[01:05.250 --> 01:06.350] Good morning, again. [01:06.710 --> 01:08.470] Welcome to the 7 o'clock session. [01:09.570 --> 01:13.470] Just a reminder that if you have your phones, put them on vibrate. [01:14.830 --> 01:19.850] If you see the exit signs in case of an emergency, follow the exit signs. [01:19.850 --> 01:30.470] If you have some other type of emergency, follow someone or talk to someone who has a radio or who is wearing a blue volunteer shirt or a security on the back of their shirt. [01:32.170 --> 01:33.370] Keep yourself hydrated. [01:33.630 --> 01:34.790] There's water fountains around the corner. [01:35.490 --> 01:38.750] Right now, we're going to introduce the panel for the CFAA. [01:39.070 --> 01:42.350] The CFAA has come a long way, or has it. [01:42.570 --> 01:44.990] It'll be an hour and 50 minutes. [01:45.430 --> 01:52.830] Unfortunately, the session on batteries has been canceled due to some emergency. [01:53.190 --> 01:55.730] So this panel will be taking extended time. [01:56.470 --> 01:58.610] Right now, I'd like to introduce Alex Urbelis. [01:58.870 --> 02:00.210] He'll be moderating tonight's panel. [02:00.810 --> 02:03.590] It's entitled, The CFAA has come a long way, or has it? [02:04.330 --> 02:11.810] Alex is a cybersecurity attorney with the law firm of Cromwell and Morning, and previously served as a chief information security officer of the National Football League. [02:12.050 --> 02:18.850] This federal service includes positions with the Central Intelligence Agency, couldn't just say CIA, the U.S. [02:19.150 --> 02:21.590] Army JAG Corps, the U.S. [02:21.710 --> 02:23.070] Court of Appeals, and the Armed Forces. [02:23.070 --> 02:34.550] Alex is a member of the Technology Advisory Board for Human Rights, FIRST, and the UL Security Council, and the Uniform Law Commission Committee for the Study of Cybercrime. [02:35.030 --> 02:42.630] Alex's published works can be found in the Financial Times, CNN, the Philadelphia Inquirer, The Intercept, and of course, 2600 Magazine. [02:43.070 --> 02:43.250] Alex. [02:43.710 --> 02:45.370] Well, thank you very much, everybody. [02:47.370 --> 02:48.210] I appreciate it. [02:50.650 --> 02:51.970] Good evening, New York. [02:52.090 --> 02:52.730] How is everybody? [02:53.110 --> 02:53.830] Everyone good? [02:54.270 --> 02:55.430] Everyone excited about HOPE? [02:55.450 --> 02:56.430] It's the first night of HOPE. [02:56.610 --> 02:58.170] We're all here in person. [02:58.170 --> 02:59.290] This is really exciting. [02:59.450 --> 03:01.750] We've got a lot of people joining online as well. [03:02.370 --> 03:18.290] I'm really excited to introduce a really just talented, you know, multifaceted, and I just think absolutely fantastic panel that we're going to have here tonight, talking about cutting-edge issues with the Computer Fraud and Abuse Act. [03:18.430 --> 03:25.670] And just by show of applause, how many people here have heard of the CFAA or the Computer Fraud and Abuse Act? [03:27.750 --> 03:28.150] Okay. [03:28.530 --> 03:29.110] All right. [03:29.250 --> 03:29.390] Yeah. [03:29.530 --> 03:30.730] Or booze, I guess, right? [03:30.830 --> 03:33.610] But, you know, we're here to bridge the gap, so to speak. [03:35.350 --> 03:40.270] So, I want to first introduce, right to my left, Sagar Ravi. [03:40.490 --> 03:45.270] So, Sagar is the co-chief of the Complex Frauds and Cybercrime Unit at the U.S. [03:45.510 --> 03:50.490] Attorney's Office for the Southern District of New York, just across the river over there. [03:50.490 --> 04:05.790] And he has supervised and worked on matters involving computer intrusions, national security, cyber issues, dark web markets, cryptocurrency, money laundering, investigated, you know, lots of different types of frauds, and is just an all-around great guy and a fantastic attorney. [04:06.030 --> 04:07.150] We're lucky to have him. [04:07.330 --> 04:10.430] To his left is Joel DiCapua. [04:10.930 --> 04:15.070] Joel is a supervisory special agent in the FBI's cyber division. [04:15.610 --> 04:21.910] His day job consists of chasing a wide assortment of ransomware affiliates, money launderers, and online scammers. [04:22.530 --> 04:32.990] And Joel enjoys spending his free time tinkering, like most of us, researching, sharing knowledge about network security, and, according to him, writing terrible code. [04:33.330 --> 04:35.310] So, you know, not my own characterization. [04:35.750 --> 04:39.030] And via Zoom, I hope that we can see Jay at some point. [04:39.030 --> 04:40.250] There he is. [04:40.330 --> 04:40.610] All right. [04:40.850 --> 04:42.530] We see your handsome face there, Jay. [04:43.170 --> 04:44.930] So, we also have joining via Zoom today. [04:45.090 --> 04:48.390] Unfortunately, we had some mechanical issues on the way here. [04:48.650 --> 04:50.430] But Jay, we have Jay Kramer. [04:50.750 --> 04:56.250] And Jay is the managing director of the National Cyber Forensics Training Association in New York. [04:56.730 --> 05:00.450] Jay is also a former supervisory special agent with the FBI. [05:01.290 --> 05:02.810] And nobody's perfect. [05:03.110 --> 05:04.570] Jay is also a lawyer. [05:04.570 --> 05:11.230] So, with that, I want to jump into the panel and also level set here for a second. [05:11.430 --> 05:16.210] Because the next panel had canceled, so we don't really have a time limit. [05:16.350 --> 05:23.510] We're going to go on for a little while longer, hopefully, and be able to take more questions and hopefully have answers to those questions. [05:24.050 --> 05:25.950] So, let's jump right into it. [05:26.370 --> 05:32.390] On the 19th of May this year, there was a major development with the Department of Justice. [05:32.390 --> 05:35.930] They had revised their guidelines for the Computer Fraud and Abuse Act. [05:36.090 --> 05:38.690] There were prosecutions with regard to the Computer Fraud and Abuse Act. [05:38.810 --> 05:45.710] And to my knowledge, I think this is the first time that they have revised those guidelines in about ten years. [05:45.710 --> 05:59.510] And what was a major change here was that now accessing a computer for the purpose of good faith security research is no longer to be considered a prosecutable offense. [05:59.510 --> 06:16.050] So, this is a major development and could have a huge impact on our community, ranging from how we collect cyber threat intelligence to how we go about defending our networks and how we research and even remediate security vulnerabilities. [06:16.390 --> 06:18.590] So, there's some really exciting stuff we're about to dig into. [06:18.650 --> 06:25.970] And we're going to have some really interesting hypothetical scenarios in which we'd all like you to participate towards the end of this. [06:25.970 --> 06:27.930] But let's start here at the top. [06:28.290 --> 06:45.110] Even though you do have familiarity with the CFAA, I want to pass it over to our colleague online here, Jay Kramer, and ask you, Jay, what can you tell us background-wise about the Computer Fraud and Abuse Act from your perspective as a lawyer and as a FBI agent? [06:46.050 --> 06:46.870] Yeah, sure. [06:47.190 --> 06:47.870] And thanks. [06:48.010 --> 06:48.810] It's great to be here. [06:49.110 --> 06:51.870] I apologize for not being there in person, but thrilled to be here remotely. [06:51.870 --> 06:51.910] Absolutely. [06:52.450 --> 07:05.270] So, Computer Fraud and Abuse Act, Title 18, USC 1030, has multiple parts, but really is the primary tool used to counter hacking activity. [07:06.090 --> 07:16.350] Primary tool used by the federal government, FBI, others, to enforce or to counter hacking activity. [07:16.350 --> 07:19.730] So, it has an interesting legislative history. [07:20.450 --> 07:30.730] For those of you who have seen the film War Games, going back to 1983, I'd ask for a show of hands, but I don't think I'd be able to see that. [07:31.870 --> 07:41.610] Matthew Broderick, high school student, stumbles upon an enclave, the Wargaming DOD enclave, and all kinds of chaos ensues. [07:41.610 --> 08:00.370] Well, the then president at the time, Ronald Reagan, saw the film and was so concerned with this kind of activity that he implored Congress to act and to pass a bill to criminalize this activity, a bill that he would later sign in 1984. [08:00.370 --> 08:06.090] So, reality in some cases is a bit stranger than fiction. [08:06.370 --> 08:11.770] And that was the impetus for the passage of CFAA in 1984. [08:12.810 --> 08:23.150] And significantly, and we'll talk about this throughout our session here, there were or there are a couple of terms that are not defined in the statute. [08:23.150 --> 08:31.890] And that's two significant terms, unauthorized access and exceeds authorized access. [08:32.530 --> 08:36.670] So, neither of those, which are key components of the statute, are defined. [08:36.830 --> 08:49.530] And that's led to really almost 40 years or so of split authority and confusion that has been addressed recently through this DOJ guidance and some Supreme Court action. [08:50.590 --> 08:50.990] Fantastic. [08:51.370 --> 08:51.850] Thanks, Jay. [08:52.070 --> 08:55.890] Joel, what about you as an active FBI agent, your experience with the CFAA? [08:56.090 --> 08:58.130] Anything to add to what Jay had mentioned? [08:58.490 --> 08:58.710] So, yeah. [08:58.910 --> 09:01.430] So first, I just want to say thank you for having me. [09:02.130 --> 09:05.870] I am spot the Fed on easy mode with my suit jacket. [09:06.010 --> 09:09.430] But surprisingly, no one came up to me and said, hey, you know, you're the Fed, I win the prize. [09:09.990 --> 09:14.550] So maybe after the talk, now that I've outed myself, I'm expecting people to approach me. [09:15.630 --> 09:21.290] So CFAA, so a little bit of inside baseball with the FBI, we don't call it the CFAA, we call it 1030. [09:21.610 --> 09:32.550] 1030 is the actual part in the U.S. code that if you want to find the language that was enshrined with the CFAA, it is Section 18 USC 1030. [09:34.590 --> 09:36.270] I work cybercrime. [09:36.810 --> 09:45.730] And 1030 is one of the basic tools that we use that gives us authority from Congress to investigate network intrusions. [09:46.450 --> 09:56.450] And as a investigator, the types of things that I'm concerned about with, you know, interpreting 1030 is there's certain elements you need to hit. [09:56.790 --> 10:08.610] So, for instance, protected computer, if a victim or a complainant comes to us and says, hey, we've been affected by a network intrusion, I've got to think to myself, is this a protected computer under the statute? [10:08.970 --> 10:17.550] And then if that element is met, then I move on and I have to look, well, was, did someone exceed the authorization they had? [10:17.850 --> 10:21.910] If the target had authorization to be on the computer, did they actually exceed it? [10:22.110 --> 10:29.510] And then the third major prong is, did someone not have authorization to access the computer? [10:29.510 --> 10:32.710] And that's basically, like, how detailed we get. [10:32.810 --> 10:49.450] I'm not an attorney, and so my job is just to bring the facts of an incident, and then let the attorneys and the prosecutors do their job to interpret what prongs of 1030 are actually met for charges. [10:49.610 --> 10:55.190] So, also, I'm the only non-attorney that's on stage here, so I'm kind of, I see myself as the foil. [10:56.770 --> 10:58.590] So, I have a copy of 18 U.S. [10:58.650 --> 11:10.270] Code 1030 here, and I'm reading it, and I'm realizing that when it was originally written, it was probably written by people that had never used a computer. [11:11.670 --> 11:25.350] And so, you get some really interesting terms and definitions, and you go through it, and there's, it's pretty long, and you see that there's indentations, and you go through it, and it says, if this, you know, then, you know, skip to here, and there's lots of, [11:25.350 --> 11:29.110] like, ands, and ors, like, if this, and this, or that. [11:29.470 --> 11:32.210] And then, for definitions, you have to go to a separate part of the U.S. [11:32.270 --> 11:34.190] Code to find definitions of stuff. [11:34.530 --> 11:45.990] And it's confusing reading it, but going through it as a layperson, I had a very similar feeling to when I'm reviewing, like, code, like Python or C. [11:45.990 --> 11:59.190] And I came to realize that you can read 1030, it has if statements, it has lots of if-else, else-if, and then it has the variables in the actual definitions. [12:00.710 --> 12:04.330] So, just in general, when I think about 1030, it's confusing. [12:04.550 --> 12:09.690] It's kind of like, I would refer to it as spaghetti code that was written in the 1980s. [12:10.590 --> 12:28.390] I wish it was a little bit more clear for the purposes of just allowing people to understand what is across the line, and easier for someone like me that has to actually gather the facts and present them to prosecutors to understand better what actually meets the illegal conduct. [12:29.570 --> 12:34.490] So, my day-to-day focus, though, a lot of the things that I investigate, it's ransomware. [12:34.650 --> 12:41.970] It's things that are very far across the line with loss amounts and the tens of thousands of dollars, if not the millions of dollars. [12:42.130 --> 12:45.530] And so, we don't really have very much gray area with 1030. [12:46.190 --> 12:53.250] There isn't a whole lot of debates about whether or not someone interfering with an election system is actually in violation of 1030. [12:53.250 --> 13:01.530] So, like I said, my job is just to gather the facts, and 1030 is just a tool given to us by Congress to help us investigate network intrusions. [13:02.710 --> 13:09.830] I love the analog that you made between coding and the conditional statements that were found in 1030 and CFAA. [13:10.010 --> 13:10.470] It's fantastic. [13:11.030 --> 13:16.170] Sagar, I want to pass it over to you to talk about any kind of lingering issues with the CFAA that you want to bring up. [13:16.850 --> 13:21.310] Thank you, and thank you to HOPE, to having me here. [13:21.570 --> 13:23.910] I really appreciate the opportunity to speak with you all. [13:24.010 --> 13:36.330] I do have to make a little caveat at the beginning, which is something that is very lawyerly, but although I am an employee of the Department of Justice, my statements here today are my personal opinions and do not represent those in the department. [13:36.570 --> 13:38.830] So, with that, I can talk freely. [13:39.430 --> 13:39.690] Perfect. [13:39.690 --> 13:52.590] So, as a prosecutor, thankfully, Joel has my help when he's interpreting the Section 1030 here, but he's right. [13:52.790 --> 13:54.510] You know, it is a very complicated statute. [13:54.690 --> 14:07.570] Criminal law, you know, generally can be very complicated, but I think on the spectrum of complicated statutes, 1030 certainly is on the kind of more complicated area, and it has a complicated history, right? [14:07.570 --> 14:08.510] Think about this. [14:08.610 --> 14:11.010] It was written in 1984, right? [14:11.690 --> 14:15.270] There hasn't been any technological advances in computing since then, right? [14:15.750 --> 14:30.250] So, it is a statute that we are applying, sitting here, you know, more than 30, 40 years later, and to apply to, you know, hackers today who are causing, you know, real harm. [14:30.250 --> 14:36.230] And my job is to, you know, is generally applying the