[00:02.120 --> 00:09.700] All right, I'm going to go ahead and get started, because I'm trying to cram probably slightly too much into roughly 35, 40 minutes to leave room for questions. [00:10.800 --> 00:12.580] So my name is Fred Jennings. [00:12.860 --> 00:14.440] Thank you all for coming out to this talk. [00:14.600 --> 00:15.500] I'm excited to give it. [00:17.080 --> 00:20.180] By way of introductions, actually, let me start with the boring disclaimers. [00:20.580 --> 00:23.100] First off, this talk is not legal advice. [00:23.280 --> 00:25.340] You should not take legal advice from conference talks. [00:26.120 --> 00:30.080] Second, unless we've had a very specific conversation prior to this talk, I'm not your lawyer. [00:30.840 --> 00:33.820] And third, nothing here represents the views of my clients, employers, et cetera. [00:35.060 --> 00:39.640] By way of introductions, I've been working in this field for a bit over a decade. [00:39.800 --> 00:44.260] I got my start doing cybercrime defense, federal cases defending hacktivists around the country. [00:44.960 --> 01:04.200] After about four and a half years of that, I went in-house at GitHub, where, among many other hats I wore, I was the lawyer primarily responsible for dealing with law enforcement requests for data, ranging from informal letters all the way up to FISA court warrants and national security letters. [01:04.940 --> 01:07.640] And I want to talk as much as I can about all of that tonight. [01:09.540 --> 01:16.760] After that, I went to a healthcare tech company called ZocDoc as their product counsel, dealing with, also dealing with government requests. [01:16.860 --> 01:23.340] So we got a much lower volume of them, but also dealing with things like data minimization, which we will get back to later in the talk. [01:26.240 --> 01:42.440] What we'll cover here is, first, I want to walk through the kind of primary mechanisms by which government actors, usually either state police up through FBI and federal agencies, seek data, what legal mechanisms they have to seek data from an online platform, [01:42.460 --> 01:46.640] and then broadly, what those online platforms can do about it. [01:47.180 --> 01:56.340] So just out of curiosity, how many people in the audience have some sort of role, you know, within an online platform that has users or subscribers of any sort? [01:56.460 --> 01:57.060] Just raise a hand. [01:58.620 --> 01:59.240] All right. [01:59.680 --> 02:03.040] How many of you are users of online platforms that you have a login for? [02:03.580 --> 02:04.960] Great, you're in the right place. [02:07.360 --> 02:20.240] Just to set expectations, this is not, because it is way outside the realm of an hour-long talk, going to be a deep dive on Fourth Amendment questions or on the, like, precise parts of legal process you might use to fight these orders. [02:21.260 --> 02:31.020] I think my philosophy as a lawyer who does a lot of work for these platforms, either as in-house or outside counsel, is if we've landed in court on a motion to quash, we've already lost. [02:31.260 --> 02:36.380] That is expensive, painful, and honestly, most companies don't even want to do it. [02:36.500 --> 02:37.760] We'll get back to that later as well. [02:39.620 --> 02:50.660] And so once we've gone through those sort of base mechanisms, I also want to talk about kind of what you can do as someone, you know, with a role in those online platforms to minimize the amount of data that you give back. [02:51.340 --> 03:00.660] You know, sort of starting from the assumption that you want to protect user privacy, keep, you know, law enforcement agents from getting any more user data than they're completely entitled to. [03:02.540 --> 03:06.180] And sorry, I got my con crud early this year, so my throat's a little stiff. [03:06.300 --> 03:08.020] I might take a cough drop break midway through. [03:08.520 --> 03:13.900] But yeah, without further ado, let me jump forward into our next step. [03:14.500 --> 03:21.240] So generally speaking, there are three types of categories by which law enforcement can seek data from an online platform. [03:22.040 --> 03:24.300] They all have more or less the same structure. [03:24.760 --> 03:30.120] The law enforcement agent through one of its officers sends a request to the platform. [03:30.880 --> 03:33.800] You know, these requests take more or less three different forms. [03:33.960 --> 03:35.060] There are a few different ones. [03:35.200 --> 03:36.040] I'll get to that a bit later. [03:37.900 --> 03:43.780] The platform receives that request, runs it often through the security team to say, hey, we got this request. [03:43.780 --> 03:44.580] What do we have? [03:45.000 --> 03:49.080] And then prepares a response to send back, you know, responding to that request. [03:51.520 --> 03:59.220] The first and probably by far most common is an administrative subpoena, which is a relatively informal process. [03:59.220 --> 04:02.080] There is no court order or judge signing off on this. [04:02.200 --> 04:05.360] This is just a formal thing sent by the agent. [04:06.460 --> 04:08.040] There's a 2703D order. [04:08.360 --> 04:11.640] And I'll get into more depth on each of these, which is kind of in the middle. [04:11.780 --> 04:13.040] You can think of it as kind of in between. [04:13.100 --> 04:14.680] It's like a subpoena plus. [04:15.060 --> 04:16.640] A court has signed off on it. [04:16.940 --> 04:24.180] But the burden of proof, the sort of thing that the agent has to show to get it signed off on, is a much lower standard than a warrant. [04:25.000 --> 04:35.080] And then there's a search warrant, which has a much broader scope and has a higher burden that the officer has to show, which is not really that protective at the end of the day. [04:35.220 --> 04:37.820] And I'll get into that, into that further down too. [04:40.780 --> 04:46.020] So what does the administrative subpoena actually sort of, what does that come from and what can it access? [04:46.620 --> 04:55.920] So what this all kind of stems from