Showing posts with label infosec. Show all posts
Showing posts with label infosec. Show all posts

04 May 2014

Yahoo Sports pages leaking browser tab with links to Backyard, Yahoo's internal network

[12/27/2015 UPDATE]: The browser tab is showing up again this afternoon...

[9/30/2014 UPDATE]: This blog post has been getting a ton of hits lately, because the Backyard browser tab is leaking to the Internet, again (Backyard is apparently some version of Yahoo's internal network). Presumably, everyday Internet users like you and me shouldn't be seeing this. See the details below from May.


Here's a screenshot from September 30, 2014. You see the tab at the bottom right:


I'm moderately impressed by how quickly Yahoo responded to my tweet:


The tab shows up at the bottom right of the browser when visiting Yahoo Sports using Chrome. I could not duplicate the behavior in Firefox or Chrome.

Here is the tab:


And here are the links from the tab:

Y! Confidential: https://backyard.yahoo.com/globalcomms/Confidential.html
Megaphone: https://backyard.yahoo.com/qna/sports-grandslam-feedback/moderator
Bug: http://tiny.corp.yahoo.com/PDk61L

It appears that this behavior has been going on for at least a few days.

12 April 2014

Law in Plain English: United States v. Auernheimer

This is one in a series of posts designed to describe court decisions in plain English. For more detail and background on the legal issues, see the link to the case below. For similar posts, click here.

Case: United States v. Andrew Auernheimer

Argument: Mar 13, 2014 (Aud.)

Background: Andrew Auernheimer ("Weev") was convicted of violating the Computer Fraud and Abuse Act (CFAA) by collecting the email addresses of iPad customers through an "account slurper" program.

Issues: (1) Did Auernheimer and Spitler access a computer “without authorization” under 18 U.S.C. § 1030(a)(2)(C)?

(2) If Auernheimer was properly convicted of a conspiracy to violate the CFAA, was that conspiracy a misdemeanor or a felony?

(3) Did Auernheimer violate the identity theft statute, 18 U.S.C. § 1028(a)(7)?

(4) Was venue proper in the District of New Jersey?

(5) Do AT&T’s costs in mailing a letter to its customers support an eight-level upward adjustment under the United States Sentencing Guidelines? 

Holding: The Third Circuit ruled that trying Auernheimer in New Jersey, where no elements of the crime occurred, denied Auernheimer’s substantial right to be tried in the place where his alleged crime was committed. As a result, it reversed the decision of the District Court and vacated his conviction. Weev was released on Friday night to the custody of his lawyer, Tor Ekeland.

It is important to note that the Third Circuit did not rule on the CFAA in this case. Venue is a threshold issue; by deciding the venue was improper, the District Court never had jurisdiction to hear the case. Venue is a procedural matter that doesn't go to the substance of the underlying charges. That is why it is possible that Weev could likely be charged again without violating double jeopardy, see i.e., Haney v. Burgess, 799 F.2d 661 (11th Cir. 1986) (retrial of a defendant whose conviction was reversed because of improper venue does not violate double jeopardy).


Date Proceedings and Orders
Jan 13 2011 Criminal Complaint
Jun 22 2011 Plea Agreement with Daniel Spitler
Aug 16 2012 Superseding Indictment
Sep 21 2012 Memorandum of Law in Support of Defendant's Motion's to Dismiss
Oct 5 2012 Brief in Opposition to Defendant's Motion to Dismiss
Nov 20 2012 Trial Verdict
Dec 3 2012 Memorandum of Law in Support of Defendant's Motion for a Judgment of Acquittal Under Federal Rule of Criminal Procedure 29
Mar 17 2013 Defendant's Sentencing Memorandum
Mar 19 2013 Judgment
Jul 1 2013 Appellant's Opening Brief
Jul 8 2013 Amicus Brief of Mozilla Foundation, Computer Scientists, and Security and Privacy Experts
Jul 8 2013 Amicus Brief of Security Researchers
Jul 8 2013 Amicus Brief of Digital Media Law Project
Jul 8 2013 Amicus Brief of National Association of Criminal Defense Lawyers
Aug 5 2013 United States’ Motion for a Word Limit Extension to 26,500 Words and A Stay of the Briefing Schedule
Aug 5 2013 Opposition to United States' Motion for A Word Limit Extension to 26,500 Words and Stay of Briefing Schedule
Aug 6 2013 Reply To Appellant’s Opposition To United States’ Motion For A Word Limit Extension And Stay of Briefing Schedule
Sep 20 2013 Brief of Appellee (United States)

