Research: CFAA Prosecutorial Patterns — The Quiet Crusade Against Security Researchers
Contents 44 sections
The Thesis in One Sentence
The United States government, aided by corporate legal departments, has spent four decades prosecuting the people who actually find security vulnerabilities — while paying billions annually to compliance consultancies that produce PDF reports nobody reads.
1. The Law Itself: A Brief Anatomy of the CFAA
The Computer Fraud and Abuse Act (18 U.S.C. § 1030) was enacted in 1986 as an amendment to the first federal computer fraud law from 1984. It was written in an era when “computer” meant a mainframe in a government facility, and “unauthorized access” meant physically breaking into a room.
The statute criminalises:
- Accessing a computer “without authorization” or “exceeding authorized access”
- Obtaining information from protected computers
- Trafficking in passwords
- Causing damage to protected computers
- Extortion involving computers
The critical problem: the CFAA never defines “without authorization.” This omission has been the weapon of choice for federal prosecutors and corporate legal departments for nearly 40 years.
Maximum penalties for first-time offenders range from 1 to 10 years depending on the offence category. But the real power is in charge stacking — prosecutors can layer multiple CFAA counts for what is effectively a single act, turning misdemeanours into decades of potential prison time.
Sources:
- 18 U.S.C. § 1030 — Computer Fraud and Abuse Act
- DOJ Justice Manual — CFAA Charging Policy
- NACDL — CFAA Background
2. The Famous Three (Brief, Because You Know Them)
Aaron Swartz (2011)
Downloaded ~4.8 million academic articles from JSTOR via the MIT network. Federally indicted on 13 counts of wire fraud and CFAA violations. Faced up to 35 years in prison and $1 million in fines. Prosecutors rejected his plea deal counter-offer. Swartz took his own life on 11 January 2013 at age 26.
JSTOR itself declined to pursue charges. MIT stayed silent. The federal government prosecuted anyway.
Sources:
Andrew “weev” Auernheimer (2012)
Discovered an AT&T vulnerability that exposed iPad owners’ email addresses on a public-facing URL. Notified AT&T, which did nothing. Disclosed to Gawker. Convicted, sentenced to 41 months in federal prison plus $73,000 in restitution. The government attempted to bootstrap a state computer crime charge to elevate the federal CFAA misdemeanour to a felony — a charge-stacking trick the defence called a Double Jeopardy violation since all 50 states have similar statutes, meaning essentially all federal CFAA misdemeanours could be inflated to felonies. Conviction overturned on appeal (venue, not merit) in 2014.
AT&T was never charged for exposing customer data.
Sources:
- United States v. Auernheimer — DMLP
- NACDL — CFAA Cases
- Orin Kerr’s pro bono representation brief — Volokh Conspiracy
Marcus Hutchins (2017)
The researcher who stopped WannaCry was arrested at DEF CON and charged under the CFAA for malware he allegedly wrote as a teenager years earlier. Pleaded guilty to two counts in 2019. Sentenced to time served with one year of supervised release. The message to every security researcher was clear: even if you save the internet, they can still come for you.
3. The Ones You Haven’t Heard Of
Robert Morris Jr. (1988) — The First Prosecution
The very first CFAA prosecution was not of a criminal but of a Cornell graduate student. Robert Morris, son of an NSA computer scientist, released the “Morris Worm” as part of his PhD research exploring internet security. The worm was not designed to cause damage but a coding error caused it to replicate uncontrollably, affecting roughly 6,000 of the internet’s then 60,000 connected machines. Convicted of a felony in 1990. Sentenced to three years’ probation, 400 hours of community service, and a $10,050 fine. The CFAA’s baptism: prosecuting a curious graduate student.
Sources:
Bret McDanel (2001) — Imprisoned for Warning Users
McDanel worked at Tornado Development, an email service provider. He discovered that the system stored user login credentials in plaintext as part of the URL — meaning every website a user visited after leaving Tornado could capture their credentials in server logs. He reported it to Tornado. Six months later, the flaw was still unpatched. McDanel emailed Tornado’s users from “Secret Squirrel” to warn them. Tornado reported him to the FBI.
Convicted after a bench trial. Sentenced to 16 months in federal prison. For telling users their passwords were being broadcast in plaintext.
The federal government later admitted the prosecution was an error and voluntarily moved to vacate the conviction. But McDanel had already served his time.
Sources:
- FindLaw — The Federal Government’s Strange Cyber-Defamation Case Against Bret McDanel
- Slashdot — Feds Admit Error In McDanel Security Case
- ResearchGate — Vulnerability Disclosure: The Strange Case of Bret McDanel
Justin Shafer (2016) — Raided for Finding an Open FTP Server
Shafer, a Texas dental software technician and security researcher, discovered that Eaglesoft practice management software (by Patterson Dental) had an anonymous FTP server exposing the protected health records of approximately 22,000 patients. Anyone could access it. No password required. He reported it to Patterson Dental.
Patterson claimed Shafer had “exceeded authorized access” and the FBI raided his home with at least a dozen armed agents. Shafer then blogged about the raids. For blogging about the FBI raiding him, he was charged with cyberstalking an FBI agent and spent eight months in jail awaiting trial. The government eventually dropped five felony charges, and Shafer pleaded guilty to a single misdemeanour.
The anonymous FTP server remained Patterson’s problem. Patterson was not prosecuted for the HIPAA violations.
Sources:
- Daily Dot — FBI Raids Dental Software Researcher
- DataBreaches.net — CFAA Overreach: FBI Raids Home of Security Researcher
- Emmotton Technology — Dental Security Researcher Justin Shafer
Randal Schwartz (1995) — Password Cracking as a Consultant
Schwartz, author of the O’Reilly Learning Perl book, had worked as a systems administrator contractor at Intel (1988-1993). After leaving, he ran a password cracking tool against Intel’s systems to demonstrate that security had deteriorated since his departure. Convicted of three felony counts under Oregon’s computer crime statute (the state equivalent of CFAA). Sentenced to five years’ probation, 480 hours of community service, 90 days in jail, and ordered to pay Intel $68,000 plus $170,000 in legal defence costs.
The conviction was finally expunged in 2007 — twelve years later.
Sources:
- Randal L. Schwartz — Wikipedia
- The Register — Intel ‘Hacker’ Clears His Name
- Slashdot — Randal Schwartz’s Charges Expunged
Matthew Keys (2016) — Two Years for a 40-Minute Defacement
Keys, a journalist formerly employed at a Tribune Company television station, shared CMS login credentials in an Anonymous chatroom. An unknown person used them to deface a single Los Angeles Times article for approximately 40 minutes. Keys was convicted on three CFAA counts carrying a maximum of 25 years. Sentenced to two years in federal prison. The “loss” to Tribune was estimated at $249,000 — for a 40-minute headline change that an editor reversed.
Sources:
- TechCrunch — Journalist Matthew Keys Sentenced to 2 Years
- Boing Boing — Former Reuters Journalist Sentenced to 2 Years for a 40-Minute Web Defacement
- EFF — United States v. Matthew Keys
Coalfire Penetration Testers (2019) — Arrested for Doing Their Job
Gary DeMercurio and Justin Wynn, penetration testers at Coalfire Labs, were contracted by the Iowa Court Information System to conduct physical security tests on courthouses — including impersonating employees, tailgating, and entering restricted areas. During a test at the Dallas County Courthouse, they triggered an alarm. The local sheriff arrived, saw their authorisation contract, and arrested them anyway. Charged with felony third-degree burglary and possessing burglary tools. Held on $100,000 bail. Spent nearly 24 hours in jail.
Charges were eventually downgraded to misdemeanour trespass, then dropped in January 2020. Dallas County later paid a $600,000 settlement for the wrongful arrest.
The sheriff had not been informed of the engagement. The state that hired them prosecuted them.
Sources:
- CyberScoop — Coalfire Security Pros Arrested
- CNBC — Iowa Paid Coalfire to Pen Test Courthouse, Then Arrested Employees
- Krebs on Security — Iowa Prosecutors Drop Charges
- Dark Reading — County Pays $600K to Wrongfully Jailed Pen Testers
4. Corporate Weaponisation: CFAA as a Silencing Tool
The CFAA’s civil action provision (§ 1030(g)) allows private companies to sue researchers directly. This is where the real volume lives. Criminal prosecutions make headlines; cease-and-desist letters arrive quietly and are designed to.