is an act called ECPA, or the Electronic Communications Privacy Act, and the Stored Communications Act, or SCA. [04:56.980 --> 05:06.640] Much like the, much like the Computer Fraud and Abuse Act, these date from kind of the late 80s, early 90s, when the legislation was being drafted up and passed into law. [05:07.060 --> 05:18.900] And so a lot of the actual sort of plain text terminology comes from an era of dial-up Internet, monthly subscribers, and like the terminology doesn't really match what the Internet looks like today. [05:21.220 --> 05:27.500] So you can find the like exact list of everything they're entitled to give under 18 U.S.C. [05:27.960 --> 05:28.680] 2702 . [05:28.680 --> 05:34.780] But broadly speaking, the administrative subpoena covers non-content or routing information. [05:35.400 --> 05:39.920] And if you want like the really, really high level overview, all of this works by analogy. [05:40.360 --> 05:46.440] And all of government surveillance law essentially goes back to the early days of opening people's envelopes. [05:47.000 --> 05:50.200] If you wanted to open the envelope and read the contents, that's a warrant. [05:50.540 --> 05:56.500] If you want to just read the routing information on the cover of the of the of the envelope, that's considered relatively public. [05:56.620 --> 05:57.520] So the standard is lower. [05:58.560 --> 06:00.900] The administrative subpoena works sort of the same way. [06:00.900 --> 06:17.540] The court and the legislature has gone through what they view as non-content data and said, well, yep, if you send the subpoena, you're entitled to the name of the subscriber, their address, their local and long distance telephone connection records, the length that they've been a subscriber of that [06:17.540 --> 06:24.880] service and the types of services they subscribe to, and their specific telephone or instrument number, and their means and source of payment. [06:25.020 --> 06:29.240] And there's a few others, but this is kind of the the broad the broad spectrum. [06:31.580 --> 06:39.980] Importantly, under this same set of laws, under ECPA, there are other gigantic holes in what can be provided. [06:40.360 --> 06:54.720] One of it, which is the service can just can disclose basically whatever it wants to, it has the lawful consent of that subscriber, which is not in this slide, it is in the law. [06:55.200 --> 07:00.740] And so, you know, what I like to caution people about is if you're a user of these services, check the terms. [07:00.740 --> 07:06.300] If they say we can send whatever we want to law enforcement, then you've probably consented to that. [07:07.720 --> 07:13.360] There may be some limits, but it's, you know, one of those areas where it's not well, not well defined or well protected. [07:14.020 --> 07:29.460] There's also another carve out for if the provider in good faith believes that the disclosure is necessary for an emergency involving danger of death or serious physical injury, they can disclose. [07:29.780 --> 07:37.460] And most places carve this out in their terms as one of the sort of exceptions to their usual law enforcement response process. [07:40.080 --> 07:52.820] That is one of those things where if you are someone involved in the, you know, legal or security response to these requests, what the provider's good faith belief there and where you set that bar is a matter of internal policy. [07:53.900 --> 08:06.340] So as a matter of sort of policy advocacy, there's a lot of areas here where it's sort of up to the provider to determine how much rights they want to give themselves to respond either in public facing or internal policy documents. [08:08.580 --> 08:17.760] The other thing to be aware of is under ECPA, you know, all of this language kind of goes back to sort of old timey, almost like telephone service types of terms. [08:19.040 --> 08:24.000] So like connection records, instrument identifiers, don't be fooled by the plaintext. [08:25.080 --> 08:41.760] There's a number of cases, U.S. versus Forester is probably the kind of seminal case on this on this issue of, well, you know, and certainly this is what I thought when I very first encountered these laws was like, well, is an IP address a connection identifier? [08:41.760 --> 08:42.920] Is that like a phone number? [08:43.300 --> 08:48.280] Or is that not mentioned in the statute and therefore something that I can tell them to, you know, go pound sand about? [08:48.780 --> 09:11.660] The reality is that the courts, you know, both in a couple of larger name cases, and then in a very long, boring list of extremely obscurely named cases, like in Ray, the U.S. application for a search order from 2006, I think, have sort of analogized the specific language used in ECPA to cover everything that a modern Internet service would use. [09:14.280 --> 09:18.440] So, you know, your phone number becomes your IP address. [09:20.000 --> 09:23.720] There is some really interesting time hair splitting here about URLs. [09:25.460 --> 09:31.300] Instrument number is read to include your IP address, arguably includes MAC address and browser agent as those are non-content. [09:32.160 --> 09:33.340] URLs get interesting. [09:35.080 --> 09:43.220] If my request includes, you know, if I'm a law enforcement officer sending this to a platform and I say, give me a list of all the URLs this person's visited. [09:45.340 --> 09:49.240] Yahoo.com, probably fine because that's not content. [09:49.380 --> 09:51.080] That's just an address, just like a home address. [09:52.120 --> 09:59.720] Yahoo.com slash, you know, q equals my search terms, that query part of the URL, that's content. [09:59.920 --> 10:09.360] And courts have mostly agreed with this distinction of, you know, once you get into stuff that the user entered, you're now beyond an analogy to the phone number you dialed. [10:09.420 --> 10:10.820] You're getting parts of the conversation. [10:11.860 --> 10:26.740] And if we sort of walk back that analogy, one step in the tech, in sort of the technology tree, that goes