statute. [14:36.550 --> 14:53.970] And I think, you know, Joel is right in that every day in terms of the conduct that we're investigating, in terms of the calls that I get that we need to investigate with the FBI, it's not really, it's not such a fine line between kind of what's clearly legal and what's not. [14:53.970 --> 14:56.970] The statute is clear on a few things. [14:57.150 --> 14:59.670] It defines something as what's a protected computer. [14:59.850 --> 15:06.190] And all that means is it's a computer that is connected to interstate traffic, which is almost every computer these days, right? [15:07.310 --> 15:15.530] Yeah, but the exceeding authorized access and what is acting without authorization was very complicated. [15:16.810 --> 15:28.390] And, you know, just last year, the Supreme Court actually ruled in a case kind of explaining what is the exceeding authorized access language, explaining what it was. [15:28.470 --> 15:29.350] And I'll just go on that briefly. [15:29.370 --> 15:30.130] I think it might be helpful. [15:30.250 --> 15:30.630] I think so. [15:30.650 --> 15:43.390] You know, that was a case where, you know, prosecutors charged effectively a law enforcement officer who has access to look up kind of criminal history records of individuals. [15:44.150 --> 15:47.110] That's part of their general access on their computer. [15:47.590 --> 15:57.490] However, they were kind of paid on the side to look up the same records as a personal matter for someone that they were kind of doing a favor with. [15:58.250 --> 16:03.910] And so there are the prosecutors kind of working within the law of their circuit, which is the 11th Circuit. [16:03.910 --> 16:07.290] There's more than a dozen circuits here in the United States. [16:07.490 --> 16:10.970] So each one has its own kind of law that is binding on them. [16:11.130 --> 16:27.470] And working within that case law, they decided that because even though he had access to do this, because he was doing it for a personal matter and not for a law enforcement matter, that he was exceeding his authorized access and therefore violated the statute. [16:27.790 --> 16:33.270] And so prosecutors tried to bring that case, and I believe he was convicted at trial. [16:33.270 --> 16:38.030] So a jury of 12 found him guilty of that statute, of this statute. [16:38.990 --> 16:43.530] And it was appealed to the circuit court, and the circuit court affirmed based on that. [16:43.630 --> 17:01.830] But then the Supreme Court came in last year and reversed, basically explaining that if you already have access to something, and even if you're not supposed to look at it, for example, if you're at work and you're using computer for work, but you decide to check your personal bank account, [17:02.130 --> 17:08.870] arguably that is also exceeding authorized access, because you're only supposed to be using your computer for work based on your employment contract. [17:08.870 --> 17:21.950] But I think ultimately the Supreme Court decided that that conduct can't constitute a crime under Section 1030, because you already had access to it. [17:22.030 --> 17:35.830] I think what the Supreme Court envisions would be a violation of the exceeding authorized access, is if you have access to a computer, but you're blocked off, for example, from a specific drive or a folder through technological means. [17:35.830 --> 17:52.470] And if you decide to somehow get around that using someone else's passwords, using, you know, whatever tools you might have available to you through technology, if you're able to get past that and get into that folder or that drive, that would be exceeding unauthorized access. [17:52.650 --> 17:53.670] So, authorized access. [17:53.850 --> 17:56.090] So, it is a very complicated area. [17:56.250 --> 17:57.930] The Supreme Court came in and explained it. [17:57.990 --> 18:01.870] And we'll talk about that and the regulations and the policies that come out. [18:01.990 --> 18:03.030] But that's where it stands. [18:03.170 --> 18:03.630] Yeah, absolutely. [18:03.630 --> 18:10.970] And I think also in the Supreme Court, you know, the analogies that they made for things that would not violate the CFAA in this case were really interesting. [18:11.170 --> 18:27.050] I think, didn't they also mention, like, lying on a dating profile, you know, would not violate the CFAA because there were circuit splits about this, if I recall correctly, that established that you could violate 1030 if you violated terms of service under certain circumstances. [18:27.050 --> 18:27.650] Exactly. [18:27.950 --> 18:30.730] So, on your Match.com profile, which I'm sure many of you might have. [18:32.430 --> 18:44.370] You know, if you lie about yourself, technically under the contract you signed with Match, which is very fine print, and you kind of click in order to actually get access to it. [18:44.430 --> 18:45.910] No one actually reads that, we all know. [18:46.550 --> 18:56.210] But technically, according to that, if you lie on your profile, you are automatically violating their user terms, and therefore you no longer should have access to the website. [18:56.890 --> 19:08.490] So, there was a kind of aggressive reading of the statute where, if you lie on your profile, you therefore no longer have access to the site, but if you continue on it, you're exceeding authorized access. [19:08.690 --> 19:13.150] And that was kind of something that the Supreme Court had kind of shut down with its opinion. [19:13.390 --> 19:13.610] Yeah. [19:13.890 --> 19:18.170] I mean, it was a fascinating case, but still so many things, I think, remain unanswered about it. [19:18.170 --> 19:29.050] Now, with this background about the CFAA out of the way, I want to keep with you for a second, Sagar, and ask you to talk about what are the role of guidelines in the Department of Justice? [19:29.350 --> 19:34.610] And Jay, feel free to chime in here as well, because you might have some familiarity with this. [19:34.810 --> 19:36.690] So, can you tell us about the guidelines? [19:36.690 --> 19:37.790] How do they bind you? [19:37.890 --> 19:38.630] Where do they come from? [19:38.630 --> 19:39.430] Yeah. [19:39.610 --> 19:50.990] So, the guidelines come from the Office of the Deputy Attorney General, which is effectively the person sitting under Merrick Garland, but ultimately comes from the Department of Justice, that very head. [19:52.830 --> 19:56.750] And all the guidelines, it's very long, if you want to search. [19:56.870 --> 19:59.050] You can search for the, basically, the Justice Manual. [19:59.050 --> 20:18.610] If you Google search for that, you'll find all of the guidelines that are issued and that provide what are, you know, what they are, which are policies to guide prosecutors and the government as to how we should be exercising our discretion when it comes to prosecuting these types of crimes. [20:18.610 --> 20:22.070] So, you know, they are, what they are, their policy. [20:22.190 --> 20:24.490] We do look at it very carefully. [20:24.690 --> 20:25.770] They're very important to us. [20:25.990 --> 20:28.730] And they provide guidance in exercising our discretion. [20:29.890 --> 20:32.890] You know, and we're, we are required to follow them. [20:33.590 --> 20:39.930] That said, you know, just to be very clear, there's language at the end of every single guideline that explains that these are internal procedures. [20:40.290 --> 20:42.730] They're intended solely for the guidance of our attorneys. [20:43.110 --> 20:51.990] And they're not intended to and may not be relied on to create any sort of right, benefits, substantive, or procedural that's enforceable at law in any litigation. [20:52.670 --> 20:53.470] But it's important... [20:53.470 --> 20:55.670] So let me, let me interrupt you there for one second, Sagar, too. [20:55.810 --> 21:02.130] So, so with that in mind, the guidelines, they're not necessarily binding on any of the U.S. [21:02.230 --> 21:03.950] attorneys, any of the prosecutors, federal prosecutors. [21:04.210 --> 21:09.190] And I guess it's an important distinction you made there, too, is that they don't actually change the law, right? [21:09.190 --> 21:12.630] So the, the Computer Fraud and Abuse Act is still the Computer Fraud and Abuse Act. [21:12.990 --> 21:14.310] 1030 is still 1030. [21:14.550 --> 21:19.010] It's just how you interpret or the facts that would give rise to a crime? [21:19.390 --> 21:19.790] Correct. [21:20.030 --> 21:23.770] And, you know, we are the, you know, we're, Department of Justice is part of the executive branch. [21:23.950 --> 21:27.070] Like, you know, we're under the President of the United States, technically. [21:27.510 --> 21:31.170] But the courts are not bound by these guidelines in any way. [21:32.610 --> 21:34.790] And neither is Congress in any way. [21:35.010 --> 21:39.130] This is simply something in the Department of Justice that we have to follow. [21:39.470 --> 21:39.790] Great. [21:40.110 --> 21:40.670] So, Alex. [21:41.450 --> 21:41.570] Oh. [21:41.930 --> 21:42.690] Go ahead, Jay. [21:42.810 --> 21:44.290] I was just about to bounce over to you, too. [21:45.050 --> 21:45.430] Yeah, yeah. [21:45.830 --> 21:46.270] I think it's pretty... [21:46.270 --> 21:47.030] Oh, and one second. [21:47.110 --> 21:48.050] If we could just interrupt you. [21:48.390 --> 21:54.410] We, is it possible for you to switch the HDMI input over to, to the laptop here for a second? [21:54.550 --> 21:55.710] Because we actually have the guideline. [21:55.890 --> 21:56.350] There we go. [21:56.490 --> 21:57.010] Split screen. [21:57.450 --> 21:57.690] All right. [21:57.810 --> 21:58.510] Fantastic, Jay. [21:58.510 --> 21:59.770] Right. [22:00.090 --> 22:12.150] What I was going to relate, because we're here in New York, is an example that really puts this struggle to interpret those guidelines and to use 1030 as a tool in context. [22:12.510 --> 22:16.170] So, many of you may remember the cannibal cop case. [22:16.330 --> 22:16.650] Yes. [22:17.030 --> 22:26.150] In New York, Gil Valley, Gilberto Valley, NYPD officer, I think he was a sergeant or detective, if I recall. [22:26.890 --> 22:36.750] And in his personal life, he was engaged with a couple of dozen others on a dark net forum that was focused on cannibalism. [22:37.050 --> 22:42.810] Basically, they would talk about it, how they would, how they would like to find people to eat. [22:43.590 --> 22:48.310] And it's really strange to even talk about something like this. [22:48.470 --> 23:07.730] But it turns out that after years of engagement in this forum, his wife found a trove of documents and communications that indicated that, by the way, she was on that list to be captured in Eden at some point, and she was so concerned about it that she reported it to the FBI. [23:08.250 --> 23:41.690] And after a long investigation, it turns out that Gil Valley, the NYPD police officer, had used some of the tools given to him, access to which he was entitled through NYPD, to identify and run license plates, queries, motor vehicle records, for an individual that he and his co-conspirators had planned to kidnap and rape and torture and kill and ultimately eat. [23:42.790 --> 23:55.610] So, a really bizarre case, but the relationship to 1030 is that, that, by the way, that woman ended up being an undercover FBI agent, so that didn't work out so well for Gil. [23:55.850 --> 24:12.570] But he was arrested and charged with conspiracy to commit kidnapping and the violation of Title 18, Section 1030, for his misuse of the computer systems and running those queries. [24:13.070 --> 24:17.150] And, you know, on the one hand, and this, I think, is the teaching moment. [24:17.270 --> 24:25.570] On the one hand, you would say, wow, well, he was entrusted as a New York City police officer to use those systems to further his job and fight crime. [24:25.670 --> 24:36.950] I can't think of a better case where he's exceeded his authorized access to use that, those tools to find someone to kidnap and torture and eat. [24:38.170 --> 24:50.150] But after being found guilty by a jury after deliberation, that jury, that verdict was set aside for a number of grounds. [24:50.310 --> 25:00.330] But regarding 1030, the Second Circuit, and Sagar, you mentioned this, that the circuits were split, and that's the struggle that we've had with 1030. [25:00.330 --> 25:04.450] The Second Circuit felt that, no, basically, in essence, shame on you. [25:04.630 --> 25:08.030] If you authorize someone, you give someone access to a computer system. [25:08.550 --> 25:13.250] If they use it for a purpose that you didn't intend, well, that's on you. [25:13.490 --> 25:16.410] You know, be more careful with who you entrust with access. [25:16.730 --> 25:17.790] That's not the intent. [25:17.950 --> 25:20.870] That wasn't Congress's intent in passing 1030. [25:21.110 --> 25:28.270] It was more to prevent people from accessing systems that they had absolutely no access to, not for those that were going to misuse the access. [25:28.270 --> 25:36.770] And interestingly, in the case that we're talking about here, the Supreme Court case just decided last year, the facts are very similar, right? [25:36.990 --> 25:43.870] Another law enforcement officer using a system he was entrusted to for a purpose that wasn't intended. [25:43.870 --> 25:56.370] And this time the Supreme Court said in the decision that basically what the intent of that statute was means that you have to access something that was entirely off limits. [25:56.610 --> 26:00.090] Off limits was, I think, the term used in the majority decision. [26:00.310 --> 26:05.370] That it's not that you were entrusted with access and you misused that access. [26:05.370 --> 26:07.690] It's something that you were never intended to have. [26:08.730 --> 26:10.210] You know, it's fascinating, Jay. [26:10.350 --> 26:17.970] There's so many precedential cases involved law enforcement officers tangled up with 1030 or the CFAA. [26:18.430 --> 26:23.530] I want to shift here and dive right into the actual guidelines themselves. [26:23.770 --> 26:27.810] Now, let's read them for the benefit of those all the way in the back there. [26:27.810 --> 26:35.870] So the new guidelines, and this is a small excerpt, but I think a relevant excerpt that we can focus on here in terms of our analysis. [26:36.050 --> 26:40.170] So the new DOJ guidelines that came out on the 19th of May say this. [26:40.230 --> 26:50.390] They say that the government should decline prosecution if available evidence shows that the defendant's conduct consisted of and the defendant intended good faith security research. [26:50.550 --> 27:05.210] Now, farther down the guidelines, it also defines good faith security research as accessing a computer solely for purposes of good faith testing, investigation, and or correction of a security flaw or vulnerability. [27:05.610 --> 27:10.110] Now, remember these words because they're going to be very relevant to our hypotheticals that come up a little bit later. [27:10.290 --> 27:13.750] So, and or correction of a security flaw or vulnerability. [27:13.990 --> 27:15.110] That's an important one. [27:15.290 --> 27:21.730] Where such activity is carried out in a manner designed to avoid any harm to individuals or the public. [27:21.730 --> 27:33.410] And where the information derived from the activity is used primarily to promote the security or safety of the class of devices, machines, or online services to which the accessed computer