Live data from Hacker News

US cybercrime laws being used to target security researchers

theguardian.com

11–20 of 94 posts

Re: US cybercrime laws being used to target security researchers

#11
post #6
post #3

Note that this concerns the subset of security research that involves actively talking to computer systems owned by other people, presumably in production, on the public Internet. Most security research does not in fact work this way. Consider, for instance, virtually any memory corruption vulnerability; while it was once straightforward (in the 90s) to work out an exploit "blind", today, researchers virtually always…

So should someone find a remote exploit in OpenWhatever that gives them remote root access and they publicly disclose that (without having tested it on the Internet... just in their lab) then they are not subject to the CFAA?

Correct. They are also probably (depending on circumstances) exempt from some provisions of the DMCA that might otherwise allow the research target to employ copyright law to stop them from conducting the research. US Federal Law has provisions that explicitly protect vulnerability research in some cases.

Re: US cybercrime laws being used to target security researchers

#12
post #6
post #3

Note that this concerns the subset of security research that involves actively talking to computer systems owned by other people, presumably in production, on the public Internet. Most security research does not in fact work this way. Consider, for instance, virtually any memory corruption vulnerability; while it was once straightforward (in the 90s) to work out an exploit "blind", today, researchers virtually always…

So should someone find a remote exploit in OpenWhatever that gives them remote root access and they publicly disclose that (without having tested it on the Internet... just in their lab) then they are not subject to the CFAA?

[deleted]

Re: US cybercrime laws being used to target security researchers

#13
post #3

Note that this concerns the subset of security research that involves actively talking to computer systems owned by other people, presumably in production, on the public Internet. Most security research does not in fact work this way. Consider, for instance, virtually any memory corruption vulnerability; while it was once straightforward (in the 90s) to work out an exploit "blind", today, researchers virtually always…

Google, Facebook, and now over 70 companies do grant tacit permission for anyone to test their systems, and will pay the researchers for a disclosure, as long as they follow the program rules, which are usually quite reasonable. I'm serious when I say that few people are more thankful than myself for the existence of security bug bounties.

However, one thing has always crossed my mind: since the legal definition of authorization is still very fuzzy, what stops a third party from going after a researcher, even though the company who owns the server which was technically hacked has no interest in filing any complaint against the researcher?

To clarify my question, the recent Brazilian law regarding computer hacking establishes that only the owner of the hacked computer can file a complaint against the attacker, and legal proceedings can commence only after such a complaint has been filed. Does it work the same way in the U.S.? My understanding of american law is very weak, but I know that, for some crimes, the victim does not have a say, i.e. the state will prosecute regardless of the victim's will.

Re: US cybercrime laws being used to target security researchers

#14
post #7

this is dumb on many layers - threatening white hat who could be held accountable but could be hired to do further audit; failing to come to grips that if you are insecure enough to threaten someone, you know - internet will find out that you rather than fixing holes in your system rather use expensive lawyers to intimidate people who on the whole trying to a good thing for you. The whole thing about unauthorized acc…

It in no way diminishes the effect of a crime if a person does not lock their front door. It is not the victim's fault if they did not install bulletproof glass and employ a security guard. If you think differently you have a twisted outlook on life, a sort of might-makes-right view of righteousness.

Such rationale is the rationale of a lowlife. "The front door was unlocked so its their fault I stole from them." "If they didn't want me to steal their lawnchair, they shouldn't have left it unchained on their porch." Nothing is inexcusable with that line of thinking. "If she didn't want to get raped, she shouldn't have been all alone in the middle of the night in a dark alleyway." "If he didn't want to get brutally assaulted, he shouldn't have left such a stupid comment on HN."

Re: US cybercrime laws being used to target security researchers

#15
post #6
post #3

Note that this concerns the subset of security research that involves actively talking to computer systems owned by other people, presumably in production, on the public Internet. Most security research does not in fact work this way. Consider, for instance, virtually any memory corruption vulnerability; while it was once straightforward (in the 90s) to work out an exploit "blind", today, researchers virtually always…

So should someone find a remote exploit in OpenWhatever that gives them remote root access and they publicly disclose that (without having tested it on the Internet... just in their lab) then they are not subject to the CFAA?

Correct.

The CFAA requires access without authorization or exceeding authorized access. Presumably you are an authorized user of your own systems.

It is possible that some vendors may try to use User Acceptance Licenses to further restrict what actions can be taken with their software (even in case where you've purchased it and installed it on your system).

