You are committing a crime right now
erratasec.blogspot.com
erratasec.blogspot.com
The opinion is not only compelling, it is a brilliant example of law at its best, for it shows how a wonderful legal mind wrestles with a knotty problem that can be summed up with the question, "Should courts apply a badly drafted piece of legislation to lead to the absurd result of criminalizing a whole host of minor misdeeds committed by individuals every day in using the web and their computers?" Judge Kozinski answered this question with a resounding "no."
He did so by applying the "rule of lenity," which requires "penal laws . . . to be construed strictly." (at p. 3872) "The rule of lenity not only ensures that citizens will have fair notice of the criminal laws, but also that Congress will have fair notice of what conduct its laws criminalize. We construe criminal statutes narrowly so that Congress will not unintentionally turn ordinary citizens into criminals." Applying this rule, he held as follows: "Therefore, we hold that 'exceeds authorized access' in the CFAA is limited to violations of restrictions on access to information, and not restrictions on its use." (emphasis in original)
In other words, though the CFAA is so badly worded that one might potentially give it an absurd and unconstitutional interpretation so as to criminalize things one would think shocking for Congress to have criminalized, the courts have the power to apply well-established rules of statutory construction so as to avoid such an absurdity. Here, the Ninth Circuit did so by construing the CFAA to criminalize violations of access restrictions (i.e., hacking) and not violations of use restrictions (terms of use on website and the like).
Now, there is a split in the federal circuits on this issue and it will either be resolved by an amendment to the statute or it will eventually find its way to the Supreme Court for resolution. But, even granting the split, the most extreme cases in which the CFAA has been applied criminally have involved things such as employees misappropriating trade secrets and other items that go far beyond innocuous things such as violating an employer's computer use policies by surfing the internet on company time.
In other words, no court has gone so far as to adopt anything close to the absurd outcomes suggested in this piece. Even the government in its arguments to Judge Kozinski strongly stated that it would never consider prosecuting such items as crimes. ("The government assures us that, whatever the scope of the CFAA, it won't prosecute minor violations. But we shouldn't have to live at the mercy of the local prosecutor." at p. 3870)
Thus, it is fit and proper to call out the alarmist tone of this piece as being wildly outside the mainstream of where the courts have gone with the CFAA and of where they are likely to go. Is it badly drafted legislation? Yes, it is a mess (if you want to lose your mind, try reading through the text of the statute here: http://www.law.cornell.edu/uscode/text/18/1030). Can it be interpreted to criminalize things that Congress might not have intended to criminalize? Yes, including acts by employees that, though wrongful, may not have been within the contemplation of Congress when it passed the statute. But, that said, is there a risk that the CFAA can be applied to criminalize our daily interaction with computers and the web? No, not unless normal, sound principles of law are wholly disregarded by the courts, which they won't be.
Rather than having knowable, deterministic laws we are all at the mercy of the lawyers and judges we happen to get that "day".
It's still probably the least bad system.
Why? Because you can't formalize away the fact that humans can't think of everything ahead of time. We make laws about your rights regarding messages you write on paper, then telegraphs and telephones and email come along. Either you try to interpret the law to cover them, or you revise your definitions of "messages" to include or exclude them.
In a "specify everything" system, everything that the courts currently interpret would have to be sent back to the legislature. The effect would depend on what you do with gray areas in court.
Option 1 would be "if a case is ambiguous, put it on hold until the legislature clarifies the law." That would clog up the courts and effectively merge the court and the legislature.
Option 2 would be "decide cases based strictly on existing law and let the legislature revise things for the next go round." That would create a lot of absurd outcomes, where a small loophole, with no ability to apply "common sense", means innocent people are convicted or guilty people are freed.
Like a group of elected officials who's only job is to close these loopholes without massive fanfare and a simple vote. A process that is incredibly fast and decisive in order to get double digits done per day.
Because, y'know, having officials crank through tons of difficult decisions per day is such a supremely effective[1] and corruption-free way to create a social process. It's worked so very well for the patent system, why not for law and jursiprudence?
[1] cf. "decision fatigue": https://www.nytimes.com/2011/08/21/magazine/do-you-suffer-fr...
Many things involve context (it is illegal to murder someone, but a killing in the context of self-defense is often not murder). Even where context is not explicitly recognized by the law, we want judgment and discretion to exist (speeding because you are drag racing is very different than speeding to a hospital with a bleeding passenger.)
So, you're saying that's more dystopian than the thought of secret laws for 'national security', on top of a body of laws that already spans over 200,000 pages, whereby even with non-poorly-written laws, you're still likely breaking one every single day?
Because that's what we have now. So if those are my options, then shit yes, I will take mathematical certainty of the legality of my actions any day.
I don't expect laws to be formally defined, I just expect them to be few, sensible, and transparent. Reasonable people shouldn't have a hard time inferring whether a specific activity is illegal.
Right now, our body of law is vast, complex, opaque and uncertain. Because of this, as I said above, most people likely break the law every single day. This gives rise to tyranny by selective enforcement (http://en.wikipedia.org/wiki/Selective_enforcement), burdened economies and reduced investments due to untested and protectionist regulatory regimes, and an overall reduction in freedom and civil liberties.
