Malwarebytes, Inc. v. Enigma Software Group USA, LLC

Supreme Court of the United States·Decided October 13, 2020·No. 19-1284·Relating-to

Opinion

SUPREME COURT OF THE UNITED STATES MALWAREBYTES, INC. v. ENIGMA SOFTWARE GROUP USA, LLC

ON PETITION FOR WRIT OF CERTIORARI TO THE UNITED STATES COURT OF APPEALS FOR THE NINTH CIRCUIT No. 19–1284. Decided October 13, 2020

The petition for a writ of certiorari is denied. Statement of JUSTICE THOMAS respecting the denial of certiorari.

This petition asks us to interpret a provision commonly called §230, a federal law enacted in 1996 that gives Internet platforms immunity from some civil and criminal claims. 47 U. S. C. §230. When Congress enacted the statute , most of today’s major Internet platforms did not exist. And in the 24 years since, we have never interpreted this provision. But many courts have construed the law broadly to confer sweeping immunity on some of the largest companies in the world. This case involves Enigma Software Group USA and Malwarebytes , two competitors that provide software to enable individuals to filter unwanted content, such as content posing security risks. Enigma sued Malwarebytes, alleging that Malwarebytes engaged in anticompetitive conduct by reconfiguring its products to make it difficult for consumers to download and use Enigma products. In its defense, Malwarebytes invoked a provision of §230 that states that a computer service provider cannot be held liable for providing tools “to restrict access to material” that it “considers to be obscene, lewd, lascivious, filthy, excessively violent, harassing , or otherwise objectionable.” §230(c)(2). The Ninth Circuit relied heavily on the “policy” and “purpose” of §230 to conclude that immunity is unavailable when a plaintiff alleges anticompetitive conduct.

The decision is one of the few where courts have relied on purpose and policy to deny immunity under §230. But the court’s decision to stress purpose and policy is familiar. Courts have long emphasized nontextual arguments when interpreting §230, leaving questionable precedent in their wake.

I agree with the Court’s decision not to take up this case. I write to explain why, in an appropriate case, we should consider whether the text of this increasingly important statute aligns with the current state of immunity enjoyed by Internet platforms.

I

Enacted at the dawn of the dot-com era, §230 contains two subsections that protect computer service providers from some civil and criminal claims. The first is definitional . It states, “No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider.” §230(c)(1). This provision ensures that a company (like an e-mail provider) can host and transmit third- party content without subjecting itself to the liability that sometimes attaches to the publisher or speaker of unlawful content. The second subsection provides direct immunity from some civil liability. It states that no computer service provider “shall be held liable” for (A) good-faith acts to restrict access to, or remove, certain types of objectionable content; or (B) giving consumers tools to filter the same types of content. §230(c)(2). This limited protection enables companies to create community guidelines and remove harmful content without worrying about legal reprisal.

Congress enacted this statute against specific background legal principles. See Stewart v. Dutra Constr. Co., 543 U. S. 481, 487 (2005) (interpreting a law by looking to the “backdrop against which Congress” acted). Traditionally , laws governing illegal content distinguished between

publishers or speakers (like newspapers) and distributors (like newsstands and libraries). Publishers or speakers were subjected to a higher standard because they exercised editorial control. They could be strictly liable for transmitting illegal content. But distributors were different. They acted as a mere conduit without exercising editorial control, and they often transmitted far more content than they could be expected to review. Distributors were thus liable only when they knew (or constructively knew) that content was illegal. See, e.g., Stratton Oakmont, Inc. v. Prodigy Services Co., 1995 WL 323710, *3 (Sup. Ct. NY, May 24, 1995); Restatement (Second) of Torts §581 (1976); cf. Smith v. California , 361 U. S. 147, 153 (1959) (applying a similar principle outside the defamation context).

The year before Congress enacted §230, one court blurred this distinction. An early Internet company was sued for failing to take down defamatory content posted by an unidentified commenter on a message board. The company contended that it merely distributed the defamatory statement . But the company had also held itself out as a familyfriendly service provider that moderated and took down offensive content. The court determined that the company’s decision to exercise editorial control over some content “render [ed] it a publisher” even for content it merely distributed . Stratton Oakmont, 1995 WL 323710, *3–*4.

