Mr. President, I am pleased that the Senate is passing legislation to help staunch the torrent of unwanted commercial e-mail, commonly known as spam. During the past year, I worked closely with Senator Hatch and other members of the…
Mr. President, I am pleased that the Senate is passing legislation to help staunch the torrent of unwanted commercial e-mail, commonly known as spam. During the past year, I worked closely with Senator Hatch and other members of the Judiciary Committee to craft criminal penalties for a variety of spammer tactics. Those penalties, which we introduced in June as part of the Criminal Spam Act, S. 1293, are included in the broader anti-spam legislation that we pass today. The bill will now go back to the House of Representatives for final approval, and then to the President for signing.
Spam is much more than a technological nuisance. In the past few years, it has become a serious and growing problem that threatens to undermine the vast potential of the Internet.
Businesses and individuals currently wade through tremendous amounts of spam in order to access e-mail that is of relevance to them--and this is after Internet Service Providers, businesses, and individuals have spent time and in some cases enormous amounts of money blocking a large percentage of spam from reaching its intended recipients.
In my home State of Vermont, one legislator recently found that two- thirds of the 96 e-mails in his inbox were spam. And this occurred after the legislature had installed new spam-blocking software on its computer system that seemed to be catching 80 percent of the spam. The assistant attorney general in Vermont was forced to suggest to computer users the following means to avoid these unsolicited commercial e- mails: ``It's very bad to reply, even to say don't send anymore. It tells the spammer they have a live address . . . The best thing you can do is just keep deleting them. If it gets really bad, you may have to change your address.'' This experience is echoed nationwide.
E-mail users are having the online equivalent of the experience of the woman in the Monty Python skit, who seeks to order a Spam-free breakfast at a restaurant. Try as she might, she cannot get the waitress to bring her the meal she desires. Every dish in the
restaurant comes with Spam; it is just a matter of how much. There is ``egg, bacon and Spam''; ``egg, bacon, sausage and Spam''; ``Spam, bacon, sausage and Spam''; ``Spam, egg, Spam, Spam, bacon and Spam''; ``Spam, sausage, Spam, Spam, Spam, bacon, Spam, tomato and Spam''; and so on. Exasperated, the woman finally cries out: ``I don't like Spam! . . . I don't want ANY Spam!''
Individuals and businesses are understandably reacting similarly to electronic spam. A Harris poll taken late last year found that 80 percent of respondents view spam as ``very annoying,'' and fully 74 percent of respondents favor making mass spamming illegal. Earlier this month, more than three out of four people surveyed by Yahoo! Mail said it was ``less aggravating to clean a toilet'' than to sort through spam. Americans are fed up.
Some 30 States now have anti-spam laws, but the globe-hopping nature of e-mail makes these laws difficult to enforce. Technology will undoubtedly play a key role in fighting spam, but a technological solution to the problem is not likely in the foreseeable future. ISPs block billions of unwanted e-mails each day, but spammers are winning the battle.
Millions of unwanted, unsolicited commercial e-mails are received by American businesses and individuals each day, despite their own, additional filtering efforts. Ferris Research has estimated that spam costs U.S. firms $8.9 billion annually in lost worker productivity, consumption of bandwidth, and the use of technical support to configure and run spam filters and provide helpdesk support for spam recipients.
The costs of spam are significant to individuals as well, including time spent identifying and deleting spam, inadvertently opening spam, installing and maintaining anti-spam filters, tracking down legitimate messages mistakenly deleted by spam filters, and paying for the ISP's blocking efforts.
And there are other prominent and equally important costs of spam. It may introduce viruses, worms, and ``Trojan horse'' programs--that is, programs that unsuspecting users download onto their computers that are designed to take control of those computers--into personal and business computer systems, including those that support our national infrastructure.
Spammers are constantly in need of new machines through which to route their garbage e-mail, and a virus makes a perfect delivery mechanism for the engine they use for their mass mailings. Some analysts said the SoBigF virus may have been created with a more malicious intent than most viruses, and may even be linked to spam e- mail schemes that could be a source of cash for those involved in the scheme.
The interconnection between computer viruses and spam is readily apparent: Both flood the Internet in an attempt to force a message on people who would not otherwise choose to receive it. Criminal laws I wrote prohibiting the former have been invoked and enforced from the time they were passed. It is the latter dilemma we must now confront.
