6 ms·
Perhaps it would be helpful to consider an offline analogy. Suppose there were no computers involved and all the information was stored in files in a locked roo
by ddlatham 5y ago
Perhaps it would be helpful to consider an offline analogy. Suppose there were no computers involved and all the information was stored in files in a locked room.
Now Van Buren is given a key to access the filing room for his duties, and then uses his key to go in and look up the file on some license plate in exchange for money.
Clearly, this is a terrible breach of trust and authority. It should be against policy. He should be fired. Likely there should also be criminal statutes about police or government employees selling or abusing government records.
But he's not guilty of breaking and entering. He was given access to that data, even if this is not what he was supposed to be going in there for.
As one of the justices noted, if merely misusing computer access that you were otherwise allowed to access were a criminal offense, then potentially "an employee sending a personal email or checking sports scores on a work device" could be criminal, rather than just breaking a company policy.
- foota 5y agoIt seems to me like the issue here is that reasonable people disagree on where the boundary between work misconduct and criminal liability is, and that computers being involved are pushing that to the forefront in these kinds of cases.
- bobthepanda 5y agoAlso there is no reason that misconduct of this kind couldn’t be prosecuted under laws preventing similar breaches that aren’t digital in nature. Selling private data for bribes should be illegal whether or not it’s a database or a file cabinet.
- deleted 5y ago[deleted]
- ddlatham 5y agoI agree that defining where the boundary should be is tricky in practice, and it's a good point that this was hardly a unanimous decision, not to mention overruling the appealed ruling. On the other hand, the underlying law, the CFAA, is about more than just workplace issues like this issue. Interpreting it broadly could mean that violating some terms of use could be a criminal offense, and I am glad that the court avoided that interpretation. It's better having this law be more specific to the intent of criminalizing "hacking" and leaving other laws or policies to deal with how one might abuse computers or networks that one is otherwise entitled to access.
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- matthewmarkus 5y agoYeah, I don't buy this line of argumentation. Suppose the locked room is an apartment and the person with a key is your landlord. I'm pretty sure he's not authorized to enter and do whatever. A plain reading of "authorized" means "having official permission or approval." Van Buren might have been "authorized" to access the system but he certainly wasn't "authorized" to access certain data for cash bribes. I guess I'm at a loss to see this as a "win" for civil liberties, but maybe I'm missing something.
- LocalPCGuy 5y agoYou're trying to make the same argument as in the dissent, but the Court decision spent something like parts of 5 pages defining the word "so" and how this specific law applies to this kind of situation. It's a win for civil liberties because how an employer writes their policies should not potentially open an individual up to federal criminal prosecution under the CFAA specifically.
- matthewmarkus 5y agoSo, what about the Michael Thomas case? Does this verdict overturn his conviction? http://www.epspros.com/news-resources/news/2018/it-worker-loses-argument-justifying-sabotage.html http://www.epspros.com/news-resources/news/2018/it-worker-lo... "Mr. Thomas challenged the verdict, arguing that his conduct was not illegal because his IT position provided him full access to the system and empowered him to 'damage' the system by deleting files or taking the system offline. Thus, any acts were not 'without authorization.' The Fifth Circuit rejected this argument, finding that the statute’s prohibition against exceeding authorized access applies to insiders who go beyond the permission granted them in order to cause damage."
- ghaff 5y agoHe'd presumably be guilty of other things but those might well be civil. IANAL. But when laws/interpretations change, they're not necessarily retroactive.
- LocalPCGuy 5y ago
- kstrauser 5y agoI think there's a solid online analogy for HIPAA data. Certain employees at a hospital have authorization to pull up medical records as part of their jobs. It is extremely illegal for them to view records that aren't required for specific work purposes. If a nurse is treating Jane Smith in room 203, it's OK and normal for her to look at Jane Smith's records. It's absolutely not OK, and punishable with huge fines, for her to pull up her ex-boyfriend's records just out of curiosity. However, it's not a violation of the CFAA for her to look at her ex's data. It's 100% against HIPAA, but she didn't have to break into a computer system to view them. She was authorized to access the system. She wasn't authorized (by virtue of her work requirements) to pull up those specific, but as a nurse, the system permitted her to without going around any login prompts or doing anything harder than typing "John Doe" into the search box. That's the distinction that the CFAA cares about. It's about breaking into systems, or, at least, that's why it was written and that's how the SCOTUS just ruled that it was meant for. It's about access to the system in general, not access to a specific record in the system. There are other laws that govern those specifics.
- dmix 5y agoSo the actual crimes are far better enforced by more accurate legislation. Not swept up by an overly broad, and borderlom irrational interpretation of the CFAA. For ex: the accused is still authorized to access the computer. A cashier at a grocery store is authorized to open/close the til all day long. These may present opportunities but shouldn't be the focus of any crime. The theft itself is already firmly in the criminal code as being illegal. The fact it was computers doesn't change things.
- kstrauser 5y agoNailed it.
- treis 5y ago>But he's not guilty of breaking and entering He is in my state: >A person commits the offense of criminal trespass when he or she knowingly and without authority: >(1) Enters upon the land or premises of another person or into any part of any vehicle, railroad car, aircraft, or watercraft of another person for an unlawful purpose;
- the_pwner224 5y ago> A person commits the offense of criminal trespass when he or she knowingly and without authority Note emphasis. Going in my house without my permission (without authority) to do something illegal is criminal trespass, based on what you quoted. If you have permission to be in my house and do something illegal while in my house then that is not criminal trespass, based on what you quoted. Whatever illegal thing you did is still illegal, but you weren't trespassing. Exactly the same as what GP and the parent of that said about CFAA. The CFAA, as the Supreme Court clarified with this ruling, makes it illegal to break into a computer system. But if you have permission to be in a computer system and do something illegal with that access, whatever you did is still illegal, but you didn't break into the computer system so you didn't violate the CFAA. Making it an exact digital equivalent of your trespassing law.
- R0b0t1 5y agoIt can reasonably argued (and has been argued iirc) that you are not authorized to enter the room if not on official business.
- treis 5y ago>If you have permission to be in my house and do something illegal Sure, but having permission to come in for a certain reason doesn't also grant you permission to come back lather for another reason. To use the analogy, the defendant had permission to enter the "house" for certain purposes. They subsequently entered it for an explicitly unauthorized purpose. That latter entry is trespassing.
- eganist 5y ago