You should know this > “What do connected cars and toilets have in common?”

What do connected cars and toilets have in common? That is the title to a recent Blog Post about an upcoming presentation at VMWorld 2013, Barcelona and, when I read it, I just had to quiz my readers to see who remembered … Come on now, you do know the answer to this question, right? I …

Combating Corporate Espionage Seminar – Prezi and a few thoughts

Today I had the honor of speaking at the Combating Corporate Espionage: Protecting Your Organization From “hackers, insiders & fraudster” seminar with Jarrett Kolthoff and David Major. Jarrett is the CEO of SpearTip Cyber Counterintelligence; he and I have worked together quite a bit so he first impressed me long ago with the depth of his …

Loss and Damage Are Not Interchangeable Under CFAA–District Court Blows Right Past CFAA’s “Loss” Requirement in Sysco Corp. v. Katz

In denying a motion to dismiss a civil Computer Fraud and Abuse Act claim, a district court found that a departing employee’s purported cover-up of nefarious activity by deleting e-mails from his “sent” and “deleted items” folders on Plaintiffs’ computer system was sufficient to allege damage pursuant to 18 U.S.C. § 1030(c)(4)(A)(i) which provision, however, does not address the issue …

District Court Finds Breach of Contractual Limits on Access Violates the CFAA

TAKEAWAY: Businesses (and anyone else) that allow others to access to their computers should have contractual agreements with those persons that clearly specify the restrictions on their authorization to access and use the computers and data.  This is the lesson of United States v. Cave, 2013 WL 3766550 (D. Neb. July 16, 2013), a case in which …

Yes, Case Law Says It Really Is A CFAA Violation To DDoS A Website

On October 3, 2013, a federal grand jury in Virginia indicted 13 members of Anonymous for conspiracy premised on underlying violations of the Computer Fraud and Abuse Act, 18 U.S.C. § 1030 (CFAA). Those indicted allegedly committed a DDoS attack (distributed denial of service) on certain websites. The indictment (download) has, yet again, stirred up …

3 Steps to Enable Companies to Use the CFAA’s Remedies for Misuse of Computers and Info – Even in the 9th Cir

Takeaway: Companies that follow these 3 steps can use the Computer Fraud and Abuse Act as a tool to combat the misuse of their computers (and information) by (1) actively monitoring for misuses, (2) taking reasonable steps to actively resist and prevent such misuses, and (3) clearly notifying the transgressor that his authorization has been …

Hackers continue to exploit vulnerabilities in car computer systems

A couple of years ago I blogged about (what was then) the hypothetical question of whether hacking a car would violate the Computer Fraud and Abuse Act. Since that time we have seen the idea of hacking a car become a reality.  I have written updated blog posts in shared a video showing how hackers …

Computer Fraud and Abuse Act Limitations Accrued With Awareness of Unauthorized Access–Not Identity of Perpetrator

SUMMARY: The two year statute of limitations for Computer Fraud and Abuse Act claim began to run when the plaintiff had an awareness of an unauthorized access into its computer system even if the plaintiff did not know the identity of the alleged perpetrator at that time. This is an update on a previous post: Two …

Presentation Slides: Overview and Update of the Computer Fraud and Abuse Act

Today I had the opportunity to present to the Privacy, Data Security, and eCommerce Committee of the State Bar of Texas on an overview and update of recent cases and issues for the Computer Fraud and Abuse Act. Here are the presentation slides and, of course, feel free to let me know if you have any …

Yes, you can even hack a toilet! #IoT

Ahhh yes, hacking toilet now seems to be possible … and you folks thought I was crazy a few years ago for blogging about hacking a car, a home, or even hacking a human … but as you know see, you can even hack a toilet. Can you just imagine the frustration caused by a …