Murthy v. Missouri, Jawboning, and How What the Supreme Court Had to Say Could Bear on Cybersecurity and Online Speech
Cathy Gellis
ShmooCon XX (Final) · Day 2 · Bring It On
Overview
In an era defined by rapid information dissemination and heightened scrutiny of online content, the interplay between governmental influence and private platform moderation has become a contentious battleground. Cathy Gellis's ShmooCon talk, "Murthy v. Missouri, Jawboning, and How What the Supreme Court Had to Say Could Bear on Cybersecurity and Online Speech," delves into the intricate legal landscape surrounding the First Amendment, government "jawboning," and the Supreme Court's recent pronouncements. Gellis, a seasoned lawyer and frequent contributor to Techdirt, aims to demystify this complex and often misunderstood area, providing attendees with the analytical tools to discern what constitutes legitimate government interaction versus unconstitutional coercion in the realm of online speech.

Key moments
- 0:00 Welcome and introduction to Murthy v. Missouri and jawboning
- 2:00 Important legal disclaimer and speaker's qualifications
- 3:15 First Amendment basics: government vs. private censorship
- 5:00 Definition of 'jawboning' and its First Amendment implications
- 5:45 NRA v. Vullo: an offline example of jawboning
- 6:20 Internet platforms' First Amendment right to moderate content
- 7:00 Moody v. NetChoice: platforms' editorial discretion confirmed
Murthy v. Missouri, Jawboning, and How What the Supreme Court Had to Say Could Bear on Cybersecurity and Online Speech
Speakers: Cathy Gellis, Lawyer, Writer at Techdirt
Conference: ShmooCon
YouTube: https://www.youtube.com/watch?v=yIutY_X2FcU
Overview
In an era defined by rapid information dissemination and heightened scrutiny of online content, the interplay between governmental influence and private platform moderation has become a contentious battleground. Cathy Gellis's ShmooCon talk, "Murthy v. Missouri, Jawboning, and How What the Supreme Court Had to Say Could Bear on Cybersecurity and Online Speech," delves into the intricate legal landscape surrounding the First Amendment, government "jawboning," and the Supreme Court's recent pronouncements. Gellis, a seasoned lawyer and frequent contributor to Techdirt, aims to demystify this complex and often misunderstood area, providing attendees with the analytical tools to discern what constitutes legitimate government interaction versus unconstitutional coercion in the realm of online speech.
The presentation dissects the landmark Murthy v. Missouri case, which examined the extent to which executive branch agencies, including those focused on cybersecurity, can communicate with social media platforms about content moderation without infringing upon free speech rights. Gellis meticulously explains the foundational principles of the First Amendment, clarifying that its protections primarily apply to government actions, not those of private entities. This distinction is crucial for understanding the nuances of "jawboning"—the informal but potentially coercive pressure exerted by the government on third parties to suppress speech it dislikes.
Ultimately, Gellis's talk serves as an essential guide for anyone navigating the complexities of online speech, government oversight, and platform responsibility. It is particularly pertinent for the cybersecurity community, as it illuminates the delicate balance between federal agencies sharing critical threat intelligence (e.g., CISA's role) and the imperative to safeguard the First Amendment. By unpacking the legal precedents and the specific findings of Murthy v. Missouri, Gellis empowers her audience to critically evaluate news reports and public discourse, distinguishing between legitimate concerns about government overreach and common misconceptions regarding free speech online.
Background
▶ Watch: Welcome and introduction to Murthy v. Missouri and jawboning (0:00)
To understand the implications of Murthy v. Missouri, it's essential to establish a firm grasp of First Amendment principles and the concept of jawboning. The First Amendment famously states, "Congress shall make no law respecting an establishment of religion, or prohibiting the free exercise thereof; or abridging the freedom of speech, or of the press; or the right of the people peaceably to assemble, and to petition the Government for a redress of grievances." A critical takeaway, often misunderstood by the public and even prominent technology executives, is that this amendment primarily restricts the government from abridging speech. Private parties, conversely, retain the right to favor or disfavor speech as they choose.
