Domain Name Commission Limited v. DomainTools, LLC

District Court, W.D. Washington·Decided March 26, 2020·No. 2:18-cv-00874·Unknown

Opinion

UNITED STATES DISTRICT COURT AT SEATTLE DOMAIN NAME COMMISSION LIMITED, NO. C18-0874RSL Plaintiff, v. ORDER GRANTING IN PART DEFENDANT’S MOTION TO DOMAINTOOLS, LLC, DISMISS Defendant. This matter comes before the Court on defendant’s “Motion to Dismiss Pursuant to FRCP 12(b)(1) and 12(b)(6).” Dkt. # 64. Plaintiff is a New Zealand non-profit corporation that regulates the use of the .nz top level domain, including registering new domain names and responding to inquiries regarding registrants. Defendant collects domain and registrant information from around the world, stores the information, and uses its current and historic databases to sell monitoring and investigative services and products to the public. Plaintiff alleges that the way defendant accessed .nz domain and registrant information before June 6, 2018, any and all access after that date, and its continuing storage and use of the domain and registrant information violates the Computer Fraud and Abuse Act (“CFAA”) and the Washington Consumer Protection Act (“CPA”). Defendant seeks dismissal of the statutory ORDER GRANTING IN PART claims.1 The question for the Court on a motion to dismiss is whether the facts alleged in the complaint sufficiently state a “plausible” ground for relief. Bell Atl. Corp. v. Twombly, 550 U.S. 544, 570 (2007). All well-pleaded allegations are presumed to be true, with all reasonable inferences drawn in favor of the non-moving party. In re Fitness Holdings Int’l, Inc., 714 F.3d 1141, 1144-45 (9th Cir. 2013). If the First Amended Complaint (Dkt. # 54) fails to state a cognizable legal theory or fails to provide sufficient facts to support a claim, however, dismissal is appropriate. Shroyer v. New Cingular Wireless Servs., Inc., 622 F.3d 1035, 1041 (9th Cir. 2010). Having reviewed the memoranda submitted by the parties and heard the arguments of counsel, the Court finds as follows: A. Computer Fraud and Abuse Act, 18 U.S.C. § 1030 As relevant to this litigation, the CFAA prohibits “intentionally access[ing] a computer without authorization or exceed[ing] authorized access,” 18 U.S.C. § 1030(a)(2), as well as “intentionally access[ing] a protected computer without authorization” and causing “damage and loss,” 18 U.S.C. § 1030(a)(5)(C). Plaintiffs argue that defendant is liable under both provisions because it accessed the .nz servers in ways and for purposes that violated plaintiff’s terms of use and continued to access the .nz servers after its right of access had been expressly revoked. Plaintiff’s terms of use prohibited use of Port 43, a communication channel through which users can query plaintiff’s servers regarding specific .nz domain names, to send high 1 Plaintiff has also asserted a breach of contract claim, regarding which the Court entered a preliminary injunction on September 12, 2018. Dkt. # 43. The preliminary injunctive relief was affirmed on appeal, and defendant is not seeking dismissal of the contract claim. ORDER GRANTING IN PART volume queries to the .nz servers with the effect of downloading or collecting all or part of the .nz register, to access the .nz register in bulk, to store or compile .nz domain data to build up a secondary register, and/or to publish historical or non-current versions of the .nz data. Dkt. # 54- 1 at 18. On November 2, 2017, plaintiff sent defendant a cease-and-desist letter notifying defendant that it had violated plaintiff’s terms of use and demanding that it “immediately cease and desist accessing .nz WHOIS servers or using and publishing .nz WHOIS data except as permitted by the [terms of use].” Dkt. # 54-1 at 24. When defendant continued to access the .nz servers in ways that plaintiff felt violated the limited license it had granted defendant, plaintiff sent a June 6, 2018, letter revoking defendant’s right to access the .nz servers entirely. Dkt. # 54- 1 at 30. Plaintiff alleges that defendant accessed the .nz servers after the June 6, 2018, revocation. Dkt. # 54 at ¶ 106.2 Plaintiff argues that defendant’s access to the .nz server in ways that violated plaintiff’s terms of use prior to June 6, 2018, constitutes both access “without authorization” and in excess of authorized access. Dkt. # 54 at ¶¶ 74-79 and 104. Plaintiff also argues that defendant’s queries to the .nz servers after plaintiff revoked defendant’s right of access was “without authorization.” Dkt. # 54 at ¶ 106. Plaintiff alleges that defendant’s unlawful conduct caused plaintiff “loss in an amount far in excess of the $5,000 statutory minimum during each relevant one-year period.” Dkt. # 54 at ¶ 107. 2 Defendant challenges the adequacy of this allegation, but it is more than enough to give rise to a plausible inference that defendant continued to access the .nz servers after June 6, 2018. Twombly does not require that plaintiff include in its complaint a log indicating the times and dates on which such access occurred, nor has defendant demanded such specificity as to the pre-June 6 access allegations. If, as appears to be the case, defendant is contesting the veracity of the post- June 6 access allegation, it may not do so in the context of this motion to dismiss. ORDER GRANTING IN PART 1. “Without Authorization” The CFAA does not contain a definition of “without authorization.” The Ninth Circuit has, therefore, applied the ordinary, common meaning of “authorization,” concluding that one is authorized to access a computer when the owner of the computer gives permission to use it. LVRC Holdings LLC v. Brekka, 581 F.3d 1127, 1132-33 (9th Cir. 2009). See also hiQ Labs, Inc. v. LinkedIn Corp., 938 F.3d 985, 999 (9th Cir. 2019) (“We have held in another context that the phrase “without authorization” is a non-technical term that, given its plain and ordinary meaning, means accessing a protected computer without permission.”) (internal quotation marks and citation omitted). A defendant runs afoul of the “without authorization” provisions of the CFAA “when he or she has no permission to access a computer or when such permission has been revoked explicitly. Once permission has been revoked, technological gamesmanship or enlisting of a third party to aid in access will not excuse liability.” Facebook, Inc. v. Power Ventures, Inc., 844 F.3d 1058, 1067 (9th Cir. 2016). The Ninth Circuit has rejected the argument that permission or authorization to access a computer is automatically withdrawn when the user violates a duty owed to the owner of the computer. Rather, whether access is authorized or unauthorized “depends on actions taken by the employer.” Brekka, 581 F.3d at 1134-35. If the computer owner has not affirmatively rescinded the defendant’s right to access the computer, any existing authorization/permission remains. Id. Prior to June 6, 2018, defendant had permission to access the .nz servers, albeit with limitations imposed on the manner in which and purposes for which that access could be ORDER GRANTING IN PART exercised.3 That permission was revoked on June 6, 2018. Taking plaintiff’s allegations of access as true, the Court finds that defendant accessed the .nz servers with authorization prior to June 6, 2018, and without authorization after that date.4 2. “Exceeds Authorized Access” The CFAA defines “exceed