back to cases with, um, I feel like this is, this is an ancient technology at this point, but have you ever used like a dialed phone menu? [10:27.080 --> 10:30.680] You know, you call up a number and the robot says, press one for this thing. [10:31.280 --> 10:37.740] The same laws interpreted for those phone numbers, those, what's called a post dialed digit. [10:38.000 --> 10:39.300] That's where we get this today. [10:40.040 --> 10:43.500] The same distinction applies of, you know, the number you dialed, fine. [10:43.660 --> 10:44.640] That's routing information. [10:44.840 --> 10:46.880] That's the, that's the cover of the envelope and the stamp. [10:47.480 --> 10:50.400] Those digits you dial afterwards are post dialed digits. [10:50.540 --> 10:53.680] That's content because that's the conversation you're having with the service. [10:55.080 --> 10:58.340] So this all sort of works by way of analogy to much older technologies. [10:59.240 --> 11:05.840] And in due course, the courts have sort of carried these forward to analogize to current technologies from the base language. [11:06.720 --> 11:14.420] The other place this comes up in terms of, uh, interesting areas where non-content information becomes very, very revealing. [11:14.940 --> 11:25.360] Um, someone gave a quick question, uh, before the talk started on, um, sort of, uh, John Doe lawsuits or other situations where the target is not necessarily identified. [11:25.740 --> 11:45.120] Uh, this comes up with VPN services where, um, the routing and log records may not contain any content per se, but they have the IP address of the exit from the VPN and they have the IP address of the logged in user, which is a very common route for law enforcement to identify unidentified [11:45.120 --> 11:57.400] individuals because all they really need is that routing information plus the subscriber information from the ISP or service provider providing that person with their sort of endpoint Internet service. [11:58.060 --> 12:00.540] It's a little tangent, but feels related. [12:01.000 --> 12:08.480] Um, in terms of like things that VPNs do that mess up sort of promises of anonymity, that is pretty high on the list. [12:09.660 --> 12:21.760] Um, and that is pretty much everything on subpoenas, uh, which I'm lingering on a bit longer because from that state, basically everything else is just that plus scope. [12:23.220 --> 12:30.720] So when we talk about 2703D orders, uh, the plain language of this law makes it sound like it reaches content. [12:31.160 --> 12:36.400] Uh, thanks to a case called U.S. v. Warshak, um, that is no longer true. [12:36.540 --> 12:41.980] The courts took a look at that and said, you know, even though the law says it gets content, that's not how the fourth amendment works. [12:41.980 --> 12:43.860] If you want content, you need, you need a warrant. [12:44.540 --> 12:52.540] Um, but you can sort of think of a 2703D order kind of like a, an administrative subpoena plus. [12:53.060 --> 12:57.980] So, um, it permits active collection. [12:58.020 --> 13:02.220] It permits sort of ongoing discovery requests being sent to the platform. [13:02.660 --> 13:09.300] Um, and it typically permits a wider scope because it's been signed, it's been sort of reviewed and signed off on by a judge. [13:09.700 --> 13:19.700] So, you know, a subpoena may be a relatively low bar of, you know, give us everything you have about this username for, you know, the last six months. [13:20.160 --> 13:20.560] Sure. [13:21.160 --> 13:24.060] Give us everything you have for this username for the last five years. [13:24.060 --> 13:24.700] Maybe not. [13:25.180 --> 13:31.380] If they come back with the deorder, that five years is probably more enforceable or at least harder to challenge. [13:32.540 --> 13:32.880] Um, [13:39.950 --> 13:42.650] and then likewise with search warrants, it's a higher bar. [13:42.830 --> 13:46.730] They have to be able to show probable cause, um, to get the search warrant ordered. [13:47.350 --> 13:52.130] The reality is that judges still tend to approve these things very readily. [13:52.810 --> 14:03.130] Um, and kind of equally importantly, there is no rule saying that if a judge says no to the officer's first request, you know, there, there's no three strikes and you're out. [14:03.270 --> 14:09.290] Yeah, that officer can go back with a new, you know, refined request, at least, you know, theoretically until they get it. [14:09.770 --> 14:18.190] Um, so warrants are not really like, it's a higher bar, but it's not a higher bar as much as you'd think it would be in practice. [14:19.190 --> 14:24.790] The thing with a warrant is also it certainly permits ongoing collection in the same way a deorder does. [14:25.130 --> 14:26.350] It reaches content. [14:26.730 --> 14:36.650] Um, so, you know, if in, in say, like, um, a private message board context, it would get that person's content of their messages. [14:36.690 --> 14:39.210] It would get, you know, chats they've had with people. [14:39.630 --> 14:43.230] It kind of reaches almost whatever they can get approval from, from the judge. [14:43.530 --> 14:50.370] And that includes, you know, ongoing collection and even on-site seizure of data, documents, records from the actual platform itself. [14:50.810 --> 14:53.170] So the potential reach of a warrant is quite broad. [14:53.990 --> 15:05.930] Um, there are some other, you know, I'm sort of really focusing this on the kind of ECPA and Stored Communication Act stretch here because that keeps the talk to a reasonable scope and length. [15:06.170 --> 15:08.530] There are definitely other types of discovery. [15:08.810 --> 15:13.750] Um, DMCA unmasking subpoenas under, uh, I think it's 17 U.S.C. [15:14.310 --> 15:24.270] 512H are another form of discovery that can be used to get, um, certain types of subscriber data in copyright infringement scenarios. [15:25.010 --> 15:29.010] Um, the other one that's sort of interesting to talk about is what's called the All Ritz Act. [15:29.330 --> 15:36.770] Um, if you were following the, uh, Apple