Showing posts with label 18 USC 1030. Show all posts
Showing posts with label 18 USC 1030. Show all posts

Monday, September 23, 2019

HR 3710 Reported in House – Cybersecurity Vulnerabilities


Last month the House Homeland Security Committee published their report on HR 3710, the Cybersecurity Vulnerability Remediation Act. The Committee held their markup hearing back in July and ordered the bill reported without amendment. The bill is currently scheduled for consideration under the House suspension of the rules process on Wednesday. There will be limited floor debate, no amendments may be offered from the floor and a supermajority is required for passage.

Commentary


The Committee did not deal with the copywrite issue or software ownership issue that I mentioned in my blog post on the introduction of the bill. This means that any mitigation measures that the Cybersecurity and Infrastructure Security Agency publishes as a result of this bill will have to be limited to the generic measures that CISA already includes in the control system security advisories published by NCCIC-ICS. CISA is not going to be able to publish any true ‘hacks’ of the affected software or firmware because of these issues and the bill would do nothing to provide liability protection for owners or users that would use such ‘hacks’ even if reported by CISA.

Making changes to the software, owned in most cases by the vendor not the facility in which the software operates, could be held to be a violation of 18 USC 1030(a)(5)(A) for CISA or any researcher providing a software ‘hack’ to CISA or a violation of 18 USC 1030(a)(5)(C) for facility owners that employed such a software hack to their systems.

So again, we have Congress taking action to solve a cybersecurity action that is really no action at all. There is a potential (but very unlikely) way for the House to correct this bill, even under the suspension of the rules process. Under a motion to reconsider after passage, the bill could be sent back to the Homeland Security Committee with direction to offer an amendment. That amendment would read:

On page 4, line 21; insert “(a)” before “The director”;
On page 5, line 2; delete the period after “dor” and insert a colon;
On page 5, after line 2; insert:
“(b) Not withstanding 18 USC 1030(a)(5), the publication by CISA of any mitigation measure that changes the programing of a computer or device to provide a mitigation measure as described in (a) is not considered to be a fraud related activity as defined in §1030; and
“(c) Not withstanding 18 USC 1030(a)(5), the use of a mitigation measure described in (b) by a government agency or private entity to mitigate a vulnerability defined in (a) is not considered to be a fraud related activity as defined in §1030.”
On page 6, line 15; insert “(a)” before “The Under”;
On page 6, line 23; delete the period at the end and insert “; and”
On page 6, after line 23; insert:
“(b) Not withstanding 18 USC 1030(a)(5), the submission to CISA of suggested changes to the affected software to mitigate an identified vulnerability as part of the program described in (a) is not considered to be a fraud related activity as defined in §1030.”

I do not really expect that this would happen, but I can always be surprised by congresscritters. More likely such changes would have to be undertake in the Senate Homeland Security Committee if/when they markup HR 3710 after it passes in the House, but before it is considered under the unanimous consent process in the Senate. Again, I would not really expect that to happen. It would be too much like actually trying to accomplish something.

Friday, July 5, 2019

HR 3270 Introduced – Hack Back


Last month Rep Graves (R,GA) introduced HR 3270, the Active Cyber Defense Certainty Act. The bill would amend 18 USC 1030 to allow use of limited defensive measures that exceed the boundaries of one’s network in order to monitor, identify and stop attackers. The bill is identical to HR 4036 from the 115th Congress; no action was seen on that bill.

While the new bill has more cosponsors than HR 4036 (17 vs 9) there is still no representation on the House Judiciary Committee, the committee to which this bill was assigned for consideration, by a sponsor or cosponsor of the bill. This means that the bill is unlikely to be considered in that Committee.

As I noted in my post on HR 4036 there is a natural legislative inertia when it comes to changing criminal law. I expect that the same inertia would apply to this bill, above and beyond the lack of influence that the sponsors have to move the bill forward.

There is one point that I did not make in my post about the original bill that needs to be addressed. Both bills include a sunset clause (§9) that terminates “exclusion from prosecution created by this Act” two years after the bill is enacted. This short termination provision would make it exceedingly difficult to have the Federal guidance (from the FBI and DOJ)  mandated by the bill developed and published in time for corporate attorneys to review and plan the corporate implementation of the cybersecurity measures.

