Live data from Hacker News

Man Convicted of Hacking Despite Not Hacking

wired.com

31–40 of 51 posts

Re: Man Convicted of Hacking Despite Not Hacking

#31
post #25

Ok, exactly what did he do that is illegal: He paid another company's employees to get information from said company's database, and that these employees accessed the data by using some other employee's login credentials without permission?

Well, "industrial espionage" actually is a crime since 1996, no matter what tools you use to do it (and notably, has the harshest sentence of the 3 major types of crimes Nosal was charged with). Unauthorized access to a computer network was made to help complete the crime, which is itself criminal, just like there is a charge "mail fraud" that makes use of the postal system to further any criminal act illegal. Conspi…

thank you. i couldn't recall the exact words, but yeah this is classic industrial espionage

Re: Man Convicted of Hacking Despite Not Hacking

#32
post #30

Earlier quoted context omitted.

The problem is that there is already a well developed set of laws to govern human interactions with each other and with the environment. This is like the broken patent system: it's something that has been done for 40 years, except on a computer! We do not need a patent for that, and we do not need a new law for stealing information on a computer. We already have laws for theft.

The problem the authors of CFAA faced when the law was written is that this is actually not the case. Existing laws regarding e.g. burglary did not cleanly apply to computer crimes. I think there are probably cases that do a better job showcasing the need for computer-specific crime laws, and crimes that do a worse job at that. Basic wire fraud cases don't really need CFAA from what I can tell, and CFAA serves primar…

Was it really the case that someone could steal information from a computer and not be charged with a crime, or indicted by a grand jury and then successfully prosecuted under existing law, and that until recently, when information was stolen from a computer, that was not a crime?

Re: Man Convicted of Hacking Despite Not Hacking

#33
post #9

Earlier quoted context omitted.

The point is that Wired's egregiously shitty journalism isn't doing anybody any favors when it comes to mustering up legitimate opposition to the CFAA. If I opposed the CFAA in its present incarnation (which I do), I'd be embarassed to be associated with Wired's coverage. If I were a friend of Aaron Swartz, I'd be offended at Wired's repeated attempts to compare guys with malicious intent like this guy and the Watts…

First of all, Watt did not have any malicious intent -- he wrote a packet sniffing program and gave it to a friend, and did not participate in nor benefit from his friend's crime. Really, I am not seeing what your issue is with the comparison between the three cases. In all three cases, men faced charges of CFAA violations that were completely inappropriate. In all three cases, the CFAA charges were used for no reaso…

I'm no expert in the Watt prosecution and know nothing about him, but from the reading I did: he wasn't accused of writing an innocuous tool and sharing it with a friend, or even writing a particularly useful network security testing tool. He's accused of writing a sniffer specifically designed to capture and record credit card transactions. Then he shared that tool with the ringleader of the largest credit card theft ring in the history of credit cards, who was a personal friend of his, with whom he partied during the ongoing criminal activities. At least one other longtime associate of Watt's was an active, remunerated contributor to the theft ring.

Re: Man Convicted of Hacking Despite Not Hacking

#34
post #30

Earlier quoted context omitted.

The problem the authors of CFAA faced when the law was written is that this is actually not the case. Existing laws regarding e.g. burglary did not cleanly apply to computer crimes. I think there are probably cases that do a better job showcasing the need for computer-specific crime laws, and crimes that do a worse job at that. Basic wire fraud cases don't really need CFAA from what I can tell, and CFAA serves primar…

Was it really the case that someone could steal information from a computer and not be charged with a crime, or indicted by a grand jury and then successfully prosecuted under existing law, and that until recently, when information was stolen from a computer, that was not a crime?

You think I'm arguing something I'm not arguing. I'm not saying there aren't crimes that are chargeable under CFAA that could be better charged under a pre-existing law. I'm just saying there are crimes that can't be charged that way, thus the need for computer-specific crime laws.

CFAA is not a good computer-specific crime law. Two gigantic problems with it: sentences that scale linearly with damages despite the fact that criminal intent and diligence does not scale the same way, and the CFAA's "sentencing accelerant" property, where it bonds covalently with other criminal charges to increase penalties.

Re: Man Convicted of Hacking Despite Not Hacking

#35

Earlier quoted context omitted.

What's your point? Had he walked away with a paper copy of the data in question, more than half those charges would not exist. The issue here is that "involving a computer" has become an excuse for harsher sentencing and greater power for police and prosecutors. Driving that is a law that is so broad that nearly anyone with computer access could be accused of violating it (in other words, the majority of Americans).

Yes, and a bunch of other charges would exist. Since you're so convinced of your rightness on this, be specific, tell u which charges he would have faced in the two different situations, and calculate the different penalties he'd be eligible for.

