Live data from Hacker News

Van Buren is a victory against overbroad interpretations of the CFAA

eff.org

41–50 of 99 posts

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#42

This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…

What he did was despicable and a grotesque abuse of his position, but it had nothing to do with hacking. The prosecutors decided to charge him under the CFAA because the data he sold for money was stored in a computer system. Van Buren accessed data he was authorized to access, using his own perfectly valid credentials. Because of this, the Supreme Court says it is not a violation of the Computer Fraud and Abuse act.…

Well, van Buren was convicted of a felony wire fraud charge as well with an equal length concurrently served sentence as the CFAA charge. So there was another crime we could charge him with, and we did successfully. The only difference is the lack of a CFAA charge on his record and some good case law about what the CFAA actually means so that hopefully it'll only be pushed against true computer crimes rather than crimes that happen to involve a computer.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#43

Earlier quoted context omitted.

Yeah, I don't buy this line of argumentation. Suppose the locked room is an apartment and the person with a key is your landlord. I'm pretty sure he's not authorized to enter and do whatever. A plain reading of "authorized" means "having official permission or approval." Van Buren might have been "authorized" to access the system but he certainly wasn't "authorized" to access certain data for cash bribes. I guess I'm…

You're trying to make the same argument as in the dissent, but the Court decision spent something like parts of 5 pages defining the word "so" and how this specific law applies to this kind of situation. It's a win for civil liberties because how an employer writes their policies should not potentially open an individual up to federal criminal prosecution under the CFAA specifically.

So, what about the Michael Thomas case? Does this verdict overturn his conviction?

http://www.epspros.com/news-resources/news/2018/it-worker-lo...

"Mr. Thomas challenged the verdict, arguing that his conduct was not illegal because his IT position provided him full access to the system and empowered him to 'damage' the system by deleting files or taking the system offline. Thus, any acts were not 'without authorization.' The Fifth Circuit rejected this argument, finding that the statute’s prohibition against exceeding authorized access applies to insiders who go beyond the permission granted them in order to cause damage."

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#44
post #28

Earlier quoted context omitted.

It seems to me like the issue here is that reasonable people disagree on where the boundary between work misconduct and criminal liability is, and that computers being involved are pushing that to the forefront in these kinds of cases.

Also there is no reason that misconduct of this kind couldn’t be prosecuted under laws preventing similar breaches that aren’t digital in nature. Selling private data for bribes should be illegal whether or not it’s a database or a file cabinet.

[deleted]

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#45

Earlier quoted context omitted.

You're trying to make the same argument as in the dissent, but the Court decision spent something like parts of 5 pages defining the word "so" and how this specific law applies to this kind of situation. It's a win for civil liberties because how an employer writes their policies should not potentially open an individual up to federal criminal prosecution under the CFAA specifically.

So, what about the Michael Thomas case? Does this verdict overturn his conviction? http://www.epspros.com/news-resources/news/2018/it-worker-lo... "Mr. Thomas challenged the verdict, arguing that his conduct was not illegal because his IT position provided him full access to the system and empowered him to 'damage' the system by deleting files or taking the system offline. Thus, any acts were not 'without authorizati…

He'd presumably be guilty of other things but those might well be civil. IANAL. But when laws/interpretations change, they're not necessarily retroactive.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#46

This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…

> So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win.

Whether Van Buren deserves punishment is a separate question from whether the legal theory the DoJ sought to use to get him punished was proper.

> Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liable for anything they do with access to that system, even if the owner explicitly prohibits it.

No, it doesn't. This is not a finding that the activity is Constitutionally protected, or even non-criminal in any broad sense, but that it is not within the scope of the criminal provisions of the CFAA, which is a win, because the interpretation of the CFAA necessary to make it applicable is ludicrously broad.

> In other words, lets say I work at a gay hookup website and they grant me access to their production database as part of my job. If I start selling off information about user to third parties (say journalists), how can that be legal

It shouldn't be, but that doesn’t justify abusing the CFAA into a blank prosecutorial check.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#47
post #19

This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…

> I should be able to use a bot to access that data in the same ways a human could. I don't think even this is something that follows naturally. For example, a human can sit next to the highway and write down license plates. However, it is still a crime if you use a computer to do the same (and perhaps sell a huge database containing this information).

Where is this a crime? Dashcams are generally not illegal.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#48

This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…

The CFAA is a law about how you access systems, so this ruling defines "authorization" under the CFAA as "had legitimate access to this system" only.

There are many other laws that you can still be charged with that govern what you access, irrespective of how, ie copyright, child porn, confidential information.

The people who view this as a win are worried that if "authorization" is defined as "against any rule, made by anyone" then the CFAA could be used to criminalize almost anything online. Note that restriction of the CFAA does not let you off the hook of other laws.

The people who worry about this are worried that judges had to use a fair bit of extrapolation and guessing as to the intent and effects of the law because the wording is pretty vague, and probably problematic for internet activity if interpreted very narrowly.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#49
post #18

The key takeaway for me is how this decision affects port scanning. According to the article: > Van Buren is really good news for port scanning, for example: so long as the computer is open to the public, you don’t have to worry about the conditions for use to scan the port. As a frequent user of nmap, this is good to hear.

OK that's good to hear yes. But I am confused by the implications here. How is port scanning different legally from brute forcing passwords? Iterating integers is fine, iterating the dictionary is not? What if there's an integer ID in the URL but it's MD5 hash'd and I recognize for what it is and iterate integers and MD5 them?

It’s not about the techniques used, it’s about the intent of the functions. Remember that we’re in the legal domain and sometimes a common sense argument prevails even if there are some potential holes (if a hole is discovered, a future court case can worry about it). Port scanning is like looking at the outside of a house and noting where the doors and windows are. Brute forcing a password is like picking a lock to gain access to something, or possibly identity theft to authenticate yourself as someone else. Judges can easily understand the difference even if the technical method might be similar. Nobody is going to believe you “port scanned” your way into someone’s online banking access and took money out of their account.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#50

Earlier quoted context omitted.

You're trying to make the same argument as in the dissent, but the Court decision spent something like parts of 5 pages defining the word "so" and how this specific law applies to this kind of situation. It's a win for civil liberties because how an employer writes their policies should not potentially open an individual up to federal criminal prosecution under the CFAA specifically.

So, what about the Michael Thomas case? Does this verdict overturn his conviction? http://www.epspros.com/news-resources/news/2018/it-worker-lo... "Mr. Thomas challenged the verdict, arguing that his conduct was not illegal because his IT position provided him full access to the system and empowered him to 'damage' the system by deleting files or taking the system offline. Thus, any acts were not 'without authorizati…

I was initially going to say no, that when he went on to damage files, he caused material harm. He was not authorized to "damage" the system, and although he had access to the system and so gaining access in and of itself is not a crime, causing damage would be.

But then I looked into the case a bit closer and I start to think he has an argument for not being charged under the CFAA. As with many laws, intent matters, so it is possible that if his intent was to harm the business, there may well be charges that could be applied in that realm. And obviously he could be held civilly liable for damages, which is no different than any other employee who does something to damage their employer's equipment. Offline example - if I work at a construction company, and I wreck construction equipment because I wasn't happy my co-worker got fired, that isn't going to be a criminal offense, but the company will likely fire me and try to collect damages.

So I'm going to go back on my initial judgement and say that I think he may have grounds to get his conviction overturned and while he may be charged with other crimes, not sure it would come from the CFAA.

*disclaimer, not a lawyer

Post reply on HN