{"id":2085,"date":"2014-03-24T15:12:35","date_gmt":"2014-03-24T15:12:35","guid":{"rendered":"http:\/\/jolt.richmond.edu\/?p=2085"},"modified":"2019-03-08T19:52:29","modified_gmt":"2019-03-09T00:52:29","slug":"blog-the-overbroad-computer-fraud-and-abuse-act-its-implications-and-why-its-scope-should-be-narrowed","status":"publish","type":"post","link":"https:\/\/blog.richmond.edu\/jolt\/2014\/03\/24\/blog-the-overbroad-computer-fraud-and-abuse-act-its-implications-and-why-its-scope-should-be-narrowed\/","title":{"rendered":"Blog: The Overbroad Computer Fraud and Abuse Act: Its Implications and Why Its Scope Should be Narrowed"},"content":{"rendered":"<p>by Barry Gabay, Associate Staff<\/p>\n<p>If you are at work and you are reading this, you may be subject to federal criminal sanctions.<\/p>\n<p>The Computer Fraud and Abuse Act, the federal government\u2019s key anti-hacking law, was originally enacted in 1986 to deter hackers from wrongfully obtaining confidential governmental and financial information, or inflicting \u201cfederal interest\u201d computers with harmful viruses. \u00a0In passing the act, Congress sought to regulate only those computer crimes that were interstate in nature, particularly those involving large financial institutions and governmental organizations.<a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[1]<\/a> \u00a0However, the statute was amended several times to ultimately broaden the CFAA\u2019s reach.\u00a0 In the mid-90s, for example, Congress placed criminal misdemeanor liability upon individuals who acted merely \u201crecklessly\u201d in their computer use,<a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[2]<\/a> and later placed liability upon individuals who obtained and read \u201cany information of any kind so long as the conduct involved an interstate or foreign communication.\u201d<a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[3]<\/a> \u00a0But Congress went even further in 2008\u00a0when it most recently amended\u00a0the CFAA.\u00a0 For starters, Congress eliminated the $5,000 misappropriation threshold for CFAA liability. \u00a0But further, while previously a defendant must have stolen information through interstate commerce or foreign communication to be prosecuted under the CFAA, the statute was amended to now encompass all information obtained \u201cfrom any protected computer.\u201d<a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[4]<\/a> \u00a0<\/p>\n<p>Today, liability under the CFAA can be proven by showing that a defendant (1) intentionally accessed a computer (2) without authorization or exceeding authorized access, and thereby (3) obtained information from a protected computer.<a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[5]<\/a>\u00a0 The pertinent definition of \u201cprotected computer\u201d is any computer \u201cwhich is used in or affecting interstate or foreign commerce or communication.\u201d<a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[6]<\/a> \u00a0Courts have found that the Internet is \u201can instrumentality and channel of interstate commerce,\u201d thus within the realm of Congressional regulation, and for purposes of CFAA violations, the defining characteristic of a \u201cprotected computer.\u201d<a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[7]<\/a>\u00a0 To put it in perspective, this criminal statute was broadened from pertaining only to computers with direct \u201cfederal interest\u201d to now any computer connected to the Internet.<\/p>\n<p>Nevertheless, the main litigable issue has proven to be determining when an individual is \u201cauthorized\u201d to use a computer.\u00a0 Under the CFAA the phrase \u201cexceeds authorized access\u201d is \u201cto access a computer with authorization and to use such access to obtain or alter information in the computer that the accesser is not entitled to obtain or alter.\u201d<a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[8]<\/a> \u00a0Whereas an employee who uses a computer \u201cwithout authorization\u201d has \u201cno rights, limited or otherwise, to access the computer in question,\u201d an employee who \u201cexceeds authorized access\u201d had initial authorization to use the computer \u201cfor certain purposes but goes beyond those limitations.\u201d<a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[9]<\/a> \u00a0However, the phrase, \u201cwithout authorization\u201d is not defined in the CFAA, and a circuit split has thus developed over the interpretation of the phrase. \u00a0<\/p>\n<p>The majority broad view, adopted by the First, Fifth, Seventh and Eleventh Circuits, holds that an employee\u2019s computer authorization is terminated the moment that an employee acts contrary to his employer\u2019s interest.<a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[10]<\/a> \u00a0These circuits hold that any time an employee uses a company computer in a way not in direct benefit to his employer the Department of Justice has jurisdiction to prosecute.\u00a0 As Justice Floyd noted in the summer of 2012, \u201c[s]uch a rule would mean that any employee who checked the latest Facebook posting or sporting event scores in contravention of his employer\u2019s use policy would be subject to the instantaneous cessation of his agency and, as a result, would be left without any authorization to access his employer\u2019s computer systems.\u201d<a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[11]<\/a><\/p>\n<p>However, in the two most recent federal appellate cases on the issue, the Fourth and Ninth Circuits both adopted a narrow interpretation of the statute.\u00a0 Those circuits held that an employee is \u201cauthorized\u201d to use a company computer when the employer gives that employee permission to use it. \u00a0An employee\u2019s subsequent misuse of an employer\u2019s computer would not be subject to federal sanctions, as that employee was \u201cauthorized\u201d to use that computer under the CFAA. <a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[12]<\/a><\/p>\n<p>While a broad interpretation of the CFAA may deter some individuals from using computers in ways not intended by their employers, that deterrence derives from ludicrous sentencing for comparatively innocuous criminal actions.