The Mugshot Heard ‘round the World

It was no surprise that the mugshot was immediately copied onto tees, hats, coffee mugs, etc. and sold to Americans who see either a martyr or a traitor in the same image. It was also no surprise that Team Trump produced merch of its own to sell for campaign (a.k.a. criminal defense) fundraising purposes. But these and other uses of the photograph have fostered some legal discussions on chat boards and elsewhere as to who, if anyone, has the right to control the exploitation of the mugshot. And so, I offer my own takes for what they’re worth.

Who Owns the Copyrights in the Image?

This is actually two questions:  1) is the Trump mugshot copyrightable at all? and 2) if so, who would be the owner of the copyright? Opinions will vary, but in my view, there are several factors that militate against enforceable copyright in this photograph, which is tantamount to having no copyright at all. If any party could own the copyright, it would logically be the State of Georgia or Fulton County, but aside from the fact that neither entity is likely to file a registration application for the photo with the Copyright Office, there is arguably no basis for finding sufficient originality in the image.

The mugshot photo station at the jailhouse is presumably as static as a surveillance camera—arranged to capture the same, fact-intensive photo for a highly utilitarian, informative purpose. No human (e.g., officer or clerk) can reasonably claim to have made any creative choices to produce original expression in the Trump mugshot, and this militates against copyright rights, which would then automatically transfer to the state or county employer. If there is any expression in the image at all, it is arguably Trump’s “creative” choice to make the angry face. But although I have explored the question of co-authorship by subjects in photographs, this is 1) a thought experiment outside the bounds of case law; and 2) a theory that would likely find less foundation in an image that is more factual than expressive in nature.

For these reasons alone, I believe the image would not be copyrightable, even if the state entity were to try to register the photograph with the Copyright Office. But no matter what, there is no legal authority under which Trump could own the copyright.

Can the Trump Campaign Control the Merch?

On August 29, Trump campaign adviser Chris LaCivita posted on X, “If you are a campaign, PAC, scammer and you try raising money off the mugshot of @realDonaldTrump and you have not received prior permission…WE ARE COMING AFTER YOU…you WILL NOT SCAM DONORS.”

Notwithstanding the tongue-biting irony of Team Trump using the word scam, LaCivita’s message could be read as a valid warning to any parties that might pretend to be the Trump campaign, but that would be an odd statement in regard to the mugshot because this type of fraud has nothing to do with use of the photograph per se. If, instead, LaCivita means to imply that the Trump campaign has an exclusive right to sell “official” mugshot merchandise for commercial purposes—or to prevent use of the image to raise funds in opposition to Trump—then he’s dead wrong on the law, as that crowd so often is.

Trademark Law Does Nothing for Trump

Although it is permissible to register trademarks in certain words or images used in political campaigns (e.g., slogans or logos), there are both administrative and doctrinal reasons why the Trump campaign could not claim the mugshot as a service mark. As a practical matter, the trademark claimant must use the relevant mark in trade when applying for protection and then go through a rather lengthy process to affirm the mark remains in use—and use in a specific class (or classes) of goods and/or services.

But in this case, the instant the mugshot was shared with the world, it conveyed irreconcilably divergent meanings to the public. So, under trademark practice, could Trump assert the exclusive right to use the “mark” in a class called Multiply Indicted, Seditious Former Presidents? Probably not since no such class exists. But that’s generally what the image conveys to millions of Americans, and the purpose of trademark is to protect the earned integrity of brands, not to burnish the reputations of politicians reviled by more than half the population.

What About Trump’s Likeness?

It may not be Trump’s mugshot as IP, but it is certainly his mug, and doesn’t his right of publicity (ROP) allow him to control how his likeness is used? As discussed in context to artificial intelligence, ROP laws are statutory in half the states, common law elsewhere, and there is no federal ROP statute. Most importantly, though, ROP generally applies to commercial use of an individual’s likeness for endorsement or advertising purposes. Thus, Susan Scafidi, founder of the Fashion Law Institute is off the mark, as quoted in the New York Times stating, “Trump could, in theory, attempt to shut down sales of merch with his mug shot, not unlike the way Obama objected to appearing on a Weatherproof Garment Company billboard…”

I believe this is incorrect. Unauthorized use of a likeness (even of a political figure) for commercial advertising is likely to be a paradigmatic violation of ROP. So, if an entity were to use the Trump mugshot to promote its goods or services, Trump should have a strong legal foundation for stopping that use.[1] By contrast, reproducing the mugshot for the purpose of mocking, criticizing, or downright hating any political figure is protected speech at the core of the First Amendment, and Trump would have no legal foundation to enjoin such uses.