Cisco vs. Michael Lynn (2005) — “Ciscogate”
Security researcher Michael Lynn, working at ISS (Internet Security Systems), reverse-engineered Cisco IOS and discovered a critical vulnerability in the operating system that runs most of the internet’s core routers. He was scheduled to present his findings at Black Hat 2005 in Las Vegas. Cisco and ISS obtained a federal temporary restraining order. Conference organisers were ordered to rip Lynn’s pages from the printed proceedings. Lynn presented anyway — after quitting his job on stage.
Settlement terms required Lynn to hand over all his research data for forensic analysis, then destroy it. He was permanently prohibited from discussing the vulnerability.
The message: find a bug in the internet’s backbone and we will erase you.
Sources:
- Ciscogate — Wikipedia
- Schneier on Security — Cisco Harasses Security Researcher
- Computerworld — Furor Over Cisco IOS Router Exploit
Oracle’s CSO Rant (2015)
Oracle Chief Security Officer Mary Ann Davidson published a blog post titled “No, You Really Can’t” — telling customers and security consultants to stop reverse-engineering Oracle products to find vulnerabilities, threatening to enforce licence agreement provisions against anyone who did. She accused researchers of wasting Oracle’s time with false positives and breaking Oracle’s terms of service.
Oracle pulled the post within hours and issued a statement that it did not reflect company policy. But the damage was done: it revealed exactly how a major enterprise vendor views independent security research — as a nuisance to be litigated away.
Sources:
- Schneier on Security — Oracle CSO Rant Against Security Experts
- Mary Ann Davidson — Wikipedia
- SecurityLedger — Oracle’s Cantankerous CSO
Voatz vs. MIT Researchers (2020)
MIT graduate students Michael Specter and James Koppel conducted a security analysis of Voatz, a mobile voting app used in the 2018 West Virginia midterm elections. They found critical vulnerabilities including opportunities to alter, stop, or expose how users voted. Voatz accused the researchers of “bad faith,” reported a University of Michigan student studying election security to the FBI, and then filed an amicus brief with the Supreme Court arguing that the CFAA should criminalise any security research conducted without explicit vendor permission.
HackerOne cut ties with Voatz over its hostility toward researchers. A coalition of security firms, researchers, and organisations signed a letter opposing Voatz’s position.
A voting app vendor tried to use the nation’s highest court to make it illegal to check whether elections are secure.
Sources:
- MIT News — MIT Researchers Identify Security Vulnerabilities in Voting App
- CyberScoop — Voatz Urges Supreme Court to Not Protect Ethical Research
- The Register — Infosec Big Names Rally Against Voatz
Missouri Governor vs. a Journalist (2021)
St. Louis Post-Dispatch reporter Josh Renaud discovered that the Missouri Department of Elementary and Secondary Education website was embedding teachers’ Social Security numbers in the HTML source code of public web pages. He found this by pressing F12 — the browser’s built-in “View Source” function. The Post-Dispatch responsibly notified the state, delayed publication to allow the flaw to be patched, and then reported on it.
Missouri Governor Mike Parson held a press conference accusing Renaud of “hacking” and vowing criminal prosecution, claiming the state would seek charges against Renaud and “all those who aided” him. The investigation produced a 158-page file that found zero evidence of hacking. The Cole County prosecutor declined to press charges.
The Governor never retracted his accusations. He spent more effort attacking the reporter than fixing the system that exposed 100,000+ teachers’ Social Security numbers.
Sources:
- TechCrunch — F12 Isn’t Hacking
- Krebs on Security — Missouri Governor Vows to Prosecute Post-Dispatch
- Missouri Independent — Claim That Reporter Hacked State Website Was Debunked
The Broader Pattern
The disclose.io project maintains a public repository of legal threats against good-faith security researchers — a running catalogue of disclosure gone wrong. Cases include threats from Boeing, CyberLock (invoking the DMCA), and dozens of smaller companies. The repository is a continuation of attrition.org’s earlier documentation work.
Facebook and LinkedIn have both used cease-and-desist letters citing the CFAA against researchers and journalists whose access they wanted to curtail.
Sources:
- disclose.io — Research Threats Database
- GitHub — disclose/research-threats
- EFF — The Worst Law in Technology Strikes Again: 2017 in Review
5. The Prosecutorial Logic: How “Unauthorized Access” Becomes Whatever They Need It to Be
The CFAA’s core weapon is ambiguity. “Without authorization” and “exceeds authorized access” are nowhere defined in the statute. This gives prosecutors — and corporate lawyers filing civil suits — essentially unlimited discretion.
The Government’s Preferred Reading (Pre-2021)
For decades, DOJ’s position was maximally broad: if you accessed a computer in a way the owner didn’t like, that was “unauthorized.” Violating a website’s Terms of Service? Unauthorized. Using a work computer for personal email? Unauthorized. Accessing data that was technically public but that the vendor wished you hadn’t found? Unauthorized.
As Orin Kerr — former federal prosecutor and one of the most cited CFAA scholars — has argued, under the government’s interpretation, prosecutors could put “any Internet user they want” in jail.
The Lori Drew Problem (2009)
Lori Drew created a fake MySpace account to cyberbully 13-year-old Megan Meier, who died by suicide. Prosecutors charged Drew under the CFAA, arguing that creating a fake profile violated MySpace’s Terms of Service and therefore constituted “unauthorized access.” The jury convicted on misdemeanour counts. The judge overturned the conviction, ruling that the government’s theory would render the CFAA “unconstitutionally vague” — because it would criminalise every Terms of Service violation on the internet.
The prosecution was legally absurd but emotionally irresistible, which is exactly the combination the CFAA invites.
Sources:
Van Buren v. United States (2021) — The Supreme Court Finally Weighs In
Nathan Van Buren, a Georgia police officer, used his legitimate access to a law enforcement database to look up a licence plate in exchange for money. The government charged him under the CFAA’s “exceeds authorized access” provision.
In a 6-3 decision, the Supreme Court adopted a “gates-up-or-down” approach: either you are entitled to access the information, or you are not. Merely accessing data for an improper purpose does not “exceed authorized access” if you were technically permitted to view it. The Court explicitly rejected the government’s broad interpretation.
This was a significant narrowing — but it left enormous grey areas for security researchers, whose work by definition involves accessing systems they don’t own without explicit permission.
Sources:
- Van Buren v. United States — Wikipedia
- EFF — Van Buren is a Victory Against Overbroad Interpretations of the CFAA
- ACS — The Computer Fraud and Abuse Act After Van Buren
The 2022 DOJ Policy Revision
In May 2022, the DOJ announced it would no longer charge “good-faith security research” under the CFAA. Deputy AG Lisa Monaco claimed “the department has never been interested in prosecuting good-faith computer security research as a crime.”
The definition of “good faith” is the catch: research must be “solely” for testing, investigation, or correction of a security flaw, “designed to avoid any harm,” and information must be “used primarily to promote the security or safety” of the affected systems. Research with “ulterior” or “mixed motives” remains fair game.
Critical limitations:
- This is a prosecutorial policy, not a law. Any future administration can reverse it with a memo.
- It only covers federal criminal prosecution. It does nothing about civil CFAA lawsuits by companies, which constitute the vast majority of legal threats against researchers.
- It does not bind state prosecutors.
- The “solely” and “good faith” qualifiers give enormous discretion to the same prosecutors the policy is supposed to restrain.
- It explicitly states that receiving a cease-and-desist letter can convert previously permissible access into a CFAA violation.
Sources:
- DOJ — Department of Justice Announces New Policy for Charging CFAA Cases
- EFF — DOJ’s New CFAA Policy is a Good Start But Does Not Go Far Enough
- Wilson Sonsini — DOJ Acknowledges Limits to the CFAA, but Questions Remain
- Krebs on Security — What Counts as “Good Faith Security Research?”
6. The Numbers: What We Know (and What We Don’t)
Hard statistics on CFAA prosecutions are scarce by design. The DOJ does not publish CFAA-specific breakdowns. What we have:
What Exists
- The Federal Justice Statistics Program (Bureau of Justice Statistics) tracks federal criminal case workloads, including convictions and sentencing, but does not separate CFAA cases as a distinct category.
