Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think lawyers are still the new lawyers.

One of the major benefits of society is to remove the need for individuals to keep their own firepower. You're allowed to defend yourself, but the goal is to make it so you can feel safe in a city of 8 million people with no more than a heavy bag, cell phone, or can of mace.

In the digital world, you still need self-defense (network protections, strong passwords, small attack surface), but hopefully not everybody has to hire cyber-thugs to defend their turf. If another cyber-thug attacks you, you figure out who they are, call your lawyer, and let the state deal with it.

It's not perfect, but I'd think lawyers will learn unmasking techniques before corporations hire body-guard divisions full of black-hat crypto types. And international conflict is always messier...



Unfortunately lawyers still depend on the law as their weapon. And laws tend to respect borders whereas cyber weapons do not. The ability for a lawyer to defend against a cyber attack is incredibly limited.

I think the article addresses this in both suggesting these attacks are more common in China (where lawyers from other countries tend to be notoriously ineffective) and in the hypothetical scenario that corporations grow in power to be above the law.


That's also fortunate, because if some country has odd laws (and many do), at least their effects don't spread too much. Politicians and lawyers try their best to combat this (with laws as their weapon) through treaties.

It's really two-sided coin. On the other hand, average person don't have to to learn about technical stuff. On the other, there is also weird stuff like illegal numbers, battles on encryption, censorship, restrictions on reverse engineering and learning, all the copyright/DRM weirdness, and, on more common level, also a lot of uncertainity about if something's legal or not[1] (because, duh, engineering and lawmaking are completely different worlds and they mismatch heavily).

____

[1] You encounter a computer system. You just can't tell if it's legal to access it or not. And a smart lawyers can make it look both ways - it's not tech (where things are straightforward but harsh), just humans persuading other humans.


> You encounter a computer system. You just can't tell if it's legal to access it or not.

I find this point of view fascinating. Walking down the street, do you have any trouble telling which buildings are legal to access and which are not?

I would posit that there is nothing unclear about the law here. In meat-space, the social norm is clear: you go into other peoples' property only if you have business there, you go in through the front door, and once there, you do only what the owner would want you to do. Otherwise, your entry is illegal. Nobody complains that you can't tell just by looking at a building whether going inside is legal or not.

Some people resist this clear social norm in cyber-space. They want to posit a "right to tinker" or a "right to explore." It is that resistance that creates uncertainty, not the law.


> In meat-space, the social norm is clear

Local social norm, in your meat-space neighborhood, sure. Also, norms from the other places, if you've did the research, or if their norms are close enough to what you're used to so your behavior is compliant or at least tolerable (for a foreigner).

Still, nerd social awkwardness issues aside, I tend to believe there there are quite different social norms in drastically different meatspace areas.

On the Internet it's only worse. You can't even tell which country/jurisdiction the site you plan to visit belongs to (no, addresses from whois may be a continent away from the legal system site ToS mentions). I neither think there are universal laws regarding this (to best of my knowledge, there aren't), nor that you can always know whenever it's legal to click that link you saw someone had posted on IRC or not, or read that link's contents, or save it.

(Ever thought that "liking" a post on a social network can be a criminal offense punishable with a few years in jail? In some countries it could be.)


> In meat-space, the social norm is clear

I think it is only clear most of the time.

There are plenty of odd situations.

I might ask where the restroom is in a retail store and learn I need to walk through a back storage room to get there.

What if I walk into a business an it appears empty, as if the sole proprietor just walked out and forgot to lock it.

Where exactly is the dividing line between the park or field and the similar looking lawn.

If I am hiking in the woods and I come upon the back of a sign I will walk around to the front. If it says "Tresspassers will be shot" I really start to worry what I just walked through.

Cyberspace hasn't had time to work out good samaritan laws or castle doctrine and the only property are purely technical in nature. I mean, do I own the VM on a VPS host or does the VPS host, certainly I own the software on it I wrote and they own the host OS but where is that line? Then IP laws come into play...


Absolutely, "paper" trails through and walking along rivers and beaches bordered by private property are other interesting examples of where the law and "norms" of the situation are often pretty blurry. That's just land, computers are a whole other level of complexity, plus the "norms" are not yet decided.


