Live data from Hacker News

Van Buren is a victory against overbroad interpretations of the CFAA

eff.org

31–40 of 99 posts

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#31
post #28

Earlier quoted context omitted.

Perhaps it would be helpful to consider an offline analogy. Suppose there were no computers involved and all the information was stored in files in a locked room. Now Van Buren is given a key to access the filing room for his duties, and then uses his key to go in and look up the file on some license plate in exchange for money. Clearly, this is a terrible breach of trust and authority. It should be against policy. H…

It seems to me like the issue here is that reasonable people disagree on where the boundary between work misconduct and criminal liability is, and that computers being involved are pushing that to the forefront in these kinds of cases.

I agree that defining where the boundary should be is tricky in practice, and it's a good point that this was hardly a unanimous decision, not to mention overruling the appealed ruling.

On the other hand, the underlying law, the CFAA, is about more than just workplace issues like this issue. Interpreting it broadly could mean that violating some terms of use could be a criminal offense, and I am glad that the court avoided that interpretation. It's better having this law be more specific to the intent of criminalizing "hacking" and leaving other laws or policies to deal with how one might abuse computers or networks that one is otherwise entitled to access.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#32

This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…

It isn't saying it is legal, just that it doesn't run afoul of the CFAA and become a federal computer hacking crime. There very well be other laws and repercussions, whether at different levels, like State, or being fired, etc.

It is refreshing because it doesn't put the risk of federal criminal prosecution at the whim of how an employer writes their policies.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#33

This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…

My understanding of the issue is that the prosecutor chose to use the CFAA rather than going after the real crime because of the circumstances.

The accused in the case was caught in a sting operation. The police created a fake situation where they pretended to have an undercover agent, and tries to see if the accused would interfere with the case. He did. The prosecutor however did not charge the accused over obstruction of justice, but rather CFAA and hacking charges. I would guess that the reason is that the prosecutor thought it was easier than charging someone with interfering with a fake case.

From what I understand, courts and judges do not like it when either side try to be clever. CFAA is not a tool to be used when the prosecutor want to avoid a more difficult case, and so it needed to be limited in scope.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#34
post #18

The key takeaway for me is how this decision affects port scanning. According to the article: > Van Buren is really good news for port scanning, for example: so long as the computer is open to the public, you don’t have to worry about the conditions for use to scan the port. As a frequent user of nmap, this is good to hear.

OK that's good to hear yes. But I am confused by the implications here. How is port scanning different legally from brute forcing passwords? Iterating integers is fine, iterating the dictionary is not? What if there's an integer ID in the URL but it's MD5 hash'd and I recognize for what it is and iterate integers and MD5 them?

I think brute-forcing passwords offline isn't illegal under the CFAA. Using a password you got that way would be illegal.

Similarly, password stuffing (just trying many passwords on the login form) would be illegal, since you are trying to gain access. Not sure how that works if you are not successful though.

Port-scanning would be fine. Interesting edge case is, what happens if you port-scan, find an open telnet port, and use it to get a shell. There is no authentication, but does that mean you are authorized? My gut says that logging in to such a telnet port (when the device is not yours) is a CFAA violation. Just like walking in to a random house when the door is open is still illegal.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#35

Earlier quoted context omitted.

Perhaps it would be helpful to consider an offline analogy. Suppose there were no computers involved and all the information was stored in files in a locked room. Now Van Buren is given a key to access the filing room for his duties, and then uses his key to go in and look up the file on some license plate in exchange for money. Clearly, this is a terrible breach of trust and authority. It should be against policy. H…

Yeah, I don't buy this line of argumentation. Suppose the locked room is an apartment and the person with a key is your landlord. I'm pretty sure he's not authorized to enter and do whatever. A plain reading of "authorized" means "having official permission or approval." Van Buren might have been "authorized" to access the system but he certainly wasn't "authorized" to access certain data for cash bribes. I guess I'm…

You're trying to make the same argument as in the dissent, but the Court decision spent something like parts of 5 pages defining the word "so" and how this specific law applies to this kind of situation.

It's a win for civil liberties because how an employer writes their policies should not potentially open an individual up to federal criminal prosecution under the CFAA specifically.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#36

This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…

If ruled the other way then basically everyone who works a desk job would be breaking the CFAA daily. Let me explain. If an employer only allowed employees to use their work computers for work (I assume most do, at least officially) as soon as an employee does anything personal on it (checks FB, checks HN, etc) even if on lunch break, they have exceeded their authorization, broken the law under the CFAA, and face up…

That's incorrect. If you read the full statute, it has to be unauthorized access combined with some sort of theft of data, or access of governmental records. It wouldn't apply to browsing public sites. The specific subsection that was applied to Can Buren lays out three cases. Unauthorized access plus obtaining:

(A)information contained in a financial record of a financial institution, or of a card issuer as defined in section 1602(n) [1] of title 15, or contained in a file of a consumer reporting agency on a consumer, as such terms are defined in the Fair Credit Reporting Act (15 U.S.C. 1681 et seq.);

(B)information from any department or agency of the United States; or

(C)information from any protected computer;

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#37
post #12

This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…

The majority are happy to see that minor or even trivial access of things people aren't "supposed" to look at--even though they have access to systems--are no longer CFAA violations. The assumption is that if it isn't trivial they're probably violating some other law or at least doing something they'll be fired for. That said, I have sympathy for the dissent as well which essentially argues that the majority is drawi…

> so long as you're OK to access a system for some purpose, you're fine so far as the CFAA is concerned

This is a pretty gross simplification of the position by the majority. I get it was an example and maybe a bit exaggerated, but wanted to point this out. They even specifically said that you have to have the specific access to the information you are retrieving - the example (paraphrased) was if you have access to folder X, but not folder Y, and you then access folder Y, you are now in violation.

If anything, the minority was basically being, IMO, too trusting that people with the authority to bring these charges would be reasonable and exercise it in an unbiased and even manner.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#38

This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…

What he did was despicable and a grotesque abuse of his position, but it had nothing to do with hacking.

The prosecutors decided to charge him under the CFAA because the data he sold for money was stored in a computer system. Van Buren accessed data he was authorized to access, using his own perfectly valid credentials. Because of this, the Supreme Court says it is not a violation of the Computer Fraud and Abuse act. They say that a person cannot be charged under the CFAA just because the crime they committed involved a computer.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#39

This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…

Van Buren was also convicted of wire fraud for the same act, with a concurrent prison sentence with the CFAA count of the same length (18 months). So at least in this case he's getting the same punishment either way for his actions.

Reducing the scope of the CFAA in case law just means that we take the teeth out of a overused and honestly crappy law that's ruined lives without reason to.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#40

This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…

Van Buren clearly committed a heinous act and should be punished.

The issue is that this is a hacking statue. He didn't hack into the system, he just used it in a bad way. The punishment should be the same if he got it from a filing cabinet he had the keys to.

The takeaway isn't "If you have access, everything you do is legal" -- not for computers, not for filing cabinets.

Post reply on HN