“Some of the things you look at considering are the history of the person, including criminal history, and the severity of the offense,” says Christian (left), who is now an attorney with the international law firm Mayer Brown. There is an issue of deterrence and an issue for young folks in terms of talent that could be developed by the cybersecurity community, Christian says. Look closer at federal handling of youth hacking cases, he adds, and you will find discretion being used.However, given the breadth of anti-hacking legislation, discretion under the law may not be sufficient, says Glenn Chisholm, chief technology officer at Cylance, the Irvine, Calif.-based provider of anti-malware products. “The bundling of all crimes involving a computer leads to the inevitable demand that severe punishment be applied in some attempt at creating a deterrent,” Chilsholm says. “Of course, no minor seeking to satiate their intellectual curiosity, without intent, damage or seeking to make a financial gain should be punished as we would an adult. It should be a teachable moment that allows the individual to develop and contribute to society rather than face extended jail time, a damaged future and a massive real cost to society.”In any event, young hackers do often intentionally break the law for financial gain, sometimes causing significant financial damage. Yet even in those cases, the authorities shouldn't come down on these youthful offenders as if they were adults, says Misha Glenny, a British journalist who specializes in cybersecurit and author of DarkMarket: How Hackers Became the New Mafia.Young hackers hone their skills before their moral compass is fully formed, Glenny says. “They are often very impressionable at this age and the target of criminals, intelligence agencies and other state and non-state actors who are only too willing to offer them incentives to use their hacking and social engineering capabilities for subversive ends.” Law enforcement should prioritize rehabilitation of young hackers over prosecution, says Glenny. “Locking them up in severe regimes, which happens regularly in the United States, for example, is simply going to deepen their hostility to the state and push them in the direction of a masters [degree] from the university of crime.”
The most prominent effort to keep young cybersecurity enthusiasts away from online misdeeds is the USCC, a nonprofit organization backed by business and government that seeks to recruit 10,000 young people to cyberdefense jobs. At the USCC camp, young people participate in an ethics panel with the FBI, the Secret Service, (ISC)2 and industry executives. “The campers discuss their motivations and why they are doing what they do,” says Karen Evans (right), USCC national director. Participants get to hear from the cybersecurity community on how their actions may be interpreted.But the lack of criminal intent by young hackers is no guarantee of escaping prosecution. That's because the CFAA, along with similar state statutes, are written too broadly, says Hanni Fakhoury, a senior staff attorney on the civil liberties team of the Electronic Frontier Foundation (EFF), a San Francisco-based nonprofit organization which advocates for civil liberties.“Bad people are doing bad things, and they should be prosecuted,” Fakhoury says. “We don't have a problem with that.” The issue, he says, is that people are being charged under CFAA for things such as violating a website's terms of service – as when Missouri native Lori Drew was unsuccessfully prosecuted for using a fake MySpace account in a cyberbullying case that involved the suicide of a 13-year-old. Another controversial CFAA case – United States vs. Nosal, currently before the United States Court of Appeals for the Ninth Circuit – was brought because of an alleged violation of employer-dictated computer policy. With such broad interpretation of CFAA and similarly written state statutes, young pranksters can find their futures threatened by aggressive prosecutors, Fakhoury says, pointing to the case of Domanik Green, a 14-year-old middle school student in Holiday, Fla., who faced a state felony charge for hacking his teachers' computer and placing a photo on its home screen.And from the EFF's perspective, those problems could soon get worse, given proposed changes to CFAA that Fakhoury calls “terrible.”“People are talking about criminal law reform,” he says. “When it comes to the CFAA, the tendency is the opposite – to make it broader and make the penalties harsher.” | Headstart: USCC to the rescue
“Given events in both the public and private sectors, it is undoubtedly clear to all that we have a long way to go to properly secure our networks and protect the private information of individuals,” said Federal Communications Commission CIO David Bray. “Seeing these individuals competing in the U.S. Cyber Challenge CTF gives me hope that we have the talent and it's just a matter of working with them to get them into the right jobs to help protect our nation and reduce vulnerabilities.” USCC photo by Prudy Pierson |
U.S. Cyber Challenge (USCC) announced the winners of its sixth Annual Delaware Cyber Camp competition. Following a week of intensive classroom instruction on a variety of cybersecurity topics, more than 60 participants competed in a “Capture the Flag” competition on July 24 at Delaware Technical Community College in Dover. Those who came out on top and won the competition include Alyssia Bates, Jon Butler, Rauni Kangas and Tim Plimpton.


