Pet Owners Look to Muzzle Police Who Shoot Dogs [Last Updated On: September 27th, 2014] [Originally Added On: September 27th, 2014]
- Volokh Conspiracy: A few thoughts on Heien v. North Carolina [Last Updated On: September 29th, 2014] [Originally Added On: September 29th, 2014]
- Volokh Conspiracy: Third Circuit on the mosaic theory and Smith v. Maryland [Last Updated On: October 1st, 2014] [Originally Added On: October 1st, 2014]
- Volokh Conspiracy: Third Circuit gives narrow reading to exclusionary rule [Last Updated On: October 2nd, 2014] [Originally Added On: October 2nd, 2014]
- Volokh Conspiracy: Supreme Court takes case on duration of traffic stops [Last Updated On: October 2nd, 2014] [Originally Added On: October 2nd, 2014]
- Search & Seizure, Racial Bias: The American Law Journal on the Philadelphia CNN-News Affiliate WFMZ Monday, October 6 ... [Last Updated On: October 4th, 2014] [Originally Added On: October 4th, 2014]
- Argument preview: How many brake lights need to be working on your car? [Last Updated On: October 4th, 2014] [Originally Added On: October 4th, 2014]
- The 'Barney Fife Loophole' to the Fourth Amendment [Last Updated On: October 4th, 2014] [Originally Added On: October 4th, 2014]
- Search & Seizure: A New Fourth Amendment for a New Generation? - Promo - Video [Last Updated On: October 4th, 2014] [Originally Added On: October 4th, 2014]
- Lubbock Liberty Workshop With Arnold Loewy On The Fourth Amendment - Video [Last Updated On: October 5th, 2014] [Originally Added On: October 5th, 2014]
- Ap Government Fourth Amendment Project - Video [Last Updated On: October 5th, 2014] [Originally Added On: October 5th, 2014]
- Volokh Conspiracy: Oral argument in Heien v. North Carolina [Last Updated On: October 6th, 2014] [Originally Added On: October 6th, 2014]
- Feds Hacked Silk Road Without a Warrant? Perfectly Legal, Prosecutors Argue [Last Updated On: October 7th, 2014] [Originally Added On: October 7th, 2014]
- Supreme Court Starts Term with Fourth Amendment Case [Last Updated On: October 7th, 2014] [Originally Added On: October 7th, 2014]
- Feds Say That Even If FBI Hacked The Silk Road, Ulbricht's Rights Weren't Violated [Last Updated On: October 8th, 2014] [Originally Added On: October 8th, 2014]
- Argument analysis: A simple answer to a deceptively simple Fourth Amendment question? [Last Updated On: October 8th, 2014] [Originally Added On: October 8th, 2014]
- Mass Collection of U.S. Phone Records Violates the Fourth Amendment - Video [Last Updated On: October 8th, 2014] [Originally Added On: October 8th, 2014]
- Leggett sides with civil liberties supporters [Last Updated On: October 10th, 2014] [Originally Added On: October 10th, 2014]
- Search & Seizure / Car Stops: A 'New' Fourth Amendment for a New Generation? - Video [Last Updated On: October 10th, 2014] [Originally Added On: October 10th, 2014]
- Broken Lights And The Fourth Amendment National Constitution Center - Video [Last Updated On: October 10th, 2014] [Originally Added On: October 10th, 2014]
- The Fourth Amendment- The Maininator Period 4 - Video [Last Updated On: October 10th, 2014] [Originally Added On: October 10th, 2014]
- Judge nukes Ulbricht's complaint about WARRANTLESS FBI Silk Road server raid [Last Updated On: October 11th, 2014] [Originally Added On: October 11th, 2014]
- Montgomery County will not hold immigrants without probable cause -- Gazette.Net [Last Updated On: October 13th, 2014] [Originally Added On: October 13th, 2014]
- Debate: Does Mass Phone Data Collection Violate The 4th Amendment? [Last Updated On: October 15th, 2014] [Originally Added On: October 15th, 2014]
- Does the mass collection of phone records violate the Fourth Amendment? [Last Updated On: October 18th, 2014] [Originally Added On: October 18th, 2014]