Tuesday, April 7, 2015

State Trooper Disciplined For Taking Photo With Person With 'Well-Known Criminal Background'

Tired of hearing about just the bad cops? Here's one with a good cop, surrounded by worse cops, and the amazing amount of pettiness the latter group can display.

Texas State Trooper Billy Spears was working an approved security detail at the recent South by Southwest conference when he was approached by one of the performing artists and his publicist. The artist asked for a photo with the trooper, who obliged. The photo was taken by the publicist and later posted to Instagram. Here's the photo.

Trooper Spears is on the left.


In most other realities, this would have been the end of the story -- one Billy Spears would be able to tell for years. Instead, it's turned into something else. It's still a story that Spears will be able to tell for years, but there won't be many happy memories attached to it.

Much of what came next has been compiled by Spears' attorney, Ty Clevenger, who submitted this to Techdirt. Instead of nothing happening, a whole bunch of petty crap went down, starting with the response from his "superiors."
[H]ere’s an excerpt of the “deficiencies indicating need for counseling” in Billy’s official record: “While working a secondary employment job, Trooper Spears took a photo with a public figure who has a well-known criminal background including numerous drug charges. The public figure posted the photo on social media and it reflects poorly on the Agency.”
The "counseling" doesn't mean a psychiatric evaluation but it does mean the addition of disciplinary documentation that could negatively affect Spears' future employment or advancement opportunities. The Texas Dept. of Safety -- of which the State Troopers are a division -- has so far refused to comment on this action, something that appears to be vindictive rather than deserved.

First, there's the ridiculousness of demanding troopers not pose with anyone who has a "criminal background." Many people do. Far too many, given the law enforcement's willingness to criminalize all sorts of behavior under vague charges like "obstruction," "interference" and "resisting arrest." No small percentage of a population possess a "criminal background." As Clevenger points out, this sort of expectation is not only moronic, but it's completely nonexistent.
And of course DPS has no policy requiring a criminal background check on everyone who requests a picture with a uniformed trooper. In fact, DPS has no policy forbidding a photograph with someone who has a criminal conviction.
The other problem with the DPS's disciplinary action is that Spears didn't post the photo. Snoop Dogg did.

Despite Spears having violated no existing policies, his supervisors went out of their way -- way out of their way -- to assure he was punished for this non-misdeed. This is from Clevenger's letter to the director of the Texas Dept. of Public Safety.
At approximately 9 p.m., Trooper Spears was informed by Sgt. Michael Sparks that Lt. Jimmy Jackson would be driving from Tyler to Gilmer to serve him with a copy of the counseling form. Sgt. Sparks also told Trooper Spears that DPS is now requiring the presence of two superior officers for any incident involving him. I doubt there are any other troopers who must be served by at least two superior officers, and I must wonder why Trooper Spears was singled out for special treatment. I must also ask what is so special about Trooper Spears that a lieutenant would drive 80 miles round trip to serve him at 9:24 p.m. in the evening.
As Clevenger sees it, this is retaliation for Spears' willingness to cross the blue line.
Last year, Trooper Spears filed a complaint and requested a criminal investigation of Sgt. Marcus Stokke of the Texas Alcoholic Beverage Commission. The complaint arose from a May 10, 2014 off-duty incident at Lake Fork wherein Sgt. Stoke detained Trooper Spears, with no apparent probable cause, because he thought Trooper Spears had been disrespectful to him at a public event.

The detention appears to have been a straightforward violation of Section 39.03 of the Texas Penal Code, but neither DPS nor TABC investigated the complaint against Sgt. Stokke. Instead, Trooper Spears's superiors filed a disciplinary complaint against him, apparently because he “rocked the boat” by requesting an investigation of an officer from another agency.
The suspension was ultimately lifted, in large part because Sgt. Stokke was unable to keep his story straight during his testimony, which was also directly refuted by a number of eyewitnesses, including other troopers and game wardens.

What should have been nothing but a cool story is now an all-too-familiar story with bad cops as the antagonists. Someone who refuses to play within the confines of a broken system must be dealt with, and a pure BS disciplinary action predicated on policies that don't exist illustrates perfectly why most cops just shut up and ignore the bad behavior of their colleagues.

