Lecture Notes: Computers, Crime and Privacy 1996

[While I do not intend to follow the same structure in 1997, I will be covering much of the same material]

I. Class Mechanics: Seminar

II. Three topics:

 

III. Privacy and encryption: The need

IV. Encryption: The technology (Detailed information is in the FAQ from rsa.com. Some excerpts are on p. 33 of BBB. The following is my simplified version.

 

V. The Supporting Technology: power, bandwidth, Virtual Reality

 

VI. Implications of strong privacy

8/23/95

 

I. Can strong privacy be stopped, and if so how?

 

I. About encryption:

 

II. Key distribution and management problems.

 

III. Public key as a solution to both problems.

 

III. A Digital Signature serves three functions--identify sender, prove sender, untampered text.

 

IV. As computers get faster, they can encrypt faster, decrypt faster, and break encryption faster.

 

8/30/95

 

I. Non-cryptographic attacks: Consider a simple password cracking problem. You are a hacker who had dialed into a computer and is trying to get privileges on it--which requires giving it a password it recognizes as associated with a legitimate user.

 

II. Why does the government care about cryptography?

 

III. The question of standards:

 

I. Review:

II. On to Clipper

 

9/11/95

 

I. Odds and Ends

 

The proposed section 1201 would provide:

No person shall import, manufacture or distribute any device, product, or component incorporated into a device or product, or offer or perform any service, the primary purpose or effect of which is to avoid, bypass, remove, deactivate, or otherwise circumvent, without the authority of the copyright owner or the law, any process, treatment, mechanism or system which prevents or inhibits the violation of any of the exclusive rights of the copyright owner under section 106.

 

II. How important is wiretapping? Freeh's statement

 

9/13/95

 

I. Non-clipper escrow solutions:

II. Function of Clipper

 

III. Hardware v Software encryption--can we do the equivalent of Clipper in software?

 

IV. Digital Telephony bill

 

V. Cost/benefit calculations:

 

9/18/95

 

I. Readings from Chapter 6 of BBB

 

I. Verisign is a new firm, marketing its product as a way of facilitating the use of digital signatures rather than an encryption approach. Nonetheless, it may be very important for the spread of strong privacy. Information can be found at: http://www.verisign.com/faqs/id_faq.html and, in much briefer form, below.

 

II. How does a digital signature work?

 

II. So far we have assumed the recipient already has the sender's public key. We now drop that assumption. The sender can, of course, send the recipient his public key--but how can he prove that public key XYZ really belongs to person P? Until he does so, he cannot provide a digital signature--and without a digital signature, he cannot prove that the message is really being sent by him.

 

III. What Verisign is doing:

 

IV. Who are they?

 

V. Details:

 

VI. Is a digital signature legally valid? We don't know yet.

 

VII. Verisign can be viewed as a Trojan Horse for Public Key Encryption!

0: Guest Lecturer--Silicon Valley's Computer Cop. Some bits.

I. Review Digisign

 

II. The new hole in Netscape Security?

 

III. Economic espionage problem?

 

IV. DSS--was the trap door intentional?

 

V. Is ITAR constitutional?

 

I. Lund v Commonwealth of Virginia 232 S.E. 2d 745 (Va. 1977); SC of VA

 

II. United States v. Seidlitz 589 F.2d 152 (4th Cir. 1978)

 

III. United States v Jones 553 F. 2d 351 (4th Cir. 1977)

 

IV. The People of New York v. Robert Versaggi

 

I. If someone wants to do a paper on the pretensions of the Attorney General of Minnesota to rule the internet, some interesting questions might be:

 

II. The Hacker Crackdown: The sociology of computer crime

 

III. U.S. v. Robert Riggs (and Craig Neidorf)

 

IV. Unix source code cases. 1990.

 

VI. Review: Issues raised by the criminal cases.

 

VII. Steve Jackson case:

 

VIII. "Sending a Message"

 

IV. Sociology issue: "Those Kids aren't Criminals"

 

V. Odds and Ends:

 

According to Restatement (2d) of Torts sec. 623A,

 

"One who publishes a false statement harmful to the interests of another is subject to liability for pecuniary loss resulting to the other if

 

(a) he intends for publication of the statement to result in harm to interests of the other having a pecuniary value, or either recognizes or should recognize that it is likely to do so, and

 

(b) he knows that the statement is false or acts in reckless disregard of its truth or falsity."

 

 

I: The old nightmare: Computers as the end of privacy.

 

II. Public Fork:

III. Rogan v City of Los Angeles

IV. Private fork: Thompson v San Antonio Retail Merchants Association

V. Fair Credit reporting act.

 

III. Obscenity on-line

 

I. Why it matters:Interactive Services Association: Not just obscenity. defamation, franchise, real estate laws, ...

 

II. Tangibility, means of transmission:

Does law apply only to tangible objects: U.S. v. Carlin only case to interpret. Phone sex case under. USC 1465 "facility or means of interstate commerce."!= "any means of communication?" as judge instructed jury. Congress could have added computer, phone terms to statute, did for child porn, did not here when revised. AG had given the opinion that 1465 did not cover phone transmission. not "by private conveyance" (section the govt chose to rely on)

[prosecution denies tangible, claims Carlin was wrong]

 

III. Who transported it? Transfer initiated by customer. like Buying book and bringing it home. They paid for the call. Civil analog.

 

IV. What is the relevant community?

CA? Local police had seized, looked at, released. Not child porn.