The U.S. Attorney for the Southern District of Texas issued a news release on April 13 announcing an FBI operation to copy and remove malicious web shells from hundreds of vulnerable computersrunning on-premises versions of Microsoft Exchange Server software" The announcement coincided with the partial unsealing of a search warrant.
The legal authority the FBI used for this operation was Rule 41 of the Federal Rules of Criminal Procedure, a rule detailing the requirements and process for issuing search warrants.
Yet its clear from the unsealed search warrant that the primary purpose of the FBIs operation here was to remove malicious code surreptitiously; an admirable goal, but a slippery slope when it comes to the legal basis upon which executed.
The Fourth Amendment guarantees a persons right to be secure in theirhouses, papers, and effects, against unreasonable searches and seizures, and requires that in order for a search to occur in these private spaces, the government must secure a search warrant, issued based upon probable causeparticularly describing the place to be searched, and the persons or things to be seized. Rule 41 basically provides the road map for adhering to these Fourth Amendment requirements, through issuance of that probable cause warrant.
Putting aside the question as to how the government establishes probable cause when the search warrant doesnt provide identifying information about the victims whose servers are to be accessed nor the places to be searched, the point is that Rule 41s purpose is to further investigative evidence gathering, not to disrupt crime nor delete code (which ironically, is evidence in itself).
Its true that Rule 41 was amended in 2016 to allow remote searches and seizures (Section (b)(2)(6)), but the premise of this amendment was to aid investigations that span across more than five federal districtsnot to clean and secure victim computers.
This time the government removed rogue nation-state code; something most agree is dangerous. But what if the next time its Saudi Arabia objecting to their portrayal in a movie? Lets call this Sony Pictures Part 2, after North Koreas infamous 2014 attack on Sony Pictures, because its movie The Interview portrayed Kim Jong Un in a negative light?
What if this time, the FBI decides that Saudi Arabias concerns warrant hacking into private networks to delete all copies of the offending movie, under the premise of stopping a national security threat, a move arguably violative of the 1st Amendment?
Having been a member of both the law enforcement and intelligence communities, Ive seen first hand the motivation that drives people to serve, and the dedication they bring. And while the FBIs heart was in the right place, heart alone doesnt suffice.
In this case, the FBI is knowingly causing the transmission of a program, information, code, or command to intentionally damagedamage having been defined to include deleting information protected computers (in this case, the victims servers), without the authorization of the victims whose systems are being accessed.
In any other context, this would be criminal under Section 1030(a)(5)(A) of the Computer Fraud and Abuse Act (CFAA), which ironically, is one of the very statutes the FBI alleges was violated by the Chinese nation-state group known as Hafnium, at the heart of the threat to Microsoft Exchange Servers. But two wrongs dont make a right. Not even in 2021.
From a practical perspective, if the motivation was to search computers for evidence, in virtually any other case there would be a point where the additional evidence to be gained would be duplicative, and the marginal return too low, to warrant searching additional computers. And that point would be long before searching over 100 victims servers.
Notably, Section 1030(f) of the CFAA states that this section does not prohibit any lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency... But not prohibiting an action is different from lawfully authoriz[ing] one. And with no court having interpreted application of 1030(f), we return to the FBIs need for a route to secure court-authorization, which brings us back to Rule 41.
Interestingly, the FBI used Rule 41 in 2017 when it neutered a virulent botnet called Kelihos. But in that case, the operation involved rerouting victim computers, as opposed to gaining access and clean[ing] them. This newest operation is therefore the next step down the slippery slope that law professors, activists, and defense attorneys love to argue when challenging governmental action.
Yet with the damage done in just the past few months by Solar Winds and the Hafnium hacks alone, we clearly need a fresh approach. And the FBIs solution here is just that. But its a solution without a clear legal basis.
So, whether it means amending the CFAA or passing a new law, one thing is clear: Contorting a long-standing federal procedural rule in a way for which 22 Senators raised concerns back in 2016, concerns precisely about using Rule 41 to clean computerssurely cannot be the right answer.
