Footnotes (150)



Criminalizing Hacking, Not Dating: Reconstructing the CFAA Intent Requirement

David Thaw

University of Pittsburgh - School of Law; Yale University - Information Society Project

August 4, 2013

Journal of Criminal Law and Criminology, Vol. 103, No. 3, 2013

Cybercrime is a growing problem in the United States and worldwide. Many questions remain unanswered as to the proper role and scope of criminal law in addressing socially-undesirable actions affecting and conducted through the use of computers and modern information technologies. This Article tackles perhaps the most exigent question in U.S. cybercrime law, the scope of activities that should be subject to criminal sanction under the Computer Fraud and Abuse Act (CFAA), the federal "anti-hacking" statute.

At the core of current CFAA debate is the question of whether private contracts, such as website "Terms of Use" or organizational "Acceptable Use Policies" should be able to define the limits of authorization and access for purposes of criminal sanction under the CFAA. Many scholars and activists argue that such contracts should not, because they may result in ridiculous consequences such as the criminalization of misrepresenting one's "desirability" on an online dating website. Critics of such arguments rebut that failing to allow contract-based restrictions opens the door for hackers to engage in many types of activity not otherwise subject to criminal sanction.

This Article examines the tension between these two positions, both from the standpoint of current U.S. jurisprudence and scholarship, and from the standpoint of the respective purposes of criminal and tort law in deterring and punishing socially-undesirable behavior. The Article concludes by proposing a legislative revision to the CFAA that substantially mitigates the risk of overbroad criminalization, while leaving intact the ability of the law to deter and punish the most serious acts affecting and utilizing computers.

Number of Pages in PDF File: 43

Keywords: Cybercrime, Computer Crime, Computer Fraud and Abuse Act, CFAA, Deterrence

Download This Paper

Date posted: February 28, 2013 ; Last revised: August 14, 2013

Suggested Citation

Thaw, David, Criminalizing Hacking, Not Dating: Reconstructing the CFAA Intent Requirement (August 4, 2013). Journal of Criminal Law and Criminology, Vol. 103, No. 3, 2013. Available at SSRN: http://ssrn.com/abstract=2226176

Contact Information

David Thaw (Contact Author)
University of Pittsburgh - School of Law ( email )
3900 Forbes Ave.
Pittsburgh, PA 15260
United States
HOME PAGE: http://www.davidthaw.com
Yale University - Information Society Project ( email )
P.O. Box 208215
New Haven, CT 06520-8215
United States
Feedback to SSRN

Paper statistics
Abstract Views: 756
Downloads: 181
Download Rank: 103,996
Footnotes:  150

© 2015 Social Science Electronic Publishing, Inc. All Rights Reserved.  FAQ   Terms of Use   Privacy Policy   Copyright   Contact Us
This page was processed by apollo4 in 0.359 seconds