Live data from Hacker News

Man Convicted of Hacking Despite Not Hacking

wired.com

41–50 of 51 posts

Re: Man Convicted of Hacking Despite Not Hacking

#41

Earlier quoted context omitted.

"What about accessory charges? You don't get to have clean hands just because some else does the dirty work for you." What about them? My issue is not with whether or not the guy is a criminal, but with whether or not it makes sense for "involves a computer" to mean "doubles the penalty." "why should we abstain from charging the guy with everything we can pin on him?" What if we had a law that criminalized crime itse…

What if we had a law that criminalized crime itself This is an empty argument. You haven't shown that merely doing things with a computer makes it worse. "You need to show that prosecutors could not bring as many charges for an equivalent crime of stealing something from a safe or locked filing cabinet" That is not equivalent. The equivalent crime would be having a friend in the office hold a door open so that you ca…

"why do you equate accessing the system to simply holding a door open, as if there were no login security?"

They were using a valid login; one of the coconspirators had given his credentials to them.

"the example of documents being held in a safe as a proxy for the fact that you need to log into"

No, that is what the door in my example is. The door was held open by a coconspirator.

To put it another way, nothing had to be broken; they accessed the computer in the normal fashion and downloaded the files in the normal fashion. They did not sneak in, they were allowed in by someone with legitimate, authorized access.

Re: Man Convicted of Hacking Despite Not Hacking

#42

Earlier quoted context omitted.

What if we had a law that criminalized crime itself This is an empty argument. You haven't shown that merely doing things with a computer makes it worse. "You need to show that prosecutors could not bring as many charges for an equivalent crime of stealing something from a safe or locked filing cabinet" That is not equivalent. The equivalent crime would be having a friend in the office hold a door open so that you ca…

"why do you equate accessing the system to simply holding a door open, as if there were no login security?" They were using a valid login; one of the coconspirators had given his credentials to them. "the example of documents being held in a safe as a proxy for the fact that you need to log into" No, that is what the door in my example is. The door was held open by a coconspirator. To put it another way, nothing had…

If you've conspired with someone to let you in, then your claim of authorized access is a sham. The question is whether the employer would have authorized such access, not whether you could successfully suborn a member of the employer's staff.

I don't know why, but there is this persistent misconception that just because you can do something easily it shouldn't be illegal.

It matters with what intent deeds are performed. If you come into my office at my invitation for a social chat, and while I'm visiting the restroom you notice a trade secret lying on my desk and copy it, you've stolen the trade secret but you were entitled to be there. But if you know I have a trade secret and you go into my office without permission, or trick me into admitting you under false pretenses, then you're guilty of criminal trespass as well.

The defendant knew that Korn/Ferry wouldn't want him copying client lists. Just because he used someone else as his man on the inside does not sanitize the unauthorized access. You're essentially applying the principles of money laundering to information and saying it's cool. This is total bullshit. I think you know better and that you would howl like a lonely coyote if anyone pulled the same trick on you.

Re: Man Convicted of Hacking Despite Not Hacking

#43

Earlier quoted context omitted.

The problem is that there is already a well developed set of laws to govern human interactions with each other and with the environment. This is like the broken patent system: it's something that has been done for 40 years, except on a computer! We do not need a patent for that, and we do not need a new law for stealing information on a computer. We already have laws for theft.

I'm asking a specific yes/no question, not one about theft.

Would the charge be burglary for unauthorized access, or burglary if information was stolen after unauthorized access, and otherwise breaking and entering or just entering? To that, yes. If the information that was stolen was then used to commit other crimes, then other charges should follow as appropriate.

Re: Man Convicted of Hacking Despite Not Hacking

#44
post #34

Earlier quoted context omitted.

Was it really the case that someone could steal information from a computer and not be charged with a crime, or indicted by a grand jury and then successfully prosecuted under existing law, and that until recently, when information was stolen from a computer, that was not a crime?

You think I'm arguing something I'm not arguing. I'm not saying there aren't crimes that are chargeable under CFAA that could be better charged under a pre-existing law. I'm just saying there are crimes that can't be charged that way, thus the need for computer-specific crime laws. CFAA is not a good computer-specific crime law. Two gigantic problems with it: sentences that scale linearly with damages despite the fac…

I understand and I share your point of view to a degree, but I remain skeptical that until CFAA, there were no successful prosecutions for crimes that we are told are only now covered by CFAA. Computers and criminals have been around for a while now.

