14 ms·
Court: Breaking Your Employer's Computer Policy Isn't a Crime
- SeanDav 11y agoI almost think the entire EFF should receive the civilian equivalent of the Congressional Medal of Honor. Amazing work and gratz to all those involved!
- DINKDINK 11y agoVote with your wallet, make a donation!
- workitout 11y agoThe efforts of the EFF are to be lauded in this case.
- sixtypoundhound 11y agoThis is awesome piece of work - massive kudos to the EFF! In true authoritarian tradition, the establishment took an unsympathetic example (on the surface, this defendant is a hard one to explain to the common person) and used it to push through some scary interpretations into case law that would affect a much broader (and more mainstream) group.
- x1798DE 11y agoI've seen other places in this thread indicating that charging this guy under the CFAA was an inappropriate choice (i.e. not just the only choice if they want to pursue criminal charges); does anyone know if there have been similar cases of abuse of law enforcement data where the accused was charged under a different statute?
- r0m4n0 11y agoI'm not a lawyer by any means but in CA I'm completely aware of an employer clause in subsection H of 502c that obviously excludes these acts performed within the scope of employment, as long as there wasn't real damage as an outcome. I don't have a copy of the CFAA but I'm assuming it does as well. Interesting that there was dissent to begin with... http://www.leginfo.ca.gov/cgi-bin/displaycode?section=pen&group=00001-01000&file=484-502.9 http://www.leginfo.ca.gov/cgi-bin/displaycode?section=pen&gr...
- mcherm 11y agoThe topic is interesting, but I would rather read an intelligent synopsis with comments on the implications than try to read the court opinion on my own without any input from those properly trained in the law. (Linking to the actual decision IN ADDITION to some expert analysis would be a great idea.)
- sageabilly 11y agoGood point, here's the Gizmodo article about it: http://gizmodo.com/court-rules-that-breaking-your-employers-computer-polic-1746133150 http://gizmodo.com/court-rules-that-breaking-your-employers-... In short: The United States Court of Appeals for the Second Circuit issued an opinion rejecting the government’s attempt to hold an employee criminally liable under the federal hacking statute—the Computer Fraud and Abuse Act (“CFAA”)—for violating his employer-imposed computer use restrictions... The court also ruled that the government cannot hold people criminally liable on the basis of purely fantastical statements they make online—i.e., thoughtcrime.
- bumbledraven 11y agoFrom the gizmodo article: Valle was also charged with violating the CFAA for accessing a police database to look up information about people without a valid law enforcement purpose, in violation of NYPD policy. Querying a government database for personal use is a serious offense. I hope the court would address it separately from lesser rules such as "don't use Facebook at work."
- pilif 11y agoIn general, that's probably the right decision. But I also think that using police records for personal purposes is different from browsing Facebook at work. One only damages the employer slightly, the other has huge potential issues against society at large. The CFAA is not the correct solution for this issue, but none the less, I think such behavior should be a criminal matter.
- regularfry 11y agoThis is true, but the correct response would probably be to criminalise abuse of police records specifically, rather than criminalising general organisation policy breaches.
- Beltiras 11y agoThere must be different statutes to charge under. That cop infringed the civil liberties of the persons who came up in the search at a minimum.
- vinceguidry 11y agoYeah, I find it weird that they used CFAA. Maybe that law carries harsher penalties than the others.
- mannykannot 11y agoPerhaps it is an example of prosecutorial overreach, and I wonder if the judges' ruling is, in part, intended to make a stand on that issue. FWIW (and IANAL), I would have preferred to see this person charged only for the unauthorized data access, with his purpose taken into consideration (negatively) in sentencing.
- sageikosa 11y agoIt should be a police disciplinary action, and there should be a policy in place to review database access on a regular basis.
- walshemj 11y ago
- nicolai123 11y agoGreat news !
- ubercow 11y ago> The court also ruled that the government cannot hold people criminally liable on the basis of purely fantastical statements they make online—i.e., thoughtcrime. I think this is the bigger news here.
- deleted 11y ago[deleted]
- DiabloD3 11y agoDupe: https://news.ycombinator.com/item?id=10675396 https://news.ycombinator.com/item?id=10675396
- Illniyar 11y ago"Valle was also charged with violating the CFAA for accessing a police database to look up information about people without a valid law enforcement purpose, in violation of NYPD policy." I find it odd that the prosecutors decided to go with a computer fraud charge for this crime, aren't there any laws that would prohibit this action regardless of method used? If he chose to lookup paper files on unrelated people, would he be immune to prosecution?
