#cfaa — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cfaa, aggregated by home.social.
-
Ninth Circuit: Your AI Agent Can’t Violate Hacking Law. But You Might.
-
Ninth Circuit: Your AI Agent Can’t Violate Hacking Law. But You Might.
-
Ninth Circuit: Your AI Agent Can’t Violate Hacking Law. But You Might.
-
Ninth Circuit: Your AI Agent Can’t Violate Hacking Law. But You Might.
-
Ninth Circuit: Your AI Agent Can’t Violate Hacking Law. But You Might.
-
#AppealsCourt Agrees with @eff that Building a #WebBrowser Doesn’t Violate the #CFAA
#browser -
#AppealsCourt Agrees with @eff that Building a #WebBrowser Doesn’t Violate the #CFAA
#browser -
#AppealsCourt Agrees with @eff that Building a #WebBrowser Doesn’t Violate the #CFAA
#browser -
#AppealsCourt Agrees with @eff that Building a #WebBrowser Doesn’t Violate the #CFAA
#browser -
#AppealsCourt Agrees with @eff that Building a #WebBrowser Doesn’t Violate the #CFAA
#browser -
Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated
Can autonomous AI agents be sued or prosecuted for hacking? It’s no longer a question for sci-fi movies.…
#NewsBeep #News #US #USA #UnitedStates #UnitedStatesOfAmerica #Business #Anthropic #CFAA #Cybersecurity #databreach #hackers #HuggingFace #Law #OpenAI
https://www.newsbeep.com/us/801906/ -
Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated
Can autonomous AI agents be sued or prosecuted for hacking? It’s no longer a question for sci-fi movies.…
#NewsBeep #News #US #USA #UnitedStates #UnitedStatesOfAmerica #Business #Anthropic #CFAA #Cybersecurity #databreach #hackers #HuggingFace #Law #OpenAI
https://www.newsbeep.com/us/801906/ -
https://www.europesays.com/people/176790/ Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated #Anthropic #CFAA #Cybersecurity #DataBreach #Hackers #HuggingFace #law #OpenAI #SamAltman
-
⚠️ The Password Bypass Illusion: How SMS 2FA Destroys Authentication Logic
A recent experience while changing my account info reminded me why relying on telecom routing for security is an absolute nightmare, and why the infosec community needs to kill off SMS authentication for good.
🚩 Battle.net SMS 2FA Failure and Security Theater:
I attempted to log into Battle.net using a phone number I had legitimately owned for months, assuming I had added to my alt profile when I switched to that number. Instead of asking for a password or throwing an error, the platform sent an SMS code, accepted it, and instantly logged me into a complete stranger's legacy account.
🚩 The Architectural Flaw:
The platform's backend treated a single SMS verification token not as a supplementary second factor, but as a primary identity credential that bypassed traditional password authentication entirely. Because a stranger had left my number on their account months prior, the system assumed current possession of the SIM trumped all other security metrics.
🏳 The Legal Reality of Intent:
From a legal standpoint (like the CFAA), navigating into an account this way lacks the malicious intent required for criminal unauthorized access (Mens Rea); it's an accidental entry caused entirely by broken corporate infrastructure. But the fact that a user can simply input their own phone number and inadvertently hijack a stranger's digital life without a single exploit is a staggering failure of AppSec logic.
✅ The Solution:
SMS is not identity proof. It is a highly volatile, easily routed carrier token. If a platform allows SMS to override or bypass a standard password barrier without out-of-band verification (like a mandatory email confirmation), it isn't secure.
Stop letting telcos act as your root of trust. Switch to cryptographic hardware standards like NFC Yubikeys or standard TOTP apps.
#CyberSecurity #Infosec #MFA #SecurityTheater #AppSec #Yubikey #CFAA #Hacking
-
⚠️ How SMS 2FA Destroys Authentication Logic
A recent experience while changing my account info reminded me why relying on telecom routing for security is an absolute nightmare, and why the infosec community needs to kill off SMS authentication for good.
🚩 Battle.net SMS 2FA Failure and Security Theater:
I attempted to log into Battle.net using a phone number I had legitimately owned for months, assuming I had added to my alt profile when I switched to that number. Instead of asking for a secondary 2FA, the platform sent an SMS code, accepted it, and provided me access to a complete stranger's account.
