Monday, 29 February 2016

RICKY TARFA (SAN): THE RIGHT TO REMAIN SILENT AND PASSWORD-PROTECTED MOBILE PHONES



 On the 24th of February, 2016 a Senior Advocate of Nigeria, Mr. Rickey Tarfa withdrew an N5billion fundamental rights violation suit he filed against the Economic and Financial Crimes Commission (EFCC) and four other respondents. The senior lawyer had filed the suit, alleging violation of his right to privacy by the respondents

Mr. Tarfa in the suit sought a court declaration that his right to privacy was violated when the call records/log on his phone with mobile number 08034600000 was allegedly accessed without his authority and made available to Sahara Reporters and other online news media without any reasonable cause or a lawful court order.

He also urged the court to hold that it was unlawful for his iPhone 6 with mobile number 08034600000 to have been used in calling one Alhaji Ado in Kaduna on mobile number 08061272929 on February 9, 2016 while the said phone was with Magu and the EFCC without any reasonable cause or any court order.

Furthermore, Mr. Tarfa also urged the court to hold that it was unlawful for the EFCC to access his bank details, clients’ information, private and confidential information contained in his iPhone 6 with number 08034600000 and Samsung 6 phone with number 08077341616 without any reasonable cause or any court order.

The writer cannot tell if Mr. Tarfa’s mobile phones were password-protected but assuming he had pass-worded/locked his mobile phones (just like Syed Rizwan Farook, one of the two killers (who were later killed in a shootout with the police) in the December 2, 2015 San Bernardino, California mass shootings, who left behind a pass-worded/locked iPhone 5c whose data the FBI has not been able to get access to) and the EFCC were unable to access the mobile phones either through hacking or guessing his passwords, would it have been lawful for the EFCC to demand from Mr. Tarfa or compel him to provide the passwords to his mobile phones?

The Position of the Law in Nigeria
According to Section 35(2) 1999 Constitution as amended:
“Any  person  who  is  arrested  or  detained  shall  have  right  to  remain silent  or  avoid  answering  any  question  until  after  consultation  with  a legal practitioner or any other person of his own choice”

Section 36(11) further provides that “No person who is tried for a criminal offence shall be compelled to give evidence”. However, section 35(2) is more germane to the issue at hand so this discourse will be limited to the said section.

The import of the section 35(2) is that whenever a suspect is in police custody, his constitutional right to remain silent begins, and this right is to the effect that he cannot be forced or coerced to say a word unless he volunteers to do so as it is the duty of the prosecution to prove its case beyond reasonable doubt. The above position of the law has been upheld by the Supreme Court of Nigeria in the case of Sugh v. State (1988) NWLR (Pt. 77)475. See also Ajudua v. FRN (2014) LPELR-24126(CA) where it was held that an  accused  has the  right  to  remain  silent  as  he  cannot  be forced to make a statement during investigation.

The Position of the Law in the United States
In the United States the general position of the law regarding the right to remain silent or right against compelled self-incrimination is provided for in the Fifth Amendment to the United States Constitution which provides that “No person shall…be compelled in any criminal case to be a witness against himself.”

In the case of Securities and Exchange Commission (SEC) v. Bonan Huang et al (Case 2:15-cv-00269-MAK), the SEC were investigating the defendants who allegedly used insider information associated with their jobs to trade stocks. The SEC suspected the mobile devices were holding evidence of insider trading and demanded (via a motion filed in court) that the defendants turn over their passcodes. The defendants declined supplying their passcodes contending that the Fifth Amendment protected them.  The issue was therefore, whether the defendants could be forced to give up passcodes to devices that were provided by their employer, but secured by passcodes chosen by the employees themselves. The Federal District Court (the Supreme Court has never ruled on the constitutionality of the issue) in Eastern Pennsylvania ruled that the defendants cannot be compelled to give up the passcode to their cell phones as doing so would be equal to giving self-incriminating  testimony.

The Position of the Law in the United Kingdom
The privilege against compelled self-incrimination or the right to remain silent is deeply rooted in the common law. Goddard LJ in Blunt v Park Lane Hotel [1942] 2 KB 53 at 257 stated thus;
"No one is bound to answer any question if the answer thereto would, in the opinion of the judge, have a tendency to expose (him) to any criminal charge, penalty or forfeiture which the judge regards as reasonably likely to be preferred …" 

In Saunders v UK [1996] 23 EHRR 313 it was held that Article 6 of the European Convention of Human Rights guarantees the protection against self-incrimination.
"The right to silence and the right not to incriminate oneself, are generally recognised international standards which lie at the heart of the notion of a fair procedure under article 6….the right not to incriminate oneself, in particular, presupposes that the prosecution in the criminal case seek to prove their case against the accused without resort to evidence obtained through methods of coercion or oppression in defiance of the will of the accused. In this sense the right is closely linked to the presumption of innocence contained in article 6(2)".

