
Introduction
This blog provides a high-level overview of the Computer Fraud and Abuse Act (CFAA) and its implications for ethical hackers, particularly those involved in bug bounty programs, vulnerability disclosure programs (VDPs), penetration testing, and red teaming engagements. Drawing from extensive research, this blog aims to equip cybersecurity professionals with the knowledge needed to navigate legal complexities, ensuring their work remains both effective and lawful.
DISCLAIMER: This blog should not be taken as legal advice and is only for educational and research purposes only.
Origins of the CFAA
The CFAA was enacted in 1986 by the US Congress as an amendment to address the limitations of earlier laws, specifically the Counterfeit Access Device and Computer Fraud and Abuse Act of 1984. It aimed to extend tort law to intangible property, initially focusing on federal interest computers, such as those used by government agencies and financial institutions. Over time, amendments, including those in 1994 and 2008, expanded its scope to include any computer used in or affecting interstate or foreign commerce, significantly broadening its reach – this also included conspiring to commit computer crime.
High-profile cases have significantly shaped the interpretation of the Computer Fraud and Abuse Act (CFAA), clarifying its scope and implications for cybersecurity practitioners. In United States v. Morris (1991), Robert Tappan Morris, a Cornell graduate student, unleashed the Morris worm, one of the first internet worms, inadvertently disrupting thousands of federal and university computers. It’s also important to note that this was the first felony conviction for a computer crime under the CFAA.
Robert Tappan Morris’s punishment for his conviction in United States v. Morris included three years of probation, 400 hours of community service, a fine of $10,050, and the responsibility to pay the cost of his probation supervision. Despite the potential for a prison sentence, Morris ultimately received probation for his role in releasing the internet worm.
Another notable case, Van Buren v. U.S. (2021), clarified the meaning of “exceeds authorized access,” ruling that it applies to accessing information for an improper purpose, not just exceeding technical permissions. This case involved Nathan Van Buren, a police sergeant, who used his valid credentials to access a law enforcement database to retrieve license plate information in exchange for money. This action violated his department’s policy, which authorized database access only for law enforcement purposes.
Two key concepts, “Access Without Authorization” and “Exceeding Authorized Access,” are central to the CFAA. The former refers to gaining entry without any permission, while the latter involves using authorized access in a way that goes beyond what was permitted, often leading to legal disputes in ethical hacking contexts.
Seven Prohibited Acts of the CFAA
The CFAA outlines seven specific prohibited acts, each with potential criminal penalties, including fines and imprisonment. Below is a detailed summary, with associated penalties based on the severity and context of the offense:
CFAA Section (a)(1): Hacking to commit espionage
This section criminalizes accessing a computer without authorization to obtain information related to national defense or foreign relations and then communicating or delivering that information to unauthorized persons. It is designed to prevent espionage conducted through computer hacking. Violators can face fines and up to 10 years in prison for a first offense, and up to 20 years for subsequent offenses.
CFAA Section (a)(2): Hacking to obtain information
This provision makes it illegal to intentionally access a computer without authorization or to exceed authorized access to obtain financial records, information from U.S. government agencies, or data from any protected computer. Penalties include fines and up to 1 year in prison for a first offense, which can increase to 5 years if the offense was committed for commercial advantage, in furtherance of a criminal or tortious act, or if the value of the information exceeds $5,000. Repeat offenses can lead to fines and up to 10 years in prison.
CFAA Section (a)(3): Hacking a federal government computer
This specifically targets unauthorized access to nonpublic computers of U.S. government departments or agencies, where such access affects the computer’s use. The penalties are similar to those in section (a)(2): fines and up to 1 year in prison for a first offense, potentially increasing to 5 years under the same conditions (commercial advantage, criminal act, or value over $5,000), and up to 10 years for subsequent offenses.
CFAA Section (a)(4): Hacking to commit fraud
This part of the CFAA addresses accessing a protected computer without authorization or exceeding authorized access with the intent to defraud, and thereby obtaining something of value exceeding $5,000 within a one-year period. Offenders can be fined and imprisoned for up to 5 years for a first offense, and up to 10 years for subsequent offenses, reflecting the serious nature of fraud involving computers.
CFAA Section (a)(5): Hacking to commit damage
This section encompasses various forms of causing damage to a protected computer, such as knowingly causing the transmission of a program, information, code, or command that intentionally causes damage, or intentionally accessing a protected computer without authorization and recklessly causing damage, or causing damage and loss by intentional unauthorized access. Penalties vary based on the specific conduct and the extent of the damage caused, ranging from fines and up to 1 year in prison for lesser offenses under certain conditions to up to 10 years for more serious damage, with provisions for up to 20 years or life imprisonment if the conduct results in serious bodily injury or death.
CFAA Section (a)(6): Trafficking in passwords
This prohibits knowingly trafficking in passwords or similar information with the intent to defraud, where such trafficking affects interstate or foreign commerce or involves computers used by or for the U.S. government. Penalties are fines and up to 1 year in prison for a first offense, increasing to 5 years if the offense involves commercial advantage, is part of a criminal or tortious act, or the value exceeds $5,000, and up to 10 years for repeat offenses.
CFAA Section (a)(7): Threats of Hacking
This provision makes it a crime to transmit threats in interstate or foreign commerce to damage a protected computer, to obtain information without authorization, or to demand money or other value in relation to damage to a protected computer, with the intent to extort. Offenders can face fines and up to 5 years in prison for a first offense, and up to 10 years for subsequent offenses, highlighting the severity of extortion through computer threats.
Implications for Bug Bounty Programs and Vulnerability Disclosure Programs
Bug Bounty Programs and VDPs are critical for organizations to identify and fix security vulnerabilities, but they operate under the shadow of the CFAA, which can create legal uncertainties for participants. The law prohibits accessing a computer without authorization or exceeding authorized access, potentially criminalizing good-faith testing without proper protections.
Safe Harbor and Scope
Many platforms, such as HackerOne, YesWeHack, and Intigriti, offer safe harbor clauses, ensuring researchers following program rules are protected from CFAA violations. Staying within scope is crucial; exceeding it can lead to legal trouble.
For example, in 2017, a teenage Hungarian security researcher was arrested for finding an exploit to the Budapest Transport Authority(BKK) online payment system which allowed him to manipulate the price of a ticket through the client-side browser. He had reported it to the proper authorities, but during this time, there was no vulnerability disclosure program or bug bounty program in place – and was arrested even though the teenager’s intentions were good.
Some real world examples in the US include legal cases, such as United States v. Rodriguez (2010) (Not to be confused with UNITED STATES OF AMERICA v. ROBERTO RODRIGUEZ), where a Social Security employee was convicted for exceeding authorized access by using work computers for personal purposes, highlight the CFAA’s potential to affect researchers. While not directly a bug bounty case, it shows how the law can be applied broadly, deterring good-faith security research.
DOJ Framework for Vulnerability Disclosure Programs
The U.S. Department of Justice (DOJ) has introduced critical guidance, such as its 2017 A Framework for a Vulnerability Disclosure Program for Online Systems (VDPs), to clarify legal boundaries under the Computer Fraud and Abuse Act (CFAA) and foster safe vulnerability reporting. This framework outlines structured processes for organizations to authorize security researchers to test systems without fear of prosecution under CFAA section (a)(2), which penalizes unauthorized access with fines and up to 1-5 years in prison. Of note, CFAA section (a)(2) is also a frequent basis for many CFAA criminal prosections and civil litigations. By establishing clear “safe harbor” provisions, the DOJ encourages good-faith disclosures, as seen in platforms like HackerOne and Intigriti, which integrate VDP policies to protect researchers who stay within scope.
Implications for Penetration Testing and Red Teaming Engagements
Penetration testing and red teaming are essential for assessing an organization’s security posture, but they must be conducted with explicit authorization to avoid CFAA violations. Without proper scope and rules of engagement (ROE), testers risk being seen as unauthorized hackers.
Clear Scope and Rules of Engagement (ROE)
The Computer Fraud and Abuse Act (CFAA) can significantly impact penetration testing, as illustrated by legal precedents that highlight its broad application. It’s vital to have a well-defined scope and ROE agreed upon with the client, documenting all activities to prove authorization.
For instance, in the 2019 Coalfire case involved penetration testers arrested during an authorized physical penetration test at an Iowa courthouse, charged with burglary initially, later reduced to misdemeanor trespass. This case demonstrates how miscommunication can lead to legal issues, even with authorization, highlighting an unexpected detail: the risk extends beyond technical access to physical security tests.
In United States v. Nosal (2010), David Nosal, a former executive at Korn Ferry, was convicted under CFAA section (a)(4) for exceeding authorized access by persuading employees to extract confidential client data for his competing venture, violating company access policies. This case, resulting in a year in prison and fines, demonstrates the CFAA’s reach beyond technical hacking to include social engineering, a tactic often used in penetration testing, with violations carrying fines and up to 5-10 years in prison.
Conclusion
Understanding the CFAA is crucial for ethical hackers to operate within the law, ensuring their work protects organizations without risking legal issues. Staying within scope, whether in bug bounties or penetration testing, is essential. Clear communication with clients, documenting ROE, and verifying program guidelines help maintain legal compliance. This is particularly important given the CFAA’s evolution, now covering a wide range of computers, including those in small businesses, due to amendments expanding its scope to interstate commerce.
The CFAA is a complex and evolving law that requires careful navigation by ethical hackers. While it poses challenges, modern approaches like safe harbor clauses and clear VDPs offer protections. This blog, for educational purposes only, emphasizes the importance of staying informed and consulting legal professionals for advice. By understanding the CFAA, ethical hackers can continue to contribute to cybersecurity while staying on the right side of the law.
– Z333RO
US Cases Referenced:
- United States v. Morris (1991)
- Van Buren v. U.S. (2021)
- United States v. Rodriguez (2010)
- United States v. Nosal (2010)
- Coalfire case (2019)
Further Reading:
- Cybersecurity Law, 2nd Edition by Jeff Kosseff
- The Law of Cybercrimes and Their Investigations, 1st Edition by George Curtis
