Live data from Hacker News

US cybercrime laws being used to target security researchers

theguardian.com

51–60 of 94 posts

Re: US cybercrime laws being used to target security researchers

#51
post #47

Earlier quoted context omitted.

It makes me wonder who actually likes the CFAA the way it is. Does anybody? I don't see how it's helping anybody. Most of the actually malicious computer intrusions come from outside of U.S. jurisdiction. It's like trying to reduce child labor in China by increasing the breadth of the offense and severity of the penalties in Texas. The next thing you know nothing has changed in China but a father in Texas is facing f…

The CFAA exists because during the 1980s, there was a concern that no existing statute would deter purely malicious attacks on systems, or any other attack that didn't fit the narrow definition of wire fraud. I actually do not have a problem with the CFAA's statutory prohibitions on unauthorized access. They seem eminently sensible to me. Don't mess with systems that don't belong to you. I do think the CFAA has a gra…

I agree that significantly reducing the penalties under the CFAA would mitigate almost all of the damage it causes, but I don't see how that makes the language any better. It just limits the damage.

"Don't mess with systems that don't belong to you" worked much better in 1980 when typical computers cost a million dollars and were only expected to be used by the employees of the bank or government that owned them, because in that context you know you're authorized when you file a W2 and are issued a security badge.

Once you put systems on the internet for access by the general public it changes everything. "Mess with systems that don't belong to you" is practically the definition of The Cloud. The defining question is no longer who is authorized, because everybody is authorized, so the question becomes what everybody is authorized to do.

The problem is that nobody has any idea what that means in practice. All we can do is make some wild guesses -- maybe SQL injection against random servers of unsuspecting third parties is unauthorized access whereas typing "google.com" into a web browser without prior written permission from Google, Inc. is not. But what about changing your useragent string to Googlebot? What if that will bypass a paywall? What if that will bypass a paywall, but you're a web spider like the real Googlebot? What if you demonstrate a buffer overrun against the web host you use in order to prove their breach of a contract to keep the server patched? Can you charge a journalist for reading a company's internal documents when the company made its intranet server accessible to the internet without any authentication?

The answers to these questions depend primarily on which judge is deciding the case. Which is ridiculous, and the hallmark of a bad piece of legislation.

Re: US cybercrime laws being used to target security researchers

#52
post #27

Earlier quoted context omitted.

Does it really only turn in one direction, though? I hear that kind of talk a lot, usually about taxes and government programs. It seems incredibly depressing, for one thing. It's fundamentally saying that you can never win, just delay the inevitable loss. Fortunately, it doesn't seem to be true, whether it's taxes or computers. Computers might be getting squeezed a bit now, but there have been far worse periods, fol…

I think my favorite example of things going the other way was when we more or less won the battle on export control laws which restricted the distribution of cryptography.

I momentarily forgot about that! You're right, though. Netscape International Edition, with 40-bit crypto for SSL. Good times.

Re: US cybercrime laws being used to target security researchers

#53
post #7

this is dumb on many layers - threatening white hat who could be held accountable but could be hired to do further audit; failing to come to grips that if you are insecure enough to threaten someone, you know - internet will find out that you rather than fixing holes in your system rather use expensive lawyers to intimidate people who on the whole trying to a good thing for you. The whole thing about unauthorized acc…

It in no way diminishes the effect of a crime if a person does not lock their front door. It is not the victim's fault if they did not install bulletproof glass and employ a security guard. If you think differently you have a twisted outlook on life, a sort of might-makes-right view of righteousness. Such rationale is the rationale of a lowlife. "The front door was unlocked so its their fault I stole from them." "If…

Where I come from it does. The police will blame the victim if they left their door unlocked and got burgled. Also, insurance will sometimes won't pay out.

Re: US cybercrime laws being used to target security researchers

#54
A fundamental difference between online "property" and physical property is that you can never fully protect physical property. Build a stronger wall and someone can use a bigger bulldozer to break it. But build a secure website and you might find that it doesn't get hacked no matter the resources of the hacker. If it does, you have plans to limit the effects.

I wonder if people are so busy rushing to do things online they don't want to pay the cost of strong security, so they let themselves be vulnerable and need laws to protect them. As a few people have said, foreign government hackers aren't bound by such laws and even they can't get in to many sites.

If we stop seeing hackers as guilty people to blame, and think of them as an unavoidable natural presence on the internet, just like data corruption or power failures, then we won't need laws, instead we'll need safety standards and licenses for IT workers just as we do for, say gas plumbers.

Every day, spammers "hack" my web forum by solving the captcha. I don't want to find them and send them to prison. I want to build better defenses to prevent them doing it.

Re: US cybercrime laws being used to target security researchers

#55
post #47

Earlier quoted context omitted.

The CFAA exists because during the 1980s, there was a concern that no existing statute would deter purely malicious attacks on systems, or any other attack that didn't fit the narrow definition of wire fraud. I actually do not have a problem with the CFAA's statutory prohibitions on unauthorized access. They seem eminently sensible to me. Don't mess with systems that don't belong to you. I do think the CFAA has a gra…

I agree that significantly reducing the penalties under the CFAA would mitigate almost all of the damage it causes, but I don't see how that makes the language any better. It just limits the damage. "Don't mess with systems that don't belong to you" worked much better in 1980 when typical computers cost a million dollars and were only expected to be used by the employees of the bank or government that owned them, bec…

Well, the Weev case showed that accessing unsecured data that doesn't belong to you is punishable under the law.