By contrast, yes, the knowability and certitude afforded by a hypothetical-but-impossible legal system based on mathematics would be preferable. This is really not a complicated idea.
“Corruptissima republica plurimae leges. [The more numerous the laws, the more corrupt the state.]” — Tacitus, the Annals ca. AD 69
So's our society. Roman law was quite a bit simpler, but justice in ancient Rome was extremely unpredictable.
By contrast, yes, the knowability and certitude afforded by a hypothetical-but-impossible legal system based on mathematics would be preferable. This is really not a complicated idea.
As HL Mencken said, 'For every complex problem there is an answer that is clear, simple, and wrong.' Godel's theorem tells us that in any sufficiently expressive formal system (such as mathematics), you can have consistency or completeness, but not both. A hypothetical mathematically-precise legal system would thus yield cases that either couldn't be judged because there was no prescription for such a situation (a div zero problem, if you will), or else would yield contradictory results on the same facts at different times.
People are emotional and subjective by their very nature. It is not possible to be objective - one can only tend towards objectivity by applying constant introspection and reassessing one's world view. Nonetheless, an Ape is not capable of being a Vulcan. It is, frankly, a travesty that people's fates are being decided by other people's stomachs.
I'd argue that you really can't say anything with such certainty. If true friendly AI is ever possible (and that is up in the air), such a system would be a better one. Obviously, this is all speculation.
In other words, by the time we have consistent laws (in the mathematical sense), "Precrime" could already exist.
I guess that one positive impact of your idea would be moving mathematicians into the almost celebrity status of lawyers. They'd be fun to watch when interviewed too.
Just to be clear, I'm not proposing to teach kids to be lawyers. Being a lawyer would be like having a PhD in mathematics. But we do teach kids basic calculus, algebra and stuff like that, so why not "basic legal stuff" (whatever it's called)?
New rule: (forall ?X (implies (and (isa ?X USCitizen) \
(locatedIn ?X UnitedStatesLegalJurisdiction)) (bearArms ?X)))
- Rule 2 added.
New rule: (thereExists ?X (isa ?X USCitizen) \
(locatedIn ?X UnitedStatesLegalJurisdiction))
- Rule 20 Added
New rule: (implies (and (locatedIn ?X ?Y) (isa ?Y USState)) \
(locatedIn ?X UnitedStatesLegalJurisdiction))
- Rule 21 Added
...
New rule: (isa California USState)
-Rule 1850-342 Added
...
New rule: >(forall ?Y (implies (locatedIn ?Y California) (not (bearArms ?Y)))
- Error: New Rule #4422 conflicts with Rule #2
Request Ruling:
(locatedIn JamieBriant224112344 California)
(bearArms JamieBriant22411234)
- Data is consistent.
The problem with our legal system is that it is expected that it is ambiguous. Those in power tell us that it is good for the law to be ambiguous. Yet what are the results: 1. You need a law degree to even practice - control.
2. The government can selectively prosecute - corruption.
3. Fear of losing, even when morally right.
4. Everyone is a criminal.> In other words, no court has gone so far as to adopt anything close to the absurd outcomes suggested in this piece.
Pardon me if I'm missing something here, but doesn't the post exactly say that that has what weev has been charged for?
> This is the issue behind the recent conviction of Andrew Auernheimer for “hacking” AT&T.
weev's actions are a gray area. I don't think that convicting him under the CFAA is absurd. It might be unreasonable or unconstitutional, but there's a valid security issue at stake. To liken weev's actions to viewing a deliberately published-for-public-consumption blog post is a false equivalence: and precisely what makes the piece alarmist.
He's saying that the courts can make distinctions between what Congress intended (to make it illegal to bypass computer security systems without permission), and what the law might technically forbid but what is completely normal and innocuous to do (like browsing someone's website without their explicit permission).
Now, is this something that I, with a bit of idle time, curl, and awk might have done on a lark - yup. Does it scare me that I then might have been found guilty of criminal behavior? Yes. Would I have done something like publish people's personal information on Gawker? Not anymore. Would I let AT&T know personally that they had a security hole? Probably not - likely to be the messenger that would get shot. Is the NET result of this that the bad guys, who keep quiet, and make use of this information for nefarios purposes now have free rein, because nobody will mention it to AT&T? Yes. Is the NET-EFFECT of this law a reduction in security and increased number of security exploitations? Yes. Should the Law be Fixed? Yes.
There are plenty of physical crimes that are easy to commit. For example, opening up someone's unlocked mailbox is technically a federal crime in the US (even if you don't take any thing and just put a leaflet there). Pointing out that a 'bad guy' could easily steal someone's mail by opening their mail box does not constitute security research.
Also: let's say someone accidentally exposes their password because it's on a post-it in the background of a photo. Clearly this is crappy security; clearly, at that point, information protected by that password is readily available until the password is changed.
The intent of the owner of the data does, in fact, count.
Sort of as if AT&T had chosen really bad, unchangeable default passwords for all their users.
The security on a ICCID is arguably better than any of these things. Unless it's transmitted in the clear? I don't know.
This is all silly.
