Matot v. CH

975 F. Supp. 2d 1191, 2013 WL 5431586, 2013 U.S. Dist. LEXIS 138327
District Court, D. Oregon·Decided September 26, 2013·No. Civ. No. 6:13-cv-153-MC·Published·Cited by 2 cases

Opinion

OPINION AND ORDER

McSHANE, Judge:

Plaintiff brings this action seeking damages and equitable relief for alleged violation of the Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030, defamation, negligent supervision, and parental liability pursuant to Oregon Revised Statute § 30.765. Defendant, Gary Hill, filed this motion to dismiss for lack of subject matter jurisdiction (# 14). Defendant, S.A., filed this motion for entry of a limited [1192] judgment and injunction (#25). Magistrate Judge Thomas M. Coffin filed two Findings and Recommendations (F & R) in response to defendants’ motions (# 14) and (# 25), and these matters are now before this court. See 28 U.S.C. § 636(b)(1)(B) (2012); Fed.R.Civ.P. 72(b).

Because no objections to either F & R were filed, this court reviews only the legal principles de novo. United States v. Reyna-Tapia, 328 F.3d 1114, 1121 (9th Cir.2003) (en banc); see also United States v. Bernhardt, 840 F.2d 1441, 1445 (9th Cir.1988). Upon review, this court finds find no error in F & R(# 27) or F & R(# 29) and ADOPTs both in full. Defendant Gary Hall’s motion to dismiss for lack of subject matter jurisdiction (# 14) is GRANTED and defendant S.A.’s motion for entry of a limited judgment and injunction (#25) is DENIED consistent with this opinion.

DISCUSSION

Plaintiffs CFAA claim rests on defendants’ alleged use “without authorization” of social media sendees (e.g., Facebook and Twitter) and defendants’ alleged use “exceeding] authorized access” of social media services, i.e., defendants’ violation of the terms of use of the particular social media service. As indicated by Judge Coffin in F & R(# 27), a mere violation of a use restriction, i.e., “exceeding] authorized access,” is not actionable under the CFAA in the Ninth Circuit. U.S. v. Nosal, 676 F.3d 854, 863 (9th Cir.2012) (“[W]e hold that the phrase ‘exceeds authorized access’ in the CFAA does not extend to violations of use restrictions.”). Thus, the crux of plaintiffs argument is that defendants accessed social media services “without authorization” under 18 U.S.C. § 1030.1

Plaintiffs “without authorization” argument focuses on defendants’ alleged use of plaintiffs name and image in creating “forged” social media accounts (e.g. Facebook and Twitter). Plaintiff attempts to cast defendants’ behavior as analogous to that of hacking2 proscribed by the CFAA. Plaintiffs argument is unpersuasive in light of (1) LVRC Holdings LLC v. Brekka, (2) United States v. Nosal, and (3) the rule of lenity.

I. LVRC Holdings LLC v. Brekka

In LVRC Holdings LLC v. Brekka,3 the Ninth Circuit held that “a person uses a computer “without authorization’ under [the CFAA] when the person has not received permission to use the computer for any purpose (such as when a hacker accesses someone’s computer without any permission), or when the employer has rescinded permission to access the computer and the defendant uses the computer anyway.” 581 F.3d at 1135 (emphasis added). The Court further provided that “a person who uses a computer ‘without authorization’ has no rights, limited or otherwise, to access the computer in question.” Brekka, 581 F.3d at 1133. Despite this relatively bright-line rule, this Court is reluctant to use it as an absolute bar to [1193] plaintiff’s claim. To begin, unlike in Brekka, defendants are not employees of Twitter or Facebook who initially used the service for purposes of employment. Rather, as plaintiff alleges, defendants’ relationship with the social media websites was “forged ... from the ground up,” i.e., the defendants, as social media users, never were authorized because they breached the terms of use at the inception of the relationship. Likewise, this court doubts that even the Brekka Court would enforce its “without authorization” language to the extent implicated.4 For example, if a hacker5 targeted a United States governmental website for malicious purposes, such a hacker may be “authorized” to access the website under Brekka because many governmental websites are open to the public.6 In other words, if interpreted strictly, Brekka could preclude CFAA application of “without authorization” to hackers who breach governmental websites that are open to the public.7 For the same reason, strict adherence to Brekka’s bright-line rule outside of the employment context appears to be in conflict with the underlying legislative purpose.8

[1194] II. United States v. Nosal

Free access — add to your briefcase to read the full text and ask questions with AI

Matot v. CH, 975 F. Supp. 2d 1191, 2013 WL 5431586, 2013 U.S. Dist. LEXIS 138327 (D. Or. 2013).

975 F. Supp. 2d 1191 (Matot v. CH) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Ticketmaster L.L.C. v. Prestige Entm't W., Inc.
315 F. Supp. 3d 1147 (C.D. California, 2018)
Bittman v. Fox
107 F. Supp. 3d 896 (N.D. Illinois, 2015)