Live data from Hacker News

Court: Breaking Your Employer's Computer Policy Isn't a Crime

eff.org

31–40 of 125 posts

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#31
For the people who skipped the article and assumed that the case was about some stupid office policy:

> Valle was also charged with violating the CFAA for accessing a police database to look up information about people without a valid law enforcement purpose, in violation of NYPD policy.

This is not a typical "employer policy". This a policy about access to sensitive private data that is only available to the government. Wouldn't you want improper access to such data punished?

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#32
post #5

In general, that's probably the right decision. But I also think that using police records for personal purposes is different from browsing Facebook at work. One only damages the employer slightly, the other has huge potential issues against society at large. The CFAA is not the correct solution for this issue, but none the less, I think such behavior should be a criminal matter.

Its gross misconduct and in the uk Malfeasance in office (surely there is an equivalent law in the USA. And doesn't the US equivalent of the official secrets act apply to all police officers?

Doesn't the UK Official Secrets Act apply to matters of national security? The closest U.S. equivalent is the Espionage Act of 1917. Records from a city's criminal database are not national security secrets.

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#33

For the people who skipped the article and assumed that the case was about some stupid office policy: > Valle was also charged with violating the CFAA for accessing a police database to look up information about people without a valid law enforcement purpose, in violation of NYPD policy. This is not a typical "employer policy". This a policy about access to sensitive private data that is only available to the governm…

In this case, I would either want the NYPD to control access to their own database more effectively (which is perfectly within their power) or I would want the law to be written much more narrowly, so it couldn't apply to "typical employer policy". Essentially, I don't want to have to rely on prosecutorial restraint.

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#34

"Valle was also charged with violating the CFAA for accessing a police database to look up information about people without a valid law enforcement purpose, in violation of NYPD policy." I find it odd that the prosecutors decided to go with a computer fraud charge for this crime, aren't there any laws that would prohibit this action regardless of method used? If he chose to lookup paper files on unrelated people, wou…

It's disquieting that this isn't sanctioned. There ought to be a law against this.

You're seeing the justice process work as intended. The CFAA is absolutely the wrong statute to be prosecuting his crime under. But we need actual, real-world cases to highlight these discrepancies. Now legislators can come up with a law that covers the specific case of government workers abusing the tools of state for their personal ends. Perhaps it already existed, that means the prosecutors screwed up and charged him under the wrong statute. Now they know the limits of that law and so will use the right law next time.

It's tempting to want a perfect judicial code, but it's impossible, iterated law is really the only way.

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#35
post #5

In general, that's probably the right decision. But I also think that using police records for personal purposes is different from browsing Facebook at work. One only damages the employer slightly, the other has huge potential issues against society at large. The CFAA is not the correct solution for this issue, but none the less, I think such behavior should be a criminal matter.

There must be different statutes to charge under. That cop infringed the civil liberties of the persons who came up in the search at a minimum.

Yeah, I find it weird that they used CFAA. Maybe that law carries harsher penalties than the others.

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#36
post #25

> A court should not uphold a highly problematic interpretation of a statute merely because the Government promises to use it responsibly. This. Whether a law is just needs to be considered in light of its worst-case abuse potential, not just on the basis of how it is currently being applied. It is a great advantage of the common law system that over-broad, ill-specified or otherwise broken laws can be remedied throu…

Could you extrapolate from that though that:

1. Since the first amendment allows the free exercise of religion, prayer must be allowed in schools as long as no specific religion is established via those prayers?

2. Since the second amendment allows the right to keep and bear arms, without further amendment, that right should be unrestricted by any registration process considered onerous or restrictive?

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#37

"Valle was also charged with violating the CFAA for accessing a police database to look up information about people without a valid law enforcement purpose, in violation of NYPD policy." I find it odd that the prosecutors decided to go with a computer fraud charge for this crime, aren't there any laws that would prohibit this action regardless of method used? If he chose to lookup paper files on unrelated people, wou…

I thought the CFAA, like the UK equivalent Computer Misuse Act 1990, governed unauthorised access to computer systems and data. Seems appropriate to me.

Paper files would probably be locked up - the equivalent prosecution would then be something like trespass, breaking and entering, or what have you.

If you have access to data for operational purposes then access outside of operational needs is just unauthorised access which on computer systems is an offence in itself because physical access is already historically covered under various laws.

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#38

For the people who skipped the article and assumed that the case was about some stupid office policy: > Valle was also charged with violating the CFAA for accessing a police database to look up information about people without a valid law enforcement purpose, in violation of NYPD policy. This is not a typical "employer policy". This a policy about access to sensitive private data that is only available to the governm…

He was apparently fired for violating his terms of employment, so he was punished, but not criminally punished. While I am very disturbed that a major restraint (the threat of criminal prosecution) has been taken off the table for abuse of sensitive private government data, I'm happy that it has been taken off the table for me as well, as a non-government employee that only has access to sensitive company private data.

Quote from the appeals court ruling: "Valle concedes that he violated the terms of his employment by putting his authorized computer access to personal use..."

Ref: " rel="nofollow">http://arstechnica.com/tech-policy/2015/12/repugnant-online-...

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#39
post #25

> A court should not uphold a highly problematic interpretation of a statute merely because the Government promises to use it responsibly. This. Whether a law is just needs to be considered in light of its worst-case abuse potential, not just on the basis of how it is currently being applied. It is a great advantage of the common law system that over-broad, ill-specified or otherwise broken laws can be remedied throu…

Could you extrapolate from that though that: 1. Since the first amendment allows the free exercise of religion, prayer must be allowed in schools as long as no specific religion is established via those prayers? 2. Since the second amendment allows the right to keep and bear arms, without further amendment, that right should be unrestricted by any registration process considered onerous or restrictive?

No, I don't think you can extrapolate that, those seem like entirely unrelated issues. Neither of those points imply an overly broad law that only works based on the trust and restraint of the government.
Post reply on HN