US Cybercrime Laws Being Used To Target Security Researchers
Security researchers say they have been threatened with indictment for their work investigating internet vulnerabilities
Some of the world’s best-known security researchers claim to have been threatened with indictment over their efforts to find vulnerabilities in internet infrastructure, amid fears American computer hacking laws are perversely making the web less safe to surf.
Many in the security industry have expressed grave concerns around the application of the US Computer Fraud and Abuse Act (CFAA), complaining law enforcement and lawyers have wielded it aggressively at anyone looking for vulnerabilities in the internet, criminalising work that’s largely benign. They have also argued the law carries overly severe punishments, is too vague and does not consider context, only the action.
HD Moore, creator of the ethical hacking tool Metasploit and chief research officer of security consultancy Rapid7, told the Guardian he had been warned by US law enforcement last year over a scanning project called Critical.IO, which he started in 2012. The initiative sought to find widespread vulnerabilities using automated computer programs to uncover the weaknesses across the entire internet...
- Tags:
- Aaron Swartz
- Aaron’s Law
- Andrew “weev” Auernheimer
- AT&T
- computer hacking laws
- Critical.IO
- digital rights
- Duo Security
- hacking
- HD Moore
- internet infrastructure vulnerabilities
- Internet safety
- Internet security researchers
- Jeremiah Grossman
- JSTOR
- Marcia Hoffman
- Metasploit
- Rapid7
- U.S. Congress
- Universal Plug and Play (UPnP)
- US Computer Fraud and Abuse Act (CFAA)
- Whitehat Security
- Zach Lanier
- Zoe Lofgren
- Login to post comments