The Computer Fraud and Abuse Act is a pain point for many in the cybersecurity industry, particularly ethical hackers testing systems for research purposes. The most notable case was that of Aaron Swartz, a programmer and hacktivist who was indicted under the law in 2011 and later committed suicide rather than face up to 35 years in prison.

During a talk at Black Hat 2015, Leonard Bailey, special counsel for national security at the Department of Justice’s Computer Crime and Intellectual Property Section, called Swartz’s death a tragedy for the cybersecurity community and tried to assuage fears that the law would be used against researchers.

Justice prosecuted 194 CFAA cases in 2014, a minor fraction of the more than 56,000 total cases filed last year, Bailey pointed out. Even so, he asserted the department’s commitment to ensuring the law isn’t abused and outlined the kind of activities that are obviously research-oriented and those that will have investigators knocking at your door.

Hackers penetrating a network for legitimate research “look a lot like a bad guy,” Bailey said. “On some level, it would be wrong if investigators weren’t trying to figure out what you were doing — you could be a bad guy.”

However, the government does not want to discourage legitimate research and Justice is working to avoid what Bailey called “a chilling effect” that such prosecutions can have.

In order to avoid getting into trouble when investigators do come knocking, Bailey laid out a set of suggestions, including what kind of low-level activities are definitely permitted and how to ensure you don’t get indicted for bigger projects.

“If you’re pinging a network that is not illegal conduct,” he said. “If you’re port scanning, it’s not a problem unless you’re doing it at a level that is likely to result in a denial of service attack.”

Bailey recommended having an explanation of what you’re doing and why you’re doing it on hand just in case. He suggested posting it online before you start, so you can point to that when investigators take interest in your work.

When it comes to critical infrastructure, investigators are sure to take notice, he said.

“I recommend that you avoid that,” he said. “If not, I strongly recommend you minimize the kinds of information you will be holding onto,” as differentiating between hackers harvesting PII to sell on the market and those doing it for research is difficult.

Justice has also implemented a number of policies to avoid prosecuting legitimate research activities and ensure CFAA is applied consistently.

When deciding whether to prosecute, federal attorneys are told to consider six factors: resulting harm; the victim(s); sensitivity of the data; harm to national security or public safety; larger criminal activity; and deterrence.

On the last factor, Bailey explained prosecutors might bring a case to shine a light on new kinds of crime to show the public (and hacking community) that it is a series issue.

Bailey added that he understood concerns about the law and how it might be “chilling legitimate security research.”

“Sentences are not being given out in a crazy way,” he said, noting the average sentence is 23 months. “Prosecutors are not going wild. Does this mean concerns about chilling should be disregarded? Absolutely not … We are not targeting computer security researchers and in fact we want to figure out how we can facilitate legitimate security research.”

About 

Aaron Boyd is an awarding-winning journalist currently serving as editor of Federal Times — a Washington, D.C. institution covering federal workforce and contracting for more than 50 years — and Fifth Domain — a news and information hub focused on cybersecurity and cyberwar from a civilian, military and international perspective.