Aaron projects/CFAA

From Noisebridge
Revision as of 04:48, 9 November 2013 by Sj (talk | contribs)
Jump to navigation Jump to search
Goal
Let's prepare for a full repeal of the CFAA and replacement with sane law.
Questions
How would we construct good law in these areas, from scratch?
How do different areas of law, policy, and internet governance view the law and its impact?
What would it take to generate support for a [repeal + replace] action, in each area?
What are the professional and philosophical circles for each of these areas, where these issues are discussed?

Overview

The CFAA was developed over time as a merger of ~7 different areas of law. It has developed in an aggregate way, and few groups are happy with the current law. It is so broad that prosecutors like it because they can use it to force plea bargains, since it applies to almost everything in its sphere of action (relying on prosecutorial judgement).

Different parts of the story: National defense, cyber war, data sec, corporate law, contracts online. Authorization based on code, contract, social norms. Legal frameworks used to push political means. Career standards for prosecutors defined in political ways.

Background

Aaron's Law

Details

Aspects of the search
  • "Advanced technical crime" -- The deployment of the SS was a bit peculiar; but they were the only fed. agents trained in what they were looking for.
Civil rights concerns
  • Part of the prosecution that was particularly troubling: at one point in the invest., it felt that they were keeping the prosecution going b/c they'd spent so much time bringing it along. There was no will from victims to keep it going, and not necc. any other desire, but the prosecutors for their own reason wanted conclusion.
    Suggestion: employ economists to remind people of sunk costs
Three levels of problem
  • Occlusion of different agendas and sets of laws
    Compare pre-computer to post-computer laws for identical crimes.
  • Problems with prosecution as it happens today
    Motivations for initiating/closing cases
  • The nature of CFAA as it's been employed
    Failure of proportionality

EFF proposals

Limiting scope of "exceeding authorized access"
  • Say: contractual violation can't be the basis for this
Amend the Wire Fraud Act
Say: contractual violation can't be the basis for this