HomeSecuritySharing passwords is considered hacking under the CFAA

The sharing of passwords is considered hacking according to the CFAA

The 9th Circuit Court of Appeals in California ruled that if a person willingly uses a password shared with someone else, it still constitutes a “hacking” offense in some circumstances, under the ancient CFAA law.
The court ruled on an appeal from a case that began in 2008, when David Nosal was charged with hacking offenses under the CFAA.

hacking

According to the original indictment, Nosal, a former Korn/Ferry employee, had resigned from the company to start his own business.

After leaving the company and having lost access to the company's IT network, Nosal asked his former secretary to provide him with her details for his former employer's network, which she did.

He also did the same thing to two other Korn/Ferry employees after promising them jobs at his new company.

Korn/Ferry, when it discovered what Nosal had done, filed a complaint with the authorities.
In 2008, criminal charges were filed, and in 2013 Nosal was found guilty by a jury after a trial.

In early 2014, a U.S. district court sentenced Nosal to one year and one day in prison, along with a $60,000 fine.
Nosal appealed, arguing that authorities had misinterpreted the CFAA and that he had not carried out any actual hacking attacks.

In a published decision, the appeals court explains that the CFAA was enacted to prohibit and prevent unauthorized access.

Judge Reinhardt said that this decision does not criminalize all people who engage in password sharing, but only those who use such social engineering tricks to gain access to services for which their access rights had been revoked, as was the case in Nosal.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS