Computer Fraud and Abuse Act

From ICANNWiki
Jump to navigation Jump to search

The Computer Fraud and Abuse Act or CFAA was originally enacted in 1984.[1][2] The act addressed "protected" computers, such as government computers or computers that had access to foreign commerce or communication information from unauthorized access.[3][2] The act also protects the computers of financial institutions from attacks.[4] The CFAA's practical use, however, has expanded in scope to include attacks and unauthorized access to private computers in addition to government computers.[5][2]

Historical Use

The CFAA has been amended multiple times since it was enacted in 1984.[6][7] In its original version, it was only used in one case.[6] However, revisions expanded its scope to include transmitting viruses, damaging computers or files, exceeding one's authorization, and attempting to cause financial harm.[7] The first person to be prosecuted under the 1986 CFAA was Robert Morris for releasing a worm that damaged and threatened protected computers.[6][8] Despite his claims that he did not want to damage other computer networks or realize how quickly the worm would spread, Morris was fined and sentenced to community service.[8]


  • This act was aimed at securing government computers from attacks such as botnets attacks, attacks caused by malware, and data theft enabled by hacking, which can be prosecuted using the CFAA.[3]
  • The CFAA makes it illegal to use "malicious code" to damage protected computers, although it does not address creating malicious code.[2]
  • Under this law, it is also illegal to "knowingly traffic in computer passwords" or to commit extortion by threatening or attacking a protected computer.[3]
  • Additionally, civil lawsuits can take place and damages can be awarded.[3][4]
  • Additions to the CFAA in 2008 made "conspiracy" to commit computer crimes punishable as well.[2]
  • Penalties under the CFAA include fines and imprisonment depending on the severity of the offense.[4]

Calls for Reform

  • Despite periodic reforms, some feel that the CFAA needs major renovation in order to remain relevant and just.[9][10]
  • Aaron's Law, a proposed bill that would change the CFAA, was introduced in the Senate in June of 2013 where it was then referred to a committee.[11]
    • This bill named for Aaron Swartz, who committed suicide while facing charges for violations of the CFAA. [9] These charges arose after Swartz apparently accessed MIT's network without authorization and downloaded articles from the private database JSTOR.[9] According to a New York Times article, for downloading approximately 4.8 million articles, he was possibly facing "up to 35 years in prison and $1 million in fines."[9]
  • Another concern voiced about the CFAA involves the act's incredibly broad scope and general application.[12] In fact, employers have tried to use the undefined phrase "unauthorized access" to prosecute employees who use their computers without explicit permission.[12] People have also attempted to use the CFAA to prosecute those who violate the terms and conditions of specific websites or services.[12][2] Some argue that the current scope of the CFAA may leave it open to possibly abusive or even unconstitutional interpretations.[12]

Additional Resources

Related Articles