Ryanair Booking.com CFAA Claim: Not About Hacking
Protecting Legitimate Online Activity: Why Overbroad CFAA Interpretations Harm Innovation and Research
The Computer Fraud and Abuse Act (CFAA) is a critical piece of legislation, but its interpretation has become a battleground for defining what constitutes illegal hacking versus everyday online behavior. The Supreme Court’s decision in Van Buren v. United States offered a crucial clarification, emphasizing that “authorization” pertains to technical concepts of computer authentication. This ruling is vital for safeguarding legitimate online activities that could or else be criminalized by overly broad interpretations of the CFAA.
The Van Buren Precedent: Narrowing the Scope of the CFAA
In Van Buren v. United States, the Supreme Court established a significant precedent by explaining that “authorization” within the CFAA refers to technical concepts of computer authentication. This means that simply violating terms of service, such as sharing account credentials with a family member or withholding personal information when creating an account, does not automatically trigger a CFAA violation.
As articulated in the EFF’s amicus brief, “The CFAA does not apply to every person who merely violates terms of service by sharing account credentials with a family member or by withholding sensitive information like one’s real name and birthdate when making an account.” This distinction is paramount. The CFAA was designed to target malicious hacking, not the myriad of common online interactions that may technically breach a company’s user agreement.
Building on Van Buren: The Importance of Bypassing Access Restrictions
The EFF, building on the foundational principles of van Buren and the Ninth Circuit’s ruling in HIQ Labs v. linkedin, has actively advocated for a clear interpretation of the CFAA. In a third Circuit case, the EFF urged the court to hold that a CFAA violation requires bypassing a technology that restricts access.
The core issue lies in the nature of access. When login credentials are legitimately created and used, accessing data within the scope of those credentials should not be considered a CFAA violation. The lower court’s rule, though, threatened to criminalize many everyday behaviors.Examples include logging into a streaming service with a partner’s login or accessing a spouse’s bank account to pay bills at their request. These actions,while possibly violating a company’s terms of service,do not constitute hacking or a violation of the CFAA. They represent a breach of a company’s “wish list” in its Terms of Service, not a circumvention of security measures.
The Chilling Effect on journalism and Academic research
The implications of a broad reading of the CFAA are particularly dire for journalists and academic researchers. These professionals often employ sophisticated techniques to gather information and understand online systems.Testing Accounts and Adversarial Research: Researchers frequently create multiple testing accounts to study how services operate. As a notable example, a researcher investigating housing discrimination might create accounts with varying race, gender, or language settings to observe how housing offers are displayed. While these methods might be considered “adversarial” by a company,they are essential for uncovering systemic issues and should not be illegal.
Criminalizing Legitimate Inquiry: Under a broad interpretation of the CFAA,a company could simply notify a researcher that they are not authorized to use the service in a particular way.This notification, coupled with the court’s opinion, could then render the researcher’s entire endeavor criminal. This creates a risky precedent where legitimate research can be criminalized by a company’s unilateral declaration, rather than by evidence of actual malicious intent or security breach.
Broader societal Impacts: Competition and Accountability
Beyond the direct impact on researchers, a broad CFAA interpretation can stifle innovation and competition.
Limiting Data Scraping: Companies could leverage an expansive CFAA to limit data scraping, effectively cutting off a vital method for consumers to compare prices and features across different websites. This undermines market transparency and consumer choice.
Undermining Independent Accountability: Website owners should not be granted new shields against independent accountability. A narrow interpretation of the CFAA ensures that companies remain answerable for their practices,and that users are not unduly penalized for exploring and understanding the digital landscape.
The Path Forward: Adhering to Van Buren’s Narrow Interpretation
The courts must follow the lead set by Van Buren and interpret the CFAA as narrowly as it was originally designed. Logging into a public website with valid credentials, even if data is scraped afterward, is not hacking. A broad reading of the CFAA leads to unintended consequences, chilling valuable research, hindering competition, and ultimately failing to protect users and the integrity of the internet.
The EFF’s amicus brief in Ryanair DAC v. Booking.com B.V. further elaborates on these critical points. The core principle remains: the
