We also know from prosecutions in other statutes that the government will often prosecute a a broad crime with many separate sub-definitions of the various way you can break it, then refuse to tell you under which sub-definition you're being charged, meaning you have no way to know if the jury even were unanimously convicting for the same thing and no way to know what you're even defending against.
Unlocked doors, open windows, any lack of security doesn't give you permission to enter. Just as "incrementing a GET request" doesn't mean anything outside of the intent.
The intent was to do damage.
His intent of releasing the data was bad (assuming he started with that intent!) but he wasn't committing any fraud when collecting it. He didn't bypass any authentication or damage the server. CFAA is the wrong law to use.
If a restaurant puts a bunch of proprietary documents in a dusty corner of the public lobby, you shouldn't browse through them but you're not breaking and entering if you do so. No matter what your intent is.
Don't fuck with other people's shit if they don't want you to.
I seem to remember cases or interpretations of the CFAA in which even guessing the username password combo of "admin:admin" would violate the act, resulting in teenagers or children being caught up in cYbEr FrAuD
Which raises sincere doubts about the commenter's credibility to make such a claim.
To continue the garage door analogy, you wouldn't walk up to any random garage door and try code 12345 to help protect the owner's stuff, would you?
There is no law for "white-hat hackers". You don't get to break into a system because the color of your hat.
"White-hat hackers" have contracts, or very specific rules of engagement. Having run many a bug bounty, if someone was malicious, we would absolutely work to prosecute.
You can also find bugs in software freely, as long as you don't obtain unauthorized access to other people's systems.
Don't mess with people's stuff if they don't want you to. This seems very simple to me. But I'm aware that you're trying to find some fringy gray area where you think it will be OK to mess with people's stuff even though they don't want you to.
The point is that in the physical world there is some notion of proportionality in the response to trespassing depending on the actual damage done and sophistication and premeditation of the act. We don't generally lock up people because they accidentally walked into an area they shouldn't have. But once computers are involved we have laws that automatically make even even minor infractions into a big scary issue that allows the government to essentially destroy someone's live.
Or not, depending on how the party who owns what's inside that door feels. But if it feels he should be prosecuted, then hell yes, the state should do that. My 2c.
I suppose if it's the White House the guy'd just get pardoned by the next president anyways.
But CFAA charges should, and this is the issue a lot of people have with them afaict, have a sliding scale for premeditation though.
If I knock on a door, it swings open, and I walk inside and steal something, then imho there should be a lesser maximum charge for possessing burglary tools than if I show up with a lock gun, crowbar, and concrete saw.
A lot of the CFAA excesses are maximum penalties from the CFAA being thrown at people using minimally sophisticated / premeditated methods, in addition to charges about the underlying crime.
That doesn't seem just or fair.
In practice it's turned into an if(computer){increase maximum penalty} clause, solely at the government's discretion.
I think intent probably matters a lot more than the technicality of how you succeeded.
Why? (I'm not a lawyer...) - shouldn't intent and harm (i.e. the value of the stolen item) be the only relevant details? Now of course its much easier to demonstrate intent if there's a crowbar involved, but once that's already established, it seems irrelevant.
There's an underlying result crime (eg causing business harm by destroying a database), then the method by which one chose to do it (eg exceeding authorized access to a computer with the intent to cause harm).
The CFAA was originally passed under the erroneous worry that existing laws wouldn't be enforceable against cybercrime, which turned out to generally be false.
When you cause damage, there's almost always a law by which someone can sue you for those damages.
What there wasn't, and what the CFAA created, were extra penalties for computer crimes and an ability to charge people with computer crimes where there were no damages (eg Aaron Swartz).
And why should those things need to exist? Theft is theft. Destruction is destruction.
It was an underspecified law, ripe for prosecutor overreach. See: https://www.congress.gov/crs_external_products/R/HTML/R47557...
It fit with 'premeditated intent' intensifiers (where penalties escalate if premeditated intent can be proven)... but that wasn't actually how it was written or how it is used. Instead, it's a method-based checkbox that allows prosecutors to tack on additional charges / penalties. If a computer was used to destroy this thing, add X years the sentence.
But if there are burglary tool charges, they should depend on whether you used burglary tools to burgle, not how much theft you did.