Taken at face value, §230(c) alters the Stratton Oakmont rule in two respects. First, §230(c)(1) indicates that an Internet provider does not become the publisher of a piece of third-party content—and thus subjected to strict liability— simply by hosting or distributing that content. Second, §230(c)(2)(A) provides an additional degree of immunity when companies take down or restrict access to objectionable content, so long as the company acts in good faith. In short, the statute suggests that if a company unknowingly leaves up illegal third-party content, it is protected from publisher liability by §230(c)(1); and if it takes down certain

third-party content in good faith, it is protected by §230(c)(2)(A).

This modest understanding is a far cry from what has prevailed in court. Adopting the too-common practice of reading extra immunity into statutes where it does not belong , see Baxter v. Bracey, 590 U. S. —— (2020) (THOMAS, J., dissenting from denial of certiorari), courts have relied on policy and purpose arguments to grant sweeping protection to Internet platforms. E.g., 1 R. Smolla, Law of Defamation §4:86, p. 4–380 (2d ed. 2019) (“[C]ourts have extended the immunity in §230 far beyond anything that plausibly could have been intended by Congress); accord, Rustad & Koenig, Rebooting Cybertort Law, 80 Wash. L. Rev. 335, 342–343 (2005) (similar). I address several areas of concern.

A

Courts have discarded the longstanding distinction between “publisher” liability and “distributor” liability. Although the text of §230(c)(1) grants immunity only from “publisher” or “speaker” liability, the first appellate court to consider the statute held that it eliminates distributor liability too—that is, §230 confers immunity even when a company distributes content that it knows is illegal. Zeran v. America Online, Inc., 129 F. 3d 327, 331–334 (CA4 1997). In reaching this conclusion, the court stressed that permitting distributor liability “would defeat the two primary purposes of the statute,” namely, “immuniz[ing] service providers ” and encouraging “selfregulation.” Id., at 331, 334. And subsequent decisions, citing Zeran, have adopted this holding as a categorical rule across all contexts. See, e.g., Universal Communication Systems, Inc. v. Lycos, Inc., 478 F. 3d 413, 420 (CA1 2007); Shiamili v. Real Estate Group of NY, Inc., 17 N. Y. 3d 281, 288–289, 952 N. E. 2d 1011, 1017 (2011); Doe v. Bates, 2006 WL 3813758, *18 (ED Tex., Dec. 27, 2006).

To be sure, recognizing some overlap between publishers and distributors is not unheard of. Sources sometimes use language that arguably blurs the distinction between publishers and distributors. One source respectively refers to them as “primary publishers” and “secondary publishers or disseminators,” explaining that distributors can be “charged with publication.” W. Keeton, D. Dobbs, R. Keeton, & D. Owen, Prosser and Keeton on Law of Torts 799, 803 (5th ed. 1984).

Free access — add to your briefcase to read the full text and ask questions with AI

Malwarebytes, Inc. v. Enigma Software Group USA, LLC, (U.S. 2020).

Malwarebytes, Inc. v. Enigma Software Group USA, LLC (Malwarebytes, Inc. v. Enigma Software Group USA, LLC) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Smith v. California
361 U.S. 147 (Supreme Court, 1960)
Russello v. United States
464 U.S. 16 (Supreme Court, 1983)
Stewart v. Dutra Construction Co.
543 U.S. 481 (Supreme Court, 2005)
Federal Trade Commission v. Accusearch Inc.
570 F.3d 1187 (Tenth Circuit, 2009)
Kenneth M. Zeran v. America Online, Incorporated
129 F.3d 327 (Fourth Circuit, 1997)
Barnes v. Yahoo!, Inc.
570 F.3d 1096 (Ninth Circuit, 2009)
Fair Housing Coun., San Fernando v. Roommates. Com
521 F.3d 1157 (Ninth Circuit, 2008)
Jones v. Dirty World Entertainment Recordings LLC
755 F.3d 398 (Sixth Circuit, 2014)
Jane Doe No. 1 v. Backpage.Com, LLC
817 F.3d 12 (First Circuit, 2016)
Sikhs for Justice, Inc. v. Facebook, Inc.
697 F. App'x 526 (Ninth Circuit, 2017)
Force v. Facebook, Inc.
934 F.3d 53 (Second Circuit, 2019)
Shiamili v. Real Estate Group of New York, Inc.
952 N.E.2d 1011 (New York Court of Appeals, 2011)
Sikhs for Justice "SFJ", Inc. v. Facebook, Inc.
144 F. Supp. 3d 1088 (N.D. California, 2015)
Batzel v. Smith
333 F.3d 1018 (Ninth Circuit, 2003)
M.A. ex rel P.K. v. Village Voice Media Holdings, LLC
809 F. Supp. 2d 1041 (E.D. Missouri, 2011)