Earlier quoted context omitted.
>I'd find a better case, for starters. I was responding to the general point. But as for finding a better case, the problem is that you don't get to pick which cases get prosecuted. If the parties have decided to appeal then a precedent is going to be set here one way or the other. So let him go to jail for what he actually did -- there is no reason to allow the CFAA charge to be piled on top of that and set a terrib…
Why is it OK to have a law against something as general as mail fraud, given that pretty much everyone has used the post at some time or another, but have no law at all regarding computer crimes? I would understand arguing that CFAA in particular is overbroad but it's hard to claim it's being used in this case in a way that's inconsistent with the rest of the U.S. Code. In fact even the CFAA is more narrowly-focused…
I don't understand what your question has to do with what we were discussing. Who said we should "have no law at all regarding computer crimes"? There may be a need for specific regulation regarding some unique aspect of what computers do, or for carving out specific provisions in existing laws when some distinctive feature of computers changes the analysis, but that isn't what the CFAA is. We have laws against theft of trade secrets, what cause is there for them to work differently or have different penalties just because a computer is involved? And if there is such a cause, why must it be addressed with a law having such breadth and penalties as the CFAA rather than something more narrowly targeted at the actual evil?
>In fact even the CFAA is more narrowly-focused than the aforementioned mail fraud law.
The mail fraud law may be similarly problematic, though it at least is mitigated by the fact that it requires you to use the mail, which is becoming less and less common and even in its heyday was never involved in so much of the everyday activities of normal citizens as the internet is today.
>Prosecutors pile charges on, that's what they do. They only get one trial to sort everything out and entire swaths of their case can be thrown out in one fell swoop so yes, they'll stick everything they feel they can prove on there.
Which is kind of the point: They're willing to abuse whatever you give them, so we shouldn't be giving them anything so easy to abuse.
>Even with some theoretical replacement for CFAA that is more fair I would think that at least the authorized access using a co-conspirator's credentials would end up being a chargeable offense, so the difference here is with the remaining accesses that were made.
I think there is a case to be made that authenticating with someone else's credentials (and nothing more) does not need to be a federal offense. Imagine the same scenario (you log on to a friend's work computer using their credentials) but you do so for some totally innocuous purpose like reading The New Yorker online while your friend is finishing up some work. How do you suppose that behavior justifies a federal prosecution? That's the thing the law prohibits, not the actually malicious thing that may or may not follow it.
And all of this is ignoring the original point, which is that even if unauthorized access without any distinct malicious act is to be illegal, the existing penalties remain unjustifiable.
>And even those are hard to claim would be "authorized" access with a straight face, as why would any company authorize access to their networks for the purpose of industrial espionage?
I think you're just proving the point that "unauthorized access to a computer" is a preposterous basis for legislation. If the way you know that access is unauthorized is that breaking some other law implies unauthorized access, what good is the law against unauthorized access? Just attach the penalties you would have attached to unauthorized access to the actually malicious thing the doing of which implies that access was unauthorized and be done with it.