5 ms·
It isn't just about access to the system, but access to the data as well, and he accessed data that he was not authorized to access. That is "exceeding authoriz
by secothroa 5y ago
It isn't just about access to the system, but access to the data as well, and he accessed data that he was not authorized to access. That is "exceeding authorized access".
- Logging onto the system: officer has technical access to log on and is authorized to log on, no problem
- Accessing normal data the officer needs for legitimate reason: officer has technical access to this data and is authorized to access it, no problem
- Accessing data for the purpose of a bribe: officer has technical access to this data, but is not authorized to access it, thus they are exceeding their authorized access
- kstrauser 5y agoHis crime was violating the policy. He clearly did not hack into the computer system to get the data, and that's what the CFAA was meant to prosecute. Put another way, he didn't work around any computer controls to get at the information.
- secothroa 5y ago>Put another way, he didn't work around any computer controls to get at the information. That's irrelevant. You can do unauthorized things without having to "work around" controls. >He clearly did not hack into the computer system to get the data, and that's what the CFAA was meant to prosecute. The CFAA was meant to prevent computer-related crimes including but not limited to unauthorized access, fraud, abuse, etc, which this clearly was.
- kstrauser 5y ago> That's irrelevant. You can do unauthorized things without having to "work around" controls. SCOTUS disagrees with you, and so do I. > The CFAA was meant to prevent computer-related crimes including but not limited to unauthorized access, fraud, abuse, etc, which this clearly was. He didn't do any of those with respect to the computer system. He accessed a resource that he had authorization to access as part of his job. He misused it, but didn't break into the system or gain access by fraud. His reasons for accessing the data were wrong, but his access was authorized.
- secothroa 5y ago>His reasons for accessing the data were wrong This, by definition, makes his access unauthorized. That's the point. "Authorization" is more than just technical controls. He was not authorized to access the data for this reason.
- deleted 5y ago[deleted]
- kstrauser 5y ago> "Authorization" is more than just technical controls. SCOTUS just literally said the opposite.
- willseth 5y ago> "Authorization" is more than just technical controls. You are applying too broad a definition to "authorization." In this context it refers specifically to the configured authorization behavior of the computer system. They gave him the equivalent of a key to a lock implemented in the computer system, and the law is meant to address the equivalent of someone who pick locks, not someone who misuses the access provided by keys they were given.
- jameshart 5y agoActually I don't know that SCOTUS has much to say in this ruling on the necessity of effective technical controls. If the officer was explicitly told 'you can use the computer system, and it can do plate lookups, but you're not allowed to perform plate lookups ever', then he went ahead and made a plate lookup anyway, I'm not entirely clear that the ruling would exclude that from being a CFAA charge, even without there being any password or permission model to lock him out of that functionality. I could be wrong there - there may be other caselaw on that - but I didn't read much in the ruling that suggested they were interested in the extent to which the system technically restricted access to this functionality. But in this case he had legitimate technical access, he was authorized to use it to look up plate data, and the SCOTUS verdict, sensibly, concludes that using that access for an illegitimate purpose does not merit a CFAA charge.
- chipsa 5y agoCFAA now is about violating technical controls, not policy controls. If policy says "Don't look at HR data", but nothing technically stops you from looking, it's not a CFAA violation to look.
- deleted 5y ago[deleted]
- hackinthebochs 5y ago>You can do unauthorized things without having to "work around" controls. The term "unauthorized" is overloaded. There is one sense in which he was unauthorized by policy. There is another sense by which he was authorized by technical access. These are separate scenarios and separate violations. It makes no sense for unauthorized-by-policy to be a violation of a computer hacking statute.
- NovemberWhiskey 5y agoThere's some kind of weird penumbra here. The intent of the owner of the computer system clearly matters, but how much? At the "seems pretty clearly like unauthorized access" end of the spectrum, we can imagine someone brute-forcing a password to gain access to a system. They're "authorized by technical access" once they have the username/password, but that's surely a focal case of the kind of crime that the statute was intended to address. Alternatively, say there was a guest account activated with a default password. Would we argue that someone with no relationship to the owner who discovered the account was active and then used it was "authorized by technical access"? Presumably the answer is that authorization in that case depends on whether it was the intent to allow strangers to use the system as a guest or whether it was some kind of technical oversight. What about if you were hired as a data entry operator, but your account was accidentally set up as a superuser? The owner of the system intended to give you one level of access but accidentally gave you another. Are you a hacker if you use the unintended access grant to snoop around? Again, you're "authorized by technical access". What about if your boss puts his username/password on a post-it note on his monitor and you use his account without his knowledge? What about if you use it with his knowledge and agreement?
- hackinthebochs 5y agoYeah, the issue is a lot more ambiguous than my comment let on. If I had to make a determination, I would say any specialized technical knowledge or extra effort to access the resource would fall under the CFAA. So knowing of a default guest account that wasn't pointed out to you by staff, or finding the boss' password on a post-it note and entering it would count. Being given a superuser account is even greyer. Perhaps if you come across sensitive data in the natural course of your work, then you would be safe from this law. If you recognized your elevated privileges and then went out of your way to find sensitive information, then that should be a violation.
- TeeMassive 5y ago> >Put another way, he didn't work around any computer controls to get at the information. > That's irrelevant. You can do unauthorized things without having to "work around" controls. You are conflating bypassing security measures (which in the digital world would be equivalent of lock picking) and abuse of trust (throwing a party and trashing the home of someone who trusted you with the keys to only feed the cat).