I suspect the definition of 'unauthorized access' will need to be more clearly defined since I know many cases in the past relied around users doing shit that was unauthorized by the TOS.
I suspect the definition of 'unauthorized access' will need to be more clearly defined since I know many cases in the past relied around users doing shit that was unauthorized by the TOS.
I've been saying this for years! For reasons unrelated to TOS rulings, too.
A little bit of background...
In 2011, I was charged with unauthorized access to a protected computer. The website in question (Infragard Tampa Bay, run by the FBI through a company called Sylint) was running an older version of DotNetNuke that had a 2008 vulnerability.
The nature of the vulnerability was as follows: If you accessed a specific URL which required no authorization, you could upload files to the server and presumably execute them. (I say presumably, because I didn't.)
I wanted to fight the charge because I never exceeded "authorized access" by using a publicly accessible web form on the public Internet, and the CFAA's terms were vague.
* The website was publicly accessible, without needing authorization
* The file upload form was publicly accessible, without needing authorization
* The folder that files were uploaded to was publicly accessible, without needing authorization
* All of my conduct was authorized by the software they ran on the public Internet, and therefore the unauthorized access I was accused of never actually occurred
My overworked public defender didn't have any fight in him. The EFF wouldn't help either (the person I talked to didn't see the significance of this CFAA ambiguity for civil rights). I grew up in a poor family and couldn't afford legal counsel, so I ended up pleading guilty, which has totally fucked my life up ever since. (It really doesn't get better, even 8-9 years later.)
> since I know many cases in the past relied around users doing shit that was unauthorized by the TOS.
Good. I hope this becomes a precedent that frustrates prosecutors and helps defense cases in appeals court.
Employment!
I tried to go the crypto consultant route in recent years and was told by many people via Twitter/Reddit private message that they can't or won't go with the company I helped start simply because of my criminal background.
I spent most of last year job-searching. I interviewed well, but many companies rescinded offers after my background check concluded, even when I told them about this incident up front.
In 2011, everyone joked that I'd be fine. "The government will probably follow up with a job offer," they insisted. Instead, I was rendered unemployable by most of the companies that desire the skills I possess.
The silver lining is that some companies restrict their background checks to a time-gate, which means it's not totally impossible to make a living. But they're the minority.
> Is it directly related to the charges or is it the outcome of spending time behind bars?
My sentence was probation and a short duration of house arrest, community service, and paying Sylint $9,370 (which, at barely above minimum wage, took a few years). My probation was terminated early for good behavior.
The problem has less to do with the courts and more to do with background checks.
People make mistakes. Especially young people. (I was 21 when this happened.)
Learning itself is a messy process that often requires making mistakes to be successful.
Punishing someone in perpetuity for having not lived a perfect life is a problem that society hasn't yet solved.
We have hacks ("Right to be Forgotten") to try to alleviate some of the symptoms, but with the advent of the Internet, there is now a public, immutable record of your most embarrassing fuck-ups. And I don't think we were ready for that.
This also happened in the state of Florida, which has very open records.
Avoid the finance industry or anything related to financial transactions. The risk is too high for them, they won't hire you.
Sylint pressed the charges through the FBI.
Originally, they also insisted I caused damage days before the date of incident and tried to tack on $32k in damages. I pointed out that I do not possess a time machine, and they shifted it from (June 18-24) to (June 21-27) and lowered the dollar amount to $9k.
I haven't really thought about that angle since, either.
You used a vulnerability to hack into some server associated with the FBI, I don't see any ambiguity here.
I never said or implied that.
All I said is, because all of my conduct involved publicly accessible components of their web application, I never exceeded authorized access.
Which means that the CFAA's clause about "unauthorized access" in particular does not apply, since none of my packets exceeded or bypassed an authentication or authorization control on their web app.
> Most homes are accessible from public roads, that doesn't mean you are allowed to climb through any open window that you see.
A better analogy is knocking on someone's door, only to discover it swings open, then walking away. And then getting charged with breaking and entering for their failure to shut their door, and then paying for damages for leaving a muddy footprint on their exterior welcome mat.
> You used a vulnerability to hack into some server associated with the FBI, I don't see any ambiguity here.
I won't argue that I'm fully without blame.
The mistake I made during all of this was, upon discovering they were running an outdated version of DotNetNuke (right click > view source; not exactly something I had to go out of my way to detect), I panicked. And to assuage my own anxiety, I tested the file upload to confirm that it was real.
That was the mistake that let them prosecute me at all. And it's a mistake I have learned from:
In the years since, I have never sent a packet with security implications to another network even for projects with a public bug bounty. I constrained myself henceforth to reviewing source code and reverse engineering, since that doesn't involve sending packets over a network and invoking a law that was written before the concept of a public network existed. (And that law being problematic is my entire point in this discussion, not appealing for amnesty in the opinions of HN users. Anyone who decides to hate me won't be the first.)
Even if I knew not to do that then, I still would have informed them of their vulnerability as soon as it was discovered. Because that was the right thing to do.
>Access Complexity Medium (The access conditions are somewhat specialized. Some preconditions must be satistified to exploit)
No.
And even if you tried to argue that, the exploit was public on exploit-db for years, and therefore the expected security from the broken obfuscation is zero bits; so in this case, it would not count.
More pertinent:
> Authentication Not required (Authentication is not required to exploit the vulnerability.)
Thats why I don't agree with the article that contrasts the Facebook/Power Ventures case with the hiQ Labs case. These are fundamentally different. Power Ventures was using Facebook Users credentials to log on to facebook and I think thats a clear case of unauthorised access. Facebook had no direct relationship with Power Ventures and had not granted them access to those accounts at all.
