Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Saturday, April 13, 2013

Journalist "Cracker" and CFAA

The hottest issue of the Japanese ICT field is the "cracking" conducted by a journalist of a reputable news service. The journalist was gathering news on the high-profile fake blackmail case which I previously posted. Somehow, the journalist guessed the password of the suspect's web-mail account and browsed the inbox and other folders. As you may recall from my previous post, the Japanese version of the CFAA criminalizes the usage of fraudulently obtained ID/passwords and according to the Ministry of Internal Affairs and Communications, this password guessing was the most frequently used method of unauthorized access in 2008. So, it is likely that the conduct of the journalist is a prima facie CFAA violation. The question is whether the journalist's conduct can somehow be justified.

On this issue, the Supreme Court held that
the freedom of news gathering for the news report deserves sufficient protection in light of the spirit of the (Japanese version of) First Amendment, in In Re Subpoena against RKB Mainich Broadcast Co., 23-11 Keishu 1490 (November 26, 1969). However, that does not mean that anything journalists do would be justified.

I already posted on
one old case where a journalist who had a sexual relationship with a government official to obtain secret information was convicted. Further, in another old case, a journalist received a piece of important evidence from a criminal group and eventually burned it up (allegedly, to avoid being confused as a group member). The prosecutor accused him and he was convicted in People v. Doe, 703 Hanrei-Jiho 121 (Urawa District Court, September 27, 1972). The court stated that it was regretful that the journalist approached the information source without consideration and made intimate connections which resulted in him assisting the criminal group.

Relatively recently, two new cases were held. Although they do not directly deal with typical journalists, they are somewhat relevant. One case is an
environmental protest group case. Group members, who wanted to investigate and report allegedly unlawful whale-hunting stole a piece of whale meat. Although they argued that it was necessary information gathering, the court did not buy the argument. The court held that even an investigation for public interest cannot be justified unless conducted so as not to invade other people's freedom and rights, and convicted them. This was an unreported case of Sendai High Court on July 12, 2011.

Another case is that a journalist approached a doctor who was appointed as an expert on a high-profile criminal case and had some secret documents of the case. The doctor lent her the documents and later she wrote a book using the information. Both the journalist and doctor were arrested but only the doctor was prosecuted and later convicted. Nara District Court stated although more deliberate and careful review was necessary in the case of journalist, as the doctor accused was only an information source, the level of scrutiny is different and was thus denied justification.
People v. Doe, 2048 Hanrei-Jiho 135 (Nara District Court April 15, 2009). The conclusion of denying justification is affirmed by the Supreme Court in People v. Doe, 66-44 Keishu 405 (Feb 13, 2012).

As of now the information is scarce, and as a result, I cannot say whether the acts of a journalist "hacker" are justifiable. But three things can be said. First, prosecutors seem to respect the freedom of the press when they exercise their discretion on whether to accuse a suspect. So, there is a possibility that the prosecutors will decide not to accuse the journalist, like in Nara's secret document case. Second, once a journalist is accused, the chance of acquittal might not be very large considering the courts' attitude in two old cases. Third, the defense should focus on the distinction Nara District Court made (and Sendai High Court might have made implicitly) between real journalists and others (such as information sources or activist groups). The defense counsel can emphasize the fact that the journalist belongs to a reputable news service but, as I said, I am not sure whether this line of argument acquits the journalist. 

DISCLAIMER: "IT Law issues in Japan" only provides general information about Japanese information technology law and does not, under any circumstances, constitute legal advice. You should first obtain the advice of professional legal counsel who is qualified in Japan before acting or refraining from acting based on this blog.

Wednesday, March 6, 2013

Japanese Whistleblower Protection Act - Will Japanese Manning be Protected?

Professor Yochai Benkler recently wrote a persuasive article on the Bradley Manning case. I believe that the result of this case may have an impact of chilling off potential whistle-blowers. Then, what about Japanese whistle-blower protection?

Japan has the Whistle-blower Protection Act ("WPA" )which essentially categorizes three types of whistle-blowing.
One type is internal whistle-blowing like the boss or the ethics hotline. In such a case, whistle-blowers are strongly protected. Only as long as the whistle-blower considers the illegal facts occurred or were about to occur, whistle-blowing is protected. Article 3(i).
Another type is whistle-blowing to administrative authority. In this type, intermediate protection is given. When there are reasonable grounds to believe that illegal facts occurred or were about to occur, whistle-blowing is protected. Article 3(ii).
The other type is whistle-blowing to mass media or other organizations neither internal nor administrative authority. In this case, at least, there should be reasonable grounds to believe that illegal facts occurred or were about to occur, but that is not enough. Additionally required are reasonable grounds to believe either (1) other types of whistle-blowing would cause lay offs or other disadvantageous treatment, (2) internal whistle-blowing would cause concealing the evidence, or (3) the boss asked the whistle-blower not to resort to whistle-blowing. Article 3(iii).

