5 ms·
Feels like this is going to create some headaches for prosecuting CFAA cases if the verdict stands. I suspect the definition of 'unauthorized access' will need
by ds 7y ago
Feels like this is going to create some headaches for prosecuting CFAA cases if the verdict stands.
I suspect the definition of 'unauthorized access' will need to be more clearly defined since I know many cases in the past relied around users doing shit that was unauthorized by the TOS.
- bosswipe 7y agoGood.
- threatofrain 7y agoDo technical communities have a consensus on how to classify these behaviors or scenarios? Then what anchor do we have?
- CiPHPerCoder 7y agoThe onus should be on the service operators to clearly define what's authorized and what isn't; and if they miss something, the liability should be borne by the service operator, not the person who found their gap.
- deleted 7y ago[deleted]
- gowld 7y agoDefine via ToS, or technical countermeasures? In the meatspace world, we use ToS and expectations (like don't ransack my house even if he door is unlocked).
- CiPHPerCoder 7y agoTechnical countermeasures. My proposal would require companies to actually take security very seriously. https://www.troyhunt.com/we-take-security-seriously-otherwise/ https://www.troyhunt.com/we-take-security-seriously-otherwis...
- threatofrain 7y agoWhat about someone who “Zoom bombs” a prime minister? Is that hacking? Espionage?
- CiPHPerCoder 7y agoWhy the hell are prime ministers using Zoom in the course of their civic duty? Are they discussing national secrets over Zoom? Without end-to-end encryption?! That's some form of criminal negligence and/or mishandling of classified information in every jurisdiction I know. If not, it's little more than a nuisance and a reminder that Zoom should not be relied on for important communications.
- deleted 7y ago[deleted]
- threatofrain 7y agoIt's known that PM Boris Johnson used Zoom recently for a cabinet meeting, with all the Zoom ID's published.
- clort 7y agoIt should not be the simple act of accessing a computer contrary to the owners terms and conditions that is a crime, but the specific acts of searching for, wilfully accessing and sharing privileged information on systems where the persons whose information you were accessing had a reasonable expectation that that information would be private. I think that covers police databases, social security and also customer details on a website amongst others. It would not necessarily cover accidentally accessing customer data on a system (that happens) but if you started wilfully sharing that data or details about how to access it with persons other than the owners of the system then you could start to get into the problematic zone. To prevent the scenario where the owners just do nothing and then when the 'hacker' tells somebody else they call the cops and accuse, it should probably be a crime, after being notified that your system is leaking private data, that you didn't take any action to plug that hole.
- alasdair_ 7y ago>if you started wilfully sharing that data or details about how to access it with persons other than the owners of the system then you could start to get into the problematic zone Here I disagree, assuming we are still talking about the USA. There are strong freedom of speech implications when you make sharing the fact that some company left their S3 bucket world-readable a criminal offense. Would the New York Times be open to criminal prosecution for publishing such information on their front page? Very tightly-defined, personally-identifiable data I can see being protected. Things like financial and medical records, sensitive search queries etc. but general disclosure of security issues should not be something that is criminal.
- clort 7y agoSo look at the general gist of what I wrote and think about the principle a bit. I did say 'start to get into the problematic zone' so I am not saying here is an abrubt transition between not-crime and crime-with-terrible-punishment. So you find a company leaves their S3 bucket world-readable by accident and it contains personal information that the persons concerned would reasonably consider private (from medical records all the way to my real identity on a forum). The correct course of action is not to exercise your free speech by going first to the New York Times so they can publish a story about it allowing all and sundry to access that information, but to go to the company and tell them that this is open and that information they are responsible for is leaking. This is your responsibility to your fellow citizens whose data is leaking! However, if the company do not fix it in a reasonable time then you can report them to the relevant authorities who can decide what action to take and now the criminal aspect of this data leakage will now be attached to the owners of the company which has not fixed the problem and you are free to exercise your free speech rights. If I sell (for money, fame, fake internet points or smug satisfaction) access to your personal data without your consent how can I claim that is my free speech? I think the USA has the concept of limits to freedom, ably illustrated by the phrase "Your Freedom To Swing Your Fist Ends Where My Nose Begins"
- CiPHPerCoder 7y ago> I suspect the definition of 'unauthorized access' will need to be more clearly defined I've been saying this for years! For reasons unrelated to TOS rulings, too. A little bit of background... In 2011, I was charged with unauthorized access to a protected computer. The website in question (Infragard Tampa Bay, run by the FBI through a company called Sylint) was running an older version of DotNetNuke that had a 2008 vulnerability. The nature of the vulnerability was as follows: If you accessed a specific URL which required no authorization, you could upload files to the server and presumably execute them. (I say presumably, because I didn't.) I wanted to fight the charge because I never exceeded "authorized access" by using a publicly accessible web form on the public Internet, and the CFAA's terms were vague. * The website was publicly accessible, without needing authorization * The file upload form was publicly accessible, without needing authorization * The folder that files were uploaded to was publicly accessible, without needing authorization * All of my conduct was authorized by the software they ran on the public Internet, and therefore the unauthorized access I was accused of never actually occurred My overworked public defender didn't have any fight in him. The EFF wouldn't help either (the person I talked to didn't see the significance of this CFAA ambiguity for civil rights). I grew up in a poor family and couldn't afford legal counsel, so I ended up pleading guilty, which has totally fucked my life up ever since. (It really doesn't get better, even 8-9 years later.) > since I know many cases in the past relied around users doing shit that was unauthorized by the TOS. Good. I hope this becomes a precedent that frustrates prosecutors and helps defense cases in appeals court.
- 3pt14159 7y agoYikes man. I'm sorry that happened to you. If you don't mind my asking, what part of your life is still messed up because of this? Is it directly related to the charges or is it the outcome of spending time behind bars?
- CiPHPerCoder 7y ago> If you don't mind my asking, what part of your life is still messed up because of this? Employment! I tried to go the crypto consultant route in recent years and was told by many people via Twitter/Reddit private message that they can't or won't go with the company I helped start simply because of my criminal background. I spent most of last year job-searching. I interviewed well, but many companies rescinded offers after my background check concluded, even when I told them about this incident up front. In 2011, everyone joked that I'd be fine. "The government will probably follow up with a job offer," they insisted. Instead, I was rendered unemployable by most of the companies that desire the skills I possess. The silver lining is that some companies restrict their background checks to a time-gate, which means it's not totally impossible to make a living. But they're the minority. > Is it directly related to the charges or is it the outcome of spending time behind bars? My sentence was probation and a short duration of house arrest, community service, and paying Sylint $9,370 (which, at barely above minimum wage, took a few years). My probation was terminated early for good behavior. The problem has less to do with the courts and more to do with background checks. People make mistakes. Especially young people. (I was 21 when this happened.) Learning itself is a messy process that often requires making mistakes to be successful. Punishing someone in perpetuity for having not lived a perfect life is a problem that society hasn't yet solved. We have hacks ("Right to be Forgotten") to try to alleviate some of the symptoms, but with the advent of the Internet, there is now a public, immutable record of your most embarrassing fuck-ups. And I don't think we were ready for that.
- simonh 7y agoFor me, there's a distinction between accessing information you have not been authorised to access, and doing something unauthorised with data you had authorised access to. Thats why I don't agree with the article that contrasts the Facebook/Power Ventures case with the hiQ Labs case. These are fundamentally different. Power Ventures was using Facebook Users credentials to log on to facebook and I think thats a clear case of unauthorised access. Facebook had no direct relationship with Power Ventures and had not granted them access to those accounts at all. In the hiQ Labs case they had legitimate access to LinkedIn and were just scraping publicly viewable information. It's jut that LinkedIn didn't like what they were doing with it. Of course the SSA database access case from 2010 is an anomaly in this aspect. The user was authorised to access the data if doing so in the course of his work, and I think the police case from 2015 was ruled correctly. In both case they're reprehensible creeps, but they should be prosecuted as creeps, not as hackers.
- danShumway 7y ago> Power Ventures was using Facebook Users credentials to log on to facebook and I think thats a clear case of unauthorised access. Facebook had no direct relationship with Power Ventures and had not granted them access to those accounts at all. I strongly disagree. Facebook didn't have a relationship with Power Ventures, but it did have a relationship with its own users who granted Power Ventures access to their accounts. And while I admit it's not legally recognized yet, I firmly believe that users have an inherent Right to Delegate lawful access to 3rd-party software products and services[0]. I don't think the Power Ventures case had anything at all to do with unauthorized access. I think it was an attempt by Facebook to block users from exercising control over their own data. For context, look at the DMCA claims Facebook also filed in that case. It's been a really long battle to fight against the DMCA's unconstitutional provisions against subverting DRM for legal reasons. We have a lot of precedent to see how companies use systems like the DMCA. And the way they commonly use them is not to go after pirates, it's for market lock in and to restrict legitimate users. To paraphrase Doctorow, there are really bad consequences when we allow a company to make it a federal offense to use a product in a way that doesn't make their shareholders money. Treating ToS violations as a federal crime gives companies that ability on an even broader scale. It's legal to circumvent DRM? Oh, but our ToS blocks that. You exported your own data that you legally own? No, our ToS blocks that. You build a Matrix bridge for your DMs in my chat app and another competing service? Sorry, that's a federal offense now. A company should not be allowed to arbitrarily invent new federal laws. At most, violating a ToS should be a civil offense, and companies like Facebook should be forced to sue their own users, not providers like Power Ventures. [0]: https://anewdigitalmanifesto.com/#right-to-delegate https://anewdigitalmanifesto.com/#right-to-delegate