The "bunch of other charges" is actually two charges: conspiracy, and unauthorized receipt and possession of stolen trade secrets. That would have been plenty to charge this guy with, and would have meant a lengthy maximum sentence of fifteen years in prison.

The CFAA charges have a maximum penalty of five years in prison per charge. So with all six charges, the maximum penalty was thirty five years.

All charges carried a maximum $250000 fine. Again, the CFAA charges more than doubled the maximum penalty.

Really though, what is your point in asking? This is laid out in rayiner's link, anyone can read it. Yes, the judge has leeway in deciding the penalty, but that is not really the issue; the issue is that a defendant facing 35 years faces a much harder choice than a defendant facing 15 years. The CFAA violations are an example of a typical prosecutor strategy of pressuring defendants into making a guilty plea, and of trying to reduce the likelihood of an acquittal.

Re: Man Convicted of Hacking Despite Not Hacking

#36

Earlier quoted context omitted.

OK, so would you be OK with it if unauthorized access to a computer system (eg an ex-employers or some other case where the lack of authorization is clear and criminal intent is present ) resulted in a charge of burglary?

The problem is that there is already a well developed set of laws to govern human interactions with each other and with the environment. This is like the broken patent system: it's something that has been done for 40 years, except on a computer! We do not need a patent for that, and we do not need a new law for stealing information on a computer. We already have laws for theft.

I'm asking a specific yes/no question, not one about theft.

Re: Man Convicted of Hacking Despite Not Hacking

#37

Earlier quoted context omitted.

Yes, and a bunch of other charges would exist. Since you're so convinced of your rightness on this, be specific, tell u which charges he would have faced in the two different situations, and calculate the different penalties he'd be eligible for.

The "bunch of other charges" is actually two charges: conspiracy, and unauthorized receipt and possession of stolen trade secrets. That would have been plenty to charge this guy with, and would have meant a lengthy maximum sentence of fifteen years in prison. The CFAA charges have a maximum penalty of five years in prison per charge . So with all six charges, the maximum penalty was thirty five years. All charges car…

What about accessory charges? You don't get to have clean hands just because some else does the dirty work for you.

Really though, what is your point in asking?

Because you keep making these assertions about how awful the CFAA but handwaving away critiques of your argument and any charges you don't like. So, you say that conspiracy and trade secrets charges are plenty, but from the point of view of interest of the public, why should we abstain from charging the guy with everything we can pin on him? Because he's a white-collar criminal as opposed to some kid with a bunch of drugs or a gun? Or because the deterrent 'yield' on marginal charges diminishes?

I get that you hate the CFAA, but you always spluttera bout how unfair it is and how much it's used for leverage against defendants. You need to show that prosecutors could not bring as many charges for an equivalent crime of stealing something from a safe or locked filing cabinet, and you need to show why the breach of trust involved in compromising a private computer system doesn't or shouldn't matter. As it is, all your arguments seem to revolve around 'it's just a computer, it's not that bad.'

I had the same problem with the Aaron Swatz case with people saying it was no big deal that he plugged his laptop into the wiring closet. Just because an act is trivially easy to commit doesn't mean that you have a right to do it. My neighbor tends to leave his window open, but I don't think it entitles me to enter his apartment even though I could do so very easily.

Re: Man Convicted of Hacking Despite Not Hacking

#38
post #30

Earlier quoted context omitted.

The problem the authors of CFAA faced when the law was written is that this is actually not the case. Existing laws regarding e.g. burglary did not cleanly apply to computer crimes. I think there are probably cases that do a better job showcasing the need for computer-specific crime laws, and crimes that do a worse job at that. Basic wire fraud cases don't really need CFAA from what I can tell, and CFAA serves primar…

Was it really the case that someone could steal information from a computer and not be charged with a crime, or indicted by a grand jury and then successfully prosecuted under existing law, and that until recently, when information was stolen from a computer, that was not a crime?

It would be an awful lot easier to argue that. I'd need to go back and look up a bunch of cases which I don't feel like doing at present because it would be a large research project, but absent any specific computer-crime laws I'd argue that because a computer is a digital system and a digital system is just a complex agglomeration of switches, there's no qualitative difference between accessing a computer system and turning a light switch on and off. You'd never convict someone of a crime for turning a light switch on and off; if they entered your office at night to do so that would just be trespass rather than burglary. So how is operating a computer all that different? You're just opening and closing a few million different circuits. Sure, you could say my client illegally obtained information by doing so, but where is this information? Can you produce it in evidence? If you can't do so without printing it out, and you can't show that my client printed it out, where is the crime? Etc. etc. Likewise I could argue that no fraud has taken place because fraud involves a deception, a deception involves a deceiver and a deceived, and computers are not sapient, therefore they're not capable of being deceived. Defeating a login system isn't a case of deception because administrator of said system was not consulted for permission; arguably he automated away his duty of granting or withholding access and the defendant should not be blamed for the inadequacy of that automated process.

Sure, these are bullshit arguments, but the point is that our legal system works on a rough mix of common sense and code. If I can find an exploitable ambiguity in statute or precedent and apply it to a defendant's case, then it's like an exploit in which throwing an exception is equivalent to a trial resulting in an acquittal. we have laws defining what a computer system is and what constitutes access to one etc. precisely because the virtualized nature of digital information makes it tricky to apply laws that were drafted to deal with theft of physical property.

Re: Man Convicted of Hacking Despite Not Hacking

#39

Earlier quoted context omitted.

The "bunch of other charges" is actually two charges: conspiracy, and unauthorized receipt and possession of stolen trade secrets. That would have been plenty to charge this guy with, and would have meant a lengthy maximum sentence of fifteen years in prison. The CFAA charges have a maximum penalty of five years in prison per charge . So with all six charges, the maximum penalty was thirty five years. All charges car…

What about accessory charges? You don't get to have clean hands just because some else does the dirty work for you. Really though, what is your point in asking? Because you keep making these assertions about how awful the CFAA but handwaving away critiques of your argument and any charges you don't like. So, you say that conspiracy and trade secrets charges are plenty, but from the point of view of interest of the pu…

"What about accessory charges? You don't get to have clean hands just because some else does the dirty work for you."

What about them? My issue is not with whether or not the guy is a criminal, but with whether or not it makes sense for "involves a computer" to mean "doubles the penalty."

"why should we abstain from charging the guy with everything we can pin on him?"

What if we had a law that criminalized crime itself, so that nobody could ever claim to have broken only one law? How would you feel about prosecutors using such a law to double the number of charges against every defendant?

I do not want to live in a society where anyone who is accused of a crime faces decades in prison, especially not when we already have the largest prison population on the planet. Computers are already ubiquitous, and will be even more ubiquitous in the future. If any crime that involves a computer is really two, three, or more crimes, then as time goes on the penalties for crimes will become increasingly severe regardless of whether or not the harm to society increases.

"you always splutter about how unfair it is and how much it's used for leverage against defendants"

Most defendants never have a jury trial, because they are pressured into taking a plea bargain. That is a problem, especially when defendants already have to wait years before they get a trial. Anything that gives prosecutors more power over defendants exacerbates this situation and clears the way for even more people to be imprisoned.

"You need to show that prosecutors could not bring as many charges for an equivalent crime of stealing something from a safe or locked filing cabinet"

That is not equivalent. The equivalent crime would be having a friend in the office hold a door open so that you can enter and make a copy of some documents. There are two crimes there: conspiracy, and theft of trade secrets.

"you need to show why the breach of trust involved in compromising a private computer system doesn't or shouldn't matter"

It does matter, but what matters is that there was a breach of trust. The fact that a computer is involved is irrelevant.

Re: Man Convicted of Hacking Despite Not Hacking

#40

Earlier quoted context omitted.

What about accessory charges? You don't get to have clean hands just because some else does the dirty work for you. Really though, what is your point in asking? Because you keep making these assertions about how awful the CFAA but handwaving away critiques of your argument and any charges you don't like. So, you say that conspiracy and trade secrets charges are plenty, but from the point of view of interest of the pu…

"What about accessory charges? You don't get to have clean hands just because some else does the dirty work for you." What about them? My issue is not with whether or not the guy is a criminal, but with whether or not it makes sense for "involves a computer" to mean "doubles the penalty." "why should we abstain from charging the guy with everything we can pin on him?" What if we had a law that criminalized crime itse…

What if we had a law that criminalized crime itself

This is an empty argument. You haven't shown that merely doing things with a computer makes it worse.

"You need to show that prosecutors could not bring as many charges for an equivalent crime of stealing something from a safe or locked filing cabinet" That is not equivalent. The equivalent crime would be having a friend in the office hold a door open so that you can enter and make a copy of some documents. There are two crimes there: conspiracy, and theft of trade secrets.

You're committing criminal trespass in that example, why don't you include that? And why do you equate accessing the system to simply holding a door open, as if there were no login security? I mentioned the example of documents being held in a safe as a proxy for the fact that you need to log into a system before copying documents from it, it's not like you just SSH in and get automatic access to the shell prompt for the asking. The reason that we have a crime of unauthorized access to a computer system is precisely because it's easier to get into a computer without damaging it than it is to get through a window without breaking it.

You're rewriting the facts to make your argument stand up. that's what's wrong with it. You do not get to just walk into someone else' place of business and start using the copier, and then only be charged for the copies you made, for the same reason that if you break into my house at night and take some money you're guilty of burglary as well as theft. Just because the unauthorized access/ criminal trespass/ burglary is a necessary prerequisite to the theft of trade secrets/ cash does not mean it's incorporaated into it.

Post reply on HN