Aaron's Law Reintroduced To Try To Reform Dangerous, Broken Anti-Hacking Law

from the can-we-get-this-one-done-already? dept

We've written in the past how Rep. Zoe Lofgren and Senator Ron Wyden had introduced "Aaron's Law" (named after Aaron Swartz) as a way to fix the very broken CFAA law, which was used to throw the book at Swartz for downloading too many JSTOR journal articles on MIT's campus (where anyone on the network is allowed to download whatever they want from JSTOR). Swartz later committed suicide, which many blame on the aggressive prosecution against him (I hesitate to join those who do so, as you never know all the factors that went into the decision). Still, the CFAA has long needed a massive overhaul, as the law is frequently abused by law enforcement to threaten massive penalties for rather routine activities on a computer network.

Lofgren and Wyden have now reintroduced Aaron's Law, and this time they've added Senator Rand Paul as a sponsor, which is interesting to see (especially as he courts the tech industry). They also have a nice group of co-sponsors, including Reps. Jim Sensenbrenner, Mike Doyle, Dan Lipinski, Jared Polis and Beto O'Rourke. Here are the three key things the new bill does, according to Lofgren:
  • Establishing that breaches of terms of service, employment agreements, or contracts are not automatic violations of the CFAA. By using legislative language based closely on 9th and 4th Circuit Court opinions, the bill would instead define 'access without authorization' under the CFAA as gaining unauthorized access to information by circumventing technological or physical controls — such as password requirements, encryption or locked office doors. Hack attacks such as phishing, injection of malware or keystroke loggers, denial-of-service attacks, and viruses would continue to be fully prosecutable under the strong CFAA provisions this bill does not modify.
  • Bringing balance back to the CFAA by eliminating a redundant provision that enables an individual to be punished multiple times through duplicate charges for the same violation. Eliminating the redundant provision streamlines the law, but would not create a gap in protection against hackers.
  • Bringing greater proportionality to CFAA penalties. Currently, the CFAA's penalties are tiered, and prosecutors have wide discretion to ratchet up the severity of the penalties in several circumstances, leaving little room for non-felony charges under CFAA (i.e., charges with penalties carrying less than a year in prison). The bill ensures prosecutors cannot seek to inflate sentences by stacking multiple charges under the CFAA, including state law equivalents or non-criminal violations of the law.
Frankly, I'd like to see CFAA reform go even further, but this is a good (and necessary) start. If you agree, you should let your own elected officials know that this is a bill worth supporting. Unfortunately, the White House is pushing a terribly bad update to the CFAA that won't actually fix the problems with it and could make the bill even worse. The DOJ, for example, remains a big fan of the CFAA and would like to see it expanded so it can be used more widely. At the same time, some large tech companies, like Oracle, have worked hard to prevent any significant CFAA reform, because they want to be able to use the law themselves. In other words, meaningful CFAA reform, no matter how strongly needed, is nowhere near a sure thing.
Hide this

Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.

Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.

While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.

–The Techdirt Team

Filed Under: aaron swartz, aaron's law, cfaa, cfaa reform, rand paul, ron wyden, zoe lofgren


Reader Comments

Subscribe: RSS

View by: Time | Thread


  1. icon
    That One Guy (profile), 22 Apr 2015 @ 7:26pm

    "If we can't threaten someone with decades in prison for breaking the TOS, then the terrorists win!"

    Elimination of redundant charge stacking and greatly reducing the number of felonies available for the prosecution to threaten the defense with? Oh yeah, the DOJ is going to flip over this bill.

    link to this | view in thread ]

  2. identicon
    Annonimus, 23 Apr 2015 @ 3:31am

    Send it to John Oliver

    This topic could use more wide spread coverage.

    link to this | view in thread ]

  3. icon
    Mason Wheeler (profile), 23 Apr 2015 @ 7:09am

    Haven't I read, more than once, Techdirt articles claiming that laws named after dead people are universally terrible?

    link to this | view in thread ]

  4. identicon
    Anonymous Coward, 23 Apr 2015 @ 12:57pm

    It doesn't look like this would have affected the case against its namesake though. Isn't that a bit weird?

    link to this | view in thread ]


Follow Techdirt
Essential Reading
Techdirt Deals
Report this ad  |  Hide Techdirt ads
Techdirt Insider Discord

The latest chatter on the Techdirt Insider Discord channel...

Loading...
Recent Stories

This site, like most other sites on the web, uses cookies. For more information, see our privacy policy. Got it
Close

Email This

This feature is only available to registered users. Register or sign in to use it.