The federal government has further work to do defining what constitutes "good faith" security research when applying the Computer Fraud and Abuse Act. But in the meantime, security researchers should "take the W" and embrace recent victories, a Justice official said Monday.A Supreme Court opinion issued last year, Van Buren vs. United States, significantly narrowed the scope of the CFAA’s application to incidents where an individual accessed a computer “in excess of authorization.” More recently, the department formalized a policy that officials say it has long followed informally: not charging hackers who conduct “good faith” security under the CFAA.Both of those changes signal that after years of ambiguity, the legal system is coming around to the idea that third-party researchers scrutinizing products and systems are a vital part of the United States’ cybersecurity ecosystem.“DoJ takes computer security research quite seriously — we do value it,” said Leonard Bailey, head of the cybersecurity unit and special counsel for national security in the Computer Crime and Intellectual property section at DoJ. “We believe that cybersecurity is complicated enough to not take certain players off the playing field when they’re helping.”Click here for all the coverage coming out of RSAC.Despite this sentiment, the CFAA remains one of the most feared laws in the cybersecurity community, one that some security researchers say still creates a chilling effect around their work. That view initially caused confusion within DoJ because in responding to those concerns, the department went back to look at the last decade of cases it has prosecuted and found only one in which the CFAA was used against a security researcher for doing computer security research.“We took a look at our practices to figure out where we might be — for example, going after security researchers — and one of the things we discovered was that we weren’t,” he said.However, further discussions with the information security community caused Bailey to realize ethical hackers did, in fact, have a legitimate beef with being pursued under the CFAA, just not by the federal government.That’s because in addition to allowing for the criminal prosecution of hackers who violate the law, the CFAA also allows private individuals and organizations to bring legal action against those same researchers. Until recently, businesses could legally bring a claim for trivial or absurd violations of their terms of service, such as creating fictional accounts on their website or posting under a pseudonym on a social networking site.Circuit courts around the country have interpreted those laws differently, with most either reining in the way the CFAA defines “in excess of authorization” or endorsing it. But the end result is a series of split decisions that only add to the confusion and the sense that “the exact scope of your liability was really determined by where your courthouse was,” said Haley Geiger, senior director for public policy at Rapid7.
RSAC, Threat Management, Threat Management
The (still) unanswered questions around the CFAA and ‘good faith’ security research

U.S. Attorney General Merrick Garland, center, announces a resolution of a foreign-bribery investigation during a news conference. The past year has brought a number of court-imposed and policy changes to the nation’s premier hacking law, the Computer Fraud and Abuse Act (CFAA). (Photo by Chip Somodevilla/Getty Images)
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