- The U.S. Sentencing Commission publishes sentencing data by guideline category but the computer fraud guidelines encompass more than just CFAA.
- The NACDL maintains the most comprehensive public case database of notable CFAA prosecutions.
The Chilling Effect Data
The Center for Democracy and Technology surveyed security researchers and found over half reported forgoing some research or avoiding research altogether because of potential CFAA liability. A 2018 CDT report interviewing 20 academic and independent researchers found that over half cited the CFAA as a major risk factor in their work.
The majority of concerns stemmed from uncertainty around the undefined term “access” — meaning researchers cannot reliably predict whether their work is legal before they do it.
Cease-and-desist letters citing the CFAA “have become an all-too-common tool for intimidation.” The exact number is unknowable — that’s the point of a chilling effect.
Sources:
- Federal Justice Statistics Program — Bureau of Justice Statistics
- U.S. Sentencing Commission — Data Reports
- New America — Cybersecurity Research Should Not Be a Crime
- CDT — The Supreme Court and the Copyright Office
- Brookings — America’s Anti-Hacking Laws Pose a Risk to National Security
Sentencing Patterns from Known Cases
| Case | Charge | Outcome | Sentence |
|---|---|---|---|
| Robert Morris (1988) | Felony CFAA | Convicted | 3 yrs probation, 400 hrs community service, $10,050 fine |
| Randal Schwartz (1995) | 3 felony counts (state) | Convicted (expunged 2007) | 5 yrs probation, 480 hrs community service, 90 days jail, $238,000 costs |
| Bret McDanel (2001) | CFAA violation | Convicted, later vacated | 16 months prison |
| Aaron Swartz (2011) | 13 counts wire fraud + CFAA | Died before trial | Faced up to 35 years |
| Andrew Auernheimer (2012) | CFAA + NJ state bootstrap | Convicted, reversed on appeal | 41 months prison + $73,000 restitution |
| Matthew Keys (2015) | 3 CFAA counts | Convicted | 2 years prison |
| Justin Shafer (2016) | CFAA + cyberstalking | Pled to 1 misdemeanour | 8 months jail (pretrial) |
| Marcus Hutchins (2017) | CFAA (malware-related) | Pled guilty 2 counts | Time served + 1 yr supervised release |
| Coalfire testers (2019) | Felony burglary | Charges dropped | $600,000 settlement to defendants |
7. International Comparison: Everyone Has the Same Problem, Some Handle It Worse
United Kingdom — Computer Misuse Act 1990
The UK’s Computer Misuse Act (CMA) is arguably worse than the CFAA. The US at least has a more developed vulnerability research ecosystem — companies like Shodan and Censys are headquartered in the US precisely because the methods they use would be illegal under the CMA.
The CMA criminalises “unauthorized access to computer material” with the same definitional vacuum as the CFAA. But it lacks the CFAA’s civil cause of action — meaning the UK problem is purely criminal. The CMA has no explicit carve-out for security research.
The CyberUp Campaign has been pushing for CMA reform for years, producing detailed evidence for Parliament documenting how the law chills legitimate security research. In 2025, the UK government pledged to rewrite the CMA, introducing long-overdue statutory protections for cyber security professionals and threat researchers.
Sources:
- Rapid7 — Reforming the UK’s Computer Misuse Act
- CyberUp Campaign — Written Evidence to Parliament
- SCL — The 30-Year-Old Computer Misuse Act Is Not Fit For Purpose
- Computer Weekly — UK Government Pledges to Rewrite Computer Misuse Act
Netherlands — The Model That Works
The Netherlands has the most mature responsible disclosure framework in Europe. The Dutch government explicitly states that if researchers comply with disclosure conditions, “the government will not attach any legal consequences to your notification.” The Public Prosecution Office has a standing policy not to prosecute ethical hackers who follow the framework.
Sources:
Belgium — Safe Harbour (2023)
Belgium became the first European country to adopt a comprehensive, nationwide safe harbour for ethical hackers, effective 15 February 2023. The Centre for Cyber Security Belgium (CCB) framework protects anyone who reports security vulnerabilities in Belgian systems from prosecution, provided they meet strict conditions. According to the CCB’s legal officer, Belgium’s framework is the most comprehensive in Europe; France and Slovakia fall short of “full legal protection,” and Lithuania’s is limited to critical infrastructure.