However, the right is subject to numerous statutory exceptions which limit, amend, or abrogate the privilege in specified circumstances. Therefore, despite the privilege, individuals may sometimes be required to answer questions or provide information or documents which may incriminate them. For instance the Regulation of Investigatory Powers Act 2000 (RIPA), Part III, activated by ministerial order in October 2007, requires persons to supply decrypted information and/or keys/passwords to government representatives or law enforcement agents with a court order. Failure to disclose carries a maximum penalty of two years in jail. Thus, under the provisions of the RIPA Syed Hussain was convicted of failing to provide police with the password to the USB memory stick seized in a counter-terrorism operation. When Hussain was arrested in April 2012, police seized a USB memory stick from his home - but they discovered the information on the device was protected by sophisticated encryption technology. Hussain told detectives that he could not remember the password because he was suffering from stress – which meant they could not access its contents. Police called in experts from GCHQ, the government's secret eavesdropping and communications agency, but even they were unable to crack the device.

Oliver Drage, a 19-year old was arrested as part of an investigation into child sexual abuse images. His computer was seized by police who were unable to access some material on it thanks to a 50-character encryption password. Police formally requested the password from Drage, he refused to co-operate, an offence under the RIPA. He was accordingly sentenced to 16 weeks in a young offenders’ institution for refusing to give police the password to an encrypted file on his computer. See-

Conclusion
Considering the position or state of the law in Nigeria it may be safe to conclude that if Mr. Tarfa’s mobile phones were locked or pass-worded, the EFCC would have acted outside the law or illegally if they compelled Mr. Tarfa to disclose the passwords to his mobile phones which they seized. This is so as to the best of the writer’s knowledge there is no exception to the right to remain silent under Nigerian law; unlike the position in the UK, during interrogation in the custody of law enforcement agents.

However, as one writer observed:
“Realistically, the right to silence has a low value and not really exercised by most suspects. Only a suspect who knows the law and the right well would exercise the right as most people would not be able to withstand the mental pressures during the interrogation. False evidences, lies, isolation and many other psychological tactics are practiced to make the suspect confess the crime. As a result of this, many false confessions happen due to unbearable psychological pressures.”

It may therefore, not be out of place to suggest that it would take an extraordinarily strong-willed suspect undergoing interrogation during detention by any of the law enforcement agencies in Nigeria, especially the Nigerian Police who are notorious for torturing suspects in detention, to exercise his right to remain silent as guaranteed by section 35(2) of the 1999 Constitution as amended!

Friday, 26 June 2015

INACCURATE AND INCOMPLETE BIS DATA USAGE REPORT BY MTN


If you subscribe for the one month Blackberry Internet Service (BIS) plan on Glo, Etisalat and Airtel and you check the status of your subscription they inform you via sms of how much data in MB(megabytes) you have left for the plan. This enables a subscriber to better manage his data usage and ensure the subscriber doesn't exhaust his data and therefore the subscription before the end of the one month.

However, the story isn't the same with MTN as when you check the status of your BIS they only inform you via sms that you are within the Fair Usage Plan and if you are not they also inform you of that fact without showing you the ACTUAL data in MB that is remaining on your subscription.

I do not think MTN is being fair to its customers/subscribers and that is not right. In fact they could actually be breaching the General  Consumer  Code  of  Practice  published by the Nigerian Communications Commission pursuant to section 106 of the Nigerian Communications Act 2003 which imposes a duty on service providers such as MTN to provide consumers with information on their services that  is  complete,  accurate,  and  up  to  date  and  in  simple,  clear  language. Below is a screen shot of the status inquiry of MTN and Glo one month BIS respectively:
In view of the foregoing, can it be said that MTN has provided its customers or consumers of her one month BIS plan, information on the status of their subscription that is COMPLETE and ACCURATE? In my opinion, I don't think so!

I therefore call on the relevant authorities such as the Nigeria Communications Commission and the Consumer Protection Council of Nigeria to wade into this matter and direct MTN to provide her consumers of the one month BIS plan, information on the status of their subscription that is COMPLETE and ACCURATE just like Glo, Etisalat and Airtel does.
 


Friday, 13 February 2015

DON'T IGNORE THAT UPDATE NOTIFICATION ON YOUR SMARTPHONE OR DEVICE


Mimidoo and Hembafan are smartphone freaks. They are young adults who love to use high-end smartphones. Mimidoo uses a BlackBerry Passport while Hembafan uses a HTC One (M8). The following conversation ensued between Mimidoo and Hembafan.

Mimidoo: I hate these updates notification I keep seeing on my BB. If it’s not ‘updates available for BBM,” it’d be “updates available for Whatsapp or PicMix”. Babe, (referring to Hembafan) do you often get these updates notification too?

Hembafan: I do get them too. The annoying thing is that even after you update the apps, you don’t see any changes in their features or functions. At most you see a few new smileys after updating the BBM. In fact I've updated the WhatsApp app on my phone twice but I didn’t notice any new feature or function.

From the conversation above, it can be deduced that there is a misunderstanding among many users of smartphones and users of computers/computer-like devices who are routinely required to install updates for softwares (apps) and operating systems (OS) installed on their devices (smartphones, computers etc.)

Updates aren't necessarily meant to introduce new features/functions for apps or operating systems. Assuming you buy a car and install an anti-theft security system in the car and after six months the security company that installed the system discovers a flaw or fault in the system to the effect that if urine touches the alloy wheels of the car, the anti-theft security system would be disabled and the company offers to fix the flaw free of charge, won't you allow them to fix the flaw? Or according to Justin Pot in “How & Why You Need To Install That Security Patch”:
Pretend you bought a security system for your house, because you need to protect an extremely valuable diamond. Two years after the system is set up, the company that installed it for you notices a flaw: criminals who clap three times while bouncing on one leg cannot be detected. If the company that installed your security system offered to fix this vulnerability, free of charge, would you let them? Of course you would. Think of patches (updates) the same way.


To understand what updates do and why the next time you get that update notification on your device you SHOULD NOT ignore it click HERE

Friday, 28 November 2014

Electronic Evidence in Nigeria

As earlier promised in a previous blogpost, below is the link to my article: 'Electronic Evidence in Nigeria'. Electronic evidence is steadily assuming or has assumed a very important position in the adjudication of disputes or cases, be they criminal or civil. Anything done on the computer or the internet usually leaves traces or digital footprints which can serve as evidence in legal proceedings. Electronic evidence can therefore aid the investigation and solving of crimes by law enforcement agents. All this is possible because we are living in an age where most of the things we used to do manually are now done on computers, computer-like devices, or with the aid of computers and computer networks (such as the internet). For instance, using a debit card, the customer can use an Automated Teller Machine (ATM) to obtain access to their account, and to withdraw money anywhere in the world. With an internet-enabled cellphone, the customer can authorise the transfer of money to anybody anywhere in the world at any time, as well as making purchases using the same internet-enabled cellphone.

The article therefore highlights; with the aid of Nigerian and foreign cases, the importance of electronic evidence and why the Nigerian lawyer, to be considered to be competent, ought to be sufficiently literate in the technical issues regarding electronic evidence so as to understand and make use of electronic evidence. The article concludes by recommending the inclusion of a core course on electronic evidence in the curriculum of legal education in Nigeria.


Click to read the article: Electronic Evidence in Nigeria. The article is published in the Digital Evidence and Electronic Signature Law Review. Clicking on the link will take you to the law review's website, scroll down the page a little to find the article.

Please after reading endeavor to leave your comments or thoughts about the article here on this blog and also try to share it on social media platforms and to your friends(including lawyers and non-lawyers). Issues addressed in the article are of utmost importance not just to lawyers but to any person in the 21st century who uses a cell-phone, the bank, computers, computer-like devices, or computer networks (such as the internet).

Note, the article is in PDF(Portable Document Format) file format so if you cannot read PDFs on your device(cell-phone or tab) you can download it to your device and then copy it to a laptop or desktop computer which has a PDF reader/viewer installed and read the article there.


Sunday, 2 November 2014

How Not To Use Social Media

A contestant in a beauty contest while soliciting for votes from her Facebook friends posted a link to the website where her friends could vote for her on her Facebook wall and in the alternative also asked them to send to her their email addresses and phone numbers so that she could use them(email addresses and phone numbers) to do the voting in case they couldn't do it themselves.  Some of her Facebook friends in responding to her requests posted their email addresses and phone numbers on her Facebook wall. Below is a screenshot of the relevant portion of her Facebook wall:

Phishing and Spam
Some of her friends decided to post their email addresses and phone numbers on her Facebook wall, instead of sending same to her Facebook inbox. This is not good as the addresses and numbers posted on her wall can be viewed by person in any corner of the world who views her Facebook wall as it appears that her Facebook privacy settings does not limit the persons that can view her wall. Therefore, what those friends did is akin to walking on the streets of every country in the world and giving anybody they come across including strangers their email addresses and phone numbers! Probably those her friends who posted their email addresses and phone numbers on her wall thought that it is only her and her Facebook friends that could view their chat which contained the email addresses and phone numbers or  it could be that they knew all that but did not give a damn! Well, they should give a damn. Why? It is because scammers could use their email addresses and phone numbers to defraud them through a technique referred to as phishing. Phishing refers to the process of deceiving recipients of text messages and more often, emails into sharing sensitive information with an unknown third party (usually a cyber-criminal).

