Tomorrow’s Wall Street Journal is running an op-ed I authored on the proposed amendments to the Computer Fraud and Abuse Act. It begins: Imagine that President Obama could order the arrest of anyone who broke a promise on the Internet. So you could be jailed for lying about your age or weight on an Internet […]
Archive | Computer Fraud and Abuse Act
Comments on DOJ’s Defense of The Broad View of “Exceeds Authorized Access” in the Computer Fraud and Abuse Act — And A Proposed Statutory Fix
In his post below, Stewart Baker writes that DOJ official James Baker “gave a persuasive defense” of the broad view of that the Computer Fraud and Abuse Act should apply to Terms of Service violations and employee restrictions on computers. In this post, I want to explain why I don’t find DOJ’s defense of existing […]
Poisoning the Hamburger Helper
The Obama Administration’s legislative proposals on cybersecurity are a distinctly mixed bag. But probably the worst ideas are those put forward by the Justice Department, which last week testified about the need to update the Computer Fraud and Abuse Act. Again. In fact, for the eleventh time since it was adopted in the 1980s. We’ve seen […]
Senate Judiciary Committee Holds Hearing on Expanding CFAA – and Only Invites Government Witnesses
I’ve blogged a bunch about the dangerous scope of the Computer Fraud and Abuse Act (CFAA), and the remarkable fact that Congress seems poised to make the penalties in the act even higher. So here’s an update: The Senate Judiciary Committee held a hearing yesterday on the proposals to expand the CFAA. No one other […]
Did the “News of the World” Phone Hacks Violate U.S. Criminal Law?
As most readers are aware, the English newspaper “News of the World” has recently been shut down over reports that the paper’s reporters regularly hacked into the voicemail boxes of celebrities and political figures to gather news for stories. The hacking has had huge ripple effects, ranging from its impact on UK politics to Rupert […]
If You Don’t Know, Just Say You Don’t Know
NPR’s All Things Considered had a segment today on computer hacking featuring an interview with computer security expert Hugh Thompson. NPR’s Robert Seigel started off by asking Thompson about the law of computer hacking. Thompson is a tech guy, not a law guy. But Thompson tried to wing it, and unfortunately he managed to bungle […]
Petition for Rehearing Filed in United States v. Nosal, the Ninth Circuit Case on Criminalizing Violations of Computer Use Policies
A petition for rehearing was recently filed in United States v. Nosal, the Ninth Circuit decision holding that an employee who violates his employer’s computer use policy is guilty of “exceeding authorized access” to the employer’s computer. I have posted a copy here. I hope the Ninth Circuit grants rehearing, as I think the Nosal […]
Employer Sues Former Employee For Checking Facebook and Personal E-Mail and “Excessive Internet Usage” at Work
The Ninth Circuit recently ruled that an employee “exceeds authorized access” to his employer’s computer when he violates the employer’s Internet use restrictions: Given that federal law criminalizes exceeding authorized access, see 18 U.S.C. 1030(a)(2)(C), that would mean that every employee who surfs the Internet, checks Facebook, or logs in to personal e-mail from work […]
Copying Public Website In Violation of Terms of Use Doesn’t Violate the Computer Fraud and Abuse Act, District Court Holds
The case is Koch Industries, Inc. v. Does, 2011 WL 1775765 (D.Utah 2011), handed down May 9. In this case, a group called “Youth for Climate Truth” copied the Koch Industries website (kochind.com) and created a fake website designed to look just like it at koch-inc.com. The “Youth for Climate Truth” then issued a fake […]
What is a “Computer”?
Certainly a cell phone counts, the Eighth Circuit correctly concludes, at least when it comes to the definition of “computer” in 18 U.S.C. 1030(e)(1) of the Computer Fraud and Abuse Act. Hat tip: FourthAmendment.com
Today’s Award for the Silliest Theory of the Computer Fraud and Abuse Act
…goes to the arguments made by Sony’s lawyers in a complaint and motion for a TRO in a recently-filed civil case: Sony Sues PS3 Hackers. The argument: You’re guilty of felony computer hacking crimes if you access your own computer in a way that violates a contractual restriction found in the fine print of the […]
Eleventh Circuit Holds That It is a Federal Crime For an Employee To Use His Employer’s Computer For “Non Business Reasons” After Receiving Clear Instruction From Employer Not to Do So
Last week, the Eleventh Circuit decided an important case, United States v. Rodriguez, on the computer crime statute known as the Computer Fraud and Abuse Act, 18 U.S.C. 1030. The decision by Judge Pryor touches on the same issue that was in play in the Lori Drew case: When does violating express conditions on computer […]
Final Version of “Vagueness Challenges to the Computer Fraud and Abuse Act”
The final version of my recent essay on the Computer Fraud and Abuse Act — aka the statute that swallowed the Internet — is here: Vagueness Challenges to the Computer Fraud and Abuse Act, 94 Minn. L. Rev. 1561 (2010).
Interesting “Unauthorized Access” Case
Readers who were interested in the Lori Drew case, and the question of when computer use counts as criminal “unauthorized access” to a computer, will want to read this New Jersey state case from last fall: State v. Riley, 12 N.J.Super. 162, 988 A.2d 1252 (2009) (link to google cache version). It’s a case on […]
United States v. John and the Meaning of “Authorization” to Access a Computer
The federal computer crime statute criminalizes accessing a computer “without authorization” or “exceeding authorized access,” with the important caveat that no one seems to know what it mean to access a computer “without authorization” or to “exceed authorized access.” See 18 U.S.C. 1030. The concepts are particularly tricky in the case of a written restriction […]