belongs. [27:33.710 --> 27:38.130] Or those who use such devices, machines, or online services. [27:38.590 --> 27:49.710] So, Jay, can you keep going a little bit here and talk to us a bit about these guidelines, how they would relate to the private sector, and then I want to pass it back to Joel and Saga. [27:50.470 --> 27:51.110] Yeah. [27:51.110 --> 27:51.130] Yeah. [27:51.490 --> 28:02.570] So, you know, as the threat landscape has grown here, and the threats are coming from all sides, they're financially motivated threats, they're nation state threats. [28:02.770 --> 28:07.190] There's a whole community that's developed around the response to these threats. [28:07.190 --> 28:13.970] So, we have security researchers, we have digital forensics folks, incident responders. [28:14.190 --> 28:20.230] I'm sure many in the audience touch, operate within those circles. [28:20.230 --> 28:32.250] And the ability to lean forward, let's put it that way, to lean forward to investigate and engage and understand the adversary is impacted by 1030. [28:32.250 --> 28:56.210] Because there's been that lingering specter or that concern that if I'm engaged and investigating a bad actor and on a network or a system, the potential for me to run afoul of Section 1030, and you never know who is on the line, so to speak, there could be undercover law enforcement officers, [28:56.510 --> 29:05.130] there could be members of the intelligence community, or other security researchers that report on me as though I'm an active participant and a bad actor. [29:05.130 --> 29:22.470] So, I think that's the concern, that for years folks that are operating and trying to be aggressive and understand the threat landscape are concerned that their activity could be construed as exceeding authorized access or being unauthorized in some way. [29:22.830 --> 29:25.150] And Joel, I want to pass it back to you now. [29:25.250 --> 29:31.330] What about these guidelines has changed the way you do your business or your viewpoints? [29:32.270 --> 29:34.930] So, not much has changed, to be perfectly honest with you. [29:35.670 --> 29:42.910] First, I just want to say, if you have an opportunity and if you're interested, I would seriously check out the DOJ prosecution manual. [29:43.130 --> 29:54.890] It goes into great detail about the things that prosecutors need to think about when they're negotiating a plea agreement or when they're determining whether or not someone deserves to be charged with a felony or a misdemeanor. [29:54.890 --> 29:58.830] And it's written in simple language, unlike the statutes themselves. [29:59.130 --> 30:00.570] And it's really descriptive. [30:00.810 --> 30:12.230] And it's a level of transparency that they offer that, in practice, when I'm sitting with prosecutors and they're explaining to me why they're going to allow someone to plea to a misdemeanor or something. [30:12.410 --> 30:14.390] But I see them actually go through the steps. [30:14.390 --> 30:17.390] So, it's not just something in writing that is performative. [30:18.030 --> 30:19.630] It's something that they actually adhere to. [30:19.890 --> 30:32.310] And it makes it really clear when you wonder, like, why did the Department of Justice choose to prosecute a certain crime and not some other crime? [30:32.950 --> 30:34.540] But in terms of the guidance itself... [30:34.950 --> 30:39.550] So, after a careful reading of the recent guidance, I think it does two things. [30:39.870 --> 30:44.490] First, it codifies the Van Buren decision that Sagar talked about. [30:44.650 --> 30:57.330] And basically, it mirrors the language that Justice Coney Barrett, writing in the majority, talks about in the Supreme Court decision that effectively narrows the CFAA and clarifies some of the things. [30:57.330 --> 31:03.010] It turns 1030 into a trespassing statute. [31:03.010 --> 31:07.230] It's not just a break of policy statute. [31:07.470 --> 31:10.590] You actually need to trespass into somewhere that you don't belong. [31:10.750 --> 31:12.730] And so, I think it gives a lot of clarity. [31:14.850 --> 31:29.410] The other thing that it does is it gives comfort to security researchers who are acting in good faith, who are doing their job, and incident responders, who might be afraid of crossing some line and exposing themselves to criminal culpability. [31:31.970 --> 31:36.470] There's a lot of attorneys that usually get involved when there is a network security incident. [31:37.230 --> 31:47.070] And in my experience, incident responders, they're hard chargers, they're aggressive, they're trying to expel the attacker from their network. [31:48.030 --> 31:50.550] They're trying to get their data back, they're trying to mitigate. [31:52.750 --> 31:57.150] And a lot of times, they might come up with ideas that are excessively aggressive. [31:57.390 --> 32:05.850] And then they talk to the attorneys, and the attorneys will talk them down and explain to them why you need to be a little bit more circumspect before you hard charge. [32:05.850 --> 32:10.990] One example, some of the questions that get risen are pretty silly. [32:11.210 --> 32:27.710] Like, for instance, if an attacker creates a dummy account on a Linux machine that they use for persistence, is the owner of that computer allowed to go into that account and look at what's actually in there? [32:27.710 --> 32:29.370] Or are they breaking 1030? [32:29.910 --> 32:33.650] Now, for me, I'm like, well, that's like a silly question. [32:33.650 --> 32:37.550] If I go home right now and I see that someone has created an account on my computer that... [32:37.550 --> 32:38.510] Like, it's my computer. [32:38.670 --> 32:41.750] I'm going to investigate and I'm going to wipe that account. [32:41.990 --> 32:51.990] But those are the types of questions when corporate attorneys get involved and they start raising these types of issues where they're really worried about any liability that a company might face. [32:52.170 --> 33:09.350] So when I read the part about good faith security research and good faith investigation, I like to think it's the Department of Justice messaging to corporate attorneys and the folks who are involved in these types of matters and saying, hey, look, you're not going to be charged for this. [33:09.610 --> 33:14.830] You're not going to be charged with a felony for doing something in good faith. [33:14.830 --> 33:21.010] In fact, my understanding of criminal statutes is you actually have to have criminal intent in order to be charged with a crime. [33:21.250 --> 33:24.790] Doing something in good faith is usually the antithesis. [33:24.970 --> 33:34.330] Even if you meet all the other technical elements of the statute, if you're doing something in good faith, it's really hard to prove that that person actually committed a crime. [33:34.330 --> 33:39.050] So I think the guidance is helpful. [33:39.190 --> 33:40.530] I think it's helpful for the general public. [33:40.530 --> 33:45.770] But it doesn't really change anything that I do, just because we're not interested in... [33:45.770 --> 33:46.770] We're busy. [33:46.910 --> 33:47.830] We're very, very busy. [33:47.930 --> 33:52.410] We're turning down cases where there's real loss amounts and real victims. [33:52.610 --> 33:59.450] We're referring those cases to state and local law enforcement because we don't have the resources to address them. [33:59.450 --> 34:07.150] And we certainly don't have the resources, nor do we want to pursue anyone acting in good faith, to include investigators, security researchers, and the like. [34:08.190 --> 34:12.550] Now, it's interesting you say that, too, because there also seems to be a little bit of push and pull here. [34:13.670 --> 34:18.610] Because, you know, Sagar, you mentioned the Deputy Attorney General, Lisa Monaco. [34:18.890 --> 34:21.570] She's the one that promulgates these guidelines, right? [34:21.630 --> 34:22.510] So they filter down. [34:22.910 --> 34:43.050] Now, what she had said specifically about these guidelines are that they are intended to, quote, focus the Department's resources on cases where a defendant is either not authorized at all to access a computer or, despite knowing about a restriction, accessed part of a computer to which his authorized access did not extend. [34:43.050 --> 35:02.430] So why... So, Joel, if it was the case, then, that we're turning away cases where there isn't the mental element or there was... or, rather, there wasn't an absence of good faith, there's real cases that you're turning down, why, then, did these new guidelines have to come out? [35:02.490 --> 35:04.350] Why did the Attorney General have to do that? [35:04.390 --> 35:11.830] I guess maybe it's perhaps because there's differences between jurisdictions when it comes to the investigation of these types of crimes? [35:11.830 --> 35:12.830] So I'm not sure. [35:12.990 --> 35:16.410] I suspect... I suspect it was twofold. [35:16.530 --> 35:20.810] It was to codify Van Buren and just formalize that, that, hey, this is the new policy now. [35:21.270 --> 35:26.810] It's been the law of the land for over a year, but now we just want to make it clear that it's also DOJ policy. [35:27.350 --> 35:37.670] And I think the other reason is just to message from the top that we're not interested in going after good faith researchers. [35:37.670 --> 35:39.050] Yeah, gotcha. [35:39.410 --> 35:45.350] That isn't... as far as I know, there's been no targeting of good faith security researchers. [35:45.610 --> 35:51.330] Now, there are bad faith security researchers for sure, but there really hasn't been any targeting. [35:51.650 --> 36:01.230] But they just wanted to be very explicit when they message what prosecutors are supposed to calculate when they're thinking about whether or not there's criminal liability. [36:01.230 --> 36:01.830] Yep. [36:02.010 --> 36:04.350] And Sagar, I want to pass it to you for comment on that, too. [36:04.690 --> 36:04.890] Yeah. [36:05.070 --> 36:16.410] So I think that, look, after the Supreme Court decision came out on the exceeding authorized access issue, I think there was an opportunity to take a hard look at these guidelines and revise them. [36:17.350 --> 36:17.970] Excuse me. [36:18.250 --> 36:26.570] And I think, you know, really the good faith researcher language that was just stated is very different than the exceeding authorized... [36:26.570 --> 36:29.170] Those are two different, entirely different issues. [36:29.330 --> 36:34.050] And so I think the fact that they were revising the guidelines anyway, they felt... [36:34.050 --> 36:44.050] You know, again, I cannot speak to why they included it at that time, but I think it was a recognition that good faith security research is really helpful to the community. [36:44.750 --> 36:55.990] And in fact, you know, Lisa Monaco, the Deputy Attorney General said, quote, Computer security research is a key driver of improved cybersecurity. [36:56.530 --> 37:01.850] The department has never been interested in prosecuting good faith computer security research as a crime. [37:02.070 --> 37:10.510] And today's announcement promotes cybersecurity by providing clarity for good faith security researchers who root out vulnerabilities for the common good, end quote. [37:10.510 --> 37:13.150] So and I think she's right. [37:13.370 --> 37:26.730] I don't think if you look at kind of history of all the crimes that have been prosecuted under 1030, I think there's a couple that where, you know, it's arguable that it was a good faith security researcher who was prosecuted. [37:26.910 --> 37:31.130] This is not an area where we are spending a lot of our time and resources at all. [37:31.430 --> 37:31.910] Right. [37:31.910 --> 37:39.590] Again, I think, as Joel mentioned, we have more than enough nation state actors, extremely malicious actors to deal with. [37:39.810 --> 37:43.470] We don't have the resources to go after good faith security researchers. [37:43.650 --> 37:44.730] It's not a priority. [37:44.970 --> 37:47.470] And and this kind of is a recognition of it. [37:47.830 --> 37:58.350] And just to add to that, you know, I don't think that these guidelines change anything from my perspective, because, again, it is a defense under the law if you're acting in good faith. [37:58.890 --> 38:04.010] That's a standard jury strict instruction that is kind of given in every jury trial. [38:04.190 --> 38:09.930] And so this just is messaging to the public that this is something we value. [38:10.130 --> 38:19.950] And in fact, we oftentimes look at, you know, threat security reports and things like that, when we're trying to also do our investigations of various APTs and things like that. [38:20.270 --> 38:28.030] So a lot of the information that's out, you know, public publicly sourceable information is very helpful in our investigations. [38:28.030 --> 38:30.950] And I think it shows we value it. [38:31.050 --> 38:32.770] But ultimately, it doesn't change anything. [38:32.910 --> 38:38.690] What matters is, you know, what someone's intent is, which is kind of what the guidelines go to. [38:38.790 --> 38:45.050] And I think it's also helpful to mention, you know, the Section 1030 prosecutes kind of generally real harm. [38:45.250 --> 38:45.350] Right. [38:45.350 --> 38:48.570] It's not just accessing a computer without authorization. [38:48.730 --> 38:53.470] If you go through there, you have to obtain information. [38:53.810 --> 38:55.710] You have to cause damage. [38:56.030 --> 39:02.530] You have to have the intent to defraud and obtaining something of value of more than $5,000. [39:03.070 --> 39:09.750] You have to recklessly cause damage, causing loss, trafficking in passwords, things like that. [39:09.910 --> 39:10.650] You know, these are real. [39:10.870 --> 39:11.090] Yeah. [39:11.270 --> 39:13.450] It's not just accessing computer. [39:13.450 --> 39:14.670] It's much more than that. [39:14.670 --> 39:16.910] So there's actual harm that needs to be done. [39:17.030 --> 39:23.970] And your position, and it seems like Joel's too, is that because of this mental element, what we would call in a law the mens rea, right? [39:24.110 --> 39:28.130] You know, the mental thing that has to be present. [39:28.510 --> 39:31.010] So these guidelines don't really change all that much. [39:31.110 --> 39:31.970] Would you agree, Jay? [39:32.550 --> 39:33.850] Yeah, yeah, I do. [39:33.870 --> 39:38.390] And let me highlight what I think is the most important part of this policy change. [39:38.390 --> 39:42.730] Because Sagar, you and Joel have both said in different ways. [39:42.970 --> 39:47.530] Joel, I think you've said rightly that this doesn't change the way you go about your business. [39:47.710 --> 39:50.230] You've got a lot more work than you can ever do. [39:50.250 --> 39:55.470] So you have to decide what's the most impactful and where the best use of your time is. [39:55.470 --> 39:56.330] Same for the U.S. [39:56.630 --> 39:57.090] Attorney's Office. [39:57.610 --> 40:00.270] And I'll say, I've spoken to a number of people about this. [40:00.490 --> 40:10.530] A lot of former prosecutors who've said, well, you know, yes, it's good that DOJ has come out with this announcement, this good faith security research exemption, let's call it. [40:11.250 --> 40:15.710] But, you know, in reality, this is the way we've operated for many years. [40:15.890 --> 40:17.170] So I don't see it as a big deal. [40:18.830 --> 40:34.990] The big deal part of it, I think, and Joel, I think you