encryption legal disputes a few years back, that's what that was about. [15:37.090 --> 15:42.010] And this is kind of an old legal right that is kind of like, it's almost like the fallback option. [15:42.390 --> 15:53.550] Uh, it's a law that basically says if there's no other way to get this, the, you know, law enforcement agency can seek an order under the All Ritz Act compelling certain kinds of, of disclosure or discovery. [15:54.150 --> 15:56.810] Um, that San Bernardino case is really interesting. [15:57.150 --> 16:05.790] Um, it's probably the best example to date that I can think of, of a sort of well-fought legal battle over things in this area. [16:06.330 --> 16:12.610] Um, in which Apple basically went back and said, hey, uh, encryption is a big thing that we market on. [16:12.750 --> 16:13.850] This is part of our business. [16:14.490 --> 16:18.530] You don't get this order because if you did, it would destroy our business model. [16:18.970 --> 16:23.150] Um, and they kind of litigated this out pretty fully, uh, which is rare. [16:23.850 --> 16:35.490] Um, but broadly speaking, you know, search warrants, 27 and 3D orders, these all kind of have the same basic mechanic of the request lands with the platform. [16:35.710 --> 16:44.090] The platform processes it in whatever way it's going to pushes back if it feels that's appropriate and, you know, submit some kind of response down the road. [16:46.310 --> 16:52.930] Um, since we have time, I will talk real quick about national security letters and FISA warrants. [16:53.230 --> 16:57.950] Um, full disclosure, I may or may not have signed a thing that says, I will never talk about these. [16:58.270 --> 17:04.950] Um, so I can neither confirm, firm nor deny that I've processed somewhere between zero to 10,000 of them. [17:05.410 --> 17:12.290] And, you know, that's kind of, that's kind of long and short of it is, um, the bad news is they're super secret. [17:12.510 --> 17:18.410] There is very little out there publicly on, you know, what they contain, what's done with them. [17:18.410 --> 17:30.730] Um, the reality is national, national security letters have about the same reach as, as an, as an administrative subpoena and a FISA warrant has about the same reach as a standard search warrant. [17:31.110 --> 17:43.250] It's just that the reporting and transparency on them are tightly restricted because these all go through the foreign intelligence surveillance courts and are, you know, subject to various national security restrictions on any sort of disclosure about them. [17:43.590 --> 17:47.170] Um, there've been, there's been some really interesting litigation about that. [17:47.550 --> 18:04.370] And, um, as a means of kind of getting to a place of slightly better transparency, those aggregate disclosures of, you know, this platform has received between zero and some number of thousands or hundreds of requests in the last year has now been approved, but it's been a very slow process getting there. [18:07.270 --> 18:18.510] Um, but I guess sort of the most encouraging thing I can say about them is in terms of what's actually accessed, it's not that different from these sort of traditional means. [18:18.950 --> 18:22.430] Um, so the same sort of methods and techniques for mitigating apply. [18:23.290 --> 18:25.570] Um, so let's talk about those. [18:25.810 --> 18:35.190] Um, you know, in terms of what legally must be done, the law is not great if you're the user of these platforms. [18:35.630 --> 18:44.650] Um, one thing that's important to note is almost all of this takes place under a gag order, even for a relatively informal letter request from law enforcement. [18:45.170 --> 18:54.930] Um, at GitHub, we had a policy, a sort of user facing policy of if there's not a legally binding gag order, we're going to tell the user that we've received this request. [18:55.350 --> 19:05.190] And usually the result of telling the requester that was if it was an informal letter with no court signed gag order on it, they'd withdraw the request. [19:05.890 --> 19:15.630] Um, and maybe 50% of the time come back with a deorder or a search warrant with a gag order attached. [19:15.930 --> 19:27.270] But the gag order rules are very permissive because they basically say, if there's any kind of ongoing investigation or this might tip that person or some other third-party off to a law enforcement action, you can't say anything. [19:28.410 --> 19:31.190] Importantly, they can't, they can't be forever anymore. [19:31.470 --> 19:34.950] Um, there was a period of time when those did not have a time cap on them. [19:35.530 --> 19:42.050] And now there is within, within these laws, a requirement that that gag order has to expire. [19:42.470 --> 19:48.150] It can be extended, but that's something that like that law enforcement officer has to actually go through each time. [19:48.150 --> 19:51.310] So it adds a little bit more hassle if they want to keep stuff secret. [19:52.210 --> 19:56.690] But the reality is that if you're a user of these platforms, you may not know any of this is even happening. [19:57.070 --> 20:04.370] Um, to the extent you will, you may find out, you know, one, two, three, five years after the disclosure has happened. [20:04.950 --> 20:17.130] Um, it is, I, you know, in my experience, it is an extremely unusual case for that gag order not to be attached in such a way that the person, that the end user can actually be told in time to do anything about it. [20:18.050 --> 20:28.030] So unfortunately, a lot of this really falls on the platform to, you know, say, hey, here's what we're going to do to minimize the exposure of our users to law enforcement data requests. [20:29.250 --> 20:35.070] And broadly speaking, within the bounds of what the law allows you to do, there are kind of three things you can do. [20:35.790 --> 20:41.830] The first one, and I feel like this is one of those trite but true kind of data privacy norms, minimize your data. [20:42.430 --> 20:44.590] You know, what do you really need to keep? [20:44.770 --> 