Reply All
Reply All

#43 The Law That Sticks

The Computer Fraud and Abuse Act is a law. It's been on the books for almost 30 years. And it makes totally mundane online behavior illegal. Learn more about your ad choices. Visit podcastchoices.com/adchoices

Featured Speakers

Mike Masnick GuestMatthew Keyes Guest

Topics Discussed

Episode Summary

Executive Summary: Reply All examines the Computer Fraud and Abuse Act (CFAA) through the Matthew Keys case, showing how a vague anti-hacking law can turn a minor website defacement into a felony carrying years in prison. The episode argues the CFAA’s broad “unauthorized access” language lets prosecutors inflate harm, while critics warn it can criminalize everyday online behavior and be used against unpopular targets.

Main Topics: Matthew Keys and the Tribune/LA Times website hack (Priority: 5/5): The episode centers on former Fox 40 web producer and reporter Matthew Keys, who allegedly gave Anonymous credentials to Tribune’s CMS, leading to a brief defacement of an LA Times article. The CFAA and vague definitions of computer crime (Priority: 5/5): The hosts explain that the Computer Fraud and Abuse Act, written in 1986, predates the modern internet and is broad enough to cover activities many people would not consider hacking. How prosecutors and companies calculate 'damage' (Priority: 5/5): A major focus is the escalating damage estimate in Keys’s case: from $5,000 to $17,650 to nearly $930,000, showing how costs can be used to raise charges and sentencing exposure. Sentencing, intent, and the moral framing of hacking (Priority: 4/5): The episode contrasts the triviality of the changed headline with prosecutors’ claims of malice and conspiracy, arguing that sentencing law punishes intended harm as well as completed harm. Aaron Swartz as a cautionary example (Priority: 5/5): Aaron Swartz’s prosecution under the CFAA is used to illustrate how the law can be wielded aggressively, even against conduct involving no clear financial harm or distribution of stolen material. Reform efforts and political resistance (Priority: 4/5): The discussion closes by noting efforts like Aaron’s Law and the broader push to narrow the CFAA, but also the resistance from law enforcement, companies, and the Obama administration’s desire to expand cybercrime penalties.

Key Arguments: The CFAA is dangerously broad because 'unauthorized access' can include conduct like violating terms of service or using someone else’s login. In the Keys case, the actual harm was tiny and temporary, but damage estimates were escalated to trigger felony penalties and harsher sentencing. Prosecutors argue that even limited damage can reflect serious criminal intent, especially when the defendant encourages further sabotage and uses anonymous channels to coordinate it. The law is attractive to prosecutors because it can be used when other charges do not fit, making it a flexible tool against a wide range of conduct. Aaron Swartz’s prosecution shows the human cost of overbroad computer crime laws: severe felony exposure for conduct many consider nonviolent and nonmalicious. Reform has been difficult because institutions that benefit from the law’s flexibility do not want it narrowed.

Data Points: Year CFAA written: 1986 - The law was created before the modern web existed. Matthew Keys age at conviction coverage: 26 - He was described as a 26-year-old former Tribune employee. Initial damage estimate: $5,000 - Tribune’s early estimate of the cost of the website defacement. Intermediate damage estimate: $17,650 - Prosecution’s trial figure based on 333 hours of work. Later damage estimate: $929,977 - Tribune’s post-conviction figure, likely to be used at sentencing. Sentencing guideline impact: About 5 years in prison - A million dollars in damage under the guidelines was said to translate to roughly five years. Duration of article defacement: 40 minutes - The LA Times article headline/deck was altered briefly before being restored. Aaron Swartz articles downloaded: 4.8 million - Files downloaded from JSTOR at MIT. Aaron Swartz charges: 13 felonies - He faced severe criminal exposure under the CFAA. Aaron Swartz maximum exposure: 35 years and a $1 million fine - Potential punishment cited in the episode. Aaron Swartz plea offer: 6 months - Prosecution offered a plea deal if he admitted guilt to all charges. Aaron Swartz age at death: 26 - He died by suicide one month before trial.

Pivotal Quotes: "It's written so broadly and in such a bizarre way that it's really easy to use against lots of people doing things that most people would not think of as criminal." — Mike Masnick: Describing the CFAA’s overbreadth and prosecutorial flexibility. "There were things that I did. I can't deny it. I'm not going to now." — Matthew Keyes: Audio from Keyes’s FBI confession played at trial. "There just isn't one." — Aaron Swartz’s defenders / narration: Referring to the idea that no version of the conduct justified decades in prison.

Implications: The episode warns that overbroad cybercrime laws can turn minor online misconduct into severe felonies, giving prosecutors wide leverage. For listeners, it underscores the need for clearer limits on digital access laws and more proportionate penalties.

🔓 Sign Up for Unlimited Episode Search

About Reply All

View all episodes from Reply All