🚩 The Architectural Flaw:
The platform's backend treated a single SMS verification token not as a supplementary second factor, but as a primary identity credential. Because a stranger had left my number on their account months prior, the system assumed current possession of the SIM trumped all other security metrics.
🏳 The Legal Reality of Intent:
From a legal standpoint (like the CFAA), navigating into an account this way lacks the malicious intent required for criminal unauthorized access (Mens Rea); it's an accidental entry caused entirely by broken corporate infrastructure. But the fact that a user can simply input their own phone number and inadvertently hijack a stranger's digital life without a single exploit is a staggering failure of AppSec logic.
✅ The Solution:
SMS is not identity proof. It is a highly volatile, easily routed carrier token. If a platform allows SMS to override or bypass a standard password barrier without out-of-band verification (like a mandatory email confirmation), it isn't secure.
Stop letting telcos act as your root of trust. Switch to cryptographic hardware standards like NFC Yubikeys or standard TOTP apps.
#CyberSecurity #Infosec #MFA #SecurityTheater #AppSec #Yubikey #CFAA #Hacking
-
⚠️ The Password Bypass Illusion: How SMS 2FA Destroys Authentication Logic
A recent experience while changing my account info reminded me why relying on telecom routing for security is an absolute nightmare, and why the infosec community needs to kill off SMS authentication for good.
🚩 Battle.net SMS 2FA Failure and Security Theater:
I attempted to log into Battle.net using a phone number I had legitimately owned for months, assuming I had added to my alt profile when I switched to that number. Instead of asking for a password or throwing an error, the platform sent an SMS code, accepted it, and instantly logged me into a complete stranger's legacy account.
🚩 The Architectural Flaw:
The platform's backend treated a single SMS verification token not as a supplementary second factor, but as a primary identity credential that bypassed traditional password authentication entirely. Because a stranger had left my number on their account months prior, the system assumed current possession of the SIM trumped all other security metrics.
🏳 The Legal Reality of Intent:
From a legal standpoint (like the CFAA), navigating into an account this way lacks the malicious intent required for criminal unauthorized access (Mens Rea); it's an accidental entry caused entirely by broken corporate infrastructure. But the fact that a user can simply input their own phone number and inadvertently hijack a stranger's digital life without a single exploit is a staggering failure of AppSec logic.
✅ The Solution:
SMS is not identity proof. It is a highly volatile, easily routed carrier token. If a platform allows SMS to override or bypass a standard password barrier without out-of-band verification (like a mandatory email confirmation), it isn't secure.
Stop letting telcos act as your root of trust. Switch to cryptographic hardware standards like NFC Yubikeys or standard TOTP apps.
#CyberSecurity #Infosec #MFA #SecurityTheater #AppSec #Yubikey #CFAA #Hacking
-
⚠️ The Password Bypass Illusion: How SMS 2FA Destroys Authentication Logic
A recent experience setting up an account reminded me why relying on telecom routing for security is an absolute nightmare, and why the infosec community needs to kill off SMS authentication for good.
🚩 Battle.net SMS 2FA Failure and Security Theater:
I attempted to log into Battle.net using a phone number I had legitimately owned for months, assuming I had added to my alt profile when I switched to that number. Instead of asking for a password or throwing an error, the platform sent an SMS code, accepted it, and instantly logged me into a complete stranger's legacy account.
🚩 The Architectural Flaw:
The platform's backend treated a single SMS verification token not as a supplementary second factor, but as a primary identity credential that bypassed traditional password authentication entirely. Because a stranger had left my number on their account months prior, the system assumed current possession of the SIM trumped all other security metrics.
🏳 The Legal Reality of Intent:
From a legal standpoint (like the CFAA), navigating into an account this way lacks the malicious intent required for criminal unauthorized access (Mens Rea); it's an accidental entry caused entirely by broken corporate infrastructure. But the fact that a user can simply input their own phone number and inadvertently hijack a stranger's digital life without a single exploit is a staggering failure of AppSec logic.
✅ The Solution:
SMS is not identity proof. It is a highly volatile, easily routed carrier token. If a platform allows SMS to override or bypass a standard password barrier without out-of-band verification (like a mandatory email confirmation), it isn't secure.
Stop letting telcos act as your root of trust. Switch to cryptographic hardware standards like NFC Yubikeys or standard TOTP apps.
