Live data from Hacker News

Van Buren is a victory against overbroad interpretations of the CFAA

eff.org

71–80 of 99 posts

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#71

This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…

> Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liable for anything they do with access to that system, even if the owner explicitly prohibits it.

What you are missing is that you are assuming that the CFAA is the only means by which Van Buren should be punished. So you are assuming that either the CFAA covers this abuse, or he gets off completely free.

The CFAA isn't the only means to deal with his conduct. Although it doesn't apply, he is still liable to be punished under whatever regime he was given access to it.

In simplified form:

He was granted access to the system pursuant to his employment - ie he was able to log into it, whereas the average citizen can't. Whatever conditions are applicable to that grant are the ones to apply when he abuses that access (eg if the policy says "you can only access this for these purposes, or you will be fired" then if he accesses it for a different purpose, they can fire him).

That is quite separate from the CFAA.

The CFAA is a parallel source of obligations, and is part of the criminal law.

Just because Van Buren breached the terms on which his employer let him access the database doesn't necessarily mean he committed a crime as well.

What SCOTUS did was say that the criminal law provision essentially deals with the "technical" side of access:

* if you get into a computer that you have no access to (ie hacking into it), you breach the relevant section.

* if you are authorised by the operator to have the technical means to access to certain info in the computer (eg permissions), and you do something to access other material, you breach the section (eg escalation of privileges)

* if you have the technical means to access the computer (eg log/password) and you access material that is permitted under those means (ie the user account), but you are not authorised to have that means of access (ie stolen login credentials), you also breach the section.

The problem with the interoperation that SCOTUS rejected was that under EULAs, the provider could essentially say "you can use our systems to log in and view information. But if we decide we don't like you, or you haven't paid your bill, or if you decide you are going to vote for politician X in the upcoming election, then if you actually view any information while you are logged in, you breach the act and commit a crime"

The rejected interpretation said: "authorised does not just mean you have been provided with the technical means to access the information, but also any additional conditions put on your use of the technical means by the person who granted it, which may change at any time" (eg change of policy, what is going through the user's mind)

So the answer to your observation:

> I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment.

is: it is exactly that. But it is punishment to be delivered via the process granting him the access to the information (ie whatever sanctions apply to violation of departmental policy). What he did was a breach of that policy, leaving him open to whatever sanctions are provided in it. But it is not also a crime under the CFAA.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#72

Earlier quoted context omitted.

"Yeah, I don't buy this line of argumentation. Suppose the locked room is an apartment and the person with a key is your landlord" So he would not be Breaking and Entering, and if he has a valid reason such as emergency it would be legal. There are different crimes with different punishments and it's important the right ones are applied. Fraud and theft are different. Manslaughter and murder are different. Sexual har…

"If a landlord does not give notice to the tenants or enters for an unauthorized purpose, the landlord may be charged with trespassing" [1]. [1] https://www.criminaldefenselawyer.com/resources/can-you-tres...

Which is different than breaking and entering

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#73
post #51
post #27

Earlier quoted context omitted.

I mean he’s dead and that’s an ok result for the police, being guilty or not doesn’t really matter. And we’ll never know if this ruling would be sufficient because again, he’s dead.

There should be some sort of count of people who committed suicide because of overcharging by prosecutors.

Prosecutors could paint hit counters on the side of their cars like fight pilots do their planes (in the movies anyways).

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#74

Earlier quoted context omitted.

"If a landlord does not give notice to the tenants or enters for an unauthorized purpose, the landlord may be charged with trespassing" [1]. [1] https://www.criminaldefenselawyer.com/resources/can-you-tres...

Which is different than breaking and entering

Yes, sure. But the point is that, under certain circumstances, the use of the key can exceed your level of authorization. Possession of the key isn't a get out of jail free card.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#75

Earlier quoted context omitted.

Perhaps it would be helpful to consider an offline analogy. Suppose there were no computers involved and all the information was stored in files in a locked room. Now Van Buren is given a key to access the filing room for his duties, and then uses his key to go in and look up the file on some license plate in exchange for money. Clearly, this is a terrible breach of trust and authority. It should be against policy. H…

I think there's a solid online analogy for HIPAA data. Certain employees at a hospital have authorization to pull up medical records as part of their jobs. It is extremely illegal for them to view records that aren't required for specific work purposes. If a nurse is treating Jane Smith in room 203, it's OK and normal for her to look at Jane Smith's records. It's absolutely not OK, and punishable with huge fines, for…

So the actual crimes are far better enforced by more accurate legislation. Not swept up by an overly broad, and borderlom irrational interpretation of the CFAA.

For ex: the accused is still authorized to access the computer. A cashier at a grocery store is authorized to open/close the til all day long.