20:46.510] How long do you really need to keep it? [20:46.990 --> 20:49.410] And if you don't need to keep it, get rid of it. [20:49.950 --> 20:50.070] Um, [20:53.510 --> 21:02.330] the general, you know, the general truth and that there are cases that have kind of enshrined this into law is, you know, you can't be asked to produce something that you don't have. [21:02.790 --> 21:10.410] And if you don't have it because you delete it after three weeks, as a matter of course, every time you can't be blamed for that. [21:10.970 --> 21:20.230] Now, if a preservation request or some kind of search of some sort of data demand comes in and then you delete it, that's going to go badly for you. [21:20.750 --> 21:30.970] But if this is part of your sort of general business practice of just, you know, removing data on a schedule that is as tight as it can be, that's a very effective way to minimize the amount of data that can be discovered there. [21:32.010 --> 21:32.290] Um, [21:35.510 --> 21:50.950] and, and sort of, you know, maybe this is not data minimization in the, like, industry sense per se, but other things in that sort of minimization state are, to the extent you can, you know, make these things that only the end user has power to provide the plain text of. [21:51.150 --> 21:57.590] You know, if you can end-to-end encrypt or otherwise put sort of plain text production in the hands of the user, all the better. [21:58.030 --> 22:07.870] You know, you can, again, because you can't be, except in very rare cases, you really can't be compelled to produce stuff beyond what you have access to. [22:08.410 --> 22:11.210] If that's in the hands of your user, that's going to be much harder to get. [22:14.820 --> 22:26.960] And that kind of gets into the second point, which is, for more sensitive data that you do need to keep on hand, the more difficult that is to get to, the more costly or time-consuming that is to access, the better. [22:29.240 --> 22:36.880] There is a, within this sort of broad umbrella of ECPA, one of the subsections, 2706, provides for cost reimbursement. [22:37.020 --> 22:47.300] So if I'm an online platform and the FBI comes and sends me a letter and says, hey, we need all your information on users who were logged in, you know, between these hours last Wednesday. [22:49.400 --> 22:52.980] It is within my right to write back to them and say, you know, we can do that. [22:53.080 --> 22:59.000] I don't see anything illegal in your request, but that's going to cost us, you know, 300 man hours at however many dollars an hour. [22:59.820 --> 23:03.700] Once you send the bill for, you know, three million, we'll get right on that. [23:04.500 --> 23:13.020] If your costs are reasonable and you, you know, and are sort of justifiable for the difficulty of getting that data, that's a legit thing to respond back. [23:13.260 --> 23:15.780] And now you've turned a free request into a budget item. [23:16.260 --> 23:27.160] And in my experience, that does a lot to dissuade those requests coming in, because most of those, you know, regional, federal offices, state law enforcement, they have a set budget for this. [23:27.640 --> 23:37.320] And when you, when you've sent the message that your production is no longer free, the amount of thought and process and time that goes into it on their end to say, hey, is this really worth it? [23:37.420 --> 23:39.320] Or are we just kind of fishing around to see what we can get? [23:40.160 --> 23:46.720] You set off a conversation there that usually ends with that request being, you know, revoked. [23:48.180 --> 23:48.820] Not always. [23:49.020 --> 23:50.400] And it's not as good as data minimizing. [23:50.700 --> 23:51.440] That's why it's number two. [23:51.940 --> 23:53.400] But it certainly helps. [23:57.440 --> 23:59.800] And then third is to push back. [24:00.020 --> 24:04.540] And when I say this, I want to really emphasize that fighting back doesn't need to look like fighting. [24:04.760 --> 24:07.680] In fact, it's usually better and more effective if it doesn't. [24:09.840 --> 24:24.340] You know, yes, this can mean and, you know, in certain circumstances, that Apple San Bernardino case being a great example, it does mean going to court, you know, carrying the legal spend to fight back and say, hey, we don't think you have a right to this data. [24:24.500 --> 24:24.980] Here's why. [24:25.800 --> 24:37.720] But kind of like I said earlier, I feel like from the viewpoint of the platform, and I think, you know, doubly or triply so for platforms without the legal budget that places like Apple have, that's rarely a good option. [24:37.880 --> 24:40.800] It's expensive, it's time consuming, it's risky, it's very public. [24:41.240 --> 24:44.400] You know, there's a whole host of reasons why this is not well litigated. [24:44.620 --> 24:47.480] And, you know, ideologically, I hate them. [24:47.920 --> 24:49.500] Practically, they're pretty good reasons. [24:51.720 --> 24:56.140] So when I say fight back, I don't necessarily mean in the court system unless you have to. [24:57.940 --> 25:11.980] It is a known issue that things like that emergency exception that says, hey, if it's a, you know, threat of death or serious injury, you can give them whatever, that is on record as being abused by people forging emergency search requests. [25:12.380 --> 25:18.420] So, you know, usually I would recommend for a platform looking to kind of improve their law enforcement response policy. [25:18.820 --> 25:23.940] The first thing is have a policy of writing back as soon as you can, saying, hey, is this legitimate? [25:24.000 --> 25:27.720] We got this request, but we want someone from your office to confirm that it's real. [25:28.760 --> 25:30.680] Because it does, first off, it does happen. [25:30.800 --> 25:35.040] And second off, now you've added a bit more friction in the mix and you've started a conversation. [25:38.980 --> 25:52.320] The other things, you know, I've actually had a lot of luck getting these narrowed down when, and I feel like this is more often a live issue with state or local level law enforcement requests. [25:53.680 --> 25:55.520] They will send very broad requests. [25:55.840 --> 26:09.640] And I've actually had a lot of luck getting these scoped down with just an informal email back saying, hey, we know you asked for this, but we think that's actually beyond the bounds of what you're entitled to under an administrative subpoena or goes beyond the language of the court order that you [26:09.640 --> 26:12.300] actually sent us a copy of for a deorder or for a warrant. [26:14.020 --> 26:29.540] And my experience, especially at the federal level, law enforcement tends to be pretty receptive to that because what they don't want is, you know, six months, two years down the road, when the user finds out this has been produced, they don't want that reactive battle over whether it's admissible. [26:29.740 --> 26:31.780] They want to be sure from day one, it's admissible. [26:32.080 --> 26:45.180] So usually those, those, you know, if that's coming from company legal or someone within the company, that's usually treated with some respect and engaged with, and often can narrow that scope to, you know, usually not nothing, unless it's a really ridiculous request, [26:45.400 --> 26:50.540] but usually narrows it from something crazily overbroad to something at least colorably legal. [26:53.940 --> 26:59.080] On the topic of what not to do, how many of you have, how many of you have heard of Lavabit? [27:00.520 --> 27:02.580] That is actually more hands than I expected. [27:03.460 --> 27:05.000] So you might know this story already. [27:05.340 --> 27:09.420] They are my favorite example of what not to do in response to a government request for data. [27:09.420 --> 27:22.700] So for those of you who are not familiar, Lavabit was an encrypted messaging program run by a fellow named Ladder Levinson, and probably most notably used by Edward Snowden. [27:24.040 --> 27:35.760] And the short version of what happened is after Snowden's leaks were made public, the government went to Lavabit and said, hey, we think that this person was corresponding on your service. [27:36.240 --> 27:39.720] We want you to give us the content of those of that correspondence. [27:40.680 --> 27:43.780] And Levinson basically said, well, that's all SSL encrypted. [27:45.160 --> 27:46.360] And that's core to my business. [27:46.500 --> 27:48.160] This is an encrypted private chat program. [27:48.200 --> 28:02.740] If you make us reveal this, you know, we're hosed, we're done, which is all well and good, except the way that Lavabit did it was to ignore and avoid these requests for as long as possible, including, and maybe this is apocryphal, but it's the story that I heard. [28:02.860 --> 28:14.180] So I'm going to repeat it uncritically, including up to at some point when the FBI came to his door with, you know, papers to serve for discovery, Levinson running out the back door and disappearing. [28:15.040 --> 28:15.900] Don't do that. [28:16.080 --> 28:17.440] It doesn't look good in court afterwards. [28:19.520 --> 28:32.260] When this was eventually, you know, brought to court, what that meant was the judge looked at this person as an untrustworthy actor who couldn't be, you know, relied on to comply in good faith. [28:32.860 --> 28:34.960] They ordered the SSL keys turned over. [28:36.040 --> 28:47.040] Levinson produced the SSL keys in a printed out hard copy paper format, which was also not as appreciated by the court as it might be by privacy advocates. [28:48.580 --> 28:53.940] And long story short, had to shut down the service in order to not disclose this information. [28:54.480 --> 28:58.940] And in the meantime, bought himself a whole lot of legal bills and probably years of legal trouble afterwards. [28:59.700 --> 29:00.680] So don't do that. [29:03.000 --> 29:07.840] You know, it's an interesting story, because at the end of the day, I think the information was protected. [29:08.560 --> 29:14.380] But the amount of harm it did to people advocating for better data privacy in this space is still with us today. [29:16.260 --> 29:19.540] You know, there are sort of ways to fight this and ways to litigate this. [29:19.700 --> 29:24.560] And that is really not the way you want to start out, because it sort of ruins the credibility going forward. [29:24.560 --> 29:26.540] If you're saying, hey, here's why we can't do this. [29:27.240 --> 29:33.280] The Apple case with San Bernardino, you know, budgetary differences aside is a much better example of what to do. [29:33.600 --> 29:38.540] You know, they showed up in court, they said, hey, here's a list of reasons why we can't do this. [29:38.920 --> 29:41.480] And why if you force us to do this, it will destroy our business. [29:42.280 --> 29:48.060] And, you know, it's almost, it's funny, because it's almost word for word, the same basic concepts that Lavabit was saying. [29:49.080 --> 29:58.520] But the means by which they did it meant they actually had credibility with the court, had an ability to kind of carry that litigation process through, and get some successes on, you know, what was being argued. [30:05.270 --> 30:10.370] And that, that more or less gets us to the whole of the subject. [30:11.910 --> 30:15.270] If you have further questions, my contact info is up there. [30:16.530 --> 30:18.410] I am reachable on email and Signal. [30:19.810 --> 30:25.150] I meant to put my PGP key up there, just in case anyone's still using that, but Signal's just fine. [30:27.390 --> 30:36.970] And then I did put up some additional resources and links to some of these laws and case citations and things up on the GitHub as well, if you want to, you know, dig in further. [30:37.930 --> 30:41.210] So yeah, if there are any questions, please come to either of the mics and we'll take them in turn. [30:53.100 --> 30:54.160] I absolutely can. [30:54.380 --> 30:57.420] So the question was, can you speak to the practice of warrant canaries? [30:58.400 --> 30:59.580] Warrant canaries are great. [30:59.800 --> 31:01.320] I've done some