22 February 2014

Email from President Wallace D. Loh, University of Maryland, College Park regarding security breach of 300,000 records

From: President Wallace D. Loh 
Sent: Wednesday, February 19, 2014 6:06 PM
Subject: UMD Data Breach

February 19, 2014

Dear students, faculty, and staff of the University of Maryland (at College Park and Shady Grove):

Last evening, I was notified by Brian Voss, Vice President of Information Technology, that the University of Maryland was the victim of a sophisticated computer security attack that exposed records containing personal information.

I am truly sorry.  Computer and data security are a very high priority of our University.

A specific database of records maintained by our IT Division was breached yesterday.  That database contained 309,079 records of faculty, staff, students and affiliated personnel from the College Park and Shady Grove campuses who have been issued a University ID since 1998. The records included name, Social Security number, date of birth, and University identification number.  No other information was compromised -- no financial, academic, health, or contact (phone, address) information.

With the assistance of experts, we are handling this matter with an abundance of caution and diligence.  Appropriate state and federal law enforcement authorities are currently investigating this criminal incident.  Computer forensic investigators are examining the breached files and logs to determine how our sophisticated, multi-layered, security defenses were bypassed.  Further, we are initiating steps to ensure there is no repeat of this breach.

The University is offering one year of free credit monitoring to all affected persons.  Additional information will be communicated within the next 24 hours on how to activate this service.

University email communications regarding this incident will not ask you to provide personal information.  Please be cautious when sharing personal information.

We have established a website with FAQs at www.umd.edu/datasecurity.   Any updates will be posted to this site.  If you have any questions or comments, please call our special hotline at 301-405-4440 or email us at datasecurity@umd.edu.

Universities are a focus in today's global assaults on IT systems.  We recently doubled the number of our IT security engineers and analysts.  We also doubled our investment in top-end security tools.  Obviously, we need to do more and better, and we will.

Again, I regret this breach of our computer and data systems.  We are doing everything possible to protect any personal information that may be compromised.

Sincerely,

Wallace D. Loh
President, University of Maryland

21 January 2014

Shmoocon Firesides 2014 (Having Your Cake and Eating It Too: FOIA, Surveillance, and Privacy)

A correction to my talk: the pen register was installed by the police to record the numbers dialed from the telephone at Smith's home; not to record the numbers received by the telephone at the victim's home.

11 January 2014

ShmooCon 2014 Travel ProTips: Arrivals

First of all, keep in mind that  two stations on the Red Line, including Dupont Circle (which is the closest stop to the Hilton), will be closed all weekend for maintenance. It is unclear when on the 17th this maintenance will start, so you might be able to get to the Hilton from Dupont Circle on Friday if the maintenance shutdown doesn't start until later on Friday. Stay tuned, and I'll update this post when more information becomes available. You might be better off looking into Super Shuttle or some other means from the airport and avoiding the Metro.

If you still intend on riding Metro, you'll have to disembark the Red Line at Woodley Park (if you're coming from the north) or Metro Center (if you're coming from the south); alternatively, you could ride the Orange Line to Farragut West. From there, you'll have to walk to the Hilton or take a cab or Uber.

Arriving via DCA (Reagan National)? Take the Yellow Line to L'Enfant Plaza and then the Orange Line to Farragut West. Walk/cab/Uber to the Hilton.