- HarryHirsch 11y agoIt's disquieting that this isn't sanctioned. There ought to be a law against this.
- vinceguidry 11y agoYou're seeing the justice process work as intended. The CFAA is absolutely the wrong statute to be prosecuting his crime under. But we need actual, real-world cases to highlight these discrepancies. Now legislators can come up with a law that covers the specific case of government workers abusing the tools of state for their personal ends. Perhaps it already existed, that means the prosecutors screwed up and charged him under the wrong statute. Now they know the limits of that law and so will use the right law next time. It's tempting to want a perfect judicial code, but it's impossible, iterated law is really the only way.
- HarryHirsch 11y agoI'm looking at this from a more practical angle. Government employees are in a position of trust because you cannot choose not to deal with them, and sometimes are backed up with force of arms (like our friendly policeman). Besides, traditionally, because of the sheer expense, large databases with potential for abuse would belong to governmental entities. Things like Facebook and Google are upstarts, the legislative hasn't had time to deal with those yet in any way. That's why I'm saying that I'm surprised that there isn't a law. The problem must have come up before. Someone asking about a competitor's tax records because the sister-in-law works at the IRS, arrest records of a political competitor becoming public the week before election, that sort of thing. Perhaps a suitable statute is on the books but the prosecution picked the CFAA instead, hoping the case would get thrown out or go to revision and then get thrown out. It's within the realm of possibilities.
- aluhut 11y agoMh I'm getting a 403 from Germany for the whole domain. downforeveryoneorjustme says it's up. Could someone paste the content for me?
- Nilzor 11y agoI'm sorry that would break my employers computer policy on copyrights (nah not really.403 here as well)
- aluhut 11y agoWeird stuff. eff.org delivers a 403 also but https://www.eff.org/deeplinks/2015/12/loading-screen-game-patent-finally-expires https://www.eff.org/deeplinks/2015/12/loading-screen-game-pa... works. Edit: doesn't work anymore too.
- fenomas 11y agoSame for me, and it worked fine maybe an hour ago. Server issue it seems.
- QuantumCookie 11y agoProbably: working now from Germany
- FLUX-YOU 11y agoThe United States Court of Appeals for the Second Circuit issued an opinion rejecting the government’s attempt to hold an employee criminally liable under the federal hacking statute—the Computer Fraud and Abuse Act (“CFAA”)—for violating his employer-imposed computer use restrictions. The decision is important because it ensures that employers and website owners don’t have the power to criminalize a broad range of innocuous everyday behaviors, like checking personal email or the score of a baseball game, through simply adopting use restrictions in their corporate policies or terms of use. The court also ruled that the government cannot hold people criminally liable on the basis of purely fantastical statements they make online—i.e., thoughtcrime. The case, United States v. Gilberto Valle, received a lot of attention in the press because it involved the so-called “cannibal cop”—a New York City police officer who was charged with conspiracy to kidnap for posts he wrote on fetish websites about cannibalism. Valle was also charged with violating the CFAA for accessing a police database to look up information about people without a valid law enforcement purpose, in violation of NYPD policy. The jury convicted Valle on all counts, but the trial court reversed the jury’s conspiracy verdict, stating that “the nearly yearlong kidnapping conspiracy alleged by the government is one in which no one was ever kidnapped, no attempted kidnapping ever took place, and no real-world, non-Internet-based steps were ever taken to kidnap anyone.” The trial court ultimately found that holding Valle guilty of conspiracy to kidnap would make him guilty of thoughtcrime. But the trial court upheld the CFAA conviction. And on appeal, we filed an amicus brief with the Second Circuit, urging the court to overturn the lower court’s dangerous ruling. We argued that the lower court’s ruling would make criminals out of millions of innocent individuals, and the Second Circuit agreed—throwing out Mr. Valle's CFAA conviction and joining two other federal circuit courts in rejecting the government’s attempt to expand the reach of the vaguely worded federal statute: “We decline to adopt the prosecution’s construction [of the CFAA], which would criminalize the conduct of millions of ordinary computer users[.]” The court went on: While the Government might promise that it would not prosecute an individual for checking Facebook at work, we are not at liberty to take prosecutors at their word in such matters. A court should not uphold a highly problematic interpretation of a statute merely because the Government promises to use it responsibly. The Second Circuit also upheld the trial court’s decision to throw out the conspiracy conviction, as we had urged in a second amicus brief filed in the case, holding that “[t]he mere indulgence of fantasy, even of the repugnant and unsettling kind here, is not, without more, criminal.” Thanks again to the Center for Democracy & Technology, the National Association of Criminal Defense Lawyers, and the Internet scholars who joined our CFAA amicus brief, and to UCLA law professor Eugene Volokh of the Scott & Cyan Banister First Amendment Clinic for writing our amicus brief regarding the conspiracy charges. Related Cases United States v. Gilberto Valle
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- ss64 11y agoStill down, heres a cached version http://webcache.googleusercontent.com/search?q=cache:Bj2aVsY9v94J:https://www.eff.org/deeplinks/2015/12/federal-court-appeals-rejects-notion-violating-your-employers-computer-use+&cd=1&hl=en&ct=clnk&gl=uk http://webcache.googleusercontent.com/search?q=cache:Bj2aVsY...
- aluhut 11y agoThanks.
- dkbrk 11y ago> A court should not uphold a highly problematic interpretation of a statute merely because the Government promises to use it responsibly. This. Whether a law is just needs to be considered in light of its worst-case abuse potential, not just on the basis of how it is currently being applied. It is a great advantage of the common law system that over-broad, ill-specified or otherwise broken laws can be remedied through precedent, however the responsibility still lies with the government to make laws that are well-considered, based on sound principles and not overly broad.
- purpled_haze 11y agoCould you extrapolate from that though that: 1. Since the first amendment allows the free exercise of religion, prayer must be allowed in schools as long as no specific religion is established via those prayers? 2. Since the second amendment allows the right to keep and bear arms, without further amendment, that right should be unrestricted by any registration process considered onerous or restrictive?
- Retra 11y agoThe first amendment doesn't really "allow" anything; it is a prohibition of certain actions by congress.
- dragonwriter 11y ago> Since the first amendment allows the free exercise of religion, prayer must be allowed in schools as long as no specific religion is established via those prayers? Prayer is allowed in schools, government-officer-led prayer is not allowed in public schools.
- Deregibus 11y agoNo, I don't think you can extrapolate that, those seem like entirely unrelated issues. Neither of those points imply an overly broad law that only works based on the trust and restraint of the government.
- 11y ago
- deleted 11y ago[deleted]
- golergka 11y agoFor the people who skipped the article and assumed that the case was about some stupid office policy: > Valle was also charged with violating the CFAA for accessing a police database to look up information about people without a valid law enforcement purpose, in violation of NYPD policy. This is not a typical "employer policy". This a policy about access to sensitive private data that is only available to the government. Wouldn't you want improper access to such data punished?
- themartorana 11y agoBut it's not defined. This strikes down the ability to use arbitrary office policy under any conditions as the basis for criminal prosecution. It's easy enough to pass a law stating that the use of police databases for anything other than the pursuit of justice is a crime itself... But I'd rather have to go through the process of creating a specific law than to know a court upheld my employer's right to basically write criminal law into the same policy manual that describes if I have to wear a tie or not.
- Spoom 11y agoIn this case, I would either want the NYPD to control access to their own database more effectively (which is perfectly within their power) or I would want the law to be written much more narrowly, so it couldn't apply to "typical employer policy". Essentially, I don't want to have to rely on prosecutorial restraint.
- gvb 11y agoHe was apparently fired for violating his terms of employment, so he was punished, but not criminally punished. While I am very disturbed that a major restraint (the threat of criminal prosecution) has been taken off the table for abuse of sensitive private government data, I'm happy that it has been taken off the table for me as well, as a non-government employee that only has access to sensitive company private data. Quote from the appeals court ruling: "Valle concedes that he violated the terms of his employment by putting his authorized computer access to personal use..." Ref: <http://arstechnica.com/tech-policy/2015/12/repugnant-online-discussions-are-not-illegal-thoughtcrime-court-rules/> http://arstechnica.com/tech-policy/2015/12/repugnant-online-...
- sowbug 11y agoHow might this court have handled the Aaron Swartz case? I don't know the facts of either case well enough to tell whether they're comparable.