Live data from Hacker News

Court: Breaking Your Employer's Computer Policy Isn't a Crime

eff.org

21–30 of 125 posts

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#23
post #5

In general, that's probably the right decision. But I also think that using police records for personal purposes is different from browsing Facebook at work. One only damages the employer slightly, the other has huge potential issues against society at large. The CFAA is not the correct solution for this issue, but none the less, I think such behavior should be a criminal matter.

It should be a police disciplinary action, and there should be a policy in place to review database access on a regular basis.

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#24
post #5

In general, that's probably the right decision. But I also think that using police records for personal purposes is different from browsing Facebook at work. One only damages the employer slightly, the other has huge potential issues against society at large. The CFAA is not the correct solution for this issue, but none the less, I think such behavior should be a criminal matter.

Its gross misconduct and in the uk Malfeasance in office (surely there is an equivalent law in the USA.

And doesn't the US equivalent of the official secrets act apply to all police officers?

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#25
> A court should not uphold a highly problematic interpretation of a statute merely because the Government promises to use it responsibly.

This. Whether a law is just needs to be considered in light of its worst-case abuse potential, not just on the basis of how it is currently being applied. It is a great advantage of the common law system that over-broad, ill-specified or otherwise broken laws can be remedied through precedent, however the responsibility still lies with the government to make laws that are well-considered, based on sound principles and not overly broad.

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#27
post #14

Mh I'm getting a 403 from Germany for the whole domain. downforeveryoneorjustme says it's up. Could someone paste the content for me?

The United States Court of Appeals for the Second Circuit issued an opinion rejecting the government’s attempt to hold an employee criminally liable under the federal hacking statute—the Computer Fraud and Abuse Act (“CFAA”)—for violating his employer-imposed computer use restrictions. The decision is important because it ensures that employers and website owners don’t have the power to criminalize a broad range of innocuous everyday behaviors, like checking personal email or the score of a baseball game, through simply adopting use restrictions in their corporate policies or terms of use.

The court also ruled that the government cannot hold people criminally liable on the basis of purely fantastical statements they make online—i.e., thoughtcrime.

The case, United States v. Gilberto Valle, received a lot of attention in the press because it involved the so-called “cannibal cop”—a New York City police officer who was charged with conspiracy to kidnap for posts he wrote on fetish websites about cannibalism. Valle was also charged with violating the CFAA for accessing a police database to look up information about people without a valid law enforcement purpose, in violation of NYPD policy. The jury convicted Valle on all counts, but the trial court reversed the jury’s conspiracy verdict, stating that “the nearly yearlong kidnapping conspiracy alleged by the government is one in which no one was ever kidnapped, no attempted kidnapping ever took place, and no real-world, non-Internet-based steps were ever taken to kidnap anyone.” The trial court ultimately found that holding Valle guilty of conspiracy to kidnap would make him guilty of thoughtcrime.

But the trial court upheld the CFAA conviction. And on appeal, we filed an amicus brief with the Second Circuit, urging the court to overturn the lower court’s dangerous ruling. We argued that the lower court’s ruling would make criminals out of millions of innocent individuals, and the Second Circuit agreed—throwing out Mr. Valle's CFAA conviction and joining two other federal circuit courts in rejecting the government’s attempt to expand the reach of the vaguely worded federal statute: “We decline to adopt the prosecution’s construction [of the CFAA], which would criminalize the conduct of millions of ordinary computer users[.]” The court went on:

While the Government might promise that it would not prosecute an individual for checking Facebook at work, we are not at liberty to take prosecutors at their word in such matters. A court should not uphold a highly problematic interpretation of a statute merely because the Government promises to use it responsibly.

The Second Circuit also upheld the trial court’s decision to throw out the conspiracy conviction, as we had urged in a second amicus brief filed in the case, holding that “[t]he mere indulgence of fantasy, even of the repugnant and unsettling kind here, is not, without more, criminal.”

Thanks again to the Center for Democracy & Technology, the National Association of Criminal Defense Lawyers, and the Internet scholars who joined our CFAA amicus brief, and to UCLA law professor Eugene Volokh of the Scott & Cyan Banister First Amendment Clinic for writing our amicus brief regarding the conspiracy charges.

Related Cases United States v. Gilberto Valle

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#28
post #5

In general, that's probably the right decision. But I also think that using police records for personal purposes is different from browsing Facebook at work. One only damages the employer slightly, the other has huge potential issues against society at large. The CFAA is not the correct solution for this issue, but none the less, I think such behavior should be a criminal matter.

Indeed - I was thinking how convenient this is for the NSA and FBI.

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#29

"Valle was also charged with violating the CFAA for accessing a police database to look up information about people without a valid law enforcement purpose, in violation of NYPD policy." I find it odd that the prosecutors decided to go with a computer fraud charge for this crime, aren't there any laws that would prohibit this action regardless of method used? If he chose to lookup paper files on unrelated people, wou…

It's disquieting that this isn't sanctioned. There ought to be a law against this.

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#30
post #5

In general, that's probably the right decision. But I also think that using police records for personal purposes is different from browsing Facebook at work. One only damages the employer slightly, the other has huge potential issues against society at large. The CFAA is not the correct solution for this issue, but none the less, I think such behavior should be a criminal matter.

Its gross misconduct and in the uk Malfeasance in office (surely there is an equivalent law in the USA. And doesn't the US equivalent of the official secrets act apply to all police officers?

In the US, seemingly, no laws apply to police officers.
Post reply on HN