The U.S. Department of Justice is defending computer hacking laws that make it a crime to use a fake name on Facebook or lie about your weight in an online dating profile at a site like Match.com.
In a statement obtained by CNET that’s scheduled to be delivered tomorrow, the Justice Department argues that it must be able to prosecute violations of Web sites’ often-ignored, always-unintelligible “terms of service” policies.
The law must allow “prosecutions based upon a violation of terms of service or similar contractual agreement with an employer or provider,” Richard Downing, the Justice Department’s deputy computer crime chief, will tell the U.S. Congress tomorrow.
Scaling back that law “would make it difficult or impossible to deter and address serious insider threats through prosecution,” and jeopardize prosecutions involving identity theft, misuse of government databases, and privacy invasions, according to Downing.
The law in question, the Computer Fraud and Abuse Act, has been used by the Justice Department to prosecute a woman, Lori Drew, who used a fake MySpace account to verbally attack a 13-year old girl who then committed suicide. Because MySpace’s terms of service prohibit impersonation, Drew was convicted of violating the CFAA. Her conviction was later thrown out.
What makes this possible is a section of the CFAA that was never intended to be used that way: a general-purpose prohibition on any computer-based act that “exceeds authorized access.” To the Justice Department, this means that a Web site’s terms of service define what’s “authorized” or not, and ignoring them can turn you into a felon.
On the other hand, because millions of Americans likely violate terms of service agreements every day, you’d have a lot of company.