Realistically, there isn't any legitimate reason for me to be doing this to AT&T's website anyways, other than idle juvenile curiosity (which I'll admit to having an abundance of).
I really don't see how. He used the exact same query that AT&T's own script used. The server did not break, or expose any unexpected behavior - in fact it worked exactly as AT&T designed and intended for it to work. I don't think you can pin any of this on weev when it's clearly AT&T who screwed up and provided all their customers' data for the asking.
Look, I'm not arguing that this should be criminal behavior, and it certainly doesn't merit a jail term. I can't tell you how many times I've done stuff exactly like this - probably in the hundreds of times. Is it hacking when I paid $15 for a 1 week pass and then used curl to download 11 gigabytes and 10+ years of the American Journnal of Clinical Nutrition? Probably. But, to give all due credit to the AJCN, they detected my repeated queries, and redirected me to a page that asked me to wait 30 seconds between each query when doing bulk downloads.
So, there is a case where I wasn't doing the obvious (downloading through the web interface), "hacking", if you will, but the AJCN was clearly fine with it, they just wanted me to ease up a bit, and instructed me how to do so in a friendly way.
If weev is guilty of anything, it was not realizing that posting high-profile individuals names onto gawker was probably a Really Bad Idea (TM).
I think the worst part about this is that it once again sends the message to companies that its OK to be this negligent. The law came in and fixed everything, the system works! Bad things were done, the bad people are in jail, full resolution.
I don't feel safer if every hacker ends up in jail. I feel safer when things are too hard to hack, or at the very least not brain dead easy to hack. This is very similar to Sony's response to repeated hackings of their customer's credit card numbers stored in plaintext: "We'll get those perpetrators!" instead of "oh we'll stop being ridiculously negligent now". The arguments of discouraging future hackers with harsh sentences don't work when 15 year olds are doing this all around the world. I want my information protected so that my money can't be stolen, not to receive retribution for it afterwards. If my bank left all the security boxes wide open for anyone to steal from, sure its still a crime to steal from them but I'd be much more pissed at the bank -- I pay them to keep that stuff safe!
I think we have too often come to accept crime followed by punishment as an ideal scenario, forgetting that sometimes there even exists the possibility of avoiding the initial crime in the first place.
Edit: To be clear, ICCID's are not private, they're printed on the outside of the SIM card.
In addition, there's a whole grey area which he highlights and you disregard just by trusting the courts, which doesn't prevent you from getting arrested and sued with all the financial and mental stress those things entail.
If you want better legislation, then you need to make sure the people writing it are well-educated in the areas you care about. This is the original purpose of lobbying.
The article's claim about the chilling effect was, of course, highly specific to the author's personal area of expertise. This is based on something I can't comment on: that the details of weev's case are generalizable to all cybersecurity researchers. I don't know the details of weev's case; do you think it's generalizable? My quick Google yielded me a Wired article that ended with weev laughing about how it might be illegal and the likely possibility it would damage a legitimate business's stock price. Is that a thing all cybersecurity researchers do?
I mean, I agree that the law sucks. That's fairly self-evident here. But what, exactly, do you guys want done about it? "Oh no, something bad happened 26 years ago and I just realized it because of something that happened recently" is weak. Talk to the EFF. Talk to your Congresscritters. Ask other people to do so. Sound and fury signify nothing. If you feel so terribly chilled, explain it to the politicians and get some lawyers working on the problem. I'd suggest civil disobedience, but you probably don't have the courage to get arrested if you're busy being chilled.
Yes, it sucks to be a case study. Cancer patients go through it all the time: the result? LESS CANCER. That's what the courts are also for. You go up there and say, "My situation shows how this law is stupid." You take a beating as all the relevant details are dragged out and scrutinized so that they can be sure. And hopefully, they agree with you and set precedent that the law is, in fact, stupid and fewer people have to deal with it in the future.
I'm not personally scared, but I understand what the problems with this kind of laws (bad, vague ones) are. The problems almost disappear when everything works as expected.
The real problem which you ignore is that laws of this sort give the authorities a big loophole for abuse (which probably is not what has happened to weev, but that's not what I'm discussing.) If you think that's not a worry, I envy your worldview.
That said, I fully agree that more formal action should be taken, contacting EFF and congressmen and whatnot. But writing about it can motivate people who were not in the know to act, it's not just empty "sound and fury."
I recommend this book that's somewhat related to this problem: http://www.amazon.com/Nothing-Hide-Tradeoff-between-Security...
Let me know how that works out if you get dragged into a patent lawsuit in East Texas. :-)
Having such a law on the books means that a boss, computer service provider, etc. could show a laymen this law, even let them look up the law themselves and then threaten to have someone prosecuted for things which may be proper (or at least not illegal). The person being threatened would be able to verify that the law was real and without having a lawyer to explain the full situation may feel they are in a very bad bargaining position for whatever demands the other side makes.
As the court said, "We shouldn't have to live at the mercy of the local prosecutor" but neither should people without lawyers have to live at the mercy of those who could use such a law to threaten prosecution for negotiating purposes.
When they have a law that seems on first reading to say what the employer says it does, then the employer can show it to the employee to gain credence and the law itself will confuse any employee who does a little research without going further.