Free access — add to your briefcase to read the full text and ask questions with AI

Domain Name Commission Limited v. DomainTools, LLC, (W.D. Wash. 2020).

Domain Name Commission Limited v. DomainTools, LLC (Domain Name Commission Limited v. DomainTools, LLC) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Watters v. Wachovia Bank, N. A.
550 U.S. 1 (Supreme Court, 2007)
Shroyer v. New Cingular Wireless Services, Inc.
622 F.3d 1035 (Ninth Circuit, 2010)
United States v. Nosal
676 F.3d 854 (Ninth Circuit, 2012)
International Airport Centers, L.L.C. v. Jacob Citrin
440 F.3d 418 (Seventh Circuit, 2006)
United States v. Rodriguez-Reyes
714 F.3d 1 (First Circuit, 2013)
Hangman Ridge Training Stables, Inc. v. Safeco Title Insurance
719 P.2d 531 (Washington Supreme Court, 1986)
LVRC HOLDINGS LCC v. Brekka
581 F.3d 1127 (Ninth Circuit, 2009)
Shamrock Foods Co. v. Gast
535 F. Supp. 2d 962 (D. Arizona, 2008)
Federal Trade Commission v. Wyndham Worldwide Corp.
799 F.3d 236 (Third Circuit, 2015)
Hiq Labs, Inc. v. Linkedin Corporation
938 F.3d 985 (Ninth Circuit, 2019)
Klem v. Washington Mutual Bank
295 P.3d 1179 (Washington Supreme Court, 2013)
Facebook, Inc. v. Power Ventures, Inc.
844 F.3d 1058 (Ninth Circuit, 2016)