5 ms·
Policies, by definition, are ways by which authorization rules are enforced. If the officer violated a policy, they also by definition violated their authorizat
by secothroa 5y ago
Policies, by definition, are ways by which authorization rules are enforced. If the officer violated a policy, they also by definition violated their authorizations.
>The idea that you could be authorized, but suddenly not
They were never authorized to use this system in this way, so there was not a "authorized but then suddenly not". The officer's authorization was static: not authorized.
Authorization is more than just the technical controls in a system, and lack of a technical control to prevent an officer using a system in certain ways does not mean said officer is authorized to use the system in any way they please.
- badRNG 5y agoI think we are confusing two concepts here. The officer's actions were unauthorized on a system he was provided access to. He didn't gain unauthorized access to a system, he failed to follow the rules on a system he already had access to.
- secothroa 5y agoIt isn't just about access to the system, but access to the data as well, and he accessed data that he was not authorized to access. That is "exceeding authorized access". - Logging onto the system: officer has technical access to log on and is authorized to log on, no problem - Accessing normal data the officer needs for legitimate reason: officer has technical access to this data and is authorized to access it, no problem - Accessing data for the purpose of a bribe: officer has technical access to this data, but is not authorized to access it, thus they are exceeding their authorized access
- kstrauser 5y agoHis crime was violating the policy. He clearly did not hack into the computer system to get the data, and that's what the CFAA was meant to prosecute. Put another way, he didn't work around any computer controls to get at the information.
- secothroa 5y ago>Put another way, he didn't work around any computer controls to get at the information. That's irrelevant. You can do unauthorized things without having to "work around" controls. >He clearly did not hack into the computer system to get the data, and that's what the CFAA was meant to prosecute. The CFAA was meant to prevent computer-related crimes including but not limited to unauthorized access, fraud, abuse, etc, which this clearly was.
- kstrauser 5y ago> That's irrelevant. You can do unauthorized things without having to "work around" controls. SCOTUS disagrees with you, and so do I. > The CFAA was meant to prevent computer-related crimes including but not limited to unauthorized access, fraud, abuse, etc, which this clearly was. He didn't do any of those with respect to the computer system. He accessed a resource that he had authorization to access as part of his job. He misused it, but didn't break into the system or gain access by fraud. His reasons for accessing the data were wrong, but his access was authorized.
- secothroa 5y ago>His reasons for accessing the data were wrong This, by definition, makes his access unauthorized. That's the point. "Authorization" is more than just technical controls. He was not authorized to access the data for this reason.
- deleted 5y ago[deleted]
- kstrauser 5y ago> "Authorization" is more than just technical controls. SCOTUS just literally said the opposite.
- willseth 5y ago> "Authorization" is more than just technical controls. You are applying too broad a definition to "authorization." In this context it refers specifically to the configured authorization behavior of the computer system. They gave him the equivalent of a key to a lock implemented in the computer system, and the law is meant to address the equivalent of someone who pick locks, not someone who misuses the access provided by keys they were given.
- treis 5y agoAuthorization isn't just yes or no though. It's conditional on intent. Say I give a neighborhood kid a key to come water my plants while I'm out of town. If they use that key to gain access and throw a party they're trespassing. I don't see why it should be different for a CPU
- JumpCrisscross 5y ago> Authorization isn't just yes or no though For purposes of this law, it is. The Government agreed “that Van Buren ‘access[ed] a computer with authorization HK’ when he used his patrol-car computer and valid credentials to log into the law enforcement database” [1]. “The dispute is whether Van Buren was ‘entitled so to obtain’ the record.” The Court found that Van Buren was entitled so to obtain the record, in that entitlement is the operative word. If the file is electronically accessible to the user, they have entitlement to so, *i.e. electronically, obtain it. They aren’t properly authorised or permitted or something else to it. But those weren’t the words used. "Authorized," unadorned, and "entitled so to." [1] https://www.supreme https://www.supreme court.gov/opinions/20pdf/19-783_k53l.pdf
- treis 5y agoI know, but it doesn't make sense. It's like arguing the kid was entitled to throw a party because he had my key.
- JumpCrisscross 5y ago> like arguing the kid was entitled to throw a party because he had my key Did he steal your key? Or did you give it to him? If he stole your key, he wasn't entitled to your house. But if you gave him the key, he had entitlement to it. If this were a friend, not a kid, you might be able to sue her for throwing a party in your house without permission. You would not be able to get her charged with breaking and entering because she overstepped the conditions that came with your key.
- treis 5y ago
- a1369209993 5y ago> The officer's actions were unauthorized on a system he was provided access to. Er, no, that's specifically not the case. The officer's actions on the system in fact were authorized; he was authorized to look up licence plate information. The officer's actions later - specifically sharing private information with a third party - were criminal[0], and would be criminal regardless of whether a computer was even involved. 0: Give or take legislative and judicial corruption a al misrepresenting theft as 'civil forfeiture', but that's not really the point.
- saghm 5y ago> would be criminal regardless of whether a computer was even involved I don't think GP is in disagreement with you that it's potentially illegal, just that the CFAA shouldn't apply here.
- a1369209993 5y ago> I don't think GP is in disagreement with you I am confused about how(/whether?) confused you are about what I said. > > > The officer's actions were unauthorized on a system he was provided access to. The CFAA does not apply here, because the officer's actions on the system were authorized. He did not "failed to follow the rules on a system he already had access to", he followed those rules, then separately did something illegal[see previous footnote] with the information he obtained in accordance with those rules. If his actions (on the system) were unauthorized, that would be a CFAA violation, even he was authorized to access the system in some other way.