Live data from Hacker News

Man Convicted of Hacking Despite Not Hacking

wired.com

21–30 of 51 posts

Re: Man Convicted of Hacking Despite Not Hacking

#21
post #16

Earlier quoted context omitted.

First of all, Watt did not have any malicious intent -- he wrote a packet sniffing program and gave it to a friend, and did not participate in nor benefit from his friend's crime. Really, I am not seeing what your issue is with the comparison between the three cases. In all three cases, men faced charges of CFAA violations that were completely inappropriate. In all three cases, the CFAA charges were used for no reaso…

> First of all, Watt did not have any malicious intent -- he wrote a packet sniffing program and gave it to a friend, and did not participate in nor benefit from his friend's crime. The jury concluded based on the evidence that he knew that his friend intended to use it to commit a crime. Knowledge and concious disregard for the fact that your work is being used to commit a crime is indeed malicious intent. > Really,…

>If you're trying to show the injustices of a law, it's generally a good idea to find sympathetic defendants rather than criminals or their accomplices.

So what do you do if you're trying to show that the law has excessive and disproportionate penalties?

Re: Man Convicted of Hacking Despite Not Hacking

#23
post #14

Earlier quoted context omitted.

If I fire someone, and they come back into the office afterwards at night to do whatever, is that still "a civil dispute between two private parties"?

You make a good point. There is clearly theft of proprietary information. (Though the guy who got convicted didn't do the stealing.) But I reiterate. The fact that the information was stored on a computer shouldn't trigger massively bigger penalties. Everything is stored on computers these days!

OK, so would you be OK with it if unauthorized access to a computer system (eg an ex-employers or some other case where the lack of authorization is clear and criminal intent is present) resulted in a charge of burglary?

Re: Man Convicted of Hacking Despite Not Hacking

#24
post #4

A more fact-based article: http://7thspace.com/headlines/436581/executive_recruiter_dav... .

What's your point? Had he walked away with a paper copy of the data in question, more than half those charges would not exist. The issue here is that "involving a computer" has become an excuse for harsher sentencing and greater power for police and prosecutors. Driving that is a law that is so broad that nearly anyone with computer access could be accused of violating it (in other words, the majority of Americans).

Yes, and a bunch of other charges would exist. Since you're so convinced of your rightness on this, be specific, tell u which charges he would have faced in the two different situations, and calculate the different penalties he'd be eligible for.

Re: Man Convicted of Hacking Despite Not Hacking

#25

Ok, exactly what did he do that is illegal: He paid another company's employees to get information from said company's database, and that these employees accessed the data by using some other employee's login credentials without permission?

Well, "industrial espionage" actually is a crime since 1996, no matter what tools you use to do it (and notably, has the harshest sentence of the 3 major types of crimes Nosal was charged with).

Unauthorized access to a computer network was made to help complete the crime, which is itself criminal, just like there is a charge "mail fraud" that makes use of the postal system to further any criminal act illegal.

Conspiracy is always illegal itself as well.

Re: Man Convicted of Hacking Despite Not Hacking

#26
post #16

Earlier quoted context omitted.

> First of all, Watt did not have any malicious intent -- he wrote a packet sniffing program and gave it to a friend, and did not participate in nor benefit from his friend's crime. The jury concluded based on the evidence that he knew that his friend intended to use it to commit a crime. Knowledge and concious disregard for the fact that your work is being used to commit a crime is indeed malicious intent. > Really,…

>If you're trying to show the injustices of a law, it's generally a good idea to find sympathetic defendants rather than criminals or their accomplices. So what do you do if you're trying to show that the law has excessive and disproportionate penalties?

I'd find a better case, for starters.

The trade secret charge has the harshest penalty, and is independent of computer use.

The conspiracy charge has the same maximum as the unauthorized network access charge.

Someone who is an expert at the Federal Sentencing Guidelines will have to chime in with what that means for an eventual sentence, but I suspect that even if the computer violation were considered extremely minor that it would have nearly the same marginal effect on the eventual sentence, once the trade secret and conspiracy sentences are thrown into the mix.

Even if the prosecutors had never mentioned the term "computer" this guy would be in some deep shit...

Re: Man Convicted of Hacking Despite Not Hacking

#27
post #2

I don't see what the big deal is. If you pay somebody to commit a crime (e.g., murder), you may be prosecuted for the crime itself.

Four of the six charges were related to accessing a computer. In this case, that amounted to logging in and downloading files.

And yet the trade secret charge had the harshest penalty, and the conspiracy charge was tied for second-harshest. Maybe the Federal Sentencing Guidelines count the number of charges convicted on but it's hard to claim that the CFAA is the only or predominant reason Nosal will be facing jail time in this particular case.

Re: Man Convicted of Hacking Despite Not Hacking

#28
post #14

Earlier quoted context omitted.

You make a good point. There is clearly theft of proprietary information. (Though the guy who got convicted didn't do the stealing.) But I reiterate. The fact that the information was stored on a computer shouldn't trigger massively bigger penalties. Everything is stored on computers these days!

OK, so would you be OK with it if unauthorized access to a computer system (eg an ex-employers or some other case where the lack of authorization is clear and criminal intent is present ) resulted in a charge of burglary?

The problem is that there is already a well developed set of laws to govern human interactions with each other and with the environment. This is like the broken patent system: it's something that has been done for 40 years, except on a computer! We do not need a patent for that, and we do not need a new law for stealing information on a computer. We already have laws for theft.

Re: Man Convicted of Hacking Despite Not Hacking

#29
post #4

A more fact-based article: http://7thspace.com/headlines/436581/executive_recruiter_dav... .

What's your point? Had he walked away with a paper copy of the data in question, more than half those charges would not exist. The issue here is that "involving a computer" has become an excuse for harsher sentencing and greater power for police and prosecutors. Driving that is a law that is so broad that nearly anyone with computer access could be accused of violating it (in other words, the majority of Americans).

This is a common pattern for objects that are force multipliers. For example, the use of firearms and/or automobiles in the commission of a crime leads to harsher sentencing. Anything that gives the everyman an outsize advantage, like a computer, is treated harshly if that advantage is used against society.

Re: Man Convicted of Hacking Despite Not Hacking

#30

Earlier quoted context omitted.

OK, so would you be OK with it if unauthorized access to a computer system (eg an ex-employers or some other case where the lack of authorization is clear and criminal intent is present ) resulted in a charge of burglary?

The problem is that there is already a well developed set of laws to govern human interactions with each other and with the environment. This is like the broken patent system: it's something that has been done for 40 years, except on a computer! We do not need a patent for that, and we do not need a new law for stealing information on a computer. We already have laws for theft.

The problem the authors of CFAA faced when the law was written is that this is actually not the case. Existing laws regarding e.g. burglary did not cleanly apply to computer crimes.

I think there are probably cases that do a better job showcasing the need for computer-specific crime laws, and crimes that do a worse job at that. Basic wire fraud cases don't really need CFAA from what I can tell, and CFAA serves primarily as a sentence accelerant in them. But in other cases, particularly where people cause damage but don't reap profits, the need for specific laws is clearer.

Post reply on HN