said this well, is that it, and you too, Sagar, that it's a signal to not the security researcher that's just trying to help his or her community, or those even maybe that are going after bug bounties, [40:35.150 --> 41:04.950] but the in-house cyber threat intelligence teams that are working at the large financial institutions or the large pharmas or the multinational retailers, that are trying to stay ahead of the threats and are trying to get authorization internally from their legal departments to engage with bad actors on forums or to access parts of networks that they, [41:05.370 --> 41:17.810] because of company policy, may require some pre-authorization to get the green light to conduct those intelligence-gathering operations. [41:18.150 --> 41:34.870] And for them, I think the very conservative legal community in those large organizations have said for many years, well, we don't like the overall risk that this brings by you engaging in this kind of activity because, well, for one, it could violate Title 18, [41:35.190 --> 41:39.050] Section 1030, or it could draw fire from the adversary. [41:39.210 --> 41:40.270] So, you know, it's too much risk. [41:40.410 --> 41:44.350] We're not comfortable with that risk coming on to our large organizations. [41:44.430 --> 41:48.690] So we're going to deny this request, and that's caused great frustration. [41:48.690 --> 41:54.790] So when you guys talk about a signal, I think, excuse me, the U.S. [41:55.090 --> 42:01.070] Attorney's Office and DOJ is signaling that this community is an important player. [42:01.430 --> 42:02.950] Government can't do it alone. [42:03.650 --> 42:06.910] Private sector can't do it alone to stay ahead of the threats here. [42:06.910 --> 42:26.730] We need the security researchers' input, and we want to empower them to go ahead and help inform this broader public-private partnership community of what's going on and how to stay ahead and prevent and mitigate threats. [42:26.730 --> 42:34.970] And just one thing I'd like to add about the importance of security researchers and people, you know, in the community, the hackers, folks in this room. [42:37.290 --> 42:47.230] Some of the FBI's best investigations, really all of them, they usually have security researchers who bring things to our attention. [42:47.430 --> 42:51.270] Hey, did you know about these Cobalt Strike team servers? [42:52.650 --> 42:56.430] Are you aware of this ransomware panel that is open to the public? [42:57.310 --> 43:03.030] Or it's people saying, hey, are you aware that on exploit.in, there's something... [43:03.030 --> 43:07.110] They're selling a network to a power plant or a hospital. [43:07.370 --> 43:17.350] And it's extraordinarily valuable to us because as the government, we're encumbered by, you know, just being the government. [43:17.350 --> 43:26.450] And we're not allowed to do as much stuff as folks in the private sector. [43:28.550 --> 43:31.490] Things are very bureaucratic and there's layers of approval. [43:31.490 --> 43:36.270] And so we are slower and less agile than security researchers. [43:36.470 --> 43:41.350] So very often security researchers are on the bleeding edge of information. [43:41.350 --> 43:56.010] And some of the best FBI cases that you read about in the newspaper, they have security researchers who are behind the whole thing that were basically pointing us in the right direction and giving extraordinary assistance. [43:56.450 --> 43:58.850] I couldn't agree with you more. [43:59.470 --> 44:03.770] I've even, you know, helped FBI on numerous occasions myself. [44:04.250 --> 44:11.810] But I want to ask a really tough question of all of you here on the panel now, too, is that this one will get a little contentious. [44:12.370 --> 44:15.030] Because on the one hand, we're saying we have to... [44:16.030 --> 44:18.410] We need this public-private partnership, essentially. [44:18.510 --> 44:19.570] We need the help. [44:19.790 --> 44:23.610] And also, we don't want to go after good faith security researchers. [44:24.770 --> 44:31.930] And part of, I think, these new guidelines is helping bridge that gap where there was a gap, possibly because of some history. [44:31.930 --> 44:36.990] And that history I'm referring to is the Aaron Swartz case, which was a 1030 charge. [44:37.110 --> 44:39.410] And it was a charge under the Computer Fraud and Abuse Act. [44:39.510 --> 44:42.930] And it was a really beloved and dear member of our community here. [44:43.690 --> 44:56.630] And so I want to ask all three of you on the panel your thoughts about the Aaron Swartz case and whether the guidelines today would have prevented that charge years ago. [44:57.450 --> 44:59.890] So why don't I hand it over to Sagar. [45:01.210 --> 45:05.050] Yeah, I mean, certainly that case was a tragedy. [45:06.770 --> 45:09.950] Regardless of kind of anyone being prosecuted, no one wants that to result. [45:10.390 --> 45:10.770] Yeah. [45:10.770 --> 45:11.550] That's never the goal. [45:12.890 --> 45:14.230] You know, it's interesting. [45:14.550 --> 45:15.970] You know, I was reading up on it. [45:16.150 --> 45:18.870] And kind of reading up on the facts of that case. [45:18.990 --> 45:22.430] And I saw kind of two different versions when I was reading up on it. [45:22.430 --> 45:25.130] You know, online if you're just kind of generally looking at things. [45:25.630 --> 45:29.110] It was about a guy who, you know, had access to a computer. [45:29.890 --> 45:35.910] Went and kind of used something to download a lot more things than he, in a quicker way. [45:36.090 --> 45:37.390] The academic journals. [45:37.610 --> 45:38.670] The JSTOR journals. [45:38.930 --> 45:39.110] Yeah. [45:39.410 --> 45:40.350] Downloading all these journals. [45:40.350 --> 45:45.710] And, you know, any person can go into MIT's campus and go to computer. [45:46.150 --> 45:46.270] Right. [45:46.370 --> 45:50.050] And, you know, access these journals and download them and look at them. [45:50.170 --> 45:51.090] And you can do that. [45:51.230 --> 45:52.910] He used a tool. [45:53.430 --> 45:55.010] I forget exactly what he was using. [45:55.150 --> 45:57.290] But he used a tool that allowed him to download, you know. [45:57.510 --> 45:58.610] It was like an automation. [45:58.910 --> 45:59.270] Automated downloading. [45:59.270 --> 46:01.370] Keep grabbing.py, I believe it was called. [46:01.510 --> 46:01.970] There you go. [46:03.070 --> 46:06.970] You know, I think it ultimately allowed him to get $4 million or so. [46:08.150 --> 46:13.710] And so he had access and he then used something to accelerate his ability to get things. [46:13.910 --> 46:22.190] But under the Van Buren decision and the, you know, it seems like that wouldn't necessarily be something that could be prosecutable right now. [46:22.190 --> 46:22.370] Right. [46:22.370 --> 46:30.110] However, I actually pulled up the indictment from the District of Massachusetts. [46:30.470 --> 46:33.010] And to be clear, I was not involved in any way in prosecuting this case. [46:33.510 --> 46:33.970] Absolutely. [46:34.090 --> 46:37.470] And in fact, I think anybody on this panel was at all involved in the Swartz case. [46:37.910 --> 46:37.990] Yeah. [46:38.170 --> 46:49.350] But it talks about how he broke into a restricted wiring closet at MIT, accessed it, and then accessed MIT's network without authorization from a switch within that closet. [46:49.910 --> 46:51.410] And that's how he was able to connect. [46:51.410 --> 46:53.370] So, look, I don't know what actually happened. [46:53.770 --> 46:56.970] These are allegations and indictment, which are not, you know, proven. [46:57.970 --> 47:05.870] But, you know, the latter seems to be a situation where it might still be prosecutable under the Section 1030. [47:06.070 --> 47:09.170] So that just shows the kind of dividing lines there. [47:09.310 --> 47:09.970] That's interesting. [47:10.130 --> 47:11.770] So it's still a pretty nuanced area. [47:11.770 --> 47:17.670] So the access, perhaps, you know, through whatever cabinet he had access, that might have been the 1030 violation. [47:17.670 --> 47:25.210] But downloading in an automated fashion academic journals to which you already had accessed, based on the Van Buren decision that came out. [47:25.290 --> 47:26.510] Not necessarily the guidelines. [47:26.790 --> 47:29.730] It probably wouldn't have amounted to a charge. [47:30.690 --> 47:31.230] Interesting. [47:31.230 --> 47:32.770] I'll pass it over to you, Joel. [47:36.930 --> 47:40.410] So I think what happened with Aaron is unspeakably sad. [47:41.570 --> 47:45.190] And I didn't know him when he was charged. [47:45.190 --> 47:46.550] I was a baby FBI agent. [47:46.590 --> 47:47.630] I was still at Quantico. [47:48.470 --> 47:53.190] And I never really even heard about the case until I moved. [47:53.450 --> 47:55.330] I worked public corruption part of my career. [47:55.390 --> 48:00.330] And then I moved to cyber seven years ago. [48:00.330 --> 48:03.410] And I had never heard of the case. [48:03.630 --> 48:05.730] And there's lots of stuff you can find. [48:06.230 --> 48:07.370] I saw the documentary. [48:07.750 --> 48:12.070] You can find articles about the investigation. [48:15.650 --> 48:16.650] But something... [48:16.650 --> 48:19.970] What makes it so tragic is... [48:21.150 --> 48:22.710] Aaron Schwartz, he was a writer. [48:22.710 --> 48:23.630] And he was a thinker. [48:23.630 --> 48:27.510] And you read some of his essays. [48:28.690 --> 48:33.690] And I know he's famous for Reddit and for his political activism. [48:33.950 --> 48:41.590] But the thing that I think is most interesting is just his clarity of thought on social issues. [48:41.910 --> 48:44.090] And about privacy. [48:45.370 --> 48:47.990] And even things that... [48:47.990 --> 48:49.130] He was just very... [48:49.130 --> 48:50.250] He was a curious person. [48:50.250 --> 48:59.330] So you can read his essay about Keynes' general theory on economics. [48:59.370 --> 49:01.410] And this is something that 19-year-olds do not read. [49:01.490 --> 49:03.310] This is something economists avoid reading. [49:03.490 --> 49:07.050] And it's just amazing to hear how clearly he summarizes it. [49:08.230 --> 49:10.510] Same with, like, David Foster Wallace. [49:10.910 --> 49:12.250] He read Infinite Jest. [49:12.290 --> 49:16.170] And then he writes this literary criticism as, like, an 18-year-old. [49:17.910 --> 49:25.510] And I think, like, it's awful that we don't have him in this decade especially. [49:25.650 --> 49:32.130] Because I feel like now when we're talking about things like moderation on social media platforms. [49:32.150 --> 49:37.010] And we're talking about disinformation and misinformation. [49:40.710 --> 49:43.310] I would just love to hear, like, what his thoughts are on it. [49:44.270 --> 49:50.770] I think it would be very, very illuminating just to have his commentary and see how his thought has evolved. [49:52.850 --> 50:00.050] I'm not sure if the guidelines that were released, as Sagar was mentioning, really would affect his case. [50:00.050 --> 50:06.990] Because this is more geared towards security researchers. [50:07.450 --> 50:13.130] And I think Aaron falls more in the bucket of an activist, the civil disobedience. [50:13.350 --> 50:19.370] Which, you know, our country has a rich history of civil disobedience bringing light to laws that are unjust. [50:19.390 --> 50:21.830] And then the law is changing through the democratic process. [50:22.810 --> 50:29.510] So I'm not sure if this would... if this new guidance would really address his specific matter. [50:29.670 --> 50:32.710] But I do think a lot has changed in ten years. [50:33.230 --> 50:38.410] In terms of the prioritization of the type of investigations that the federal government is interested in. [50:39.050 --> 50:42.390] Ten years ago, we didn't have nation-state hackers breaking into private companies. [50:43.170 --> 50:46.590] Ten years ago, there were no attacks on our democracy. [50:48.830 --> 50:55.630] Ten years ago, there was no ability to monetize network access for $100 million or $200 million. [50:56.170 --> 51:03.530] And so I think just the prioritizations themselves have changed from looking at these hacktivist cases. [51:03.550 --> 51:03.770] Yeah. [51:04.270 --> 51:08.490] More towards the cases where there's enormous loss. [51:08.550 --> 51:12.250] Well, let me interrupt you and ask you a direct question about that, too, then. [51:13.390 --> 51:26.710] With the shift in priorities, if this type of case, if the Swartz case came over to you as an FBI agent today, do you think you would say, oh, my goodness, there's no way that we could go after this? [51:26.930 --> 51:31.990] Or would this be something you would put in the never-to-prosecute-or-never-investigate pile? [51:32.010 --> 51:33.470] Or what would happen? [51:34.050 --> 51:38.230] I mean, so the FBI's job is just to get the facts. [51:38.690 --> 51:40.890] And so if this case came to me... [51:40.890 --> 51:42.610] I mean, this isn't the type of cases I work. [51:43.270 --> 51:45.750] But if the case came to me, I would gather the facts. [51:46.630 --> 51:48.410] And I would go where the facts take me. [51:48.810 --> 51:52.470] And then I would give them to prosecutors to make the decision. [51:54.030 --> 52:02.990] I wouldn't be particularly aggressive about wanting to work and invest a hacktivist case. [52:03.390 --> 52:11.410] Because, like I said, we're turning down cases where victims are losing a lot of money. [52:11.410 --> 52:14.570] And, you know, there's a lot... [52:14.570 --> 52:23.110] There's a wealth of targets that I think would, in my mind at least, we would prioritize over this type of conduct. [52:23.330 --> 52:24.830] But again, it's not my decision. [52:24.950 --> 52:29.350] My job is to gather the facts and to go where the facts take me. [52:29.810 --> 52:30.250] Gotcha. [52:30.450 --> 52:31.530] I appreciate that. [52:32.310 --> 52:33.310] Jay, what about you? [52:33.970 --> 52:34.410] Yeah. [52:34.710 --> 52:47.870] I had the benefit earlier this week, back on Monday, the Deputy Attorney General was over in our space at NCFTA National Crime Cyber Forensics and Training Alliance. [52:48.090 --> 52:49.390] She was there for a different reason. [52:49.610 --> 52:56.890] It was really more about how to develop a cyber-trained workforce within the legal ranks. [52:57.050 --> 53:06.390] And while we were chatting in a round table type setting, I said to her, I said, by the way, thanks for the guidance, the ethical hacking guidance. [53:06.950 --> 53:10.070] It's, from all that I've spoken with, it's been very well received. [53:10.370 --> 53:14.170] And she, I think, was taken aback a bit and said, you're welcome. [53:14.190 --> 53:16.930] And I have to tell you, it was a very easy decision. [53:17.630 --> 53:24.230] It's time, when this came across my desk, it was time to signal this change. [53:25.670 --> 53:26.510] That's interesting. [53:26.910 --> 53:27.730] You know, it's... [53:27.730 --> 53:33.330] I appreciate all your thoughts, and I know that they're all heartfelt in speaking about this tragedy. [53:33.490 --> 53:48.030] And I certainly hope that the evolution that we've seen coming from on high in the Supreme Court, together with the change in the guidelines, the change in the attitude from the Department of Justice, from the FBI, the shifting prioritization, I think, [53:48.110 --> 53:56.010] is such an important point that Joel has brought