In the hiQ Labs case they had legitimate access to LinkedIn and were just scraping publicly viewable information. It's jut that LinkedIn didn't like what they were doing with it.
Of course the SSA database access case from 2010 is an anomaly in this aspect. The user was authorised to access the data if doing so in the course of his work, and I think the police case from 2015 was ruled correctly. In both case they're reprehensible creeps, but they should be prosecuted as creeps, not as hackers.
I strongly disagree. Facebook didn't have a relationship with Power Ventures, but it did have a relationship with its own users who granted Power Ventures access to their accounts. And while I admit it's not legally recognized yet, I firmly believe that users have an inherent Right to Delegate lawful access to 3rd-party software products and services[0].
I don't think the Power Ventures case had anything at all to do with unauthorized access. I think it was an attempt by Facebook to block users from exercising control over their own data.
For context, look at the DMCA claims Facebook also filed in that case. It's been a really long battle to fight against the DMCA's unconstitutional provisions against subverting DRM for legal reasons. We have a lot of precedent to see how companies use systems like the DMCA. And the way they commonly use them is not to go after pirates, it's for market lock in and to restrict legitimate users. To paraphrase Doctorow, there are really bad consequences when we allow a company to make it a federal offense to use a product in a way that doesn't make their shareholders money.
Treating ToS violations as a federal crime gives companies that ability on an even broader scale. It's legal to circumvent DRM? Oh, but our ToS blocks that. You exported your own data that you legally own? No, our ToS blocks that. You build a Matrix bridge for your DMs in my chat app and another competing service? Sorry, that's a federal offense now.
A company should not be allowed to arbitrarily invent new federal laws. At most, violating a ToS should be a civil offense, and companies like Facebook should be forced to sue their own users, not providers like Power Ventures.
I absolutely should be charged with unauthorized access, because the person who gave me access had no right to give me that access and I knowingly used a protected computer system against the wishes of the owner, for my own aims.
Replace the above with "medical records" or "banking information" or whatever you wish.
Just because someone gave me a password, doesn't mean I'm allowed to use it, even if THEY were allowed to use it.
First, the cop who gave you access didn't have the right to use it in the way they offered. They don't own the data. The "right" they're delegating to you isn't a lawful right they actually have to delegate.
This is a really big difference -- the problem in the scenario you propose isn't that a police company got hacked (in fact, I would argue it didn't). The problem is the police department illegally abused information and distributed that information to other people, and you willingly participated in that crime.
In contrast, all of the data access that was delegated to Power Ventures and all of the stuff that Power Ventures did with that data was stuff that users had the right to do.
Second problem, this would be illegal because of privacy laws around how the police are allowed to use your data, not because a company declared it so. I'm not saying you should have carte blanch privileges to violate any law just because another person violated that law first, I'm saying companies shouldn't have carte blanch privileges to make new laws.
To re-emphasize the point above, the problem in this scenario isn't that the police department got hacked. The problem is that people were performing illegal background checks. If the police officer didn't give you a password, and instead just did whatever background checks you wanted on their own without you ever touching the system, this would still be a crime. The system access isn't the important part.
Third, in the scenario you propose, both you and the cop would get in trouble. Hopefully, the cop would get in even more trouble than you. So when Facebook brings every user who "illegally" shared their password into court, then I'll entertain the notion that they think this is a real hacking case. Otherwise, why are we comfortable letting off all these willing accomplices to an unlawful entry case?
My proposal would require companies to actually take security very seriously.
https://www.troyhunt.com/we-take-security-seriously-otherwis...
Are they discussing national secrets over Zoom? Without end-to-end encryption?! That's some form of criminal negligence and/or mishandling of classified information in every jurisdiction I know.
If not, it's little more than a nuisance and a reminder that Zoom should not be relied on for important communications.
I think that covers police databases, social security and also customer details on a website amongst others. It would not necessarily cover accidentally accessing customer data on a system (that happens) but if you started wilfully sharing that data or details about how to access it with persons other than the owners of the system then you could start to get into the problematic zone. To prevent the scenario where the owners just do nothing and then when the 'hacker' tells somebody else they call the cops and accuse, it should probably be a crime, after being notified that your system is leaking private data, that you didn't take any action to plug that hole.
Here I disagree, assuming we are still talking about the USA. There are strong freedom of speech implications when you make sharing the fact that some company left their S3 bucket world-readable a criminal offense. Would the New York Times be open to criminal prosecution for publishing such information on their front page?
Very tightly-defined, personally-identifiable data I can see being protected. Things like financial and medical records, sensitive search queries etc. but general disclosure of security issues should not be something that is criminal.
So you find a company leaves their S3 bucket world-readable by accident and it contains personal information that the persons concerned would reasonably consider private (from medical records all the way to my real identity on a forum). The correct course of action is not to exercise your free speech by going first to the New York Times so they can publish a story about it allowing all and sundry to access that information, but to go to the company and tell them that this is open and that information they are responsible for is leaking. This is your responsibility to your fellow citizens whose data is leaking! However, if the company do not fix it in a reasonable time then you can report them to the relevant authorities who can decide what action to take and now the criminal aspect of this data leakage will now be attached to the owners of the company which has not fixed the problem and you are free to exercise your free speech rights.
If I sell (for money, fame, fake internet points or smug satisfaction) access to your personal data without your consent how can I claim that is my free speech? I think the USA has the concept of limits to freedom, ably illustrated by the phrase "Your Freedom To Swing Your Fist Ends Where My Nose Begins"
Why wouldn't that apply to some website that's using some cache exploit to probe users' browsing histories?
I mean, a computer is a computer, and unauthorized access is unauthorized access. No matter who's involved.