6 ms·
The CFAA isn't super complicated. It basically boils down to: Don't fuck with other people's shit if they don't want you to.
by VWWHFSfQ 1y ago
The CFAA isn't super complicated. It basically boils down to:
Don't fuck with other people's shit if they don't want you to.
- boston_clone 1y agoAre you a lawyer by chance? I seem to remember cases or interpretations of the CFAA in which even guessing the username password combo of "admin:admin" would violate the act, resulting in teenagers or children being caught up in cYbEr FrAuD
- petcat 1y agoIt doesn't matter if you brute forced their crappy login with commonly-used credentials. You think it's OK for someone to rummage around in your garage just because they correctly guessed your keycode was 12345? Of course not.
- boston_clone 1y agoI'm more focused on the assertion that "The CFAA isn't super complicated." Which raises sincere doubts about the commenter's credibility to make such a claim.
- echoangle 1y agoHow does „you’re not allowed to guess credentials“ mean it’s complicated?
- boston_clone 1y agoI think that's a massive oversimplification of how the CFAA has been applied.
- RankingMember 1y agoDoesn't this posture also criminalize white-hat hackers, whose disclosures would protect you from the people who actually want to do damage?
- dpassens 1y ago(I don't know enough about the CFAA to know whether this is true so I'll assume it is.) To continue the garage door analogy, you wouldn't walk up to any random garage door and try code 12345 to help protect the owner's stuff, would you?
- RankingMember 1y agoTo stick with this analogy: I think a white hat equivalent would be more like driving down the street with a garage door remote set to a default code and then notifying anyone whose door opens in response that they should change their code. I don't think that should be illegal.
- ecb_penguin 1y ago> Doesn't this posture also criminalize white-hat hackers, whose disclosures would protect you from the people who actually want to do damage? There is no law for "white-hat hackers". You don't get to break into a system because the color of your hat. "White-hat hackers" have contracts, or very specific rules of engagement. Having run many a bug bounty, if someone was malicious, we would absolutely work to prosecute. You can also find bugs in software freely, as long as you don't obtain unauthorized access to other people's systems.
- tptacek 1y agoThis isn't true: there is, jurisdictionally dependent and I think also dependent on DOJ norms, a broad exception for good-faith white hat vulnerability research that would otherwise violate CFAA. Like I said, CFAA is very complicated in practice.
- account42 1y agoYou think walking through an unlocked door should result in federal charges?
- petcat 1y agoSo now the door is unlocked?? Where are the goal posts? Don't mess with people's stuff if they don't want you to. This seems very simple to me. But I'm aware that you're trying to find some fringy gray area where you think it will be OK to mess with people's stuff even though they don't want you to.
- Dylan16807 1y agoIf we're making an analogy to the Weev case then yes the door was unlocked, with the explicit intent that the general public could come through that door and access some of the documents.
- Ekaros 1y agoSo what about using rakes or bump keys? Very low tech, very easy. Can defeat some poor quality locks.
- account42 1y agoStill sounds like petty crime that doesn't need the FBI to roll in. The point is that in the physical world there is some notion of proportionality in the response to trespassing depending on the actual damage done and sophistication and premeditation of the act. We don't generally lock up people because they accidentally walked into an area they shouldn't have. But once computers are involved we have laws that automatically make even even minor infractions into a big scary issue that allows the government to essentially destroy someone's live.
- ptero 1y agoWalking through an unlocked door that has a sign "private property, do not enter", searching for sensitive information, finding it and exposing it surely could. Or not, depending on how the party who owns what's inside that door feels. But if it feels he should be prosecuted, then hell yes, the state should do that. My 2c.
- codyb 1y agoI mean... if someone walked into your house cause you only closed the screen door while running to the store quick you'd still call the cops cause there was someone breaking into your house lol.
- efdee 1y agoBreaking in in a system, whether or not the password was easy to guess, sounds like a crime to me.
- ethbr1 1y agoIt is a crime! But CFAA charges should, and this is the issue a lot of people have with them afaict, have a sliding scale for premeditation though. If I knock on a door, it swings open, and I walk inside and steal something, then imho there should be a lesser maximum charge for possessing burglary tools than if I show up with a lock gun, crowbar, and concrete saw. A lot of the CFAA excesses are maximum penalties from the CFAA being thrown at people using minimally sophisticated / premeditated methods, in addition to charges about the underlying crime. That doesn't seem just or fair. In practice it's turned into an if(computer){increase maximum penalty} clause, solely at the government's discretion.
- efdee 1y agoYou have a point. But on the other hand you have no idea of what tools the intruder possesses, only (at best!) what they used. I think intent probably matters a lot more than the technicality of how you succeeded.
- JambalayaJimbo 1y ago>If I knock on a door, it swings open, and I walk inside and steal something, then imho there should be a lesser maximum charge for possessing burglary tools than if I show up with a lock gun, crowbar, and concrete saw. Why? (I'm not a lawyer...) - shouldn't intent and harm (i.e. the value of the stolen item) be the only relevant details? Now of course its much easier to demonstrate intent if there's a crowbar involved, but once that's already established, it seems irrelevant.
- ethbr1 1y agoBecause that's the way most method-specific laws work, at least in the US. There's an underlying result crime (eg causing business harm by destroying a database), then the method by which one chose to do it (eg exceeding authorized access to a computer with the intent to cause harm). The CFAA was originally passed under the erroneous worry that existing laws wouldn't be enforceable against cybercrime, which turned out to generally be false. When you cause damage, there's almost always a law by which someone can sue you for those damages. What there wasn't, and what the CFAA created, were extra penalties for computer crimes and an ability to charge people with computer crimes where there were no damages (eg Aaron Swartz). And why should those things need to exist? Theft is theft. Destruction is destruction. It was an underspecified law, ripe for prosecutor overreach. See: https://www.congress.gov/crs_external_products/R/HTML/R47557.web.html#_Toc135223781 https://www.congress.gov/crs_external_products/R/HTML/R47557... It fit with 'premeditated intent' intensifiers (where penalties escalate if premeditated intent can be proven)... but that wasn't actually how it was written or how it is used. Instead, it's a method-based checkbox that allows prosecutors to tack on additional charges / penalties. If a computer was used to destroy this thing, add X years the sentence.
- brookst 1y agoIf those teenagers or children enter someone's house and vandalize or steal because the door (or window) isn't locked, is it no big deal?
- aveao 1y agoStrictly speaking, unless you do destructive actions, it's not stealing, but instead unauthorized access. If I walk into your house, take a picture of your financial documents, that's not theft. That's still (potentially:) breaking and entering, trespassing, and depending on what I do with those pictures also fraud, but it's not theft. This is all semantics of course, but I just really dislike the idea that digital data can be "stolen". --- But also: No one deserves to get their things broken into, but if you expose things to the internet without proper security, you can't cry too much if you get broken into I think. It's not okay (and possibly illegal? idk) for me to read other patients' medical records if they're in open display when I go to the doctor's office, but they also have an obligation to secure this information. I do like the approach of "Mens rea" / "Guilty mind" overall, to differentiate of children/teenagers fucking around (ofc depends on the extent of what they do), white hat researchers finding vulnerabilities (should not be criminalized), and black hat people doing things with criminal intent.
- tptacek 1y agoThe CFAA is in fact pretty complicated. The text of the law isn't, but the implications of that text are, and so is the jurisprudence. Rockenhaus's CFAA case does not appear to have been at all complicated, though.