The story is in two parts, The Lawyers Hackers Call and ‘Find the Best Defense Attorney You Can’, and it includes quotes from me and several others. I had related thoughts in 2011 here.
Archive | Computer Fraud and Abuse Act
District Court Holds That Intentionally Circumventing IP Address Ban Is “Access Without Authorization” Under the CFAA
During the debate over the Aaron Swartz case, one of the legal issues was whether Swartz had committed an unauthorized access under the CFAA when he changed his IP address to circumvent IP address blocking imposed by system administrators trying to keep Swartz off the network. There was significantly more to the CFAA charges than […]
Washington Post on United States v. Auernheimer
Last month, I blogged about why I agreed to represent Andrew Auernheimer pro bono in his appeal before the Third Circuit. Tomorrow’s Washington Post has a front-page story by Jerry Markon focusing on the case. It begins: Their guns drawn, a dozen federal agents, police and forensics experts kicked in the door of a run-down […]
A Question for Supporters of Increasing Maximum Sentences Under the Computer Fraud and Abuse Act
As I recently noted, Congress is considering legislation to increase maximum punishments under the Computer Fraud and Abuse Act. Here’s my question for supporters of this legislation: Can you identify any cases under the current version of the CFAA in which judges sentenced defendants to the current maximum sentences? In other words, have there been […]
House Judiciary Committee New Draft Bill on Cybersecurity is Mostly DOJ’s Proposed Language from 2011
The Hill reports that a draft of language to reform the CFAA is being circulated among House Judiciary Committee members for feedback: A draft cybersecurity bill circulating among House Judiciary Committee members would stiffen a computer hacking law used to bring charges against Internet activist Aaron Swartz. The bill draft would tighten penalties for […]
No, Aaron Swartz Was Not Charged With Violating JSTOR’s Terms of Service
Writing in Slate, Justin Peters has a puzzling article on the CFAA charges brought against Aaron Swartz. Peters appears to think that the basis of the Swartz prosecution was violating the Terms of Service at JSTOR, the service that hosted the database that Swartz tried to copy. Peters then discusses whether Swartz should be held […]
The Prospects for Reform of the Computer Fraud and Abuse Act
Will Congress amend the Computer Fraud and Abuse Act in light of the Aaron Swartz case? Don’t expect reforms any time soon, Politico suggests: Despite some recent momentum, there’s not much clamor for change coming from the White House — and as expected, the Justice Department, which once tried to expand the penalties of the […]
Drafting Problems With the Second Version of “Aaron’s Law” from Rep. Lofgren
Congresswoman Zoe Lofgren has posted a new draft version of “Aaron’s Law,” an amendment to 18 U.S.C. 1030 in the wake of the Aaron Swartz case. In this new draft, Lofgren adopts the idea I floated and others have since adopted of eliminating the concept of “exceeds authorized access” and instead defining “access without authorization.” […]
“Tom the Dancing Bug” on the Scope of the Computer Fraud and Abuse Act — And A Related Note from My Computer Crime Casebook
I have been beating the drum on the need to narrow the Computer Fraud and Abuse Act for a decade or so, so I was happy to see today’s cartoon for “Tom the Dancing Bug” pick up the cause, too. I don’t know if I can reprint the cartoon here copyright reasons, but you can […]
More Thoughts on the Six CFAA Scenarios About Authorized Access vs. Unauthorized Access
In last night’s post, I offered six scenarios to help identify what should be the proper line between access to a computer that is authorized versus without authorization under the Computer Fraud and Abuse Act. The reader responses are still coming in, and if you haven’t voted yet, please read that post and do so. […]
Aaron’s Law, Drafting the Best Limits of the CFAA, And A Reader Poll on A Few Examples
In a recent post, I offered a series of amendments to narrow the Computer Fraud And Abuse Act. One amendment woud eliminate the concept of “exceeds authorized access” and instead limit the concept of unauthorized access to “access without authorization.” I offered the following definition of “access without authorization” that would be required for most […]
Proposed Amendments to 18 U.S.C. 1030
There has been a lot of interest in amending the Computer Fraud and Abuse Act in light of the Aaron Swartz prosecution. I have drafted some changes and uploaded a red-lined version here. My proposal has lots of parts, but the big ones are: (1) eliminating liability for exceeding authorized access, (2) tightening the felony […]
Boyle on Kerr on Swartz, and Cornyn on Holder on Swartz
Two quick links related to the Aaron Swartz prosecution: 1) Duke lawprof Jamie Boyle has posted a thoughtful reply to my two posts on the Aaron Swartz case over at The Public Domain. I plan to post a response to Jamie when I have time to do so — in a day or two, I […]
The Criminal Charges Against Aaron Swartz (Part 2: Prosecutorial Discretion)
This is the second in a series of posts on the Aaron Swartz prosecution. In my first post, I analyzed whether the charges that were brought against Swartz were justified as a matter of law. In this post, I consider whether the prosecutors in the case properly exercised their discretion. As some readers may know, […]
The Criminal Charges Against Aaron Swartz (Part 1: The Law)
The Internet activist Aaron Swartz has died from an apparent suicide. Swartz was facing a criminal trial in April on charges arising from his effort to “liberate” the JSTOR database, and there has been a lot of commentary accusing the prosecutors in his case of having abused their role in ways that contributed to Swartz’s […]