{"id":243222,"date":"2017-12-30T13:01:41","date_gmt":"2017-12-30T11:01:41","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=243222"},"modified":"2017-12-30T13:02:27","modified_gmt":"2017-12-30T11:02:27","slug":"the-worst-law-in-technology","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/243222-the-worst-law-in-technology.html","title":{"rendered":"The worst law in technology"},"content":{"rendered":"<p><em>By EFF Deeplinks Blog<\/em><\/p>\n<p>The latest on the\u00a0<a href=\"https:\/\/www.eff.org\/deeplinks\/2016\/12\/our-fight-rein-cfaa-2016-review\">Computer Fraud and Abuse Act<\/a>? It\u2019s still terrible. And this year, the detrimental impacts of the notoriously vague and outdated criminal computer crime statute showed themselves loud and clear. The statute lies at the heart of the Equifax breach, which might have been averted if our laws didn\u2019t criminalize security research. And it\u2019s at the center of a court case pending in the Ninth Circuit Court of Appeals,\u00a0<a href=\"https:\/\/www.eff.org\/cases\/hiq-v-linkedin\">hiQ v. LinkedIn<\/a>, which threatens a hallmark of today\u2019s Internet: free and open access to publicly available information.<\/p>\n<p>At EFF, we\u2019ve spent 2017 working to make sure that courts and policy makers understand the role the CFAA has played in undermining security research, and that the Ninth Circuit rejects LinkedIn\u2019s attempt to transform a criminal law meant to target serious computer break-ins into a tool for enforcing corporate computer use policies. We\u2019ve also continued our work to protect programmers and developers engaged in cutting-edge exploration of technology via our\u00a0<a href=\"https:\/\/www.eff.org\/issues\/coders\">Coders\u2019 Rights Project<\/a>\u2014coders who often find themselves grappling with the messiness that is the CFAA. As this fight carries us into 2018, we stand ready to do all we can to rein in\u00a0<a href=\"https:\/\/www.newyorker.com\/news\/news-desk\/fixing-the-worst-law-in-technology\">the worst law in technology<\/a>.<\/p>\n<h3 class=\"my-4\">Equifax<\/h3>\n<p>The CFAA makes it illegal to engage in \u201cunauthorized access\u201d to a computer connected to the Internet, but the statute doesn\u2019t tells us what \u201cauthorization\u201d or \u201cwithout authorization\u201d means. This vague language might have seemed innocuous to some back in 1986 when the statute was passed, but in today\u2019s networked world, where we all regularly connect to and use computers owned by others, courts\u00a0<a href=\"http:\/\/thehill.com\/blogs\/congress-blog\/judicial\/264061-supreme-court-needs-to-clarify-the-scope-of-the-cfaa\">cannot even agree<\/a>\u00a0on what the law covers. And as a result, this pre-Web law is causing serious problems.<\/p>\n<p>One of the biggest problems: the law notorious for\u00a0<a href=\"https:\/\/www.eff.org\/deeplinks\/2013\/08\/letter\">chilling the work of security researchers<\/a>.<\/p>\n<p>Most of the time, we never hear about the research that could have prevented a security nightmare. But with Equifax\u2019s data breach, we did. As if the news of the catastrophic breach wasn\u2019t bad enough, we learned in October\u2014thanks to\u00a0<a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/ne3bv7\/equifax-breach-social-security-numbers-researcher-warning\">reporting<\/a>\u00a0by Motherboard\u2014that a security researcher had warned Equifax \u201c[m]onths before its catastrophic data breach . . . that it was vulnerable to the kind of attack that later compromised the personal data of more than 145 million Americans[.]\u201d According to Equifax\u2019s own timeline, the company didn\u2019t patch the vulnerability for six months\u2014and \u201conly after the massive breach that made headlines had already taken place[.]\u201d<\/p>\n<p>The security researcher who discovered the vulnerability in Equifax\u2019s system back in 2016 should have been empowered to bring their findings to someone else&#8217;s attention after Equifax ignored them. If they had, the breach may have been avoided. Instead, they faced the risk of a CFAA lawsuit and potentially\u00a0<a href=\"https:\/\/www.eff.org\/deeplinks\/2016\/10\/what-were-scared-about-halloween-prosecutorial-discretion-under-notoriously-vague\">decades in federal prison.<\/a><\/p>\n<p>In an era of massive data breaches that impact almost half of the U.S. population as well as people around the globe, a law that ostracizes security researchers is foolish\u2014and it undermines the security of all of us. A security research exemption is necessary to ensure that our security research community can do their work to keep us all safe and secure without fear of prosecution. We\u2019ve been\u00a0<a href=\"https:\/\/www.eff.org\/deeplinks\/2013\/06\/aarons-law-introduced-now-time-reform-cfaa\">calling for these reforms<\/a>\u00a0for years, and it\u2019s long overdue.<\/p>\n<h3 class=\"my-4\">hiQ v. Linkedin<\/h3>\n<p>One thing that\u2019s consistently gotten in the way of CFAA reform: corporate interests. And 2016 was no different in this respect. This year, LinkedIn has been pushing to expand the CFAA\u2019s already overly broad scope, so that it can use the statute to maintain its edge over a competing commercial service, hiQ Labs. We blogged about the\u00a0<a href=\"https:\/\/www.eff.org\/deeplinks\/2017\/08\/judge-cracks-down-linkedins-shameful-abuse-computer-break-law\">details of the dispute<\/a>earlier this year. The social media giant wants to use the CFAA to enforce its corporate policy against using automated scripts\u2014<i>i.e<\/i>., scraping\u2014to access publicly available information on the open Internet. But what that would mean is potentially criminalizing automated tools that we all rely on every day. The web crawlers that power Google Search, DuckDuckGo, and the Internet archive, for instance, are all automated tools that collect (or scrape) publicly information from across the Web. LinkedIn paints all \u201c<a href=\"https:\/\/en.wikipedia.org\/wiki\/Internet_bot\">bots<\/a>\u201d as bad, but they are a common and necessary part of the Internet. Indeed, \u201c<a href=\"https:\/\/www.incapsula.com\/blog\/bot-traffic-report-2016.html\">good bots<\/a>\u201d were responsible for 23 percent of global Web traffic in 2016. Using them to access publicly available information on the open Internet should not be punishable as a federal felony.