This is a smoke and mirrors bill that allows congresscritters to look like they are doing something.

Saturday, June 29, 2013

HR 2454 Introduced – Cybersecurity

As I mentioned last week Rep. Lofgren (D,CA) introduced HR 2454, Aaron’s Law Act of 2013. This bill was introduced in response to the suicide of Aaron Swartz, a noted activist/hacker, who apparently killed himself because of aggressive prosecution by federal authorities for hacking. The bill would revise the language of 18 USC 1030 to effectively change the definition of hacking from ‘exceeds authorized access’ to ‘access without authorization’.

Access Without Authorization

Section 2 of the bill replaces §1030(e)(6), removing the definition of ‘exceeds authorized access’ and adding the definition of ‘access without authorization’. The new term requires three components:

• The access must be made to “obtain information on a protected computer” {§1030(e)(6)(A)};
• The “accesser lacks authorization to obtain” {§1030(e)(6)(B)} access; and
• The access was gained by “knowingly circumventing one or more technological or physical measures that are designed to exclude or prevent unauthorized individuals from obtaining that information” {§1030(e)(6)(C)}.

The definition of the original term included language that encompassed either obtaining or altering information. The altering of information is not included in the definition of the new term.

Removes Fraud as an Offense

Section 3 of the bill removes §1030(a)(4). That paragraph made it an offense to “knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value”.

There is no substitute fraud wording included in the bill.

Punishment

Section 4 of the bill modifies the language of §1030(c)(2). That paragraph sets for the punishments authorized for violations of the provisions of the section.

Similar wording changes are made in two separate sub-paragraphs {§1030(c)(2)(A) and §1030(c)(2)(C)} in that the bill changes the wording from “after a conviction for another offense” to “after a subsequent offense”. Since an offense cannot occur after a subsequent offense (by definition a ‘subsequent offense’ must occur after the other offense), this wording will have to be modified.

The bill introduces the term “fair market value” in two subparagraphs {§1030(c)(2)(B)(i) and §1030(c)(2)(B)(iii)}. In the first it adds the requirement that the “fair market value of the information obtained exceeds $5,000” for cases where the offense was committed for commercial advantage or personal gain. The second replaces the term ‘value’ in requiring that the value of the information obtained exceeds $5,000.

Unintended Consequences

As I mentioned earlier, this bill is intended to lower the consequences of hacking that is done purely for reasons of social or political activism such as defacing a web site. Unfortunately it appears that there may be some unintended consequences to the proposed changes.

Currently, the only language in 18 USC 1030 that can be used to define as criminal an attack on an industrial control system is found in two subparagraphs of §1030(a)(5). They are:

“(B) intentionally accesses a protected computer without authorization, and as a result of
such conduct, recklessly causes damage; or

“(C) intentionally accesses a protected computer without authorization, and as a result of
such conduct, causes damage and loss.”

The current language of §1030 does not define ‘accesses without authorization’ so there is certain amount of leeway that the courts have in interpreting that term. The definition provided in this bill, however, specifically requires that the access must be made “to obtain information on a protected computer” {§1030(e)(6)(A)}. Thus it appears that changing the programing of an ICS system or device would no longer be a federal offense under §1030, even if the attack resulted in ‘damage or loss’ intended or otherwise.

Moving Forward

I don’t see the House, in the current environment of concern about cybersecurity, taking up any legislation that has the appearance of reducing the seriousness of any kind of cybersecurity attack. The Senate version of this bill {S 1196 introduced by Sen. Wyden (D,OR)} may have an easier time getting considered, but I still don’t see it overcoming general cybersecurity concerns.


Including this in an authorization bill or an appropriations bill is not an option. This changes a criminal statute and thus cannot be included in spending bills according to both House and Senate rules. Including this (with some modifications) in a comprehensive cybersecurity bill would provide the best chance of passage, but no one is seriously pushing such a bill at this time.
 
/* Use this with templates/template-twocol.html */