#CyberSecurity #Infosec #MFA #SecurityTheater #AppSec #Yubikey #CFAA #Hacking
-
New: "Sticking their heads out above the parapets" — the first qualitative study of researchers' lived experiences of legal risk, by Sunoo Park & Daniel R. Thomas (USENIX Security 2026). 36 researchers, 130 incidents, three decades. The CFAA and UK Computer Misuse Act chill good-faith research; it names disclose.io as part of the fix. Read it + catch the talk:
https://blog.disclose.io/above-the-parapets-the-chilling-effect-finally-has-receipts/
#infosec #CFAA #vulndisclosure -
New: "Sticking their heads out above the parapets" — the first qualitative study of researchers' lived experiences of legal risk, by Sunoo Park & Daniel R. Thomas (USENIX Security 2026). 36 researchers, 130 incidents, three decades. The CFAA and UK Computer Misuse Act chill good-faith research; it names disclose.io as part of the fix. Read it + catch the talk:
https://blog.disclose.io/above-the-parapets-the-chilling-effect-finally-has-receipts/
#infosec #CFAA #vulndisclosure -
New: "Sticking their heads out above the parapets" — the first qualitative study of researchers' lived experiences of legal risk, by Sunoo Park & Daniel R. Thomas (USENIX Security 2026). 36 researchers, 130 incidents, three decades. The CFAA and UK Computer Misuse Act chill good-faith research; it names disclose.io as part of the fix. Read it + catch the talk:
https://blog.disclose.io/above-the-parapets-the-chilling-effect-finally-has-receipts/
#infosec #CFAA #vulndisclosure -
New: "Sticking their heads out above the parapets" — the first qualitative study of researchers' lived experiences of legal risk, by Sunoo Park & Daniel R. Thomas (USENIX Security 2026). 36 researchers, 130 incidents, three decades. The CFAA and UK Computer Misuse Act chill good-faith research; it names disclose.io as part of the fix. Read it + catch the talk:
https://blog.disclose.io/above-the-parapets-the-chilling-effect-finally-has-receipts/
#infosec #CFAA #vulndisclosure -
New: "Sticking their heads out above the parapets" — the first qualitative study of researchers' lived experiences of legal risk, by Sunoo Park & Daniel R. Thomas (USENIX Security 2026). 36 researchers, 130 incidents, three decades. The CFAA and UK Computer Misuse Act chill good-faith research; it names disclose.io as part of the fix. Read it + catch the talk:
https://blog.disclose.io/above-the-parapets-the-chilling-effect-finally-has-receipts/
#infosec #CFAA #vulndisclosure -
Hey #lawFedi:
How many ways besides libel can a false statement, whether on its own, or in combination with something else, be made to constitute civil or criminal offence? (What suffices to constitute fraud? negligent misrepresentation? breach of contract or warranty? tortuous interference? perjury? etc.…?)
Suppose a rudimentary open-source #DRM were to be implemented in web servers and web browsers (or a web-browser add-on), such that the key to the TPM comprises proof of the user's agreement to and utterance of legal statements to the effect that they're not using "generative AI" (plagiarism synthesis) to interact with the site, will not use it during that interaction, and will not allow any #genAI software to access information from it or disclose that information to any entity that would? Suppose the ToS for the site were to require that perfunctory DRM.
Would there be a way to exploit #DMCA1201 and/or the #CFAA to make it an offence (whether a crime, or a viable cause to sue) to bypass that DRM in order to interact with the website?
Maybe @lessig or #EbenMoglen (anyone know him?) could draft something, to do to AI, through inversion of intent of those laws, as #copyleft to #copyright?
@mgeist Would those laws correspond approximately to CMA §41 and to §342 of the Criminal Code?
-
Hey #lawFedi:
How many ways besides libel can a false statement, whether on its own, or in combination with something else, be made to constitute civil or criminal offence? (What suffices to constitute fraud? negligent misrepresentation? breach of contract or warranty? tortuous interference? perjury? etc.…?)
Suppose a rudimentary open-source #DRM were to be implemented in web servers and web browsers (or a web-browser add-on), such that the key to the TPM comprises proof of the user's agreement to and utterance of legal statements to the effect that they're not using "generative AI" (plagiarism synthesis) to interact with the site, will not use it during that interaction, and will not allow any #genAI software to access information from it or disclose that information to any entity that would? Suppose the ToS for the site were to require that perfunctory DRM.
Would there be a way to exploit #DMCA1201 and/or the #CFAA to make it an offence (whether a crime, or a viable cause to sue) to bypass that DRM in order to interact with the website?
Maybe @lessig or #EbenMoglen (anyone know him?) could draft something, to do to AI, through inversion of intent of those laws, as #copyleft to #copyright?
@mgeist Would those laws correspond approximately to CMA §41 and to §342 of the Criminal Code?
-
Hey #lawFedi:
How many ways besides libel can a false statement, whether on its own, or in combination with something else, be made to constitute civil or criminal offence? (What suffices to constitute fraud? negligent misrepresentation? breach of contract or warranty? tortuous interference? perjury? etc.…?)
Suppose a rudimentary open-source #DRM were to be implemented in web servers and web browsers (or a web-browser add-on), such that the key to the TPM comprises proof of the user's agreement to and utterance of legal statements to the effect that they're not using "generative AI" (plagiarism synthesis) to interact with the site, will not use it during that interaction, and will not allow any #genAI software to access information from it or disclose that information to any entity that would? Suppose the ToS for the site were to require that perfunctory DRM.
Would there be a way to exploit #DMCA1201 and/or the #CFAA to make it an offence (whether a crime, or a viable cause to sue) to bypass that DRM in order to interact with the website?
Maybe @lessig or #EbenMoglen (anyone know him?) could draft something, to do to AI, through inversion of intent of those laws, as #copyleft to #copyright?
@mgeist Would those laws correspond approximately to CMA §41 and to §342 of the Criminal Code?
-
Hey #lawFedi:
How many ways besides libel can a false statement, whether on its own, or in combination with something else, be made to constitute civil or criminal offence? (What suffices to constitute fraud? negligent misrepresentation? breach of contract or warranty? tortuous interference? perjury? etc.…?)
Suppose a rudimentary open-source #DRM were to be implemented in web servers and web browsers (or a web-browser add-on), such that the key to the TPM comprises proof of the user's agreement to and utterance of legal statements to the effect that they're not using "generative AI" (plagiarism synthesis) to interact with the site, will not use it during that interaction, and will not allow any #genAI software to access information from it or disclose that information to any entity that would? Suppose the ToS for the site were to require that perfunctory DRM.
Would there be a way to exploit #DMCA1201 and/or the #CFAA to make it an offence (whether a crime, or a viable cause to sue) to bypass that DRM in order to interact with the website?
Maybe @lessig or #EbenMoglen (anyone know him?) could draft something, to do to AI, through inversion of intent of those laws, as #copyleft to #copyright?
@mgeist Would those laws correspond approximately to CMA §41 and to §342 of the Criminal Code?
-
Hey #lawFedi:
How many ways besides libel can a false statement, whether on its own, or in combination with something else, be made to constitute civil or criminal offence? (What suffices to constitute fraud? negligent misrepresentation? breach of contract or warranty? tortuous interference? perjury? etc.…?)
Suppose a rudimentary open-source #DRM were to be implemented in web servers and web browsers (or a web-browser add-on), such that the key to the TPM comprises proof of the user's agreement to and utterance of legal statements to the effect that they're not using "generative AI" (plagiarism synthesis) to interact with the site, will not use it during that interaction, and will not allow any #genAI software to access information from it or disclose that information to any entity that would? Suppose the ToS for the site were to require that perfunctory DRM.
Would there be a way to exploit #DMCA1201 and/or the #CFAA to make it an offence (whether a crime, or a viable cause to sue) to bypass that DRM in order to interact with the website?
Maybe @lessig or #EbenMoglen (anyone know him?) could draft something, to do to AI, through inversion of intent of those laws, as #copyleft to #copyright?
@mgeist Would those laws correspond approximately to CMA §41 and to §342 of the Criminal Code?
-
I would like to believe that if the US federal government weren't completely fucked up right now then OpenAI and the other AI parasites with a nexus in the US would have been criminally charged by now with violating the #CFAA by actively circumventing the crawling protections added recently to websites specifically to block them.
Alas, the government is too busy engaging in vindictive prosecution of #Trump's enemies who aren't actively bribing him.
#infosec #AI
Ref: https://darmstadt.social/@claudius/115436859378534835 -
I would like to believe that if the US federal government weren't completely fucked up right now then OpenAI and the other AI parasites with a nexus in the US would have been criminally charged by now with violating the #CFAA by actively circumventing the crawling protections added recently to websites specifically to block them.
Alas, the government is too busy engaging in vindictive prosecution of #Trump's enemies who aren't actively bribing him.
#infosec #AI
Ref: https://darmstadt.social/@claudius/115436859378534835 -
I would like to believe that if the US federal government weren't completely fucked up right now then OpenAI and the other AI parasites with a nexus in the US would have been criminally charged by now with violating the #CFAA by actively circumventing the crawling protections added recently to websites specifically to block them.
Alas, the government is too busy engaging in vindictive prosecution of #Trump's enemies who aren't actively bribing him.
#infosec #AI
Ref: https://darmstadt.social/@claudius/115436859378534835 -
I would like to believe that if the US federal government weren't completely fucked up right now then OpenAI and the other AI parasites with a nexus in the US would have been criminally charged by now with violating the #CFAA by actively circumventing the crawling protections added recently to websites specifically to block them.
Alas, the government is too busy engaging in vindictive prosecution of #Trump's enemies who aren't actively bribing him.
#infosec #AI
Ref: https://darmstadt.social/@claudius/115436859378534835 -
I would like to believe that if the US federal government weren't completely fucked up right now then OpenAI and the other AI parasites with a nexus in the US would have been criminally charged by now with violating the #CFAA by actively circumventing the crawling protections added recently to websites specifically to block them.
Alas, the government is too busy engaging in vindictive prosecution of #Trump's enemies who aren't actively bribing him.
#infosec #AI
Ref: https://darmstadt.social/@claudius/115436859378534835 -
Jon Prosser przegapia termin – Apple kontynuuje proces bez jego udziału
Sąd Okręgowy Północnej Kalifornii przyjął wniosek Apple o rozpoczęcie postępowania przeciwko Jonowi Prosserowi bez jego reprezentacji.
YouTuber, znany z przecieków o produktach Apple, nie złożył w terminie odpowiedzi na pozew dotyczący wycieku danych z wewnętrznych narzędzi firmy.
Apple pozwało Prosssera i Michaela Ramacciottiego w lipcu, zarzucając im ujawnienie tajemnic handlowych oraz złamanie ustawy o oszustwach komputerowych (CFAA). Według pozwu, Ramacciotti miał włamać się na tzw. Development iPhone należący do byłego pracownika Apple, Ethana Lipnika, a następnie przekazać dane Prosserowi.
Prosser miał wykorzystać te materiały do stworzenia filmów na YouTube, w których ujawnił elementy nowego projektu interfejsu – Liquid Design, wprowadzonego później w iOS 26. Apple twierdzi, że Prosser zarobił na publikacji poufnych informacji dzięki przychodom z reklam.
Co dalej?
Prosser nie zareagował na pozew w wyznaczonym terminie, dlatego sąd uznał tzw. default, co pozwala Apple kontynuować sprawę bez jego udziału. Ramacciotti uzyskał natomiast przedłużenie terminu do 17 października.
Prosser może jeszcze wnioskować o uchylenie decyzji, jeśli udowodni tzw. „usprawiedliwione zaniedbanie”, jednak brak reakcji jego prawników budzi wątpliwości co do dalszej obrony.
Jeśli sytuacja się nie zmieni, sąd może wydać wyrok zaoczny na korzyść Apple.
Jon Prosser nie pęka. Pozwany przez Apple, odpowiada przeciekiem na temat iPhone’a 17 Pro
#Apple #CFAA #ios26 #JonProsser #LiquidDesign #procesApple #przeciekiApple #tajemnicehandlowe #technologia #wyciekiApple #YouTubeLeaks
-
Jon Prosser przegapia termin – Apple kontynuuje proces bez jego udziału
Sąd Okręgowy Północnej Kalifornii przyjął wniosek Apple o rozpoczęcie postępowania przeciwko Jonowi Prosserowi bez jego reprezentacji.
YouTuber, znany z przecieków o produktach Apple, nie złożył w terminie odpowiedzi na pozew dotyczący wycieku danych z wewnętrznych narzędzi firmy.
Apple pozwało Prosssera i Michaela Ramacciottiego w lipcu, zarzucając im ujawnienie tajemnic handlowych oraz złamanie ustawy o oszustwach komputerowych (CFAA). Według pozwu, Ramacciotti miał włamać się na tzw. Development iPhone należący do byłego pracownika Apple, Ethana Lipnika, a następnie przekazać dane Prosserowi.
Prosser miał wykorzystać te materiały do stworzenia filmów na YouTube, w których ujawnił elementy nowego projektu interfejsu – Liquid Design, wprowadzonego później w iOS 26. Apple twierdzi, że Prosser zarobił na publikacji poufnych informacji dzięki przychodom z reklam.
Co dalej?
Prosser nie zareagował na pozew w wyznaczonym terminie, dlatego sąd uznał tzw. default, co pozwala Apple kontynuować sprawę bez jego udziału. Ramacciotti uzyskał natomiast przedłużenie terminu do 17 października.
Prosser może jeszcze wnioskować o uchylenie decyzji, jeśli udowodni tzw. „usprawiedliwione zaniedbanie”, jednak brak reakcji jego prawników budzi wątpliwości co do dalszej obrony.
Jeśli sytuacja się nie zmieni, sąd może wydać wyrok zaoczny na korzyść Apple.
Jon Prosser nie pęka. Pozwany przez Apple, odpowiada przeciekiem na temat iPhone’a 17 Pro
#Apple #CFAA #ios26 #JonProsser #LiquidDesign #procesApple #przeciekiApple #tajemnicehandlowe #technologia #wyciekiApple #YouTubeLeaks
-
Jon Prosser przegapia termin – Apple kontynuuje proces bez jego udziału
Sąd Okręgowy Północnej Kalifornii przyjął wniosek Apple o rozpoczęcie postępowania przeciwko Jonowi Prosserowi bez jego reprezentacji.
YouTuber, znany z przecieków o produktach Apple, nie złożył w terminie odpowiedzi na pozew dotyczący wycieku danych z wewnętrznych narzędzi firmy.
Apple pozwało Prosssera i Michaela Ramacciottiego w lipcu, zarzucając im ujawnienie tajemnic handlowych oraz złamanie ustawy o oszustwach komputerowych (CFAA). Według pozwu, Ramacciotti miał włamać się na tzw. Development iPhone należący do byłego pracownika Apple, Ethana Lipnika, a następnie przekazać dane Prosserowi.
Prosser miał wykorzystać te materiały do stworzenia filmów na YouTube, w których ujawnił elementy nowego projektu interfejsu – Liquid Design, wprowadzonego później w iOS 26. Apple twierdzi, że Prosser zarobił na publikacji poufnych informacji dzięki przychodom z reklam.
Co dalej?
Prosser nie zareagował na pozew w wyznaczonym terminie, dlatego sąd uznał tzw. default, co pozwala Apple kontynuować sprawę bez jego udziału. Ramacciotti uzyskał natomiast przedłużenie terminu do 17 października.
Prosser może jeszcze wnioskować o uchylenie decyzji, jeśli udowodni tzw. „usprawiedliwione zaniedbanie”, jednak brak reakcji jego prawników budzi wątpliwości co do dalszej obrony.
Jeśli sytuacja się nie zmieni, sąd może wydać wyrok zaoczny na korzyść Apple.
Jon Prosser nie pęka. Pozwany przez Apple, odpowiada przeciekiem na temat iPhone’a 17 Pro
#Apple #CFAA #ios26 #JonProsser #LiquidDesign #procesApple #przeciekiApple #tajemnicehandlowe #technologia #wyciekiApple #YouTubeLeaks
-
Correct me if I'm wrong, US #lawfedi, but I'm pretty sure @404mediaco is right that every case of of the landlords accessing the (prospective) tenants' workplace logins is a #CFAA violation, because employees are not legally entitled to authorize the landlord to log into the employers' systems, so the landlords are exceeding their authorized access.
-
Correct me if I'm wrong, US #lawfedi, but I'm pretty sure @404mediaco is right that every case of of the landlords accessing the (prospective) tenants' workplace logins is a #CFAA violation, because employees are not legally entitled to authorize the landlord to log into the employers' systems, so the landlords are exceeding their authorized access.
-
Correct me if I'm wrong, US #lawfedi, but I'm pretty sure @404mediaco is right that every case of of the landlords accessing the (prospective) tenants' workplace logins is a #CFAA violation, because employees are not legally entitled to authorize the landlord to log into the employers' systems, so the landlords are exceeding their authorized access.
-
Correct me if I'm wrong, US #lawfedi, but I'm pretty sure @404mediaco is right that every case of of the landlords accessing the (prospective) tenants' workplace logins is a #CFAA violation, because employees are not legally entitled to authorize the landlord to log into the employers' systems, so the landlords are exceeding their authorized access.
