Live data from Hacker News

Van Buren is a victory against overbroad interpretations of the CFAA

eff.org

21–30 of 99 posts

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#21
post #18

The key takeaway for me is how this decision affects port scanning. According to the article: > Van Buren is really good news for port scanning, for example: so long as the computer is open to the public, you don’t have to worry about the conditions for use to scan the port. As a frequent user of nmap, this is good to hear.

OK that's good to hear yes. But I am confused by the implications here. How is port scanning different legally from brute forcing passwords? Iterating integers is fine, iterating the dictionary is not? What if there's an integer ID in the URL but it's MD5 hash'd and I recognize for what it is and iterate integers and MD5 them?

Brute forcing passwords is attempting to access a computer without authorization, port scanning.. is not

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#22
post #18

The key takeaway for me is how this decision affects port scanning. According to the article: > Van Buren is really good news for port scanning, for example: so long as the computer is open to the public, you don’t have to worry about the conditions for use to scan the port. As a frequent user of nmap, this is good to hear.

OK that's good to hear yes. But I am confused by the implications here. How is port scanning different legally from brute forcing passwords? Iterating integers is fine, iterating the dictionary is not? What if there's an integer ID in the URL but it's MD5 hash'd and I recognize for what it is and iterate integers and MD5 them?

> How is port scanning different legally from brute forcing passwords?

Because humans are trivially able to recognize the difference between those two activities. A judge that has that case in front of them can _really_ easily see the difference between those activities.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#24

This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…

"This ruling is really confusing to me. So I feel like what Van Buren did is a massive abuse of authority and it warrants punishment."

The Supreme Court decision does not by itself exonerate Van Buren. It just remands the case to the lower court to decide again, taking into account the clarification of the CFAA's applicability. Van Buren could still be found guilty and punished, on other grounds.

Just because some action involves a computer (database) and does not violate the CFAA does not necessarily mean it will not trigger potential culpability or liability under other criminal or civil law.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#25

This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…

If ruled the other way then basically everyone who works a desk job would be breaking the CFAA daily. Let me explain.

If an employer only allowed employees to use their work computers for work (I assume most do, at least officially) as soon as an employee does anything personal on it (checks FB, checks HN, etc) even if on lunch break, they have exceeded their authorization, broken the law under the CFAA, and face up to 10 years in prison.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#26

This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…

All the ruling says is that he didn’t violate the CFAA. It doesn’t say anything about bribery laws, selling government information, etc

It is typical for a prosecution to include every charge possible. In this case they included the CFAA, and the Supreme Court said that particular charge was an invalid application of that particular law. It has no effect on any other charges, and no effect on any other laws.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#27
post #23

Related: "Aaron Swartz, Vindicated" https://news.ycombinator.com/item?id=27394974

Except he wasn't. Not by this ruling.

I mean he’s dead and that’s an ok result for the police, being guilty or not doesn’t really matter. And we’ll never know if this ruling would be sufficient because again, he’s dead.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#28

This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…

Perhaps it would be helpful to consider an offline analogy. Suppose there were no computers involved and all the information was stored in files in a locked room. Now Van Buren is given a key to access the filing room for his duties, and then uses his key to go in and look up the file on some license plate in exchange for money. Clearly, this is a terrible breach of trust and authority. It should be against policy. H…

It seems to me like the issue here is that reasonable people disagree on where the boundary between work misconduct and criminal liability is, and that computers being involved are pushing that to the forefront in these kinds of cases.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#29

This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…

Perhaps it would be helpful to consider an offline analogy. Suppose there were no computers involved and all the information was stored in files in a locked room. Now Van Buren is given a key to access the filing room for his duties, and then uses his key to go in and look up the file on some license plate in exchange for money. Clearly, this is a terrible breach of trust and authority. It should be against policy. H…

Yeah, I don't buy this line of argumentation. Suppose the locked room is an apartment and the person with a key is your landlord. I'm pretty sure he's not authorized to enter and do whatever.

A plain reading of "authorized" means "having official permission or approval." Van Buren might have been "authorized" to access the system but he certainly wasn't "authorized" to access certain data for cash bribes.

I guess I'm at a loss to see this as a "win" for civil liberties, but maybe I'm missing something.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#30
post #28

Earlier quoted context omitted.

Perhaps it would be helpful to consider an offline analogy. Suppose there were no computers involved and all the information was stored in files in a locked room. Now Van Buren is given a key to access the filing room for his duties, and then uses his key to go in and look up the file on some license plate in exchange for money. Clearly, this is a terrible breach of trust and authority. It should be against policy. H…

It seems to me like the issue here is that reasonable people disagree on where the boundary between work misconduct and criminal liability is, and that computers being involved are pushing that to the forefront in these kinds of cases.

Also there is no reason that misconduct of this kind couldn’t be prosecuted under laws preventing similar breaches that aren’t digital in nature.

Selling private data for bribes should be illegal whether or not it’s a database or a file cabinet.

Post reply on HN