More than that, the employer may not realize they are misrepresenting it when the law seems to say something. They may be misusing the law in good faith. Something that will happen less often with clearly written laws that are not heavily interpreted in the common law.
http://www.technologyreview.com/view/507661/jail-looms-for-m...
Legal uncertainty is not something that any company would prefer to endure.
http://www.justice.gov/criminal/cybercrime/docs/ccmanual.pdf
Essentially, anything you do exceeding authorization to a computer connected to the internet is potentially a U.S. federal crime. Anywhere in the world. No fraud need be proved. For example, here are the elements of a crime under 1030(a)(2):
1030(a)(2) Summary (Misd.) 1. Intentionally access a computer 2. without or in excess of authorization 3. obtain information 4. from financial records of financial institution or consumer reporting agency OR the U.S. government OR a protected computer
So if the government can prove these things: you intentionally accessed a computer; without or in excess of authorization; obtained any information at all; and it was a computer connected to the internet, then they have successfully proved that you violated 1030(a)(2). Numerous whistleblowers have been charged with violating this law, including Bradley Manning; at least one "cyberbullying" case has been charged under it, etc.
NO FRAUD IS REQUIRED. You can shouldersurf someone's password, log in as them, type "ls", log out and never use that password again - you've violated that law.
Every person working with computers in the U.S. or anywhere the U.S. can reach with its laws should have this engraved along the top of their keyboard.
What is it with Hacker News lately? I've never whined about the quality of community before, but this trend is beginning to worry me.
Further bellow you can see someone else saying that your arguments are "bullshit". Then there was this submission the other day stating that "Stephen Elop is so full of shit". Not even "full of it" -- no, it's like that "Madagascar" quote: "Well, of course we're going to throw poo at him!"
I often state my position quite bluntly when I disagree with someone, but personal insults are a different story. (Not that I haven't made that mistake ever, but you make a mistake and you learn from it.)
Honestly, I don't know what I might achieve by writing this, but there's a small part of me that harbors hope that things might change. It doesn't hurt anyone to maintain a modicum of civility, people.
Not to make it about me; I'm just saying, there are message board pathologies that are as annoying as "knucklehead" but not as obvious, so let's not single them out.
Normally I would go and dig up a bunch of supporting material to justify this assertion, but your blanket assertions and dismissal of other posters as 'knuckleheads' tells me that it's simply not worth the effort. Flagged.
I am not disagreeing with you, but in your example, wouldn't the part I have emphasised technically be fraud in some letter of the law way, because you have represented yourself as them to the computer?
It's quite possible to violate 1030(a)(2) without any deception and without any financial or personal gain.
I agree, you should stop embarrassing yourself. Multiple lawyers, including practitioners in this field, are discussing in depth why you are completely wrong. Fraud, it should be noted, is only one of the possible violations--there are others. But tptacek's point was that the intent to commit one of these violations is necessary (and that specific intent determines which charges apply. As you can clearly see from the statute, intent is an element for every one of these charges http://www.law.cornell.edu/uscode/text/18/1030.
You can shouldersurf someone's password, log in as them, type "ls", log out and never use that password again - you've violated that law. That's not fraud. That's accessing a protected system, which is a separate charge. It's a problem if you don't have permission, express or implicit, for that access.
No, to be clear, tptacek is saying that fraud is necessary for any conviction under 1030(a). That's false. You're saying that intent to commit a crime is necessary for any conviction under 1030(a). That's false too.
It's you and tptacek vs. the DOJ's cybercrimes manual. Good luck!
The core of your argument is that Rob is right that there's a chargeable offense happening when you read his blog, because the 1030(a) statute is so vague. That's just not true. There's specific precedent for why it's not true.
If you want to refine your argument to say that 1030(a)(2) (plain unauthorized access) and 1030(e)(2)(b) ("protected computer") are unconscionably vague and leave too many people exposed to frivolous prosecution, we agree, modulo that I think we diverge on the fact that nobody's going to be convicted in those prosecutions without an allegation of fraud to accompany it.
Yes, it makes legal citations, but so do the US PTO guidelines. It's like reading one of the briefs for a supreme court case and declaring that's what the law is.
Like any legal brief, it's just a glorified policy position with legal citations instead of study citations.
If you want to know what you may get arrested for, sure, it's great. If you want to know what you may get convicted of, it's near worthless.
The first one would be very hard to solve anyway. Most laws don't specifically prevent arrest for minor violations, and at least right now, you can almost never prevent the police from arresting you for something (in most cases, they don't actually have to tell you why they are arresting you, only that you are being arrested. They can charge you with something different than they tell you anyway).
Does that constitute intent?
If I am unconscious, and someone lifts my hand up and uses my fingers to type in a password, I didn't have intent to access a computer - I am not guilty of a crime. But if I intentionally struck keys on my keyboard, knowing that I was striking keys on my keyboard - that's intent. I do NOT have to know that it's a crime or intend to commit a crime.
Some crimes do have specific intent elements, where the person must be proved to have intended some specific result. This isn't one of them.
Jesus, Rob. You know this isn't true. Under the CFAA, you can't simply declare your blog "off limits" and then press charges. I have to access the site with the intent to commit fraud. And my access to your site has to further that fraud.
