Jesus, Rob. You know this isn't true. Under the CFAA, you can't simply declare your blog "off limits" and then press charges. I have to access the site with the intent to commit fraud. And my access to your site has to further that fraud.
Jesus, Rob. You know this isn't true. Under the CFAA, you can't simply declare your blog "off limits" and then press charges. I have to access the site with the intent to commit fraud. And my access to your site has to further that fraud.
For the most part he CAN declare his blog off limits and press charges. Except that Federal prosecutor has to decide to press charges, not the individual.
Note tptacek: you should understand there are several different sorts of crimes criminalized by this statute, and fraud is only one of them, and for the other ones, no fraud is required to have occurred. Read carefully.
The law is here: http://www.law.cornell.edu/uscode/text/18/1030
EFF's analysis of the law is here: http://ilt.eff.org/index.php/Computer_Fraud_and_Abuse_Act_(C...
The Ninth Circuit's model jury instructions are here: http://www3.ce9.uscourts.gov/web/sdocuments.nsf/0/71dd91317b...
Read the government manual:
http://www.justice.gov/criminal/cybercrime/docs/ccmanual.pdf
You're filling this whole thread with disinformation. Stop it.
You can feel free to point to the part of the DOJ manual that rebuts me, too.
obviously includes formal language that means something i don't understand.
1030(a)(2)(C) Whoever intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains information from any protected computer; shall be punished as provided in subsection (c) of this section.
Under the statute, a "protected computer" generally means any computer connected to the internet.
Also, based on the legislative history, "obtains information" has been read to mean "merely observing" information.
The only issue is "without authorization." Based on its plain meaning, the law could mean that you need affirmative authorization to access any website.
Obviously, that's a real stretch, but there was a case decided by the 1st Circuit Court of Appeals [1] that held a company liable for using a web scraper - where the court said the defendants exceeded authorized access based on the website's boilerplate copyright notice.
[1]http://openjurist.org/274/f3d/577/ef-cultural-travel-bv-v-ex...
http://en.wikipedia.org/wiki/Reasonable_person
You can't parse sentences out of context and apply programmer logic to them, that's not how laws work.
It's true that Judge Kozinski in the 9th Circuit said he would not "apply a badly drafted piece of legislation to lead to [an] absurd result."
But the issue is not cut and dry.
Kozinski essentially acknowledged he was interpreting the statute in a manner possibly at odds with its very language. These courts get reversed all the time (over 70% of their cases) - and other circuits have read the law more narrowly.
And the government itself supports a narrow reading of the law.
OP's article is over the top. My point is, the "authorization" part of the law appears extremely broad and as the DOJ puts it: "the case law on this issue is muddy."
As for common law:
http://en.wikipedia.org/wiki/Common_law
I am still not a lawyer.
Common law is judge-made and only governs in the absence of statutory authority. (Due process and trial by jury are constitutional laws). The reasonable man is primarily a negligence standard.
http://online.wsj.com/article/SB1000142405311190406060457657...
Cybercrime: A Sketch of 18 U.S.C. 1030 and Related Federal Criminal Laws[1]
It was written by the Congressional Research Service and is well suited for non-lawyers. It is all of 9 pages including cover material and is the tl;dr version of the 97 page:
Cybercrime: An Overview of the Federal Computer Fraud and Abuse Statute and Related Federal Criminal Laws[2]
You can't just focus on statute and ignore precedent, because precedent defines the standards for statutory interpretation. So many people on HN look at the statute and think that's the whole law, and then assume that any arguable interpretation of said statute is legally binding. This is absolutely not the case.
Edit: Actually, the EFF page that tptacek linked to earlier mentions the US vs Drew case, where they charged that a person was "unauthorized" simply by being in violation of the MySpace terms of service, but the court instead ruled that they were not unauthorized because the law itself was too vague ("the absence of minimal guidelines to govern law enforcement"), and because the terms of service weren't prominent enough.