He was released on appeal over a jurisdictional issue, not a statue or misapplication of the law.

Re: US cybercrime laws being used to target security researchers

#56
post #26

Earlier quoted context omitted.

Which parallels white hats getting arrested for legitimate security research. Hence my analogy stands.

Yes, your analogy does stand. And it stands to reason that the intruder should be punished, and/or sued, for trespass. It is not a legitimate reason to be in someone else's house. Going around trying to open everyone's doors is a similar analogy to some other security research. And while its not as clear-cut, in fact arguably not a commonly cognizable crime, it certainly is suspicious and its reasonable for law enfor…

So if I suspect that someone else will steal from a house if the door is left open, (And I have strong evidence for this)

And I see that the door is significantly ajar (one can see valuables through the open door)

And the house appears to be empty,

And the doorway is flush against the sidewalk, where I am walking by on my way somewhere else (the door opens inwards and is not in my way)

If I knock on the door (holding it so as to not make it swing inwards further and hit the wall) and ask if anyone is there,

And recieving no responce, close the door,

I should be punished?!?

If I see someone injured and unconcious on a sidewalk, should I just walk around them in order to avoid infringing on their personal space?

What if I have relevant medical experience?

Am I to let them lie there?

If someone (a stranger) is unconscious from drinking alcohol to excess, and is lying on their back, am I to refrain from turning them on their side, and instead allow them to choke on their own vomit and die, so to avoid running afoul of laws intended to protect against pickpockets?

If someone has a problem and is in danger of significant loss, but is unaware of it, and I am unable to inform them of it, but I am able to easily lessen the danger, at no cost to them or any other person, through an interaction that bears some similarity with some action that would be reasonable to forbid due to causing harm, Should I not help that person simply due to that similarity?

Edit:

It's possible that I misunderstood what was said somewhat. I'm not sure.

Re: US cybercrime laws being used to target security researchers

#57

Earlier quoted context omitted.

I agree that significantly reducing the penalties under the CFAA would mitigate almost all of the damage it causes, but I don't see how that makes the language any better. It just limits the damage. "Don't mess with systems that don't belong to you" worked much better in 1980 when typical computers cost a million dollars and were only expected to be used by the employees of the bank or government that owned them, bec…

Well, the Weev case showed that accessing unsecured data that doesn't belong to you is punishable under the law. He was released on appeal over a jurisdictional issue, not a statue or misapplication of the law.

> He was released on appeal over a jurisdictional issue, not a statue or misapplication of the law.

This is actually why we don't know anything from that case. District court rulings aren't binding on other courts and the appellate court apparently threw out the case without ruling on the CFAA, so there was no precedent created either way.

But if the appellate court had ruled the same way as the district court and created that precedent, I don't think you could reasonably describe that as an improvement in the CFAA situation.

Re: US cybercrime laws being used to target security researchers

#58
post #43
post #38

Earlier quoted context omitted.

How would you feel if I broke into your place of business, made a list of all of the things you were doing that were out of compliance with federal and state laws and regulations, then left you my card and offered to let you hire me to do legal compliance work for you?

If it was well known that large and highly funded subsets of foreign militaries were roaming around breaking into everyones businesses and stealing things / exploiting the lack of legal compliance then, yes, I'd be very pleased that someone took the time to both find the mistake and give me the chance to fix it / get it fixed by them before it was used against me with legitimate malicious intent.

There actually are real-life burglars. That isn't hypothetical. Would you really grant people permission to burglarize your business to demonstrate its susceptibility to burglary?

Re: US cybercrime laws being used to target security researchers

#59
post #38

Earlier quoted context omitted.

"...testing deployed systems without authorization is always risky..." While what you describe may be the sad reality, it makes zero sense. If a legit researcher, 'specially one that's being transparent about it, researches any domestic system, then that's got to be better than the Iranians, Russians or Chinese doing it (which they do anyway). But hey, what do we know anyway. There's probably some benefit that makes…

How would you feel if I broke into your place of business, made a list of all of the things you were doing that were out of compliance with federal and state laws and regulations, then left you my card and offered to let you hire me to do legal compliance work for you?

"Broke in" rather presupposes the point.

If we're analogizing, an exterminator seeing rat droppings in your restaurant and offering to solve your problem rather than letting the department of health deal with it, is a slightly more realistic example.

Re: US cybercrime laws being used to target security researchers

#60
post #38

Earlier quoted context omitted.

"...testing deployed systems without authorization is always risky..." While what you describe may be the sad reality, it makes zero sense. If a legit researcher, 'specially one that's being transparent about it, researches any domestic system, then that's got to be better than the Iranians, Russians or Chinese doing it (which they do anyway). But hey, what do we know anyway. There's probably some benefit that makes…

How would you feel if I broke into your place of business, made a list of all of the things you were doing that were out of compliance with federal and state laws and regulations, then left you my card and offered to let you hire me to do legal compliance work for you?

That's not quite a fair analogy. It'd be more like if you go into a bank and see a giant hole in their vault. You tell them about it and they sue you for breaking it. Meanwhile actual criminals come and go as they please anonymously. The bank's clients are the actual victims of course, it's not like this just affects the bankers.
Post reply on HN