Feeds

Lawyers fear misuse of cyber murder law

Squeezing quick guilty pleas from non-lethal cyberpunks?

  • alert
  • submit to reddit

5 things you didn’t know about cloud backup

securityfocus.com A genuine cyber murder may never happen outside the pages of tabloid newspapers and Tom Clancy novels, but defense attorneys say that won't keep federal prosecutors from getting some mileage out of a provision in the newly-passed Homeland Security bill that dictates a maximum sentence of life imprisonment without parole for computer hackers with homicide in their hearts.

One of many information security and cybercrime measures in the 484-page bill - which won final approval in the Senate Tuesday - the life sentence is reserved for those who deliberately transmit a program, information, code, or command that impairs the performance of a computer or modifies its data without authorization, "if the offender knowingly or recklessly causes or attempts to cause death".

If the attacker only causes or attempts to cause bodily injury through hacking, the crime carries a 20-year sentence.

While it sounds straightforward enough, defense attorneys who've worked on significant hacking cases worry that many aspects of computer crime law remain too unclear to provide a sound anchor for as weighty a sentence as life imprisonment, and they say the new provisions add more confusion to a still-evolving area of law.

"You can drive a truck through the ambiguities in that language," says Donald Randolph, the Los Angeles criminal defense attorney who represented hacker Kevin Mitnick. "It's a daunting prospect to address this when you have words like 'attempts to cause' and 'recklessly.' I could see prosecutors arguing that the term 'reckless' defines every instance of hacking."

"While it's completely understandable that society would want to impose a life sentence for any kind of murder... what we've done is attached that idea to the underlying vagueness of the anti-hacking law, and there are a lot of things that are not clear in the law and not clear in the statute," says Jennifer Granick, director of Stanford Law School's Center for Internet and Society, and defense attorney in several federal hacker cases. "Technology is progressing so rapidly... to attach a life sentence to an area of the law that is still in the earliest stages of the development is dangerous."

Plea Bargains

Notwithstanding apocryphal reports of hackers changing blood types at a New York hospital, or a twelve-year-old boy coming within keystrokes of opening the floodgates at an Arizona dam, no cases of attempted cyber murder or cyber terrorism have been reliably reported. But the defense lawyers believe that the new law -- or the threat of it -- will play a significant role in conventional, non-lethal, hacker cases.

"I'll be used to get guilty pleas," says Granick. "People will be afraid that they're going to get the life sentence so they'll take a deal for less than life, and give up their right to appeal and to test the law."

Other legal experts disagree. "I doubt it," says Orin Kerr, a cyber law professor at George Washington University Law School, and a former attorney with the Justice Department's computer crime section. Kerr believes prosecutors won't use the attempted murder language to squeeze guilty pleas out of hackers, and says the new provision will most likely gather dust -- an unused and overlooked curiosity in the law books.

"The practical effect of this is almost none," says Kerr. "It's probably mostly symbolic -- perhaps useful in a case of a terrorist act of computer hacking designed to cause a lot of deaths, in which case it would give the federal government jurisdiction."

"Forgive me for being pessimistic after 28 years as a criminal defense attorney... but I would say it will absolutely, positively be used to compel plea bargains," counters Randolph. "That's the name of the game in 90% of the prosecutions I'm involved in."

© 2002 Security Focus.

Next gen security for virtualised datacentres

More from The Register

next story
Microsoft: We plan to CLEAN UP this here Windows Store town
Paid-for apps that provide free downloads? Really
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Hear ye, young cyber warriors of the realm: GCHQ wants you
Get involved, get a job and then never discuss work ever again
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.