Hacker Law for Hackers

Presented at ShmooCon 2023, Jan. 20, 2023, 6 p.m. (30 minutes)

Laws that restrict hacking have changed in the last 2 years. In several ways, the changes are beneficial to security research. However, other laws have not evolved and continue to equate good faith security research with malicious hacking, and some laws create new liability for security research and vulnerability disclosure.

This presentation will provide an overview of the current legal landscape for security research–what has improved, what needs to change, and the areas of greatest legal risk for both hackers and the hacked. This will include an explanation of changes to US major anti-hacking laws–CFAA, DMCA Sec. 1201, and state laws. The presentation will also summarize developments on international laws such as China’s vulnerability disclosure law and the UK’s Computer Misuse Act. Finally, the presentation will provide suggestions on where the community should focus next to advocate for better legal protections for security research, vulnerability disclosure, and security tools.

Key takeaways include a basic understanding of major US hacking laws, recent changes to legal restrictions on security research and vulnerability disclosure, and opportunities for engagement on policy to protect good faith security research.


Presenters:

  • Harley Geiger
    Harley Geiger (@harleygeiger) is an attorney with Venable LLP, serving as Counsel in the Privacy and Data Security group. Harley has worked on hacking law and policy for a decade, in addition to counseling on laws related to personal information security, IoT security, regulatory compliance, and cyber incident management. Prior to joining Venable, Harley led the public policy and government affairs program at Rapid7, advising executives on global security regulatory and public policy issues affecting the company and its client base. Harley also served as Senior Legislative Counsel at the US House of Representatives and is CIPP/US certified.

Similar Presentations: