US Supreme Court’s Computer Fraud Ruling Has Big Implications for Crypto
This summer, the U.S. Supreme Court will consider how to interpret the 1986 Computer Fraud and Abuse Act, a key data protection law. The court’s decision could criminalize common but technically prohibited computer-related conduct, put limitations on a powerful law that punishes insider data theft and abuse like exchange hacks, or come down somewhere in the middle.
At issue in United States v. Van Buren is the interpretation of a provision of the CFAA, [18 U.S.C. § 1030(a)(2)(C)] which makes it a federal crime to “access[] a computer without authorization or exceed[] authorized access,” and “thereby obtain[] information from any protected computer.” To “exceed[] authorized access” means “to access a computer with authorization and to use such access to obtain or alter information in the computer that the accesser is not entitled so to obtain or alter.”
The case was initiated by a Georgia police officer, Nathan Van Buren, who was authorized to access and search a police database for law enforcement purposes, but instead accessed that database to identify a person in exchange for payment by a private citizen. Van Buren was charged criminally with a violation of the CFAA.
Van Buren argued that “accessing [information] for an improper or impermissible purpose does not exceed authorized access as meant by” the CFAA. The government argued that “a defendant violates the CFAA not only when he obtains information that he has no ‘rightful[]’ authorization whatsoever to acquire, but also when he obtains information ‘for a nonbusiness purpose.’”
Van Buren was convicted at trial of violating the CFAA. On appeal, his conviction was upheld by the Eleventh Circuit Court of Appeals based on United States v. Rodriguez, which holds that a person with access to a computer for business reasons “exceed[s] his authorized access” when he “obtain[s] … information for a nonbusiness reason.”
This interpretation could also criminalize 51% attacks against public network blockchains.
Not all circuit courts of appeal interpret that provision of the CFAA the same way. The First, Fifth, Seventh, and Eleventh Circuits have imposed liability where an authorized person accesses data on a system with authorization and exceeds that authorization by obtaining information for an improper purpose. The Second, Fourth, and Ninth Circuitshave ruled that a person violates that portion of the CFAA only if he accesses information on a computer that he is prohibited from accessing for any reason.
Van Buren’s appeal asks the U.S. Supreme Court to decide on this split and determine “[w]hether a person who is authorized to access information on a computer for certain purposes violates [the CFAA] if he accesses the same information for an improper purpose.”
What’s at stake
Resolving this conflict is important.
The position taken by the Eleventh Circuit may protect crypto users in case of insider theft. For example, if an insider at a crypto exchange has the right to access customer data or private keys and uses that access for an improper purpose (i.e. to sell that data on the dark web), that insider could be charged under the CFAA and subject to criminal penalties.
However, it has been argued that this interpretation could criminalize common conduct, such as operating March Madness pools on employer-owned computers in violation of company policies, and activities that are not illegal but are contractually prohibited, like lying about your height on an online dating site in violation of the website’s terms of service.
This broad interpretation has been attacked in Van Buren as problematic from a constitutional perspective on the grounds that it can transform a violation of a private agreement into a criminal offense and raise due process issues.
From a crypto perspective, the broad (11th Circuit) interpretation may suggest that a trader on a crypto exchange who spoofs, churns, or wash trades (actions which may violate applicable commodities law but which are rarely punished) may be subject to criminal liability under the CFAA if that activity violates the exchange’s terms of use. This interpretation could also criminalize 51% attacks against public network blockchains if a court viewed the consensus rules, software, and work contributed by miners to form implied contracts that prohibit such conduct.
Under this broader interpretation, intermediaries like exchanges or custodians that grant insiders access to valuable information may attempt to protect themselves and their information by updating their policies to expressly prohibit insiders from using that information for any non-business purpose. These companies may also seek to confirm that their insurance policies cover any potential violations.
The outcome could have big implications for the cryptocurrency industry which increasingly relies on legally enforceable privacy rights.
