Live data from Hacker News

Van Buren is a victory against overbroad interpretations of the CFAA

eff.org

81–90 of 99 posts

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#81

Earlier quoted context omitted.

I was initially going to say no, that when he went on to damage files, he caused material harm. He was not authorized to "damage" the system, and although he had access to the system and so gaining access in and of itself is not a crime, causing damage would be. But then I looked into the case a bit closer and I start to think he has an argument for not being charged under the CFAA. As with many laws, intent matters,…

If the CFAA doesn't apply to sys admins working at the highest levels of authorization, it seems to be a useless law. Foreign actors can simply hire sys admins to access whatever they want, no need for hacking. I really do think the court has opened Pandora's box on this one. They should've voided the statute for vagueness if that was the concern. As it stands now, it has to be one of the dumbest laws on the books.

It prevents you from using someone else's credentials to access the system.

It prevents a whole bunch of other sophisticated attacks as well, but let's be honest, people just giving out their password or using a really weak password is the most likely scenario.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#82

Earlier quoted context omitted.

I was initially going to say no, that when he went on to damage files, he caused material harm. He was not authorized to "damage" the system, and although he had access to the system and so gaining access in and of itself is not a crime, causing damage would be. But then I looked into the case a bit closer and I start to think he has an argument for not being charged under the CFAA. As with many laws, intent matters,…

If the CFAA doesn't apply to sys admins working at the highest levels of authorization, it seems to be a useless law. Foreign actors can simply hire sys admins to access whatever they want, no need for hacking. I really do think the court has opened Pandora's box on this one. They should've voided the statute for vagueness if that was the concern. As it stands now, it has to be one of the dumbest laws on the books.

> If the CFAA doesn't apply to sys admins working at the highest levels of authorization, it seems to be a useless law. Foreign actors can simply hire sys admins to access whatever they want, no need for hacking.

It's still illegal to steal IP. But no, you can't charge a janitor with keys to the whole building for breaking and entering if he uses those keys to steal something.

You charge him for theft.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#83

Earlier quoted context omitted.

Yeah, I don't buy this line of argumentation. Suppose the locked room is an apartment and the person with a key is your landlord. I'm pretty sure he's not authorized to enter and do whatever. A plain reading of "authorized" means "having official permission or approval." Van Buren might have been "authorized" to access the system but he certainly wasn't "authorized" to access certain data for cash bribes. I guess I'm…

You're trying to make the same argument as in the dissent, but the Court decision spent something like parts of 5 pages defining the word "so" and how this specific law applies to this kind of situation. It's a win for civil liberties because how an employer writes their policies should not potentially open an individual up to federal criminal prosecution under the CFAA specifically.

Private corporations are not legislatures. If you are an invited guest to my house and I say it's not ok to drink wine out of a shot glass, and instead you must always drink from a wine glass when in my house, and you do it, that's not a felony. If the family album is on the couch and I give it to you and say you can look at it, but don't look at the last two pages which have the pictures of the wife nude and you do that, that's not a felony.

You could, in both cases, theoretically argue that it's a trespass to chattels and get nominal damages, but that's a civil matter.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#85
post #70

Earlier quoted context omitted.

> A person commits the offense of criminal trespass when he or she knowingly and without authority Note emphasis. Going in my house without my permission (without authority) to do something illegal is criminal trespass, based on what you quoted. If you have permission to be in my house and do something illegal while in my house then that is not criminal trespass, based on what you quoted. Whatever illegal thing you d…

>If you have permission to be in my house and do something illegal Sure, but having permission to come in for a certain reason doesn't also grant you permission to come back lather for another reason. To use the analogy, the defendant had permission to enter the "house" for certain purposes. They subsequently entered it for an explicitly unauthorized purpose. That latter entry is trespassing.

I would be keen on seeing caselaw on this. Got any references I can read?

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#86
post #28

Earlier quoted context omitted.

Perhaps it would be helpful to consider an offline analogy. Suppose there were no computers involved and all the information was stored in files in a locked room. Now Van Buren is given a key to access the filing room for his duties, and then uses his key to go in and look up the file on some license plate in exchange for money. Clearly, this is a terrible breach of trust and authority. It should be against policy. H…

It seems to me like the issue here is that reasonable people disagree on where the boundary between work misconduct and criminal liability is, and that computers being involved are pushing that to the forefront in these kinds of cases.

[deleted]

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#87
post #28

Earlier quoted context omitted.

Perhaps it would be helpful to consider an offline analogy. Suppose there were no computers involved and all the information was stored in files in a locked room. Now Van Buren is given a key to access the filing room for his duties, and then uses his key to go in and look up the file on some license plate in exchange for money. Clearly, this is a terrible breach of trust and authority. It should be against policy. H…

It seems to me like the issue here is that reasonable people disagree on where the boundary between work misconduct and criminal liability is, and that computers being involved are pushing that to the forefront in these kinds of cases.

[deleted]

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#88
post #28

Earlier quoted context omitted.

Perhaps it would be helpful to consider an offline analogy. Suppose there were no computers involved and all the information was stored in files in a locked room. Now Van Buren is given a key to access the filing room for his duties, and then uses his key to go in and look up the file on some license plate in exchange for money. Clearly, this is a terrible breach of trust and authority. It should be against policy. H…

It seems to me like the issue here is that reasonable people disagree on where the boundary between work misconduct and criminal liability is, and that computers being involved are pushing that to the forefront in these kinds of cases.

[deleted]

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#89

Earlier quoted context omitted.

Which is different than breaking and entering

Yes, sure. But the point is that, under certain circumstances, the use of the key can exceed your level of authorization. Possession of the key isn't a get out of jail free card.

The point seems to be that using the key isn’t the crime.

Re: Van Buren is a victory against overbroad interpretations of the CFAA

#90
post #19

Earlier quoted context omitted.

> I should be able to use a bot to access that data in the same ways a human could. I don't think even this is something that follows naturally. For example, a human can sit next to the highway and write down license plates. However, it is still a crime if you use a computer to do the same (and perhaps sell a huge database containing this information).

Where is this a crime? Dashcams are generally not illegal.

It becomes illegal when you make a database of license plates coupled to locations and times.

And even more illegal when you publish a service for looking up this data.

Post reply on HN