But what if the mugshot is reproduced (on merch or elsewhere) without accompanying commentary? If I walk through town wearing a tee shirt with the unaltered mugshot on it, observers who don’t know me would have no idea whether I am celebrating or denouncing the Georgia arraignment. So, does this ambiguity alter the First Amendment consideration such that Trump would have any grounds to stop the production of merchandise that merely reproduces the photo? Again, I would say no if only because the mugshot is a factual statement of extraordinary newsworthy value to the public. Thus, the production and distribution of merchandise bearing no communication other than the image should still be protected by the speech and press rights, even if the right of redress is not implicated.

So, that’s my 50 cents on some of the legal discussion surrounding this image, which may one day be more widely reproduced than Alberto Korda’s photograph of Che Guevara.[2] Of course, this is all nerdy food for thought because it’s hard to imagine that any of these questions will ever be presented in court. Even if Team Trump could show standing, they have bigger sheep to fleece and zero hope of controlling the perception of millions that a mugshot is usually just a photograph of a criminal.


[1] It is of course possible to blur the line between a company’s politics and its marketing, which would result in a fact-intensive inquiry into the matter. Likewise, a not-for-profit could promote a policy message that Trump does not endorse and use the mugshot to illustrate the opposition, and this should not be a violation of ROP.

[2] Ironically, this is actual and rampant infringement of the photographer’s copyright rights.

How the Supreme Court Made Life Harder for Victims of Cyberstalking

It was such a busy Summer that I never got a chance to write about the Supreme Court’s June decision in the cyberstalking case Counterman v. Colorado. The story caught my attention when legal scholar and president of Cyber Civil Rights Initiative Mary Anne Franks tweeted, “the Supreme Court has just decreed that stalking is free speech protected by the First Amendment if the stalker genuinely believes his actions are non-threatening. That is, the more deluded the stalker the more protected the stalking.” [1] The key facts as summarized in the opinion are as follows:

Billy Counterman sent hundreds of Face­book messages to C. W., a local singer and musician. The two had never met, and C. W. did not respond. In fact, she tried repeatedly to block him, but each time, Counterman created a new Facebook account and resumed contacting C. W. Several of his messages envisaged vio­lent harm befalling her. Counterman’s messages put C. W. in fear and upended her daily existence: C. W. stopped walking alone, declined so­cial engagements, and canceled some of her performances. C. W. even­tually contacted the authorities. The State charged Counterman un­der a Colorado statute making it unlawful to “[r]epeatedly . . . make[] any form of communication with another person” in “a manner that would cause a reasonable person to suffer serious emotional distress and does cause that person . . . to suffer serious emotional distress.”

Read accounts of people who have been cyberstalked, and the stories are often harrowing. The content of the stalker’s communication doesn’t even have to be threatening, though it usually gets there. Just knowing that somebody (usually a man) has selected you (usually a woman) as a target for unwanted attention can be unnerving to the point that it can have life-altering consequences including general anxiety, fear of movement, fear of speech, job and opportunity loss, and even suicide. That can be true even if the stalker doesn’t take or induce any action outside cyberspace, though many incidents that begin online eventually become physical and violent contact.

To be clear, no member of the Court defended (nor do I believe would defend) Counterman’s conduct. The question addressed was what legal standard should have been applied in the enforcement of the Colorado law to determine the threshold where the defendant’s speech is no longer protected by the First Amendment. At trial, the state court applied an “objective” standard to determine whether the content of the speech at issue would be perceived by a reasonable observer as a “true threat,” a term of art that encompasses one category of unprotected speech—threats of violence.

The Supreme Court majority held that Colorado erred by not applying a “subjective” standard, under which it must be shown that the defendant intended to threaten plaintiff or had reason to know that the speech at issue was threatening; and the Court further held that it would be sufficient to show that a defendant recklessly disregarded the threatening nature of his communications. Hence, Dr. Franks’s observation that the more unreasonable the cyberstalker the more likely his online harassment will be protected speech. And how many cyberstalkers are reasonable?

Sound Dissent by Justice Barrett

Noting that I do not have a deep knowledge of the relevant case law, Justice Barrett’s dissent (joined by Thomas) reads as the better argument—both as law and common sense. The dissent argues that the majority singled out “true threats” in this case for preferential treatment to fashion a “Goldilocks decision” (i.e., inventing a middle ground that is neither necessary nor consistent with precedent). “True threats do not enjoy First Amendment protection, and nearly every other category of unprotected speech may be restricted using an objective standard,” the dissent states.

The extent to which the Court departs from precedent is difficult to comment upon without studying all the underlying First Amendment case law, but Justice Barrett’s focus on “context” rings soundly as a rationale that an objective standard can maintain the balance between protected and unprotected speech. “…the statement must be deemed threatening by a reasonable listener who is familiar with the ‘entire factual context’ in which the statement occurs [citation omitted]. This inquiry captures (among other things) the speaker’s tone, the audi­ence, the medium for the communication…” Barrett writes.