These may present opportunities but shouldn't be the focus of any crime. The theft itself is already firmly in the criminal code as being illegal.

The fact it was computers doesn't change things.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#76

Earlier quoted context omitted.

I was initially going to say no, that when he went on to damage files, he caused material harm. He was not authorized to "damage" the system, and although he had access to the system and so gaining access in and of itself is not a crime, causing damage would be. But then I looked into the case a bit closer and I start to think he has an argument for not being charged under the CFAA. As with many laws, intent matters,…

If the CFAA doesn't apply to sys admins working at the highest levels of authorization, it seems to be a useless law. Foreign actors can simply hire sys admins to access whatever they want, no need for hacking. I really do think the court has opened Pandora's box on this one. They should've voided the statute for vagueness if that was the concern. As it stands now, it has to be one of the dumbest laws on the books.

Companies have a responsibility to vet their employees, first. I don't know how that is affected by the CFAA being a bit more constrained than it was before, which was extremely overly broad.

I strongly disagree with your assessment (re: Pandora's box, dumbness), but I do think and acknowledge it is a law worthy of being replaced with one more up to date and more clear.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#77
post #63

Earlier quoted context omitted.

>But he's not guilty of breaking and entering He is in my state: >A person commits the offense of criminal trespass when he or she knowingly and without authority: >(1) Enters upon the land or premises of another person or into any part of any vehicle, railroad car, aircraft, or watercraft of another person for an unlawful purpose;

> A person commits the offense of criminal trespass when he or she knowingly and without authority Note emphasis. Going in my house without my permission (without authority) to do something illegal is criminal trespass, based on what you quoted. If you have permission to be in my house and do something illegal while in my house then that is not criminal trespass, based on what you quoted. Whatever illegal thing you d…

If you read the opinions, the dissent reads the CFAA as if it were just importing common law property-based rules to the electronic realm. As it applies to property, authorization is absolutely contextual. If I give a key to a housecleaner and they use it one afternoon intending to steal something, that's trespass. If they just happen to steal something on the spur of the moment, that's not trespass. However, the CFAA has additional language ("exceeds authorized access") that would capture such behavior. As the dissent notes, you can absolutely be charged with criminal trespass if you, for example, enter a National Park to remove a grain of sand in violation of park rules; it's the intent to do something in violation of the terms of access that makes it trespass.

The majority opinion says that applying common law property-based meanings is not the right approach. Rather, the CFAA makes far more sense if you understand authorization and similar terms in the sense they're more often used in computer science, which turn on the design of the authentication and authorization system itself, and are agnostic to external policy, agent intent, etc.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#78
post #67

Earlier quoted context omitted.

> Foreign actors can simply hire sys admins to access whatever they want, no need for hacking This is prosecutable under a myriad of existing laws. CFAA was specifically crafted to deter and punish hacking. As far as I know, that's still very much a thing.

It's not immediately clear which laws. The whole point of the CFAA was that existing trespass & theft laws don't really work for digital files.

> not immediately clear which laws

Yes it is, theft of trade secrets [1].

[1] https://www.justice.gov/opa/pr/former-dow-research-scientist...

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#79
post #75

Earlier quoted context omitted.

I think there's a solid online analogy for HIPAA data. Certain employees at a hospital have authorization to pull up medical records as part of their jobs. It is extremely illegal for them to view records that aren't required for specific work purposes. If a nurse is treating Jane Smith in room 203, it's OK and normal for her to look at Jane Smith's records. It's absolutely not OK, and punishable with huge fines, for…

So the actual crimes are far better enforced by more accurate legislation. Not swept up by an overly broad, and borderlom irrational interpretation of the CFAA. For ex: the accused is still authorized to access the computer. A cashier at a grocery store is authorized to open/close the til all day long. These may present opportunities but shouldn't be the focus of any crime. The theft itself is already firmly in the c…

Nailed it.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#80

This ruling is really confusing for me. So I feel pretty strongly that what van Buren did is a massive abuse of authority and it warrants punishment. Yet so many people I usually agree with (SCOTUS judges, EFF, privacy lawyers) are all calling this a win. Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liabl…

Van Buren violated policy. He should have been terminated. Van Buren was prosecuted for a criminal act not narrowly reflected by the law he was prosecuted against. The SC majority opinion mentioned exactly this.

> Am I missing something? To me, this ruling means that if a person is granted technical access to a computer system, then that person cannot be held criminally liable for anything they do with access to that system, even if the owner explicitly prohibits it.

Yes, you are confusing a policy violation for something more grand. I suspect most people are confused on this matter due to a selection bias favoring criminality for a violation of public trust.

Post reply on HN