On the other hand, violating any sort of unambiguous access restriction is clearly illegal. Suppose you start work at a new job. The boss tells you not to read the files in the "BOSS" directory on the webserver, which is connected to the internet and not password protected. You read them. Have you committed a Federal misdemeanor? Yes. No court disagrees. Many people have been convicted and sentenced to prison terms for extremely similar behavior (often involving employees who take files with them when they leave employment, or similar).
The Wikipedia article about web scraping [1] is quite interesting though very much just a start; it becomes pretty complex when you look at some older rulings such as Feist v. Rural [2] or (especially) Dastar v. Twentieth Century Fox Film Corp. [3].
Then you start thinking about how some of the more recent "click-wrap" agreements play into things... To me they seem unrealistic and/or unenforceable, but it even more complicated when you factor in that the 'protected contents' might be public domain or otherwise potentially preempted by copyright, etc...
It's definitely an evolving area of law. And an area of law that I really enjoy as a 'hacker'. I just hope for continually positive legal evolution...
1 - http://en.wikipedia.org/wiki/Web_scraping
2 - http://en.wikipedia.org/wiki/Feist_v._Rural
3 - http://en.wikipedia.org/wiki/Dastar_Corp._v._Twentieth_Centu....
The additional crimes chargeable under the CFAA are:
* Access to state secrets
* Access to financial records or to "protected systems"
* Access to government computers
* Attempts to intentionally cause damage
* Attempts to commit extortion using the access
None of these apply to blogs.
> In the general case, the government must prove beyond a reasonable doubt that the unauthorized access to the computer system was in furtherance of an actual fraud that produced something of value for the accused.
That is 100% false, and I'm calling you out as having simply made it up. Fraud is NOT required, take a look at 1030, we can quite clearly read:
"Whoever - (2) intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains (C) information from any protected computer, shall be punished as provided in subsection (c) of this section"
It's there in black and white.
Nobody is making anything up. On either side of the argument.
I seriously don't care about the fine point we're hung up on here. 1030(a)(2) is a bad rule, at least until we fix the definition of "protected computer". There's no underlying political disagreement about whether the statute reads as reasonable, even though in practice it does not mean the thing Rob thinks it means.
My only investment in this debate is that it's clear that most people on HN think that the unreasonable part of CFAA is how they determine "unauthorized access", and that incrementing a number in a URL to harvest information should be fair game. There, I care a lot. People skilled in the art can make a convincing argument for lots of vulnerabilities being so trivial they can't reasonably constitute unauthorized access. That's not how the law works and it's not how the law should work. When Rob says that the problem with the law we have is that it's too easy to make a case that access is unauthorized, Rob is wrong. He's wrong in the specifics: you won't be charged and couldn't be convicted for reading his blog. He's also wrong in principle: the problem with the CFAA, such as it is, isn't that it's too easy to make "unauthorized access".
That said, I'm curious which specific case you're referring to in your first paragraph - and which court it was in.
I've done a fair amount of research into this type of case law and, from what I've seen, it seems like things have gone both ways in various different courts. As far as I know there is no binding precedent, at least not from a higher court, but I'd love to be wrong on this.
Seeing as this comment may end up lost within this thread, feel free to shoot me an email directly (available on my profile).
> I seriously don't care about the fine point we're hung up on here.
... and that's why you're getting your facts wrong.
Did you read the post? That's not the case, which is exactly the problem. If you access a web site that is publicly available, not behind any login system, but happen to embarrass a large company by doing so (like they mistakenly made it public) then you go to jail. That's why it's so unbelievably stupid and has to be fixed, hence his post.
<i>"intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains ... information from any protected computer"</i>
It doesn't say "intent to commit fraud" or even "intent to obtain information". It just says "intent to unauthorized access". Negligence and recklessness count as intent, so accessing a computer without caring whether you had authorization or not is still "intent".
When the CFAA was written in 1986, all access to computers was explicitly authorized. Then the web happened, when people started recklessly accessing computers without caring whether they were authorized, and everyone was in technical violation of the law.
A member of the public can enter and look around the area that is obviously designated as public. There are areas in the restraunt that is marked "staff only" - some may have locks, some may not. But anyone who is not a staff entering those areas (whether they broke the lock, or just opened the door coz it was unlocked) is trespassing.
