SpinSafe
  • Cloud Backup Solutions
  • Torrents
    • Are Torrent Websites Safe?
    • How to Torrent
    • Popular Torrent Website List
  • Best VPN
  • Security Alerts
    • National Cyber Alerts
    • NIST
  • How To
    • Secure Your Wireless Network
    • Home Network Security
  • News
    • Active Threat Alerts
    • Computer Security News
    • Internet Security News
    • Mobile Security News
    • Tech Video News
  • Search
  • Menu Menu
  • Twitter
  • Rss

Cybersecurity researchers no longer will face hacking charges under CFAA

May 24, 2022/in Computer Security


Placeholder while article actions load

The U.S. Justice Department on Thursday said it would not use the country’s long-standing anti-hacking law to prosecute researchers who are trying to identify security flaws, a move that provides both protection and further validation for a craft still villainized by many officials, companies and the general public.

In a news release and five-page policy statement issued to federal prosecutors, top Justice officials said local U.S. attorneys should not bring charges when “good faith” researchers exceed “authorized access,” a vague phrase from the 1986 Computer Fraud and Abuse Act (CFAA) that has been interpreted to cover such routine practices as automated downloads of Web content.

The guidance defines good faith to mean research aimed primarily at improving the safety of sites, programs or devices, as opposed to exploration aimed at demanding money in exchange for withholding disclosure or exploitation of a security flaw.

Companies can still sue those who claim to be acting in good faith, and officials could continue to charge hackers under state laws that often echo the CFAA. But most state prosecutors tend to follow federal guidance when their laws are similar.

Well-intentioned hackers in the past were routinely silenced by legal threats. Even in recent years, civil suits and criminal referrals have been used to cancel public talks on dangerous vulnerabilities or cast doubt on research findings.

In 2019, a mobile voting company, Voatz, referred to the FBI a Michigan college student who was researching its app for a course. Twenty years ago, a former employee of email provider Tornado Development served more than a year in prison on federal CFAA charges after the company refused to fix security flaws and he emailed their customers about it.

In a case that drew national attention in October, the governor of Missouri threatened hacking charges against a local newspaper that examined the publicly available source code of a government website and then warned the state that it was exposing the Social Security numbers of 100,000 educators.

The Justice Department did not respond to a question about what prompted the new policy.

But security work…

Source…

Share this entry
  • Share on Facebook
  • Share on Twitter
  • Share on WhatsApp
  • Share on Pinterest
  • Share on Tumblr
  • Share on Reddit
https://spinsafe.com/wp-content/uploads/2022/05/DDGQFKWGZQI6ZDH7GOYFT5GBW4.jpgw1440.jpeg 960 1440 SecureTech https://spinsafe.com/wp-content/uploads/2016/11/spinsafelogo-1.png SecureTech2022-05-24 00:00:152022-05-24 00:00:15Cybersecurity researchers no longer will face hacking charges under CFAA

Archives

© 2022 SpinSafe
SpinSafe may be compensated by providing links to products, services, websites, and various other options.
  • Twitter
  • Rss
  • Privacy Policy
  • Terms of Service
Ransomware Protection Market Statistical Forecast, Trade Analysis 2022 –Intel...For New Microsoft MVP, training Power Platform beginners is all in a day’s...
Scroll to top