Arriving via IAD (Dulles)? The Metro doesn't reach out that far yet. Try the Super Shuttle or take a cab to somewhere along the Orange Line. Take the Orange Line to Farragut West. Walk/cab/Uber to the Hilton.

Arriving via BWI? Take the MARC Penn Line to Union Station, then follow the directions below via Union Station. The MARC Penn Line schedule is here.

Alternate BWI method: Alternatively, you can take the B30 bus from BWI to Greenbelt, then hop on the Metro Green Line.

Arriving via Union Station? Take the Red Line to Metro Center, then the Orange Line to Farragut West. Walk/cab/Uber to the Hilton. Alternatively, cab/Uber to the Hilton from Union Station.

A few extra tips:

Metro trains run less frequently on the weekends. You can expect to wait 10-20 minutes (or more) for a train.

As of December 2013, the MARC Penn Line runs a limited weekend schedule.

"DC Metro Rails" is a useful Android app for Metro arrival times. There are several similar ones for the iPhone.

If you have any other questions about travel in the local area, don't hesitate to ask. You can find me on Twitter at @theprez98.

08 January 2014

ShmooCon 2014 Travel ProTips: Metro closures

If you're traveling to Shmoocon next week, take into account that two stations on the Red Line, including Dupont Circle, will be closed all weekend for maintenance.

Update: The maintenance window starts at 10PM on Friday, so you should be fine if you're traveling before then.

24 December 2013

Disney's Windows application crashes, exposes data?


While on-board our Disney cruise, we visited an area of the ship where Disney provides kiosks or large touchscreen monitors that display photographs that have been taken of you (or your party). To access the photographs, you swipe your "Key to the World" card. Except when the "PhotoFinder" program crashes (see first image below). And when the card reader program exposes folio numbers (see second image below).

I have no idea if or how the "folio numbers" relate to individual customers or their "Key to the World" cards. I don't know if this data could lead to exposure of customer data, because, although I am curious, I wanted to enjoy my cruise and didn't investigate further. But it does demonstrate that data leaks can happen when programs crash.

One other thing: the touchscreen displays appear to be covered at the bottom by an inch or so--presumably so that your fingers don't activate the "Start" menu. But this is just a guess (and, it doesn't work!).

Oh, and in case you're wondering: I re-started PhotoFinder. :-)


16 December 2013

ShmooCon Firetalks submission


In Washington, DC, the federal government is arguing against a prolific Freedom of Information Act (FOIA) requester that his multitudinous requests, taken together, constitute a "mosaic" of information whose release could "significantly and irreparably damage national security" and would have "significant deleterious effects" on the bureau's "ongoing efforts to investigate and combat domestic terrorism." In the District of Columbia, the federal government is defending the legality of the intelligence community's surveillance programs under a 1979 Supreme Court case, Smith v. Maryland, that found constitutional use of a “pen register” device to gather information on numbers called by a criminal suspect. So, yes: the government is simultaneously arguing to that too much otherwise-legitimate FOIA data creates a mosaic that threatens national security--but large scale metadata collection, far beyond anything contemplated by a simple pen register device in 1979--is perfectly legitimate. Is this a problematic dichotomy? And if so, what can we do about it?

23 November 2013

Here are my ShmooCon submissions

I made two submissions to ShmooCon this year. The first is a full-fledged talk and the second is a "One Track Mind" 20-minute talk. Here are the abstracts, and wish me luck!

©opyright Gone Wrong: Our Broken System and How We Can Fix It

The Constitution grants the Congress the power to enact intellectual property laws "[t]o promote the Progress of Science and useful Arts, by securing for limited Times to Authors and Inventors the exclusive Right to their respective Writings and Discoveries." Since the founding of our country, protection of intellectual property has undergone several systematic changes that have extended the time rights are protected. Additionally, protections have gotten increasingly aggressive and oppressive. This presentation will briefly discuss the history and development of IP law, and then focus on the more recent and onerous provisions that have become embroiled in controversy. Along the way, we'll talk about the Digital Millennium Copyright Act,  copyright and patent trolls, and other methods of intellectual property abuse. Lastly, we will take a look at some of the ways we can reform our broken system to free consumers from burdensome restraints, while at the same time protecting the intellectual property of the creators.