Sources:
- Intigriti — Safe Harbor Legal Framework for Ethical Hackers Launches in Belgium
- PortSwigger — Belgium Launches Nationwide Safe Harbor
European Union — NIS2 Directive (2022)
The NIS2 Directive (EU 2022/2555) includes provisions for coordinated vulnerability disclosure and “encourages” member states to adopt guidelines on non-prosecution of security researchers. Note the word: “encourages.” Not “requires.” Member states “should aim to address the challenges faced by vulnerability researchers, including their potential exposure to criminal liability, in accordance with national law.”
A 2025 paper in the Oxford Journal of Cybersecurity called for defining “good-faith security research” as a legally recognised safe harbour in EU law, arguing that the current patchwork approach creates legal uncertainty that “may hinder or even prevent the reporting of vulnerabilities.”
Sources:
- NIS 2 Directive — Article 12: Coordinated Vulnerability Disclosure
- ENISA — Coordinated Vulnerability Disclosure Policies in the EU (PDF)
- Oxford Academic — Hunting for Vulnerabilities: Call for European Protection of Security Researchers
Germany — They’ll Fine You for Finding Their Bugs
In 2021, a German IT consultant known as Hendrik H. discovered that Modern Solution GmbH’s e-commerce software stored database passwords in plaintext, exposing nearly 700,000 customer records. He reported it to the company. Modern Solution reported him to the police. A Jülich District Court initially sided with the consultant, then reversed itself on appeal. In January 2024, Hendrik H. was fined EUR 3,000 for discovering that a company was storing passwords in plaintext. He filed a constitutional complaint; the Cologne Higher Regional Court confirmed the judgment.
Sources:
- The Register — IT Consultant in Germany Fined for Exposing Shoddy Security
- Dark Reading — German IT Consultant Fined Thousands for Reporting Security Failing
- Heise Online — Modern Solution: Convicted IT Expert Files Constitutional Complaint
Australia — No Safe Harbour
Australia’s Cybercrime Act 2001 and the Criminal Code Act 1995 criminalise unauthorised access and modification of data. There is no explicit exemption for security research. IT security professionals “need to be aware of the abovementioned provisions so as not to get caught by a technical breach” — because the mere possession of security tools can trigger the statute.
Australia has no formal coordinated vulnerability disclosure framework with legal protection.
Sources:
- Pavuk Legal — Cybercrime Law in Australia
- Good Faith Cybersecurity Researchers Coalition — Laws Around the World
8. Reform Efforts: A Catalogue of Failed Attempts
Aaron’s Law (2013, 2015)
Introduced by Reps. Zoe Lofgren and Jim Sensenbrenner, with Senators Ron Wyden and Rand Paul, Aaron’s Law proposed:
- Terms of Service are not crimes. Access “without authorization” would require circumventing a technological or physical barrier (passwords, encryption, locked doors) — not violating a website’s TOS.
- Anti-charge-stacking. Prosecutors could not inflate sentences by layering multiple CFAA counts for the same underlying act.
- Privacy protections. Masking your identity (IP address, MAC address, real name) would not itself constitute unauthorized access.
Both versions died in committee. Congress has never passed CFAA reform legislation.
Sources:
- Rep. Lofgren — Aaron’s Law Press Release
- EFF — Aaron’s Law Introduced
- Sen. Wyden — Wyden and Lofgren Introduce Aaron’s Law
EFF’s Ongoing Campaign
The Electronic Frontier Foundation has been the most persistent advocate for CFAA reform, maintaining a dedicated campaign page and intervening in major CFAA cases including Swartz, Auernheimer, Keys, Drew, and Van Buren. Their position: the CFAA needs both legislative reform and judicial narrowing, because prosecutorial policies can be revoked at any time.
Sources:
The Rapid7 Proposal (2021)
Rapid7 published a detailed proposed statutory amendment to the CFAA that would create explicit protection for security researchers. The proposal would add a new subsection establishing that good-faith security research does not constitute a violation, provided the researcher acts to promote safety and does not cause harm.