Indeed, any target of online stalking knows instinctively that words as seemingly unthreatening as You look lovely today may indeed be threatening if, for example, the statement comes from a stranger or an angry, obsessive ex-husband or boyfriend. Weighing the legality of speech without context—not just online, but anywhere—is a half-baked analysis. For instance, “Vote for me or you won’t have a country anymore” delivered on the stump is protected hyperbole, while “Fight like hell, or you won’t have a country anymore” delivered to an angry mob ready to march to the Capitol is considered by many reasonable observers to be incitement.

Justice Barrett highlights the Colorado cyberstalking statute (and notes that other states have similar laws) as an example of a contextual, objective analysis in which juries are instructed to weigh the defendant’s communications in a five-factor test to thoroughly understand the nature of the speech.[2] “Each considera­tion helps weed out protected speech from true threats,” she writes, and again, this strikes me as the more rational approach to address the alleged crime at issue.

Further, the dissent argues that the majority leans heavily and improperly on the 1964 case New York Times v. Sullivan. There, the Court held that it is necessary to prove that a defendant showed reckless disregard for the known falsity of a statement in order for a public figure to obtain damages relief for libel or defamation. But citing subsequent case law from 1974 and 1985, Justice Barrett argues that Sullivan applies to public parties while, “A private person need only satisfy an objective standard to recover actual damages for defamation. And if the defamatory speech does not involve a matter of public concern, she may recover punitive damages with the same showing.” [Citations omitted]

Assuming the dissent is correct about the majority’s inapt reliance on Sullivan in this case, the public/private distinction is significant because a typical cyberstalking incident involves ordinary citizens rather than public figures—let alone “matters of public concern.” If someone tweets at Sen. Tuberville and calls him a sniveling, treasonous, ignorant weasel who should have been aborted, that is paradigmatically protected speech. Elected officials volunteer for public scorn as a bedrock principle of the First Amendment,[3] and it would be an offense to two of the amendment’s freedoms if it were sufficient to find some cohort willing to call that tweet a “true threat.” Thus, evidence of the speaker’s intent and ability to cause violence must be present before his speech may be considered unprotected.

By contrast, the cyberstalker who tells his target that he wishes she were dead or writes that her death is imminent or that he hopes she gets raped, etc. may not express a “true threat” by words alone, but in context, the messages can have the same effect as a “true threat.” Even facially innocuous communication can be used to make a private individual feel threatened, especially when she has no idea who she’s dealing with, or what his intent might be.

By the time the target of a cyberstalker turns to law enforcement for relief, she has usually suffered substantial harassment, fear for her safety, and some form of irreparable damage to her liberty and/or financial interests. In Counterman, the Court compounds these injuries by elevating the standard for punishing an alleged cyberstalker to one in which a jury must read the mind of the defendant to find that he both understood and recklessly disregarded the threatening nature of his communication. This sets the bar higher than necessary in cases where the speech at issue is of no public interest other than, in most cases, making it stop.

The Tech-Utopian Concept of the Speech Right Lives in this Case

Unsurprisingly, the Electronic Frontier Foundation filed an amicus brief for the petitioner in Counterman stating, “This Court should make clear that the definition of a true threat necessarily includes a subjective speaker’s intent to threaten.” True to form, the EFF inflated its brief with praise for the scope, scale, and cultural significance of social media; and it cites examples of violent terms or rhetoric, which may be interpreted as threatening but may still be protected. Notably, no variant of the word stalking appears in the EFF’s brief.

All that general discussion about the value of social media as an alleged free speech machine may be true in certain contexts, but it should be seen as irrelevant in regard to cyberstalking. Because here’s where the “digital rights” organizations err, and where the Court has now made matters worse:  cyberstalking is action more than it is speech. It may take the form of words and/or images, but the ongoing contact itself is intended to cause suffering, and very often, it succeeds in doing just that. As Dr. Franks put it, quoted in Reuters shortly after the decision:

It is deeply disappointing that the Supreme Court has chosen not only to allow stalkers to act with impunity, but to do so on the basis that stalking is free speech protected by the First Amendment. In doing so, they have sentenced victims of stalking to potentially lifelong sentences of terror, as well as increasing their risk of being killed by their stalkers.


If you or anyone you know is a target of cyberstalking the two best resources I know are Cyber Civil Rights Initiative  and the Carrie Goldberg Victims’ Rights Law Firm.

