Hacking Law Must Be Revised to Prevent Its ‘Gross Misuse’
Today, the Center for Democracy & Technology joined a group of individuals and organizations from across the philosophical spectrum in signing a letter to Senators Patrick Leahy (D-VT) and Chuck Grassley (R-IA) on recommended reforms to the Computer Fraud and Abuse Act (CFAA).
The Senate Judiciary Committee, of which Senators Leahy and Grassley are Chairman and Ranking Member, respectively, is planning to hold a hearing on “Cybercrime: Updating the Computer Fraud and Abuse Act to Protect Cyberspace and Combat Emerging Threats.” So far, only government witnesses have been named to the panel, and they will likely submit testimony that support the Administration’s proposals to increase CFAA penalties.
Revisions to the CFAA are necessary because, while the law imposes civil and criminal liability for accessing a computer without or in excess of authorization, it does not clearly define “authorization.” This vagueness has led to an overbroad application of the CFAA and has exposed employees to criminal liability for breaching employers’ network terms of service, and social network users to criminal liability for violating terms of service of their social network. The letter notes:
Three federal circuit courts have agreed that an employee who exceeds an employer’s network acceptable use policies can be prosecuted under the CFAA. At least one federal prosecutor has brought criminal charges against a user of a social network who signed up under a pseudonym in violation of terms of service.
Instead of focusing solely on malicious hacking and identity theft, the CFAA has been used to turn acts into “computer crimes” that would not be considered criminal in the physical world, “[t]his is a gross misue of the law,” the letter says. The letter cites examples, and calls for the Committee to address these issues.
CDT-led Coalition Calls for Transparency for White House AI Framework
CDT and Americans for Responsible Innovation led a broad, bipartisan coalition of over two dozen civil society groups in calling on the White House to release its Framework for review of frontier AI models.
CDT Amicus Brief Calls on Fourth Circuit to Rein In Geofence Warrants
Earlier this year the Supreme Court ruled in Chatrie v United States that the Fourth Amendment protected all cell phone location information, which CDT lauded as a landmark decision, but sent the case back down to the Fourth Circuit to assess the propriety of the geofence warrant at issue.
CDT and Partners Post Floor Alert Opposing CA SB 1013 Automated License Plate Readers Bill
The best way to ensure that Automated License Plate Readers are not abused is to limit the retention of stored data and to keep loopholes to lawful process closed. CA SB 1013 is a step in the wrong direction, and we urge the California legislature to reject this approach.
British Public Oppose Secret Surveillance Powers and Want Strong Protections for Encrypted Communications
CDT released nationally representative polling data revealing that a the British public are broadly concerned about the security, privacy, and free speech consequences of allowing law enforcement to access encrypted communications.