But again, I am not a lawyer.
But again, I am not a lawyer.
Suppose that you have an ISP that only allows you to connect one device to their modem. (This used to be very common.) Suppose that you want to connect a different device. (Again a common desire.) Suppose that you spoof the MAC address of the original device so that you can connect. (This use case is a big part of why consumer electronics added the ability to spoof MAC addresses.)
Under federal law, you've now committed a felony for which you can serve jail time. Your access to your ISP's network is unauthorized.
Let me make this personal. This is not a random use case. I have done this. If anyone had cared, I could be charged with a felony. I could serve jail time, for accessing a network that I paid for in a way that I thought was pretty fair. (My "crime" being that I wanted to attach a wireless modem to the network so that I didn't have to have a wire connecting my laptop while I was using it. OK, I was bad, my wife and I could both use computers at the same time.) I didn't think I was doing anything wrong. It was a pretty common act. It was still a felony.
So no, randomizing your MAC address is not illegal. But the line between legal and a felony here is awfully easy to cross.
Setting up four different laptops all with the same MAC, so that either you or your three neighbors could share the connection, is probably closer to the kind of thing that would land you in jail.
I used that network from more than one device, and plugged a router in. I was therefore accessing the cable network in a way that was not authorized. Furthermore I intentionally changed the MAC address on my router so that I could circumvent their control mechanism that was intended to make sure that I followed their terms of use. There is no question that I did this in full knowledge of the fact that, according to the owner of that network, I was not allowed to do that. Among other things that I did with that network connection was gained access to online collections of software, including CPAN and Debian repositories.
I therefore used unauthorized access to a computer to obtain information. When valued in accord to the standards used in precedent as described in http://www.volokh.com/2013/01/14/aaron-swartz-charges/ there is no question that the cost of production of the property that I gained access to was worth more than $5000. (The fact that my cable provider did not produce that content does not enter into the statute, and is therefore irrelevant.)
By my reading, my changing of the MAC address allowed me to gain unauthorized access under false pretenses to property worth more than $5000 that resided in another state from me at that time. That means that a prosecutor could, in theory, have charged me with the first 3 of the 4 original charges that were leveled at Aaron Swartz.
But, you say, no prosecutor would have actually done so, and a judge would not impose a serious penalty if one did? That is absolutely true. The phenomena is called selective enforcement. And selective enforcement of bad laws only against people that someone in power doesn't like is a real problem.
Which would be my whole point.
Is this really true? I would think the circumvented security and the damaged party would need to be more "proximate". If you downloaded 500 copies of antivirus software from the Comcast only FTP site there'd be a case.
I don't think piling on of charges is right, but I don't think charges are piled on in quite the way you're describing. There is a connection, even if tenuous, between them.
Aaron had unauthorized access to MIT's network, through which he downloaded JSTOR's documents, and the value calculation they would use was based on the effort of various academic authors around the world. MIT complained to the prosecutor, and who brought the case despite JSTOR not being interested and no complaint from the actual owners of those documents (which mostly was not JSTOR).
In my parallel scenario, the cable company takes the role of MIT, open source repositories take the role of JSTOR, and open source authors take the role of the academic researchers, journals, etc who owned the documents downloaded. The parallel is exact. If the cable company (like MIT) complained, the fact that the other pieces of the puzzle do not want charges brought would not stop an overzealous prosecutor from being able to charge me.
What could I be charged with? Of the 4 initial charges against Aaron Swartz, the fact that he caused damage only matters for the last one. The first three are only concerned with the fact of unauthorized access over a network of valuable property. My parallel scenario has that.
The amendment that is being proposed saying that violation of terms of service does not suffice to count as unauthorized access under this bill would protect my case. That change is definitely needed. As I've commented elsewhere, the fact that Aaron's access required physical trespass means that his lack of authority did not merely stem from violating the terms of service. Therefore I don't believe that he would have been protected by the proposed bill that bears his name.
The CFAA criminalizes "unauthorized access" and "exceeding authorized access."
The unauthorized access provision applies to various means of hacking into a computer. The exceeding authorized access provision applies (in general) to company and government insiders. "The term “exceeds authorized access” means to access a computer with authorization and to use such access to obtain or alter information in the computer that the accesser is not entitled so to obtain or alter." 18 U.S.C. §1030(e)(6)[3]
Your contract with your ISP gives you access to the network. By spoofing a device, you would breach your agreement with the ISP, but you would not be obtaining or altering information that you are not already entitled to under your agreement with the ISP as an authorized user.
In sum, for an authorized user to commit a crime, he must break through the access level he was granted by his authorization and reach information that was effectively closed-off to him.
1. http://en.wikipedia.org/wiki/Lori_Drew#Guilty_verdict_set_as...
