Live data from Hacker News

US cybercrime laws being used to target security researchers

theguardian.com

81–90 of 94 posts

Re: US cybercrime laws being used to target security researchers

#81
post #80
post #79

Earlier quoted context omitted.

There's nothing to that anecdote other than a company getting mad about exposing defects in a product and their lawyer making a nasty phone call. The CFAA is vague and over-broad, you won't get any disagreement from me on that. Applying it in a case involving a device you bought and own is totally inconsistent with traditional norms of private property. But those are edge cases. The actual prosecutions people get up…

You've also got the Sony VS Hotz lawsuit, where Hotz was forced to back-off. Edge cases, maybe, but demonstrate that not everybody draws the line at the same place. For you, someone finding a vulnerability in the software that provides a network service, hosted in some server he doesn't own, is clearly trespassing private property -even if he only accesses his own account's data- but finding a vulnerability in the so…

Sony vs. George Hotz was a civil case in which the CFAA played a small role compared to the numerous other statutes invoked, and that case ended in a settlement.

What we are talking about in this thread is the supposed criminalization of security research. If you're trying to get someone to take the other side of the argument that security research is needlessly legally risky, you're probably not going to find many takers. There is a world of difference, however, between being sued and being imprisoned.

Re: US cybercrime laws being used to target security researchers

#82
post #38

Earlier quoted context omitted.

How would you feel if I broke into your place of business, made a list of all of the things you were doing that were out of compliance with federal and state laws and regulations, then left you my card and offered to let you hire me to do legal compliance work for you?

That's not quite a fair analogy. It'd be more like if you go into a bank and see a giant hole in their vault. You tell them about it and they sue you for breaking it. Meanwhile actual criminals come and go as they please anonymously. The bank's clients are the actual victims of course, it's not like this just affects the bankers.

No, you've misread the story. Nobody is being threatened simply for observing vulnerabilities. Instead, people are discovering vulnerabilities in popular software, and then exploiting them across thousands of machines to "prove" something everyone already knows: lots of people are vulnerable.

Re: US cybercrime laws being used to target security researchers

#83
post #3

Note that this concerns the subset of security research that involves actively talking to computer systems owned by other people, presumably in production, on the public Internet. Most security research does not in fact work this way. Consider, for instance, virtually any memory corruption vulnerability; while it was once straightforward (in the 90s) to work out an exploit "blind", today, researchers virtually always…

So what happens when the NSA does it without permission and keeps discovered vulnerabilities secret?

Is this setting up a precedent?

Re: US cybercrime laws being used to target security researchers

#84
post #80
post #79

Earlier quoted context omitted.

There's nothing to that anecdote other than a company getting mad about exposing defects in a product and their lawyer making a nasty phone call. The CFAA is vague and over-broad, you won't get any disagreement from me on that. Applying it in a case involving a device you bought and own is totally inconsistent with traditional norms of private property. But those are edge cases. The actual prosecutions people get up…

You've also got the Sony VS Hotz lawsuit, where Hotz was forced to back-off. Edge cases, maybe, but demonstrate that not everybody draws the line at the same place. For you, someone finding a vulnerability in the software that provides a network service, hosted in some server he doesn't own, is clearly trespassing private property -even if he only accesses his own account's data- but finding a vulnerability in the so…

[deleted]

Re: US cybercrime laws being used to target security researchers

#85
post #80
post #79

Earlier quoted context omitted.

There's nothing to that anecdote other than a company getting mad about exposing defects in a product and their lawyer making a nasty phone call. The CFAA is vague and over-broad, you won't get any disagreement from me on that. Applying it in a case involving a device you bought and own is totally inconsistent with traditional norms of private property. But those are edge cases. The actual prosecutions people get up…

You've also got the Sony VS Hotz lawsuit, where Hotz was forced to back-off. Edge cases, maybe, but demonstrate that not everybody draws the line at the same place. For you, someone finding a vulnerability in the software that provides a network service, hosted in some server he doesn't own, is clearly trespassing private property -even if he only accesses his own account's data- but finding a vulnerability in the so…

Apologies for drifting the thread out of the CFAA scope, I was never specifically referring to CFAA to be honest -sorry if it seemed that I was.

Re: US cybercrime laws being used to target security researchers

#86
post #73
post #70

Earlier quoted context omitted.

To your typical juror off the street, "hacking" into a computer for ostensibly "white hat" reasons is no different than breaking into a store to "test the alarm system." That sounds a lot like ignorance.

Because there is an obvious difference between "understanding of the facts of a case" and "different value systems used to evaluate those facts", the ignorance here might be in your assertion.

