8 ms·
I very much feel their ruling is correct. The CFAA is intended to target "hackers," not policy violations. Here's a quote from the ruling making the point that
by fooey 5y ago
I very much feel their ruling is correct. The CFAA is intended to target "hackers," not policy violations.
Here's a quote from the ruling making the point that applying the law to something like access policy is far too broad to be viable
> The Government’s interpretation of the “exceeds authorized access” clause would attach criminal penalties to a breathtaking amount of commonplace computer activity. For instance, employers commonly state that computers and electronic devices can be used only for business purposes. On the Government’s reading, an employee who sends a personal e-mail or reads the news using a work computer has violated the CFAA. The Government speculates that other provisions might limit its prosecutorial power, but its charging practice and policy indicate otherwise. The Government’s approach would also inject arbitrariness into the assessment of criminal liability, because whether conduct like Van Buren’s violated the CFAA would depend on how an employer phrased the policy violated
- anonymousiam 5y agoI agree that the ruling is correct. The officer was granted the accesses he had, and he was fully authorized to use them. He violated a department policy by using his access improperly. The government wants to turn policy violations into a felony, and even set up a sting operation in this case to get a felony conviction. The officer should be disciplined/fired/etc. for violating department policy, but the CFAA should not be used to turn him into a felon.
- yarcob 5y agoThe problem is that the officer is corrupt, and he should be charged for taking a bribe. I don't think corruption is "just a policy violation", but I don't know enough about US law to know if taking bribes make you a felon or not (I would hope so, but I assume it depends on circumstances). In any case, it shouldn't matter that he used a computer to commit a crime. If he had gotten the relevant information by reading them from a paper file or by asking a coworker the crime should be the same, in my opinion.
- Natsu 5y agoI think that what the officer did is likely illegal for other reasons. So this ruling doesn't mean the officer deserves no punishment, it just means they committed some other crime than unauthorized access to a computer system.
- rPlayer6554 5y agoBut then he should be charged under the set of laws pertaining to bribery or corruption. I don't think anyone here disagrees with that. The question is should this crime of corruption get a massive additional pentaly specifically because it was committed on a computer. The supreme court says that this law has a purpose: to catch people who gain unauthorized access to computers. If laws are interpreted too broadly, they can be used to overcharge people. The example given by the supreme court is that if this law covers unauthorized use of a computer you are authorized to have access to, then sending a personal email on a work computer can be a felony.
- ALittleLight 5y agoOne thing that's weird about the Justice system is that there are so many laws. I agree that what the police officer did should be a crime, but it seems like there are potentially many ways to slice it. Maybe it's bribery, stalking, sharing privileged information, prior to this ruling CFAA, maybe other crimes too. If you add up all the crimes that may have been committed here it seems like the punishment gets pretty severe. Even 18 months in prison for this already seems severe to me. I would think justice is more like getting fired, fined, and community service rather than prison.
- thayne 5y agoI would hope that there are stronger protections against such abuses of authorization. What if a police officer (or system administrator, etc.) sold information about a potential victim to a criminal that resulted in physical or financial harm to said victim?
- the_pwner224 5y agoThat is / should be illegal on its own, the fact that the information was obtained through a computer system instead of a paper file doesn't change anything in your example.
- secothroa 5y ago>and he was fully authorized to use them This line is the crux, and the problem is that "authorized" means subtle, yet critically important, different things to different people. The officer was surely "authorized" in the sense that he had technical authorization to log into the system and accomplish the task. But in the sense that "authorization" is defined by more than just technical controls, and also has to do with many dynamic situations that technical controls can't often restrict (or just aren't in place), it doesn't sound like was "authorized". Think of walking into a restaurant and they have a sign that says "Employees Only Behind Counter". Even if there was no technical/physical control preventing you from going behind the counter (eg there was no locked door or anything like that), I think it would still be understood that you as a customer do not have "authorization" to go back there. In my experience as a security consultant, my technically-minded clients typically think of "authorization" as the first way, defined by technical controls and thinking that lack of technical controls in a system means they have carte blanche to do whatever they want with that system. But my experience with anyone outside of tech is that they don't think of it that way at all, and that just because you have the physical/technical ability to do something does not make it okay to do that. "Authorization" is an overloaded term and the CFAA suffer for it, but personally I do not think an average person would think the officer was "authorized" to do what he did, even if he did have the technical access to do it. The points about "average employees technically violating the CFAA by doing stuff like reading the news on their work laptop" are valid concerns and I think they need to be resolved, but I think that is a completely different concern than someone like this officer abusing their access for legitimately bad acts.
- Natsu 5y agoYou're right about a lot of that, but there are huge problems with making mere policy violations into federal felonies. We want to stop people from hacking stuff, but at the same time, we can't do that by giving every random company the power to make things into federal felonies via their own complex and often-ignored rules. I posted up thread too, but my own personal view is that unauthorized access should hinge on whether the person used deception to obtain access. That provides a clear separation between lawful and unlawful conduct without giving private parties the power to define new felonies. With computers, I don't think that the proverbial "employees only" sign on a load of private data means anything and the incentive should be on the business to provide a proper access control there. Meanwhile, if they add a guard who asks "are you an employee?" and you lie to them to get access, I would say you're unauthorized. That gives us some semblance of mens rea while not going to far in any direction, I believe.
- pessimizer 5y agoI'm absolutely fine with him being charged with a felony, as he is a corrupt government official, I just don't think that felony should be hacking.
- bryanrasmussen 5y ago>I very much feel their ruling is correct. The CFAA is intended to target "hackers," not policy violations. ok, but devil's advocate for a second - much hacking is actually just lying to people to get access to things you shouldn't have access to - so pretty much closer to policy violations than the stuff most people associate with 'hacking'
- zozbot234 5y agoThat's fraud and it's always been illegal.
- secothroa 5y agoCFAA stands for "Computer Fraud and Abuse Act". The entire purpose of the law is that is addresses that type of fraud.
- colechristensen 5y agoBut let’s say you called someone on the phone and lied to them to gain access to a computer system, you committed wire fraud doing so. It’s just a different crime because the thing you did wrong involves lying on the phone.
- anonymousiam 5y agoIf you obtain access using somebody else's credentials through fraud, YOU are not authorized. Thus you are violating the CFAA.
- ClumsyPilot 5y agoObtaining access through fraud is fraud. Why do you need to morph one crime into another? Think Breaking and Entering requires breakin. If someone gave you keys under false pretences, thats a different crime.
- jdmichal 5y agoI believe this would still be covered by the first clause, the one not even being argued in this decision. > Subsection (a)(2) specifies two distinct ways of obtaining information unlawfully—first, when an individual “accesses a computer without authorization,” §1030(a)(2), and second, when an individual “exceeds authorized access” by accessing a computer “with authorization” and then obtaining information he is “not entitled so to obtain,” §§1030(a)(2), (e)(6). I fraudulently obtain and use credentials to a system which authorize another person to access it. I am still "accessing a computer without authorization", because those credentials never authorized me. This starts to get really fuzzy if I fraudulently have credentials explicitly granted to me...
- perihelions 5y ago"The CFAA is intended to target "hackers," not policy violations." However, they also explicitly write that they're not addressing that distinction (footnote 8 on page 13, to my best ability to parse it). There's some semantic gap between "policy violations" and "improper motives". "For present purposes, we need not address whether this inquiry turns only on technological (or “code-based”) limitations on access, or instead also looks to limits contained in contracts or policies. Cf. Brief for Orin Kerr as Amicus Curiae 7 (urging adoption of code-based approach)." I discovered this nuance from Orin Kerr's twitter (the same one cited in this footnote); he says he's not confident he understands this footnote. https://twitter.com/OrinKerr/status/1400461828807741455 https://twitter.com/OrinKerr/status/1400461828807741455
- tialaramex 5y agoI don't know if it can always be avoided, but I think it makes sense for a court to try to avoid the code-based approach. It seems to be all downside (exploiting bugs will typically be OK because the code said this was OK, even if the people who wrote it never intended that) with no upside (the things rendered illegal already don't work, because code forbade them). Courts ought to be familiar with the fact that they're present mostly to make decisions about fuzzy things like "Did the accused intend to cause harm to the victim?" and not simple mechanics like "Does being injected with cyanide kill people?".
- Natsu 5y agoI agree, I don't think it can always be code-only. If you socially engineer someone into giving you an account, I really think that should be fraud. I've thought about this for some years now and looked at various different cases tried under the CFAA or otherwise claimed to be unauthorized access. I personally believe it should turn on whether or not you used deception as the means to gain access. That is, but for your deception, would you have gained access? This, in my mind, proves they were up to no good (mens rea) and acts to make it clearer whether or not you were authorized. It also connects to the idea that the law is mean to counteract a type of fraud in general. I mean, how can anyone say they had authorized access if they had to lie to gain access?
- deleted 5y ago[deleted]