The opinion is not only compelling, it is a brilliant example of law at its best, for it shows how a wonderful legal mind wrestles with a knotty problem that can be summed up with the question, "Should courts apply a badly drafted piece of legislation to lead to the absurd result of criminalizing a whole host of minor misdeeds committed by individuals every day in using the web and their computers?" Judge Kozinski answered this question with a resounding "no."
He did so by applying the "rule of lenity," which requires "penal laws . . . to be construed strictly." (at p. 3872) "The rule of lenity not only ensures that citizens will have fair notice of the criminal laws, but also that Congress will have fair notice of what conduct its laws criminalize. We construe criminal statutes narrowly so that Congress will not unintentionally turn ordinary citizens into criminals." Applying this rule, he held as follows: "Therefore, we hold that 'exceeds authorized access' in the CFAA is limited to violations of restrictions on access to information, and not restrictions on its use." (emphasis in original)
In other words, though the CFAA is so badly worded that one might potentially give it an absurd and unconstitutional interpretation so as to criminalize things one would think shocking for Congress to have criminalized, the courts have the power to apply well-established rules of statutory construction so as to avoid such an absurdity. Here, the Ninth Circuit did so by construing the CFAA to criminalize violations of access restrictions (i.e., hacking) and not violations of use restrictions (terms of use on website and the like).
Now, there is a split in the federal circuits on this issue and it will either be resolved by an amendment to the statute or it will eventually find its way to the Supreme Court for resolution. But, even granting the split, the most extreme cases in which the CFAA has been applied criminally have involved things such as employees misappropriating trade secrets and other items that go far beyond innocuous things such as violating an employer's computer use policies by surfing the internet on company time.
In other words, no court has gone so far as to adopt anything close to the absurd outcomes suggested in this piece. Even the government in its arguments to Judge Kozinski strongly stated that it would never consider prosecuting such items as crimes. ("The government assures us that, whatever the scope of the CFAA, it won't prosecute minor violations. But we shouldn't have to live at the mercy of the local prosecutor." at p. 3870)
Thus, it is fit and proper to call out the alarmist tone of this piece as being wildly outside the mainstream of where the courts have gone with the CFAA and of where they are likely to go. Is it badly drafted legislation? Yes, it is a mess (if you want to lose your mind, try reading through the text of the statute here: http://www.law.cornell.edu/uscode/text/18/1030). Can it be interpreted to criminalize things that Congress might not have intended to criminalize? Yes, including acts by employees that, though wrongful, may not have been within the contemplation of Congress when it passed the statute. But, that said, is there a risk that the CFAA can be applied to criminalize our daily interaction with computers and the web? No, not unless normal, sound principles of law are wholly disregarded by the courts, which they won't be.