Government lawyers don’t understand the Internet. That’s a problem.
By Garrett M. Graff, Washington Post, September 23, 2016
Last year, the FBI nearly destroyed the life of an innocent physicist. In May 2015, agents arrested Xi Xiaoxing, the chairman of Temple University’s physics department, and charged that he was sneaking Chinese scientists details about a piece of restricted research equipment known as a “pocket heater.” An illustrious career seemed suddenly to implode. A few months later, though, the Justice Department dropped all the charges and made an embarrassing admission: It hadn’t actually understood Xi’s work. After defense experts examined his supposed “leaks,” they pointed out that what he’d shared with Chinese colleagues wasn’t a restricted engineering design but in fact a schematic for an altogether different type of device. The case helped lead earlier this year to new Justice Department restrictions that took power away from prosecutors in the field and centralized certain investigations in Washington, where they could receive more oversight from a specially trained team of lawyers.
Whether it’s high-level physics research or the technology of our daily lives, the government’s lawyers are struggling to grasp the increasingly technical cases that come before them. Both federal prosecutors and the attorneys who represent executive agencies in court are bungling lawsuits across the country because they don’t understand what they’re talking about. Too few lawyers have the skill set or the specialized knowledge to make sense of code, networks and the people who use them, and too few law schools are telling them what they need to know. “It would be enormously helpful to have a deeper bench of lawyers with technical backgrounds,” says Susan Hennessey, a Brookings Institution fellow and former National Security Agency lawyer.
This situation is stymieing criminal investigations, upending innocents’ lives and making it harder to set legal boundaries around mass-surveillance programs. The result is that, when it comes to technology, justice is increasingly out of reach.
Just this week, a federal judge in Iowa threw out evidence collected by the FBI in a child porn investigation because the Justice Department’s search warrant misstated the technical details of where and how it hoped to gather the evidence. As the judge concluded, either the FBI or the prosecutors hadn’t understood exactly how their own “network investigative technique” worked, or they’d failed to explain it correctly in the courtroom. What’s more, the judge who issued the original warrant didn’t have the jurisdiction to do so, because the “network investigative technique,” a piece of FBI-designed malware that sniffed out people trading illegal files, collected evidence far beyond the bounds of the Virginia district where the warrant was authorized.
Today, cyber, data and privacy questions lie at the core of numerous corporate and government cases, and there aren’t anywhere near enough practicing lawyers who can adequately understand the complex issues involved, let alone who can sufficiently explain them in court or advise investigators on how to build a successful case. “This is a problem that pervades all of the national security apparatus,” says Alvaro Bedoya, who previously worked as the chief counsel to the Senate Judiciary Committee’s subcommittee on privacy, technology and the law, and now leads Georgetown Law’s Center on Privacy & Technology. “You don’t have a pipeline of lawyers right now who can read code.”
The fallout from Edward Snowden’s revelations exposed numerous instances in which agency lawyers miscommunicated to courts about what the government was doing. There are two possible explanations: Either they wilfully exploited judges’ lack of technical knowledge, or the lawyers themselves couldn’t fathom the programs they were trying to explain. In a 2009 case that became public in 2013, NSA Director Keith Alexander admitted that none of the lawyers overseeing one surveillance program grasped what it was doing when it queried a particular agency database: “It appears there was never a complete understanding among the key personnel ... regarding what each individual meant by the terminology used.” In a 2011 suit, Judge John Bates of the secret Foreign Intelligence Surveillance Court wrote an angry (and heavily redacted) 85-page decision saying he was “troubled” that the case marked “the third instance in less than three years in which the government has disclosed a substantial misrepresentation regarding the scope of a major collection program.” And in yet another case, Solicitor General Donald B. Verrilli Jr. found in 2013 that he’d misled the Supreme Court about how the Justice Department was using evidence derived from warrantless surveillance programs targeting foreigners, an error that led to a months-long internal debate as Verrilli questioned the department’s interpretation of the law.
Such confusion is hardly confined to the NSA’s most technical work. On a more mundane basis, government attorneys frequently confuse content and metadata, even though the two types of information face very different legal standards. One possible reason: The Justice Department’s decade-old Electronic Surveillance Manual is incorrect about the basic mechanics of how email works, according to a forthcoming article in the Harvard Journal of Law & Technology. Such problems are becoming more pervasive as lawyers misapply law designed for telephone surveillance to cases focused on the Internet, says Susan Landau, a computer scientist at Worcester Polytechnic Institute and one of the article’s authors. They “don’t know the right questions to ask.” And it’s not just them: “A judge may not even know what’s wrong with the briefs. It’s an extremely serious problem,” she says.
One scientist said that too often he sees prosecutors limited by the complexity of the crimes confronting them. In one recent prosecution of a security researcher accused of illegal hacking, an assistant U.S. attorney summarized the case to the court by saying, “He had to download the entire iOS system on his computer, he had to decrypt it, he had to do all of these things I don’t even understand.” The government ultimately lost the case.
“The number of people involved in cybersecurity [law] has to increase dramatically,” says Harriet Pearson, who helps lead Hogan Lovells’s cybersecurity and privacy practice, and who was IBM’s first chief privacy officer. “There’s going to need to be a huge amount of education.”