I believe (and would love to be corrected by a lawyer), that even those cases would be civilly prosecuted, and still not related to the CFAA.

This is one of the reasons why when providing penetration testing/application testing training we always took great pains to drill into their heads to never use any of those techniques on systems you do not own. Not poking around on your bank's website, etc.

If you knowingly access a system that you do not have authorization for, the owner of the system might not care (or might not notice), but under the CFAA, they can file charges against you.

Reasonable people may disagree what constitutes "exceeding authorized access" (where reasonable people might be your attorney and a prosecutor).

Re: US cybercrime laws being used to target security researchers

#16
post #7

this is dumb on many layers - threatening white hat who could be held accountable but could be hired to do further audit; failing to come to grips that if you are insecure enough to threaten someone, you know - internet will find out that you rather than fixing holes in your system rather use expensive lawyers to intimidate people who on the whole trying to a good thing for you. The whole thing about unauthorized acc…

A better analogy would be someone entering your house if the door is left open, and then them shouting to see if someone is home or if they left for work - in view of closing the door for them.

Re: US cybercrime laws being used to target security researchers

#17
post #16
post #7

this is dumb on many layers - threatening white hat who could be held accountable but could be hired to do further audit; failing to come to grips that if you are insecure enough to threaten someone, you know - internet will find out that you rather than fixing holes in your system rather use expensive lawyers to intimidate people who on the whole trying to a good thing for you. The whole thing about unauthorized acc…

A better analogy would be someone entering your house if the door is left open, and then them shouting to see if someone is home or if they left for work - in view of closing the door for them.

And then someone called the police when they found someone random was in their house without authorization. And the intruder said "I was only there to shut the door for them."

Re: US cybercrime laws being used to target security researchers

#18
post #3

Note that this concerns the subset of security research that involves actively talking to computer systems owned by other people, presumably in production, on the public Internet. Most security research does not in fact work this way. Consider, for instance, virtually any memory corruption vulnerability; while it was once straightforward (in the 90s) to work out an exploit "blind", today, researchers virtually always…

Google, Facebook, and now over 70 companies do grant tacit permission for anyone to test their systems, and will pay the researchers for a disclosure, as long as they follow the program rules , which are usually quite reasonable. I'm serious when I say that few people are more thankful than myself for the existence of security bug bounties. However, one thing has always crossed my mind: since the legal definition of…

> only the owner of the hacked computer can file a complaint against the attacker, and legal proceedings can commence only after such a complaint has been filed. Does it work the same way in the U.S.?

After a US law enforcement agency has been notified of a complaint by a victim of a crime they forward it to a prosecutor. At this point the victim can no longer drop the charges. The only person who can drop the case then is the prosecuting lawyer. They occasionally do drop cases where it doesn't make sense anymore. But procescuters don't get 'cybercrime' cases very often and they often make headlines , especially these days, so I doubt many lawyers would voluntarily drop that opportunity for their resumes and work on the usual murder or drug trials instead.

Re: US cybercrime laws being used to target security researchers

#19
post #7

this is dumb on many layers - threatening white hat who could be held accountable but could be hired to do further audit; failing to come to grips that if you are insecure enough to threaten someone, you know - internet will find out that you rather than fixing holes in your system rather use expensive lawyers to intimidate people who on the whole trying to a good thing for you. The whole thing about unauthorized acc…

It in no way diminishes the effect of a crime if a person does not lock their front door. It is not the victim's fault if they did not install bulletproof glass and employ a security guard. If you think differently you have a twisted outlook on life, a sort of might-makes-right view of righteousness. Such rationale is the rationale of a lowlife. "The front door was unlocked so its their fault I stole from them." "If…

Agreed. You don't get a pass for breaking into someone's house just because you say you weren't there to cause any harm. Yes, it's good to be pragmatic and understand that there's always something the owner of the house could have done to help prevent the break in -- close the door, lock them, get locks that are harder to pick, install security cameras, etc. etc. -- but the person breaking into your house is still wrong for doing so, even if they claim they just wanted to tell you about the weaknesses of your house's security. I don't see any reason the same reasoning shouldn't apply to digital property.

Re: US cybercrime laws being used to target security researchers

#20

Call your congress critter, form a PAC, and elected one of your own. If you are in a gerrymandered district, join the party that controls that district, and primary the congress critter out.

Take your rational thinking elsewhere. This is the Internet.
Post reply on HN