Feeds

Hackers at mercy of US judges

Supreme Court ruling grants leeway in sentencing

  • alert
  • submit to reddit

Beginner's guide to SSL certificates

A landmark U.S. Supreme Court decision last month giving judges more leeway in deciding federal prison terms could be good news for computer intruders who don't fit the classic criminal mold, legal experts say.

In US v. Booker, decided 12 January, the court ruled 5-4 to overturn part of a 1984 law that required judges to sentence offenders strictly by a book of written guidelines produced and periodically revised by a seven-member, presidential appointed commission.

Originally intended to eliminate unfair disparity in sentencing, the guidelines are built on an elaborate point system that sets a baseline value for each category of crime, and then adds or subtracts points for specific aggravating or mitigating circumstances. The more points, the higher the minimum and maximum sentences available to the judge.

In computer crimes the most significant guideline factor by far was the amount of financial loss the offender caused - a calculus that led to a decade of fierce courtroom battles over what constitutes loss in different computer intrusion scenarios. In the most famous example, in 1999 federal prosecutors claimed that hacker Kevin Mitnick inflicted $291m in losses on his corporate victims, based primarily on the companies' own assessment of the value of proprietary source code that Mitnick copied, but did not damage.

More recently, prosecutors put the losses caused by convicted virus-modifier Jeffrey Lee Parson at over $1,225,000, while Parson's lawyer counted less than $10,000 in damage. "Everything comes down to damages, basically," says Orin Kerr, a cyber law professor at George Washington University Law School, and a former attorney with the Justice Department's computer crime section. "How much harm is caused by the crime? It became a monetary calculation. The victim says we've lost $5m, the defendant says it was only $100,000."

But under the Booker ruling, the sentencing guidelines are just that: guidelines. Judges are free to disregard them and consider other factors. In cases where a defendant has a story to tell, that could translate to an easier sentence.

"Now that the guidelines are merely advisory, the judges will really have a lot of discretion in sentencing," says San Francisco defense attorney Omar Figueroa. "It's going to help a lot of hacker cases in the future because the sentencing calculation isn't going to be so formulaic."

Chaos

That could help one of Figuroa's clients: 21-year-old Robert Lyttle, who faces five felony counts for his role in a string of high-profile website defacements in the spring of 2002. Under the moniker "the Deceptive Duo", Lyttle and another intruder, Benjamin Stark, specialized in cracking vulnerable U.S. government websites and posting a patriotic "mission outline" in which they described themselves as anonymous US citizens determined to save the country from cyberterrorists by exposing security holes. According to the government, Lyttle caused over $70,000 in losses.

Before last month, an attacker's motives could have little influence over his sentencing exposure for such a crime. "Now when you have, like in Robert's situation, somebody who was acting in good faith and meant no harm, the judge can take into account the lack of malice," says Figueroa.

Kerr agrees that some cyber offenders could fare better under the new regime. "There will probably be less focus on dollar loss, more focus on the equities of the case and why the defendant did what he did," Kerr says. Moreover, some judges won't see straightforward computer intrusion as comparable to larceny or bank fraud - while under the guidelines, they were all the same.

But judicial independence swings both ways, and without the guidelines a computer crime defendant's fate will have much to do with what kind of judge they draw. "It's chaos," says Jennifer Granick, clinical director for the Center for Internet and Society at Stanford Law School "The question is, would the judge guided by his or her own discretion sentence a computer crime case more or less harshly than the sentencing guidelines?"

"Some judges are going to look at computer crime cases and think, oh, this is only a virtual crime, there's no real physical harm," Kerr says. "And others will probably think, this is really worrisome, online crime is out of control, and this really needs to be stopped. It introduces uncertainty more than anything else."

Copyright © 2004, SecurityFocus logo

Related stories

Hacker charged with US gov attack
'Deceptive duo' hacker pleads guilty
Chapter One: Kevin Mitnick's story

Intelligent flash storage arrays

More from The Register

next story
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
Oi, Europe! Tell US feds to GTFO of our servers, say Microsoft and pals
By writing a really angry letter about how it's harming our cloud business, ta
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
5 critical considerations for enterprise cloud backup
Key considerations when evaluating cloud backup solutions to ensure adequate protection security and availability of enterprise data.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Protecting against web application threats using SSL
SSL encryption can protect server‐to‐server communications, client devices, cloud resources, and other endpoints in order to help prevent the risk of data loss and losing customer trust.