Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>This proviso wouldn't have helped Swartz (13 count indictment: 2 counts 'Wire Fraud' to obtain valuables; 5 counts 'Computer Fraud' to obtain unauthorized computer access and valuables; 5 counts 'Unlawfully Obtaining Information from a Protected Computer'; 1 count 'Recklessly Damaging a Protected Computer'). It wouldn't have helped Auernheimer (2 count indictment: 'Conspiracy to Access a Computer without Authorization', and 'Fraud in Connection with Personal Information').

Of course not. That's covered by the CFAA. The purpose of this bill is to get an information pipeline for cyber attacks on American companies or infrastructure. You cannot be charged with a "CISPA violation".



It was tptacek who touted CISPA as "specifically restricted from applying to Aaron Swartz-style ToS violations". That claim is false -- CISPA could and would be used to hoover up evidence that leads to Swartz-style Computer Fraud and Abuse Act prosecutions. So no citizen will be charged for a 'CISPA violation'... but they might be arrested, searched, or convicted based on data hoovered-up via CISPA.

(And here, 'hoover' refers to both the vacuum cleaner and the abusive 20th-century FBI director.)


CISPA would not authorize JSTOR to share information about a user exceeding the bounds of MIT's licensing agreement with the site. It says so explicitly. There was no need for it to say that; nobody was clamoring for CISPA to make abuse investigations harder. But it does, because the bill is not about TOS violations and they wanted to be clear. I do not understand why you're pretending that it isn't clear about this.


Huh? JSTOR, and MIT, and law enforcement thought -- and indeed the DoJ spent over a year prosecuting the idea -- that a CFAA 'cybersecurity crime' had been committed. Such alleged crimes are specifically what CISPA covers.

None of the 13 counts the DoJ charged (http://www.wired.com/images_blogs/threatlevel/2012/09/swartz...) relied on any "consumer terms of service" or "consumer license agreement" violation, so the exception you've quoted is irrelevant. (Also, there's no chance law enforcement would be advancing your strict short-leash interpretation of that exception, in actual practice. They'd try for an expansive idea of what 'cybersecurity crimes' are happening, and wait for the courts to maybe later snap them back. That amounts in most cases to a 'free look', because those whose information is 'shared' will usually never know unless prosecuted.)

Of course, even without CISPA, these parties were able to share information just fine. And if say law enforcement had wanted other Boston ISPs or cellular networks to reveal if they'd ever seen any similar traffic, CISPA would have allowed them to assert a 'good faith' interest in investigating an ongoing CFAA 'cybersecurity crime', and request more potential evidence from usage logs and customer accounts. All through immunized 'sharing', rather than formal subpoenas.

You've made the claim: "[CISPA is] specifically restricted from applying to Aaron Swartz-style ToS violations, or, for that matter, to intellectual property misappropriation".

As documented above, the Swartz case wasn't about ToS violations, so CISPA would be used to collect evidence against alleged future Swartz-like activities.

And I've asked for where CISPA specifically excludes IP crimes; you've not provided any reference to related bill text or expert interpretation. Maybe it exists; you haven't provided it when requested. Where did you get that idea?

Until I see that, forgive me for not accepting your repetitive assertions about what CISPA is really "about", when the available bill text and trusted legal experts suggest otherwise.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: