United States v. Robert Tappan MorrisUnited States v. Robert Tappan Morris
This аppeal presents two narrow issues of statutory construction concerning a provision Congress recently adopted to strengthen protection against computer crimes. Section 2(d) of the Computer Fraud and Abuse Act of 1986,
These questions are raised on an appeal by Robert Tappan Morris from the May 16, 1990, judgment of the District Court for the Northern District of New York (Howard G. Munson, Judge) convicting him, after a jury trial, of violating
We conclude that
FACTS
In the fall of 1988, Morris was a first-year graduate student in Cornell University’s computer science Ph.D. program. Through undergraduate work at Harvard and in various jobs he had acquired significant computer experience and expertise. When Morris entered Cornell, he was given an account on the computer at the Computer Science Division. This account gave him explicit authorization to use computers at Cornell. Morris engaged in various discussions with fellow graduate students about the security of computer networks and his ability to penetrate it.
In October 1988, Morris began work on a computer program, later known as the INTERNET “worm” or “virus.” The goal of this program was to demonstrate the inadequacies of current security measures on computer networks by exploiting the security defects that Morris had discovered. The tactic he selected was release of a worm into network computers. Morris designed the program to spread across a national network of computers after being inserted at one computer location connected to the network. Morris rеleased the worm into INTERNET, which is a group of national networks that connect university, governmental, and military computers around the country. The network permits communication and transfer of information between computers on the network.
Morris sought to program the INTERNET worm to spread widely without drawing attention to itself. The worm was supposed to occupy little computer operation time, and thus not interfere with normal use of the computers. Morris programmed the worm to make it difficult to detect and read, so that other programmers would not be able to “kill” the worm easily.
Morris identified four ways in which the worm could break into computers on the network:
(1) through a “hole” or “bug” (an error) in SEND MAIL, a computer program that transfers and receives electronic mail on a computer;
(2) through a bug in the “finger demon” program, a program that permits a person to obtain limited information about the users of another computer;
(3) through the “trusted hosts” feature, which permits a user with certain privileges on one computer to have equivalent privileges on another computer without using a password; and
(4) through a program of password guessing, whereby various combinations of letters are tried out in rapid sequence in the hope that one will be an authorized user’s password, which is entered to permit whatever level of activity that user is authorized to perform.
On November 2, 1988, Morris released the worm from a computer at the Massachusetts Institute of Technology. MIT was selected to disguise the fact that the worm came from Morris at Cornell. Morris soon discovered that the worm was replicating and reinfecting machines at a much faster rate than he had anticipated. Ultimately, many machines at locations around the country either crashed or became “catatonic.” When Morris realized what was happening, he contaсted a friend at Harvard to discuss a solution. Eventually, they sent an anonymous message from Harvard over the network, instructing programmers how to kill the worm and prevent reinfection. However, because the network route was clogged, this message did not get through until it was too late. Computers were affected at numerous installations, including leading universities, military sites, and medical research facilities. The estimated cost of dealing with the worm at each installation ranged from $200 to more than $53,000.
Morris was found guilty, following a jury trial, of violаting
DISCUSSION
I. The intent requirement in
Section 1030(a)(5)(A) , covers anyone who
(5) intentionally accesses a Federal interest computer without authorization, and by means of one or more instances of such conduct alters, damages, or destroys information in any such Federal interest computer, or prevents authorized use of any such computer or information, and thereby
(A) causes loss to one or more others of a value aggregating $1,000 or more during any one year period; ... [emphasis added].
The District Court concluded that the intent requirement applied only to the accessing and not to the resulting damage.
Morris argues that the Government had to prove not only that he intended the unauthorized access of a federal interest computer, but also that he intended to prevent others from using it, and thus cause a loss. The adverb “intentionally,” he contends, modifies both verb phrases of the section. The Government urges that since punctuation sets thе “accesses” phrase off from the subsequent “damages” phrase, the provision unambiguously shows that “intentionally” modifies only “accesses.” Absent textual ambiguity, the Government asserts that recourse to legislative history is not appropriate.
See Burlington N.R. Co. v. Oklahoma Tax Comm’n,
With some statutes, punctuation has been relied upon to indicate that a phrase set off by commas is independent of the language that followed.
See United States v. Ron Pair Enterprises, Inc.,
The first federal statute dealing with computer crimes was passed in 1984, Pub.L. No. 98-473 (codified at
First, the 1986 amendments changed the scienter requirement in
(2) intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains information contained in a financial record of a financial institution, or of a card issuer as defined in section 1602(n) of title 15, or contained in a file of a consumer reporting agency on a consumer, as such terms are defined in the Fair Credit Reporting Act (15 U.S.C. 1681 et seq.).
According to the Senate Judiciary Committee, Congress changed the mental state requirement in
Also, Congress expressed concern that the “knowingly” standard “might bе inappropriate for cases involving computer technology.”
Id.
The concern was that a scienter requirement of “knowingly” might encompass the acts of an individual “who inadvertently ‘stumble[d] into’ someone else’s computer file or computer data,” especially where such individual was autho
This use of a
mens rea
standard to make sure that inadvertent accessing was not covered is also emphasized in the Senate Report’s discussion of
The other relevant change in the 1986 amendments was the introduction of subsection (a)(5) to replace its earlier version, subsection (a)(3) of the 1984 act,
knowingly accesses a computer without authorization, or having accessed a computer with authorization, uses the opportunity such access provides for purposes to which such authorization does not extend, and by means of such conduct knowingly uses, modifies, destroys, or discloses information in, or prevents authorized use of, such computer, if such computer is operated for or on behalf of the Government of United States and such conduct affects such operation.
The 1986 version changed the mental state requirement from “knowingly” to “intentionally," and did not repeat it after the “accesses” phrase, as had the 1984 version. By contrast, other subsections of
Morris notes the careful attention that Congress gave to selecting the scienter requirement for current subsections (a)(2) and (a)(5). Then, relying primarily on comments in the Senate and House reports, Morris argues that the “intentionally” requirement of
The Government’s argument that the scienter requirement in
(1) knowingly accesses a computer without authorization or exceeds authorized access, and by means of such conduct obtains information that has been determined by the Unitеd States Government pursuant to an Executive order or statute to require protection against unauthorized disclosure for reasons of national defense or foreign relations, or any restricted data ... with the intent or reason to believe that such information so obtained is to be used to the injury of the United States, or to the advantage of any foreign nation.
Since Congress sought in subsection (a)(1) to have the “knowingly” standard govern the "accesses” phrase and the “with intent” standard govern the “results” phrase, it was necеssary to state the scienter requirement at the beginning of both phrases. By contrast, Morris argues, where Congress stated the scienter requirement only once, at the beginning of the “accesses” phrase, it was intended to cover both the “accesses” phrase and the phrase that followed it.
There is a problem, however, with applying Morris’s explanation to
Despite some isolated language in the legislative history that arguably suggests a scienter component for the “damages” phrase of
II. The unauthorized access requirement in
We assess the sufficiency of the evidence under the traditional standard. Morris was authorized to use computers at Cornell, Harvard, and Berkeley, all of which were on INTERNET. As a result, Morris was authorized to communicate with other computers on the network to send electronic mail (SEND MAIL), and to find out certain information about the users of other com
The Senate Report stated that
Morris relies on the first quoted portion to argue that his actions can be characterized only as exceeding authorized access, since he had authorized access to a federal interest computer. However, the second quoted portion reveals that Congress was not drawing a bright line between those who have some access to any federal interest computer and those who have none. Congress contemplated that individuals with access to some federal interest computers would be subject to liability under the computer fraud provisions for gaining unauthorized access to other federal interest computers. See, e.g., id. (stating that a Labor Department employee who uses Labor’s computers to access without authorization an FBI computer can be criminally prosecuted).
The evidence permitted the jury to conclude that Morris’s use of the SEND MAIL and finger demon features constituted access without authorization. While a case might arise where the use of SEND MAIL or finger demon falls within a nebulous area in which the line between accessing without authorization and exceeding authorized access may not be clear, Morris’s conduct here falls well within the area of unauthorized access. Morris did not use either of those features in any way related to their intended function. He did not send or read mail nor discover information about other users; instead he found holes in both programs that permitted him a special and unauthorized access route into other computers.
