Earlier quoted context omitted.
Except he wasn't. Not by this ruling.
I mean he’s dead and that’s an ok result for the police, being guilty or not doesn’t really matter. And we’ll never know if this ruling would be sufficient because again, he’s dead.
Van Buren is a victory against overbroad interpretations of the CFAA
51–60 of 99 posts
Re: Van Buren is a victory against overbroad interpretations of the CFAA
#52Earlier quoted context omitted.
The majority are happy to see that minor or even trivial access of things people aren't "supposed" to look at--even though they have access to systems--are no longer CFAA violations. The assumption is that if it isn't trivial they're probably violating some other law or at least doing something they'll be fired for. That said, I have sympathy for the dissent as well which essentially argues that the majority is drawi…
> so long as you're OK to access a system for some purpose, you're fine so far as the CFAA is concerned This is a pretty gross simplification of the position by the majority. I get it was an example and maybe a bit exaggerated, but wanted to point this out. They even specifically said that you have to have the specific access to the information you are retrieving - the example (paraphrased) was if you have access to…
I'm not unhappy with the result. I also think it draws a very narrow line that doesn't really exist in the law (which is why you see Thomas et al dissenting).
Re: Van Buren is a victory against overbroad interpretations of the CFAA
#53Earlier quoted context omitted.
If ruled the other way then basically everyone who works a desk job would be breaking the CFAA daily. Let me explain. If an employer only allowed employees to use their work computers for work (I assume most do, at least officially) as soon as an employee does anything personal on it (checks FB, checks HN, etc) even if on lunch break, they have exceeded their authorization, broken the law under the CFAA, and face up…
That's incorrect. If you read the full statute, it has to be unauthorized access combined with some sort of theft of data, or access of governmental records. It wouldn't apply to browsing public sites. The specific subsection that was applied to Can Buren lays out three cases. Unauthorized access plus obtaining: (A)information contained in a financial record of a financial institution, or of a card issuer as defined…
That said, doesn't this pretty much include anything on the web?
(a)Whoever— (2)intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains— (C)information from any protected computer;
where a "protected computer" is:
(e)As used in this section— (2) the term “protected computer” means a computer— (B) which is used in or affecting interstate or foreign commerce or communication
seems like that would catch an awful lot of webservers.
Re: Van Buren is a victory against overbroad interpretations of the CFAA
#54Earlier quoted context omitted.
Id agree all this means a bent cop got off on a technicality and the tabloid press get a free pass.
He was still convicted of wire fraud and bribery, how is that a free pass?
Re: Van Buren is a victory against overbroad interpretations of the CFAA
#55Earlier quoted context omitted.
So, what about the Michael Thomas case? Does this verdict overturn his conviction? http://www.epspros.com/news-resources/news/2018/it-worker-lo... "Mr. Thomas challenged the verdict, arguing that his conduct was not illegal because his IT position provided him full access to the system and empowered him to 'damage' the system by deleting files or taking the system offline. Thus, any acts were not 'without authorizati…
I was initially going to say no, that when he went on to damage files, he caused material harm. He was not authorized to "damage" the system, and although he had access to the system and so gaining access in and of itself is not a crime, causing damage would be. But then I looked into the case a bit closer and I start to think he has an argument for not being charged under the CFAA. As with many laws, intent matters,…
I really do think the court has opened Pandora's box on this one. They should've voided the statute for vagueness if that was the concern. As it stands now, it has to be one of the dumbest laws on the books.
Re: Van Buren is a victory against overbroad interpretations of the CFAA
#56This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…
The decision does not prevent punishment. It narrows the scope of how the CFAA can be applied. Had it been interpreted as broadly as the government asked, terms of service violations would be open to Federal prosecution. The EFF article lays out some particularly troublesome implications, like criminalizing the use of your work computer for personal matters.
> If I start selling off information about user to third parties (say journalists), how can that be legal?
It's not. The decision simply states that because you were given access, you can't be charged specifically for hacking. You would still on the hook for stealing and selling the data.
Re: Van Buren is a victory against overbroad interpretations of the CFAA
#57This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…
Perhaps it would be helpful to consider an offline analogy. Suppose there were no computers involved and all the information was stored in files in a locked room. Now Van Buren is given a key to access the filing room for his duties, and then uses his key to go in and look up the file on some license plate in exchange for money. Clearly, this is a terrible breach of trust and authority. It should be against policy. H…
Certain employees at a hospital have authorization to pull up medical records as part of their jobs. It is extremely illegal for them to view records that aren't required for specific work purposes. If a nurse is treating Jane Smith in room 203, it's OK and normal for her to look at Jane Smith's records. It's absolutely not OK, and punishable with huge fines, for her to pull up her ex-boyfriend's records just out of curiosity.
However, it's not a violation of the CFAA for her to look at her ex's data. It's 100% against HIPAA, but she didn't have to break into a computer system to view them. She was authorized to access the system. She wasn't authorized (by virtue of her work requirements) to pull up those specific, but as a nurse, the system permitted her to without going around any login prompts or doing anything harder than typing "John Doe" into the search box.
That's the distinction that the CFAA cares about. It's about breaking into systems, or, at least, that's why it was written and that's how the SCOTUS just ruled that it was meant for. It's about access to the system in general, not access to a specific record in the system. There are other laws that govern those specifics.
Re: Van Buren is a victory against overbroad interpretations of the CFAA
#58Earlier quoted context omitted.
I was initially going to say no, that when he went on to damage files, he caused material harm. He was not authorized to "damage" the system, and although he had access to the system and so gaining access in and of itself is not a crime, causing damage would be. But then I looked into the case a bit closer and I start to think he has an argument for not being charged under the CFAA. As with many laws, intent matters,…
If the CFAA doesn't apply to sys admins working at the highest levels of authorization, it seems to be a useless law. Foreign actors can simply hire sys admins to access whatever they want, no need for hacking. I really do think the court has opened Pandora's box on this one. They should've voided the statute for vagueness if that was the concern. As it stands now, it has to be one of the dumbest laws on the books.
This is prosecutable under a myriad of existing laws. CFAA was specifically crafted to deter and punish hacking. As far as I know, that's still very much a thing.
Re: Van Buren is a victory against overbroad interpretations of the CFAA
#59This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…
> So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Whether Van Buren deserves punishment is a separate question from whether the legal theory the DoJ sought to use to get him punished was proper. > Am I missing something? To me, this ruling means that i…
Exactly.
https://www.youtube.com/watch?v=PDBiLT3LASk
"That man's bad" / "There's no law against that" "Whilst you talk he's gone" / "And go he should, if he were the devil himself until he broke the law".
Re: Van Buren is a victory against overbroad interpretations of the CFAA
#60This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…
Just because a computer was used doesn't mean it was "hacking".
The Supreme Court essentially limited the scope of the CFAA to unauthorized access of a computer system. That is a good thing. The alternative is your employer could institute a policy change in what you can use internal systems for and you could find yourself on the wrong end of a CFAA "hacking" criminal prosecution. That's not hyperbole.
On a side note, we once again find Thomas on the wrong side of history. The dissenters have gone well beyond what they might argue is strict textualism to simply supporting broad authoritarianism.
Aaron Swartz is frequently brought up here as a prime example of prosecutorial overreach. For example, he was charged with "hacking" with the (then) interpretation of the CFAA, which then compounded to other charges, like breaking and entering to commit a felony (CFAA "hacking" was that felony).
We need less not more overbroad legislation.