The "protection" means the prohibition of firing or any other disfavorable treatment because of the whistle-blowing. Article 3 to 5.

One good thing is that the WPA covers the protection of government officials. Article 7. Also, the Q&A by the government on the WPA stipulates that as the protected whistle-blowing is on illegal acts, it is considered not worthy of protecting as secret, therefore whistle-blowing would not violate the obligation of confidentiality. This means that if the requirements of the WPA are met, Japanese Manning may receive protection.

But there are some uncertainties. One of them is how the court would interpret the statute. In one well known classic case, the Japanese Supreme Court upheld the conviction of a journalist of a newspaper for soliciting to disclose classified information. People v. Nishiyama, 32-3 Minshu 457 (May 31, 1975). Although the way he seduced a female government official is questionable from the journalists' ethics (he approached the official and formed a sexual relationship for obtaining classified information), this case would suggest that depending on the circumstances, the court may interpret the 
language of the WPA very strictly.

DISCLAIMER: "IT Law issues in Japan" only provides general information about Japanese information technology law and does not, under any circumstances, constitute legal advice. You should first obtain the advice of professional legal counsel who is qualified in Japan before acting or refraining from acting based on this blog.

Wednesday, February 27, 2013

Is Aaron's Law necessary in Japan?

After Aaron Swartz's death, a congressman proposed "Aaron's Law." One of the main points is to clarify and limit the ambiguous and extensive prohibition of the Computer Fraud and Abuse Act ("CFAA"). It is not the purpose of this post to explain US v. Nosal or other relevant cases of the CFAA in detail. Rather, this post will discuss the question of whether Japan needs to amend its equivalent CFAA.

The Act on the Prohibition of Unauthorized Computer Access (the "Act") is the Japanese equivalent of the CFAA. The basic concept of the Act is to ban two types of "unauthorized computer access". 

The first type is misuse of fraudulently obtained ID/password (or other authentication information). A typical example is that A obtains B's ID and password by social engineering (fraudulently) and uses B's ID and password to access an Internet site protected by access control function (namely, the password authentication function). Article 2(4)(i) of the Act.

The second type is making use of the security hole. If there is a security hole, an originally impossible access to a computer (because of the access control function) becomes possible by the insertion of special information or a command. Such access is also prohibited by the Act. Article 2(4)(i) and (ii) of the Act.

I believe that compared to the CFAA, the prohibited acts of the Act on the Prohibition of Unauthorized Computer Access is more limited and clearer. The requirement of "fraudulently obtained" authentication information plays a significant role in the password misuse type unauthorized access. Let's say that Company A employs B. And B is an authorized administrator of Company A's server which is password protected. As an administrator, B obtains IDs and passwords of users of the site. What happens, if one day, B changes her mind and decides to make use of the IDs and passwords and obtain the information stored in the server for an evil purpose (perhaps B decided to quit company A and wanted to search for "useful" information for when she goes to a competitor company)? That is not a violation of the Act because B did not "fraudulently" obtain the IDs and passwords at the time B obtained them. Although that conduct might be a violation of the Unfair Competition Prevention Act which protects trade secrets, that is a different law. The Japanese version of the CFAA will not criminalize users of the sites protected by the access control functions as long as they are using their ID/password they originally lawfully (or at least non-fraudulently) obtained.

In 2012, there was a reform of the Act to make it more strict. However, the definition of "unauthorized computer access" remained unchanged. Some of the amendments are: (1) the maximum penalty for unauthorized computer access of one year imprisonment and a five hundred thousand yen fine (around $5,000) was increased to a three-year imprisonment and a million yen (around $10,000) and (2) the fraudulent acquisition of ID/passwords (such as through phishing) itself became criminalized. 

Because of this, I think that this point perhaps might be relevant in Japan.  However, Professor Lawrence Lessig argued that the "corruption" of the legislative system was the cause of the problematic laws such as the CFAA and other laws, and that the corruption problem should be changed by Aaron's Laws. I think that this point perhaps might be relevant in Japan.


DISCLAIMER: "IT Law issues in Japan" only provides general information about Japanese information technology law and does not, under any circumstances, constitute legal advice. You should first obtain the advice of professional legal counsel who is qualified in Japan before acting or refraining from acting based on this blog.