For the most part he CAN declare his blog off limits and press charges. Except that Federal prosecutor has to decide to press charges, not the individual.
Note tptacek: you should understand there are several different sorts of crimes criminalized by this statute, and fraud is only one of them, and for the other ones, no fraud is required to have occurred. Read carefully.
The law is here: http://www.law.cornell.edu/uscode/text/18/1030
EFF's analysis of the law is here: http://ilt.eff.org/index.php/Computer_Fraud_and_Abuse_Act_(C...
The Ninth Circuit's model jury instructions are here: http://www3.ce9.uscourts.gov/web/sdocuments.nsf/0/71dd91317b...
Read the government manual:
http://www.justice.gov/criminal/cybercrime/docs/ccmanual.pdf
You're filling this whole thread with disinformation. Stop it.
You can feel free to point to the part of the DOJ manual that rebuts me, too.
1030(a)(2)(C) Whoever intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains information from any protected computer; shall be punished as provided in subsection (c) of this section.
Under the statute, a "protected computer" generally means any computer connected to the internet.
Also, based on the legislative history, "obtains information" has been read to mean "merely observing" information.
The only issue is "without authorization." Based on its plain meaning, the law could mean that you need affirmative authorization to access any website.
Obviously, that's a real stretch, but there was a case decided by the 1st Circuit Court of Appeals [1] that held a company liable for using a web scraper - where the court said the defendants exceeded authorized access based on the website's boilerplate copyright notice.
[1]http://openjurist.org/274/f3d/577/ef-cultural-travel-bv-v-ex...
http://en.wikipedia.org/wiki/Reasonable_person
You can't parse sentences out of context and apply programmer logic to them, that's not how laws work.
It's true that Judge Kozinski in the 9th Circuit said he would not "apply a badly drafted piece of legislation to lead to [an] absurd result."
But the issue is not cut and dry.
Kozinski essentially acknowledged he was interpreting the statute in a manner possibly at odds with its very language. These courts get reversed all the time (over 70% of their cases) - and other circuits have read the law more narrowly.
And the government itself supports a narrow reading of the law.
OP's article is over the top. My point is, the "authorization" part of the law appears extremely broad and as the DOJ puts it: "the case law on this issue is muddy."
As for common law:
http://en.wikipedia.org/wiki/Common_law
I am still not a lawyer.
Common law is judge-made and only governs in the absence of statutory authority. (Due process and trial by jury are constitutional laws). The reasonable man is primarily a negligence standard.
http://online.wsj.com/article/SB1000142405311190406060457657...
obviously includes formal language that means something i don't understand.
Deleted comment
Cybercrime: A Sketch of 18 U.S.C. 1030 and Related Federal Criminal Laws[1]
It was written by the Congressional Research Service and is well suited for non-lawyers. It is all of 9 pages including cover material and is the tl;dr version of the 97 page:
Cybercrime: An Overview of the Federal Computer Fraud and Abuse Statute and Related Federal Criminal Laws[2]
You can't just focus on statute and ignore precedent, because precedent defines the standards for statutory interpretation. So many people on HN look at the statute and think that's the whole law, and then assume that any arguable interpretation of said statute is legally binding. This is absolutely not the case.
Edit: Actually, the EFF page that tptacek linked to earlier mentions the US vs Drew case, where they charged that a person was "unauthorized" simply by being in violation of the MySpace terms of service, but the court instead ruled that they were not unauthorized because the law itself was too vague ("the absence of minimal guidelines to govern law enforcement"), and because the terms of service weren't prominent enough.
On the other hand, violating any sort of unambiguous access restriction is clearly illegal. Suppose you start work at a new job. The boss tells you not to read the files in the "BOSS" directory on the webserver, which is connected to the internet and not password protected. You read them. Have you committed a Federal misdemeanor? Yes. No court disagrees. Many people have been convicted and sentenced to prison terms for extremely similar behavior (often involving employees who take files with them when they leave employment, or similar).
The Wikipedia article about web scraping [1] is quite interesting though very much just a start; it becomes pretty complex when you look at some older rulings such as Feist v. Rural [2] or (especially) Dastar v. Twentieth Century Fox Film Corp. [3].
Then you start thinking about how some of the more recent "click-wrap" agreements play into things... To me they seem unrealistic and/or unenforceable, but it even more complicated when you factor in that the 'protected contents' might be public domain or otherwise potentially preempted by copyright, etc...
It's definitely an evolving area of law. And an area of law that I really enjoy as a 'hacker'. I just hope for continually positive legal evolution...
1 - http://en.wikipedia.org/wiki/Web_scraping
2 - http://en.wikipedia.org/wiki/Feist_v._Rural
3 - http://en.wikipedia.org/wiki/Dastar_Corp._v._Twentieth_Centu....
The additional crimes chargeable under the CFAA are:
* Access to state secrets
* Access to financial records or to "protected systems"
* Access to government computers
* Attempts to intentionally cause damage
* Attempts to commit extortion using the access
None of these apply to blogs.
