Search This Blog

Showing posts with label Computer Fraud and Abuse Act. Show all posts
Showing posts with label Computer Fraud and Abuse Act. Show all posts

Monday, April 18, 2016

How to Get Away With Unethical Lawyering, Season 1, Episode 2

Long ago I wrote a post on the first episode of How to Get Away With Murder detailing the plethora of ethical violations committed by the characters. After writing that post, however, work got busier, other legal issues grabbed my attention, jobs changed, and How to Get Away With Murder was not yet on Netflix. My attention turned to other things, and the show (and even blogging) fell off my radar.

Today, I begin to remedy this state of affairs.

This is the first of a regular series of blog posts in which I issue-spot the ethical violations in How to Get Away With Murder. Unlike other commentators who highlight the broader inaccuracies in the show's portrayal of the legal profession, these posts will focus primarily on the ethical violations committed by the show's characters. As with my first post, I will cite to Pennsylvania's Rules of Professional Conduct.

This post (and those to follow) contain spoilers for those who have not yet seen the show. My posts will start with Season One and both seasons of the show are on Netflix, so those of you who want to watch the show and avoid spoilers should have no difficulty catching up.

Sunday, February 9, 2014

Hacking Drones

From the BBC:

Independent IT security analyst Samy Kamkar showed that taking control of a civilian drone was possible in December 2013. He equipped a Parrot AR Drone 2.0 with a tiny Raspberry Pi computer, a battery and two wireless transmitters. The microcomputer ran a simple piece of software, which directed the drone to search for the wi-fi signals used to control nearby Parrot drones. Once his drone had found a victim, the program used the wireless transmitters to sever the target drone’s link to its owner and took control. According to Kamkar, a handheld computer on the ground can do the trick too. 
[Professor Todd] Humphreys calls Kamkar’s work “a clever hack” and predicts that “it won't be the last one against commercial drones; hackers will find flaws and exploit them.” 
David Mascarenas, who works for the National Security Education Center at Los Alamos National Labs, agrees. As drones are nothing but flying computers, he says they “have the potential to exhibit never before seen security flaws that couple both cyber and physical security concerns.”
The rest of the article discusses concerns that U.S. military drones may be hacked, and efforts that are being taken to address this possible danger. This story illustrates how a wider view of cybersecurity is needed as technology develops. Computers will increasingly be a part of new technology, such as drones, and are increasingly becoming a part of old technology, such as household appliances. This expansion of computer technology necessitates a corresponding expansion of cybersecurity programs and tactics.

Tuesday, October 8, 2013

Appellate Division in New York Upholds "Computer Trespass" Conviction

The case is People v. Puesan, and the court's opinion is available here.

The defendant was charged and convicted of "computer trespass" among other crimes, when he entered his place of employment while on disability leave and accessed computers in the office.  The court notes the
disability leave policy and security measures the office took:

Tom Allen, Vice President of Security at Time Warner, testified that an employee who is placed on work leave is not considered an active employee; his or her access card is disabled and thus cannot be used to gain access to the company's offices. This policy is announced in employee handbooks provided to employees, and any employee placed on leave is instructed by human resources department personnel regarding that policy. Since the public is not allowed to enter Time Warner Cable's Northern Manhattan office, security guards are stationed outside to ensure that those entering the building have valid ID cards.

Nevertheless, the defendant entered the office and accessed computers, apparently by using a program that generated password keys.  He resorted to this program after requesting the use of a coworker's login and password -- a request that was denied.

The appellate division of the superior court upheld the conviction and held that defendant had gained access to the computers "without authorization."  The court noted that New York's statute defined "without authorization" as "'access of a computer service by a person without permission . . . or after actual notice to such person, that such access was without permission' (Penal Law § 156.00[8])."  The court further clarifies what it takes for there to be access without authorization:

for access to be without authorization, the defendant must have had knowledge or notice that access was prohibited or "circumvented some security device or measure installed by the user"

The court held that the defendant's knowledge that he was not allowed in the building, and his use of the program to overcome the password security violated the statute.