<\/p>\n<p>Congress passed the CFAA to target serious computer break-ins. It did not intend to hand private companies a tool for enforcing their computer use policies. Using automated scripts to access publicly available data does not involve breaking into any computer, and neither does violating a website\u2019s terms of use. Neither should be CFAA offenses.<\/p>\n<p>LinkedIn\u2019s expansive interpretation of the CFAA would exacerbate the law\u2019s chilling effects\u2014not only for the security research community, but also for\u00a0<a href=\"https:\/\/www.propublica.org\/article\/how-we-analyzed-amazons-shopping-algorithm\">journalists<\/a>,\u00a0<a href=\"https:\/\/www.aeaweb.org\/articles?id=10.1257\/app.20160213\">discrimination researchers<\/a>, and others who use automated tools to support their socially valuable work. Similar lawsuits are already starting to pop up across the country, including one by airline\u00a0<a href=\"https:\/\/www.geekwire.com\/2017\/ryanair-sues-expedia-accusing-online-travel-giant-illegally-scraping-site-sell-flights\/\">RyanAir<\/a>\u00a0alleging that Expedia&#8217;s fair scraping violated the CFAA.<\/p>\n<p>Luckily, a court in San Francisco\u00a0<a href=\"https:\/\/www.eff.org\/document\/hiq-v-linkedin-order-granting-hiqs-preliminary-injunction-motion-against-linkedin\">called foul<\/a>, questioning LinkedIn\u2019s use of the CFAA to block access to public data, finding that the \u201cbroad interpretation of the CFAA invoked by LinkedIn, if adopted, could profoundly impact open access to the Internet, a result that Congress could not have intended when it enacted the CFAA over three decades ago.\u201d<\/p>\n<p>The case is now on appeal, and EFF, DuckDuckGo, and the Internet Archive have\u00a0<a href=\"https:\/\/www.eff.org\/deeplinks\/2017\/12\/eff-court-accessing-publicly-available-information-internet-not-crime\">urged<\/a>\u00a0the Ninth Circuit Court of Appeals to uphold the lower court&#8217;s finding and reject LinkedIn\u2019s shortsighted request to transform the CFAA into a tool for policing the use of publicly available data on the open Internet. And we\u2019re hopeful it will. During a Ninth Circuit oral argument in a different case\u00a0in July, Judge Susan Graber\u00a0<a href=\"https:\/\/www.ca9.uscourts.gov\/media\/view_video.php?pk_vid=0000011927\">pushed back<\/a>\u00a0[at around 33:40] on Oracle\u2019s argument that automated scraping was a CFAA violation.<\/p>\n<p>LinkedIn says it wants to protect the privacy of user data. But public data is not private, so why not just put the data behind its pre-existing username and password barrier? It seems that LinkedIn wants to take advantage of the benefits of the open Internet while at the same time abusing the CFAA to avoid the Web\u2019s \u201c<a href=\"http:\/\/columbialawreview.org\/content\/norms-of-computer-trespass\/\">open trespass norms<\/a>.\u201d The CFAA is an old, blunt instrument, and trying to use it to solve a modern, complicated dispute between two companies will undermine open access to information on the Internet for everyone. As we said in our amicus brief:<\/p>\n<blockquote><p>The power to limit access to publicly available information on the Internet under color of the law should be dictated by carefully considered rules that balance the various competing policy interests. These rules should not allow the handful of companies that collect massive amounts of user data to reap the benefits of making that information publicly available online\u2014<i>i.e<\/i>., more Internet traffic and thus more data and more eyes for advertisers\u2014while at the same time limiting use of that public information via the force of criminal law.<\/p><\/blockquote>\n<p>The Ninth Circuit will hear oral argument on the LinkedIn case in March 2018, and we\u2019ll continue to fight LinkedIn\u2019s expansive interpretation of the CFAA into the New Year.<\/p>\n<p><a href=\"https:\/\/www.eff.org\/deeplinks\/2017\/12\/worst-law-technology-strikes-again-2017-review\" target=\"_blank\" rel=\"noopener\">EFF<\/a><\/p>\n<h3 class=\"my-4\">Now read:\u00a0<a href=\"https:\/\/mybroadband.co.za\/news\/security\/242784-biggest-security-stories-in-south-africa-in-2017.html\" rel=\"bookmark\">Biggest security stories in South Africa in 2017<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>The latest on the\u00a0Computer Fraud and Abuse Act? It\u2019s still terrible.<\/p>\n","protected":false},"author":23,"featured_media":123802,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[21797,35],"class_list":["post-243222","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-eff","tag-headline"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/243222"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=243222"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/243222\/revisions"}],"predecessor-version":[{"id":243224,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/243222\/revisions\/243224"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/123802"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=243222"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=243222"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=243222"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}