Van Buren is a victory against overbroad interpretations of the CFAA
41–50 of 99 posts
Re: Van Buren is a victory against overbroad interpretations of the CFAA
#42This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…
What he did was despicable and a grotesque abuse of his position, but it had nothing to do with hacking. The prosecutors decided to charge him under the CFAA because the data he sold for money was stored in a computer system. Van Buren accessed data he was authorized to access, using his own perfectly valid credentials. Because of this, the Supreme Court says it is not a violation of the Computer Fraud and Abuse act.…
Re: Van Buren is a victory against overbroad interpretations of the CFAA
#43Earlier quoted context omitted.
Yeah, I don't buy this line of argumentation. Suppose the locked room is an apartment and the person with a key is your landlord. I'm pretty sure he's not authorized to enter and do whatever. A plain reading of "authorized" means "having official permission or approval." Van Buren might have been "authorized" to access the system but he certainly wasn't "authorized" to access certain data for cash bribes. I guess I'm…
You're trying to make the same argument as in the dissent, but the Court decision spent something like parts of 5 pages defining the word "so" and how this specific law applies to this kind of situation. It's a win for civil liberties because how an employer writes their policies should not potentially open an individual up to federal criminal prosecution under the CFAA specifically.
http://www.epspros.com/news-resources/news/2018/it-worker-lo...
"Mr. Thomas challenged the verdict, arguing that his conduct was not illegal because his IT position provided him full access to the system and empowered him to 'damage' the system by deleting files or taking the system offline. Thus, any acts were not 'without authorization.' The Fifth Circuit rejected this argument, finding that the statute’s prohibition against exceeding authorized access applies to insiders who go beyond the permission granted them in order to cause damage."
Re: Van Buren is a victory against overbroad interpretations of the CFAA
#44Earlier quoted context omitted.
It seems to me like the issue here is that reasonable people disagree on where the boundary between work misconduct and criminal liability is, and that computers being involved are pushing that to the forefront in these kinds of cases.
Also there is no reason that misconduct of this kind couldn’t be prosecuted under laws preventing similar breaches that aren’t digital in nature. Selling private data for bribes should be illegal whether or not it’s a database or a file cabinet.
Re: Van Buren is a victory against overbroad interpretations of the CFAA
#45Earlier quoted context omitted.
You're trying to make the same argument as in the dissent, but the Court decision spent something like parts of 5 pages defining the word "so" and how this specific law applies to this kind of situation. It's a win for civil liberties because how an employer writes their policies should not potentially open an individual up to federal criminal prosecution under the CFAA specifically.
So, what about the Michael Thomas case? Does this verdict overturn his conviction? http://www.epspros.com/news-resources/news/2018/it-worker-lo... "Mr. Thomas challenged the verdict, arguing that his conduct was not illegal because his IT position provided him full access to the system and empowered him to 'damage' the system by deleting files or taking the system offline. Thus, any acts were not 'without authorizati…
Re: Van Buren is a victory against overbroad interpretations of the CFAA
#46This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…
Whether Van Buren deserves punishment is a separate question from whether the legal theory the DoJ sought to use to get him punished was proper.
> Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liable for anything they do with access to that system, even if the owner explicitly prohibits it.
No, it doesn't. This is not a finding that the activity is Constitutionally protected, or even non-criminal in any broad sense, but that it is not within the scope of the criminal provisions of the CFAA, which is a win, because the interpretation of the CFAA necessary to make it applicable is ludicrously broad.
> In other words, lets say I work at a gay hookup website and they grant me access to their production database as part of my job. If I start selling off information about user to third parties (say journalists), how can that be legal
It shouldn't be, but that doesn’t justify abusing the CFAA into a blank prosecutorial check.
Re: Van Buren is a victory against overbroad interpretations of the CFAA
#47This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…
> I should be able to use a bot to access that data in the same ways a human could. I don't think even this is something that follows naturally. For example, a human can sit next to the highway and write down license plates. However, it is still a crime if you use a computer to do the same (and perhaps sell a huge database containing this information).
Re: Van Buren is a victory against overbroad interpretations of the CFAA
#48This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…
There are many other laws that you can still be charged with that govern what you access, irrespective of how, ie copyright, child porn, confidential information.
The people who view this as a win are worried that if "authorization" is defined as "against any rule, made by anyone" then the CFAA could be used to criminalize almost anything online. Note that restriction of the CFAA does not let you off the hook of other laws.
The people who worry about this are worried that judges had to use a fair bit of extrapolation and guessing as to the intent and effects of the law because the wording is pretty vague, and probably problematic for internet activity if interpreted very narrowly.
Re: Van Buren is a victory against overbroad interpretations of the CFAA
#49The key takeaway for me is how this decision affects port scanning. According to the article: > Van Buren is really good news for port scanning, for example: so long as the computer is open to the public, you don’t have to worry about the conditions for use to scan the port. As a frequent user of nmap, this is good to hear.
OK that's good to hear yes. But I am confused by the implications here. How is port scanning different legally from brute forcing passwords? Iterating integers is fine, iterating the dictionary is not? What if there's an integer ID in the URL but it's MD5 hash'd and I recognize for what it is and iterate integers and MD5 them?
Re: Van Buren is a victory against overbroad interpretations of the CFAA
#50Earlier quoted context omitted.
You're trying to make the same argument as in the dissent, but the Court decision spent something like parts of 5 pages defining the word "so" and how this specific law applies to this kind of situation. It's a win for civil liberties because how an employer writes their policies should not potentially open an individual up to federal criminal prosecution under the CFAA specifically.
So, what about the Michael Thomas case? Does this verdict overturn his conviction? http://www.epspros.com/news-resources/news/2018/it-worker-lo... "Mr. Thomas challenged the verdict, arguing that his conduct was not illegal because his IT position provided him full access to the system and empowered him to 'damage' the system by deleting files or taking the system offline. Thus, any acts were not 'without authorizati…
But then I looked into the case a bit closer and I start to think he has an argument for not being charged under the CFAA. As with many laws, intent matters, so it is possible that if his intent was to harm the business, there may well be charges that could be applied in that realm. And obviously he could be held civilly liable for damages, which is no different than any other employee who does something to damage their employer's equipment. Offline example - if I work at a construction company, and I wreck construction equipment because I wasn't happy my co-worker got fired, that isn't going to be a criminal offense, but the company will likely fire me and try to collect damages.
So I'm going to go back on my initial judgement and say that I think he may have grounds to get his conviction overturned and while he may be charged with other crimes, not sure it would come from the CFAA.
*disclaimer, not a lawyer