work for clients on those. [31:02.420 --> 31:10.880] The basic idea of a warrant canary, for those not familiar, is a line somewhere on the website that says, we have not received any government search requests. [31:11.280 --> 31:19.200] The idea being, much like a canary in a coal mine, if that, if that line expires or goes away, you know that that site has received a request. [31:20.720 --> 31:21.520] They're great. [31:21.940 --> 31:30.440] Last I looked into the case law on them, while gag orders for searches are well supported, the government cannot compel false speech. [31:30.780 --> 31:35.560] And if the canary is just deleted, you know, that's just keeping your speech truthful. [31:36.160 --> 31:38.440] So like, their legal ground is pretty good. [31:39.620 --> 31:54.800] I think the weakness of warrant canaries is they're a sort of, they're kind of all or nothing for things like, you know, national security letters or FISA warrants being a great example, where you can't say in your, like, yearly transparency reporting, we got three of these this year and here's the accounts they were for. [32:00.260 --> 32:02.480] The warrant canary is just kind of all or nothing. [32:03.040 --> 32:20.880] And, you know, if I'm a widely used messaging service providing private chats to my users, use, there's no way for those users to tell the difference between, you know, hey, we got a letter from the sheriff's office in Las Vegas, Nevada, asking about this one person who used the service once six [32:20.880 --> 32:33.800] years ago versus, you know, six different FBI field offices that have asked us for blanket discovery on everyone using the service, you know, for the month of April last year, you know, the warrant canary disappears the same way for both of those. [32:33.800 --> 32:36.560] And there's not a way to give nuance to that through that method, really. [32:37.080 --> 32:41.200] Um, so yeah, that's sort of the, my long insurance warrant canaries generally for them. [32:41.280 --> 32:43.720] They're just, you know, they're not perfect, but they can't be so. [32:48.060 --> 32:48.540] Yes. [32:48.540 --> 32:50.780] So, um, oh, great. [32:51.280 --> 33:12.960] Uh, if I recall correctly about the Apple San Bernardino case, one of the arguments that Apple made was that similar to the warrant canary situation, the government telling them to create software to crack their own encryption would have been compelling them to perform a First Amendment protected [33:12.960 --> 33:14.340] expression, right? [33:14.600 --> 33:17.840] They'd be writing source code to do this thing. [33:18.060 --> 33:28.300] And so that is another situation where the first, you know, First Amendment protections have stood against this kind of ask for information. [33:28.300 --> 33:36.020] Are there other situations like that where other kinds of fundamental rights rights or constitutional rights conflict other than like Fourth Amendment protections? [33:36.360 --> 33:51.660] Uh, so outside the Fourth Amendment, the only other thing that comes to mind sort of off the top of my head is in the, um, legal and policy disputes, which I believe included, and I forget if it was EFF or EPIC or both who had sort of long running lawsuits on this issue. [33:52.220 --> 34:03.060] Um, but I, I, I sort of briefly referenced the kind of long fought and eventually kind of won, uh, battle for transparency around national security letters and Pfizer requests. [34:03.440 --> 34:19.620] Um, that was also based on First Amendment issues saying, hey, you know, we have a speech interest in being able to, you know, tell our users what kind of, you know, requests we've received, let them know if those are hitting our service. [34:20.260 --> 34:22.180] Um, so it's come up, it came up there. [34:22.400 --> 34:28.540] I don't know if it was as much of a factor as it is with, say, a Warrant Canary or the All Ritz Act case. [34:28.800 --> 34:34.100] Um, I found that Apple case really interesting because there's like six different moving parts, all of which get really complicated. [34:34.560 --> 34:39.940] Um, including the fact that Apple has voluntarily decrypted lots of other stuff before that. [34:40.640 --> 34:42.540] Um, yeah, I don't know. [34:42.680 --> 34:47.580] Uh, that's the only other First Amendment thing I can think of off the top of my head on that. [34:51.250 --> 34:51.730] Great. [34:52.730 --> 34:53.050] Okay. [34:53.190 --> 34:57.670] The first one, uh, is what kinds of requests do you get at ZocDoc? [34:59.230 --> 35:00.810] Ah, interesting question. [35:01.150 --> 35:04.530] Um, so, oh, and there goes the battery. [35:04.910 --> 35:15.830] Uh, so it was interesting because, um, you know, one of the kind of soft factors here is law enforcement agencies talk to each other, right? [35:16.250 --> 35:20.350] You know, FBI talks to state police, state police talks to their local field offices. [35:20.950 --> 35:23.690] Um, there's a lot of community back and forth there. [35:24.110 --> 35:26.870] And at GitHub, we got a very high volume of requests. [35:27.250 --> 35:38.030] And the origin story, it was like a year or two before my time, but the origin story was basically, you know, first we got a few of these and we responded and, you know, sort of had our process. [35:39.110 --> 35:43.690] And because it's a site where a lot of people post, uh, let's call them dual use security tools. [35:44.130 --> 35:58.070] Um, they got a lot more, they, you know, basically like long story short, it, it grew exponentially in terms of request volume because the first few requests law enforcement realized, Hey, there's actually a lot here and a lot of it's non-content. [35:58.190 --> 36:02.350] We can get like actually a pretty good amount of data from this service that is useful in these investigations. [36:03.110 --> 36:04.850] And so it grew rapidly over time. [36:05.310 --> 36:10.610] Um, because ZocDoc is really mainly providing sort of healthcare booking and appointment services. [36:11.070 --> 36:14.330] Um, the volume of request was much