Clevenger also notes another detail that's a bit chilling on its own -- if it's what it appears to be.
Billy was informed by his sergeant that DPS monitors social media for photographs of DPS personnel. The photo contains no reference to Billy or DPS, and even Billy did not know that it had been posted to Instagram, so this begs the question of whether DPS is trolling social media with its facial recognition software.
This detail came directly from those involved in the disciplinary action against Trooper Spears.
According to Sgt. Sparks, the disciplinary action was initiated by Asst. Director David Baker after Trooper Spears's photograph was detected during routine scanning of social media.
This is a legitimate concern. If the DPS is only monitoring known social media accounts of its employees for anything questionable, that would be one thing. (And still a misuse of its power.) But the only tie to this photo was Trooper Spears' presence, something not noted anywhere in the posting, which originated from an account about as far removed from any DPS employee as possible.

Clevenger notes the DPS has already put biometric data to use in its system, comparing millions of stored drivers license photos to those stored in criminal record databases. This would be in addition to its quiet rollout of a demand for a complete set of prints in exchange for a drivers license. If it is using its database in conjunction with "social media monitoring," it has far overstepped its bounds. It may be that certain vindictive parties performed this "scan" without authorization, which would limit the abuse to person or persons performing this search, but that still wouldn't explain why or how the DPS is able to use biometric data to scan social media postings. Clevenger is demanding answers from the DPS, but it's hardly likely he'll receive them.

That's the puzzling part. The other part -- the vindictive display of power -- isn't. It's so routine it's almost banal.



Permalink | Comments | Email This Story







Barrett Brown Loses Email Access For A Year After Using Email To Complain About Prison

Last week, whistleblower Chelsea Manning was able to start tweeting from prison, while at nearly the same time reporter Barrett Brown lost his email access for an entire year for daring to email a journalist about bad prison conditions. If you don't recall, Barrett Brown is the reporter who was recently sentenced to more than five years in jail for reporting on the hacking actions of Anonymous. Bizarrely, the length of the sentence hinged on Brown's sharing a link in a chat room, even though the Justice Department dropped that particular charge. We also found it ridiculous that during the course of his trial, Brown was ordered by the court not to talk to journalists.

It appears that, once again, that was a part of the problem here. The judicial and correctional systems apparently really don't like it when you talk to journalists:

An hour or so after having used the system to contact a journalist about potential BOP [Bureau of Prisons] wrongdoing, Barrett Brown’s access to the TRULINCS prisoner e-mail system was restricted, for a full year until April 2016, without explanation.

This is contrary to the BOP’s own policy on several points, as noted in their 2009 documentation — the administration is only allowed to remove access to TRULINCS for thirty days pending an investigation of any potential misuse, and the inmate is supposed to be informed in writing of the reason for that.

But despite all of that, prison officials don't seem to care. They made it clear they just wanted to shut up Brown:
Barrett spoke to a supervisor this morning who told him that he lost his e-mail access because he was “using it for the wrong thing”. This refers to his contacts with the press. A review of his e-mail activity had been made, Barrett was also told by this person that he “wasn’t supposed to have” e-mail, when there’s been no such order or determination that we’re aware of.
Apparently, Brown had been talking to Glenn Greenwald about writing some articles for The Intercept, and that's what set off the Bureau of Prisons into a full-fledged lockdown on Brown's email account. Brown himself was later able to provide more details, suggesting a completely arbitrary process by a prison official:
Failing to find Mr. Coleman, I met that afternoon with Unit Manger Ivory, who checked my files but could find no reason why my access should have suddenly been suspended and also advised me to meet with Mr. Coleman. At some point that day, my attempts to log in started to prompt a different message stating: “This account is on suspension until 4/1/2016 11:59:59 pm (from portal 16)”. At the next lunch period on Thursday, April 2nd, I was unable to locate Mr. Coleman, but laid out my problem to the associate warden who told me to return in five minutes, when Mr. Coleman would be present.

I did so, and when I asked another group of prison officials if they knew where I could find Mr. Coleman, another individual came up to me and said that he was the person I was looking for. He pulled me aside and told me that he was the one who had cut off my email, as I wasn’t supposed to have access to it in the first place due to my charges. I noted that I had three charges and asked which one precluded me from using the email service. He told me to list my charges and I did so. He then added that he had done a review of my email correspondence and found that I had “been using it for the wrong thing.” I replied that I had simply been using it to communicate with the press. He confirmed that “that was the wrong thing.” I asked him his name, which he gave as “Moore”.
Yes, when you go to prison, you have given up a lot of your rights and freedoms. But this seems like a purely arbitrary decision to punish Brown for criticizing the prison system. And, it appears to be backfiring, only driving that much more attention to the issue.

Permalink | Comments | Email This Story







Saturday, April 4, 2015

Security Audit Of TrueCrypt Doesn't Find Any Backdoors -- But What Will Happen To TrueCrypt?

Over the past few years we've followed the saga of TrueCrypt. The popular and widely used full disk encryption system got some attention soon after the initial Snowden leaks when people started realizing that no one really knew who was behind TrueCrypt, and that the software had not been fully audited. Cryptographer Matthew Green decided to lead an effort to audit TrueCrypt. A year ago, the team released the first phase, finding a few small vulnerabilities, but no backdoors and nothing too serious. This week the full audit was completed and again finds no evidence of any backdoors planted in the code. Matthew Green's blog post on the report provides the key details, which notes a few small issues that should be fixed, but nothing too serious:
The TL;DR is that based on this audit, Truecrypt appears to be a relatively well-designed piece of crypto software. The NCC audit found no evidence of deliberate backdoors, or any severe design flaws that will make the software insecure in most instances.

That doesn't mean Truecrypt is perfect. The auditors did find a few glitches and some incautious programming -- leading to a couple of issues that could, in the right circumstances, cause Truecrypt to give less assurance than we'd like it to.

For example: the most significant issue in the Truecrypt report is a finding related to the Windows version of Truecrypt's random number generator (RNG), which is responsible for generating the keys that encrypt Truecrypt volumes. This is an important piece of code, since a predictable RNG can spell disaster for the security of everything else in the system.
However, as Green notes, the problem with the way its implemented in TrueCrypt would only be a problem in "extremely" rare circumstances that wouldn't impact most users. But it's still something that could be fixed.

But that's where the problem lies. As you may recall, in the midst of all of this, the still anonymous developers behind TrueCrypt suddenly announced that it wasn't secure and that all development had ceased. There have been some efforts to fork and rescue TrueCrypt, but that's come with some skepticism as people feared what might be hidden in the code (and also some concerns about the TrueCrypt license.

Hopefully this new audit puts at least some of those concerns to rest (though it's always good to be paranoid when building security software) and people do really put an effort developing an updated version of TrueCrypt. For what it's worth, I've seen a bunch of articles claiming the audit shows that TrueCrypt is safe. That's not quite true. It's just saying they didn't find anything -- which should be very re-assuring, but you can never say with 100% certainty that the code is safe. Either way, what's needed now is more development moving forward.

Permalink | Comments | Email This Story







Friday, April 3, 2015

Australian Politicians Create An Exemption From Data Retention Laws For Themselves -- And A Huge Security Hole

Now that the completely disproportionate data retention law has been rushed through the Australian Parliament, politicians are suddenly realizing that their metadata will be collected too. And so, as was perhaps inevitable, they have asked for an exemption, as reported here by Crikey:

An in-camera meeting of the high-powered Joint Committee on Intelligence and Security last week agreed to task the Department of Defence's signals intelligence arm, the Australian Signals Directorate, and the new Australian Cyber Security Centre with ensuring politicians' metadata is not captured by the government's new data retention regime while they are at work in [the Australian capital] Canberra.
The argument was that:
given Parliament House is supposed to be the centre of Australian democracy, they shouldn't be, you know, tracked while at work there
Well, many people would argue that they shouldn't be tracked either, but obviously politicians are special. It seems that there were two options for achieving this carve-out. One required officials personally identifying and deleting the metadata of politicians, staffers and senior public servants -- a manual process aptly dubbed "handwashing". The other, cheaper, approach -- the one chosen -- was simply to remove metadata from all communications generated within Australia's Parliament House.

Problem solved -- except that some 680,000 visitors enter the building annually, and while they are there, their metadata will not be collected either. Ironically, then, the new exemption for politicians from a scheme allegedly to help the fight against terrorism and crime will turn Parliament House into the perfect location for plotting precisely those things in relative safety.

Follow me @glynmoody on Twitter or identi.ca, and +glynmoody on Google+



Permalink | Comments | Email This Story







What Do You Do When Preserving Evidence Is Labeled 'Possession' And Destroying It Is A Felony?

Have fun with this hypothetical. A shared computer is found to contain child porn. What do you do?

Houston criminal defense lawyer Mark Bennett considered this hypothetical from a defense lawyer's standpoint. At this point, there is (possibly) no investigation already in progress (at least none the client or lawyer are aware of) and there's no way to say definitively who's responsible for the images. What do you tell your client?

It's illegal for him to continue possessing the images. So you can't advise him to do nothing (and keep breaking the law).

The smart thing for him to do would be to destroy the hard drive (if I could, I would recommend swisscheesing it with a drill press).

