4 ms·
The DOJ publishes legal guidance on prosecuting computer crimes [1], which includes this relevant passage: > An attacker need not directly send the required tr
by sjy 5y ago
The DOJ publishes legal guidance on prosecuting computer crimes [1], which includes this relevant passage:
> An attacker need not directly send the required transmission to the victim computer in order to violate this statute. In one case, a defendant inserted malicious code into a software program he wrote to run on his employer's computer network. United States v. Sullivan, 40 Fed. Appx. 740 (4th Cir. 2002) (unpublished) [2]. After lying dormant for four months, the malicious code activated and downloaded certain other malicious code to several hundred employee handheld computers, making them unusable. Id. at 741. The court held that the defendant knowingly caused transmission of code in violation of the statute. Id. at 743.
The CFAA is notoriously broad, which is probably why Pfefferkorn didn’t feel the need to undertake a detailed analysis of exactly how it prohibits the deployment of a targeted exploit which would “undetectably alter previous reports, compromise the integrity of future reports (perhaps at random!), or exfiltrate data from the Cellebrite machine.”
[1] https://www.justice.gov/sites/default/files/criminal-ccips/legacy/2015/01/14/ccmanual.pdf https://www.justice.gov/sites/default/files/criminal-ccips/l...
[2] https://www.anylaw.com/case/united-states-v-sullivan/fourth-circuit/02-28-2002/tYJVPmYBTlTomsSB8cc0 https://www.anylaw.com/case/united-states-v-sullivan/fourth-...
- Certhas 5y agoThis passage describes a really different situation though. Say I have a USB Stick with important data on it. It has a warning label on it that says "if you plug this in, it may destroy your computer unless you have the correct password file.". If you plug it in (and your OS is vulnerable) it wipes all drives (including itself) it can find unless it finds a particular password file. Is this USB Stick illegal? Signal made it very very clear that scanning their users with Celebrite tools might trigger some behavior. Now if you still go ahead and use this tool can Signal be blamed, despite warning you that this will occurr? I find all of this far from obvious. What Signal did is purely defensive _and_ clearly labeled. It's very unlike the examples cited so far. (And after all we are talking about a scenario where the cops can still get the evidence simply by taking screenshots of the open app, so they are not even preventing cops from getting to the evidence, merely making it more inconvenient.)