up that we would hopefully never see something this tragic affect our community again. [53:56.210 --> 53:58.850] That's, I think, all of our hopes here. [53:58.990 --> 54:03.430] I hope I speak, and I'm actually pretty certain I know I speak for the panel in that. [54:04.010 --> 54:28.290] But with that, I want to shift gears for a moment and go back to the slide deck here, which I believe we have on the screen, which is excellent, and move into a couple of hypothetical situations here where we can have some audience participation and get your thoughts on a couple of different hypotheticals that our panelists have come up with that test the limits of what good faith security [54:28.290 --> 54:37.550] research means and what can and what is within and without 1030 or the Computer Fraud and Abuse Act these days based on these guidelines. [54:37.550 --> 54:45.630] So, with that, let's move into hypothetical one, which I call, you know, seek and destroy here. [54:48.790 --> 55:03.090] So, the facts are this, you know, an IT staff with a large professional services organization, I know we're talking about, you know, perhaps a law firm or maybe an accounting firm or, you know, a gaggle of consultants. [55:03.090 --> 55:05.310] I think that's what you call a lot of consultants, right? [55:05.570 --> 55:06.050] Gaggle. [55:06.050 --> 55:09.450] A lot of people respond to an emerging cybersecurity incident. [55:09.950 --> 55:13.150] Alarms indicate unusual network traffic and data movement. [55:13.410 --> 55:18.290] Maybe some data has been exfiltrated, possibly, you know, internal staging. [55:18.810 --> 55:32.170] Investigation reveals that a large amount of this professional services organization, their data was exfiltrated to a cloud storage bucket of an unrelated organization, we're going to call that organization, ABC org. [55:32.470 --> 55:45.470] And the IR team finds that the config file needed for access to the ABC org bucket is there and can actually access that bucket. [55:45.730 --> 55:57.250] So, with this fact pattern here, you know, would the IR team actually violate 1030 by accessing this ABC bucket? [55:57.250 --> 55:59.130] I'm going to pass that. [55:59.290 --> 56:00.610] How about right back to you, Jay? [56:05.640 --> 56:05.920] Okay. [56:06.160 --> 56:06.860] Yeah, there I am. [56:07.000 --> 56:14.700] And let me say at the outset that this scenario is not a pie in the sky or really contrived scenario. [56:14.700 --> 56:21.220] It's based on an amalgam of a couple of incidents that have happened very recently, the actual incidents. [56:21.540 --> 56:22.640] So, yes. [56:22.860 --> 56:23.100] Okay. [56:23.340 --> 56:36.500] The team responds to the alarm and is able to trace back and see where the data that was exfiltrated went into this bucket, named something indicative of ownership by some other entity. [56:36.500 --> 56:38.440] Can they go into that bucket? [56:39.260 --> 56:40.510] Is that authorized? [56:41.840 --> 56:44.900] Are they authorized to do so to enter someone else's storage bucket? [56:46.520 --> 56:47.120] Hmm. [56:48.380 --> 56:49.520] It's a good question. [56:49.860 --> 56:55.440] So, I guess what that hinges on is, is this good faith security research under the definition? [56:55.940 --> 57:00.160] And when we look back at that definition, I don't know if we can click back on the slide. [57:01.300 --> 57:02.040] Yeah, I can. [57:02.120 --> 57:02.700] Look at that. [57:02.940 --> 57:06.480] The components of what constitutes good faith security research. [57:08.400 --> 57:24.020] It says, accessing a computer solely for the purpose of good faith testing, investigation, and or correction of a security flaw or vulnerability, where such activity is carried out in a manner designed to avoid any harm to individuals or to the public. [57:25.520 --> 57:28.360] I think it falls within that definition. [57:29.800 --> 57:30.760] Well, interesting. [57:31.120 --> 57:35.340] So, why don't we play out the fact pattern a little bit more and then I'll pass it over to Joel. [57:35.340 --> 57:39.400] So, they get access to the bucket and they find, right, they... [57:39.400 --> 57:42.280] I hope I'm not mixing up my hypotheticals here, right? [57:42.440 --> 57:42.600] No. [57:42.780 --> 57:55.360] And let's say they find the data of their own organization but together with, you know, let's say 10 other organizations' data as well that has been exfiltrated in the same S3 bucket. [57:55.880 --> 58:01.120] What then do you think an IR team, an incident response team, could do? [58:01.120 --> 58:10.500] I'm looking at you, Joel, here on this one, with their own data and other companies' data that was stolen and exfiltrated by the same threat actor group. [58:10.780 --> 58:12.520] So, I think it's up to their risk appetite. [58:14.760 --> 58:21.080] Like, look, as Jay alluded to, you call these hypotheticals, but this is what's happening in the wild. [58:21.080 --> 58:21.820] This is real life. [58:22.000 --> 58:22.880] This is real life. [58:23.100 --> 58:23.180] Yeah. [58:23.900 --> 58:34.860] And according to my reading of 1030, it seems that even breaking into the bad guy's computer would constitute a violation based on my reading. [58:36.200 --> 58:48.560] Now, whether it's something that we would be interested in investigating from the FBI's standpoint, I mean, imagine a victim comes to us and we're like, hold on, you broke into the hacker's computer. [58:48.860 --> 58:50.280] Like, you're in trouble now. [58:50.500 --> 58:50.920] You know? [58:51.680 --> 58:53.020] It's just, it's an absurdity. [58:53.840 --> 58:58.920] I can't imagine a scenario where we would be interested in that type of thing. [58:58.920 --> 59:06.340] And according to the new guidance, I can't imagine a situation where anyone would actually be prosecuted for something like that. [59:07.420 --> 59:07.860] Right. [59:07.940 --> 59:20.320] But as you say, Joel, that comes with some risk and it does depend upon your risk appetite as an employee or an incident responder on behalf of the employee, on behalf of the organization. [59:20.800 --> 59:20.980] Yeah. [59:21.080 --> 59:24.200] To be clear, I mean, according to my reading of the statute, it would still be illegal. [59:24.400 --> 59:26.880] I'm not going to advocate doing something illegal. [59:28.220 --> 59:47.180] But these are the types of questions that are arising that I don't think federal law is really equipped to give people sensible answers to how they can, how can they respond when affected with this type of situation. [59:47.880 --> 59:48.000] Yeah. [59:48.140 --> 59:50.560] Just, you know, get some audience participation here. [59:50.560 --> 59:57.880] By show of hands, how many people would think that accessing that bucket should be a crime? [01:00:00.120 --> 01:00:00.520] Nobody. [01:00:00.800 --> 01:00:01.120] Right? [01:00:01.400 --> 01:00:03.820] So, I think you're in good company here, Joel. [01:00:04.300 --> 01:00:04.400] Yeah. [01:00:04.560 --> 01:00:05.440] I mean, it... [01:00:06.020 --> 01:00:06.860] Sorry, what was that? [01:00:07.360 --> 01:00:08.420] You did have some hands. [01:00:09.380 --> 01:00:10.320] There were some hands. [01:00:10.520 --> 01:00:11.460] Oh, there were some hands. [01:00:11.580 --> 01:00:11.780] Okay. [01:00:11.860 --> 01:00:12.560] Sorry, I couldn't see. [01:00:12.560 --> 01:00:13.920] The lights are a little bright here. [01:00:14.440 --> 01:00:14.640] We're out. [01:00:14.760 --> 01:00:15.460] But that... [01:00:15.460 --> 01:00:15.540] Yeah. [01:00:15.660 --> 01:00:18.380] I think the majority would agree with Joel here. [01:00:18.480 --> 01:00:20.560] But I want to pass it to you, Sagar, for your view on this. [01:00:20.820 --> 01:00:23.940] As the actual prosecutor, the guy who makes these decisions. [01:00:24.260 --> 01:00:24.440] Yeah. [01:00:24.540 --> 01:00:25.620] Look, I... [01:00:25.620 --> 01:00:26.660] Here, right? [01:00:26.800 --> 01:00:34.680] I mean, I think, as Joel kind of indicated, certainly I think just accessing the computer without kind of doing any... [01:00:34.680 --> 01:00:38.500] Again, the 1030 requires certain actions you have to take. [01:00:38.640 --> 01:00:39.540] You have to take information. [01:00:39.740 --> 01:00:40.740] You have to cause damage. [01:00:40.920 --> 01:00:41.620] You have to cause loss. [01:00:41.920 --> 01:00:42.220] Mm-hmm. [01:00:42.220 --> 01:00:45.960] There's all these other things that are in addition to simply accessing. [01:00:46.480 --> 01:00:46.620] Mm-hmm. [01:00:46.640 --> 01:00:47.900] So, if... [01:00:47.900 --> 01:01:03.620] And if you are really doing it in good faith investigation, and the facts, the available evidence that I have and that the FBI has to, you know, show that you are, in fact, trying to investigate your own data, you know, I think arguably it would fall, [01:01:03.640 --> 01:01:06.900] you know, under the good faith security research. [01:01:07.060 --> 01:01:23.200] But again, you know, I think it's also helpful to note that this kind of language about good faith security research is part of eight different factors that are in these guidelines as to things that a prosecutor should decide whether or not to charge someone. [01:01:23.640 --> 01:01:29.400] Those other things include the impact of the crime in the prosecution, on the victim in third parties. [01:01:29.480 --> 01:01:30.760] Here are the victims actually doing it. [01:01:32.500 --> 01:01:47.180] The degree to which the damage or access raises concerns pertaining to national security, critical infrastructure, public health, the sensitivity of the affected computer system, and the deterrent value of an investigation or prosecution. [01:01:47.340 --> 01:01:47.440] Right. [01:01:47.840 --> 01:01:50.940] So, let's complicate it a little bit more with this fact. [01:01:51.060 --> 01:01:57.520] I think this one's really interesting because you mentioned one of the factors that you think about are the impact of third parties. [01:01:57.860 --> 01:02:01.460] So, we have ten other companies' data in this S3 bucket. [01:02:01.720 --> 01:02:05.360] The IR team sees this and decides, you know what? [01:02:05.640 --> 01:02:08.260] I've had it with, you know, this threat actor group. [01:02:08.560 --> 01:02:09.740] They've ruined my life. [01:02:09.740 --> 01:02:11.040] I haven't slept in five days. [01:02:11.280 --> 01:02:19.140] Makes a rash decision and says, I'm going to delete these other archives of exfiltrated data that belong to other companies. [01:02:19.940 --> 01:02:35.260] That then leads the threat actors to get very angry and then, let's say, demand additional ransom or engage in other forms of extortion with regard to those other affected companies by the threat actors. [01:02:35.440 --> 01:02:43.200] So, there has been in this situation, in the new fact pattern here, a greater impact to third parties after accessing that S3 bucket. [01:02:43.340 --> 01:02:44.560] Do you think that could cross the line? [01:02:44.800 --> 01:02:45.540] Yeah, I mean... [01:02:46.480 --> 01:02:48.480] Oh, I was going to jump in real quick on that, Alec. [01:02:48.480 --> 01:02:49.220] Go ahead, Jay. [01:02:49.440 --> 01:02:51.300] Because I think there are really two key decisions. [01:02:51.600 --> 01:03:03.160] First, okay, it's one thing if you see your data that's been exfiltrated in this bucket that presumably belongs to another organization and was likely compromised by a bad actor. [01:03:03.600 --> 01:03:10.380] So, there's one decision about, do I delete the data from my organization that I know does not belong there? [01:03:10.380 --> 01:03:14.360] And then secondarily, I see a bunch of other victims there. [01:03:15.000 --> 01:03:21.240] Should I try in good faith to help them and download that data or delete that on their behalf? [01:03:21.520 --> 01:03:24.560] Can you be sure that it's not really supposed to be there? [01:03:25.560 --> 01:03:29.400] Maybe there's some partnership I'm not aware of and that data is there for a reason. [01:03:29.400 --> 01:03:33.960] So, you are taking on some additional risk if you do delete the data. [01:03:33.960 --> 01:03:55.860] And I'll tell you, to complicate this pattern, what we'll add is, in the instance that led to the creation of this scenario, that while making those decisions, the response team had not assured that their network was completely secure and they were locked down with encryption. [01:03:56.260 --> 01:03:59.560] When the bad actor determined, wow, you deleted your data. [01:04:00.620 --> 01:04:03.700] Did you think that was our only copy of your data? [01:04:03.940 --> 01:04:09.920] The bad actor responded and locked down with... dropped some encryption malware. [01:04:10.660 --> 01:04:12.280] You know, it's... [01:04:12.280 --> 01:04:17.520] Both you and Joel, Jay, had mentioned, you know, risk here too. [01:04:17.560 --> 01:04:24.760] And I think it's worth taking a tiny bit of a detour about the CFAA too, because, you know, it's not just a criminal statute. [01:04:24.900 --> 01:04:29.020] There's also potential civil liability under the Computer Fraud and Abuse Act. [01:04:29.060 --> 01:04:44.760] And as a private practice attorney up here, you know, that's, you know, arguably very important, because let's say that the IR team, the incident responders, do that, and it leads to additional extortion or a higher ransom demand for these other companies. [01:04:45.200 --> 01:04:59.640] I think it's quite possible that there could be civil liability under the Computer Fraud and Abuse Act for that particular type of action because it resulted in some kind of damage or additional cost or extortion to these other companies. [01:04:59.820 --> 01:05:06.700] And so there is always this civil angle that you have to think about in terms of your liability under the CFAA or 1030. [01:05:06.880 --> 01:05:09.740] It's not just a criminal statute. [01:05:09.740 --> 01:05:17.780] But I want to pass it back to you, Sagar, because I'm really interested in your analysis under the more complicated fact pattern here. [01:05:17.780 --> 01:05:18.140] Yeah. [01:05:18.500 --> 01:05:20.640] I mean, look, again, it's a two-step analysis, right? [01:05:20.760 --> 01:05:25.320] One, is there a legally a violation of Section 1030? [01:05:25.680 --> 01:05:32.040] And then two, you know, based on the policies and the guidelines and the facts, you know, should... [01:05:32.040 --> 01:05:34.280] Is this a case that we should charge? [01:05:34.660 --> 01:05:34.980] Right? [01:05:35.120 --> 01:05:38.960] Prosecutorial discretion is a big part of every prosecutor's job. [01:05:38.960 --> 01:05:40.480] Whether we should charge a case. [01:05:40.620 --> 01:05:44.380] Just because there's a legal violation does not mean that we should. [01:05:44.380 --> 01:06:00.120] So here, I think, once they access it, and then they either obtain, they download the data, even if it's their own data, or even the data of the other firms, I think it is, you know, appears to be a violation of Section 1030. [01:06:01.020 --> 01:06:03.080] And then the question is, should we prosecute? [01:06:03.620 --> 01:06:08.340] So that will depend on kind of what was the... what were they trying to do? [01:06:08.340 --> 01:06:11.300] What was the point, you know, of what their access was? [01:06:11.420 --> 01:06:12.900] What was the harm that was caused? [01:06:13.200 --> 01:06:13.380] Right. [01:06:13.920 --> 01:06:16.180] And so that's a much closer case. [01:06:16.400 --> 01:06:28.880] I mean, I think my, you