> In the general case, the government must prove beyond a reasonable doubt that the unauthorized access to the computer system was in furtherance of an actual fraud that produced something of value for the accused.
That is 100% false, and I'm calling you out as having simply made it up. Fraud is NOT required, take a look at 1030, we can quite clearly read:
"Whoever - (2) intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains (C) information from any protected computer, shall be punished as provided in subsection (c) of this section"
It's there in black and white.
Nobody is making anything up. On either side of the argument.
I seriously don't care about the fine point we're hung up on here. 1030(a)(2) is a bad rule, at least until we fix the definition of "protected computer". There's no underlying political disagreement about whether the statute reads as reasonable, even though in practice it does not mean the thing Rob thinks it means.
My only investment in this debate is that it's clear that most people on HN think that the unreasonable part of CFAA is how they determine "unauthorized access", and that incrementing a number in a URL to harvest information should be fair game. There, I care a lot. People skilled in the art can make a convincing argument for lots of vulnerabilities being so trivial they can't reasonably constitute unauthorized access. That's not how the law works and it's not how the law should work. When Rob says that the problem with the law we have is that it's too easy to make a case that access is unauthorized, Rob is wrong. He's wrong in the specifics: you won't be charged and couldn't be convicted for reading his blog. He's also wrong in principle: the problem with the CFAA, such as it is, isn't that it's too easy to make "unauthorized access".
That said, I'm curious which specific case you're referring to in your first paragraph - and which court it was in.
I've done a fair amount of research into this type of case law and, from what I've seen, it seems like things have gone both ways in various different courts. As far as I know there is no binding precedent, at least not from a higher court, but I'd love to be wrong on this.
Seeing as this comment may end up lost within this thread, feel free to shoot me an email directly (available on my profile).
> I seriously don't care about the fine point we're hung up on here.
... and that's why you're getting your facts wrong.
Did you read the post? That's not the case, which is exactly the problem. If you access a web site that is publicly available, not behind any login system, but happen to embarrass a large company by doing so (like they mistakenly made it public) then you go to jail. That's why it's so unbelievably stupid and has to be fixed, hence his post.
<i>"intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains ... information from any protected computer"</i>
It doesn't say "intent to commit fraud" or even "intent to obtain information". It just says "intent to unauthorized access". Negligence and recklessness count as intent, so accessing a computer without caring whether you had authorization or not is still "intent".
When the CFAA was written in 1986, all access to computers was explicitly authorized. Then the web happened, when people started recklessly accessing computers without caring whether they were authorized, and everyone was in technical violation of the law.
This article is an uninformed rant spreading FUD in the pursuit of a personal goal and it doesn't deserve the attention it is receiving any more than the garbage legal scaremongering for which SCO was notorious.
Also it's "proof of concept" fails to identify screen resolution so not only is the author a failure at reading the law but also at writing working code.
A member of the public can enter and look around the area that is obviously designated as public. There are areas in the restraunt that is marked "staff only" - some may have locks, some may not. But anyone who is not a staff entering those areas (whether they broke the lock, or just opened the door coz it was unlocked) is trespassing.
Now, imagine a website in the above scenario. If the administration area of the website is "unlocked" and a user "stumbled" into it, is it still a crime?
See, the problem with laws like CFAA is that they are based on the premise that there is "nothing" a bank could do to prevent hackers from accessing their computers without permission. At no point did anyone stop to say, "Maybe computers that process billions of dollars in transactions every day should not be plugged into the public phone network or Internet until we have some good reason to think those computers cannot be manipulated by hackers;" instead, the thinking was, "Hackers are evil wizards, nobody could possibly protect themselves from hackers, so we should make a law that allows us to throw the evil wizards in prison!" The idea that AT&T should be blamed for leaving customer data out in the open like that is not even on the table (strangely, if AT&T left a binder full of personal information unattended on a table in a public park, and labeled the binder "DO NOT OPEN," they would probably be the target of a successful lawsuit).
I see lots of IRC conversations about things the defendants, Auernheimer and Spitler, could do with the email addresses they were getting... but no concrete plans to actually do those things. Yes, the downloading of the addresses itself was an overt act, but I see no overt act alleged that specifically reveals fraudulent intent or acts in furtherance of a plan to commit fraud. The only overt acts alleged, other than the downloading itself, were (1) they sent some email messages to some of the victims, and (2) they gave all the email addresses to Gawker. I see nothing in here alleging concrete steps toward extorting the victims, or stealing their bank accounts, or deceiving them in any way, or indeed anything by which they would actually profit. Again, they discussed various possibilities, but I see no evidence here that they actually undertook any of them.
I'm sure it didn't help their case that they figured that what they were doing was illegal or at least tortious, and that they attempted to destroy evidence.
But the crux of your response to Rob is that they had the intent to commit fraud, and frankly, reading this indictment, I still don't see any evidence of that beyond some IRC banter.
There's also, seems to me, an odd circularity to the government's argument. They're alleging conspiracy, and among the overt acts that demonstrate this alleged conspiracy, they include the scraping of the email addresses. But the crime that that overt act is supposedly in furtherance of is... conspiracy. Seems to me this recursion is missing a base case :-)
Count 2 of the indictment has a slightly different thrust. Even though it's titled "Fraud in connection with personal information", it references USC 18 § 1028 (a) (7), which says: "Whoever ... knowingly transfers, possesses, or uses, without lawful authority, a means of identification of another person with the intent to commit, or to aid or abet, or in connection with, any unlawful activity that constitutes a violation of Federal law, or that constitutes a felony under any applicable State or local law [shall be punished, etc.]." What they seem to be saying here is that the ICC-IDs themselves count as a "means of identification" and that the fraud consisted simply of using said IDs to access the AT&T accounts. But this is also circular. The "unlawful activity" is the violation of the CFAA itself. The demonstration that the CFAA was violated rests on the assertion that it was violated.
If this indictment reflects the strongest arguments the prosecution has, I must respectfully disagree with this jury.
No, the crux of his response is that the government alleged fraud, and so using the case to claim that just accessing a site is a federal crime is at best hyperbole. Whether or not the allegation of intent to commit fraud is accurate or not is not relevant fo that argument.
I think one thing that is happening here is that we're getting our wires crossed between Rob's post, which says you've committed a crime by reading his blog but that's OK because he committed a crime by sending you Javascript and that post is simply incorrect, and the Auernheimer case from yesterday which is not nearly as cut and dry.
Rob is wrong. But even I think the Auernheimer result is shady; I think "unauthorized access" should be cut and dry (if you know you're not supposed to do something with someone else's computer system and you do it anyways, that's unauthorized access), but the conspiracy charge is shady, the allegation of fraud is extremely shady (they were spitballing about the impact of what they found, not planning an elaborate fraud), and using 1030(a)(2) + conspiracy to avoid confronting those issues is also shady.
Sometimes judges and juries screw up -- maliciously, or otherwise. Most of the time they don't. It sucks, but it's the best system we've got.
That's not to say that the legislators shouldn't try to make laws clear and unambiguous, but they have a lot on their plates and patching a hole in a 1986 legislation that doesn't seem to actually harm anyone isn't high on their priority list.
I'm coming to grips with the idea that law is mostly empirical and can only be falsified. Which means that, by design, you can't know if you are following the law or not.
You can almost think of the law just like you would a complex codebase. Unfortunately, we live in an age where the law has become so complex the average person can't keep it straight. I seriously doubt that this would change no matter how the law were refactored. The good news is that we do have a society where a concerned citizen can learn a lot about the law on their own. Thus, I would argue that the law is complex, but easy to approach if you want to become an expert on a particular module or subsystem.
I've always wished there could be some kind of government agency you could go to, where you would lay out exactly what you would like to do, and they will explicitly decide in advance, and it would even set judicial precedent. Maybe you would have to pay the fees for lawyers on both sides and judge (so it wouldn't be cheap) no matter what the outcome, but if your actions were found to be legal in advance, then that would be binding, and there would be zero risk to your actions.
The flipside to this is that there is so much information that people don't know that their questions have already been answered.
No, it's not that this isn't what the law means. It's that this isn't what the law says. There are vague laws, and there are ambiguous laws, but you are way overstating your case here. Either that, or you have never read § 1030.
The defendant is charged in [Count _______ of] the indictment with
computer fraud in violation of Section 1030(a)(4) of Title 18 of the
United States Code. In order for the defendant to be found guilty of
that charge, *the government must prove each of the following elements*
beyond a reasonable doubt:
First, the defendant knowingly [accessed without authorization]
[exceeded authorized access to] a computer [that was exclusively for
the use of a financial institution or the United States government]
[that was not exclusively for the use of a financial institution or
the United States government, but the defendant’s access affected the
computer’s use by or for the financial institution or the United
States government] [used in or affecting interstate or foreign
commerce or communication] [located outside the United States but
using it in a manner that affected interstate or foreign commerce or
communication of the United States];
Second, the defendant did so with the intent to defraud;
Third, by [accessing the computer without authorization] [exceeding
authorized access to the computer], the defendant furthered the
intended fraud; [and]
Fourth, the defendant by [accessing the computer without
authorization] [exceeding authorized access to the computer] obtained
anything of value[.] [; and]
[Fifth, the total value of the defendant’s computer use exceeded
$5,000 during [specify applicable period.]
The last clause applies when the object of the fraud is access to the computer itself; for instance, if your fraud was "gain free wireless access".The defendant could also have been charged - in some other case - with 1030(a)(2), which is obtaining information from any protected computer without access. In that case, the government would not have to prove fraud.
Furthermore, regardless of whether the prosecution charges a crime that requires intent to commit fraud --- for instance, in the unlikely event that they tried to spin a yarn about a blog affecting interstate commerce --- CFAA crimes aren't strict liability. They must prove intent to exceed authorization.
http://en.wikipedia.org/wiki/Wickard_v._Filburn and subsequent cases: producing a product on your own, and thereby not engaging in commerce, is considered commerce.
(Also, this year's PPACA ruling detoothed the commerce clause's power. How much it did that is to be determined.)
That is flatly and totally wrong. Any computer connected to the internet is a "protected computer" for the purposes of this statute: full stop, end of story. Additionally, some computers not connected to the internet are protected computers.
