55. Cybercrime Knows No Borders,
InfoSecurity Magazine, (19 May 2011), at
http://www.infosecurity-magazine.com/
magazine-features/cybercrime-knows-noborders/.
56. WDR, supra § 1 A, note 10, at 222. While
such actions “blur[ ] the lines between
acts of cybercrime and cyberwar or
cyberterrorism,” it is nonetheless the
responsibility of the government to assure
public safety and security in cyberspace.
Ibid. at 223.
57. The first free, widely used end-to-end
encrypted messaging software was PGP
(“Pretty Good Privacy”), coded by Phil
Zimmermann and released in 1991. Andy
Greenberg, “Hacker Lexicon: What Is
End-to-End Encryption?,” Wired, (25 Nov.
2014), at https://www.wired.com/2014/11/
hacker-lexicon-end-to-end-encryption/.
58. Greenberg, ibid.
59. Ibid.
60. Information theory can be used to render
a cryptosystem information-theoretically
secure, and therefore cryptanalytically
unbreakable, even when the adversary
has unlimited computing power. Ueli
Maurer, “Information-Theoretically
Secure Secret-Key Agreement by NOT
Authenticated Public Discussion,” in:
EUROCRYPT’97 Proceedings of the
16th annual international conference on
Theory and application of cryptographic
techniques, (1997), pp. 209–25, at ftp://
ftp.inf.ethz.ch/pub/crypto/publications/
Maurer97.pdf.
61. Greenberg, supra note 57.
62. PFS-perfect forward secrecy is a technique
used, for instance, by TextSecure, an
SMS application for Android, and the
software integrated by WhatsApp into
its messaging services. See, e.g., Dan
Goodin, “WhatsApp Brings Strong Endto-end Frypto to the Masses,” Quora, (18
Nov. 2014), at https://www.quora.com/
How-secure-is-WhatsApps-new-end-toend-encryption.
63. For a discussion of the mathematics
behind cracking computer cyphers, see,
e.g., “The Math Behind Estimations to
Break a 2048-bit Certificate,” DigiCert,
at https://www.digicert.com/TimeTravel/
math.htm.
64. “256-bit AES key” means that every
256-bit number is a valid key or modulus.
Having superseded DES (Data Encryption
Standard), AES (Advanced Encryption
Standard) is a symmetric encryption
algorithm (specifically, a block cypher)
in use worldwide, which is defined over
keys of 128, 192 and 256 bits. Symmetric
algorithms are designed to be as simple
and quick as possible (for cryptography),
and retain a high level of security. See,
e.g., “Why Do You Need a 4096-bit
DSA Key When AES Is Only 256-Bits?,”
Information Security Stack Exchange,
at http://security.stackexchange.com/
questions/59190/why-do-you-need-a4096-bit-dsa-key-when-aes-is-only-256bits; “What Does ‘Key with Length of
X Bits’ Mean?,” Information Security
Stack Exchange, at http://security.
stackexchange.com/questions/8912/whatdoes-key-with-length-of-x-bits-mean.
65. “Why Do You Need a 4096-bit DSA Key
When AES Is Only 256-Bits?,” ibid.
66. Mary-Ann Russon, “Quantum
Cryptography Breakthrough:
‘Unbreakable Security’ Possible Using
Pulse Laser Seeding,” International
Business Times, (7 Apr. 2016), at
http://www.ibtimes.co.uk/quantumcryptography-breakthrough-unbreakablesecurity-possible-using-pulse-laserseeding-1553721. China has made
particular advances in the development
of such technology; for the implications
of implications of such advances, see
Andreas Illmer, “China Set to Launch an
‘Unhackable’ Internet Communication,”
BBC News, (25 July 2017), at http://www.
bbc.com/news/world-asia-40565722.
67. Greenberg, supra note 57.
68. See also Nandagopal Rajan, “WhatsApp
Is Not Breaking Indian Laws with 256-Bit
Encryption, for Now,” Indian Express, (12
Apr. 2016), at http://indianexpress.com/
article/technology/social/whatsapp-endto-end-encryption-not-illegal-in-india/.
69. Russon, supra note 66.
70. Brendan J. Sweeney, Global Competition:
Searching for a Rational Basis for Global
Competition Rules, Sydney Law Review,
Vol. 30 (2008), p. 209.
71. Budapest Convention, supra § 1 B, note
32.
72. EU Council Framework Decision
2005/222/JHA (24 Feb. 2005) on Attacks
against Information Systems, at http://
eur-lex.europa.eu/legal-content/EN/
ALL/?uri=CELEX:32005F0222.
Page 60 | Chapter 1 | End Notes
73. EU Council Framework Decision 2004/68/
JHA (22 Dec. 2003) on combating the
sexual exploitation of children and child
pornography. The Framework Decision
was replaced by Directive 2011/93/
EU of the European Parliament and
of the Council of 13 December 2011
on combating the sexual abuse and
sexual exploitation of children and child
pornography. See OJ 2011 L 335 (17 Dec.
2011), pp. 1–17.
74. Directive 2006/24/EC of the European
Parliament and of the Council of 15 March
2006 on the retention of data generated
or processed in connection with the
provision of publicly available electronic
communications services or of public
communications networks and amending
Directive 2002/58/EC [2006] OJ L105/54
(“Data Retention Directive”).
75. European Commission v. Hungary,
[hereafter, “Commission v. Hungary”],
Case number C-286/12, [CJEU] (8 Apr.
2014), at http://curia.europa.eu/juris/
documents.jsf?num=C-293/12; EUR-Lex,
Official Journal of the European Union, (8
Apr. 2014).
76. Richard W. Downing, “Shoring Up
the Weakest Link: What Lawmakers
Around the World Need to Consider
in Developing Comprehensive Laws to
Combat Cybercrime,” Columbia Journal
of Transnational Law, Vol. 43 (2005), p.
705; Erin I. Kunze, “Sex Trafficking Via the
Internet: How International Agreements
Address the Problem and Fail to Go Far
Enough,” Journal on Telecommunications
& High Technology Law, Vol. 10 (2010),
p. 241; Miriam F. Miquelon-Weismann,
“The Convention on Cybercrime:
A Harmonized Implementation
of International Penal Law: What
Prospects for Procedural Due Process,”
John Marshall Journal Computer &
Informational Law, Vol. 23 (2005), p. 329;
Deborah Griffith Keeling & Michael M.
Losavio, “A Comparative Review of
Cybercrime Law and Digital Forensics in
Russia, the United States and under the
Convention on Cybercrime of the Council
of Europe,” Northern Kentucky University
Law Review, Vol. 39 (2012), p. 267.
77. Viano, supra § 1 B, note 39, at 342–44.
78. Ibid., at 347–53.
79. Convention on the Protection of
Children against Sexual Exploitation
and Sexual Abuse, CoE, (25 Oct. 2007)
CETS No. 201 [hereafter, “Lanzarote
Convention”], at http://conventions.
coe.int/Treaty/Commun/ChercheSig.
asp?NT=201&CM=&DF=&CL=ENG.
Table of Contents