Car Hacking Is Very Real and Can Be Very Deadly — Watch This Video Of How To Do It

It is really quite simple: Modern cars are controlled by computers — everything, from the accelerator to the brakes to the steering to the windows to the locks — take over the computer, you take complete control over the car. The idea of hacking a car is no longer fantasy. It is real. It can …

Presentation: Helping Businesses Prepare for Computer Fraud and Data Breaches

Last night I had the wonderful opportunity to present to IMA – The Association of Accountants and Financial Professionals in Business on the topic of Helping Businesses Prepare for Computer Fraud and Data Breaches. Here are the presentation slides. I was really impressed with the quality of this event on many levels — these folks …

Computer Fraud and Abuse Act Cases Update (March 6, 2013)

Here are some recent Computer Fraud and Abuse Act (“CFAA”) cases that have been decided (or published) over the last couple of weeks: Tracfone Wireless, Inc. v. Cabrera, 883 F. Supp.2d 1220 (S.D. Fla. July 11, 2012). Defendant and former employee who engaged in selling stolen TracFone Prepaid Phones violated the unauthorized access with intent …

Court Finds Computer Fraud and Abuse Act Claim is Subject to Arbitration Agreement

TAKEAWAY: A Computer Fraud and Abuse Act claim that touches matters covered by an arbitration agreement is arbitrable. In Torbit, Inc. v. Datanyze, Inc., 2013 WL 572613 (N.D. Cal. Feb. 13, 2013), the defendant moved to compel arbitration of a Computer Fraud and Abuse Act claim under an arbitration agreement that provided that “all claims …

Plaintiff’s CFAA Claim Dismissed Because of Simple Pleading Error

This blog is full of posts about the Computer Fraud and Abuse Act’s requirement that, for a civil claim, the claimant must plead a $5,000 loss. Click here to see. One of the operative words in that sentence is plead — not argue — but plead! This means it must be in your pleading which is …

Computer Fraud and Abuse Act Incorporates Traditional Principles of Tort Causation

TAKEAWAY: The Computer Fraud and Abuse Act incorporates traditional principles of tort causation, therefore, intervening or superseding cause can be an affirmative defenses to a CFAA claim. In Denarii Systems, LLC v. Arab, 2013 WL 500826 (S.D. Fla. Feb. 11, 2013), the plaintiff brought a Computer Fraud and Abuse Act claim against the Defendants. One of the …

US Preparing to Do Digital Battle With Hackers – Will This Violate the Computer Fraud and Abuse Act?

The US could launch pre-emptive cyber strikes against countries it suspects of threatening its interests with a digital attack, under a new set of secret guidelines to safeguard the nation’s computer systems. The rules – the country’s first on how it defends or retaliates against digital attacks – are expected to be approved in coming weeks, …

The Law and the Hacker – Podcast on the Computer Fraud and Abuse Act

Not too long ago I had a nice visit with Rafal Los (@Wh1t3Rabbit) who is otherwise known as the Chief Security Evangelist for HP and blogs at Following the Wh1t3Rabbit – Practical Enterprise Security. Raf is one dude you really need to follow if you’re interested in #infosec.  Anyway, our discussion was centered around the Computer Fraud and Abuse …

Another CFAA Case Dismissed Because Plaintiff Only Recited Elements in Complaint

In North American Ins. Agency, Inc. v. Bates, the United States District Court for the Western District of Oklahoma dismissed the plaintiff’s Computer Fraud and Abuse Act claim because, rather than alleging facts to support the claim, the plaintiff merely recited the elements in the Complaint: “A pleading that offers labels and conclusions or a …

Employment Agreement Restrictions Determined Whether Employees Exceeded Authorized Access Under Computer Fraud and Abuse Act

TAKEAWAYS: The important takeaways from the Custom Hardware Engineering & Consulting, Inc. v. Dowell case are that your business really needs to have solid employment agreements or acceptable use policies that restrict (1) the duration for which access is authorized, (2) the intended-use for which access is authorized, and (3) that these restrictions apply to not only the …