In Washington, DC, the federal government is arguing against a prolific Freedom of Information Act (FOIA) requester that his multitudinous requests, taken together, constitute a "mosaic" of information whose release could "significantly and irreparably damage national security" and would have "significant deleterious effects" on the bureau's "ongoing efforts to investigate and combat domestic terrorism." In the District of Columbia, the federal government is defending the legality of the intelligence community's surveillance programs under a 1979 Supreme Court case, Smith v. Maryland, that found constitutional use of a “pen register” device to gather information on numbers called by a criminal suspect. So, yes: the government is simultaneously arguing to that too much otherwise-legitimate FOIA data creates a mosaic that threatens national security--but large scale metadata collection, far beyond anything contemplated by a simple pen register device in 1979--is perfectly legitimate. Is this a problematic dichotomy? And if so, what can we do about it?

20 November 2013

Having your cake and eating it too: FOIA, surveillance, and individual privacy


It seems pretty obvious now (if it hasn't already been for a long time!) that the government wants to have its cake and eat it, too. On one hand, the federal government is arguing against a prolific Freedom of Information Act (FOIA) requester:
...the FBI claims that Shapiro's multitudinous requests, taken together, constitute a "mosaic" of information whose release could "significantly and irreparably damage national security" and would have "significant deleterious effects" on the bureau's "ongoing efforts to investigate and combat domestic terrorism."
Disparate items of information, though individually of limited or no utility to their possessor, can take on added significance when combined with other items of information. Combining the items illuminates their interrelationships and breeds analytic synergies, so that the resulting mosaic of information is worth more than the sum of its parts.
On the other hand, in response to claims that the NSA's metadata collection program violates the Fourth Amendment:
...Gilligan argued that the government also believes the surveillance is legal under a 1979 Supreme Court case, Maryland v. Smith [sic], that found constitutional use of a “pen register” device to gather information on numbers called by a criminal suspect. 
“In terms of computer technology, things have changed an awful lot since ’79,” Leon replied. “The technology used in that case pales in comparison — pales in comparison to the technology NSA has at its disposal to query hundreds of millions of records … maybe billions of records in a matter of minutes or hours.” 
“Smith’s value may be very limited if at all in this case,” the judge added.
The mosaic theory of the Fourth Amendment suggests that the aggregate collection of information over an extended period of time may be considered a search. As Justice Ginsberg wrote in United States v. Jones (the GPS monitoring case), "[w]hen considered as a collective whole, the monitoring...revealed an intimate picture of the subject's life that he expects no one to have..."

So, yes: the government is simultaneously arguing to that too much otherwise-legitimate FOIA data creates a mosaic that threatens national security--but large scale metadata collection, far beyond anything contemplated by a simple pen register device in 1979--is perfectly legitimate. Both of these arguments are being made in the same city--Washington, DC--and in fact in the same court--the United States District Court for the District of Columbia. Right hand, meet the left hand.

I've submitted a CFP to Shmoocon to further discuss this issue, so if it gets picked up, I'll be able to flesh it out further.

What do you think?

22 October 2013

OMG, Call Yourself A Hacker, Lose Your 4th Amendment Rights!

Update (10/24/13): The Register has now picked up the story and uncritically repeats the same erroneous Fourth Amendment claims.

Update 2 (10/24/13): And just as quickly, the Register contacted me to indicate that the article has been updated to remove the Fourth Amendment references.

Two quick, but equally horrible points about this article:

First: this case has zero, zilch, squat, nothing, to do with the Fourth Amendment (or the Fifth Amendment, given the property issues). This case is about a temporary restraining order between two private parties. The Fourth Amendment's prohibition on unreasonable searches and seizures only applies to “state action." There is simply no state action here. Perhaps the author chose the title as link bait. Nonetheless, the headline is not only misleading, but erroneous, and detracts from the issue at hand.