\u00a0 Aaron Swartz, the well-documented Internet activist who allegedly downloaded millions of articles from MIT\u2019s online library, faced a maximum sentence of 35 years incarceration before the 26-year-old took his own life. <a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[13]<\/a>\u00a0 In comparison, the maximum federal sentence for a first-time felon guilty of attempted murder who left the victim with life-threatening bodily injury is 24 years. \u00a0A first-time child pornographer who distributes images of a child under the age of 12 engaged in explicit sexual acts would receive a maximum federal sentence of 30 years imprisonment.\u00a0 If an employee merely getting fired by her employer is not enough deterrence for misusing a company computer, then state criminal statutes and tort and contract law surely provide adequate deterrence.\u00a0 Thus, in practice, the broad interpretation of the CFAA merely serves to make ordinary working individuals, who, while perhaps distracted during the workday possess no real criminal intent whatsoever, into federal criminals.\u00a0<\/p>\n<p>In the wake of Aaron Swartz\u2019s suicide, the Justice Department and members of Congress have recently expressed their willingness to narrow the scope of the Computer Fraud and Abuse Act.<a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[14]<\/a>\u00a0 The bipartisan Aaron\u2019s Law was introduced in the House of Representatives to limit the scope of the CFAA.\u00a0 That limitation is long overdue.\u00a0 It is a well-established canon of statutory construction that courts must construe criminal statutes narrowly, so as to avoid over-criminalization.\u00a0 But courts, obviously unable to define a crime, are relegated merely to the text, and hinge liability on the terms \u201cwithout authorization\u201d and \u201cexceeding authorized access.\u201d\u00a0 With the firmly entrenched circuit split now in place, the Supreme Court may in the not too distant future weigh in on the issue if Congress does not first amend this overbroad statute.<\/p>\n<div>\n<hr align=\"left\" size=\"1\" width=\"33%\" \/>\n<div>\n<p><a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[1]<\/a> <i>See <\/i>Sarah A. Constant, <i>The Computer Fraud and Abuse Act: A Prosecutor\u2019s Dream and a Ha<br \/>\ncker\u2019s Worst Nightmare\u2014The Case Against Aaron Swartz and the Need to Reform the CFAA<\/i>,<i> <\/i>16 Tul. J. Tech. &amp; Intell. Prop. 231, 233 (2013). \u00a0<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[2]<\/a> Computer Abuse Amendments Act, Pub. L. No. 103-322, tit. XXIX, 108 Stat. 2097 (1994).<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[3]<\/a> Economic Espionage Act, Pub. L. No. 104-294, tit. II, 110 Stat. 3488, 3491 (1996).\u00a0<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[4]<\/a> 18 U.S.C. \u00a71030(a)(2)(C) (2008).<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[5]<\/a> <i>Id.<\/i><\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[6]<\/a> 18 U.S.C. \u00a7 1030(e)(2)(B).\u00a0<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[7]<\/a> <i>United States v. Trotter<\/i>, 478 F.3d 918, 920-21 (8th Cir. 2007) (internal citations omitted).\u00a0<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[8]<\/a> 18 U.S.C. \u00a7 1030(e)(6).\u00a0<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[9]<\/a> <i>LVRC Holdings LLC v. Brekka<\/i>, 581 F.3d 1127, 33 (9th Cir. 2009).\u00a0<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[10]<\/a> <i>See See E.F. Cultural Travel BV v. Explorica<\/i>, 274 F.3d 577 (1st Cir. 2001); <i>United States v. John<\/i>, 597 F.3d 263 (5th<i> <\/i>Cir. 2010);<i> Int\u2019l Airport Ctrs., LLC v. Citrin<\/i>, 440 F.3d 418, 420-21 (7th Cir. 2006); <i>United States v. Rodriguez<\/i>, 628 F.3d 1258 (11th Cir. 2010).<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[11]<\/a> <i>WEC Carolina Energy Solutions LLC v. Miller<\/i>, 687 F.3d 199, 206 (4th Cir. 2012).<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[12]<\/a> <i>Brekka<\/i>, <i>supra <\/i>note 10, at 1133.<\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[13]<\/a> <i>See generally <\/i>David Amsden, <i>The Brilliant Life and Tragic Death of Aaron Swartz<\/i>, Rolling Stone (2013), <i>available at <\/i>http:\/\/www.rollingstone.com\/culture\/news\/the-brilliant-life-and-tragic-death-of-aaron-swartz-20130215.<i><\/i><\/p>\n<\/div>\n<div>\n<p><a title=\"\" href=\"https:\/\/jolt.richmond.edu\/Users\/Hayley\/Desktop\/JOLT\/CFAA%20Blog%20Post%20-%20Gabay.docx\">[14]<\/a> Brian Fung, <i>The Justice Department Used This Law to Pursue Aaron Swartz. Now It\u2019s Open to Reforming It.<\/i> Wash. Post. (Feb. 7, 2014 at 4:03 PM), http:\/\/www.washingtonpost.com\/blogs\/the-switch\/wp\/2014\/02\/07\/the-justice-department-used-this-law-to-pursue-aaron-swartz-now-its-open-to-reforming-it\/.<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>by Barry Gabay, Associate Staff If you are at work and you are reading this, you may be subject to federal criminal sanctions. The Computer Fraud and Abuse Act, the federal government\u2019s key anti-hacking law, was originally enacted in 1986 to deter hackers from wrongfully obtaining confidential governmental and financial information, or inflicting \u201cfederal interest\u201d [&hellip;]<\/p>\n","protected":false},"author":4287,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[51366],"tags":[],"class_list":["post-2085","post","type-post","status-publish","format-standard","hentry","category-blog-post"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paMHOZ-xD","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/2085","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/users\/4287"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/comments?post=2085"}],"version-history":[{"count":0,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/2085\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media?parent=2085"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/categories?post=2085"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/tags?post=2085"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}