This column does not necessarily reflect the opinion of The Bureau of National Affairs, Inc. or its owners.
Write for Us: Author Guidelines
Joel Schwarz is director at MBL Technologies and serves as the firms privacy and data protection lead. He is an adjunct professor at Albany Law School and previously served as the civil liberties and privacy officer for the National Counterterrorism Center, and was a cybercrime prosecutor for the Justice Department and the New York Attorney Generals Office.
See the rest here:
The FBI's New Malware Eradication Service Is on Thin Legal Ice - Bloomberg Law
- Why Congress Must Reform FISA Section 702and How It Can - brennancenter.org - April 12th, 2024 [April 12th, 2024]
- CIA wants more power to spy on Americans - Washington Times - April 12th, 2024 [April 12th, 2024]
- Keyboard search warrants and the Fourth Amendment | Brookings - Brookings Institution - February 22nd, 2024 [February 22nd, 2024]
- Just Published: "Terms of Service and Fourth Amendment Rights" - Reason - February 22nd, 2024 [February 22nd, 2024]
- Can Texas police set up DWI checkpoints in Dallas-Fort Worth? Here's what to know - Yahoo News Canada - February 16th, 2024 [February 16th, 2024]
- The FBI's Lawless Raid on U.S. Private Vaults Shows Why the Founders Created the Fourth Amendment | Jon Miltimore - Foundation for Economic Education - February 16th, 2024 [February 16th, 2024]
- HCSO to release body cam footage to plaintiff alleging Fourth Amendment violation - Smoky Mountain News - December 19th, 2023 [December 19th, 2023]
- Section 702 surveillance doesn't belong in the NDAA - Defense One - December 16th, 2023 [December 16th, 2023]
- Valkyrie's Fourth Amendment for the Launch of a Bitcoin ETF - Crypto Times - December 16th, 2023 [December 16th, 2023]
- Digital justice: Supreme Court increasingly confronts law and the internet - Washington Times - December 14th, 2023 [December 14th, 2023]
- Trump and Section 3 of the Fourteenth Amendment: An Exploration ... - JURIST - October 13th, 2023 [October 13th, 2023]
- Expert Q&A with David Aaron on FISA Section 702 Reauthorization ... - Just Security - October 13th, 2023 [October 13th, 2023]
- A Constitution the Government Evades - Tenth Amendment Center - October 13th, 2023 [October 13th, 2023]
- First and Fourth Amendment Claims Over Arrest at Protest of Police ... - Reason - September 25th, 2023 [September 25th, 2023]
- Law enforcement violation of the fourth amendment - Daily Kos - September 25th, 2023 [September 25th, 2023]
- D.C. Appeals Court weighs whether phone seizures from 2020 ... - Washington Times - September 25th, 2023 [September 25th, 2023]
- Opinion: Why you shouldn't turn on your phone in church Palo Alto ... - The Daily Post - September 25th, 2023 [September 25th, 2023]
- Court attorneys group hosts CLE seminar with esteemed Justice ... - Brooklyn Daily Eagle - September 25th, 2023 [September 25th, 2023]
- Former Dona Ana County Deputy Sheriff Charged with Federal Civil ... - Department of Justice - September 25th, 2023 [September 25th, 2023]
- Editorial: Renters rights ruling | Opinion - nwestiowa.com - September 25th, 2023 [September 25th, 2023]
- U.S. Attorney's Statement Regarding Proposed Changes to Crime ... - Department of Justice - September 25th, 2023 [September 25th, 2023]
- New Jersey provides a road map for fighting racially biased traffic ... - Slate - September 25th, 2023 [September 25th, 2023]
- Animal rights advocates sue after facing ongoing censorship and ... - Foundation for Individual Rights in Education - September 25th, 2023 [September 25th, 2023]
- Gerald Jako Pleads Guilty to Two Counts of Murder in Ohio County - Wheeling Intelligencer - September 25th, 2023 [September 25th, 2023]
- Supreme Court of Appeals Visits Campus The Parthenon - MU The Parthenon - September 25th, 2023 [September 25th, 2023]
- Securities and Exchange Board of India (Listing Obligations and ... - Tax Management India. Com - September 25th, 2023 [September 25th, 2023]
- Legal Strategies For A Strong Defense Against Bribery Accusations - American Judicature Society - September 25th, 2023 [September 25th, 2023]
- Police get new images of area break-in suspect - Southwest Virginia Today - September 15th, 2023 [September 15th, 2023]
- Napolitano: Is the CIA in your underwear? | News, Sports, Jobs - Standard-Examiner - September 15th, 2023 [September 15th, 2023]
- Bulletin: Maryland Juvenile Services Head Says Violence Among ... - The Trace - September 15th, 2023 [September 15th, 2023]
- Tased horseman's excessive force claims clear bar Rhode Island ... - Rhode Island Lawyers Weekly - September 15th, 2023 [September 15th, 2023]
- The absurdity of fact-checkers | Columnists | leader-call.com - leader-call.com - September 15th, 2023 [September 15th, 2023]
- Facial Recognition Technology and False Arrests: Should Black ... - Capital B - September 15th, 2023 [September 15th, 2023]
- Letter to the editor - Southeast Iowa Union - September 15th, 2023 [September 15th, 2023]
- Petition hopes to stop US government agencies from using ... - Cointelegraph - September 15th, 2023 [September 15th, 2023]
- Passing on the legacy of 9/11 to the next generation The ... - The Duquesne Duke - September 15th, 2023 [September 15th, 2023]
- Congress Should Reauthorize a Key Intelligence Tool - Foreign Policy Research Institute - September 5th, 2023 [September 5th, 2023]
- Kansas City police made arrests based on rescinded warrants ... - Kansas Reflector - September 5th, 2023 [September 5th, 2023]
- Tased horsemans excessive force claims clear bar - Virginia Lawyers Weekly - September 5th, 2023 [September 5th, 2023]
- Ball is in AL's court - newagebd.net - September 5th, 2023 [September 5th, 2023]
- Lawsuit against police chief just the latest shoe to drop in Marion ... - Kansas Reflector - September 5th, 2023 [September 5th, 2023]
- In the wake of Idalia, residents of one Florida town are turning to ... - Poynter - September 5th, 2023 [September 5th, 2023]
- NYPD using drones to monitor NYC backyard Labor Day parties, spurring privacy concerns - NBC New York - September 5th, 2023 [September 5th, 2023]
- City of Grand Rapids dismissed, lawsuit against Christopher Schurr ... - FOX 17 West Michigan News - September 5th, 2023 [September 5th, 2023]
- OSHA's Proposed Rule Would Allow Union Walkthroughs of All ... - Fisher Phillips - September 5th, 2023 [September 5th, 2023]
- Letters From Readers, Aug. 31, 2023 | Opinion | avpress.com - Antelope Valley Press - September 5th, 2023 [September 5th, 2023]
- Where are the Noah's Park animals? - The Pike County Courier - September 5th, 2023 [September 5th, 2023]
- His hands were up: Attorney for football game shooting victim says civil rights violated - Yahoo News - September 5th, 2023 [September 5th, 2023]
- NYC voters explain why theyre voting for RFK Jr. over Biden: Going ... - 1330 WFIN - September 5th, 2023 [September 5th, 2023]
- Houston Food Not Bombs in Court over Feeding the Unhoused - The Texas Observer - September 5th, 2023 [September 5th, 2023]
- Search and seizure Equal protection Discriminatory policing - Massachusetts Lawyers Weekly - May 18th, 2023 [May 18th, 2023]
- The Timing of Computer Search Warrants When It Takes the ... - Reason - May 18th, 2023 [May 18th, 2023]
- Councilmembers Inquired About Pretext Stops By Police One Year ... - Pasadena Now - May 18th, 2023 [May 18th, 2023]
- BARINGS BDC, INC. : Entry into a Material Definitive Agreement, Creation of a Direct Financial Obligation or an Obligation under an Off-Balance Sheet... - May 18th, 2023 [May 18th, 2023]
- Alabama appeals court reverses murder conviction of Ala. officer ... - Police News - May 18th, 2023 [May 18th, 2023]
- Oakland narrows town manager search to five | West Orange Times ... - West Orange Times & SouthWest Orange Observer - May 18th, 2023 [May 18th, 2023]
- The Durham Report Is Right About the Need for More FBI Oversight - Reason - May 18th, 2023 [May 18th, 2023]
- Collective knowledge doctrine applies to a traffic stop - Police News - May 18th, 2023 [May 18th, 2023]
- Interpretation: The Fourth Amendment | Constitution Center - March 31st, 2023 [March 31st, 2023]
- Public Schools :: Fourth Amendment -- Search and Seizure :: US ... - January 2nd, 2023 [January 2nd, 2023]
- BSE : Securities and Exchange Board of India (Issue of Capital and Disclosure Requirements) (Fourth Amendment) Regulations, 2022 - Marketscreener.com - November 27th, 2022 [November 27th, 2022]
- Trump legal counsel vows 'Fourth Amendment based' challenge to Mar-a ... - October 21st, 2022 [October 21st, 2022]
- Get to Know the EFA: Digital Fourth - EFF - October 13th, 2022 [October 13th, 2022]
- Arguments heard in body in trunk case | News, Sports, Jobs - Minot Daily News - October 13th, 2022 [October 13th, 2022]
- Ormond Beach Planning Board to meet Thursday - Ormond Beach Observer - October 13th, 2022 [October 13th, 2022]
- Limiting the Power of Police in Schools - The Regulatory Review - October 13th, 2022 [October 13th, 2022]
- Letter to the Editor: What Republicans Believe - Door County Pulse - October 13th, 2022 [October 13th, 2022]
- Trump wants other presidents investigated - KRLD - October 13th, 2022 [October 13th, 2022]
- Trump Rally Speech Shows He's 'Guilty and Scared': Former Prosecutor - Newsweek - October 13th, 2022 [October 13th, 2022]
- Court Strips Immunity From Cop Who Shot A Dog Within Seconds Of Arriving On The Scene Of A Non-Crime - Techdirt - October 6th, 2022 [October 6th, 2022]
- Claiming to have 4.3 trillion readers, the Onion supports parodist and its writers' paychecks in SCOTUS brief - ABA Journal - October 6th, 2022 [October 6th, 2022]
- INHIBRX, INC. : Entry into a Material Definitive Agreement, Creation of a Direct Financial Obligation or an Obligation under an Off-Balance Sheet... - October 6th, 2022 [October 6th, 2022]
- PennLive goes to court for records related to U.S. Rep. Scott Perrys cell phone - PennLive - October 6th, 2022 [October 6th, 2022]
- Rusty Hardin & Associates Strengthens Litigation Team with Addition of Attorney Aisha Dennis - PR Newswire - October 6th, 2022 [October 6th, 2022]
- Vancouver City Council asked to OK $725000 deal with family of man killed by police - The Columbian - October 6th, 2022 [October 6th, 2022]
- Govt plans to auction 22 mineral blocks in 3 states within next two months - Business Standard - October 6th, 2022 [October 6th, 2022]
- Fort Worth officers sued after being accused of violating rights - WFAA.com - September 27th, 2022 [September 27th, 2022]
- LSU professors, students weigh in on constitutionality of room scans for online exams - The Reveille, LSU's student newspaper - September 27th, 2022 [September 27th, 2022]
- Solution for ideological division: Revising the Constitution? - The Christian Science Monitor - September 27th, 2022 [September 27th, 2022]
- Lawsuit says teen was thrown in solitary confinement and abused inside Maine's youth prisons - observer-me.com - September 27th, 2022 [September 27th, 2022]