My co-blogger Stewart Baker recently argued that it is legal to hack into the computer of someone who has hacked into your computer. Stewart says his analysis is “surely” right. I think it’s obviously wrong. Here’s why. The Computer Fraud and Abuse Act is a computer trespass statute. It prohibits accessing another person’s computer “without […]
Archive | Computer Fraud and Abuse Act
Magistrate Judge Concludes That Fraud Scheme Using Video Poker Machine Falls Outside the Computer Fraud and Abuse Act
Last year, I posted about a recently-filed criminal prosecution in which the federal government was charging a state fraud scheme involving poker machines under the Computer Fraud and Abuse Act: Andrew Nestor learned of a programming flaw in certain video poker machines used in Las Vegas. By using a certain feature and playing a particular […]
Recent Developments — Both in the Courts and in Congress — on the Scope of the Computer Fraud and Abuse Act
I’ve blogged a lot on the scope of the Computer Fraud and Abuse Act, and specifically on whether using a computer in violation of a computer use policy or Terms of Service is a federal crime. I’ve been banging the drum urging courts to adopt a narrow interpretations of the Act for a decade, and […]
Ninth Circuit Hands Down En Banc Decision in United States v. Nosal, Adopting Narrow Interpretation of Computer Fraud and Abuse Act
The Ninth Circuit has just handed down its long-awaited en banc decision in United States v. Nosal, the case I’ve blogged a lot about involving the scope of the Computer Fraud and Abuse Act and whether violating employee restrictions on workplace computer use is a federal crime. The opinion by Chief Judge Kozinski is a […]
Thoughts on the Oral Arguments in United States v. Nosal
I’ve blogged a lot about the Ninth Circuit’s en banc case in United States v. Nosal, on the scope of the Computer Fraud and Abuse Act — and more specifically, on whether it’s a federal crime to violate an express written restriction on using a computer. You can watch last Thursday’s oral argument in the […]
“When Computer Misuse Becomes A Crime”
Law.com has reprinted this helpful story on the Ninth Circuit en banc arguments to be held later this week in United States v. Nosal.
The Trespass Tort Versus the CFAA: A Response to the Oracle Amicus Brief in Nosal
In a recently-filed amicus brief submitted by Oracle America Inc. before the en banc Ninth Circuit in United States v. Nosal, the important Computer Fraud and Abuse Act case I have blogged a lot about, Oracle makes the following argument about interpreting “access” and “authorization” in the context of the CFAA. The CFAA’s prohibition on […]
My Assessment of Senator Leahy’s Proposed Amendment to the CFAA
Senator Leahy recently proposed an amendment to the Computer Fraud and Abuse Act to try to address the overbreadth concerns that myself and others have raised about the current statute, and particularly DOJ’s controversial view that the statute presently allows the government to prosecute computer users for TOS violations. I wanted to blog my thoughts […]
Fox News and WSJ Columns on the Scope of the Computer Fraud and Abuse Act
The scope of the CFAA has been drawing some significant press attention today. Eric Felten takes on the issue in the Wall Street Journal; Judson Berger does so over at Fox News. I’ll be on NPR’s All Things Considered this weekend discussing the same issue.
Cautiously Optimistic After the Judiciary Committee Hearing on the CFAA
I testified yesterday at a House Judiciary Committee hearing that focused in part on the need to narrow the Computer Fraud and Abuse Act, a drum I’ve been beating since 2003. You can watch the video of the hearing here; the CFAA parts were discussed mostly in the opening statements and in the last 15 […]
My Congressional Testimony on the Need to Narrow the Computer Fraud and Abuse Act
Tomorrow morning at 10am, I will be testifying before the House Judiciary Committee’s Subcommittee on Crime, Terrorism, and Homeland Security about the need to narrow the Computer Fraud and Abuse Act. I have submitted my written testimony, and it is available here. It begins: The current version of the Computer Fraud and Abuse Act (CFAA) […]
How DOJ Can Use the CFAA to Try to Federalize State Crimes
I’ve blogged a lot about 18 U.S.C. 1030, the Computer Fraud and Abuse Act (CFAA), and how broad readings of the statute potentially criminalize a tremendous amount of entirely innocuous activity. The broad readings of the CFAA also have another important effect: They allow DOJ to try to turn any state crime that happens to […]
Ninth Circuit Grants Rehearing En Banc in United States v. Nosal
I’ve blogged a few times about the recent Ninth Circuit decision in United States v. Nosal, which held that “an employee accesses a computer in excess of his or her authorization [in violation of 18 U.S.C. 1030] when that access violates the employer’s access restrictions, which may include restrictions on the employee’s use of the […]
The Law of Cyberwar: What FDR, Hitler, and the Blitz Can Teach Us
I’ve just finished a longish piece on cyberwar and the role of lawyers, published in Foreign Policy magazine. Here’s how it begins: Lawyers don’t win wars. But can they lose one? We’re likely to find out, and soon. Lawyers across the U.S. government have raised so many show-stopping legal questions about cyberwar that they’ve left […]
Senate Judiciary Committee Passes Amendment to Prohibit Prosecutions for Terms-of-Service Violations
Kashmir Hill writes at her Forbes blog on the good news from yesterday’s Senate Judiciary Committee hearing markup of amendments to the Computer Fraud and Abuse Act: No, Faking Your Name On Facebook Will Not Be A Felony. Legal scholar Orin Kerr wrote an alarming op-ed in the Wall Street Journal yesterday, warning people that […]