Spam is also fertile ground for deceptive trade practices. The FTC has estimated that 90 percent of the spam involving investment and business opportunities, and nearly half of the spam advertising health products and services, and travel and leisure, contains false or misleading information.
This rampant deception has the potential to undermine Americans' trust of valid information on the Internet. Indeed, it has already caused some Americans to refrain from using the Internet to the extent they otherwise would. For example, some have chosen not to participate in public discussion forums, and are hesitant to provide their addresses in legitimate business transactions, for fear that their e- mail addresses will be harvested for junk e-mail lists. And they are right to be concerned. The FTC found spam arriving at its computer system just 9 minutes after posting an e-mail address in an online chat room.
I have often said that Congress must exercise great caution when regulating in cyberspace. Any legislative solution to spam must tread carefully to ensure that we do not impede or stifle the free flow of information on the Internet. The United States is the birthplace of the Internet, and the whole world watches whenever we decide to regulate it. Whenever we choose to intervene in the Internet with Government action, we must act carefully, prudently, and knowledgeably, keeping in mind the implications of what we do and how we do it. And we must not forget that spam, like more traditional forms of commercial speech, is protected by the first amendment.
At the same time, we must not allow spam to result in the ``virtual death'' of the Internet, as one Vermont newspaper put it.
The Internet is a valuable asset to our Nation, to our economy, and to the lives of Americans, and we should act prudently to secure its continued viability and vitality.
On June 19 of this year, Senator Hatch and I introduced S. 1293, the Criminal Spam Act, together with several of our colleagues on the Judiciary Committee. On September 25, the Committee unanimously voted to report S. 1293 to the floor. On October 22, the Senate unanimously adopted the criminal provisions of the bill as an amendment to S. 877, the CAN SPAM Act. Today, the Senate is passing these same criminal provisions as section 4 of a modified version of S. 877, as passed by the House last week.
The Hatch-Leahy criminal provisions prohibit five principal techniques that spammers use to evade filtering software and hide their trails.
First, our legislation prohibits hacking into another person's computer system and sending bulk spam from or through that system. This criminalizes the common spammer technique of obtaining access to other people's e-mail accounts on an ISP's e-mail network, whether by password theft or by inserting a Trojan horse to send bulk spam.
Second, our legislation prohibits using a computer system that the owner makes available for other purposes as a conduit for bulk spam, with the intent of deceiving recipients as to the spam's origins. This prohibition criminalizes another common spammer technique--the abuse of third parties' ``open'' servers, such as e-mail servers that have the capability to relay mail, or Web proxy servers that have the ability to generate ``form'' mail.
Spammers commandeer these servers to send bulk commercial e-mail without the server owner's knowledge, either by ``relaying'' their e- mail through an ``open'' e-mail server, or by abusing an ``open'' Web proxy server's capability to generate form e-mails as a means to originate spam, thereby exceeding the owner's authorization for use of that e-mail or Web server. In some instances the hijacked servers are even completely shut down as a result of tens of thousands of undeliverable messages generated from the spammer's e-mail list.
The legislation's third prohibition targets another way that outlaw spammers evade ISP filters: Falsifying the ``header information'' that accompanies every e-mail, and sending bulk spam containing that fake header information. More specifically, the legislation prohibits forging information regarding the origin of the e-mail message, and the route through which the message attempted to penetrate the ISP filters.
At the suggestion of the Department of Justice, this third offense has been amended since the Senate last considered it to require a showing of materiality. This means the Government must prove that the header information was altered or concealed in a manner that would impair the ability of a recipient of the message, an Internet access service processing the message on behalf of a recipient, a person alleging a violation of this title, or a law enforcement agency, to identify, locate, or respond to the person who initiated the e-mail or to investigate the alleged violation.
Fourth, the Hatch-Leahy legislation prohibits registering for multiple e-mail accounts or Internet domain names using false identities, and sending bulk e-mail from those accounts or domains. This provision targets deceptive ``account churning,'' a common outlaw spammer technique that works as follows. The spammer registers--usually by means of an automatic computer program--for large numbers of e-mail accounts or domain names, using false registration information, then sends bulk spam from one account or
domain after another. This technique stays ahead of ISP filters by hiding the source, size, and scope of the sender's mailings, and prevents the e-mail account provider or domain name registrar from identifying the registrant as a spammer and denying his registration request. Falsifying registration information for domain names also violates a basic contractual requirement for domain name registration falsification. As with the last offense, this offense now requires that the registration information be falsified ``materially.''
Fifth and finally, our legislation addresses a major hacker spammer technique for hiding identity that is a common and pernicious alternative to domain name registration--hijacking unused expanses of Internet address space and using them as launch pads for junk e-mail. Hijacking Internet Protocol--IP--addresses is not difficult: Spammers simply falsely assert that they have the right to use a block of IP addresses, and obtain an Internet connection for those addresses. Hiding behind those addresses, they can then send vast amounts of spam that is extremely difficult to trace.
Penalties for violations of these new criminal prohibitions are tough but measured. Recidivists and those who send spam in furtherance of another felony may be imprisoned for up to 5 years. Large-volume spammers, those who hack into another person's computer system to send bulk spam, and spam ``kingpins'' who use others to operate their spamming operations may be imprisoned for up to 3 years. Other offenders may be fined and imprisoned for no more than one year. Convicted offenders are also subject to forfeiture of proceeds and instrumentalities of the offense.
In addition to these penalties, the Hatch-Leahy legislation directs the Sentencing Commission to consider providing sentencing enhancements for those convicted of the new criminal provisions who obtained e-mail addresses through improper means, such as harvesting, and those who knowingly sent spam containing or advertising a falsely registered Internet domain name. We have also worked with Senator Nelson on language directing the Sentencing Commission to consider enhancements for those who commit other crimes that are facilitated by the sending of spam.
I should note that the Criminal Spam Act, from which these provisions are taken, enjoys broad support from ISPs, direct marketers, consumer groups, and civil liberties groups alike. Again, the purpose of these criminal provisions is to deter the most pernicious and unscrupulous types of spammers--those who use trickery and deception to induce others to relay and view their messages. Ridding America's inboxes of deceptively delivered spam will help clear electronic channels for Internet users from coast-to-coast. But it is not a cure-all for the spam pandemic.
The fundamental problem inherent to spam--its sheer volume--may well persist even in the absence of fraudulent routing information and false identities. In a recent survey, 82 percent of respondents considered unsolicited bulk e-mail, even from legitimate businesses, to be unwelcome spam. Given this public opinion, and in light of the fact that spam is, in essence, cost-shifted advertising, we need to take a more comprehensive approach to our fight against spam.
While I am generally supportive of the CAN SPAM Act, it does raise some concerns. For one thing, it may not be tough enough to do the job.
The bill takes an ``opt out'' approach to spam--that is, it requires all commercial e-mail to include an ``opt out'' mechanism, by which e- mail recipients may opt out of receiving further unwanted spam. My concern is that this approach authorizes spammers to send at least one piece of spam to each e-mail address in their database, while placing the burden on e-mail recipients to respond. People who receive dozens, even hundreds, of unwanted e-mails each day may have little time or energy for anything other than opting-out from unwanted spam. Meantime, CAN SPAM will sweep away dozens of State anti-spam laws, including some that were substantially more restrictive.
I am also troubled by the two labeling requirement in the CAN SPAM Act. The first makes it unlawful to send an unsolicited commercial e- mail message unless it provides, among other things, ``clear and conspicuous identification that the message is an advertisement or solicitation,'' and ``a valid physical postal address of the sender.'' The second--added as a floor amendment during Senate consideration of the bill in October--requires ``warning labels'' on any commercial e- mail that includes ``sexually oriented material.''
While we all want to curb spam and protect our children from inappropriate material, there are important first amendment concerns to regulating commercial e-mail in ways that require specific labels on protected speech. Such requirements inhibit both the speaker's right to express and the listener's right to access constitutionally protected material.
In addition, the bill's definition of ``sexually oriented material'' as any material that ``depicts'' sexually explicit conduct seems overly broad. According to Webster's dictionary, ``depict'' may mean either to represent by a picture or to describe in words. It is my hope that the FTC, which has some rulemaking authority with respect to this labeling requirement, will clarify that it applies to ``visual'' depictions only.
The CAN SPAM Act may not be perfect, but it is a serious effort to address a difficult and urgent problem. I support its passage today, and commend the bipartisanship that was needed to get this done.