Second, the decision to grant the TRO is based on the defendant's self-label of hacker (emphasis added):
In addition, the defendants have identified themselves as hackers, as discussed above. A well-known characteristic of hackers is that they cover their tracks...This makes it likely that defendant Thuen will delete material on the hard drive of his computer that could be relevant to this case...The tipping point for the Court comes from evidence that the defendants – in their own words – are hackers. By labeling themselves this way, they have essentially announced that they have the necessary computer skills and intent to simultaneously release the code publicly and conceal their role in that act. And concealment likely involves the destruction of evidence on the hard drive of Thuen’s computer. For these reasons, the Court finds this is one of the very rare cases that justifies seizure and copying of the hard drive.
This is highly disturbing, and has potentially broader implications beyond this immediate case. If simply calling oneself a hacker can be used as evidence that someone may have criminal intent is alarming, troublesome, discouraging and discomforting (thank you, Thesaurus.com). We cannot take this sitting down; we must stand up and fight.

09 October 2013

Remember to keep your computer patched and updated...or not

Exam4 is essentially a word-processor for law school exams. But don't try to update to the most recent versions of Mac OS X or Windows 8:


17 September 2013

Seems legit

Unsecured, network-enabled vending machines. What's the worst that could happen?


23 March 2013

DEFCON CFP submission: "©opyright Gone Wrong: Our Broken System and How We Can Fix It"

Here's my DEFCON CFP submission:

Title: ©opyright Gone Wrong: Our Broken System and How We Can Fix It

Abstract: The Constitution grants the Congress the power to enact copyright laws "[t]o promote the Progress of Science and useful Arts, by securing for limited Times to Authors and Inventors the exclusive Right to their respective Writings and Discoveries." Since the founding of our country, protection of intellectual property has undergone several systematic changes that have extended the time rights are protected. Additionally, protections have gotten increasingly aggressive and oppressive. This presentation will briefly discuss the history and development of copyright law, and then focus on the more recent and onerous provisions that have become embroiled in controversy. Along the way, we'll talk about the Digital Millennium Copyright Act, copyright trolls, and other methods of intellectual property abuse. Lastly, we will take a look at some of the ways we can reform our broken system to free consumers from burdensome restraints, while at the same time protecting the intellectual property of the creators.

Bio: Michael Schearer ("theprez98") is a civil libertarian who has started numerous projects which document abuses of freedom and liberty. He is a Senior Penetration Tester at Booz Allen and a law student at UDC-DCSL. He spent nearly nine years in the Navy as an EA-6B Prowler ECMO. His military experience includes aerial combat missions over Afghanistan and Iraq and nine months on the ground doing counter-IED with the Army. He is a graduate of Georgetown’s National Security Studies Program and a speaker at ShmooCon, DEFCON, HOPE, and other conferences. Michael lives in Maryland with his wife and children.

21 March 2013

Can Adria Richards sue (and win) for retaliation?

In the wake of Adria Richards's termination, there have been some suggestions that she sue her former employer SendGrid for retaliation (well, of course she can sue; but can she win?). The common-law legal term for this would be "retaliatory discharge."

As I see it, there are a few problems with this theory.

First, Colorado (like 48 other states, with the exception of Montana) is an "at-will" employment state. That means an employee can be fired for any reason, or for no reason (subject to a handful of statutory exceptions, like civil rights, age discrimination, disability discrimination). So the presumption is already against  her.

Second, retaliatory discharge typically presumes that the retaliation was done in response to some illegal action of the employer, or fellow employers. In this case, there is no evidence to that SendGrid did anything illegal. The allegedly harassing comments were made by someone else not associated with SendGrid. So it's difficult for me to see how SendGrid retaliated against her.

Third, it's not clear that Adria actually engaged in a protected activity.

Fourth, there has been a suggestion that her employer owes her a duty of care to protect her. Generally, this would only be the case if the harm was foreseeable, or if the employer knew of a danger yet failed to warn the employee. Again, there are no facts in the public view that SendGrid somehow knew of any such danger or failed to warn Adria.

