Ok, exactly what did he do that is illegal: He paid another company's employees to get information from said company's database, and that these employees accessed the data by using some other employee's login credentials without permission?
Well, "industrial espionage" actually is a crime since 1996, no matter what tools you use to do it (and notably, has the harshest sentence of the 3 major types of crimes Nosal was charged with). Unauthorized access to a computer network was made to help complete the crime, which is itself criminal, just like there is a charge "mail fraud" that makes use of the postal system to further any criminal act illegal. Conspi…
Man Convicted of Hacking Despite Not Hacking
31–40 of 51 posts
Re: Man Convicted of Hacking Despite Not Hacking
#32Earlier quoted context omitted.
The problem is that there is already a well developed set of laws to govern human interactions with each other and with the environment. This is like the broken patent system: it's something that has been done for 40 years, except on a computer! We do not need a patent for that, and we do not need a new law for stealing information on a computer. We already have laws for theft.
The problem the authors of CFAA faced when the law was written is that this is actually not the case. Existing laws regarding e.g. burglary did not cleanly apply to computer crimes. I think there are probably cases that do a better job showcasing the need for computer-specific crime laws, and crimes that do a worse job at that. Basic wire fraud cases don't really need CFAA from what I can tell, and CFAA serves primar…
Re: Man Convicted of Hacking Despite Not Hacking
#33Earlier quoted context omitted.
The point is that Wired's egregiously shitty journalism isn't doing anybody any favors when it comes to mustering up legitimate opposition to the CFAA. If I opposed the CFAA in its present incarnation (which I do), I'd be embarassed to be associated with Wired's coverage. If I were a friend of Aaron Swartz, I'd be offended at Wired's repeated attempts to compare guys with malicious intent like this guy and the Watts…
First of all, Watt did not have any malicious intent -- he wrote a packet sniffing program and gave it to a friend, and did not participate in nor benefit from his friend's crime. Really, I am not seeing what your issue is with the comparison between the three cases. In all three cases, men faced charges of CFAA violations that were completely inappropriate. In all three cases, the CFAA charges were used for no reaso…
Re: Man Convicted of Hacking Despite Not Hacking
#34Earlier quoted context omitted.
The problem the authors of CFAA faced when the law was written is that this is actually not the case. Existing laws regarding e.g. burglary did not cleanly apply to computer crimes. I think there are probably cases that do a better job showcasing the need for computer-specific crime laws, and crimes that do a worse job at that. Basic wire fraud cases don't really need CFAA from what I can tell, and CFAA serves primar…
Was it really the case that someone could steal information from a computer and not be charged with a crime, or indicted by a grand jury and then successfully prosecuted under existing law, and that until recently, when information was stolen from a computer, that was not a crime?
CFAA is not a good computer-specific crime law. Two gigantic problems with it: sentences that scale linearly with damages despite the fact that criminal intent and diligence does not scale the same way, and the CFAA's "sentencing accelerant" property, where it bonds covalently with other criminal charges to increase penalties.
Re: Man Convicted of Hacking Despite Not Hacking
#35Earlier quoted context omitted.
What's your point? Had he walked away with a paper copy of the data in question, more than half those charges would not exist. The issue here is that "involving a computer" has become an excuse for harsher sentencing and greater power for police and prosecutors. Driving that is a law that is so broad that nearly anyone with computer access could be accused of violating it (in other words, the majority of Americans).
Yes, and a bunch of other charges would exist. Since you're so convinced of your rightness on this, be specific, tell u which charges he would have faced in the two different situations, and calculate the different penalties he'd be eligible for.
The CFAA charges have a maximum penalty of five years in prison per charge. So with all six charges, the maximum penalty was thirty five years.
All charges carried a maximum $250000 fine. Again, the CFAA charges more than doubled the maximum penalty.
Really though, what is your point in asking? This is laid out in rayiner's link, anyone can read it. Yes, the judge has leeway in deciding the penalty, but that is not really the issue; the issue is that a defendant facing 35 years faces a much harder choice than a defendant facing 15 years. The CFAA violations are an example of a typical prosecutor strategy of pressuring defendants into making a guilty plea, and of trying to reduce the likelihood of an acquittal.
Re: Man Convicted of Hacking Despite Not Hacking
#36Earlier quoted context omitted.
OK, so would you be OK with it if unauthorized access to a computer system (eg an ex-employers or some other case where the lack of authorization is clear and criminal intent is present ) resulted in a charge of burglary?
The problem is that there is already a well developed set of laws to govern human interactions with each other and with the environment. This is like the broken patent system: it's something that has been done for 40 years, except on a computer! We do not need a patent for that, and we do not need a new law for stealing information on a computer. We already have laws for theft.
Re: Man Convicted of Hacking Despite Not Hacking
#37Earlier quoted context omitted.
Yes, and a bunch of other charges would exist. Since you're so convinced of your rightness on this, be specific, tell u which charges he would have faced in the two different situations, and calculate the different penalties he'd be eligible for.
The "bunch of other charges" is actually two charges: conspiracy, and unauthorized receipt and possession of stolen trade secrets. That would have been plenty to charge this guy with, and would have meant a lengthy maximum sentence of fifteen years in prison. The CFAA charges have a maximum penalty of five years in prison per charge . So with all six charges, the maximum penalty was thirty five years. All charges car…
Really though, what is your point in asking?
Because you keep making these assertions about how awful the CFAA but handwaving away critiques of your argument and any charges you don't like. So, you say that conspiracy and trade secrets charges are plenty, but from the point of view of interest of the public, why should we abstain from charging the guy with everything we can pin on him? Because he's a white-collar criminal as opposed to some kid with a bunch of drugs or a gun? Or because the deterrent 'yield' on marginal charges diminishes?
I get that you hate the CFAA, but you always spluttera bout how unfair it is and how much it's used for leverage against defendants. You need to show that prosecutors could not bring as many charges for an equivalent crime of stealing something from a safe or locked filing cabinet, and you need to show why the breach of trust involved in compromising a private computer system doesn't or shouldn't matter. As it is, all your arguments seem to revolve around 'it's just a computer, it's not that bad.'
I had the same problem with the Aaron Swatz case with people saying it was no big deal that he plugged his laptop into the wiring closet. Just because an act is trivially easy to commit doesn't mean that you have a right to do it. My neighbor tends to leave his window open, but I don't think it entitles me to enter his apartment even though I could do so very easily.
Re: Man Convicted of Hacking Despite Not Hacking
#38Earlier quoted context omitted.
The problem the authors of CFAA faced when the law was written is that this is actually not the case. Existing laws regarding e.g. burglary did not cleanly apply to computer crimes. I think there are probably cases that do a better job showcasing the need for computer-specific crime laws, and crimes that do a worse job at that. Basic wire fraud cases don't really need CFAA from what I can tell, and CFAA serves primar…
Was it really the case that someone could steal information from a computer and not be charged with a crime, or indicted by a grand jury and then successfully prosecuted under existing law, and that until recently, when information was stolen from a computer, that was not a crime?
Sure, these are bullshit arguments, but the point is that our legal system works on a rough mix of common sense and code. If I can find an exploitable ambiguity in statute or precedent and apply it to a defendant's case, then it's like an exploit in which throwing an exception is equivalent to a trial resulting in an acquittal. we have laws defining what a computer system is and what constitutes access to one etc. precisely because the virtualized nature of digital information makes it tricky to apply laws that were drafted to deal with theft of physical property.
Re: Man Convicted of Hacking Despite Not Hacking
#39Earlier quoted context omitted.