I am also opposed to the idea that we need specific crime laws for things like this. What about vehicular manslaughter while listening to an iPod, and why would that not be covered as distraction equivalent to listening to radio, which I assume and also hope that it would be. There should be some respect for the intent of existing law in addition to the letter, because we do have laws for theft and I am certain that the intent of those laws covers these cases.

Re: Man Convicted of Hacking Despite Not Hacking

#45
post #26

Earlier quoted context omitted.

>If you're trying to show the injustices of a law, it's generally a good idea to find sympathetic defendants rather than criminals or their accomplices. So what do you do if you're trying to show that the law has excessive and disproportionate penalties?

I'd find a better case, for starters. The trade secret charge has the harshest penalty, and is independent of computer use. The conspiracy charge has the same maximum as the unauthorized network access charge. Someone who is an expert at the Federal Sentencing Guidelines will have to chime in with what that means for an eventual sentence, but I suspect that even if the computer violation were considered extremely min…

>I'd find a better case, for starters.

I was responding to the general point.

But as for finding a better case, the problem is that you don't get to pick which cases get prosecuted. If the parties have decided to appeal then a precedent is going to be set here one way or the other. So let him go to jail for what he actually did -- there is no reason to allow the CFAA charge to be piled on top of that and set a terrible precedent for next time when the defendant is sympathetic but the question has already been settled.

Re: Man Convicted of Hacking Despite Not Hacking

#46

Earlier quoted context omitted.

Was it really the case that someone could steal information from a computer and not be charged with a crime, or indicted by a grand jury and then successfully prosecuted under existing law, and that until recently, when information was stolen from a computer, that was not a crime?

It would be an awful lot easier to argue that. I'd need to go back and look up a bunch of cases which I don't feel like doing at present because it would be a large research project, but absent any specific computer-crime laws I'd argue that because a computer is a digital system and a digital system is just a complex agglomeration of switches, there's no qualitative difference between accessing a computer system and…

Is the intent of existing law considered as part of the concept of common law? Would the average member of the jury really not understand this? Why couldn't a prosecutor receive an indictment and then argue this before a court and jury and thereby develop the methodology to approach this problem. This process may require several cases but wouldn't that be preferable to have jurists extend common law rather than have legislators parachute in new laws that obviously have problems?

Re: Man Convicted of Hacking Despite Not Hacking

#47
post #26

Earlier quoted context omitted.

I'd find a better case, for starters. The trade secret charge has the harshest penalty, and is independent of computer use. The conspiracy charge has the same maximum as the unauthorized network access charge. Someone who is an expert at the Federal Sentencing Guidelines will have to chime in with what that means for an eventual sentence, but I suspect that even if the computer violation were considered extremely min…

>I'd find a better case, for starters. I was responding to the general point. But as for finding a better case, the problem is that you don't get to pick which cases get prosecuted. If the parties have decided to appeal then a precedent is going to be set here one way or the other. So let him go to jail for what he actually did -- there is no reason to allow the CFAA charge to be piled on top of that and set a terrib…

Why is it OK to have a law against something as general as mail fraud, given that pretty much everyone has used the post at some time or another, but have no law at all regarding computer crimes?

I would understand arguing that CFAA in particular is overbroad but it's hard to claim it's being used in this case in a way that's inconsistent with the rest of the U.S. Code. In fact even the CFAA is more narrowly-focused than the aforementioned mail fraud law.

And that's what I mean by "finding a better case". This is simply not a suitable demonstration of stupendous overreach. Prosecutors pile charges on, that's what they do. They only get one trial to sort everything out and entire swaths of their case can be thrown out in one fell swoop so yes, they'll stick everything they feel they can prove on there.

Even with some theoretical replacement for CFAA that is more fair I would think that at least the authorized access using a co-conspirator's credentials would end up being a chargeable offense, so the difference here is with the remaining accesses that were made. And even those are hard to claim would be "authorized" access with a straight face, as why would any company authorize access to their networks for the purpose of industrial espionage?