2. http://itlaw.wikia.com/wiki/EF_Cultural_Travel_v._Explorica (One of the most inane cases I've ever read.)
That said, "prevailing interpretations" can shift, and can vary by jurisdiction. Thus if someone living in Boston did what I described, and was sued by Ortiz, it is not guaranteed that a Massachusetts judge would decide the case on the same principles.
http://www.digitaltrends.com/mobile/att-ipad-hacker-auernhei...
The closest thing that comes to mind is the 2006 incident in which a researcher from the candidate opposing Governor Schwarzenegger logged onto the governor's public FTP site and stepped-up a directory to find a bunch of private audio recordings:
http://articles.latimes.com/2006/sep/13/local/me-audio13
A five month investigation by the CHP found that no illegal action had been done: http://www.mercurynews.com/ci_5145796
Of course, this involved a political campaign with millions of dollars (and publicity) behind it. The CHP arresting Arnold's opponent would not turn out well for anyone...if this had been a teenager who tried it, who knows?
That's why the law leaves it couched in terms unlikely to change (like "authorized access", "intentionally" doing something, etc.) and leave the charges to be considered in light of the totality of what went on.
Would a jury convict on typing in one URL, realizing it gave access to an admin panel and just leaving the site immediately? Hopefully not...
Would a jury convict on building a screen-scraper that steals the password for users by incrementing ID's on a URL that wasn't public but wasn't properly secured? I would think so. Sometimes the circumstances of the case matter more than the law itself.
Real-world analogies are fraught, but:
If you innocently walk into a room, thinking you are allowed, and find out it's a bank vault, you are (in general) innocent.
No they don't! Please don't say things like that in public, someone may actually believe you.
It is not possible for the laws to be perfect. They can't be like programs or catch every possible nuance or edge case (and when they try they look like the tax code). But we have specific articulable laws that are severely defective in ways that normal laws aren't, and they can certainly be improved to attain roughly the same level of imperfection found in the large body of legislation rather than their current state of total absurdity.
By what I mean by almost impossibly vague is things like even basic elements of the CFAA. There have been debates up and down HN, Reddit, and across the web about whether logging onto a website that uses laughably poor authentication schemes even counts as "unauthorized access".
If a specific-enough term like "unauthorized access" can lead to so much controversy in practice then yes, I don't see how one could argue that a legal code could simultaneously encompass all reasonable aspects of computer technology, in the present and future, and still not be at least somewhat vague.
It's the principle of indirection applied at a legal level. "What does unauthorized access mean? Well, I guess that's for the specific judge to hash out and the specific jury to decide"
Penalty: "shall be punished by a fine of not more than one hundred dollars or by imprisonment for not more than thirty days or both such fine and imprisonment."
On top of that, look at the wording: You have to have some specific notice that you're unauthorized before it's trespass. And then the penalty is a $100 fine or 30 days. So okay, you want to have the digital equivalent of trespass, let's do the same thing: You have to have been specifically told (not implied by some trumped up circumstantial nonsense about MAC and IP addresses or URLs) that you aren't allowed to access a particular computer and then have done it anyway, and then the penalty should be $100 or 30 days.
Because that's the trivial offense. That's the one that should have the really low penalties because it doesn't necessarily imply any substantial harm. The high penalties should be for high value financial fraud or misappropriating classified materials or disrupting the control systems at a power plant or a chemical processing facility, and they should each be separated out so that we know what they are and have penalties proportional to the specific offense.
And to do that we don't need to talk about XML or SOAP or AJAX, because that isn't what matters. It doesn't matter specifically how you did it, it matters what you did and what you intended to do. This is why we don't have laws against trespassing while wearing a yellow shirt. Because you don't need to specify the irrelevant details, only the relevant ones, and the specific underlying technology is almost always irrelevant to a particular class of criminal activity. Sometimes it does make a difference, and then you need to update the law, but that doesn't actually happen so often that we can't keep up with it if we're paying attention.
They're not difficult to interpret.
You just don't like them.
Be intellectually honest.
The laws don't recognize "information wants to be freeee" or any such pablum.
This is even empirically true: Different federal appeals courts (which have panels of knowledgable judges) have come to different conclusions about the scope, reach, and interpretation of different parts of the law.
I'm not sure what your evidence is to the contrary.
I would only point out that it's actually both: Not only are they unclear, even if they were clarified but still prohibited roughly the same breadth of things with the same extraordinary penalties, we still should not like them. A law that plausibly imposes the same (felony) penalty for using one's brother's laptop without permission as for breaking into a military intelligence satellite to steal classified materials is a defective law in need of serious reform.
A URL you found by guessing URLs, like say on an internal test site? You're on your own
Probably a line with small damages if it's just your home router.