Senator Wants to Make the Computer Fraud and Abuse Act Even Easier to Abuse
eff.org
eff.org
Voters are not going to dump Senator Whitehouse over this proposed amendment, and don’t “probably need” to do anything.
First, in general Senator Whitehouse is great, I’d say among my top 10 favorite Senators (I’m from California, so not a constituent, just a fan). Second, this EFF blog post has decontextualized and exaggerated the effects of this change to the point of absurdity. Third, a small proportion of the general public is worried at all about the CFAA.
Reading the stuff over lunch, I am a bit confused over the EFF's position.
Obviously, my subtext is that the belief that there's a potent grassroots waiting to be activated over Y.R.O. issues is an online echo-chamber fallacy.
I actually believe there are the numbers. I just believe that an organization that has the discipline to attack candidates in the manner, for example, of the NRA is just not there in the YRO space.
My immediate reaction is that the NRA speaks to core identity issues for 100% of rural voters and the overwhelming majority of the half of the country that identifies as "conservative", as well as a pretty big chunk of non-conservatives who see guns as a constitutional bulwhark issue or who just like to nerd out on guns.
So it's not surprising to me that NRA activism generates attendance and financial support that dwarfs that of YRO issues, which have none of those features.
Again: there may have been YRO-type demonstrations that generated big numbers that would rebut this argument. Maybe you can find one?
Otherwise, this is a bit like saying "you can boot a candidate over abortion issues", which handwaves away the fact that abortion is a much, much, much hotter issue in the electorate than YRO issues are.
I'm not, like, personally invested in the idea that YRO lacks broad support. I'd probably like a lot of YRO reforms. But I am invested in the notion that we are all talking and debating inside of an echo chamber that is only loosely connected to reality.
I would imagine getting public number for SOPA protests would be a good starting place. If the EFF is the lead organization and its money numbers are it, then you are correct.
[edit: http://www.ncsl.org/research/elections-and-campaigns/primary... explain primaries in various states. tldr: party selects person via primary (various ways to vote) that gets their name on general election ballot under that party's name]
Which is to say that even when you've got the entire Tea Party movement at your back, it's still so difficult to oust an incumbent in a primary that it's shocking when it happens.
Whitehouse getting booted over CFAA is approximately as likely as Lessig winning the Presidency.
(Though, really, it might be reasonable to suspect that they are generally more vulnerable to primary than general election challenges, unlike most members -- they are generally people whose seats are secure for the party, because that means that they aren't likely to be forced compromise the party's interests for their own electoral prospects, making them more attractive as leaders. But the same effect means that they can be more vulnerable to fragmentation within the party.)
Right now there is no effective group in this space.
They'll stop when they pass the bill that lobbyists for this issue want.
But before reading Nadia Kayyali's summary, you'd be well served by reading the actual amendment, linked at the top of the article. There are 4 proposed offenses:
1. "Stopping The Sale Of Americans' Financial Information"
This proposal amends the current text:
(h) Any person who, outside the jurisdiction of the United
States, engages in any act that, if committed within the
jurisdiction of the United States, would constitute an
offense under subsection (a) or (b) of this section, shall
be subject to the fines, penalties, imprisonment, and
forfeiture provided in this title if—
(1) the offense involves an access device issued, owned,
managed, or controlled by a financial institution, account
issuer, credit card system member, or other entity within
the jurisdiction of the United States; and
(2) the person transports, delivers, conveys, transfers to
or through, or otherwise stores, secrets, or holds within
the jurisdiction of the United States, any article used to
assist in the commission of the offense or the proceeds of
such offense or property derived therefrom.
To instead read: (h) Any person who, outside the jurisdiction of the United
States, engages in any act that, if committed within the
jurisdiction of the United States, would constitute an
offense under subsection (a) or (b) of this section, shall
be subject to the fines, penalties, imprisonment, and
forfeiture provided in this title if the offense involves an
access device issued, owned, managed, or controlled by a
financial institution, account issuer, credit card system member,
or other entity organized under the laws of the United States,
or any State, the District of Columbia, or other Territory
of the United States.
Notice that the larger graf in Whitehouse's amendment is essentially (h) and (1) combined, with a more precise definition for "entity".I went looking for an explanation of the change and couldn't find one, but my guess is that it solves a jurisdictional problem that prevented 18 USC 1029 from being deployed in practice.
It is also not clear how this change is "tailor-made to help indiscriminate prosecution"; if that's the case, it seems like it must also be the case that the original 18 USC 1029 was as well!
Kayyali is an attorney and should be able to explain the logic here.