Lastly, her case becomes even more difficult if the employer can show they have a legitimate, non-discriminatory reason for firing the employee. SendGrid appears to have already alleged this.

There may be other facts unknown to us that permit Adria to sue under some different claim. However, I suspect that a claim of retaliatory discharge would fail.

Of course, this doesn't mean that she won't sue--I just don't think she would win. Other smart people may very well disagree with me. You're free to post such comments below.

*I am not a lawyer. This is not legal advice. It is my opinion based upon the publicly available facts and some general legal research.

15 March 2013

Law in Plain English: In Re National Security Letter

This is one in a series of posts designed to describe court decisions in plain English. For more detail and background on the legal issues, see the link to the case below. For similar posts, click here.

In Re National Security Letter

The FBI issued a national security letter (NSL) to an unnamed ISP for certain subscriber information. The FBI certified that disclosure of the NSL could harm national security, so the ISP was prohibited from disclosing to anyone that they had received it (a gag order). The ISP challenged the constitutionality of the  non-disclosure provision as a violation of free speech, and challenged the judicial review provisions as a violation of the separation of powers. Judge Susan Illston of the United States District Court for the Northern District of California ruled that the nondisclosure provision was a form of prior restraint which was not narrowly tailored, since the provision applied to both the content of the NSL and the fact that the ISP even received it. As a result, it violated the ISP's freedom of speech. Additionally, the judicial review provisions violated both the First Amendment and the separation of powers principle by trying to narrow the ability of courts to review the nondisclosure orders. Furthermore, she prohibited the government from issuing any NSLs or from enforcing the nondisclosure provisions in this case and in any other cases. Lastly, she stayed enforcement of the judgement pending appeal or 90 days if there is no appeal (although that seems entirely likely).

Update (8/13/2013): I missed this a few months back, but the Government did file a notice of appeal.

14 March 2013

Law in Plain English: United States v. Auernheimer (Defendant's Sentencing Memorandum)

UPDATE (12:00PM, 3/18/13): Earlier this morning, Weev was sentenced to 41 months in prison, which is at the high end of the sentencing guidelines explained below.

This is one in a series of posts designed to describe court decisions in plain English. For more detail and background on the legal issues, see the link to the case below. For similar posts, click here.

Note that this post is a summary of the sentencing recommendations made by Weev's lawyers; the actual sentence will be determined at his yet-to-be-held sentencing hearing.

United States v. Auernheimer (Defendant's Sentencing Memorandum)

When considering an appropriate sentence for those convicted of a federal crime, district courts should consider a variety of factors, including the nature and circumstances of the offense, the need for the sentence to reflect the seriousness of the crime, to provide deterrence (both generally and specifically),  corrective treatment, and potential restitution. These factors work within the Federal Sentencing Guidelines, which are rules promulgated to set out a uniform federal sentencing policy.

The United States Probation Office submitted a Presentence Investigation Report (PSI) that scored Auernheimer with an Offense Level of 20 and a Criminal History Category of I. This translates within the Federal Sentencing Guidelines to a sentence of 33-41 months (note: I haven't seen the PSI, nor do I know if any copy has been made public; although Weev did mention in a recent blog post that he had just received it).
Note: These are my calculations to recreate the PSI Offense Level of 20 using the Federal Sentencing Guidelines (using the calculator here). This should not be considered to be an official calculation by the United States Probation Office.
Base Offense Level: 6
Loss Amount: $73,167 (+8)
Sophisticated Means: (+2)
Dissemination of Private Information: (+2)
Use of Special Skill: (+2) 
This results in Zone D, Level 20, History I, and 33-41 months.
This memo argues on behalf of Auernheimer that his Offense Level should be 6 (rather than 20) based upon several arguments: first, that AT&T didn't suffer any financial loss; second, that Auernheimer's offense was improperly double-counted for use of "sophisticated means" and "use of a special skill;" and third, an enhancement for "dissemination of personal information."

