EPIC-Amicus-US V. Miller
Total Page:16
File Type:pdf, Size:1020Kb
No. 18-5578 UNITED STATES COURT OF APPEALS FOR THE SIXTH CIRCUIT UNITED STATES OF AMERICA Plaintiff-Appellee, vs. WILLIAM J. MILLER, Defendant-Appellant. On Appeal from tHe United States District Court for the Eastern District of Kentucky Case No. 2:16-cr-00047-1 The Hon. David L. Bunning BRIEF OF AMICUS CURIAE ELECTRONIC PRIVACY INFORMATION CENTER (EPIC) IN SUPPORT OF APPELLANT Marc Rotenberg Counsel of Record Alan Butler Electronic Privacy Information Center 1718 Connecticut Avenue, N.W. Suite 200 WasHington, DC 20009 (202) 483-1140 October 17, 2018 UNITED STATES COURT OF APPEALS FOR THE SIXTH CIRCUIT Disclosure of Corporate Affiliations and Financial Interest Sixth Circuit Case Number: 18-5578 Case Name: United States v. Miller Name of counsel: Alan Butler Pursuant to 6th Cir. R. 26.1, Electronic Privacy Information Center Name of Party makes the following disclosure: 1. Is said party a subsidiary or affiliate of a publicly owned corporation? If Yes, list below the identity of the parent corporation or affiliate and the relationship between it and the named party: No. 2. Is there a publicly owned corporation, not a party to the appeal, that has a financial interest in the outcome? If yes, list the identity of such corporation and the nature of the financial interest: No. CERTIFICATE OF SERVICE I certify that on ____________October_______ 17,_______ 2018___________ the foregoing document was served on all parties or their counsel of record through the CM/ECF system if they are registered users or, if they are not, by placing a true and correct copy in the United States mail, postage prepaid, to their address of record. s/ Alan Butler 1718 Connecticut Ave. NW, Suite 200 Washington, DC 20009 This statement is filed twice: when the appeal is initially opened and later, in the principal briefs, immediately preceding the table of contents. See 6th Cir. R. 26.1 on page 2 of this form. 6CA-1 8/08 Page 1 of 2 TABLE OF CONTENTS CORPORATE DISCLOSURE .................................................................................. i TABLE OF AUTHORITIES ................................................................................... iii INTEREST OF AMICUS ......................................................................................... 1 SUMMARY OF ARGUMENT ................................................................................ 2 ARGUMENT ........................................................................................................... 3 I. The automated scanning of private files on Google servers affects more than a billion users, wHicH means that any errors in the detection system could Have a massive impact on user privacy. ............................................. 5 II. The use of HasH algoritHms, like otHer investigative tecHniques, requires researcH, testing, and data indicating reliability. ........................................ 10 A. On tHe record before tHis court, tHe Government cannot establisH witH “virtual certainty” tHat tHe files it searcHed were identical to the files that a Google employee previously viewed. ........................... 10 B. The National Academy of Sciences and otHer experts Have raised significant concerns about tHe lack of reliable standards for investigative tecHniques. ....................................................................... 14 C. The Government’s prior use of unreliable tecHniques to scan and collect private messages underscores tHe need for proof of reliability. .............................................................................................. 19 CERTIFICATE OF COMPLIANCE ..................................................................... 23 CERTIFICATE OF SERVICE ............................................................................... 24 ii TABLE OF AUTHORITIES CASES Carpenter v. United Sates, 138 S. Ct. 2206 (2018) .......................................................................................... 3 Daubert v. Merrell Dow Pharmaceuticals, Inc., 509 U.S. 579 (1993) ............................................................................................ 16 Melendez-Diaz v. Massachusetts, 557 U.S. 305 (2009) ...................................................................................... 15, 20 United States v. Ackerman, 831 F.3d 1292 (10th Cir. 2016) (GorsucH, J.) ....................................................... 4 United States v. Jacobsen, 466 U.S. 109 (1984) .............................................................................................. 4 United States v. Keith, 980 F. Supp. 2d 33 (D. Mass. 2013) ..................................................................... 9 STATUTES 18 U.S.C. § 3123(a)(3) ..................................................................................... 