  The Computer Fraud and Abuse Act
    does not see it your way.  Spread the word through the playgrounds.

    Doesn't apply here.
      I didn't access financial or government institutions, didn't defraud anyone or obtain anything of value (although a good attorney could call the thrill of the experience "something of value", I'm sure), didn't harm anyone's medical treatment, didn't cause $5k in damages, and didn't cause a threat to public safety.

      Not to say I was being a good boy, I certainly wasn't... but I wasn't malicious and I wasn't tearing people's systems apart.

      Obama's campaign just transformed from "Yes, we can" to "You're fuckin'-A right we did!"

      by Eddie in ME on Thu Jan 08, 2009 at 11:19:11 AM PST

      Don't be so sure.
        If it takes a sysadmin more than a day or two to investigate the compromise, even if there were no hacks preformed or data damaged, odds are that his billable time is approaching that 5K mark.  His salaried time might not be that high, but billable probably is.

        Keep in mind, when a system is compromised at all, the worst must be assumed.  You can't just look at the logs and say, "Oh, gee - I left port XYZ open, and someone got in and read my email."  No, you say, "Aw, ::explicative deleted:: I need to close XYZ down and check every single package, executable and script on the system."

        Quick to judge, Quick to anger, Slow to understand; Ignorance and prejudice and fear walk hand in hand. -- Neil Peart

        by JRandomPoster on Thu Jan 08, 2009 at 11:25:06 AM PST

      Where are you getting this list?

        From some summary of the act, or the act itself?

        By the way, you also need to check case law.  These things don't unpack themselves.