You don't think the supposed difference in values is the result of ignorance of how the internet works? Or what a security researcher does? Or that security researchers exist as a hobby and profession? Or that the security of the internet at large depends on people who do this? That the every-other-month theft of giant numbers of credit cards or passwords can be prevented if white hat hackers find the security hole first? I would expect most people don't know that big companies like Facebook or Google offer bounties to people who find exploits, or that bugs that threaten the entire internet are routinely found by people who donate their time in order to protect people they don't even know, and who don't know they exist.

The facts of the case: someone broke into a computer system without permission.

The inability to interpret those facts in the light of what a security researcher does isn't a result of different values, but a lack of knowledge of the context. People who don't know how computers or the internet work are open to being told whatever story the prosecution decides to spin.

Edit: I think the ignorance is actually made clear by the example in the GP. Imagine some good Samaritan is walking past a jewelry store after closing time. They notice that the front door is ajar, and upon testing they find that the alarm doesn't go off when they enter the store. So they call the owners and wait in the store until the owner can get there and make sure the store is secure.

Do you think it's likely that this person would be prosecuted? Or, if they were, that the prosecutors and judge would throw the book at them to "make an example"? People understand that scenario and are likely to treat it with leniency in a way that they don't understand the equivalent scenario in computing.

P.S., Always a pleasure to be slapped down by tptacek :)

Re: US cybercrime laws being used to target security researchers

#87
post #86
post #73

Earlier quoted context omitted.

Because there is an obvious difference between "understanding of the facts of a case" and "different value systems used to evaluate those facts", the ignorance here might be in your assertion.

You don't think the supposed difference in values is the result of ignorance of how the internet works? Or what a security researcher does? Or that security researchers exist as a hobby and profession? Or that the security of the internet at large depends on people who do this? That the every-other-month theft of giant numbers of credit cards or passwords can be prevented if white hat hackers find the security hole f…

They notice that the front door is ajar

But most likely a security researcher will fire off some multiple of a thousand probes to see if the door is open. Collateral damage is likely. This is not what is happening in your jewelry store door case.

That the every-other-month theft of giant numbers of credit cards or passwords can be prevented: These things can be prevented by the folks in charge paying attention to the alarms going off in the back.

Re: US cybercrime laws being used to target security researchers

#88

I disagree with people who are drawing direct analogies between someone breaking into your property to test its security and cyber security pen-testing. To me, it's more like giving your money to a bank for safe keeping with the understanding they will protect it, and then wanting to test they are actually fulfilling their promise (e.g. by going to the bank and checking they have solid thick walls, and that entry to…

There seems to be a fundamental disagreement about the correct analogy.

Is it akin to going to a bank during normal business hours and using lawful powers of observation, i.e., implicitly authorized? Or is akin to breaking into the bank after its closed, or otherwise violating some implicit lack of authorization, e.g., going somewhere off-limits, such as trying to secretly enter the vault?

Because I think you'll recognize the inherit danger of allowing people to willy-nilly try and break into banks to "test they are actually fulfilling their promise".

Re: US cybercrime laws being used to target security researchers

#89
post #77
post #76

Earlier quoted context omitted.

But they should give a shit before they can pass judgement, because they're not important just to me and because there are actual victims involved (which might be different than the accusants). What if no private data were actually accessed, let's say if the researcher only compromised his own account. Or about the case that he hacked a device that he bought, violating the Acceptable Use Policy of the producer. Or th…

The whole point of juries is for them to judge you against the norms of society at large. The fact that a small group of people might be operating under different norms is irrelevant. They don't have to understand your values in order to judge you. All they need to understand are the facts and the law. The prevailing norm is that property rights are sacrosanct, and any invasion of those rights is considered suspiciou…

>They don't have to understand your values in order to judge you. All they need to understand are the facts and the law.

That could be said for racist laws just as well (e.g Jim Crow stuff).

Even if they don't have to "understand his values", they should be made to, and the law is bad in this regard.

Hence, I don't see the point in pointing out the status quo and what privileges they have in a neutral manner. Seems like apologist to me.

Re: US cybercrime laws being used to target security researchers

#90
post #77
post #76

Earlier quoted context omitted.

But they should give a shit before they can pass judgement, because they're not important just to me and because there are actual victims involved (which might be different than the accusants). What if no private data were actually accessed, let's say if the researcher only compromised his own account. Or about the case that he hacked a device that he bought, violating the Acceptable Use Policy of the producer. Or th…

The whole point of juries is for them to judge you against the norms of society at large. The fact that a small group of people might be operating under different norms is irrelevant. They don't have to understand your values in order to judge you. All they need to understand are the facts and the law. The prevailing norm is that property rights are sacrosanct, and any invasion of those rights is considered suspiciou…

You sound like you're drawing a normative conclusion from positive facts (i.e. the is/ought problem).

The fact that juries judge things from a certain perspective says nothing about whether they ought to do so or not.

Post reply on HN