20, 21 18 U.S.C.§ 2258A(a)(2) ........................................................................................... 5 The Science, State, Justice, Commerce, and Related Agencies Appropriations Act of 2006. P.L. No. 109-108, 119 Stat. 2290 (2005) ....................................... 15 OTHER AUTHORITIES Brian Fung, Google Really is Trying to Build a Censored Chinese Search Engine, Its CEO Confirms, WasH. Post (Oct. 16, 2018) ....................................... 3 Bruce Schneier, Applied Cryptography (1996) ................................................ 11, 12 Erin E. MurpHy, Inside the Cell: The Dark Side of Forensic DNA (2015) ............ 14 Google, Our Products (2018) ................................................................................... 6 Google, Search for Images with Reverse Image Search (2018) ............................... 6 IIT ResearcH Inst., Independent Technical Review of the Carnivore System: Final Report (2000) ............................................................................................ 20 Internet and Data Interception Capabilities Developed by FBI: Hearing Before the Subcomm. on the Constitution of the H. Comm. on the Judiciary, 106th Cong. (2000) (statement of Donald M. Kerr, Assistant Director, Laboratory Division, Federal Bureau of Investigation) ...................................... 19 Jake Swearingen, Gmail Gets a Major Face-lift and Productivity Boost, Starting Today, NY Mag Intelligencer (Apr. 25, 2018) ....................................... 6 iii Jennifer L. Mnookin et al., The Need for a Research Culture in the Forensic Sciences, 58 UCLA L. Rev. 725 (2011) ............................................................. 18 Microsoft, Digital Crimes Unit, PhotoDNA ........................................................... 11 Microsoft, Photo DNA: Step-by-step ........................................................................ 9 Microsoft, PhotoDNA: Fact Sheet (2009) .............................................................. 13 National ResearcH Council of tHe National Academies, Strengthening Forensic Science in the United States: A Path Forward (2009) ...... 14, 15, 16, 17 Orin Kerr, Internet Surveillance Law After the USA PATRIOT Act: The Big Brother That Isn’t, 97 Nw. U. L. Rev. 607 (2003) ............................................. 20 Petter Christian Bjelland, Katrin Franke, & André Årnes, Practical Use of Approximate Hash Based Matching in Digital Investigations, 11 Digital Investigations S18 (2014) ................................................................................... 13 President’s Council of Advisors on Science and Technology, Forensic Science in Criminal Courts: Ensuring Scientific Validity of Feature- Comparison Methods (2016) .................................................................. 14, 17, 18 Radicati Group, Inc., Email Statistics Report, 2018-2022: Executive Summary (2018) .................................................................................................................... 6 RicHard P. Salgado, Fourth Amendment Search and the Power of the Hash, 119 Harv. L. Rev. 38 (2005) ................................................................................. 9 Ron Rivest, The MD5 Message-Digest Algorithm RFC 1321 (Apr. 1992) ............ 12 Sebastiano Battiato, Giovanni Maria Farinella, Enrico Messina, & Giovanni Puglisi, A Robust Forensic Hash Component for Image Alignment, 2011 Int’l Conf Image Analysis and Processing 473 (2011) ....................................... 12 Shoshana Wodinsky, Google Drive is About to Hit 1 Billion Users, THe Verge (Jul. 25, 2018) ....................................................................................................... 6 Simson Garfinkel & Gene Spafford, Web Security & Commerce (1997) .............. 12 iv INTEREST OF AMICUS The Electronic Privacy Information Center (“EPIC”) is a public interest researcH center in WasHington, D.C., established in 1994 to focus public attention on emerging civil liberties issues and to protect privacy, the First Amendment, and other constitutional values.1 EPIC routinely participates as amicus curiae before the United States Supreme Court and otHer courts in cases concerning emerging privacy issues, new tecHnologies, and constitutional interests. EPIC Has autHored several briefs specifically concerning Fourth Amendment standards for searches using new tecHnologies. See, e.g., Brief of Amici Curiae EPIC et. al, Carpenter v. United States, 138 S. Ct. 2206 (2018) (arguing tHat tHe FourtH Amendment protects tHe rigHt against warrantless seizure and searcH of location data); Brief of Amici Curiae EPIC et. al, Riley v. California, 134 S. Ct. 2473 (2014) (arguing that warrantless searcH of a cell pHone incident