Re: Man Convicted of Hacking Despite Not Hacking

#48

Earlier quoted context omitted.

It would be an awful lot easier to argue that. I'd need to go back and look up a bunch of cases which I don't feel like doing at present because it would be a large research project, but absent any specific computer-crime laws I'd argue that because a computer is a digital system and a digital system is just a complex agglomeration of switches, there's no qualitative difference between accessing a computer system and…

Is the intent of existing law considered as part of the concept of common law? Would the average member of the jury really not understand this? Why couldn't a prosecutor receive an indictment and then argue this before a court and jury and thereby develop the methodology to approach this problem. This process may require several cases but wouldn't that be preferable to have jurists extend common law rather than have…

Those are very good questions: the fact is that there is a huge amount of tension between the judicial and legislative branches, and within the judicial branch itself, about there the boundary between jduges' interpretation and reaasonable interpolation of teh law, and the text of statute as written. Conservative jurists like Justice Antonin Scalia think you should always go by the text of the law, and that it's dead wrong to consider legislative intent, no matter how obvious or well-documented it is/was; this approach (known as textualism) holds that if a law is no good, the correct remedy is for Congress to rewrite it. Judges should only dismiss a law as unconstitutional or go around it in cases where there is a clear and unambigious conflict between the Constitution and the statute. Other jurists, such as Justice Stephen Breyer, look at the Constitution as more of a framework document and think that you absolutely need to examine laws within the context in which they were passed and in the light of which problem they're intended to solve.

This is a very gnarly question, with good arguments on both sides - but in addition, there's a lot of unstated political baggage tied to both sides of the argument, so that what is on the surface a question of legal philosophy is on closer examination rooted in quite different philosophies of governance.

Now myself, I like the common-law approach and I would prefer a general class of crimes and that the details of individual cases be taken up by wise jurists. On the other hand, it's not a foregone conclusion that all judges are wise or selfless, and of course there might be judges who are both but who would come to quite different conclusions from me because they operate on a different moral calculus. So for the sake of consistency and predictability, there's a strong argument to have laws debated and promulgated by legislators rather than judges, so that anyone can do and look them up for guidance about what is and is not legal. Of course that involves some idealistic assumptions about legislators...

If you like high-density reading material, I strongly recommend How Judges Think by Judge Richard Posner.

Re: Man Convicted of Hacking Despite Not Hacking

#49

Earlier quoted context omitted.

I'm asking a specific yes/no question, not one about theft.

Would the charge be burglary for unauthorized access, or burglary if information was stolen after unauthorized access, and otherwise breaking and entering or just entering? To that, yes. If the information that was stolen was then used to commit other crimes, then other charges should follow as appropriate.

The former. burglary (in some places criminal trespass) is entry to premises with the intent of committing a crime [1]. Anyway we're on the same page, insofar as you're OK with extending existing law to cover virtual intrusions. See my other comment upthread, though.

1. The exact definition varies by state - in some places only residences can be burgled (but you can have criminal trespass on commercial premises) and now that I think of it burglary is usually defined as taking place during the night, whereas in the daytime the same crime would be breaking & entering, and so on.

Re: Man Convicted of Hacking Despite Not Hacking

#50
post #34

Earlier quoted context omitted.

You think I'm arguing something I'm not arguing. I'm not saying there aren't crimes that are chargeable under CFAA that could be better charged under a pre-existing law. I'm just saying there are crimes that can't be charged that way, thus the need for computer-specific crime laws. CFAA is not a good computer-specific crime law. Two gigantic problems with it: sentences that scale linearly with damages despite the fac…

I understand and I share your point of view to a degree, but I remain skeptical that until CFAA, there were no successful prosecutions for crimes that we are told are only now covered by CFAA. Computers and criminals have been around for a while now. I am also opposed to the idea that we need specific crime laws for things like this. What about vehicular manslaughter while listening to an iPod, and why would that not…

Before CFAA, computer crimes were charged under wire fraud statutes. But to prove wire fraud you have to establish the elements of a fraud, which include deliberate intent to secure some kind of gain from your deception.
Post reply on HN