news.volyx.in

Court: Violating a site’s terms of service isn’t criminal hacking (arstechnica.com)

513 points by LinuxBender · 2382 days ago · 111 comments on HN

Article summary

A US court has ruled that violating a website's terms of service is not equivalent to criminal hacking. The decision may impact how the Computer Fraud and Abuse Act (CFAA) is applied in the future. The ruling suggests that simply accessing a computer contrary to the owner's terms and conditions should not be a crime. Instead, the specific acts of searching for, accessing, and sharing privileged information should be the focus of criminal liability.

Main themes

  • CFAA interpretation
  • terms of service vs criminal law
  • hacking and unauthorized access
  • freedom of speech and security vulnerabilities
  • technical countermeasures and system security
  • criminal liability and prosecution guidelines

What commenters say

  • Violating a website's terms of service should not be considered criminal hacking, as it is a civil matter.
  • The CFAA is flawed and should be revised to clearly define what constitutes unauthorized access.
  • Technical countermeasures, rather than terms of service, should be the primary means of securing systems and determining authorized access.
  • Sharing information about a company's security vulnerabilities or lax practices should be protected under freedom of speech.
  • The definition of unauthorized access needs to be more clearly defined to avoid ambiguous and potentially unjust prosecutions.
  • Hacking attempts should be treated as a normal part of life, and systems should be designed to resist them, rather than relying on laws to deter them.
  • Criminal liability should be focused on the specific acts of accessing and sharing privileged information, rather than simply accessing a computer contrary to the owner's terms.
  • The court's decision may create headaches for prosecuting CFAA cases and highlights the need for clearer definitions and guidelines.