Suppose you are leaving a store and heading to your car. For whatever reason, the button on your keys unlocks someone else's car that is the exact same make and model as yours. You hop into the car, your key starts the ignition, and you drive off (Yes, this has really happened). That isn't legally theft because you legitimately believed that was your car - aka you didn't intend to take something that wasn't yours.
For 98% of laws, in order to be convicted, the government needs to prove you intended to commit the crime. Obviously, I'm oversimplifying what is a very complicated topic you spent two years learning, but that's the gist
As far as I am concerned, I am allowed to send any traffic I wish to public-facing hosts, and if they respond with content that the owners would not wish me to see, I have no responsibility to refrain. The only traffic I am not permitted to send are credentials I am not authorized to use (this would include password guessing, because if I manage to guess correctly, I was still not permitted to use it).
So which was it?
I am still permitted to do this. None of the details of this case give me the impression that they're using CFAA in such a way as to offend my sensibilities. Sounds like he sabotaged a former employer and caused hundreds of thousands in (tort not physical) damages. I guessed the urls for some issuu.com links that aren't available in search, and downloaded the page images to make a pdf. I was never prompted for a password. Arrest me, I'm a notorious hacker.
> I am allowed to send any traffic I wish to public-facing hosts
No you're not. Denial of service is a federal crime.
> I have no responsibility to refrain
Yes you do, and this is just beyond silly. The nuance of how you obtained it will be decided in a court. Stop making everything so reductionist and lazy.
> The only traffic I am not permitted to send are credentials I am not authorized to use
Absolutely not. Use of a vulnerability to cause a data breach is OBVIOUSLY a federal crime.
This is beyond absurd.
You and I seem to both speak/write English, but there is a language barrier. For me, "authorization" means that they have given me credentials, and any content locked down under those credentials is off-limits.
For you, "authorization" is a magical term that has no real meaning. It means that they want me to have the content. But I am no telepath, and I do not know what they want me to have or do not want me to have. The only way, from my point of view, to know what they want me to have or not is to try to retrieve the content without credentials, and if it succeeds, it's legal.
Of course, there are a few corner cases. What if I discover some software defect that very clearly shows they intended to require credentials, and a test without credentials shows that it is indeed off-limits, but exploiting the defect produces that content? I wouldn't do that, that'd be illegal.
But your way of (non-)thinking is alien to me, and no reasonable judge or legislator could possibly mean what you claim that law states. Or at least what you seem to claim.
>No you're not. Denial of service is a federal crime.
Only with intent. If I send reasonable content that shouldn't be DoS, how was I to know? I intend no crime.
>Yes you do, and this is just beyond silly.
You're the one being silly. You can't even decide what you mean by "authorized".
>The nuance of how you obtained it will be decided in a court.
I'm never going to trial, I'm not even going to be noticed.
>Use of a vulnerability to cause
Use of a clear defect. The biggest and most dangerous vulnerabilities are the apathy and stupidity of their employees, their lack of a sane business model and attainable vision, and so on. Using those is just common sense. There is a popular magazine that is subscription only. But they have the pdf download links hidden with display: none CSS. These links require no authorization. Just knowledge. I retrieve those quite punctually.
There's nothing at all CFAA-specific about this; this is really basic US criminal law and it comes up in all sorts of different criminal justice contexts. The terms you're both dancing around are mens rea and actus reus.
I'm not in trouble. There is virtually zero chance of this ever being noticed by law enforcement, and even less chance than that of them giving a shit.
Also note, I am not arguing what the worst possible interpretation might falsely convict someone of, but how the law should be viewed, or, if someone can demonstrate to my satisfaction that the law disagreed with, then how it should be altered.
If I have to guess what retards (read: juries) might think is reasonable, then there can be no public internet. We're just a few years after journalists were arrested for looking at html source with "view source", aren't we?
>The terms you're both dancing around are mens rea
I'm only mildly ignorant. Has CFAA ever been considered to describe strict liability crimes?
If I walk into your house, take a picture of your financial documents, that's not theft. That's still (potentially:) breaking and entering, trespassing, and depending on what I do with those pictures also fraud, but it's not theft.
This is all semantics of course, but I just really dislike the idea that digital data can be "stolen".
---
But also: No one deserves to get their things broken into, but if you expose things to the internet without proper security, you can't cry too much if you get broken into I think. It's not okay (and possibly illegal? idk) for me to read other patients' medical records if they're in open display when I go to the doctor's office, but they also have an obligation to secure this information.