-
Correct me if I'm wrong, US #lawfedi, but I'm pretty sure @404mediaco is right that every case of of the landlords accessing the (prospective) tenants' workplace logins is a #CFAA violation, because employees are not legally entitled to authorize the landlord to log into the employers' systems, so the landlords are exceeding their authorized access.
-
🚑 Incident Response
====================🚨 Legal & Civil Rights
Executive summary: Reported case involves a former Tor relay/exit node operator detained after refusing to assist law enforcement decrypt exit traffic. Authorities allegedly mischaracterized a SPICE graphics driver as a "Linux OS" used to evade monitoring, and used an unrelated CFAA charge as a pretext for arrest and prolonged pre-trial detention.
Technical details: The component described in court is a SPICE graphics driver — a display protocol/driver used to present virtual machine graphics to a host or client. It is neither a full operating system nor capable, by design, of "knocking out monitoring software."
Relevant artifacts for technical review include VM configuration files, installed packages lists, driver versions, Tor relay configurations, and system logs showing network activity from exit nodes.Analysis: Misinterpretation of a driver as an OS indicates a gap between technical reality and legal presentation. Such mischaracterizations can produce disproportionate legal consequences, especially when used to justify detention or deny counsel. The case raises questions about expert technical testimony standards, evidentiary validation, and proper forensic review before judicial decisions affecting liberty.
Detection (for technical reviewers): Review VM manifests, package management logs, dmesg/kernel logs for SPICE driver entries, Tor logs for relay/exit activity, and timestamps that align system events with alleged incidents. Document discrepancies between vendor/technical documentation for SPICE and claims made in legal filings.
Mitigation / Recommendations: Ensure independent technical experts are engaged early in cases with technical claims. Courts should require demonstrable linkage between specific software capabilities and alleged interference. Preservation of system images, driver metadata, and Tor relay logs is critical for defense and independent review.
Consider policy measures to mandate technical expert consultation in cyber-related prosecutions.🔹 Tor #SPICE #CFAA #forensics #legaltech
-
Ryanair’s #CFAA Claim Against Booking.com Has Nothing To Do with Actual #Hacking
#ryanair #Bookingcom #security -
Ryanair’s #CFAA Claim Against Booking.com Has Nothing To Do with Actual #Hacking
#ryanair #Bookingcom #security -
Ryanair’s #CFAA Claim Against Booking.com Has Nothing To Do with Actual #Hacking
#ryanair #Bookingcom #security -
Ryanair’s #CFAA Claim Against Booking.com Has Nothing To Do with Actual #Hacking
#ryanair #Bookingcom #security -
Ryanair’s #CFAA Claim Against Booking.com Has Nothing To Do with Actual #Hacking
#ryanair #Bookingcom #security -
"Musk’s #DOGE Goons Surreptitiously Transmitted Reams of White House Data. Musk’s team installed a Starlink Wi-Fi terminal on top of the White House, allowing them to bypass data-tracking security measures."
https://www.thedailybeast.com/elon-musks-doge-goons-surreptitiously-transmitted-reams-of-white-house-data/PS: This looks like it violates a handful of serious federal laws. But will the Trump #DOJ prosecute? Even investigate? Trump could pardon all the DOGE players or simply direct their nonprosecution. Or if the Trump-Musk spat continues, he could press for max penalties under law. If he doesn't, could it be that there's evidence of his own approval or involvement? What data was transmitted and who has copies now?
#Espionage #CFAA #Musk #Trump #Theft #USLaw #USPol #USPolitics
-
"Musk’s #DOGE Goons Surreptitiously Transmitted Reams of White House Data. Musk’s team installed a Starlink Wi-Fi terminal on top of the White House, allowing them to bypass data-tracking security measures."
https://www.thedailybeast.com/elon-musks-doge-goons-surreptitiously-transmitted-reams-of-white-house-data/PS: This looks like it violates a handful of serious federal laws. But will the Trump #DOJ prosecute? Even investigate? Trump could pardon all the DOGE players or simply direct their nonprosecution. Or if the Trump-Musk spat continues, he could press for max penalties under law. If he doesn't, could it be that there's evidence of his own approval or involvement? What data was transmitted and who has copies now?
