Prosecuting Leaks: Weaponizing Computer Fraud Laws After Air Crashes

The Perilous Pursuit of Leaks: How “Computer Trespass” Laws Can Be Abused

Could simply recording a screen with your phone land you with criminal charges? In an era defined by instant information and the constant flow of data, the line between whistleblowing and illegal activity is becoming increasingly blurred. This article explores how vague “computer trespass” laws, similar to the federal Computer Fraud and Abuse Act (CFAA), can be weaponized to punish individuals for leaking information of public interest, ultimately chilling freedom of the press and transparency. The case of a Metropolitan Washington Airports Authority (MWAA) employee accused of leaking footage of a tragic plane crash to CNN highlights the potential for abuse.

The Escalating War on Leaks: Prioritizing Control Over Transparency

Following the tragic collision of an Army helicopter and a passenger plane over the Potomac River, claiming the lives of 67 people, the FAA initiated an investigation into the causes of the accident. However, local Virginia investigators seemed more concerned with identifying and punishing the individual who leaked the CCTV footage of the event to CNN. This raises a crucial question: Is the government’s interest in controlling the dissemination of information, even when it pertains to matters of public concern, outweighing the public’s right to know?

While the government undoubtedly has a vested interest in managing the flow of information related to federal investigations, this interest must be carefully balanced against the principles enshrined in the First Amendment. Suppressing information simply because it’s inconvenient or embarrassing sets a dangerous precedent.

The CFAA and Its State-Level Counterparts: Tools for “Shooting the Messenger”

For years, the federal government relied heavily on the Computer Fraud and Abuse Act (CFAA) to prosecute individuals for a wide range of computer-related activities, often stretching the law’s interpretation beyond its original intent. The CFAA, designed to combat hacking and unauthorized access to computer systems, was frequently used to target individuals who merely interacted with online services in “unexpected ways.” This included journalists and security researchers who reported on data breaches, unsecured servers, or exploitable vulnerabilities. Effectively, the CFAA became a tool for “shooting the messenger.”

Although the CFAA has been somewhat weakened in recent years, the threat hasn’t disappeared. Many states have their own versions of computer crime laws, often as vaguely written and open to interpretation as the original CFAA. These laws can be used to achieve the same chilling effect on whistleblowing and investigative journalism, as highlighted in a report by Nikita Mazurov and Shawn Musgrave for The Intercept.

The Case of Mohamed Mbengue: A “Computer Trespass” Farce?

The case of Mohamed Mbengue, an MWAA dispatch employee, exemplifies this potential for abuse. After the Potomac River plane crash, footage from MWAA security cameras found its way to CNN. An investigation quickly zeroed in on Mbengue, based on CCTV footage from inside the dispatch center showing him using his personal cell phone to record video and take photographs of the screens displaying the crash footage.

MWAA investigator Patrick Silsbee concluded in his report that the video must have been obtained by an employee working at the police dispatch center. The locations of the MWAA security cameras are redacted in the reports provided to The Intercept, ostensibly “to prevent the disclosure of law enforcement and security techniques and procedures not generally known outside the law enforcement community.”

Mbengue was subsequently charged with violating Virginia’s “computer trespass” law. He pleaded “no contest” to the charges. But the question remains: did Mbengue’s actions truly constitute “computer trespass”?

Deconstructing “Computer Trespass”: Stretching the Definition Beyond Recognition

The common understanding of “trespass” involves unauthorized access to a physical location or property where one is not permitted to be. In Mbengue’s case, he was at work, in his designated work area, and had authorized access to the CCTV recordings as part of his job. Recording the screen with his phone and subsequently sharing the footage with CNN, while potentially a violation of MWAA policy, hardly aligns with any reasonable definition of “trespass.”

While violating agency policy might warrant disciplinary action, it should not result in criminal charges that can have devastating, long-term consequences on an individual’s life. This is where discretion becomes paramount. However, law enforcement agencies often prioritize inflicting maximum damage on those they investigate, even if it means stretching the law to its breaking point.

The Broad Interpretation of Virginia’s Law: A Recipe for Abuse

The specific clause of the Virginia law cited in Mbengue’s case criminalizes using a computer to make an “unauthorized copy” of computer data. Prosecutors argued that Mbengue’s smartphone constituted a computer, and his recording of the CCTV footage was an “unauthorized copy.” However, this interpretation requires several significant leaps of logic:

  • Treating CCTV cameras and screens as “computers/computer network”: This ignores the commonly understood utility of these technologies. While a network might connect the cameras and a computer might provide access to the recordings, the act of simply recording the playback on a screen doesn’t automatically transform the entire system into a “computer” for the purposes of the law.
  • Ignoring Authorized Access: Mbengue had every right to access the CCTV footage as part of his job duties. Recording the screen, while perhaps violating policy, doesn’t retroactively make his access “unauthorized.”

This strained interpretation suggests that the investigators were more motivated by retribution than by a genuine pursuit of justice.

A Tale of Two Dispatchers: Discretion Makes All the Difference

Interestingly, a second dispatcher, Jonathan Savoy, was also caught recording CCTV footage, though he didn’t share it with CNN. Savoy faced similar charges initially, but prosecutors later dropped the case. This highlights the arbitrary nature of these prosecutions and the critical role of prosecutorial discretion. The fact that one dispatcher was charged while the other wasn’t, despite engaging in similar behavior, suggests that the decision to prosecute wasn’t based solely on the law, but on other factors, potentially the perceived severity of the “leak.”

Feature Mohamed Mbengue Jonathan Savoy
Action Recorded CCTV footage, shared with CNN Recorded CCTV footage, did not share
Charges Filed Yes Yes (initially, then dropped)
Outcome Pleaded “no contest” Charges dropped

Protecting Whistleblowers and Preserving Transparency

The case of Mohamed Mbengue serves as a stark reminder of the potential for abuse inherent in broadly written computer crime laws. While the government has a legitimate interest in protecting sensitive information, this interest should not be used as a pretext for silencing whistleblowers or punishing individuals who bring matters of public concern to light.

The application of “computer trespass” laws in situations like this raises serious questions about the balance between security and transparency. When laws are stretched to criminalize actions that fall far outside the traditional understanding of “trespass,” it creates a chilling effect on freedom of the press and the public’s right to know. The laws created to help, often hurt.

What do you think? Should laws be re-evaluated to stop the abuse? Comment below!





Sources & Further Reading:
Original article at www.techdirt.com

spot_imgspot_img

Subscribe

Related articles

spot_imgspot_img