I do like the approach of "Mens rea" / "Guilty mind" overall, to differentiate of children/teenagers fucking around (ofc depends on the extent of what they do), white hat researchers finding vulnerabilities (should not be criminalized), and black hat people doing things with criminal intent.
Being angry at the CFAA is one thing, but this case has no relation to modifying a simple GET request.
Interestingly, Rockenhaus's isn't --- it's more or less exactly the circumstance foreseen by the authors of CFAA, who believed that even though existing law covered most hacking-type scenarios, they didn't form a clear basis for felony charges for purely destructive computer abuse.
Could you give some examples of this?
Navy sailor was convicted of possessing machine guns and destructive devices.
The ATF for example put back together de-milled RPGs, which could be a destructive device
However the statute says the following:
(2) any type of weapon by whatever name known which will, or which may be readily converted to, expel a projectile by the action of an explosive or other propellant, the barrel or barrels of which have a bore of more than one-half inch in diameter, except a shotgun or shotgun shell which the Secretary finds is generally recognized as particularly suitable for sporting purposes; and (3) any combination of parts either designed or intended for use in converting any device into a destructive device as defined in subparagraphs (1) and (2) and from which a destructive device may be readily assembled.
The ATF took his demilled RPG, put another gun (owned by the ATF) inside of it, then fired it to prove it had a bore over 0.5 inch capable of expelling projectile.But the state didn't tell him under what definition he was charged, so they didn't know if they were defending against the collection of parts the ATF took (falls under 3), or against the weapon the ATF claimed it was after they put the parts together (which falls under 2).
For what it's worth, I think this is the government's response to the argument you raise (on page 22 of the response brief, PDF page 30):
> Section 5845, captioned “[d]efinitions,” is a definitional provision, not a criminal prohibition. As relevant here, § 5845(b) defines the term “machinegun,” and § 5845(f) defines the term “destructive device.” These definitions do not create additional elements of the offenses charged under §§ 5861(d) and 922(o). Therefore, the government was not required to charge the applicable definition(s) in the indictment. See, e.g., Robbins, 476 F.2d at 30 (holding that an indictment under § 5861(d) need not refer to the definitions in § 5845 to “fairly notify a defendant of the charge against him”); United States v. Hoover, 635 F. Supp. 3d 1305, 1316 (M.D. Fla. 2022) (rejecting the argument that the government “was required to plead the specific facts supporting its contention that the [firearms] at issue fall within the definition of a machinegun”); cf. United States v. Pennington, 168 F.3d 1060, 1065 (8th Cir. 1999) (“The indictment’s failure to cite [18 U.S.C.] § 1346, a definitional provision, and to use its specific term, ‘honest’ services, does not mean no crime was charged.”).
And defendant's response, page 5:
> The question is whether the indictment “fully, directly, and expressly, without any uncertainty or ambiguity, set forth all the elements necessary to constitute the offence intended to be punished” and whether the indictment complied “with the necessity of alleging in the indictment all the facts necessary to bring the case” within the intent of the statute. United States v. Carll, 105 U.S. 611 (1881) (emphasis added). The government’s failure to give any specificity in the indictment cannot be remedied by wriggling as to whether the missing information can be considered an “element” or not. Even if the government were correct that the particular definition (or definitions) the prosecution is proceeding under does not change “elements,” it changes the “facts” underlying the scope of the statute.
I have no idea who is correct legally, and since oral arguments appear to have been held a few days ago I suppose I'll have to wait to see who is right.
The oral argument is here: https://www.ca4.uscourts.gov/OAarchive/mp3/23-4451-20250912....
The first question they asked is "why didn't you ask for a bill of particulars?".
Overall, they seemed very confused as to the argument made here - why is the indictment actually insufficient, and what words did you want them to use instead.
I don't think this will be a successful appeal at all - they seem to all agree this is not stuff that goes in an indictment, and to the degree that there was ambiguity, the correct answer was to request a bill of particulars.
At around 10 minutes, one of the judges asks counsel for the best case he has that says he's right, and he can't come up with one at all.
Which is probably the point at which he lost this appeal. :)
To be fair, i don't blame the lawyer, and i expect why the judges are being not too hard on him, is because he's doing his best to argue a losing case because of choices made at the district court level.