The narrower interpretation promoted by Van Buren would limit the application of the CFAA to access without authorization, regardless of use. This interpretation restricts the application of criminal penalties to conduct that is more like “traditional” hacking, and may reduce the possibility that minor violations of boilerplate agreements could be treated as federal crimes. This interpretation could limit claims against insiders who have the authority to access data and use that data for an improper purpose.
The CFAA can be a powerful weapon against hackers. It could allow civil parties to sue and enable prosecutors to seek criminal penalties, including potential incarceration of violators for up to five years. Limitations on the CFAA’s reach could deprive prosecutors of a tool to punish data breaches and insider attacks.
Like many other computer- related federal laws, the CFAA pre-dates the modern internet, and is showing its age. Although there may be reason to suggest a modernization of the law to better fit the current internet- enabled business world, courts, parties, and prosecutors alike continue to rely on the CFAA to protect computers, data, and on-line assets. A variety of industries and interests, including the crypto world, should await the court’s verdict with interest. The outcome could have big implications for the cryptocurrency industry which increasingly relies on legally enforceable privacy rights and the power of the law to ensure that intermediaries properly secure their customer’s digital assets.
Disclosure
The leader in blockchain news, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups.
NEO is a smart contract platform, similar to Ethereum, that was created by a team of developers in China and was formerly known as Antshares. It was designed to utilize “blockchain technology to digitize assets using smart contracts and common programming language”. The platform was created by Da Hongfei and Erik Zhang. It has the…
Amazon Web Services (AWS) is searching for a specialist to foster digital asset underwriting, transaction processing, and custody in the cloud, according to a recent job posting.The infrastructure giant wants to hire a Financial Services Specialist to work with global financial institutions and innovative fintechs, and “transform the way they transact digital assets (ex. cryptocurrencies,…
Feb 28, 2020 at 12:02 UTCUpdated Feb 28, 2020 at 12:04 UTCStock facial recognition image. Credit: ShutterstockCoinbase Is Testing Clearview’s Controversial Facial Recognition TechnologyCoinbase is among more than 2,000 entities from around the world working with Clearview, a controversial facial recognition technology provider.Internal documents obtained by BuzzFeed revealed New York-based Clearview AI – a startup…
Jan 14, 2020 at 17:00 UTCUpdated Jan 14, 2020 at 17:01 UTCWhat It Takes to Get a Crypto-Friendly Bank Charter in WyomingIt’s been more than three months since Wyoming began taking applications to charter a new type of crypto-friendly bank, and no company has announced its application while a handful of firms have indicated an…
The Commodity Futures Trading Commission oversees more than $400 trillion in notional value in the swaps market, making crypto's $1.3 trillion market cap seem paltry, yet the agency devoted 47 enforcement actions against the industry in 2023. In a year from 2022 to 2023, the CFTC cranked up its crypto case load from 20% to
Let me take you back to a simpler time. On this day two years ago, Nov. 9, 2021, bitcoin maxis were sporting red laser eyes, FTX had just closed a $420 million funding round and rumor had it that dogecoin’s (DOGE) biggest fan, Elon Musk, may host an upcoming episode of “S and L.” On
Mining machines image via ShutterstockPotentially the world's biggest bitcoin mine is said to have signed up two top corporate customers in the form of SBI Holdings and GMO.The Japanese corporate giants will be renting mining capacity at the facility in Rockdale, Texas, recently put into construction by Whinstone Inc., according to Bloomberg sources. The firms…
With bitcoin bouncing back up and approval of the first federally chartered crypto bank, CoinDesk’s Market’s Daily is back with the latest crypto news roundup.Add Markets Daily to your Alexa Flash Briefing here.This episode is sponsored by Nexo.io.Today's stories:While a 31% rally to $50,000 in two weeks may be challenging to envision, it is far…
This article originally appeared in First Mover, CoinDesk’s daily newsletter putting the latest moves in crypto markets in context. Subscribe to get it in your inbox every day.Bitcoin and stocks started the week on a hesitant note as uncertainty in markets continued. Bitcoin dropped back below $27,000 on Saturday and is down slightly over the…