Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think there is a lack of distinction over exploiting to obtain data or exploiting data obtained. In the web-server case I would argue access was allowed unfettered but authorization for the data was not. This is how more than a few cases have gone down. Gotchas don't really cut it in court.

Edit: My original comment further up in this thread hinted at this difference and how lawyers seem to be trying to shift the line so unwanted access by a user is treated the same as exploitation of the data within even if the data was not exploited upon.



While I'm not with you on how "lawyers" are trying to "shift the lines" on the distinction between accessing and exploiting information, which simply does not exist in the law, I agree that the distinction is important; in a perfect world, non-commercial non-malicious non-damaging use of unauthorized data would be relegated by the sentencing guidelines to something less than a felony.


"which simply does not exist in the law"

Rather sure it does, some crimes like credit card fraud are separate from unauthorized access of the computer systems the information came from. Exploiting the data is not the same as exploiting to access the data.

Lawyers are deployed to push their client's POV, wins or losses may "shift the line" regarding how written laws are upheld in court. Which in my opinion is used by some as a chance to defray from responsibility to properly administer public facing systems.


Here's the CFAA:

http://www.law.cornell.edu/uscode/text/18/1030

Perhaps it would be simpler if you just pointed to the part of the statute you're referring to, because I don't follow your argument.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: