The Legal Risks That Chill Good-Faith Security Research
12 hours ago
- Anti-hacking laws like the U.S. CFAA and U.K. CMA are broad and ambiguous, failing to distinguish malicious hacking from good-faith security research, causing a 'chilling effect' that discourages valuable research.
- Contract law (e.g., terms of service) is the most cited legal risk, not anti-hacking laws; researchers face threats for violating terms when studying systems.
- Legal risks lead to 'stockpiling' of vulnerabilities, where researchers withhold findings due to fear of legal consequences, making them targets for hacking or coercion.
- Researchers report significant personal and emotional tolls, including fear, stress, and even incarceration, from legal threats arising from their work.
- Institutional lawyers often prioritize protecting the university over the researcher, while personal legal counsel can help de-escalate threats.
- The current political climate increases risks for researchers, with politically motivated legal threats and academic hostility, especially in social computing.
- Researchers are motivated by a sense of public service and duty to improve security, despite legal risks, and often rely on early legal advice and anonymity measures.
- Recommendations include developing contingency plans, company pledges, supportive publication policies, and government support for research disclosure.