The "bunch of other charges" is actually two charges: conspiracy, and unauthorized receipt and possession of stolen trade secrets. That would have been plenty to charge this guy with, and would have meant a lengthy maximum sentence of fifteen years in prison. The CFAA charges have a maximum penalty of five years in prison per charge . So with all six charges, the maximum penalty was thirty five years. All charges car…
What about accessory charges? You don't get to have clean hands just because some else does the dirty work for you. Really though, what is your point in asking? Because you keep making these assertions about how awful the CFAA but handwaving away critiques of your argument and any charges you don't like. So, you say that conspiracy and trade secrets charges are plenty, but from the point of view of interest of the pu…
What about them? My issue is not with whether or not the guy is a criminal, but with whether or not it makes sense for "involves a computer" to mean "doubles the penalty."
"why should we abstain from charging the guy with everything we can pin on him?"
What if we had a law that criminalized crime itself, so that nobody could ever claim to have broken only one law? How would you feel about prosecutors using such a law to double the number of charges against every defendant?
I do not want to live in a society where anyone who is accused of a crime faces decades in prison, especially not when we already have the largest prison population on the planet. Computers are already ubiquitous, and will be even more ubiquitous in the future. If any crime that involves a computer is really two, three, or more crimes, then as time goes on the penalties for crimes will become increasingly severe regardless of whether or not the harm to society increases.
"you always splutter about how unfair it is and how much it's used for leverage against defendants"
Most defendants never have a jury trial, because they are pressured into taking a plea bargain. That is a problem, especially when defendants already have to wait years before they get a trial. Anything that gives prosecutors more power over defendants exacerbates this situation and clears the way for even more people to be imprisoned.
"You need to show that prosecutors could not bring as many charges for an equivalent crime of stealing something from a safe or locked filing cabinet"
That is not equivalent. The equivalent crime would be having a friend in the office hold a door open so that you can enter and make a copy of some documents. There are two crimes there: conspiracy, and theft of trade secrets.
"you need to show why the breach of trust involved in compromising a private computer system doesn't or shouldn't matter"
It does matter, but what matters is that there was a breach of trust. The fact that a computer is involved is irrelevant.
Re: Man Convicted of Hacking Despite Not Hacking
#40Earlier quoted context omitted.
What about accessory charges? You don't get to have clean hands just because some else does the dirty work for you. Really though, what is your point in asking? Because you keep making these assertions about how awful the CFAA but handwaving away critiques of your argument and any charges you don't like. So, you say that conspiracy and trade secrets charges are plenty, but from the point of view of interest of the pu…
"What about accessory charges? You don't get to have clean hands just because some else does the dirty work for you." What about them? My issue is not with whether or not the guy is a criminal, but with whether or not it makes sense for "involves a computer" to mean "doubles the penalty." "why should we abstain from charging the guy with everything we can pin on him?" What if we had a law that criminalized crime itse…
This is an empty argument. You haven't shown that merely doing things with a computer makes it worse.
"You need to show that prosecutors could not bring as many charges for an equivalent crime of stealing something from a safe or locked filing cabinet" That is not equivalent. The equivalent crime would be having a friend in the office hold a door open so that you can enter and make a copy of some documents. There are two crimes there: conspiracy, and theft of trade secrets.
You're committing criminal trespass in that example, why don't you include that? And why do you equate accessing the system to simply holding a door open, as if there were no login security? I mentioned the example of documents being held in a safe as a proxy for the fact that you need to log into a system before copying documents from it, it's not like you just SSH in and get automatic access to the shell prompt for the asking. The reason that we have a crime of unauthorized access to a computer system is precisely because it's easier to get into a computer without damaging it than it is to get through a window without breaking it.
You're rewriting the facts to make your argument stand up. that's what's wrong with it. You do not get to just walk into someone else' place of business and start using the copier, and then only be charged for the copies you made, for the same reason that if you break into my house at night and take some money you're guilty of burglary as well as theft. Just because the unauthorized access/ criminal trespass/ burglary is a necessary prerequisite to the theft of trade secrets/ cash does not mean it's incorporaated into it.