This distinction is foundational. A private entity, such as a conference organizer like ShmooCon, is entirely within its rights to select which talks to host and which to reject, exercising its own editorial discretion. Rejected speakers cannot claim their First Amendment rights were violated because ShmooCon is a private actor. This principle extends directly to internet platforms. These platforms—Facebook, X (formerly Twitter), YouTube, and others—are private companies that moderate content, make choices about what speech to associate with, and decide which speakers to host. Their decisions to remove content or ban users do not, in themselves, constitute a First Amendment violation, as they are not the government. However, the situation becomes legally precarious when the government attempts to influence these private moderation decisions.
This leads to the concept of jawboning. Jawboning occurs when the government, unable to directly censor speech due to First Amendment constraints, instead pressures a third party to act against speech it dislikes. If this pressure becomes sufficiently coercive, it can be deemed an unconstitutional workaround of the First Amendment. A clear offline example of this dynamic was seen in NRA v. Volo. In that case, a New York insurance regulator, disapproving of the NRA's speech, pressured insurance companies to cease doing business with the organization. The Supreme Court ruled this action violated the First Amendment, as it amounted to the government using a third party to target speech it disfavored.
The application of these principles to internet platforms was further solidified by the Supreme Court in cases like Moody v. NetChoice and NetChoice v. Paxton. These cases challenged Florida and Texas laws that attempted to dictate how social media platforms should moderate content. The Court's implicit stance in these decisions, and more explicitly stated in Murthy, confirmed that platforms possess their own First Amendment rights, including the right to exercise editorial discretion over the content they host. This mirrors the precedent set in Miami Herald v. Tornillo (1974), where the Supreme Court affirmed a newspaper's right to choose what content to publish, rejecting a Florida law that mandated certain op-eds be run in response to others. Thus, the legal framework acknowledges internet platforms as having significant autonomy over their content, akin to traditional publishers, but also sets the stage for conflict when governmental interests intersect with that autonomy.
Key Findings
▶ Watch: First Amendment basics: government vs. private censorship (3:15)
The central focus of Cathy Gellis's talk, Murthy v. Missouri, brought the complex issue of government-platform interaction to the forefront. The case involved plaintiffs who alleged that various U.S. executive agencies, including the Cybersecurity and Infrastructure Security Agency (CISA), had coerced large social media platforms into removing or suppressing speech, particularly related to election disinformation and COVID-19. The platforms, while developing their moderation policies, were indeed engaged in conversations with these agencies. For instance, CISA reportedly acted as a "switchboard," relaying information about potential election disinformation to platforms so they could factor it into their own moderation decisions.
However, the crucial finding of the Supreme Court was that the plaintiffs ultimately lost on standing grounds. This means they failed to demonstrate a sufficient injury or, more specifically, a direct causal link between the government's actions and the removal of their speech. The Court determined that while conversations between government agencies and platforms were ongoing, there was no evidence of coercion. Gellis emphasized that the record did not show any "or else" threats—no indication that platforms faced negative repercussions if they chose not to act on the government's suggestions. The platforms remained "completely free to leave it up or take it down or do whatever that pleased them." Their moderation decisions, though often consistent with the agencies' advice, were ultimately their own.
This finding carries several significant implications. Firstly, it reaffirms that mere communication between government and private platforms is not inherently unconstitutional. In a functional democracy, the right to petition allows individuals and entities (including corporations) to communicate with their government, and vice versa. It is logical and often beneficial for platforms, when crafting moderation policies, to consult with government agencies possessing specialized expertise. For example, when dealing with disinformation about vaccines, it makes sense for platforms to seek input from federal health agencies. Similarly, in the cybersecurity domain, platforms benefit immensely from intelligence shared by agencies like CISA regarding emerging threats, foreign influence operations, or specific vulnerabilities.
Secondly, the lawsuit itself had a chilling effect on these vital lines of communication. While the Murthy litigation was ongoing, many executive agencies ceased or significantly curtailed their interactions with platforms, fearing legal repercussions. This meant that valuable expertise and resources from government agencies became unavailable to platforms, potentially hindering their ability to effectively combat disinformation or respond to security threats. The Supreme Court's decision, by clarifying the threshold for unconstitutional coercion, aims to restore the ability of government and private entities to engage in productive dialogue without immediately triggering First Amendment concerns, provided such dialogue remains non-coercive.
Technical Deep Dive
▶ Watch: Definition of 'jawboning' and its First Amendment implications (5:00)
The "technical deep dive" in the context of Murthy v. Missouri and jawboning is less about code or protocols and more about the intricate legal and constitutional mechanics governing online speech. The core technicality here lies in the precise interpretation and application of the First Amendment, particularly the distinction between government action and private action, and the specific legal standard for proving coercion.
At its heart, the First Amendment is a restraint on government power. It dictates that "Congress shall make no law..." which has been extended via the Fourteenth Amendment to state and local governments. This fundamental principle means that a private entity, like a social media platform, exercises its own First Amendment rights when it decides what content to host or remove. This was explicitly affirmed in Moody v. NetChoice, where the Court recognized platforms' "editorial discretion," likening them to traditional publishers. For a platform's moderation decision to become a First Amendment violation, the government must be deemed to have transformed the private action into a state action.
The mechanism for doing so is typically through coercion. Gellis highlights that the plaintiffs in Murthy v. Missouri failed to demonstrate this coercion. The legal bar for proving coercion is high; it requires evidence of an "or else" threat. This is not merely suggesting, advising, or even strongly recommending. It requires a clear indication that the government would impose some penalty, sanction, or negative consequence on the platform if it did not comply with the government's wishes regarding specific content. Without such a threat, the platforms' decisions are presumed to be their own, made in the exercise of their private editorial judgment.
The case also grappled with the right to petition, another crucial First Amendment component. This right ensures that people (and, by extension, corporations) can communicate with their government. Conversely, it implies that the government can also communicate with its constituents and various stakeholders. Prohibiting government agencies from sharing information or expertise with platforms would undermine this right and hamstring the government's ability to inform and be informed, especially on matters of public interest like national security, public health, or election integrity. For instance, CISA (Cybersecurity and Infrastructure Security Agency) regularly shares threat intelligence with private sector entities, including social media companies, to help them defend against cyberattacks and foreign influence operations. Restricting such communication purely out of fear of a First Amendment violation could severely impede collective cybersecurity efforts.
The outcome of Murthy v. Missouri underscores that the line between permissible information sharing and unconstitutional coercion is fact-specific. It's not about the content of the government's communication (e.g., "this is disinformation") but the nature of the interaction. Was it a suggestion, or a directive backed by a credible threat of adverse action? The Court found that in Murthy, the interactions largely fell into the former category. This means that while government agencies must remain vigilant about the manner of their communication, they are not entirely barred from engaging with platforms on content-related issues, particularly when sharing information within their domain of expertise. The "technical deep dive" here is into the legal architecture that permits such interaction while attempting to prevent its abuse.
Demo / Proof of Concept
▶ Watch: Internet platforms' First Amendment right to moderate content (6:20)
This presentation, being a legal and constitutional analysis of Supreme Court rulings and First Amendment principles, did not feature a technical demonstration or a proof of concept. Cathy Gellis's talk focused on explaining complex legal frameworks and their implications rather than showcasing software, tools, or exploit techniques. The "proof" offered was in the form of legal precedent and detailed argumentation regarding the interpretation of constitutional law.
Defensive Implications
▶ Watch: Moody v. NetChoice: platforms' editorial discretion confirmed (7:00)
Understanding the nuances of Murthy v. Missouri and the concept of jawboning has significant defensive implications for various stakeholders in the online ecosystem, particularly those involved in cybersecurity and content moderation.
For internet platforms and technology companies, the primary implication is a clearer, albeit still delicate, understanding of the boundaries for government interaction. Platforms should recognize that they retain their First Amendment right to editorial discretion. This means they are not compelled to take down content simply because a government agency suggests it, unless that suggestion is accompanied by a credible, coercive "or else" threat. They should, however, continue to engage with government agencies like CISA (Cybersecurity and Infrastructure Security Agency) for legitimate information sharing. CISA, for instance, is a vital source of intelligence regarding state-sponsored cyber threats, election interference, and disinformation campaigns. Platforms can and should leverage this expertise to inform their own, independent moderation policies and security practices, without feeling legally obligated to comply with every recommendation. The key is to document interactions, ensuring that decisions remain platform-driven and voluntary, rather than coerced.
For government agencies, particularly those involved in national security, public health, or election integrity (like CISA, CDC, or the FBI), the ruling provides guidance on how to communicate effectively with platforms without crossing the line into unconstitutional coercion. Agencies can and should share relevant threat intelligence, factual corrections, or context about disinformation trends. However, they must be scrupulous in ensuring their communications are informational, advisory, and non-threatening. They should avoid language that implies penalties for non-compliance or that dictates specific moderation outcomes. The focus should be on providing expertise and data that platforms can then use in their own decision-making processes, respecting the platforms' private actor status and their own First Amendment rights. This means fostering collaborative relationships built on information exchange rather than directives.
For individual users and the general public, the talk underscores a critical distinction: the First Amendment protects against government censorship, not censorship by private entities. When a social media platform removes content or bans an account, it is typically exercising its terms of service and editorial discretion as a private company, not violating the user's First Amendment rights. While users may disagree with platform decisions, understanding this legal framework helps to correctly attribute responsibility and engage in more informed discourse about online speech. It empowers individuals to critically evaluate claims of "censorship" and discern when government overreach is genuinely at play versus when a private company is simply enforcing its own rules.
In essence, the defensive strategy for all parties revolves around clarity, documentation, and a deep understanding of First Amendment jurisprudence. Platforms should maintain clear internal policies for government interactions. Agencies should train personnel on appropriate communication protocols. And the public should be educated on the limits and scope of free speech protections in the digital age. This collective understanding is crucial for navigating the complex challenges of online speech while preserving constitutional liberties and ensuring effective cybersecurity.
Key Takeaways
- The First Amendment primarily restricts the government from abridging speech; it does not apply to the moderation decisions of private internet platforms.
- "Jawboning" occurs when the government pressures a third party to act against speech it dislikes. For this to be unconstitutional, there must be evidence of coercion, typically an "or else" threat.
- In Murthy v. Missouri, the Supreme Court found no evidence of government coercion, ruling that agencies were sharing information and expertise with platforms, which then made their own independent moderation decisions.
- Internet platforms, like traditional publishers, possess their own First Amendment rights to exercise editorial discretion over the content they host, as affirmed in cases like Moody v. NetChoice.
- Government agencies, such as CISA, can legitimately share expertise and intelligence with platforms (e.g., on cybersecurity threats or disinformation) as part of the right to petition and for public benefit, as long as these communications are non-coercive.
- The Murthy lawsuit initially created a chilling effect, hindering valuable information exchange between government and platforms. The Supreme Court's ruling clarifies the legal boundaries, aiming to restore productive, non-coercive dialogue.
About the Speaker(s)
Cathy Gellis is an experienced lawyer specializing in legal issues at the intersection of technology, free speech, and policy. She is a prolific writer on these topics, contributing extensively to Techdirt, where she analyzes complex legal developments and their impact on online rights. Gellis is also active in legal advocacy, having filed amicus briefs at the Supreme Court on pertinent issues. Her background and expertise make her uniquely qualified to demystify intricate legal concepts like the First Amendment, jawboning, and the implications of landmark cases such as Murthy v. Missouri for a diverse audience.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
This session delivered a no-nonsense, deeply informed legal analysis of Murthy v. Missouri and its nuanced implications for online speech and cybersecurity. The speaker, a credible legal expert, meticulously broke down the First Amendment's application to government "jawboning" of private platforms, particularly highlighting the critical distinction between coercion and legitimate information sharing, especially concerning agencies like CISA. It wasn't about 0-days, but it was about the legal 0-sum game of information control, providing the audience with essential tools to understand the real-world impact on how security-relevant information flows and is moderated.
Heather Calloway (CISO) — STRONG ACCEPT
This session by Cathy Gellis offers a precise and unsentimental breakdown of Murthy v. Missouri, illuminating the critical distinction between legitimate government information sharing and unconstitutional coercion in online content moderation. For CISOs and security leaders at platforms, it provides essential clarity on navigating interactions with agencies like CISA, affirming the platform's First Amendment rights while underscoring the necessity of non-coercive information exchange to manage disinformation and cyber threats. It’s a vital guide for ensuring institutional accountability and managing regulatory risk in a complex legal landscape.