The Supreme Court’s recent decision in Van Buren v United States is good news for security researchers, overturning a dangerous precedent on criminalizing access in violation of terms of service and EULAs, clarifying the notoriously ambiguous meaning of “exceeding authorized access” in the Computer Fraud and Abuse Act, as well as endorsing the interpretation of the statute’s terms using their technical meaning.
The CFAA is the federal computer crime law that’s been misused to prosecute beneficial and important online activity, and one of the primary legal risks faced by security researched, for both criminal and civil liability. The presentation will explain the Van Buren decision in the context of the evolving CFAA law, what the new “gates up or down” approach to unauthorized access means for security researchers, how the Supreme Court’s opinion will guide future courts, and what the decision left unresolved in its mysterious Footnote 8.