Live data from Hacker News

US cybercrime laws being used to target security researchers

theguardian.com

71–80 of 94 posts

Re: US cybercrime laws being used to target security researchers

#71
I disagree with people who are drawing direct analogies between someone breaking into your property to test its security and cyber security pen-testing. To me, it's more like giving your money to a bank for safe keeping with the understanding they will protect it, and then wanting to test they are actually fulfilling their promise (e.g. by going to the bank and checking they have solid thick walls, and that entry to the vault is guarded properly). Even that's not a direct analogy, as you'll likely be compensated if the bank loses your money, but you'll rarely be compensated when your personal information is disclosed. I also think there are some interesting questions raised by cloud computing. What if I were to deploy a purposefully insecure honeypot VM or application to the cloud, and an attacker managed to use that to mount an attack on other applications?

Re: US cybercrime laws being used to target security researchers

#72
post #38

Earlier quoted context omitted.

How would you feel if I broke into your place of business, made a list of all of the things you were doing that were out of compliance with federal and state laws and regulations, then left you my card and offered to let you hire me to do legal compliance work for you?

"Broke in" rather presupposes the point. If we're analogizing, an exterminator seeing rat droppings in your restaurant and offering to solve your problem rather than letting the department of health deal with it, is a slightly more realistic example.

Legally, pushing open a closed door is "breaking in." It's precisely how a lawyer would describe someone who opened the door to your business to come in and look around for stuff.

Re: US cybercrime laws being used to target security researchers

#73
post #70
post #67

Earlier quoted context omitted.

Judges and juries aren't ignorant. They just don't give a shit about the things that are important to you. To your typical juror off the street, "hacking" into a computer for ostensibly "white hat" reasons is no different than breaking into a store to "test the alarm system." The reaction is not "oh yes, we have to make sure our legal system is flexible enough to accommodate this sort of 'security research'" but rath…

To your typical juror off the street, "hacking" into a computer for ostensibly "white hat" reasons is no different than breaking into a store to "test the alarm system." That sounds a lot like ignorance.

Because there is an obvious difference between "understanding of the facts of a case" and "different value systems used to evaluate those facts", the ignorance here might be in your assertion.

Re: US cybercrime laws being used to target security researchers

#74
post #61

Earlier quoted context omitted.

> If you're deploying something you know has vulnerabilities ... Everything has vulnerabilities.

Would "something with known vulnerabilities" be better? Does everything have known vulnerabilities that are not actively being worked on?

Lots of things are vulnerable to DoS attacks in a multitude of ways. Depending on the business, it's not uncommon to just say "we'll deal with it when it happens."

But, someone asks, what if the business is really really important? Then that's all the more reason to not mess with it.

Re: US cybercrime laws being used to target security researchers

#75
post #70
post #67

Earlier quoted context omitted.

Judges and juries aren't ignorant. They just don't give a shit about the things that are important to you. To your typical juror off the street, "hacking" into a computer for ostensibly "white hat" reasons is no different than breaking into a store to "test the alarm system." The reaction is not "oh yes, we have to make sure our legal system is flexible enough to accommodate this sort of 'security research'" but rath…

To your typical juror off the street, "hacking" into a computer for ostensibly "white hat" reasons is no different than breaking into a store to "test the alarm system." That sounds a lot like ignorance.

[deleted]

Re: US cybercrime laws being used to target security researchers

#76
post #67
post #64

Earlier quoted context omitted.

There is something really disturbing about a system that allows personal ambition to play such an important role in how the institution of justice operates in effect, at least in specialised matters like this. Expensive attorneys and ambitious prosecutors, each trying to twist half-truths to, more or less, ignorant judges and jurys. Makes me wonder if some of these servants of justice are forgetting that, their speci…

Judges and juries aren't ignorant. They just don't give a shit about the things that are important to you. To your typical juror off the street, "hacking" into a computer for ostensibly "white hat" reasons is no different than breaking into a store to "test the alarm system." The reaction is not "oh yes, we have to make sure our legal system is flexible enough to accommodate this sort of 'security research'" but rath…

But they should give a shit before they can pass judgement, because they're not important just to me and because there are actual victims involved (which might be different than the accusants).

What if no private data were actually accessed, let's say if the researcher only compromised his own account.

Or about the case that he hacked a device that he bought, violating the Acceptable Use Policy of the producer.

Or the case where someone automated the retrieval of data that he already had legally access to, like, if I recall correctly, Aaron Swartz.

All these examples are unique and would fail any physical-world analogies, so they should be examined and judged differently, by people that do give a shit, want to take the effort to understand their unique aspects -and are actually able to. I'm not sure if that's the case.

My general point is about how we found ourselves in a system where justice servants, like prosecutors, appear to treat their job "just like any job" (at least in cases that they might consider abstract -"hacking", less clear and direct effects than "murder"), where they can put their careers first and ignore any consequences to others. Or that someone has to bear enormous defense costs to stand a chance, or be coerced to plead guilty or abstain from exercising what should be his right, out of fear of finding himself involved in such a situation.

Re: US cybercrime laws being used to target security researchers

#77
post #76
post #67

Earlier quoted context omitted.

Judges and juries aren't ignorant. They just don't give a shit about the things that are important to you. To your typical juror off the street, "hacking" into a computer for ostensibly "white hat" reasons is no different than breaking into a store to "test the alarm system." The reaction is not "oh yes, we have to make sure our legal system is flexible enough to accommodate this sort of 'security research'" but rath…

But they should give a shit before they can pass judgement, because they're not important just to me and because there are actual victims involved (which might be different than the accusants). What if no private data were actually accessed, let's say if the researcher only compromised his own account. Or about the case that he hacked a device that he bought, violating the Acceptable Use Policy of the producer. Or th…

The whole point of juries is for them to judge you against the norms of society at large. The fact that a small group of people might be operating under different norms is irrelevant. They don't have to understand your values in order to judge you. All they need to understand are the facts and the law.