I think there is some slightly down-in-the-weeds confusion here - what does an indictment require vs ...
I think they screwed this up at trial and then tried to argue the indictment was insufficient, but i doubt they will get any appeals court to bite on this.
I posted it elsewhere, but you can listen to the oral argument of the appeal here:
https://www.ca4.uscourts.gov/OAarchive/mp3/23-4451-20250912....
It is a very accessible argument (in the sense of not need legal knowledge to usefully process it).
You can hear the judges sort of struggle to understand how this is an indicment opportunity, but really do seem to be trying to understand. They give counsel an opportunity to try to distinguish and explain things. Att around 10 minutes, one of the judges asks counsel for the bset case he has that says he's right, and he can't come up with one at all.
Which is probably the point at which he lost this appeal. :)
As i said elsehwere, i don't blame the lawyer - this seems like it woudl be a very hard case to win because of choices made at the level below. They are essentially arguing things they know will lose because nobody objected to things they should have at the level below.
What are you getting at?
If an appeals court says “wrong jurisdiction”, that’s an “rm -rf” on the whole entire case. There’s nothing left to argue about.
> What are you getting at?
> If an appeals court says “wrong jurisdiction”, that’s an “rm -rf” on the whole entire case. There’s nothing left to argue about.
I think your parent comment meant something like "the case wasn't overturned on the basis of deficiencies in the legal theory of the crime."
If the court had no jurisdiction, it is not possible for them to rule on "deficiencies in the legal theory of the crime" in that case.
Perhaps selfishly, I'd rather get out of a trial in the motion to dismiss stage, rather than having to very-expensively argue the merits all the way to the end.
Considering he was convicted in another jurisdiction, and they can retry him in the 'right' one, why wouldn't a reasonable person anticipate that might happen?
I don't think Weev is living in Ukraine/Transnistria to practice his Slavic languages.
And the reason why I brought up it was overturned, was because I knew someone would mention his case was vacated, and I wanted to make clear it wasn't vacated because there was something improper found about the legal question of the CFAA.
I think that the type of person that excels at software development would also excel at lawyering. But they should probably go to law school and pay attention in class.
The CFAA claim was never decided in HiQ. The chances of success on that claim did not look good and Microsoft settled
Even in 2014, 3rd Cir. COA seemed doubtful there was a valid CFAA claim
"5 We also note that in order to be guilty of accessing without authorization, or in excess of authorization under New Jersey law, the Government needed to prove that Auernheimer or Spitler circumvented a code- or password-based barrier to access. See State v. Riley, 988 A.2d 1252, 1267 (N.J. Super. Ct. Law Div. 2009). Although we need not resolve whether Auernheimers conduct involved such a breach, no evidence was advanced at trial that the account slurper ever breached any password gate or other code-based barrier. The account slurper simply accessed the publicly facing portion of the login screen and scraped information that AT&T unintentionally published."
https://web.archive.org/web/20140513205343if_/http://cdn.ars...
Shutting down the server (you solely maintained) before leaving would be "minor" to me... intentionally causing damage, earning money from that, getting caught, and again causing physical damage.. that's pretty "major" to me.
Warrants (in the US anyway) require reasonable belief that the crimes listed were committed.
They don't have to be right, mind you (after all, that's what trial is for), they just need reasonable belief.
They also can't recklessly disregard the truth (IE deliberately write lies they know are wrong).
Again, it's okay for them to be wrong about their belief. It's just not okay to know they are wrong and write it anyway.
Here, reading the warrant, etc, there is nothing obviously fraudulent here.
Perhaps it is, of course, but i read everything i could find and it's completely non-obvious which part of the warrant is supposed to be fraudulent.
Even the sort of retaliation claim made here is strange - Arresting you when you appear to actually hvae broken the law is generally only considered retaliation if (among other things) the enforcement of the law is uneven - IE targeted at you and nobody else.
Given the arrest was for a parole violation and they arrest parole violations like this all the time, ....
Like if you are at a traffic stop becuase you ran a red light, call a cop an asshole, and they arrest you because you have 50kg of cocaine bricks in your back seat, it's not retaliation.
Retaliation would be if you call a cop an asshole on facebook, and they come arrest you for violation of an 1825 law that hasn't been used against anyone in 200 years.
I was responding to the implication I keep seeing here that it's OK that he got arrested because he did bad things, regardless of how the arrest came about.