lower. [36:14.690 --> 36:16.770] The amount of useful information was much lower. [36:17.030 --> 36:28.190] Um, primarily things with like the state attorney general's office involving say like investigations into some healthcare providers, arguably legal practices was like the type of request we got. [36:31.500 --> 36:31.920] Awesome. [36:33.320 --> 36:34.500] Second matrix question. [36:34.700 --> 36:46.220] Do you think a lava bit size company could have fared as well as Apple with a similar strategy or was size and depth of pocket a significant factor there too? [36:46.660 --> 36:48.180] Oh, that's a really interesting question. [36:48.500 --> 36:51.680] Um, I, I'm going to repeat it because I want to make sure I heard it right too. [36:51.880 --> 36:55.800] Um, I think what I heard was, um, oh, oh, even better. [36:55.860 --> 36:56.880] I'll, I'll read it verbatim. [36:56.880 --> 37:05.560] Um, do you think a lava bit sized company could have fared as well as Apple with a similar strategy or was it a depth of pocket and, you know, size of company issue? [37:06.420 --> 37:11.020] Um, that's a really interesting question to try and like sort of armchair lawyer about. [37:11.400 --> 37:13.740] Um, there are somewhat different situations. [37:14.280 --> 37:17.760] Um, they're very different use cases and levels of urgency. [37:18.420 --> 37:23.280] They're also separated by six-ish years, I think if memory serves. [37:23.640 --> 37:40.180] So the law had moved a bit in those times, you know, if I can, if I can fight that hypothetical just a tiny bit and say, you know, if lava bit happened at the same time that Apple did and pursued a similar, uh, excuse me, strategy, I don't know if they would have fared as well as Apple because of [37:40.180 --> 37:41.820] that depth of depth of pocket issue. [37:42.220 --> 37:44.280] I think they certainly could have fared much better. [37:44.400 --> 37:52.720] And I think more importantly, they could have not set back the precedent in this area the way that they, you know, inadvertently did by their actions. [37:53.420 --> 37:59.660] Um, and I think that's sort of where I'd come down at it is, you know, they may not have won the day in the same way. [37:59.760 --> 38:05.920] They may still have ended up in the situation they did, which was, hey, we have to shut down or else all of our users' privacy is compromised. [38:06.980 --> 38:11.400] But they could have fought to that point, you know, in a way that did less collateral damage basically. [38:13.420 --> 38:14.040] Yes. [38:14.740 --> 38:21.480] So for foreign services, because a lot of, um, email services these days, they're not based in the United States. [38:21.600 --> 38:23.000] ProtonMail is a big example. [38:24.760 --> 38:41.400] If law enforcement wants to get a warrant for, um, an American's data being stored on a server in Switzerland or Germany, I imagine that they have to go through German courts, but do they also have to go through American courts? [38:41.500 --> 38:42.720] To what extent is it different? [38:42.960 --> 38:48.860] Uh, so you've got, you've touched a topic that I meant to get to and jumped over, which is called an MLAT request. [38:49.140 --> 38:52.760] It's a mutual legal assistance treaty is what the acronym unpacks too. [38:53.040 --> 38:58.740] And this is the means by which one country sends a legal request, like a warrant to another. [38:59.260 --> 39:06.500] Um, the details of exactly what is agreed to in those MLATs differs from, you know, country to country. [39:06.980 --> 39:27.400] Um, I think generally speaking, it is a little bit like an extra extradition request standard, you know, obviously not for the haul the person to a different country part of it, but for the, um, you know, there are exceptions, but typically the foreign countries agreement under an MLAT will usually [39:27.400 --> 39:34.540] be, you know, similar to extradition standard where like, if it is criminal in our country, we'll honor this request. [39:34.960 --> 39:39.160] If the thing you're asking for is not permitted under our laws, we probably won't. [39:39.640 --> 39:42.680] Um, but again, that varies from country to country. [39:43.000 --> 40:00.860] Um, so like off the top of my head, I don't have a like specific answer to, you know, if it's an American person's data that is resident, like the data which is residing in Germany, for example, which is a good example because Germany is relatively data protective as countries go. [40:01.300 --> 40:20.960] Um, I couldn't tell you like with that hypothetical, but, um, generally there is a process and same, you know, same thing if Germany sends a request to a U.S., uh, law enforcement agency, you know, they will process that through U.S. courts, which will approve or deny the request or modify it as needed. [40:21.220 --> 40:26.020] Um, so yes, there's sort of a complicated multiple systems process there. [40:26.220 --> 40:37.720] Um, but except for countries with which, you know, the requesting country has no mutual legal assistance treaty, there is a process by which those can be, you know, sent out. [40:38.100 --> 40:46.180] Um, which also touches on like another really interesting issue of, um, kind of peripheral to data minimization, which is data sovereignty. [40:46.640 --> 41:00.840] You know, there are certainly examples of, I'm thinking of like, um, VPNs which base themselves in places like the Seychelles because there are no, no MLATs with, you know, that territory. [41:01.280 --> 41:09.760] And the idea of, well, if all this data travels through a place with which, you know, where which the U.S. cannot get to that data, then the users are much safer. [41:09.960 --> 41:21.400] So that's another place where like, if you're designing a very privacy focused platform of one type or another with users in mind, you know, thinking about where that data lives and where that data travels through is also very important. [41:33.230 --> 41:33.910] All right. [41:34.250 --> 41:35.130] No more questions. [41:35.290 --> 41:35.610] Thank you all.