know, I think the message that at least I want to convey is, you know, before you do that, you know, call law enforcement, call us, and we can work with you to figure out what's the right step. [01:06:28.880 --> 01:06:39.820] You know, what I would do is if I got that call, and I've gotten that call before, is, you know, oh, you have the keys to get into this hacker's, you know, system? [01:06:40.260 --> 01:06:42.120] Well, let's, you know, that's great. [01:06:42.260 --> 01:06:42.880] Give it to us. [01:06:42.980 --> 01:06:53.420] And then I can get legal process of a court that allows us to go preserve the evidence, take the evidence, use it for our purposes and going after the bad actors. [01:06:54.100 --> 01:07:10.660] So, you know, from our perspective, if someone goes in on their own, they could cause, you know, they can lose the evidence, they can cause more harm, which in this hypo, it actually leads to more harm because everyone, including the other firm's data is encrypted. [01:07:11.360 --> 01:07:14.960] So, you know, the message is to call us and we can work it through. [01:07:15.140 --> 01:07:18.180] And again, we are not trying to create burdens on victims. [01:07:18.280 --> 01:07:20.520] Victims, we take them very seriously. [01:07:21.460 --> 01:07:23.800] All victims are, you know, confidential. [01:07:23.800 --> 01:07:25.400] We don't want to re-victimize you. [01:07:25.520 --> 01:07:30.700] And we want to work with you as part of the private-public partnership to go after these guys. [01:07:30.700 --> 01:07:33.520] It requires kind of all of us sharing information to do it. [01:07:33.740 --> 01:07:35.940] That is such a great point. [01:07:36.120 --> 01:07:52.640] And I think doing it that way would nearly eliminate any potential civil liability that an IR team or the company for which the IR team was working could face by deleting that data and causing these untold consequences. [01:07:52.840 --> 01:07:58.740] I mean, I think there are a lot of unforeseeable consequences to these types of actions. [01:07:59.320 --> 01:08:01.560] And I want to pass it over to you, Joel. [01:08:01.760 --> 01:08:08.400] Do you want to... would you agree with Sagar there that, you know, the right action would be reported to law enforcement? [01:08:08.980 --> 01:08:13.740] And if so, how quickly do you think you guys could act? [01:08:16.000 --> 01:08:18.680] So that's a tough one because we've been in situations like that. [01:08:18.680 --> 01:08:20.940] And to be honest with you, there's a lot of factors. [01:08:21.760 --> 01:08:26.140] It depends on whether the server is in the United States or whether it's overseas. [01:08:26.420 --> 01:08:29.040] And if it is overseas, it depends on what country it's in. [01:08:30.120 --> 01:08:39.940] Because the answer might be, you know, we have to work with law enforcement overseas and, you know, give them the configuration file or the password to get into the server. [01:08:40.020 --> 01:08:45.800] And then when you're talking about overseas cooperation in law enforcement, things really slow down and it becomes difficult. [01:08:45.800 --> 01:09:04.080] But I agree with Sagar here that the right thing to do, and there shouldn't be any doubt with this, if you're concerned about risk and you're concerned about breaking 1030 and you're concerned about civil liability, is going to be pulling law enforcement into the mix, [01:09:04.600 --> 01:09:05.600] spinning us up. [01:09:06.960 --> 01:09:10.220] If it's domestic, we could probably get a search warrant fairly quickly. [01:09:10.240 --> 01:09:12.280] We would need a search warrant for this type of thing. [01:09:12.280 --> 01:09:15.080] We can get a preservation faster. [01:09:18.980 --> 01:09:27.610] But just to talk about the reality of it, normally when there's a staging server with exfil, data won't be on there for very long. [01:09:28.070 --> 01:09:29.700] We're talking hours. [01:09:30.610 --> 01:09:45.940] And so we would have to be very lucky and have to be very coordinated and work very quickly in order to be able to take action against it before the threat actor moves it or sends it to some other server that we don't have visibility. [01:09:47.190 --> 01:09:50.580] And, Joel, let me add, too, that, of course, we're not... [01:09:50.580 --> 01:10:00.420] We're discounting the human element, too, that these are teams that have been working for and been up for two days tracking an incident, trying to contain it. [01:10:00.420 --> 01:10:18.040] And when they find that data, the excitement of it being there, and the opportunity to delete the data and maybe save the day, and also perhaps be the good guy and try to help some of your partners, that comes into play when time is of the essence. [01:10:18.040 --> 01:10:24.660] And in some cases, it's easier to make a hurried decision that that does. [01:10:24.820 --> 01:10:32.270] And I'm glad you mentioned, Alex, the civil, the private cause of action there, the right of action, private right of action element of 1030. [01:10:32.440 --> 01:10:41.420] Because, yeah, if those companies incur a greater ransom, I think they're going to respond saying, you know, a notification would have been nice. [01:10:41.610 --> 01:10:45.500] You didn't have to go ahead and delete it and put us in the bucket with you. [01:10:46.500 --> 01:10:49.040] Yeah, I tend to agree with you there. [01:10:49.230 --> 01:11:00.840] I mean, if I was on the receiving end of the ransom demand, yeah, we'd probably start sending out the data preservation letters and getting the other side ready for litigation. [01:11:01.070 --> 01:11:06.460] I mean, it's such a crazy situation and bizarre and complex world that we live in here. [01:11:07.150 --> 01:11:11.780] I think I want to move on to the second hypothetical here, if everyone agrees. [01:11:12.110 --> 01:11:13.020] You guys good with that? [01:11:13.200 --> 01:11:13.940] Yeah, let's do it. [01:11:13.940 --> 01:11:15.840] So let's go on to the next one. [01:11:15.980 --> 01:11:18.500] This one I call the DIY disaster. [01:11:18.940 --> 01:11:20.580] So hypothetical two here. [01:11:20.880 --> 01:11:30.070] So let's suppose that there is, you know, God forbid, a remote access zero day discovered on many Internet-facing devices. [01:11:30.320 --> 01:11:32.040] It doesn't matter what these devices are. [01:11:32.120 --> 01:11:33.480] They're just Internet-facing. [01:11:33.620 --> 01:11:34.800] They're out on public IPs. [01:11:34.900 --> 01:11:38.650] So there's a working exploit, proof of concept, circulating on Twitter. [01:11:38.650 --> 01:11:47.780] And there's also been detection of increased worldwide scanning for these vulnerable devices, looking for things that can be exploited. [01:11:48.000 --> 01:11:49.580] So here's the question here. [01:11:49.690 --> 01:11:52.300] And I'm going to pose this one to Joel first. [01:11:52.300 --> 01:12:09.040] Could some good faith hacker, white hat as we would call them, leverage this exploit to mitigate certain vulnerable systems, to take essentially the patching of this vulnerability into her own hands? [01:12:10.380 --> 01:12:12.000] So they certainly could. [01:12:12.400 --> 01:12:15.200] I don't know if that would be the best course of action. [01:12:16.320 --> 01:12:20.620] A lot of things come into play here because the truth is patches break things. [01:12:20.860 --> 01:12:33.070] And if there's production systems that are connected to the Internet, if you patch them and restart them, things could and will break. [01:12:33.740 --> 01:12:39.690] And although, and this, again, we call it a hypothetical, but this is something that has been reported in the wild. [01:12:39.880 --> 01:12:48.020] Whenever you have these big wormable exploits, inevitably you'll see people building worms for Monero miners. [01:12:48.020 --> 01:12:51.900] You'll see people building worms just as, you know, hello world proofs of concept. [01:12:52.730 --> 01:13:01.150] You'll also see worms going around where it's people patching the flaw or closing ports and trying to mitigate. [01:13:01.150 --> 01:13:06.540] And it's just, it's pure like white hat hackers trying to do the right thing and trying to help a stranger. [01:13:07.880 --> 01:13:08.880] But there's risk to it. [01:13:08.960 --> 01:13:13.360] There's risk to it because there could be some inadvertent damage that happens. [01:13:13.480 --> 01:13:21.830] But I struggle, I struggle with this because I also think, you know, and I like to think in analogies. [01:13:21.930 --> 01:13:28.570] And if I was having a heart attack, I'd want someone to give me chest compressions up on stage, even if they were worried about breaking a rib. [01:13:30.650 --> 01:13:40.290] So, like what's worse, someone patches your system and you have some downtime or you get hit by a ransom, a wormable ransom. [01:13:40.790 --> 01:13:42.390] And so it's only a matter of time. [01:13:42.550 --> 01:13:44.370] Like there's going to be a new RDP exploit. [01:13:44.510 --> 01:13:45.770] There's going to be a new SMB exploit. [01:13:45.890 --> 01:13:48.550] There's going to be, you know, a Microsoft Exchange exploit. [01:13:48.550 --> 01:14:02.270] That's going to be wormable and there's going to be a countdown to when it gets ported into say Metasploit or when someone is able to take code from GitHub and build something that will just spread like wildfire. [01:14:04.750 --> 01:14:07.090] And, yeah, it's difficult. [01:14:07.090 --> 01:14:07.950] I wouldn't do it. [01:14:08.130 --> 01:14:08.970] I wouldn't do it. [01:14:09.050 --> 01:14:11.630] But people will do it and they have done it. [01:14:11.750 --> 01:14:13.310] The people have taken it into their hands. [01:14:13.430 --> 01:14:19.090] I think, you know, it really goes back to what you were saying earlier, Sagar, which is, I think, you know, it's about intent. [01:14:19.310 --> 01:14:28.790] And here, if you go and take patching of vulnerability into your own hands, there are foreseeable but arguably unintentional consequences of what you'd be doing. [01:14:28.790 --> 01:14:33.690] But, you know, some of those unintentional consequences, for example, could affect the hospital, right? [01:14:33.810 --> 01:14:43.310] You know, hospitals are notorious for relying on older hardware that has firmware on it that hasn't been updated since, you know, DOS 5.1, right? [01:14:43.410 --> 01:14:49.510] And you start monkeying around with those types of systems, things might go down, patients might not get care, people might die. [01:14:49.650 --> 01:14:55.330] I mean, this is all hypothetical, of course, but these are some of the unintentional consequences that could happen. [01:14:55.330 --> 01:15:00.270] And I think your CPR analogy is really apt as well. [01:15:00.690 --> 01:15:04.230] But I think it might depend on the risk for both sides, perhaps. [01:15:04.450 --> 01:15:06.130] I want to pass it over to you, Sagar. [01:15:06.570 --> 01:15:07.990] Yeah, no, I think that's right. [01:15:08.190 --> 01:15:11.830] You know, is this, again, going to kind of the two-step analysis, right? [01:15:11.930 --> 01:15:15.270] Is this a violation of Section 1030? [01:15:15.510 --> 01:15:23.250] It appears to be, you know, you're accessing someone else's computer and you're, you know, transmitting a command or a code to do something. [01:15:24.250 --> 01:15:27.110] And it changes the system, right? [01:15:27.250 --> 01:15:30.330] So I think technically it is, it appears to be a violation. [01:15:31.050 --> 01:15:38.230] You know, but then the second question is, you know, again, looking at the policies and looking at, you know, is this good faith security research? [01:15:38.390 --> 01:15:41.510] Is this someone who had no intent to harm? [01:15:41.910 --> 01:15:45.710] You know, I'm not sure, kind of, you have to look at the facts. [01:15:45.870 --> 01:15:47.570] Also, we'll have to look at the harm that was caused. [01:15:47.710 --> 01:15:49.410] We'll have to consult with the victim of that harm. [01:15:49.410 --> 01:15:52.950] And, you know, we do take victims' rights kind of very seriously. [01:15:53.210 --> 01:16:01.730] But I think the real question is, you know, what, when they decided to put the patch on, you know, what efforts did they take to avoid harm? [01:16:02.030 --> 01:16:05.270] Were there other things they could have done to avoid harm? [01:16:05.310 --> 01:16:07.310] And that's right from the guidelines, isn't it, right? [01:16:07.550 --> 01:16:07.790] Yeah. [01:16:08.430 --> 01:16:09.090] That's interesting. [01:16:09.270 --> 01:16:09.450] Joel. [01:16:09.910 --> 01:16:10.530] I'm sorry, not Joel. [01:16:10.710 --> 01:16:11.070] Jay. [01:16:11.430 --> 01:16:12.670] There's too many J's here. [01:16:12.950 --> 01:16:13.290] Yeah. [01:16:13.570 --> 01:16:14.650] Jay, what about you? [01:16:14.650 --> 01:16:17.170] I would love to get your thoughts on this one. [01:16:18.990 --> 01:16:19.430] Yeah. [01:16:20.910 --> 01:16:22.390] I'm listening to the comments. [01:16:22.590 --> 01:16:27.910] And I think this is uncharted territory, really. [01:16:28.070 --> 01:16:33.970] I mean, the landscape is so complicated. [01:16:33.970 --> 01:16:59.830] And those dependencies, I think, Joel, you referred to it, there's no way that even the most well-intentioned individual could understand the potential harm that could be visited by pushing out a hurried patch that hasn't been tested and validated that causes significant and great unintended harm. [01:16:59.830 --> 01:17:25.550] So, yes, I think what one of the potential solutions is here is to speed the coalitions through which we share those solutions so that more fertile minds can come together more quickly to evaluate the potential solutions instead of the rush to a solution when the problem may not be entirely known at that point. [01:17:25.550 --> 01:17:31.230] A few minutes of focus on the problem to make sure that the solutions appropriate would help. [01:17:32.190 --> 01:17:32.770] Yeah. [01:17:33.090 --> 01:17:35.490] I tend to agree with you there, Jay. [01:17:35.490 --> 01:17:43.230] And, you know, I also want to thank everybody for listening to us for this extended period of time here. [01:17:43.270 --> 01:17:52.850] And because the panelists that were in our slot had canceled, we've been able to extend this session and also want to open it up to Q&A at this point. [01:17:54.590 --> 01:17:59.890] It's a little bit hard to see with the lights, but we'd love to answer questions from the audience here. [01:17:59.890 --> 01:18:01.510] And I think there's one in the front. [01:18:01.710 --> 01:18:04.550] I don't know if we're using microphones or if there's a mic in the back. [01:18:05.510 --> 01:18:06.610] How's this thing working here? [01:18:07.810 --> 01:18:08.910] Oh, there's a mic in the back. [01:18:09.010 --> 01:18:09.890] All right, so how about... [01:18:10.350 --> 01:18:13.850] Yeah, if you want to line up and ask questions, that would be great. [01:18:19.670 --> 01:18:21.250] You guys all good for time here? [01:18:21.530 --> 01:18:22.670] Do a couple of questions? [01:18:22.930 --> 01:18:24.650] And yeah, fantastic. [01:18:24.650 --> 01:18:26.090] Appreciate that. [01:18:26.210 --> 01:18:26.610] Excellent. [01:18:28.330 --> 01:18:28.850] Sir. [01:18:29.050 --> 01:18:29.830] Sir in the red. [01:18:30.350 --> 01:18:31.030] Thank you, sir. [01:18:31.230 --> 01:18:32.190] Thank you, everybody. [01:18:32.990 --> 01:18:44.130] So, thanks for asking about Aaron Schwartz, who of course would be alive if not for the actions