4 ms·
> I suspect the definition of 'unauthorized access' will need to be more clearly defined I've been saying this for years! For reasons unrelated to TOS rulings,
by CiPHPerCoder 7y ago
> I suspect the definition of 'unauthorized access' will need to be more clearly defined
I've been saying this for years! For reasons unrelated to TOS rulings, too.
A little bit of background...
In 2011, I was charged with unauthorized access to a protected computer. The website in question (Infragard Tampa Bay, run by the FBI through a company called Sylint) was running an older version of DotNetNuke that had a 2008 vulnerability.
The nature of the vulnerability was as follows: If you accessed a specific URL which required no authorization, you could upload files to the server and presumably execute them. (I say presumably, because I didn't.)
I wanted to fight the charge because I never exceeded "authorized access" by using a publicly accessible web form on the public Internet, and the CFAA's terms were vague.
* The website was publicly accessible, without needing authorization
* The file upload form was publicly accessible, without needing authorization
* The folder that files were uploaded to was publicly accessible, without needing authorization
* All of my conduct was authorized by the software they ran on the public Internet, and therefore the unauthorized access I was accused of never actually occurred
My overworked public defender didn't have any fight in him. The EFF wouldn't help either (the person I talked to didn't see the significance of this CFAA ambiguity for civil rights). I grew up in a poor family and couldn't afford legal counsel, so I ended up pleading guilty, which has totally fucked my life up ever since. (It really doesn't get better, even 8-9 years later.)
> since I know many cases in the past relied around users doing shit that was unauthorized by the TOS.
Good. I hope this becomes a precedent that frustrates prosecutors and helps defense cases in appeals court.
- 3pt14159 7y agoYikes man. I'm sorry that happened to you. If you don't mind my asking, what part of your life is still messed up because of this? Is it directly related to the charges or is it the outcome of spending time behind bars?
- CiPHPerCoder 7y ago> If you don't mind my asking, what part of your life is still messed up because of this? Employment! I tried to go the crypto consultant route in recent years and was told by many people via Twitter/Reddit private message that they can't or won't go with the company I helped start simply because of my criminal background. I spent most of last year job-searching. I interviewed well, but many companies rescinded offers after my background check concluded, even when I told them about this incident up front. In 2011, everyone joked that I'd be fine. "The government will probably follow up with a job offer," they insisted. Instead, I was rendered unemployable by most of the companies that desire the skills I possess. The silver lining is that some companies restrict their background checks to a time-gate, which means it's not totally impossible to make a living. But they're the minority. > Is it directly related to the charges or is it the outcome of spending time behind bars? My sentence was probation and a short duration of house arrest, community service, and paying Sylint $9,370 (which, at barely above minimum wage, took a few years). My probation was terminated early for good behavior. The problem has less to do with the courts and more to do with background checks. People make mistakes. Especially young people. (I was 21 when this happened.) Learning itself is a messy process that often requires making mistakes to be successful. Punishing someone in perpetuity for having not lived a perfect life is a problem that society hasn't yet solved. We have hacks ("Right to be Forgotten") to try to alleviate some of the symptoms, but with the advent of the Internet, there is now a public, immutable record of your most embarrassing fuck-ups. And I don't think we were ready for that.
- rwmurrayVT 7y agoGenerally speaking, federal crimes rarely ever turn up on a standard background check. I'm writing this from a US Navy ship repair yard where I released the information personally despite the fact the check came up clean.
- CiPHPerCoder 7y ago> Generally speaking, federal crimes rarely ever turn up on a standard background check. This also happened in the state of Florida, which has very open records.
- driverdan 7y agoI have a much worse criminal record (multiple federal felonies, also under similar laws) and it has never prevented me from finding a job. Avoid the finance industry or anything related to financial transactions. The risk is too high for them, they won't hire you.
- Drip33 7y agoTell me about it, I was very publicly accused and never convicted. Fortunately I'm independently wealthy but it's a huge pain to get anyone to do large financial transactions WITH me, not talking about employment in that industry. On the employment side I just assume I'm unemployable in the security industry where my talents are so I just engage in hobbies all day every day... End rant.
- WrtCdEvrydy 7y agoWho charged you? Infragard's sole job is to facilitate data transfer between industry and the feds to ensure there's security at every layer. That's some weapons grade bullshit right there.
- CiPHPerCoder 7y ago> Who charged you? Sylint pressed the charges through the FBI. Originally, they also insisted I caused damage days before the date of incident and tried to tack on $32k in damages. I pointed out that I do not possess a time machine, and they shifted it from (June 18-24) to (June 21-27) and lowered the dollar amount to $9k.
- icheishvili 7y agoToo late now, but would it have been useful/possible to go public about it or threaten to talk the media and cause way worse problems for them? Considering that security is their game, I wonder if the bad PR would've made them re-think targeting you.
- CiPHPerCoder 7y agoI was too depressed and scared to consider that then. I haven't really thought about that angle since, either.
- google234123 7y agoJust because something is connected to the public internet doesn't mean that you can hack it. Most homes are accessible from public roads, that doesn't mean you are allowed to climb through any open window that you see. You used a vulnerability to hack into some server associated with the FBI, I don't see any ambiguity here.
- CiPHPerCoder 7y ago> Just because something is connected to the public internet doesn't mean that you can hack it. I never said or implied that. All I said is, because all of my conduct involved publicly accessible components of their web application, I never exceeded authorized access. Which means that the CFAA's clause about "unauthorized access" in particular does not apply, since none of my packets exceeded or bypassed an authentication or authorization control on their web app. > Most homes are accessible from public roads, that doesn't mean you are allowed to climb through any open window that you see. A better analogy is knocking on someone's door, only to discover it swings open, then walking away. And then getting charged with breaking and entering for their failure to shut their door, and then paying for damages for leaving a muddy footprint on their exterior welcome mat. > You used a vulnerability to hack into some server associated with the FBI, I don't see any ambiguity here. I won't argue that I'm fully without blame. The mistake I made during all of this was, upon discovering they were running an outdated version of DotNetNuke (right click > view source; not exactly something I had to go out of my way to detect), I panicked. And to assuage my own anxiety, I tested the file upload to confirm that it was real. That was the mistake that let them prosecute me at all. And it's a mistake I have learned from: In the years since, I have never sent a packet with security implications to another network even for projects with a public bug bounty. I constrained myself henceforth to reviewing source code and reverse engineering, since that doesn't involve sending packets over a network and invoking a law that was written before the concept of a public network existed. (And that law being problematic is my entire point in this discussion, not appealing for amnesty in the opinions of HN users. Anyone who decides to hate me won't be the first.) Even if I knew not to do that then, I still would have informed them of their vulnerability as soon as it was discovered. Because that was the right thing to do.