259 F.R.D. 449 (C.D. Cal. 2009)
In 2006 Lori Drew, a resident of O’Fallon, Missouri, joined others in registering a MySpace profile for a fictitious sixteen-year-old boy named “Josh Evans” and posted a photograph of an actual boy without his knowledge or consent.1
The conspirators used the profile to contact thirteen-year-old Megan Meier, a classmate of Drew’s daughter, and exchanged flirtatious messages for several days.2 On October 16, 2006, they sent a final message stating that “the world would be a better place without her in it.”3 Later that day, after learning of Megan’s suicide, Drew caused the Josh Evans account to be deleted.4
MySpace required prospective members to check a box affirming agreement to its Terms of Service and Privacy Policy during registration.5 The full text of the terms appeared only after clicking a separate “Terms” hyperlink and was not mandatory reading.6 The 2006 Terms of Service prohibited providing false registration information, creating fake profiles, posting photographs without consent, and using the service for harassment or tortious activity. They also reserved to MySpace the unilateral right to restrict or terminate access for any reason.7 All member data and communications were stored on servers located in Los Angeles County, and every message sent between members was routed through those servers.8
A three-count indictment charged Drew with one count of conspiracy and three counts of violating the felony provisions of the Computer Fraud and Abuse Act, 18 U.S.C. §§ 1030(a)(2)(C) and 1030(c)(2)(B)(ii), on the theory that creating and using the fake profile constituted accessing MySpace computers without authorization or in excess of authorization.9 At trial the jury received instructions on the lesser-included misdemeanor offense under 18 U.S.C. §§ 1030(a)(2)(C) and 1030(c)(2)(A).10 The jury deadlocked on the conspiracy count, acquitted Drew of the three felony CFAA counts, and convicted her of the three misdemeanor CFAA counts.11
Drew thereafter moved under Federal Rule of Criminal Procedure 29(c) for judgment of acquittal, contending that the only evidence of unauthorized access was the deliberate violation of MySpace’s Terms of Service.12 The court heard testimony from MySpace’s Vice President of Customer Care describing the registration process, the content and enforcement of the terms, and the volume of accounts created daily, then took the motion under submission.13
Whether an intentional breach of an Internet website’s terms of service, without more, is sufficient to constitute a misdemeanor violation of the Computer Fraud and Abuse Act under 18 U.S.C. § 1030(a)(2)(C)?14
The misdemeanor CFAA violation under 18 U.S.C. § 1030(a)(2)(C) consists of three elements.15 First, the defendant intentionally accesses a computer without authorization or exceeds authorized access.16 Second, the access involves an interstate or foreign communication.17 Third, the defendant obtains information from a protected computer used in interstate or foreign commerce.18 The term 'without authorization' is undefined in the statute but encompasses access that lacks permission from the computer owner.19 A website's terms of service can define the scope of authorized access when users affirmatively agree to them during registration.20
Yes. In 2006 Lori Drew, a resident of O’Fallon, Missouri, joined others in registering a MySpace profile for a fictitious sixteen-year-old boy named “Josh Evans” and posted a photograph of an actual boy without his knowledge or consent.21 The conspirators used the profile to contact thirteen-year-old Megan Meier, a classmate of Drew’s daughter, and exchanged flirtatious messages for several days before sending a final message on October 16, 2006, stating that “the world would be a better place without her in it.” Later that day, after learning of Megan’s suicide, Drew caused the Josh Evans account to be deleted.
MySpace required prospective members to check a box affirming agreement to its Terms of Service and Privacy Policy during registration, although the full text of the terms appeared only after clicking a separate “Terms” hyperlink and was not mandatory reading. The 2006 Terms of Service prohibited providing false registration information, creating fake profiles, posting photographs without consent, and using the service for harassment or tortious activity. They also reserved to MySpace the unilateral right to restrict or terminate access for any reason. All member data and communications were stored on servers located in Los Angeles County, and every message sent between members was routed through those servers.
The only basis for finding that Drew intentionally accessed MySpace's computer/servers without authorization and/or in excess of authorization was her and/or her co-conspirator's violations of the MSTOS by deliberately creating the false Josh Evans profile, posting a photograph of a juvenile without his permission and pretending to be a sixteen year old O’Fallon resident for the purpose of communicating with Megan.22 The court applied the rule that a website owner may define authorized access through terms of service to these specific facts of the profile creation and message routing through Los Angeles servers, concluding that the breach satisfies the first element of the misdemeanor offense.23
An intentional breach of an Internet website’s terms of service, without more, is sufficient to constitute a misdemeanor violation of the Computer Fraud and Abuse Act under 18 U.S.C. § 1030(a)(2)(C).24
Whether the Computer Fraud and Abuse Act is unconstitutionally vague when interpreted to criminalize conscious violations of a website’s terms of service?25
A statute is unconstitutionally vague if it fails to provide a person of ordinary intelligence fair notice of what is prohibited or is so standardless that it authorizes or encourages seriously discriminatory enforcement.26 The void-for-vagueness doctrine requires relatively clear guidelines as to prohibited conduct and objective criteria to evaluate whether a crime has been committed. Scienter requirements may alleviate vagueness concerns but do not eliminate the need for minimal guidelines to govern law enforcement.
Yes. The facts establish that Drew's conviction rested solely on conscious violations of MySpace's Terms of Service through creation of the fake profile and communications with Megan Meier.27 Interpreting the CFAA to criminalize any such breach would expose millions of users to prosecution for commonplace infractions such as providing inaccurate age information or posting photographs without consent, none of which involve hacking or code-based circumvention.28 The court applied the rule to these specific facts of the registration checkbox process, the non-mandatory hyperlink to the full terms, and the broad prohibitions in the MSTOS, concluding that the statute fails to provide fair notice and lacks minimal guidelines for enforcement because website owners effectively define criminal conduct through changeable contractual terms.29
The absence of any requirement that the website owner report the violation or that actual loss occur further confirms the standardless sweep that permits arbitrary prosecution.30
The Computer Fraud and Abuse Act is unconstitutionally vague when interpreted to criminalize conscious violations of a website’s terms of service.31