I've been saying this for years! For reasons unrelated to TOS rulings, too.
A little bit of background...
In 2011, I was charged with unauthorized access to a protected computer. The website in question (Infragard Tampa Bay, run by the FBI through a company called Sylint) was running an older version of DotNetNuke that had a 2008 vulnerability.
The nature of the vulnerability was as follows: If you accessed a specific URL which required no authorization, you could upload files to the server and presumably execute them. (I say presumably, because I didn't.)
I wanted to fight the charge because I never exceeded "authorized access" by using a publicly accessible web form on the public Internet, and the CFAA's terms were vague.
* The website was publicly accessible, without needing authorization
* The file upload form was publicly accessible, without needing authorization
* The folder that files were uploaded to was publicly accessible, without needing authorization
* All of my conduct was authorized by the software they ran on the public Internet, and therefore the unauthorized access I was accused of never actually occurred
My overworked public defender didn't have any fight in him. The EFF wouldn't help either (the person I talked to didn't see the significance of this CFAA ambiguity for civil rights). I grew up in a poor family and couldn't afford legal counsel, so I ended up pleading guilty, which has totally fucked my life up ever since. (It really doesn't get better, even 8-9 years later.)
> since I know many cases in the past relied around users doing shit that was unauthorized by the TOS.
Good. I hope this becomes a precedent that frustrates prosecutors and helps defense cases in appeals court.