#Espionage #CFAA #Musk #Trump #Theft #USLaw #USPol #USPolitics
-
"Musk’s #DOGE Goons Surreptitiously Transmitted Reams of White House Data. Musk’s team installed a Starlink Wi-Fi terminal on top of the White House, allowing them to bypass data-tracking security measures."
https://www.thedailybeast.com/elon-musks-doge-goons-surreptitiously-transmitted-reams-of-white-house-data/PS: This looks like it violates a handful of serious federal laws. But will the Trump #DOJ prosecute? Even investigate? Trump could pardon all the DOGE players or simply direct their nonprosecution. Or if the Trump-Musk spat continues, he could press for max penalties under law. If he doesn't, could it be that there's evidence of his own approval or involvement? What data was transmitted and who has copies now?
#Espionage #CFAA #Musk #Trump #Theft #USLaw #USPol #USPolitics
-
"Musk’s #DOGE Goons Surreptitiously Transmitted Reams of White House Data. Musk’s team installed a Starlink Wi-Fi terminal on top of the White House, allowing them to bypass data-tracking security measures."
https://www.thedailybeast.com/elon-musks-doge-goons-surreptitiously-transmitted-reams-of-white-house-data/PS: This looks like it violates a handful of serious federal laws. But will the Trump #DOJ prosecute? Even investigate? Trump could pardon all the DOGE players or simply direct their nonprosecution. Or if the Trump-Musk spat continues, he could press for max penalties under law. If he doesn't, could it be that there's evidence of his own approval or involvement? What data was transmitted and who has copies now?
#Espionage #CFAA #Musk #Trump #Theft #USLaw #USPol #USPolitics
-
"Musk’s #DOGE Goons Surreptitiously Transmitted Reams of White House Data. Musk’s team installed a Starlink Wi-Fi terminal on top of the White House, allowing them to bypass data-tracking security measures."
https://www.thedailybeast.com/elon-musks-doge-goons-surreptitiously-transmitted-reams-of-white-house-data/PS: This looks like it violates a handful of serious federal laws. But will the Trump #DOJ prosecute? Even investigate? Trump could pardon all the DOGE players or simply direct their nonprosecution. Or if the Trump-Musk spat continues, he could press for max penalties under law. If he doesn't, could it be that there's evidence of his own approval or involvement? What data was transmitted and who has copies now?
#Espionage #CFAA #Musk #Trump #Theft #USLaw #USPol #USPolitics
-
Lost the post I was trying to quote… #AI #BadBots #CreepyCrawlers #CFAA https://bsky.app/profile/did:plc:gd454babhsadtqelpkvuopqr/post/3llbdk4d5222h
-
Sue these f*ckers for unauthorised access to sites, a serious offence under the US #CFAA, and I’m sure many options for (class) civil suits… I defer of course to my learned US friends 👩💼 https://natlawreview.com/article/scotus-resolves-circuit-split-limits-scope-computer-fraud-and-abuse-act
Supreme Court Resolves Unautho... -
In A Monday Night Declaration, The White House Admits #Musk And #DOGE Violated The #CFAA (Although They Might Not Realize It) - https://www.techdirt.com/2025/02/18/in-a-monday-night-declaration-the-white-house-admits-musk-and-doge-violated-the-cfaa-although-they-might-not-realize-it/
-
In A Monday Night Declaration, The White House Admits #Musk And #DOGE Violated The #CFAA (Although They Might Not Realize It) - https://www.techdirt.com/2025/02/18/in-a-monday-night-declaration-the-white-house-admits-musk-and-doge-violated-the-cfaa-although-they-might-not-realize-it/
-
In A Monday Night Declaration, The White House Admits #Musk And #DOGE Violated The #CFAA (Although They Might Not Realize It) - https://www.techdirt.com/2025/02/18/in-a-monday-night-declaration-the-white-house-admits-musk-and-doge-violated-the-cfaa-although-they-might-not-realize-it/
-
In A Monday Night Declaration, The White House Admits #Musk And #DOGE Violated The #CFAA (Although They Might Not Realize It) - https://www.techdirt.com/2025/02/18/in-a-monday-night-declaration-the-white-house-admits-musk-and-doge-violated-the-cfaa-although-they-might-not-realize-it/
-
In A Monday Night Declaration, The White House Admits #Musk And #DOGE Violated The #CFAA (Although They Might Not Realize It) - https://www.techdirt.com/2025/02/18/in-a-monday-night-declaration-the-white-house-admits-musk-and-doge-violated-the-cfaa-although-they-might-not-realize-it/