Live data from Hacker News

Court: Breaking Your Employer's Computer Policy Isn't a Crime

eff.org

51–60 of 125 posts

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#51
post #32

Earlier quoted context omitted.

Its gross misconduct and in the uk Malfeasance in office (surely there is an equivalent law in the USA. And doesn't the US equivalent of the official secrets act apply to all police officers?

Doesn't the UK Official Secrets Act apply to matters of national security? The closest U.S. equivalent is the Espionage Act of 1917. Records from a city's criminal database are not national security secrets.

The OS act applies to a lot of things all list X organisations for example and in the UK all police answer to the home secretary.

All police and civilian police workers are vetted and access to Police databases etc is covered by the OS act.

Even access to say BT's databases that track phone numbers and circuits is covered.

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#52

Earlier quoted context omitted.

I thought the CFAA, like the UK equivalent Computer Misuse Act 1990, governed unauthorised access to computer systems and data. Seems appropriate to me. Paper files would probably be locked up - the equivalent prosecution would then be something like trespass, breaking and entering, or what have you. If you have access to data for operational purposes then access outside of operational needs is just unauthorised acce…

> Paper files would probably be locked up - the equivalent prosecution would then be something like trespass, breaking and entering, or what have you. You're making the right analogy but then the analogous thing has the same problem. The bad thing isn't trespassing, the bad thing is misusing police records. Trespassing or B&E doesn't fit at all, because he is legitimately allowed to be there (which is what that crime…

> You're making the right analogy but then the analogous thing has the same problem. The bad thing isn't trespassing, the bad thing is misusing police records. Trespassing or B&E doesn't fit at all, because he is legitimately allowed to be there (which is what that crime prohibits) and even to have that information, but isn't allowed to use the information for that purpose, which is something else entirely.

Exactly - though in most cases being fired from your position would be appropriate and the end of the story (unless there were actual people whom were harmed or material damages involved). In particular I think the comments/judgements regarding this issue are subconsciously harsher due to the subject matter.

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#53

Earlier quoted context omitted.

Its gross misconduct and in the uk Malfeasance in office (surely there is an equivalent law in the USA. And doesn't the US equivalent of the official secrets act apply to all police officers?

In the US, seemingly, no laws apply to police officers.

Agreed properly regulating police (ie only allowing state police and federal ) and enforcing strict vetting would go a long way to solving some of the problems with the police in the USA.

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#54
post #25

> A court should not uphold a highly problematic interpretation of a statute merely because the Government promises to use it responsibly. This. Whether a law is just needs to be considered in light of its worst-case abuse potential, not just on the basis of how it is currently being applied. It is a great advantage of the common law system that over-broad, ill-specified or otherwise broken laws can be remedied throu…

Could you extrapolate from that though that: 1. Since the first amendment allows the free exercise of religion, prayer must be allowed in schools as long as no specific religion is established via those prayers? 2. Since the second amendment allows the right to keep and bear arms, without further amendment, that right should be unrestricted by any registration process considered onerous or restrictive?

2a. "...well-regulated..."

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#55
post #54

Earlier quoted context omitted.

Could you extrapolate from that though that: 1. Since the first amendment allows the free exercise of religion, prayer must be allowed in schools as long as no specific religion is established via those prayers? 2. Since the second amendment allows the right to keep and bear arms, without further amendment, that right should be unrestricted by any registration process considered onerous or restrictive?

2a. "...well-regulated..."

The militia is well-regulated; the right to bear arms is unrestricted.

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#56

Earlier quoted context omitted.

There must be different statutes to charge under. That cop infringed the civil liberties of the persons who came up in the search at a minimum.

Yeah, I find it weird that they used CFAA. Maybe that law carries harsher penalties than the others.

Perhaps it is an example of prosecutorial overreach, and I wonder if the judges' ruling is, in part, intended to make a stand on that issue.

FWIW (and IANAL), I would have preferred to see this person charged only for the unauthorized data access, with his purpose taken into consideration (negatively) in sentencing.

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#57

Earlier quoted context omitted.

It's disquieting that this isn't sanctioned. There ought to be a law against this.

You're seeing the justice process work as intended. The CFAA is absolutely the wrong statute to be prosecuting his crime under. But we need actual, real-world cases to highlight these discrepancies. Now legislators can come up with a law that covers the specific case of government workers abusing the tools of state for their personal ends. Perhaps it already existed, that means the prosecutors screwed up and charged…

I'm looking at this from a more practical angle. Government employees are in a position of trust because you cannot choose not to deal with them, and sometimes are backed up with force of arms (like our friendly policeman). Besides, traditionally, because of the sheer expense, large databases with potential for abuse would belong to governmental entities. Things like Facebook and Google are upstarts, the legislative hasn't had time to deal with those yet in any way. That's why I'm saying that I'm surprised that there isn't a law.

The problem must have come up before. Someone asking about a competitor's tax records because the sister-in-law works at the IRS, arrest records of a political competitor becoming public the week before election, that sort of thing.

Perhaps a suitable statute is on the books but the prosecution picked the CFAA instead, hoping the case would get thrown out or go to revision and then get thrown out. It's within the realm of possibilities.

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#58
post #54

Earlier quoted context omitted.

2a. "...well-regulated..."

The militia is well-regulated; the right to bear arms is unrestricted.

Fair point about the separate clauses-- but what's the intent of the "well-regulated" part, then?

Re: Court: Breaking Your Employer's Computer Policy Isn't a Crime

#60
post #58

Earlier quoted context omitted.

The militia is well-regulated; the right to bear arms is unrestricted.

Fair point about the separate clauses-- but what's the intent of the "well-regulated" part, then?

To say that the country needed well managed militias to protect the country. Remember, the first several battles of the revolution were local Massachusetts militias defending their local weapons caches and supplies.
Post reply on HN