Archive | Computer Fraud and Abuse Act

My Wall Street Journal Op-Ed on the Computer Fraud and Abuse Act

Tomorrow’s Wall Street Journal is running an op-ed I authored on the proposed amendments to the Computer Fraud and Abuse Act. It begins: Imagine that President Obama could order the arrest of anyone who broke a promise on the Internet. So you could be jailed for lying about your age or weight on an Internet […]

Continue Reading 0

Comments on DOJ’s Defense of The Broad View of “Exceeds Authorized Access” in the Computer Fraud and Abuse Act — And A Proposed Statutory Fix

In his post below, Stewart Baker writes that DOJ official James Baker “gave a persuasive defense” of the broad view of that the Computer Fraud and Abuse Act should apply to Terms of Service violations and employee restrictions on computers. In this post, I want to explain why I don’t find DOJ’s defense of existing […]

Continue Reading 13

Poisoning the Hamburger Helper

The Obama Administration’s legislative proposals on cybersecurity are a distinctly mixed bag.  But probably the worst ideas are those put forward by the Justice Department, which last week testified about the need to update the Computer Fraud and Abuse Act. Again. In fact, for the eleventh time since it was adopted in the 1980s.  We’ve seen […]

Continue Reading 26

Senate Judiciary Committee Holds Hearing on Expanding CFAA – and Only Invites Government Witnesses

I’ve blogged a bunch about the dangerous scope of the Computer Fraud and Abuse Act (CFAA), and the remarkable fact that Congress seems poised to make the penalties in the act even higher. So here’s an update: The Senate Judiciary Committee held a hearing yesterday on the proposals to expand the CFAA. No one other […]

Continue Reading 6

Did the “News of the World” Phone Hacks Violate U.S. Criminal Law?

As most readers are aware, the English newspaper “News of the World” has recently been shut down over reports that the paper’s reporters regularly hacked into the voicemail boxes of celebrities and political figures to gather news for stories. The hacking has had huge ripple effects, ranging from its impact on UK politics to Rupert […]

Continue Reading 42

Petition for Rehearing Filed in United States v. Nosal, the Ninth Circuit Case on Criminalizing Violations of Computer Use Policies

A petition for rehearing was recently filed in United States v. Nosal, the Ninth Circuit decision holding that an employee who violates his employer’s computer use policy is guilty of “exceeding authorized access” to the employer’s computer. I have posted a copy here. I hope the Ninth Circuit grants rehearing, as I think the Nosal […]

Continue Reading 28

Employer Sues Former Employee For Checking Facebook and Personal E-Mail and “Excessive Internet Usage” at Work

The Ninth Circuit recently ruled that an employee “exceeds authorized access” to his employer’s computer when he violates the employer’s Internet use restrictions: Given that federal law criminalizes exceeding authorized access, see 18 U.S.C. 1030(a)(2)(C), that would mean that every employee who surfs the Internet, checks Facebook, or logs in to personal e-mail from work […]

Continue Reading 23

Copying Public Website In Violation of Terms of Use Doesn’t Violate the Computer Fraud and Abuse Act, District Court Holds

The case is Koch Industries, Inc. v. Does, 2011 WL 1775765 (D.Utah 2011), handed down May 9. In this case, a group called “Youth for Climate Truth” copied the Koch Industries website (kochind.com) and created a fake website designed to look just like it at koch-inc.com. The “Youth for Climate Truth” then issued a fake […]

Continue Reading 10

Eleventh Circuit Holds That It is a Federal Crime For an Employee To Use His Employer’s Computer For “Non Business Reasons” After Receiving Clear Instruction From Employer Not to Do So

Last week, the Eleventh Circuit decided an important case, United States v. Rodriguez, on the computer crime statute known as the Computer Fraud and Abuse Act, 18 U.S.C. 1030. The decision by Judge Pryor touches on the same issue that was in play in the Lori Drew case: When does violating express conditions on computer […]

Continue Reading 88

United States v. John and the Meaning of “Authorization” to Access a Computer

The federal computer crime statute criminalizes accessing a computer “without authorization” or “exceeding authorized access,” with the important caveat that no one seems to know what it mean to access a computer “without authorization” or to “exceed authorized access.” See 18 U.S.C. 1030. The concepts are particularly tricky in the case of a written restriction […]

Continue Reading 66

Powered by WordPress. Designed by Woo Themes