Financial loss: Auernheimer's lawyers argue that AT&T did not establish any loss at trial, and the cost of notifying AT&T's customers ($73,167) was not appropriate to include in federal sentencing recommendations. In fact, one of AT&T's own investigators admitted there was no case; no security measures had been circumvented.

Sophisticated means: Part of this section of the memorandum is redacted, but what remains suggests that the script Auernheimer used on AT&T's website was not part of a fraudulent scheme and thus  shouldn't qualify as "sophisticated means."

Dissemination of personal information: Lastly, Auernheimer's lawyers argue that dissemination of only email addresses should not constitute dissemination of personal information. They point out that the judge in the Jeremy Hammond case refused to recuse herself even though her husband's email address had been released. Her argument was that the release of just his email address constituted no harm.

Based on the Offense Level of 6 without the double-counting or enhancements, a sentence of 0-6 months is appropriate; Auernheimer's lawyers are asking for probation. Their argument for probation is based upon a claim that the Computer Fraud and Abuse Act is vague; that Auernheimer has no prior criminal history; and that probation would be consistent with the type of sentence Aaron Swartz was offered in his plea deal (3 months), arguing that Swartz's conduct was arguably more egregious that Auernheimer's.

08 March 2013

Law in Plain English: United States v. Cotterman

This is one in a series of posts designed to describe court decisions in plain English. For more detail and background on the legal issues, see the link to the case below. For similar posts, click here.

United States v. Cotterman

Cotterman was returning to the United States from Mexico. Cotterman's name was flagged for a 1992 child molestation conviction. The initial search of Cotterman's laptop and cameras revealed no incriminating information, but his laptop was seized for futher inspection. Later examination of his laptop (at a location 170 miles away from the border checkpoint) revealed the presence of child pornography. Cotterman tried to suppress the evidence, alleging that the search of his laptop was an extended border search that required reasonable suspicion. The court rejected Cotterman's extended border search claim, saying that a border search of his computer was not transformed into an extended border search simply because the device was
transported and examined beyond the border. A cursory, unintrusive search of the laptop is permissible without any suspicion. On the other hand, a forensic search of his computer was more intrusive than an initial, ordinary, and suspicion-less search at the border would normally allow. The question before the Court of Appeals for the Ninth Circuit was whether reasonable suspicion existed at the time of the border search. The court held that the totality of the circumstances (including his prior conviction for child molestation, coming from a country associated with sex tourism, frequent travels, and password protected files) amounted to reasonable suspicion. As a result, the search of Cotterman's laptop was valid, and the evidence was properly admitted. The court did point out that password protection was not, by itself, enough to give rise to reasonable suspicion (internal citations omitted):
To these factors, the government adds another—the existence of password-protected files on Cotterman’s computer. We are reluctant to place much weight on this factor because it is commonplace for business travelers, casual computer users, students and others to password protect their files. Law enforcement “cannot rely solely on factors that would apply to many law-abiding citizens,” and password protection is ubiquitous. National standards require that users of mobile electronic devices password protect their files. Computer users are routinely advised—and in some cases, required by employers—to protect their files when traveling overseas. “[T]here is one relatively simple thing attorneys can do [when crossing the border] to protect their privacy and the rights of their clients: password-protect the computer login and any sensitive files or folders.”).
The dissent writes that this decision creates a circuit split with the Fourth Circuit, who ruled in United States v. Ickes that electronic devices were "cargo" and thus could be searched without suspicion during a routine border search. Here in Cotterman, because the United States won, it is unclear if the government can appeal to the Supreme Court for clarification on whether forensic searches at the border require reasonable suspicion, as the Ninth Circuit found. And there's no incentive for Cotterman to appeal because he lost even after the court required a showing of reasonable suspicion. Either way, there does appear to be a circuit split; the majority doesn't even discuss the Ickes opinion (because it is from the Fourth Circuit; it is considered persuasive but not binding).

Update (8/11/13): Cotterman filed a cert petition with the Supreme Court.