7 ms·
So, what about the Michael Thomas case? Does this verdict overturn his conviction? http://www.epspros.com/news-resources/news/2018/it-worker-loses-argument-jus
by matthewmarkus 5y ago
So, what about the Michael Thomas case? Does this verdict overturn his conviction?
http://www.epspros.com/news-resources/news/2018/it-worker-loses-argument-justifying-sabotage.html http://www.epspros.com/news-resources/news/2018/it-worker-lo...
"Mr. Thomas challenged the verdict, arguing that his conduct was not illegal because his IT position provided him full access to the system and empowered him to 'damage' the system by deleting files or taking the system offline. Thus, any acts were not 'without authorization.' The Fifth Circuit rejected this argument, finding that the statute’s prohibition against exceeding authorized access applies to insiders who go beyond the permission granted them in order to cause damage."
- ghaff 5y agoHe'd presumably be guilty of other things but those might well be civil. IANAL. But when laws/interpretations change, they're not necessarily retroactive.
- LocalPCGuy 5y agoI was initially going to say no, that when he went on to damage files, he caused material harm. He was not authorized to "damage" the system, and although he had access to the system and so gaining access in and of itself is not a crime, causing damage would be. But then I looked into the case a bit closer and I start to think he has an argument for not being charged under the CFAA. As with many laws, intent matters, so it is possible that if his intent was to harm the business, there may well be charges that could be applied in that realm. And obviously he could be held civilly liable for damages, which is no different than any other employee who does something to damage their employer's equipment. Offline example - if I work at a construction company, and I wreck construction equipment because I wasn't happy my co-worker got fired, that isn't going to be a criminal offense, but the company will likely fire me and try to collect damages. So I'm going to go back on my initial judgement and say that I think he may have grounds to get his conviction overturned and while he may be charged with other crimes, not sure it would come from the CFAA. *disclaimer, not a lawyer
- matthewmarkus 5y agoIf the CFAA doesn't apply to sys admins working at the highest levels of authorization, it seems to be a useless law. Foreign actors can simply hire sys admins to access whatever they want, no need for hacking. I really do think the court has opened Pandora's box on this one. They should've voided the statute for vagueness if that was the concern. As it stands now, it has to be one of the dumbest laws on the books.
- JumpCrisscross 5y ago> Foreign actors can simply hire sys admins to access whatever they want, no need for hacking This is prosecutable under a myriad of existing laws. CFAA was specifically crafted to deter and punish hacking. As far as I know, that's still very much a thing.
- treis 5y agoIt's not immediately clear which laws. The whole point of the CFAA was that existing trespass & theft laws don't really work for digital files.
- pbhjpbhj 5y agoEspionage is illegal.
- JumpCrisscross 5y ago> not immediately clear which laws Yes it is, theft of trade secrets [1]. [1] https://www.justice.gov/opa/pr/former-dow-research-scientist-sentenced-60-months-prison-stealing-trade-secrets-and-perjury https://www.justice.gov/opa/pr/former-dow-research-scientist...
- deleted 5y ago[deleted]
- LocalPCGuy 5y agoCompanies have a responsibility to vet their employees, first. I don't know how that is affected by the CFAA being a bit more constrained than it was before, which was extremely overly broad. I strongly disagree with your assessment (re: Pandora's box, dumbness), but I do think and acknowledge it is a law worthy of being replaced with one more up to date and more clear.