[1] Dr. Franks also offered some sharp comments about the joking around at oral arguments, reflecting insensitivity to the dangers and traumas experienced by targets of cyberstalking. https://twitter.com/ma_franks/status/1648724142198226946

[2] (1) the statement’s role in a broader exchange, if any, including surrounding events; (2) the medium or platform through which the statement was communicated, including any distinctive conventions or architectural features; (3) the manner in which the statement was conveyed (e.g., anonymously or not, privately or publicly); (4) the relationship between the speaker and recipient(s); and (5) the subjective reaction of the statement’s intended or foreseeable recipient(s).

[3] This is a reference to Sen. Tuberville’s holding up military promotions to protest the DOD’s healthcare policy vis-à-vis abortion.

Photo source by: SBArtsMedia

Hacked Off at Facebook

Well, it finally happened. After criticizing the worst effects of social media for over 10 years, I was finally hacked, locked out of my Facebook account, and (I assume) will be unable to restore any of the material or connections going back to 2007. I’m sharing the details in this post because what I now believe to be a phishing-style attack had the appearance of Meta erroneously booting me for failure to comply with community standards. And frankly, Meta is so useless from a support standpoint that it hardly matters.

Whether Facebook moderators are in error, or the account was targeted by a hacker, there is no clear process for the average user to remedy either issue—just a Kafka-designed carousel of unhelpful articles and FAQs. And of course, beyond Facebook’s garden wall, one finds more scammers with offers to “help” because if you recently fell prey to a hacker, you’re bleeding in shark-infested waters.

Hacker or Facebook Moderators?

I say the attack was phishing-like because the initial communication did not come through email. Those are common enough and usually easy to spot. The email with the slightly blurry logo and wrong URL that claims to be your bank or insurance company or some other party with a message, invoice, or payment for you is trying to get you to click a link and download malware. As I say, these are easy enough to recognize and delete. But in this case, the communication came from within the Meta/Facebook environment—and not just as a DM in the Chat app.

Initially, I received messages from “Meta Business” in the Meta Business section of the platform. These were directed to me as the administrator of the Illusion of More page and not to me personally. I was told that IOM had been reported for (get this!) a copyright violation. As I do not engage in copyright violations, I responded to say that an error had been made, believing that I was writing to Meta since I was clearly on the Meta Business page and not some bogus URL. Unsurprisingly, there was no response, and a few days later, I was told in the same thread that my business page had been disabled. But the IOM page was not disabled, and I did not know what to make of the messages, especially when communication with Meta is not an option.

A few days later, I received a message directed to me personally, again within the Facebook platform, stating that an attempted login had occurred from an unusual location. I took the recommendation to change my password, and I do not believe I clicked on anything outside the Facebook universe such that I might provide the new password to a hacker. Nevertheless, several hours later, my personal account was disabled, and the relevant email and phone number were newly associated with an account called “Meta Copyright Infringement.”

I created a new personal account and did a search for “Meta Copyright Infringement” as People and found that many accounts have suffered this same fate. Some appear to still have pages intact, while others are blank:

Attacks of this nature have been reported since at least the start of 2023, but the articles I found all describe phishing via email, which is usually the vector. But unless I was truly distracted, all communication I received was within the Meta environment, and if hackers are spoofing Meta from within Meta, this implies a new and sophisticated campaign to acquire login credentials.

As for the rationale of the hacker(s), it is hard to say. In my case, as a copyright advocate, I can be a target for an anti-copyright hacker who just wants to mess with me. But so far, nothing inappropriate seems to have appeared on Facebook in my name. In fact, that account appears to have been deleted altogether. On the other hand, this just happened, so we’ll see. In the meantime, I no longer have control of two business pages, including Illusion of More on Facebook, because I was the sole administrator.

As mentioned above, this apparent hack is barely distinguishable from Meta disabling my account for an alleged violation of community standards, and the company offers zero remedies to address either issue. I mean, yeah, there’s a Help Center, but it makes the average DMV look like a hotel concierge. Meta provides a “review form” for disabled accounts, but this “form” only asks the customer to input a name, email, and a copy of ID to prove identity. But, of course, if the email entered is associated with a disabled account, you get a message saying that the account doesn’t exist, which indicates a hack, so…

Follow the instructions for recovering an account you think was hacked, and Meta will help you identify the account associated with the email…

Assuming that’s what FB thinks my account is now, I reluctantly click This is My Account, and…

And you can guess where that link “here” leads. Yup. Right back onto the carousel playing the calliope from Hell mocking you for getting on the ride in the first place.

I don’t know. Maybe I missed a clue somewhere in the attack, but the most compelling detail here is that it looked a lot like communication from Meta and within Meta. In fact, if Meta were to contact me at some point and confirm that they did kick me off for an alleged copyright violation, I would not be very surprised—except that it would still be an error. But apparently, this is what support looks like for a platform hosting three-billion people:  when we can’t quite tell the difference between a cyber-attack and half-assed moderation insulated from its users by layers of bullshit.