2. "Shutting Down Botnets"
To the existing fraud statute in 18 USC 1345, Whitehouse's amendment would add a fourth case, following "conspiracy to defraud the US government", "committing banking law violations", and "committing Federal health care fraud", that would read:
(D) violating or about to violate paragraph (1), (4), (5), or (7) of section 1030(a)
[the CFAA] where such conduct would affect 100 or more protected computers (as defined
in section 1030) during any 1-year period, including by denying access to or operation
of the computers, installing malicious software on the computers, or using the computers
without authorization.
Essentially, this seems to create a new offense (presumably cross-chargeable with the CFAA itself, like the wire fraud statutes are) of "CFAAing more than 100 computers in a year".This seems well-intentioned but overbroad. A change from 100 to 1000 computers might make more sense. A "knowing" standard, so that you can't be charged for a single offense that happens to touch 100 computers you didn't know existed, might also be helpful. It's also a fair argument that we perhaps don't need new law to clamp down on botnets, which are probably already black-letter illegal.
3. "Aggravated Damage To A Critical Infrastructure Computer"
42 USC 5195 defines "critical infrastructure" as systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters. Whitehouse's bill would attach more severe CFAA penalties to knowingly damage critical infrastructure, if the attack involved actually could have impaired critical infrastructure.
Language to this effect has been part of several proposed amendments to CFAA.
Kayyali claims this amendment is "redundant". Presumably, that's because PATRIOT already defines "critical infrastructure" and the CFAA already criminalizes any attacks on any computer? Otherwise, I don't see where a statute exists that would attach greater penalties to attacks that (say) took down the power grid, or halted trading on exchanges. The location of that statute in existing law would be a helpful clarification for Kayyali to provide.
Kayyali invokes CFAA's "draconian penalties". I agree: the penalty mechanism in CFAA is egregiously broken (indeed, I think it's the only totally broken part of CFAA). But this particular amendment seems like a poor place to make that stand, cabined as it is on attacks that citizens in the US would overwhelmingly want criminalized!
Remember, under Whitehouse's initial proposed language, you have to know you're attacking the power grid, or the 911 dispatching system, or the NYSE, and the attack you employ has to be plausible.
4. "Stopping Trafficking In Botnets"
18 USC 1030 (a)(6), part of the CFAA, currently reads:
(6) knowingly and with intent to defraud traffics (as
defined in section 1029) in any password or similar
information through which a computer may be accessed without
authorization, if—
(A) such trafficking affects interstate or foreign commerce;
or
(B) such computer is used by or for the Government of the
United States;
Whitehouse would prefer it read instead: (6) knowing such conduct to be wrongful, intentionally trafficks
in any password or other similar information, or any other means
of access, further knowing or having reason to know that a
protected computer would be accessed or damaged without authorization
in a manner prohibited by this section as the result of such
trafficking.
This really pissed Kayyali off, because "knowing such conduct to be wrongful" is a phrase that appears nowhere else in the US code. That
probably does mean the language would need to be changed. However:
the term "knowing" is plastered all over the US code and has a meaning
that appears to stretch all the way back to Common Law, and "wrongful"
has a legal definition ("would expose you to criminal prosecution").It's unclear from Kayyali's summary, but given the context, this appears to be the basis for Kayyali's concern that the amendment will be a "threat to security research".
Finally, I can't resist pointing out the bogus emotional appeal that leads off Kayyali's analysis. Kayyali would like you to believe that overzealous prosecutors can charge you under the CFAA for violating the terms of service of a website. But of course Kayyali is aware that after Nosal, that interpretation of CFAA has famously been rejected by the entire Ninth Circuit and is now unlikely to get much oxygen elsewhere.
So phrases such as:
"The CFAA does not explain what "without authorization" actually means."
and
"The amendment would make it much easier to prosecute anyone for trafficking in passwords or similar information through which a computer may be “accessed without authorization.” The amendment changes the mental state required to simply “knowing such conduct to be wrongful”"
Sound plenty powerful/logical to the general public who is already inclined to support the EFF, not realizing: 1. As you mention "knowing" and/or "knowledge" is not just a term of art in law but an actual legal standard that has been defined and redefined through case law (same is true of willful, and reckless in a criminal context); and 2. All law as written (in a vacuum) has very little interpretation until a set of facts is applied to the law where a court may interpret the law setting precedent, much like the Nosal case you highlighted. Just as an analogy, when talking about the 4th Amendment I could say the Founders wanted us to be free from "unreasonable search and seizures" and then tell the public how that is ripe for abuse because there is no definition of "unreasonable" in the Constitution...and I would technically be right, simultaneously ignoring 100+ years of case law which defines unreasonable as applied in 1,000's of factual scenarios.
Deleted comment
Funny, that sounds almost like you're proposing mandatory sentencing...