of people of the DOJ in prosecuting him under this act. [01:18:44.130 --> 01:18:55.290] And it's not the only time in history when prosecutors were too lacking in empathy for somebody who acted in the public interest. [01:18:56.230 --> 01:19:02.970] I do think these guidelines are better than nothing, but DOJ is not powerless here. [01:19:04.290 --> 01:19:07.210] The DOJ has influence over the law. [01:19:07.210 --> 01:19:15.890] We all know that in 2001, the Department of Justice said, we'd like these things passed, and Congress went ahead and put them into the Patriot Act. [01:19:16.230 --> 01:19:20.750] So DOJ can't go to Congress and say, we want to change the CFAA. [01:19:22.110 --> 01:19:36.450] And I don't understand why a lot of laws don't have more public interest offenses, but the CFAA in particular, DOJ could go to Congress, say, we want you to add a public interest defense to the CFAA. [01:19:36.450 --> 01:19:52.530] DOJ, so that somebody who releases information in the public interest that does not violate privacy, that doesn't have its primary use being for the purpose of an ethical business, is not going to get prosecuted. [01:19:52.950 --> 01:19:57.530] And that's going to outlast, not just, it's going to outlast the current administration. [01:19:57.570 --> 01:19:59.970] It's going to be a permanent improvement in the law. [01:20:00.290 --> 01:20:04.150] Can you give any good reason why DOJ does not do this? [01:20:05.490 --> 01:20:10.450] And just to be clear here, you're asking about essentially a lobbying question here, right? [01:20:10.550 --> 01:20:14.970] Why is DOJ not pressuring Congress to change the law? [01:20:15.150 --> 01:20:18.670] You can call it lobbying if you like, but it's more intimate than lobbying. [01:20:19.750 --> 01:20:21.450] It's more intimate than a lot of lobbying. [01:20:21.710 --> 01:20:27.730] DOJ does regularly go to Congress saying, we want more draconian laws, or we want changes in the law. [01:20:27.730 --> 01:20:35.130] Why can't they just say, we think this law would be improved by allowing the following specific public interest defense? [01:20:36.130 --> 01:20:38.430] I'll pass it to Sagar if you want to comment. [01:20:38.430 --> 01:20:42.330] Look, I don't think I can speak to that in my position. [01:20:42.730 --> 01:20:50.450] All I can say is that, you know, oftentimes I'm aware that, you know, I'm not sure whether we'd lobby for legislation. [01:20:50.450 --> 01:20:56.610] I know that Congress regularly inquires what, when there's proposed legislation, what the impact of that might be. [01:20:56.610 --> 01:21:05.250] And, you know, I think we have individuals that go and testify in front of congressional hearings as to the impact of legislation on the work that we do every day. [01:21:06.330 --> 01:21:09.250] But, other than that, I don't think I have the answer to your question. [01:21:09.610 --> 01:21:12.130] Yeah, I'm just asking, is there any reason why DOJ should not do that? [01:21:12.190 --> 01:21:13.890] Any ethical reason why they should not do that? [01:21:14.390 --> 01:21:25.770] Well, I could possibly make one comment in response, which is, you would only really want to have, you know, as a lawyer here, I'm speaking privately, not on behalf of my firm either. [01:21:25.770 --> 01:21:32.070] But I think as a lawyer, you would want to have changes in the law that would be necessary. [01:21:32.670 --> 01:21:42.510] And I think that to have Congress act while the Supreme Court was still changing and evolving the law, as it was very active in doing, might be a little bit premature. [01:21:42.510 --> 01:21:58.350] And I tend to see the evolution of the Supreme Court's interpretation of the Computer Fraud and Abuse Act, in 1030 in particular, as a continuous narrowing of what would constitute a crime under that statute. [01:21:58.590 --> 01:22:04.590] And so, arguably, there wouldn't be the need to go to Congress from DOJ's perspective to do this. [01:22:04.590 --> 01:22:08.970] And I would see the guidelines, as you admitted, I think, as a good first step here. [01:22:09.730 --> 01:22:11.270] But, look, I agree. [01:22:11.450 --> 01:22:15.050] And as we addressed in the panel, the guidelines don't change the law. [01:22:15.150 --> 01:22:16.850] The law is what the law is, right? [01:22:17.010 --> 01:22:27.430] And I think it's quite reasonable to expect that there may be other prosecutors in DOJ that might not be as enlightened as Sagar, and might have differing interpretations. [01:22:27.790 --> 01:22:30.490] And the way to prevent that would be to actually change the law. [01:22:31.450 --> 01:22:32.970] So, I take your point. [01:22:33.170 --> 01:22:35.990] And, you know, I think it's an interesting one. [01:22:36.250 --> 01:22:38.870] And we'd love to move on to another question, if that's all right. [01:22:39.010 --> 01:22:41.930] Well, let me add quickly, Alex, that I think... [01:22:42.150 --> 01:22:42.810] Yeah, yeah. [01:22:43.090 --> 01:22:48.550] I mean, the person asking the question alluded to it as a first step. [01:22:48.710 --> 01:22:53.350] And I think we have to recognize that we're in the midst of an evolution here. [01:22:53.350 --> 01:23:14.250] It may be a little hard to see because it's happening around us, but the Supreme Court decision, this necessary first step, and also the evolution of kind of the space that I'm in every day, a public-private partnership where members of the law enforcement community are working shoulder to shoulder with security researchers, [01:23:14.590 --> 01:23:16.990] threat hunters, members of academia. [01:23:16.990 --> 01:23:22.710] You know, as those efforts bear fruit and continue to evolve, if there's... [01:23:22.710 --> 01:23:43.990] If there is a calculable or an articulable need to say, you know, we could take it to the next level, but our security researchers are still concerned or the law departments haven't responded to this policy change, and we're still hearing, no, no, no, [01:23:43.990 --> 01:23:45.130] you can't do this. [01:23:46.890 --> 01:24:06.590] That's when I think the data call will go around for friends, amicus letters and briefs will come in, and the Department of Justice may, and I certainly don't speak for the Department of Justice, but I know that there is a data call that goes around every year to all the agencies to ask, [01:24:06.690 --> 01:24:08.950] what do you need to do your job more effectively? [01:24:08.950 --> 01:24:33.110] And if folks like the FBI and DHS, HSI, and Secret Service say, we need more input, and we think that a change in the law is absolutely what's chilling folks from coming forward, that's what's going to prompt Congress to lean forward and deal with constituent concerns, [01:24:33.110 --> 01:24:36.050] which they're over-indexed on, frankly. [01:24:36.230 --> 01:24:43.870] But that's... I think it takes time, and we're walking before we can jog or run. [01:24:44.070 --> 01:24:57.490] Well, you're describing a process that's adapted to widening predicates, but not to narrowing predicates, and if the Supreme Court narrows things in one way, that does not mean that all the ways in which the law needs to be narrowed need to be addressed. [01:24:57.770 --> 01:25:00.170] That's an area where crafting legislation is important. [01:25:00.170 --> 01:25:14.490] We all know the Supreme Court doesn't do a lot of the narrowing that's needed, so that's why I think I'm asking, is there any ethical reason why DOJ should not go to Congress and go in a narrowing direction, even if that's not what they're used to doing? [01:25:15.910 --> 01:25:18.350] Well, we appreciate your comments and your question. [01:25:18.490 --> 01:25:18.750] Thank you. [01:25:22.660 --> 01:25:23.100] Hello? [01:25:23.100 --> 01:25:33.680] Yeah, I was just wondering, like, for the hypothetical situations, like, how would that end up, like, in a situation where it's in front of the DOJ in the first place? [01:25:33.800 --> 01:25:35.880] Like, ABC org is not going to go. [01:25:36.780 --> 01:25:39.860] This person I'm hacking has hacked my computer back. [01:25:41.600 --> 01:25:44.110] Do you want to take that, Sagar or Joel? [01:25:44.110 --> 01:25:50.910] I mean, that's a good common sense data point, right? [01:25:51.090 --> 01:25:59.630] It's, you know, usually it's not going to come to fruition that I'm even necessarily going to learn that ABC Corp was hacked, right? [01:26:00.010 --> 01:26:12.650] Of course, however, in that hypothetical, if it leads to the encryption keys getting out and several other companies' data getting locked up, then it's something that might come to our attention. [01:26:12.910 --> 01:26:17.810] So that, I think, working within the hypo, that's how we might learn about it. [01:26:18.250 --> 01:26:27.470] Yeah, and I'll add, I think it would take some time for there to be a disclosure or an understanding of what really happened. [01:26:27.910 --> 01:26:46.170] As the company gets past the incident and rebuilds its network or pays the ransom and gets the decryption key, there's often litigation by third parties that were impacted by the outages, saying company, professional services company, you know, you didn't do enough. [01:26:46.170 --> 01:26:47.190] You didn't prepare enough. [01:26:47.390 --> 01:26:48.790] Your system wasn't secure enough. [01:26:48.890 --> 01:26:50.270] And I've been damaged in some way. [01:26:50.450 --> 01:26:56.490] And then in the wash, through discovery or otherwise, it'll come out that this is what happened. [01:26:56.710 --> 01:26:57.470] We learned. [01:26:57.650 --> 01:26:58.310] We did our best. [01:26:58.430 --> 01:26:59.630] We tried to delete the data. [01:26:59.630 --> 01:27:06.090] And there could be some disclosure that the company took some action that impacted others. [01:27:06.310 --> 01:27:07.130] But you're right. [01:27:07.250 --> 01:27:09.550] Would they volunteer that to say, oh, our bad. [01:27:09.670 --> 01:27:14.410] We meant well, but we were trying to save you and we caused you a little more harm. [01:27:15.230 --> 01:27:17.910] It wouldn't be immediately apparent to those other companies. [01:27:19.030 --> 01:27:19.630] Thank you. [01:27:20.010 --> 01:27:20.290] Great. [01:27:20.490 --> 01:27:20.770] Thank you. [01:27:22.250 --> 01:27:23.170] Thank you very much. [01:27:23.350 --> 01:27:25.090] My question is in regards to bug bounties. [01:27:25.450 --> 01:27:28.790] And like a security researcher finding a bug, they do the proper thing. [01:27:28.910 --> 01:27:31.030] They alert the organization and they wait the 90 days. [01:27:31.690 --> 01:27:45.810] And in the careful reading here indicates that if the company doesn't reply to that and doesn't take any action, that there's still no cover for that security researcher to do a public disclosure, if that disclosure was to create some type of financial harm. [01:27:46.090 --> 01:27:48.930] At least that's the way I read that. [01:27:49.530 --> 01:27:50.370] Is that correct? [01:27:52.950 --> 01:27:54.190] Anybody want to take this one? [01:27:54.730 --> 01:27:59.410] So responsible disclosure, it's not codified into law. [01:27:59.590 --> 01:28:03.870] It's more of like ethical frameworks that some people have proposed. [01:28:04.170 --> 01:28:07.370] You know, what's the waiting period for a company when you make ethical disclosure? [01:28:07.370 --> 01:28:08.170] Is it 90 days? [01:28:08.290 --> 01:28:08.970] Is it one day? [01:28:09.130 --> 01:28:09.930] Is it three months? [01:28:11.550 --> 01:28:18.050] I've seen some different, you know, takes on what the right thing to do is in that type of situation. [01:28:19.650 --> 01:28:21.850] And I think a lot of it depends. [01:28:22.250 --> 01:28:23.510] I think a lot of it depends. [01:28:23.930 --> 01:28:27.970] You know, it's hard for a large enterprise to patch their system quickly. [01:28:28.210 --> 01:28:37.230] And so I think it would be unfair if someone identifies a bug in a company's network and then says in three days I'm going to the press. [01:28:38.150 --> 01:28:45.290] Yeah, I think I was trying to clarify like the actual, the new standards that say as long as you're trying not to harm them, you're okay. [01:28:45.530 --> 01:28:48.090] But at what point, you know, does that break? [01:28:49.130 --> 01:28:49.910] I don't know. [01:28:51.050 --> 01:28:51.750] I don't know. [01:28:51.870 --> 01:28:56.210] I mean, it's something that time is going to have to bear out because you're going to have these situations in the future. [01:28:57.310 --> 01:29:14.030] One thing I will point to, so there's a lot of situations where someone will go through the motions for responsible disclosure and then they'll go to the press because they want notoriety for finding a bug. [01:29:15.110 --> 01:29:21.950] And their motivation is they want their name in the newspaper and they want to shame the enterprise. [01:29:21.950 --> 01:29:26.090] Or I shouldn't say that's their motivation, but that's kind of like what comes out of it. [01:29:26.550 --> 01:29:42.290] What I would prefer is to make the ethical notification and then to present at HOPE conference and talk about this really cool exploit that you found without, you know, showing any of the private data to anyone. [01:29:42.430 --> 01:29:52.170] You know, redact what you need to redact, but talk about the technical steps that you've found or that you used to find the bug and the timeline of when you disclosed and what the company did. [01:29:52.290 --> 01:29:59.110] I think that's more interesting than someone going to a reporter and saying, like, hey, you should report this. [01:29:59.590 --> 01:30:00.470] Thank you very much. [01:30:00.730 --> 01:30:03.410] One other point, I think, to your interesting question, too. [01:30:03.410 --> 01:30:08.450] And that's really, you know, Sagar, this is really more of a question to you, I guess. [01:30:08.570 --> 01:30:25.610] But, you know, whether it's responsible disclosure or irresponsible disclosure, and you're putting that information out into whatever the ecosystem is, that is a lot different from the type of affirmative activity that would equate to unauthorized access itself under the statute. [01:30:25.610 --> 01:30:35.810] So, talking about something, putting information out there would not necessarily lead to some kind of actionable charge, as I understand it, under 1030 or CFAA. [01:30:37.630 --> 01:30:38.630] Would that be correct? [01:30:38.850 --> 01:30:40.050] I think that's generally right. [01:30:40.190 --> 01:30:40.370] Yeah. [01:30:40.610 --> 01:30:44.230] I would say it probably depends on, like, some of the specific scenarios. [01:30:44.450 --> 01:30:53.710] Like, for instance, if you find a bug on someone's external-facing SQL database, and then you spend a month downloading every single thing on their database. [01:30:55.050 --> 01:30:58.910] Like, that's where it gets into that blurred area of, like, well, why'd you have to do that? [01:30:59.070 --> 01:31:01.810] Like, you had the proof of concept, you showed that it worked. [01:31:01.830 --> 01:31:04.250] Why did you have to pull the rest of the data from the company? [01:31:05.030 --> 01:31:08.450] So, there are some gray areas that you get into, and it's really fact-dependent. [01:31:09.170 --> 01:31:09.450] Yeah. [01:31:09.730 --> 01:31:10.930] And Joel, too, right? [01:31:11.870 --> 01:31:23.130] Some of those requests to apply for a bounty that may be available are no more than thinly-veiled extortion requests. [01:31:24.230 --> 01:31:29.770] And, yeah, sometimes the activity is not with good faith that it's conducted. [01:31:29.770 --> 01:31:45.050] It's conducted in bad faith with efforts to cause some harm and to agree to hide the damage or to stop the damage in exchange for some money. [01:31:45.050 --> 01:31:48.690] So, the facts are important in each one of those. [01:31:50.130 --> 01:31:51.270] Well, thank you very much. [01:31:51.530 --> 01:31:52.410] Thanks for your question. [01:31:52.670 --> 01:31:52.690] Thank you. [01:31:52.690 --> 01:31:53.570] Great shirt, by the way. [01:31:54.270 --> 01:31:54.650] Love it. [01:31:55.010 --> 01:31:56.230] Hi, and thank you. [01:31:56.230 --> 01:32:00.050] I sort of wanted to pose a hypothetical in a different direction, if that's all right. [01:32:00.850 --> 01:32:02.750] So, imagine this scenario. [01:32:03.090 --> 01:32:08.650] An employee at the company working at the company normally and with access to the company networks. [01:32:09.030 --> 01:32:18.090] However, due to a bug that they were not looking for, they obtain access to documents that they were not looking for, that they are not supposed to have access for. [01:32:19.350 --> 01:32:27.490] Using this, they see that the company has conducted activity that is deeply unethical, though not necessarily illegal, in the higher levels. [01:32:27.650 --> 01:32:29.110] And they give this to a reporter. [01:32:29.810 --> 01:32:42.870] The company argues that this employee used unauthorized access to obtain information that was deeply damaging to themselves, regardless of the veracity and ethicality of it. [01:32:43.070 --> 01:32:47.250] So, like, as a prosecutor, how would you pursue this? [01:32:47.370 --> 01:32:52.330] And what do you think others, I mean, the prosecutorial realm in general would do? [01:32:52.330 --> 01:32:54.630] Could I ask you one clarifying question? [01:32:54.930 --> 01:32:57.810] And your hypothetical there, too, would be so... [01:32:57.810 --> 01:33:00.690] Because it was a little bit hard to hear, and you might have touched on this. [01:33:00.810 --> 01:33:08.770] But in your hypothetical where this employee then goes and accesses certain data that indicates the company has been doing some untoward things. [01:33:09.230 --> 01:33:09.350] Yeah. [01:33:09.530 --> 01:33:14.470] Did the employee actually have the access to that particular document? [01:33:14.470 --> 01:33:18.830] Or did the employee have to get through some kind of barrier in order to get the documents? [01:33:19.430 --> 01:33:25.630] Let's say that there was a bug in the system, so that the employee... [01:33:26.650 --> 01:33:34.870] There was some way for the employee to get that information, even though they were not supposed to, perhaps using some different methods, perhaps... [01:33:34.870 --> 01:33:48.430] Or, let's say in your hypothetical, would it work that if the access the employee was granted by the company was incorrectly configured to have given them more access to a particular document, would that fit your hypothetical? [01:33:48.430 --> 01:33:49.330] Yes. [01:33:49.630 --> 01:33:54.150] If, say, their access in one certain obscure case were incorrectly configured. [01:33:54.450 --> 01:33:54.670] Okay. [01:33:55.270 --> 01:33:55.450] Great. [01:33:55.550 --> 01:33:56.930] I'll pass it over to you guys. [01:33:57.710 --> 01:33:59.750] Yeah, that's an interesting hypothetical. [01:33:59.970 --> 01:34:06.930] I think of the related hypothetical, which is, you know, you're always wondering what your bosses are thinking of you. [01:34:07.710 --> 01:34:21.750] And so then, but on your computer system, somehow, when you're clicking through kind of various folders, the folder that you always thought you never had access to, all of a sudden you click on it, and it's available to you, and it shows all the notes that your bosses have been keeping in your file. [01:34:21.930 --> 01:34:22.550] It's a trap. [01:34:25.150 --> 01:34:30.370] So, if it's not, the boss is saying if you're going to access it, you know, is that a violation? [01:34:30.570 --> 01:34:32.330] You know, it's a good question. [01:34:33.610 --> 01:34:35.830] I think it's going to be hard to prosecute that case. [01:34:35.830 --> 01:34:35.990] Yeah. [01:34:36.510 --> 01:34:37.130] I think so, too. [01:34:37.130 --> 01:34:48.990] Under the Supreme Court's decision, because the Supreme Court kind of spoke of, you know, you have to, it is something that you are blocked from by some sort of technological means. [01:34:49.510 --> 01:34:58.150] And if you, if they mess up, and due to no part, no action on your part, you have access to it, I think it's going to be a hard case. [01:34:58.150 --> 01:35:04.390] So, when we think about the two-step analysis, you know, is that a case that we should, we can prosecute? [01:35:04.790 --> 01:35:06.090] I think it's going to be hard to. [01:35:06.330 --> 01:35:06.490] Yeah. [01:35:06.730 --> 01:35:11.990] Now, let's change our colleague's hypothetical here for a second, where the access wasn't incorrectly configured. [01:35:11.990 --> 01:35:18.330] But let's say it's a folder that had, was password protected, and somebody brute forced the password. [01:35:18.750 --> 01:35:20.870] That would be a little bit more clear cut as a violation. [01:35:21.130 --> 01:35:21.470] I agree. [01:35:21.830 --> 01:35:22.010] Yeah. [01:35:22.290 --> 01:35:22.530] Yeah. [01:35:22.530 --> 01:35:30.570] And Alex, let me jump in here, because this is really interesting, in that, at the FBI, and Joel, you jump in here too. [01:35:31.470 --> 01:35:42.370] There are many times where someone will report some information of concern, and the means through which they gathered that information are arguably illegal. [01:35:43.290 --> 01:35:46.470] That doesn't preclude the government from taking that information. [01:35:46.470 --> 01:35:53.110] Now, conversely, if the person said, I can get it through this means, I could easily brute force that and crack it. [01:35:53.330 --> 01:36:00.170] You couldn't say, go do that, because then they'd be an extension of government agent, and that would violate the law. [01:36:00.230 --> 01:36:13.310] But if they had done that and reported it, that's an option, that they could report it and let the government do what it can to mitigate the harm from that. [01:36:13.310 --> 01:36:15.390] So, again, the facts are going to be important. [01:36:15.530 --> 01:36:21.450] Is it strictly unethical behavior, or is it something that could be damaging and worse? [01:36:23.070 --> 01:36:24.070] Thank you for that, Jay. [01:36:24.250 --> 01:36:25.550] And thank you for the great question. [01:36:25.910 --> 01:36:29.110] I think we're probably only able to take one more question. [01:36:29.170 --> 01:36:30.490] How many people do we have left there? [01:36:30.550 --> 01:36:31.150] Is it just two? [01:36:31.630 --> 01:36:31.850] Sure. [01:36:32.210 --> 01:36:32.730] Is it two? [01:36:35.150 --> 01:36:35.650] All right. [01:36:36.550 --> 01:36:36.770] Okay. [01:36:37.650 --> 01:36:38.370] Here we go. [01:36:38.670 --> 01:36:38.950] Hi. [01:36:39.030 --> 01:36:39.990] Sorry, I'm Gus Andrews. [01:36:40.030 --> 01:36:41.350] For the moment, I'm putting on my work hat. [01:36:41.350 --> 01:36:43.010] I am with Disarm Foundation. [01:36:43.730 --> 01:36:46.590] I have a question that's a little bit tangential to what we've been talking about. [01:36:46.750 --> 01:36:55.370] And that is, from where each of you stand, we talked about with that last case where it was like you could just release a patch. [01:36:55.450 --> 01:37:00.890] And I'm sure everybody's, you know, release and development managers would really prefer you not do that. [01:37:01.030 --> 01:37:04.570] So it's not just the law would prefer you not do it, but the, you know, the engineers would too. [01:37:05.330 --> 01:37:14.870] You said that maybe, it sounds like maybe what was preferential, what you prefer to see in that case is people communicating with each other and saying, hey, you know, this is what we're seeing, you know, can everybody jump on this? [01:37:15.190 --> 01:37:31.650] From where each of you stand, what are the things that would be most important to improve trust between organizations communicating about things like that, and to improve communication between organizations and entities around that? [01:37:32.690 --> 01:37:35.030] This sounds like one for Jay and Joel here. [01:37:36.550 --> 01:37:36.670] Yeah. [01:37:37.930 --> 01:37:46.070] Let me start here because, as we mentioned at the outset, I spent a long career in government and then represented clients and had a number of stops in this journey. [01:37:46.110 --> 01:38:01.330] And now I'm back in the space where I see every day what it takes to build those trust relationships between law enforcement agencies that maybe haven't worked together as closely as they should, and then also private sector partners. [01:38:01.850 --> 01:38:05.990] And I wish there was an easy answer to that. [01:38:06.210 --> 01:38:21.530] I think it, the landscape is changing in that I think there are people who are committed to doing the work and being more open in environments like ours at NCFTA and others. [01:38:21.530 --> 01:38:25.110] But it does require a very purposeful effort to engage. [01:38:25.510 --> 01:38:43.050] I mean, you can't sit back in your office or your home office or wherever you work from and expect that you're going to be able to build the trust relationships that are necessary when you need to call on someone to pick you up or to collaborate with you on something really important. [01:38:43.050 --> 01:39:02.550] So, I think it requires an effort to brief your leadership and your organization to express the importance of getting out and listening, going on a listening tour and working with others to define problems before solutions are rushed to. [01:39:02.550 --> 01:39:04.730] It's, there's no easy path. [01:39:04.910 --> 01:39:06.470] It requires a lot of work. [01:39:06.570 --> 01:39:30.650] And I urge the folks that are out there to think about ways and out in the audience that is to opportunities to meet with others that may be a little bit of a stretch, you know, a little outside your comfort zone and your ordinary circle, just to hear what they're working on and develop those connections that I think help when those important and harder decisions come down the road. [01:39:30.650 --> 01:39:35.370] Because you have those built-in relationships that can serve you well. [01:39:36.110 --> 01:39:36.450] Yeah. [01:39:36.790 --> 01:39:42.910] And, you know, Jay, I think it's a great comment and allows us to kind of segue into wrapping it up here, too. [01:39:43.070 --> 01:40:04.690] And, you know, I'm reminded of Ambassador Ido Aharoni, who was the longest-serving Consulate General of Israel, made a comment to me about cybersecurity and foreign diplomacy and saying that, you know, the reason why countries have embassies all around the world, [01:40:04.790 --> 01:40:13.230] the reason why the United States has an embassy in Uganda and Tanzania, as well as Paris and Russia, is not because, you know, we like to collect real estate in foreign countries. [01:40:13.230 --> 01:40:18.370] It's because, you know, we're building these bridges and have these relationships in place in case we need them. [01:40:18.370 --> 01:40:25.090] And we may be able to... and that in the cybersecurity sphere, we need to build those same types of relationships. [01:40:25.350 --> 01:40:32.710] And I think, you know, it's very obvious to us all right now that we live in really complicated and complex times. [01:40:32.710 --> 01:40:37.730] And we dwell permanently in an area of nuance and grayness. [01:40:37.730 --> 01:40:46.570] And as I think Jay and Joel and Sagar all alluded to earlier, you know, we cannot go it alone at all anymore. [01:40:46.570 --> 01:40:51.710] No party is equipped to deal with the complexities of this world just by itself. [01:40:51.710 --> 01:41:00.050] I think the guidelines, these new prosecutorial guidelines with the CFAA, really should go a long way into fostering this public-private partnership. [01:41:00.550 --> 01:41:12.090] And the hypothetical private alliance, I think that is not just hypothetical anymore and something that Jay Kramer is actively working to forge on a daily basis. [01:41:12.090 --> 01:41:21.670] And I want to pass it over for a moment before we conclude to Sagar to make essentially a couple of statements and maybe even a plea to the community here. [01:41:21.850 --> 01:41:28.370] Yeah, look, you know, I think the message I want to communicate and why I'm excited to be here is just really two words. [01:41:28.470 --> 01:41:29.350] Call me, right? [01:41:30.450 --> 01:41:32.690] Call me, call the FBI. [01:41:32.690 --> 01:41:39.510] If you see something, you know, that's suspicious, you know, we are, we want to work with you. [01:41:40.510 --> 01:41:44.750] We appreciate all of the, you know, all the cybersecurity research that is out there. [01:41:44.890 --> 01:41:54.630] We can, our jobs and our investigations where we are really prioritizing going after real bad actors can only be done kind of with the help of everybody. [01:41:54.630 --> 01:41:58.870] So please work with us, call us, we want to hear from you. [01:42:00.210 --> 01:42:08.030] And, you know, and as these new policies make clear, you know, we're not interested in prosecuting good faith cybersecurity research. [01:42:08.310 --> 01:42:09.570] That's not what we're here for. [01:42:09.790 --> 01:42:11.670] We're here to go after the bad guys. [01:42:12.490 --> 01:42:13.630] That's what we do every day. [01:42:13.730 --> 01:42:15.010] And that's what we're going to continue to do. [01:42:15.150 --> 01:42:16.830] And we can do it better with your help. [01:42:17.130 --> 01:42:18.710] Yeah, I couldn't agree more. [01:42:18.950 --> 01:42:23.430] And sometimes if you don't want to talk to them directly, you might want to talk to FBI through a lawyer. [01:42:24.150 --> 01:42:25.570] That's always an option as well. [01:42:25.950 --> 01:42:27.750] And, you know, we're obviously all friends here. [01:42:28.070 --> 01:42:31.110] So I really want to... [01:42:31.110 --> 01:42:32.750] And we can even appoint you a lawyer. [01:42:32.890 --> 01:42:33.410] That's true. [01:42:33.570 --> 01:42:33.930] Absolutely. [01:42:34.450 --> 01:42:37.450] You can even just call us and say, hey, I want to tell you something. [01:42:37.570 --> 01:42:38.810] I'm not sure if I can or should. [01:42:39.190 --> 01:42:42.510] And if you can't afford a lawyer on your own, we can also even appoint one. [01:42:42.650 --> 01:42:45.930] That's such a great point. [01:42:46.190 --> 01:42:52.010] And look, I want to wrap it up here because we've gone through such an extended period of time. [01:42:52.010 --> 01:43:04.210] And give a really heartfelt thanks to Sagar Ravi of the Department of Justice, Jay DiCapua of the FBI, and Jay Kramer of the National Cyber Forensics Training Association. [01:43:04.750 --> 01:43:13.910] Thank you guys so much for your time, for being here, for speaking to the community, for speaking from your heart, and for just being open to the conversation. [01:43:14.470 --> 01:43:18.330] We're looking forward to having you back at HOPE, and we hope you enjoy the rest of the conference. [01:43:18.510 --> 01:43:19.810] Thank you all as well. [01:43:20.090 --> 01:43:20.930] Thank you very much. [01:43:21.150 --> 01:43:21.410] Thank you. [01:43:21.690 --> 01:43:22.330] Thank you.