But tampering with evidence is illegal under both Texas and federal law. Is it a crime to destroy the hard drive? To advise the client to do so?
This isn't entirely a hypothetical situation. Scott Greenfield's blog details a 2007 case involving exactly this sort of situation.
[Connecticut attorney Philip] Russell’s client, the Greenwich Christ Church (not a bad client, I would say), did what any self-respecting church would do when it found child pornography on its church computer: It turned to its lawyer for help. No fed was knocking on the church door. There was no hint of an investigation. There was no reason to believe that anyone would ever know that some sick, disgusting human being using this computer purchased with monies from the tithing of its congregants (I’m making this part up, since I have no idea where the money came from to buy the computer and in Greenwich, they could just as easily live off the interest from the Church’s trust fund), would download photographs that would sicken any normal human being.

So Russell finds himself in the position of having to decide what to do with this computer. The Church no doubt wants its computer back, since it wouldn’t have gotten the computer if it didn’t have any need for it, But the Church does not want this pics on it. Russell, in the meantime, knows of the photos as a result of confidential communications (no argument from any source about whether this was as confidential as it comes) and has to decide what to do about it. He can’t keep the kiddie porn pics, for then he would be violating the law.

So Philip Russell does the only reasonable thing possible. He deletes the horrific photos. BAM, he’s indicted for obstruction, having destroyed evidence.
Back to Bennett, who notes that under Texas law, this is a felony only if the destruction of evidence is done with knowledge of a "pending or in progress" investigation. The problem is that -- in cases involving child porn -- federal law prevails. But not a federal law dealing with child porn possession (which would apply if the offending files remained intact) but rather a law crafted to deal with companies' financial impropriety: Sarbanes-Oxley. This law says that destruction of evidence -- with or without knowledge of a pending/ongoing investigation -- is a federal crime.

Damned if you do. Damned if you don't. The only stipulation is that an investigation is "foreseeable." And child porn on a hard drive pretty much makes an investigation "foreseeable." Turn it in to the cops, and you can guarantee an investigation will start immediately. Depending on how the files were obtained, it's entirely possible that the IP address is already on investigators' radar. Throwing the computer into the nearest dump or off a bridge just to rid yourself of someone else's wrongdoing makes you a felon.

Now, whether the child porn is the client's own, or something he/she discovered (purchased a second-hand computer/shared one with with other household residents), the client needs help. But what help can any lawyer provide? There's no answer that allows for the avoidance of felony charges.

This tainted hard drive is, in and of itself, lawbreaking. So is the deletion of the files. So is simply removing it from your possession. A lawyer really has only one course of action, thanks to Sarbanes-Oxley.
You could, of course, instruct your client on certain aspects of the law: possession of child pornography is a crime; tampering with evidence is a crime; without the hard drive the government is likely to have a hard time proving that you tampered with evidence or that you possessed child pornography; if the government gets its hands on the hard drive they won't have a hard time proving that you possessed child pornography, which will certainly land you in prison; don't talk to anyone about the contents of the hard drive.
There will be those that argue that anything involving child porn shouldn't have an easy out, even if it's a law supposedly targeting financial wrongdoing that's running around locking down all of the escape routes. But there are situations in which an innocent person could find themselves in this position and have no option but to choose the least personally destructive outcome.

And because the theoretical involves child porn (instead of less universally-reviled subject matter), there will always be other "easy" solutions presented.
Some will respond to this dilemma with the facile, “so don’t download porn and you won’t have this problem.” Aside from the fact that this isn’t just a porn problem, people are allowed to enjoy porn. Just not kiddie porn. Plus, people make mistakes, sometimes inadvertent, without any evil intent. Plus, people do stuff with evil intent, which they thereupon regret and seek to undo. Is it not societally beneficial for people who make a mistake to foster regret and the chance to make things right?
There is no "out." The government makes every investigation "foreseeable." The inadvertent discovery of illegal images doesn't take away this possibility. A lawyer can't (or shouldn't) encourage someone to break the law, but in cases like this, the only option is to mitigate the damage. The safest bet for anyone -- innocent or not -- is to destroy the evidence. But what sucks is that the innocent face charges for possessing something they never wanted and will often resort to destroying it in hopes of not being branded sexual offenders for the rest of their lives.

And it doesn't have to be child porn. It could be anything illegal. The government isn't here to help, much less not indulge in messenger-shooting. Case in point, the Iowa man who called the cops about a backpack he found containing drug paraphernalia. Just keeping it meant being in possession of illegal items. Throwing it out (which never occurred to the finder) would destroy evidence. And calling the cops did nothing more for him than turn his house into a meth lab in the eyes of the DEA. The police repaid his good deed by listing his house on the National Clandestine Laboratory Register. Being a good citizen meant virtual condemnation of his home because drug paraphernalia had been "found" on the premises.