Typically in a phishing email scam, you receive an email that appears to come from reputable organizations, such as: banks, social media (Facebook, Twitter), etc. Phishing emails may be indiscriminate. A phisher will create an email asking the user to get in touch with a bank or credit card company claiming that there is a problem with the account or that the bank may have lost some money. These sorts of messages make people justifiably worried and more likely to follow the instruction. The phisher will then include some plausible looking details such as the bank’s logo and address and then send it to millions of individuals. Among all the recipients, a few people will have accounts with that bank and will click the link in the message, or telephone a number, which will begin the process of eliciting further personal information such as account number, ATM PIN and password, internet banking login username and password which he could use to hack into or log in into a bank account and steal money.

There are times when we receive unsolicited text messages or emails from people or organizations we do not know (spammers) and then we wonder how they got our phone number or email address. Posting your phone number and email address on your friend’s Facebook wall is one of the ways they could get your phone number and email address and then start sending you spam or spam messages. Spam simply put is irrelevant or unsolicited messages sent over the internet typically to large numbers of users, for the purposes of advertising, phishing, spreading malware (computer viruses) etc. These messages could be annoying and can include bogus offers that could cost you time and money.

Conclusion
In order to avoid been scammed through phishing or spam messages or to not receive spam  messages try to limit how you share your phone number and email address in public and online (blog posts, in chat rooms and on social media networking sites). Spammers and scammers use the web to harvest email addresses. For more internet safety tips and how you can use social networking sites with minimum risks click here and here and here.


A report from the Centre for Strategic and International Studies (CSIS), shows more than US $445 billion gets lost annually with the damage for businesses nearly double than for individuals, through series of cybercrime, electronic theft, and online piracy. So, please read those tips and make sure you use them so that together we can help make using the internet a lot safer and keep the cybercriminals (419ners in Nigerian slang) out of business or at least reduce their success rate.

Tuesday, 2 September 2014

EFCC AND ATTEMPTED HACKING

On the 30th of August, 2014 Sahara Reporters posted a news story on their website; captioned: “EFCC Arrests Three Suspected Fraudsters for Attempted Hacking.” The gist of the story is that some persons conspired to break into or compromise the computer systems/computer networks of a bank using an electronic device, for the purpose of stealing funds. However; their plan failed as an insider reported them to the Economic and Financial Crimes Commission (EFCC) and they were arrested.

The caption of the story got me wondering whether there is a law in Nigeria which directly criminalizes attempted hacking or hacking or breaking into someone’s computer networks or computer systems. To the best of my knowledge there is no such law in Nigeria that directly criminalizes hacking or breaking into or compromising someone’s computer networks or computer systems? Therefore, the caption: “EFCC Arrests Three Suspected Fraudsters for Attempted Hacking.” by Sahara Reporters is inappropriate or misleading.

In the US the Computer Fraud and Abuse Act, has prohibited certain computer crimes. The Act prohibits accessing or attempting to a computer without authorization and subsequently transmitting classified government information, theft of financial information, computer fraud, transmitting code that causes damage to a computer system, trafficking in computer passwords for the purpose of affecting interstate commerce or a government computer, etc. Also in South Africa, under the Electronic Communications and Transactions (ECT) Act 25 of 2002; unauthorised access to, interception of or interference with data on a computer or computer networks is  criminalized.

However, with regard to Nigeria, there is no law like that of the US and South Africa mentioned above. It is therefore, high time that a law regulating computer/internet crime in Nigeria is enacted. The need for a law criminalizing computer crime/cybercrime in Nigeria becomes more urgent considering the drive by the Government (Central Bank of Nigeria) to encourage cashless transactions which compels people to use electronic(computer) means of transactions. Criminals may exploit weaknesses in these electronic means of transactions to defraud customers but a computer crime/cybercrime law would be able to curb such criminal acts by punishing criminals who contravene the law.

In addition to the above, many Nigerians are now taking to online transactions/ecommerce. This can be inferred from the growth and popularity of the two leading online shops in Nigeria: Konga and Jumia. It is has therefore become necessary to pass computer crime/cybercrime laws to protect users of these ecommerce channels/shops. Apart from such computer crime /cybercrime laws there is also need for a data protection law to guard against the misuse/abuse of the personal data which operators of these ecommerce sites gather and hold concerning their customers/users. For instance in China, P.R.C. Criminal Law  stipulates criminal penalties for improper sales, provision and collection of personal data. In the same China, three men were arrested for illegal sales of millions of items of personal information.