You seem to be a lawyer, and I'm not, so thanks for your information. I know a lot more about computer security theory and practice than the US federal laws; there are pretty clear lines way before "crime" which I try to stay within, myself.
As far as I can tell, CFAA was not violated, at least under the narrow (i.e. correct) interpretation of the 9th circuit. There is a circuit split right now. 1st hasn't ruled at all, so she could easily have looked to the 9th for guidance on this and not included CFAA charges.
There was no "protection" at MIT or at JSTOR, so I don't see how fraud or unauthorized access, etc. applied. He scraped a website. He may have trespassed at MIT. If net-18 restriction is considered "protection", wtf (certainly a server on a secure LAN is protected by being only on the secure LAN, but a server limited to US-only access and accessed via a proxy is not. IMO Net-18 is a lot closer to national restrictions at YouTube than a security policy, since any guest could walk in and have access.
I don't see "recklessly damaging a computer" as applying at all. Wire Fraud is essentially free always.
Turning these into multiple counts for the same offense is also BS.