The prevailing norm is that property rights are sacrosanct, and any invasion of those rights is considered suspicious and explanations about benevolent intent are disbelieved. There is no general right to "tinker" with other peoples' property without permission, for fun, for research, or for any other reason. We are not a society that requires security measures to be effective in order to serve as a signal to keep out. A velvet rope is as effective as a steel door for the purposes of signaling that access is not allowed.

This is not a matter of prosecutors putting their careers ahead of the spirit of the law. It's about hackers not understanding that we're a society that requires you to keep your hands to yourself.

NB: I have a beef with the CFAA, but it's not with the spirit of the law, but rather the fact that criminal penalties under the CFAA are totally out of line with those in analogous physical scenarios. The standards for trespass on digital networks shouldn't be higher than the standards for trespass in the physical world. But juries can't do anything about this problem, and judges really can't either. It's Congress's problem for putting the felony escalation provision in there.

Re: US cybercrime laws being used to target security researchers

#78
post #77
post #76

Earlier quoted context omitted.

But they should give a shit before they can pass judgement, because they're not important just to me and because there are actual victims involved (which might be different than the accusants). What if no private data were actually accessed, let's say if the researcher only compromised his own account. Or about the case that he hacked a device that he bought, violating the Acceptable Use Policy of the producer. Or th…

The whole point of juries is for them to judge you against the norms of society at large. The fact that a small group of people might be operating under different norms is irrelevant. They don't have to understand your values in order to judge you. All they need to understand are the facts and the law. The prevailing norm is that property rights are sacrosanct, and any invasion of those rights is considered suspiciou…

Researches that trespass a digital network aren't the only ones who are affected, though. Let's say, a quote from the OP article:

"Lanier said that after finding severe vulnerabilities in an unnamed “embedded device marketed towards children” and reporting them to the manufacturer, he received calls from lawyers threatening him with action. [...] As is often the case with CFAA things when they go to court, the lawyers and even sometimes the technical people or business people don't understand what it is you actually did. There were claims that we were 'hacking into their systems'.

The threat of a CFAA prosecution forced Lanier and his team to walk away from the research."

Re: US cybercrime laws being used to target security researchers

#79
post #78
post #77

Earlier quoted context omitted.

The whole point of juries is for them to judge you against the norms of society at large. The fact that a small group of people might be operating under different norms is irrelevant. They don't have to understand your values in order to judge you. All they need to understand are the facts and the law. The prevailing norm is that property rights are sacrosanct, and any invasion of those rights is considered suspiciou…

Researches that trespass a digital network aren't the only ones who are affected, though. Let's say, a quote from the OP article: "Lanier said that after finding severe vulnerabilities in an unnamed “embedded device marketed towards children” and reporting them to the manufacturer, he received calls from lawyers threatening him with action. [...] As is often the case with CFAA things when they go to court, the lawyer…

There's nothing to that anecdote other than a company getting mad about exposing defects in a product and their lawyer making a nasty phone call.

The CFAA is vague and over-broad, you won't get any disagreement from me on that. Applying it in a case involving a device you bought and own is totally inconsistent with traditional norms of private property. But those are edge cases. The actual prosecutions people get up in arms about aren't edge cases. They pertain to conduct that clearly violates the norms of trespassing on private property, and hackers justify their actions by saying that those norms shouldn't apply to digital networks. Juries, unsurprisingly, don't buy that. So hackers and the broader tech community call them "ignorant."

Re: US cybercrime laws being used to target security researchers

#80
post #79
post #78

Earlier quoted context omitted.

Researches that trespass a digital network aren't the only ones who are affected, though. Let's say, a quote from the OP article: "Lanier said that after finding severe vulnerabilities in an unnamed “embedded device marketed towards children” and reporting them to the manufacturer, he received calls from lawyers threatening him with action. [...] As is often the case with CFAA things when they go to court, the lawyer…

There's nothing to that anecdote other than a company getting mad about exposing defects in a product and their lawyer making a nasty phone call. The CFAA is vague and over-broad, you won't get any disagreement from me on that. Applying it in a case involving a device you bought and own is totally inconsistent with traditional norms of private property. But those are edge cases. The actual prosecutions people get up…

You've also got the Sony VS Hotz lawsuit, where Hotz was forced to back-off. Edge cases, maybe, but demonstrate that not everybody draws the line at the same place.

For you, someone finding a vulnerability in the software that provides a network service, hosted in some server he doesn't own, is clearly trespassing private property -even if he only accesses his own account's data- but finding a vulnerability in the software that comes bundled on a device he bought, is not.

For Sony, let's say, both constitutes violations of her property -it's her software, she owns it and she doesn't care if the carrier is her server or the device she just sold you. In both cases she only gives you permission to use her software in a certain way, which excludes any sort of hacking.

Maybe the reason that many draw the line to the medium, is because it is easier to visually compare a computer network to a physical property than a device that you have bought (but has data you don't own)?

But is the physical ownership of the medium that carries the data what matters or the ownership of the actual data that are being accessed? If it's the medium, why, when the really important thing that the owner cares to protect is, in almost all cases, the data?

Not trying to argue, just expressing some questions that I think are tricky and deserve more thought than they get. In any case, I think physical and digital property analogies can only take us that far, so I try to keep clear of them.

Post reply on HN