Note that this concerns the subset of security research that involves actively talking to computer systems owned by other people, presumably in production, on the public Internet. Most security research does not in fact work this way. Consider, for instance, virtually any memory corruption vulnerability; while it was once straightforward (in the 90s) to work out an exploit "blind", today, researchers virtually always…
So should someone find a remote exploit in OpenWhatever that gives them remote root access and they publicly disclose that (without having tested it on the Internet... just in their lab) then they are not subject to the CFAA?
US cybercrime laws being used to target security researchers
11–20 of 94 posts
Re: US cybercrime laws being used to target security researchers
#12Note that this concerns the subset of security research that involves actively talking to computer systems owned by other people, presumably in production, on the public Internet. Most security research does not in fact work this way. Consider, for instance, virtually any memory corruption vulnerability; while it was once straightforward (in the 90s) to work out an exploit "blind", today, researchers virtually always…
So should someone find a remote exploit in OpenWhatever that gives them remote root access and they publicly disclose that (without having tested it on the Internet... just in their lab) then they are not subject to the CFAA?
Re: US cybercrime laws being used to target security researchers
#13Note that this concerns the subset of security research that involves actively talking to computer systems owned by other people, presumably in production, on the public Internet. Most security research does not in fact work this way. Consider, for instance, virtually any memory corruption vulnerability; while it was once straightforward (in the 90s) to work out an exploit "blind", today, researchers virtually always…
However, one thing has always crossed my mind: since the legal definition of authorization is still very fuzzy, what stops a third party from going after a researcher, even though the company who owns the server which was technically hacked has no interest in filing any complaint against the researcher?
To clarify my question, the recent Brazilian law regarding computer hacking establishes that only the owner of the hacked computer can file a complaint against the attacker, and legal proceedings can commence only after such a complaint has been filed. Does it work the same way in the U.S.? My understanding of american law is very weak, but I know that, for some crimes, the victim does not have a say, i.e. the state will prosecute regardless of the victim's will.
Re: US cybercrime laws being used to target security researchers
#14this is dumb on many layers - threatening white hat who could be held accountable but could be hired to do further audit; failing to come to grips that if you are insecure enough to threaten someone, you know - internet will find out that you rather than fixing holes in your system rather use expensive lawyers to intimidate people who on the whole trying to a good thing for you. The whole thing about unauthorized acc…
Such rationale is the rationale of a lowlife. "The front door was unlocked so its their fault I stole from them." "If they didn't want me to steal their lawnchair, they shouldn't have left it unchained on their porch." Nothing is inexcusable with that line of thinking. "If she didn't want to get raped, she shouldn't have been all alone in the middle of the night in a dark alleyway." "If he didn't want to get brutally assaulted, he shouldn't have left such a stupid comment on HN."
Re: US cybercrime laws being used to target security researchers
#15Note that this concerns the subset of security research that involves actively talking to computer systems owned by other people, presumably in production, on the public Internet. Most security research does not in fact work this way. Consider, for instance, virtually any memory corruption vulnerability; while it was once straightforward (in the 90s) to work out an exploit "blind", today, researchers virtually always…
So should someone find a remote exploit in OpenWhatever that gives them remote root access and they publicly disclose that (without having tested it on the Internet... just in their lab) then they are not subject to the CFAA?
The CFAA requires access without authorization or exceeding authorized access. Presumably you are an authorized user of your own systems.
It is possible that some vendors may try to use User Acceptance Licenses to further restrict what actions can be taken with their software (even in case where you've purchased it and installed it on your system).
I believe (and would love to be corrected by a lawyer), that even those cases would be civilly prosecuted, and still not related to the CFAA.
This is one of the reasons why when providing penetration testing/application testing training we always took great pains to drill into their heads to never use any of those techniques on systems you do not own. Not poking around on your bank's website, etc.
If you knowingly access a system that you do not have authorization for, the owner of the system might not care (or might not notice), but under the CFAA, they can file charges against you.
Reasonable people may disagree what constitutes "exceeding authorized access" (where reasonable people might be your attorney and a prosecutor).
Re: US cybercrime laws being used to target security researchers
#16this is dumb on many layers - threatening white hat who could be held accountable but could be hired to do further audit; failing to come to grips that if you are insecure enough to threaten someone, you know - internet will find out that you rather than fixing holes in your system rather use expensive lawyers to intimidate people who on the whole trying to a good thing for you. The whole thing about unauthorized acc…
Re: US cybercrime laws being used to target security researchers
#17this is dumb on many layers - threatening white hat who could be held accountable but could be hired to do further audit; failing to come to grips that if you are insecure enough to threaten someone, you know - internet will find out that you rather than fixing holes in your system rather use expensive lawyers to intimidate people who on the whole trying to a good thing for you. The whole thing about unauthorized acc…
A better analogy would be someone entering your house if the door is left open, and then them shouting to see if someone is home or if they left for work - in view of closing the door for them.
Re: US cybercrime laws being used to target security researchers
#18Note that this concerns the subset of security research that involves actively talking to computer systems owned by other people, presumably in production, on the public Internet. Most security research does not in fact work this way. Consider, for instance, virtually any memory corruption vulnerability; while it was once straightforward (in the 90s) to work out an exploit "blind", today, researchers virtually always…
Google, Facebook, and now over 70 companies do grant tacit permission for anyone to test their systems, and will pay the researchers for a disclosure, as long as they follow the program rules , which are usually quite reasonable. I'm serious when I say that few people are more thankful than myself for the existence of security bug bounties. However, one thing has always crossed my mind: since the legal definition of…
After a US law enforcement agency has been notified of a complaint by a victim of a crime they forward it to a prosecutor. At this point the victim can no longer drop the charges. The only person who can drop the case then is the prosecuting lawyer. They occasionally do drop cases where it doesn't make sense anymore. But procescuters don't get 'cybercrime' cases very often and they often make headlines , especially these days, so I doubt many lawyers would voluntarily drop that opportunity for their resumes and work on the usual murder or drug trials instead.
Re: US cybercrime laws being used to target security researchers
#19this is dumb on many layers - threatening white hat who could be held accountable but could be hired to do further audit; failing to come to grips that if you are insecure enough to threaten someone, you know - internet will find out that you rather than fixing holes in your system rather use expensive lawyers to intimidate people who on the whole trying to a good thing for you. The whole thing about unauthorized acc…
It in no way diminishes the effect of a crime if a person does not lock their front door. It is not the victim's fault if they did not install bulletproof glass and employ a security guard. If you think differently you have a twisted outlook on life, a sort of might-makes-right view of righteousness. Such rationale is the rationale of a lowlife. "The front door was unlocked so its their fault I stole from them." "If…
Re: US cybercrime laws being used to target security researchers
#20Call your congress critter, form a PAC, and elected one of your own. If you are in a gerrymandered district, join the party that controls that district, and primary the congress critter out.