It's possible that a blog on an intranet machine that is absolutely not accessible to the outside world could be argued not to be a "protected computer". Any blog routable from the outside world absolutely is.
Every blog in the world accessible from the internet is in fact being run on a "protected computer". Accessing any of these machines without authorization or exceeding authorization can in fact be charged as a federal misdemeanor.
This is not arguable. It's exactly what the statute says, it's exactly what the DOJ says, it's exactly what every court to consider the issue has said.
For example, here's a direct quote from one case: "the latter two elements of the section 1030(a)(2)(C) crime [obtaining information from a protected computer] will always be met when an individual using a computer contacts or communicates with an Internet website".
Note the word ALWAYS. All that remains to be proven is that you weren't drunk or otherwise not in control of your faculties, and that you did it without authorization or exceeding authorization.
People take issue with me calling you a knucklehead. But you are making statements that anyone with a cursory knowledge of the law would know to be false, and you are making them repeatedly and refusing to educate yourself about it or to investigate in any way or to consider the possibility that you might be wrong.
His blog seems to be used in foreign communication, it can be accessed from foreign countries. Does that make it a "protected computer"? I accessed his computer and received information. And I was never "authorized" to do so, except through the implied openness of the web, which the law doesn't seem to mention at all.
"Protected computer" is explicitly defined.
This is what we have courts and an executive branch for: the law can really only provide broad guidelines. It's up to the other branches to apply these principles in practice.
[1] http://boingboing.net/2005/01/27/jailed-for-using-a-n.html
EDIT: Obligatory shout out for https://postcongress.io/
Like Al Capone for Tax. Cant get someone for real hacking, so these vague laws help along the way?
But this post made me less supportive of your cause not more.
You wont improve the standing of your argument in this manner. You'll only make regular people think you're crazy.
This is a GOOD thing. The whole point is, there's no clear line between reasonable access and hacking. It's something which the courts have to figure out.
The Common Law is largely based on common sense, and precedent; and precedent is based on a previous judge's common sense. The three big rules for interpreting laws are the plain meaning rule (use the literal meaning), the "golden rule" (ignore the plain meaning rule if it's obviously stupid), and the mischief rule (figure out what mischief the lawmakers were trying to prevent).
A vaguely written law lets judges use their common sense. While I'm sure there'll be people who disagree with their interpretations, it's either that or black and white statues which simply won't work.
Surely it's entirely within Google's gift.
http://www.google.com/intl/en/policies/terms/
That said, I can't actually see where they authorise access, only that they tell us not to misuse. Though they do give an example: "don’t interfere with our Services or try to access them using a method other than the interface and the instructions that we provide." which might imply that accessing them through the provided interface, and not interfering is OK.
True. This is how a Common Law system works, and why rants about 'activist judges' who 'legislate from the bench' are so idiotic in (most parts of) the USA: That's a pretty fair description of how Common Law works.
The legislature writes laws knowing that they can't possibly think of every possible fact pattern, every possible scenario the law might be applied to, and the legislators expect judges to apply their judgement to apply the law, clarifying it in the process. They are active because the law was written to be applied by humans, and they legislate to the extent they effectively add interpretations and nuance to the statute law.
(The only part of the USA not under Common Law is Louisiana, which inherited its Civil Law system from France, which inherited it from Rome. AFAIK, the entire United Kingdom is under Common Law; the UK is, after all, where the majority of the USA got the Common Law from.)
Because all, or nearly all, such rants are idiotic when you know how Common Law works.
That is know, but the arguing here is that the current legislation is way too vague. Is like a law saying: "Is illegal to be evil"; is haves a very subjective definition to have real-world implications and can be abused easily.
Also, this is placed on a well known public blog, also submitted to search engines and other public catalogues, means that nobody in his sane mind would consider this a private place not intended for public visitors.
It is also a common practice, accepted by vast majority of users, that sites run Javascript in user's browser, and that some data - such as cookies, display resolution, etc. - is available to these scripts. If the site took some liberties outside of accepted practices common for Internet browsing - such as using a hole in the browser to read documents on my hard disk that I did not specifically upload to the site - then yes, the site author would be liable. But to scare me into believing what author intends me to believe, he better would find any court insane enough to interpret it this way.
Ha, ha, ha. My anti-JavaScript firewall has steadfastly deflected this individual's malicious attacks!
as noted elsewhere in comments in an article about the event he laughed that what he was doing was probably illegal, suggesting knowledge of a likely crime.
i'm no fan of an absurd application of laws, but there have got to be better poster children for this sort of thing.
The government may well have been counting on weev's reputation to work against him here. If your goal is to set a precedent that allows "unauthorized access" to be defined after the fact, you want a defendant people won't stand up for. It's much easier to turn bad law into bad case law when people don't fight back.
Order allow,deny
Allow from all
in a config file somewhere.Deleted comment
http://apple.stackexchange.com/questions/59283/why-is-a-reti...
tptacek's post (http://news.ycombinator.com/item?id=4812735, '[located outside the United States but using it in a manner that affected interstate or foreign commerce or communication of the United States];') and other info on the statute appears to show that the law is extended to those that cause detriment to US trade from anywhere.