Sources:
Harvard Cyberlaw Clinic — “Coming In From the Cold”
The Harvard Cyberlaw Clinic published a comprehensive proposal for a “safe harbour” from both the CFAA and the DMCA for security researchers, arguing that the two statutes create interlocking chilling effects. Without reform to both, researchers face legal risk from multiple directions simultaneously.
Sources:
- Harvard Cyberlaw Clinic — Coming In From the Cold: A Safe Harbor from the CFAA and the DMCA
- Harvard Cyberlaw Clinic — A Researcher’s Guide to Some Legal Risks of Security Research (PDF)
Academic Scholarship
Key legal scholars:
- Orin Kerr (UC Berkeley): Former federal prosecutor, filed the pro bono brief in Auernheimer’s appeal, argued for the narrow “code-based” interpretation that the Supreme Court adopted in Van Buren. Has been pushing for narrower CFAA readings for over 20 years.
- Tim Wu (Columbia): Called the CFAA “the worst law in technology.”
- Mitchell Hamline School of Law published “Patching the CFAA so Researchers No Longer Pay” — a law review article documenting how the Van Buren decision, while helpful, left the majority of security research in legal limbo because most independent research involves accessing systems “without authorization” rather than “exceeding” it.
Sources:
- Orin Kerr — Focusing the CFAA in Van Buren (SSRN)
- Kerr — Norms of Computer Trespass (Columbia Law Review)
- Mitchell Hamline — Patching the CFAA so Researchers No Longer Pay
9. The Compliance Industrial Complex: Who Actually Gets Paid
While the federal government prosecutes people who find real vulnerabilities, the cybersecurity industry has built a $272 billion global market (2025, projected to reach $663 billion by 2033) overwhelmingly oriented around compliance paperwork rather than actual security testing.
Key statistics:
- 71% of enterprise organisations spend over $100,000 per year on compliance audits alone
- 69% of organisations say regulatory compliance — not actual security improvement — is their primary security spending driver
- 70% of service providers must comply with six or more distinct frameworks
- McKinsey estimates the total addressable cybersecurity market at $1.5 to $2 trillion annually
The business model is clear: companies pay consultancies to produce reports certifying compliance with NIST, ISO 27001, SOC 2, PCI-DSS, HIPAA, and dozens of other frameworks. These reports are largely self-assessments or controlled-scope audits. They test whether your documentation says the right things, not whether your systems can withstand an actual attack.
Meanwhile, the people who actually test systems — by accessing them and finding out what breaks — operate under perpetual legal jeopardy.
Sources:
- Grand View Research — Cyber Security Market Size & Share
- McKinsey — New Survey Reveals $2 Trillion Market Opportunity
- Bright Defense — Cybersecurity Compliance Statistics
10. The Pattern, Made Explicit
Every case in this document follows the same arc:
- A researcher finds a real vulnerability through actual testing
- The vendor/owner/government agency is embarrassed
- Instead of fixing the vulnerability, they attack the researcher
- The CFAA (or international equivalent) provides the legal weapon
- The researcher is prosecuted, threatened, raided, fined, or silenced
- The underlying vulnerability may or may not get fixed
- Nobody prosecutes the vendor for the insecure system
Meanwhile:
- Compliance consultancies collect their fees regardless of whether the organisation is actually secure
- Vendors ship the same vulnerable software with updated compliance certifications
- The researchers who could find the next vulnerability decide it’s not worth the legal risk
- Over half of security researchers have abandoned research because of CFAA liability
The CFAA doesn’t protect computer security. It protects the feelings of people who ship insecure systems. And the compliance industry exists to provide cover documentation for the institutions that refuse to let anyone test whether those systems actually work.
Source URLs
For ongoing tracking:
- NACDL — CFAA Cases Database
- disclose.io — Research Threats
- GitHub — disclose/research-threats
- EFF — CFAA Reform Campaign
- Good Faith Cybersecurity Researchers Coalition — Laws Around the World
- Lawfare — Advancing Secure by Design Through Security Research
- Stanford Cyber Policy Center — Shooting the Messenger
Prefer RSS? Subscribe here.