While this case is clear, I feel like it is worth flagging because the court's definition of "without authorization" is relevant to a current debate over the meaning of a similar provision in the federal Computer Fraud and Abuse Act, and could help inform debate on the subject.  

The definition of "without authorization" continues to be a topic of dispute at the federal level, with the case of United States v. Auernheimer in the Third Circuit being a particularly notable example.  Cases like Puesan that clarify the definition of "without authorization" are particularly important, since the definition of this term in the federal context varies widely, depending on the circuit.

Friday, October 4, 2013

Thirteen Members of Anonymous Indicted for DDoS Attack

The New York Times Reports:

Hackers took down the sites by inflicting a denial of service, or DDoS, attack, in which they fired Web traffic at a site until it collapsed under the load. Though the indictment mentions 13 hackers, thousands more participated in the attack by clicking on Web links that temporarily turned their computers into a digital fire hose aimed at each victim, in this case the Web sites.
According to the indictment, which was handed up at Federal District Court in Alexandria, Va., the hackers’ tool of choice was a simple open-source application known as Low Orbit Ion Cannon, which requires very little technical know-how.
Hackers simply posted a Web link online that allowed volunteers to download an application that turned their computer into a “botnet,” or network of computers, that flooded targets like Visa.com and MasterCard.com with traffic until they crashed.
The indictment is available here.

This attack was known as "Operation Payback" and seemed to have been launched as a way of protesting strict intellectual property laws and entities.  The attack targeted the U.S. Copyright Office, the Motion Pictures Association of America, and Mastercard, and others.

Mike Maznick at Techdirt uses this incident as an raise the argument that DDoS attacks should not be treated harshly because they are a modern equivalent of a sit-in (he has raised this argument before: see here and here).  I have strong doubts about the strength of this argument, namely because launching a DDoS attack does not carry with it the same expressive connotations as appearing in a certain place in protest.  Moreover, the information "communicated" through the attack is not expressive because it is not meant to be read by the recipient -- rather it is meant to override the recipient's capacity to read.

Maznick and other commentators also criticize the damage portion of the indictment that alleges that the attack caused over $5,000 in damage -- with Maznick wondering how DDoS attacks cause damage and with ARS Technica's Cyrus Farivar sniping that Mastercard makes millions in profits.

These arguments are also misguided.  DDoS attacks can certainly cause damages.  As this report indicates, lost productivity and reputation costs are ranked as the most significant costs of these attacks, though damage to property and equipment also made the list.  Moreover, these attacks can cost their victims anywhere from tens to hundreds of thousands of dollars, depending on the size of the attack.  The indictment lists damages of $5,000 because that is the minimum damage amount required by the criminal statute.

Finally, Maznick ponders how a DDoS attack can cause damage "without authorization," as any member of the public is free to send traffic to websites.  This concern is a little bit more interesting, but also mistaken.


Friday, August 2, 2013

A Fizzled Debate Raises an Interesting Question About the Computer Fraud and Abuse Act

Exciting times over at the Volokh Conspiracy.

Stewart Baker posted about Michael Vatis’ post (which seems to have been removed).  Baker argued that the Obama Campaign’s practice of having workers log in to Facebook and use the campaign website’s software to create and send messages to their undecided friends constitutes a violation of the Computer Fraud and Abuse Act (CFAA).  Baker thought that this could be the makings of a new scandal for the administration.   

Orin Kerr then chimed in and pointed out that there was probably no violation of the CFAA, noting that the violation would probably only have occurred under a broad reading of the law that the Department of Justice holds.  Kerr notes that under the DOJ’s interpretation – that illegal, “unauthorized” access occurs whenever a user violates the terms of service on a website – everybody is probably guilty of violating the CFAA.

Baker ended up retracting his original post, noting that upon further review of Facebook’s terms of service, it appeared that the Obama Campaign had complied and did not violate the CFAA even under the DOJ’s broad interpretation.

While it appears that Baker’s original concerns about violating the statute were misguided, I feel like had Facebook’s terms of use not authorized the campaign’s practice, this situation would have been a harder case than Kerr argued.