Employment Agreement Restrictions Determined Whether Employees Exceeded Authorized Access Under Computer Fraud and Abuse Act

TAKEAWAYS: The important takeaways from the Custom Hardware Engineering & Consulting, Inc. v. Dowell case are that your business really needs to have solid employment agreements or acceptable use policies that restrict (1) the duration for which access is authorized, (2) the intended-use for which access is authorized, and (3) that these restrictions apply to not only the …

Court Implies Unknown “Backdoor Node” On Software Licensee’s Server To Monitor Infringement May Violate CFAA

This is a case where I really wish there had been a Computer Fraud and Abuse Act claim but there wasn’t, though the court mentioned it anyway as if to goad the attorneys by saying “hey, you missed this one!” Nonetheless, the court’s passing comment sheds some light on the recent debate over using offensive …

Can You Be Outraged By The Prosecution of Aaron Swartz Under CFAA But Not Sandra Teague?

With Aaron Swartz’s suicide came the lifting of the floodgates for public criticism of the Computer Fraud and Abuse Act. The amount of venom directed at the law is second only to that directed at the federal prosecutors who were prosecuting Swartz. While I understand the emotional issues that are driving much of the criticism, as I …

What is the Proper Jurisdiction for an International Computer Fraud Lawsuit?

The proper jurisdiction for suing someone for engaging in computer fraud from a foreign country, directed at a company in the United States, is the place where the wrongfully accessed computer server is located if the defendant knew the location of the computer server. This issue was analyzed by the United States Court of Appeals …

4 Takeaways From A Really Easy Computer Fraud And Abuse Act Case

4 Practical Takeaways: A “protected computer” is any computer connected to the Internet. The $5,000 loss requirement can be aggregated and need not be met by only one single act. Lost revenue is a “loss” if it was caused by an interruption of service because the computers failed. Observation of data alone constitutes “obtaining information”. …

Break Into A Home, Violate the Computer Fraud and Abuse Act?

How’s that for a crazy sounding question? Could breaking into a home violate the Computer Fraud and Abuse Act? I know you’re wondering just how I come up with these crazy things, right? From the news, of course! I read a really interesting article by David Goldman on CNNMoney entitled Your Jetsons Home is Almost …

Share your password, do the time – lessons under the Computer Fraud and Abuse Act

The Lesson: DO NOT SHARE YOUR COMPUTER PASSWORDS! The Student: Jane Smith, a County Clerk of Court with a distinguished career of service for 39 years. The Mistake: Sharing her computer password with an IT contractor who was working on the Clerk’s office computers with the Sheriff’s Department, District Attorney’s Office, and Madison County Jail to …

Guarding Against the Inside Job (Part 1 of 2)

“You are only as strong as your weakest link” It is becoming clear that the weakest link in most companies’ information security defenses is the people who work inside the company. The company must identify the most likely risks those people face, train them to minimize those risks, develop policies to protect against those risks, …

Hacking a car? Yes, really…and you thought I was kidding!

A few weeks ago I blogged about whether an unauthorized access of a car that has a computer and is connected to the Internet would violate the Computer Fraud and Abuse Act. Did you read it? Or, did you think it sounded too ridiculous? Here it is if you want to take a look: Can …

Can hacking and stealing a CAR violate the Computer Fraud and Abuse Act?

Ford wants its cars connected to the Internet. By now we all know from my previous post on United States v. Kramer that the Computer Fraud and Abuse Act applies to anything with a microchip or data processor that is connected to the Internet. So, the question I have is, if someone steals one of these …