Skip to content
SPECIAL

THREATS TO CRITICAL INFRASTRUCTURE IN IRAN CONFLICT

READ MORE

The legal risks that chill good-faith security research

(Lee Campbell / Unsplash)

By Belen Pisaniello, Sunoo Park and Daniel R. Thomas

“I sent some emails warning people of a security incident and [law enforcement] c[a]me up at me with machine guns—that kind of doesn’t seem to balance.” — Anonymous

Anti-hacking laws, such as the U.S. Computer Fraud and Abuse Act and the U.K. Computer Misuse Act, exist to combat malicious hacking and protect digital infrastructure. But paradoxically, their broad and ambiguous scope can work against that very goal. Such laws often fail to clearly distinguish between malicious hacking and good-faith research, exposing researchers to serious legal risks for essential research activities.

This exposure can create a “chilling effect,” discouraging researchers from pursuing valuable work that could improve widespread understanding of technologies that millions of people rely on every day—and shed light on the ways those technologies can fail.

Read more at Lawfare

Click to listen highlighted text!