4 ms·
>and he was fully authorized to use them This line is the crux, and the problem is that "authorized" means subtle, yet critically important, different things t
by secothroa 5y ago
>and he was fully authorized to use them
This line is the crux, and the problem is that "authorized" means subtle, yet critically important, different things to different people.
The officer was surely "authorized" in the sense that he had technical authorization to log into the system and accomplish the task.
But in the sense that "authorization" is defined by more than just technical controls, and also has to do with many dynamic situations that technical controls can't often restrict (or just aren't in place), it doesn't sound like was "authorized".
Think of walking into a restaurant and they have a sign that says "Employees Only Behind Counter". Even if there was no technical/physical control preventing you from going behind the counter (eg there was no locked door or anything like that), I think it would still be understood that you as a customer do not have "authorization" to go back there.
In my experience as a security consultant, my technically-minded clients typically think of "authorization" as the first way, defined by technical controls and thinking that lack of technical controls in a system means they have carte blanche to do whatever they want with that system. But my experience with anyone outside of tech is that they don't think of it that way at all, and that just because you have the physical/technical ability to do something does not make it okay to do that.
"Authorization" is an overloaded term and the CFAA suffer for it, but personally I do not think an average person would think the officer was "authorized" to do what he did, even if he did have the technical access to do it.
The points about "average employees technically violating the CFAA by doing stuff like reading the news on their work laptop" are valid concerns and I think they need to be resolved, but I think that is a completely different concern than someone like this officer abusing their access for legitimately bad acts.
- Natsu 5y agoYou're right about a lot of that, but there are huge problems with making mere policy violations into federal felonies. We want to stop people from hacking stuff, but at the same time, we can't do that by giving every random company the power to make things into federal felonies via their own complex and often-ignored rules. I posted up thread too, but my own personal view is that unauthorized access should hinge on whether the person used deception to obtain access. That provides a clear separation between lawful and unlawful conduct without giving private parties the power to define new felonies. With computers, I don't think that the proverbial "employees only" sign on a load of private data means anything and the incentive should be on the business to provide a proper access control there. Meanwhile, if they add a guard who asks "are you an employee?" and you lie to them to get access, I would say you're unauthorized. That gives us some semblance of mens rea while not going to far in any direction, I believe.
- zuminator 5y agoI like your restaurant analogy but I draw the opposite conclusion. Imagine a restaurant which has a sign saying, "You must be dressed appropriately to enter - no shoes, no socks, no service." A family goes in to dine. About halfway through their meal, the cops come and arrest the father. Turns out, although nobody noticed at first, he wasn't wearing socks, and was therefore trespassing according to store policy. Is that fair though? It's one thing to ask the family to leave, but should the father be charged with an actual crime for unauthorized entry?
- LanceH 5y agoAnd at worse he's guilty of trespass, not breaking and entering. If there were a filing cabinet that he had keys to, he wouldn't be charged with breaking into the cabinet if he grabbed the wrong files. What's the penalty for using the wrong physical file he has direct access to? That's what we should be talking about.
- greycol 5y ago>Think of walking into a restaurant and they have a sign that says "Employees Only Behind Counter". Even if there was no technical/physical control preventing you from going behind the counter (eg there was no locked door or anything like that), I think it would still be understood that you as a customer do not have "authorization" to go back there. But if a customer was invited back there because they said they wanted to thank the chef? They're told not to touch anything, they touch something. Do we view that touching something as breaking the same rule as someone who just walks back there uninvited or is it another rule they are breaking? I can definitely see arguments for both views. Especially compelling to me based on the analogy is once you've taken the first unauthorized by policy action no other actions other than leaving would be authorized though this interpretation would lead to its own absurdities.