In light of this, it would appear that the government prefers people destroy evidence of other people's crimes, rather than be upstanding citizens. That route leads to lighter sentences and less horrendous outcomes. Sure, we need laws in place to prevent the destruction of evidence, but more than that, we need to offer better protections for those who voluntarily hand over evidence of criminal activity. But there's nothing there to delineate between preserving evidence prior to contacting authorities and a possession charge. The government plays it safe and treats both equally, just to avoid the possibility of being duped by actual criminals.



Permalink | Comments | Email This Story







Wednesday, April 1, 2015

Georgia Supreme Court: No, Writing Mean Things About Copyright Trolling By Linda Ellis Is Not 'Stalking'

A few years ago, we wrote about a terrible Georgia state court ruling against Matt Chan, the operator of Extortion Letter Info (ELI), a website/forum that has tracked copyright trolling for many years. There had been a number of discussions on the site about Linda Ellis, who is somewhat notorious for her trolling effort. Ellis wrote a poem called "The Dash" that gets reposted a lot online. Ellis and her lawyers then send threat letters, emphasizing the possible $150,000 in statutory damages (yet another example of how statutory damages aid in copyright trolling), before suggesting much lower (but still crazy high) dollar amounts to "settle." While some of the discussions on ELI were overly aggressive towards Ellis, it still seemed ridiculous that the court ordered Chan to remove all content relating to Ellis and to block any future mentions of her.

It seemed rather obvious that this was a pretty clear First Amendment violation, but the court felt that it was okay under Georgia's anti-stalking law. Georgia's Supreme Court has now unanimously reversed the lower court decision, saying that posting mean stuff about someone on a public website is not the same as stalking. The court focuses on the fact that the content posted to ELI wasn't sent directly to Ellis, but rather posted publicly in a place where she could (and, in fact, did) see it. It doesn't even get to the First Amendment issues, focusing just on whether or not this is stalking under Georgia's law:
The limited evidence in the record shows that Chan and others posted a lot of commentary to his website about Ellis, but it fails for the most part to show that the commentary was directed specifically to Ellis as opposed to the public. As written, most of the posts appear to speak to the public, not to Ellis in particular, even if they are about Ellis. And there is no evidence that Chan did anything to cause these posts to be delivered to Ellis or otherwise brought to her attention, notwithstanding that he may have reasonably anticipated that Ellis might come across the posts, just as any member of the Internet-using public might. The publication of commentary directed only to the public generally does not amount to “contact,” as that term is used in OCGA § 16-5-90 (a) (1), and most of the posts about Ellis quite clearly cannot form the basis for a finding that Chan contacted Ellis.

To the extent that a few of the posts may come closer to “contact” — including, for instance, the open letter to Ellis, which Chan may actually have intended as a communication to Ellis — their publication still does not amount to stalking. Even assuming for the sake of argument that Chan “contacted” Ellis by the publication of any posts, the evidence fails to show that such contact was “without [her] consent.” OCGA § 16-5-90 (a) (1). This is not a case in which Chan sent a message to Ellis by electronic mail, linked commentary to her social media account, or posted commentary on her website. To the contrary, the commentary about which Ellis complains was posted on Chan’s website, and Ellis learned of that commentary — that is, it arguably was communicated to her — only as a result of her choice to discover the content of the website. The evidence shows that Ellis visited the website herself — it appears, in fact, that she registered herself as an authorized commentator on the website — and that she had others visit the website and report back to her about the commentary published there. Generally speaking, our stalking law forbids speech only to the extent that it is directed to an unwilling listener, and even if Ellis did not like what she heard, she cannot be fairly characterized as an unwilling listener. Ellis failed to prove that Chan “contacted” her without her consent, and the trial court erred when it concluded that Chan had stalked Ellis.
The only mention of the First Amendment comes in a footnote, in response to the part of the paragraph above, where the court notes that Ellis was not an "unwilling listener" as required under the law, noting that even so, if the speech is protected by the First Amendment, the stalking law wouldn't apply:
Even then, if the speech is protected by the First Amendment, it is excluded from the scope of our stalking law. See OCGA § 16-5-92 (“The provisions of Code Sections 16-5-90 and 16-5-91 shall not apply to persons engaged in activities protected by the Constitution of the United States or of this state . . . .”).
But, by determining that the blog posts are not even stalking, the court avoided that question altogether. Either way, another important victory for free speech online, overturning a bad ruling that would have resulted in serious chilling effects for online speech.

Permalink | Comments | Email This Story