Moreover, the jury verdict need not be upheld solely on Morris’s use of SEND MAIL and finger demon. As the District Court noted, in denying Morris’ motion for acquittal,
Although the evidence may have shown that defendant’s initial insertion of the worm simply exceeded his authorized access, the evidence also demonstrated that the worm was designed to spread to other computers at which he had no account and no authority, express or implied, to unleash the worm program. Moreover, there was also evidence that the worm was designed to gain access to computers at which he had no account by guessing their passwords. Accordingly, the evidence did support the jury’s conclusion that defendant accessed without authority as opposed to merely exceeding the scope of his authority.
In light of the reasonable conclusions that the jury could draw from Morris’s use of SEND MAIL and finger demon, and from his use of the trusted hosts feature and password guessing, his challenge to the sufficiency of the evidence fails.
Morris endeavors to bolster his sufficiency argument by contending that his conduct was not punishable under subsection (a)(5) but was punishable under subsection (a)(3). That concession belies the validity of his claim that he only exceeded authorization rather than made unauthorized access. Neither subsection (a)(3) nor (a)(5) punishes conduct that exceeds authorization. Both punish a person who “accesses” “without authorization” certain computers. Subsection (a)(3) covers the computers of a department or agency of the United States; subsection (a)(5) more broadly covers any federal interest computers, defined to include, among other computers, those used exclusively by the United States,
To extricate himself from the consequence of conceding that he made “unauthorized access” within the meaning of subsection (a)(3), Morris subtly shifts his argumеnt and contends that he is not within the reach of subsection (a)(5) at all. He argues that subsection (a)(5) covers only those who, unlike himself, lack access to any federal interest computer. It is true that a primary concern of Congress in drafting subsection (a)(5) was to reach those unauthorized to access any federal interest computer. The Senate Report stated, “[T]his subsection [ (a)(5) ] will be aimed at ‘outsiders,’ i.e., those lacking authorization to access any Federal interest computer.” Senate Report аt 10, U.S.Code Cong. & Admin. News at 2488. But the fact that the subsection is “aimed” at such “outsiders” does not mean that its coverage is limited to them. Congress understandably thought that the group most likely to damage federal interest computers would be those who lack authorization to use any of them. But it surely did not mean to insulate from liability the person authorized to use computers at the State Department who causes damage to computers at the Defense Department. Congress created the misdemeanor offense of subsection (a)(3) to punish intentional trespasses into computers for which one lacks authorized access; it added the felony offense of subsection (a)(5) to punish such a trespasser who also causes damage or loss in excess of $1,000, not only to computers of the United States but to any computer within the definition of federal interest computers. With both provisions, Congress was punishing those, like Morris, who, with access to some computers that enable them to communicate on a network linking other computers, gаin access to other computers to which they lack authorization and either trespass, in violation of subsection (a)(3), or cause damage or loss of $1,000 or more, in violation of subsection (a)(5).
Morris also contends that the District Court should have instructed the jury on his theory that he was only exceeding authorized access. The District Court decided that it was unnecessary to provide the jury with a definition of “authorization.” We agree. Since the word is of common usage, without any technical or ambiguous meaning, the Court was not obliged to instruct the jury on its meaning.
See, e.g., United States v. Chenault,
An instruction on “exceeding authorized access” would have risked misleading the jury into thinking that Morris could not be convicted if some of his conduct could be viewed as falling within this description. Yet, even if that phrase might have applied to some of his conduct, he could nonetheless be found liable for doing what the statute prohibited, gaining access where he was unauthorized and causing loss.
Additionally, the District Court properly refused to charge the jury with Morris’s proposed jury instruction on access without authorization. That instruction stated, “To establish the element of lack of authorization, the government must prove beyond a reasonable doubt that Mr. Morris was an ‘outsider,’ that is, that he was not authorized to access any Federal interest computer in any manner.” As the analysis of the legislative history reveals, Congress did not intend an individual’s authorized access to one federal interest computer to protect him from prosecution, no matter what other federal interest computers he accesses.
CONCLUSION
For the foregoing reasons, the judgment of the District Court is affirmed.
Notes
. In the colorful argot of computers, a "worm” is a program that travels from one computer to another but does not attach itself to the operating system of the computer it "infects.” It differs from a "virus,” which is also a migrating program, but one that attaches itself to the operating system of any computer it enters and can infect any other computer that uses files from the infected computer.