Now, imagine a website in the above scenario. If the administration area of the website is "unlocked" and a user "stumbled" into it, is it still a crime?
See, the problem with laws like CFAA is that they are based on the premise that there is "nothing" a bank could do to prevent hackers from accessing their computers without permission. At no point did anyone stop to say, "Maybe computers that process billions of dollars in transactions every day should not be plugged into the public phone network or Internet until we have some good reason to think those computers cannot be manipulated by hackers;" instead, the thinking was, "Hackers are evil wizards, nobody could possibly protect themselves from hackers, so we should make a law that allows us to throw the evil wizards in prison!" The idea that AT&T should be blamed for leaving customer data out in the open like that is not even on the table (strangely, if AT&T left a binder full of personal information unattended on a table in a public park, and labeled the binder "DO NOT OPEN," they would probably be the target of a successful lawsuit).
This article is an uninformed rant spreading FUD in the pursuit of a personal goal and it doesn't deserve the attention it is receiving any more than the garbage legal scaremongering for which SCO was notorious.
Also it's "proof of concept" fails to identify screen resolution so not only is the author a failure at reading the law but also at writing working code.
I see lots of IRC conversations about things the defendants, Auernheimer and Spitler, could do with the email addresses they were getting... but no concrete plans to actually do those things. Yes, the downloading of the addresses itself was an overt act, but I see no overt act alleged that specifically reveals fraudulent intent or acts in furtherance of a plan to commit fraud. The only overt acts alleged, other than the downloading itself, were (1) they sent some email messages to some of the victims, and (2) they gave all the email addresses to Gawker. I see nothing in here alleging concrete steps toward extorting the victims, or stealing their bank accounts, or deceiving them in any way, or indeed anything by which they would actually profit. Again, they discussed various possibilities, but I see no evidence here that they actually undertook any of them.
I'm sure it didn't help their case that they figured that what they were doing was illegal or at least tortious, and that they attempted to destroy evidence.
But the crux of your response to Rob is that they had the intent to commit fraud, and frankly, reading this indictment, I still don't see any evidence of that beyond some IRC banter.
There's also, seems to me, an odd circularity to the government's argument. They're alleging conspiracy, and among the overt acts that demonstrate this alleged conspiracy, they include the scraping of the email addresses. But the crime that that overt act is supposedly in furtherance of is... conspiracy. Seems to me this recursion is missing a base case :-)
Count 2 of the indictment has a slightly different thrust. Even though it's titled "Fraud in connection with personal information", it references USC 18 § 1028 (a) (7), which says: "Whoever ... knowingly transfers, possesses, or uses, without lawful authority, a means of identification of another person with the intent to commit, or to aid or abet, or in connection with, any unlawful activity that constitutes a violation of Federal law, or that constitutes a felony under any applicable State or local law [shall be punished, etc.]." What they seem to be saying here is that the ICC-IDs themselves count as a "means of identification" and that the fraud consisted simply of using said IDs to access the AT&T accounts. But this is also circular. The "unlawful activity" is the violation of the CFAA itself. The demonstration that the CFAA was violated rests on the assertion that it was violated.
If this indictment reflects the strongest arguments the prosecution has, I must respectfully disagree with this jury.
No, the crux of his response is that the government alleged fraud, and so using the case to claim that just accessing a site is a federal crime is at best hyperbole. Whether or not the allegation of intent to commit fraud is accurate or not is not relevant fo that argument.
I think one thing that is happening here is that we're getting our wires crossed between Rob's post, which says you've committed a crime by reading his blog but that's OK because he committed a crime by sending you Javascript and that post is simply incorrect, and the Auernheimer case from yesterday which is not nearly as cut and dry.
Rob is wrong. But even I think the Auernheimer result is shady; I think "unauthorized access" should be cut and dry (if you know you're not supposed to do something with someone else's computer system and you do it anyways, that's unauthorized access), but the conspiracy charge is shady, the allegation of fraud is extremely shady (they were spitballing about the impact of what they found, not planning an elaborate fraud), and using 1030(a)(2) + conspiracy to avoid confronting those issues is also shady.