Tuesday, February 12, 2013

Japanese High Profile Cyber-Criminal was Arrested

The most high-profiled cyber-crime in Japan last year was the "fake" blackmail case, which framed many innocent people. Several people were arrested by the police for sending threatening emails. One assistant director of animation films was not only arrested but also accused of sending an email threatening a massive killing. Before conviction, however, it was revealed that these emails were sent by a special computer virus. All those arrested were released and the prosecutor revoked the accusation to the assistant director.

What is important for the virus writer was that he (or maybe she) sent announcement emails to the mass media, claiming that the Japanese police were incompetent and couldn't tackle with cyber-crime. Also, the perpetrator even sent a puzzle to the police, saying that if the police could solve it, they would get a clue of the suspect. The police solved the puzzle and went to the designated place where they found a cat with a choker ring on which an SD card was attached. These scenes have been broadcasted by the media again and again and the Japanese people were horrified by the unknown and terrible computer virus.


On February 10, the police announced that they had arrested a 30 year old man in Tokyo as the suspect of the cyber-crime.
According to the media, the clue was on the SD card. The message on the card said: "My life was ruined by the false charge." The police claims that the arrested person had actually been convicted of sending a threatening message regarding the conflict between the users of a bulletin board, called "2ch", and Japanese major record company, Avex, about unlicensed usage by Avex of a character loved by 2ch users called "Mona."

As the arrested seems to be claiming his innocence, it is not clear at this stage whether he is the real cyber-criminal. However, what I found most important regarding this case is that the Japanese police forced many people to make false confessions during the interview. Most of the arrested framed by the virus writer eventually "confessed" to sending threatening emails. However, this was not true. The reason they confessed was because of the police's strong pressure during the interview. Although I admit the unique nature of Japanese criminal law which makes confessions important (such as the emphasis on the state of a criminal's mind), I think that the lesson of this case for the police is to reflect on themselves and refrain from applying too much pressure during an interview.


DISCLAIMER: "IT Law issues in Japan" only provides general information about Japanese information technology law and does not, under any circumstances, constitute legal advice. You should first obtain the advice of professional legal counsel who is qualified in Japan before acting or refraining from acting based on this blog.

Monday, January 21, 2013

Nationwide Shared Address Book App Provoking a Controversy in Japan



The hottest issue of information technology in Japan is the "Nationwide Shared Address Book App" or "Zenkoku Kyoyu Denwa Cho."  This is an android app which by installing you share your address book in your smartphone with all the other users of the app.  The result is that even though you don't want your personal information like name, address, and phone number to be disclosed, your personal information will be compromised, once one of your friends installs this app!  It is said that together with the data already held by the App producer, more than 28,000,000 individuals' personal data have been compromised.

The launcher of the App is called Tottori Loop, a Japanese group in Tottori prefecture (South West of Honshu) protesting the Dowa policy of Japan. The Dowa policy is favorable treatment of the descendants of those who used to be discriminated against.  Already in around 2012, the group ran a site called "Jusho de Pon!," or "Enter the Address and Telephone Number Pops Up!" As the name shows, this is a database site where personal information like the name or the telephone number is searchable by entering the address. The intention of the group is not clear.  As most of these people treated favorably live in a certain area called the "Dowa Area" or "Dowa Chiku," one possible intention is that they want to let people know the information of those who currently live in the Dowa Area.  The group seems to be using the data in published phone books from around 2007, before everyone started being concerned about privacy and is now trying to obtain the newest data by letting users share their own address book information.

Japanese privacy experts are opposed to the group, saying it may violate privacy rights of individuals.  But there is one issue that makes the situation complicated.  All the users of the app agreed to the terms of service and privacy policy of the app when they installed this app.  The famous discussion on twitter between HiromitsuTakagi, a researcher at GTRC, National Institute of Advanced Industrial Science and Technology, and the group members revealed that the group's position is that it has not breached any existing laws and regulations because the users agreed on terms of service and "voluntarily" disclosed the data.


However, it seems to me that the group is misleading the argument.  Let's say Amy's address is in Bill's address book.  When Amy gave Bill her address, in most cases, she did not consent to sharing her address to anyone (other than Bill). By then installing the app, Bill might have consented to share Amy's personal information.  But, of course, Bill cannot lawfully consent to share Amy's personal information because the owner of Amy's information is Amy, not Bill.  So, I do not think that the argument by Tottori Loop is persuasive.  In addition, as most of users do not read the terms of service, there is another argument of whether the users really consented.

Whether the apps will be removed from Google Play is not clear.  But it can be an "unauthorized publishing or disclosure of people's private and confidential information" in violation of the policies.

DISCLAIMER: "IT Law issues in Japan" only provides general information about Japanese information technology law and does not, under any circumstances, constitute legal advice. You should first obtain the advice of professional legal counsel who is qualified in Japan before acting or refraining from acting based on this blog.