Faking It: Calculating Loss in Computer Crime Sentencing
Jennifer Stisa Granick · The Knowledge Bank (The Ohio State University) · 2006
This paper argues that the sentences courts have been imposing for violations of the federal computer crime statute -18 U.S.C. § 1030do not accurately reflect the seriousness of the offense or treat like offenders equally.By definition, sentencing is heavily dependent on economic measures of harm, particularly the cost of investigating the incident and restoring the system to its original state.The legal definition of harm, however, does not accord with the real world responses of investigators who want to get critical systems running again to improve the state of security.Also, by focusing on monetary loss, sentences do not adequately reflect intangible damage that is difficult to value monetarily, like invasions of privacy, access to or theft of data, or interruption of service.The readily measured monetary loss like labor and hardware costs associated with investigating, repairing, and restoring compromised systems are more a function of victims' choices than a reflection of perpetrator wrongdoing or system interference.Sentencing law and practice has failed to discriminate between harmful and trivial attacks.There are several legal approaches we could adopt to mitigate these problems.Ultimately, the question of how to remedy intrusions depends on whether a consensus evolves about the value of the rights and property interests that are commonly harmed by computer attacks. GRANICK MEASURING ECONOMIC LOSS IS FUNDAMENTAL IN COMPUTER CRIME CASESComputer crime sentencing requires courts to value the damage caused by a computer intrusion.In 2005, U.S. Supreme Court decisions in United States v. Booker and United States v. FanFan 1 changed the way federal courts sentence in criminal cases.The decisions stem from prior case law holding that a defendant has a right to trial by jury for any factor that increases the defendant's sentence.2 Booker and FanFan then held that the United States Sentencing Guidelines, to the extent that they are mandatory, violate the Constitution when the total offense level upon which the trial court sentences include aggravating factors not found to be true beyond a reasonable doubt by a jury.3 A different majority of the Court then held that the Guidelines are acceptable so long as they are not mandatory.4 Courts are free to be guided by the Guidelines but need not sentence in accordance with them, and sentencing decisions will be reviewed for "reasonableness." 5 The amount of harm a defendant caused is relevant to sentencing courts.Courts will calculate that harm in accordance with both statutory and Guideline definitions.The Computer Fraud and Abuse Act (CFAA), codified at 18 U.S.C. § 1030, prohibits unauthorized access to computer systems.6 Damage, expressed in terms of monetary loss, is important in computer crime cases in three ways: (1) it is an element of the crime;(2) it is a major determinative factor in sentencing; and (3) it is fundamental to restitution.While the statute clearly contemplates intangible harms from unauthorized access to data and systems, it requires fact finders to express those harms in economic terms.I United States v. Booker, United States v. FanFan, 543 U.S. 220 (2005) (case opinions are combined).2 Apprendi v. New Jersey, 530 U.