While the situations you cite are relatively less common, I don't think the social norm in those situations is at all unclear. Walking through the back storage room to find the restroom after asking is fine, but doing so without asking isn't nor using is your bathroom trip to rifle through merchandise.

I think it's only us nerds with our low social sensitivity and literal minded-ness would think otherwise.


> Walking down the street, do you have any trouble telling which buildings are legal to access and which are not?

Do you expect the same response to hacking your local computer club as hacking the IRS?

There are more than one set of social norms on the internet.

The "I know it when I see it" test is useless because it does nothing in the cases where you actually need the test to decide anything. There was never any question what happens to someone who hacks the DoD and sells secrets to the Russians -- you don't need any kind of computer-specific laws for that because it's illegal regardless of how you do it.

The problem cases are the ones where the argument is over whether permission was implicit vs. absent vs. not required. For example, should it be illegal for a journalist to access internal documents a company published on their website but probably didn't intend to? What if the journalist has to guess the URL? And those seem to be exactly the sort of cases that can be charged only under the CFAA and not any other law.

> Some people resist this clear social norm in cyber-space. They want to posit a "right to tinker" or a "right to explore." It is that resistance that creates uncertainty, not the law.

A law the relies on social norms adopts the uncertainty inherent in the social norms. In the context of the internet where all cultures are together in the same "space" this gives the law more than the usual amount of uncertainty.

Which makes the problem one that is much easier to solve technically than legally. If you in fact prevent unauthorized access using technical means then there is no occasion to resort to legal process or contend with the uncertainty of differing social norms, which is already inherently necessary for extrajurisdictional attackers who aren't subject to legal process regardless.

And if the problem can (and for foreign attackers must) be addressed mainly through technical means then the justification for uncertain laws with harsh penalties is significantly eroded, while the cost in terms of chilling effects and potential for abuse is not reduced at all.


> In the digital world, you still need self-defense (network protections, strong passwords, small attack surface), but hopefully not everybody has to hire cyber-thugs to defend their turf. If another cyber-thug attacks you, you figure out who they are, call your lawyer, and let the state deal with it.

That doesn't actually work here. If someone attacks you from Russia or China or Nigeria, there are no lawyers that can help you.

The reason hack back is unwise and unnecessary is that you don't need deterrence to prevent cyber attacks. In meatspace anybody with a rock and two hands can steal your television and the defenses necessary to prevent that are significantly more expensive than relying on the state to use prison as a deterrent.

But it's a lot more practical to maintain a secure digital system than a secure physical system, because digital systems fail closed rather than fail open. If you can't pick a physical lock you can still break a window or bust down the door, but the equivalent brute force against digital systems yields only denial of service rather than unauthorized access.

That doesn't mean you can't screw it up. Possible to succeed is not the same as impossible to fail. But it means it's possible to have a good enough defense that you require no offense.


> If someone attacks you from Nigeria, there are no lawyers that can help you.

This statement is all shades of Wrong. In Nigeria at least, I know you can easily report to the Country's Economic and Financial Crimes Commission (EFCC), which is currently doing a very good job of getting back foreign stolen money through internet scams.


Your contention supposes that Nigerian scammers are stealing money because they're keen to invest in easily confiscated securities instruments rather than spending the money like it's burning a hole in their pocket. And that the purported successes of the Nigerian "EFCC" are real and typical rather than government propaganda from a government trying to spin their country's association with 419 scams. And that having your money stolen and then going through an international bureaucratic process to maybe get some of it back is in any way comparable to not having it stolen to begin with.

But let's suppose all of that is true. If someone in Nigeria steals your money, you pick up the phone and in five minutes they're in jail and your money is returned. Then you're doing this:

http://slatestarcodex.com/2014/05/12/weak-men-are-superweapo...

Because there are still many places where no such process is available. Many of the attacks from China are state-sponsored. Many of the attacks from Russia are from organized crime who have law enforcement on payroll. ISIS. You haven't done anything to refute the point, you're just arguing about which examples I should be using this year.


How is hiring a lawyer to defend yourself against legal attacks any different than hiring a "cyber-thug" to defend yourself against technical attacks?


Yes, lawyers are still needed. For the sake of brevity, I didn't call the title "Hackers are the new lawyers, but lawyers are still useful." :)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: