The Legal Risks That Chill Good-Faith Security Research | Lawfare
The upcoming main navigation can be gotten through utilizing the tab key. Any buttons that open a sub navigation can be triggered by the space or enter key.
Search Lawfare
Search
Advanced Search
Belen Pisaniello
Sunoo Park
Daniel R. Thomas
Meet The Authors
Subscribe to Lawfare
“I sent some emails warning people of a security incident and [law enforcement] c[a]me up at me with machine guns—that kind of doesn’t seem to balance.” — Anonymous<br>Anti-hacking laws, such as the U.S. Computer Fraud and Abuse Act and the U.K. Computer Misuse Act, exist to combat malicious hacking and protect digital infrastructure. But paradoxically, their broad and ambiguous scope can work against that very goal. Such laws often fail to clearly distinguish between malicious hacking and good-faith research, exposing researchers to serious legal risks for essential research activities.<br>This exposure can create a “chilling effect,” discouraging researchers from pursuing valuable work that could improve widespread understanding of technologies that millions of people rely on every day—and shed light on the ways those technologies can fail.<br>Despite widespread awareness of these risks within research communities, there is little empirical evidence on the practical impacts of legal risks or on researchers’ experiences navigating them. Much of what is known in the community persists as professional “folklore” or anecdotal accounts rather than systematic research, making it difficult to understand the full landscape of legal risks and to advocate effectively for policy change.<br>To address this gap, our recent paper examines the legal-risk experiences of researchers in the United States and the United Kingdom. It is the most comprehensive account to date of how legal risks affect computer science researchers and their work. We heard from dozens of researchers about their firsthand encounters with legal threats, how legal risks shape research decisions, and the norms and practices surrounding legal risk. We also spoke with lawyers and other professionals who collectively have helped thousands of researchers.<br>A few disclaimers: We keep all our participants anonymous, do not link their quotes together, and omit detailed context around quotes, to reduce identification risk. Our analysis is qualitative, and our discussion of trends is based largely on participants’ experiences and impressions of trends. Our dataset is diverse and not comparable in a quantitative sense.<br>We found that research-related legal risks are serious and commonplace; for some areas, they are almost unavoidable.<br>As one anonymous participant put it, “You can’t really have a functional security research career without taking some level of risk; there’s just not enough legal certainty.”<br>These risks shape researchers’ decisions in concrete ways. We found clear evidence of “chilling effects,” with researchers describing abandoning projects, withholding disclosure of findings, or avoiding certain research areas altogether due to legal risks. That said, some researchers persevered despite the legal risks, highlighting the importance of research for keeping systems safe and secure.<br>One particularly alarming manifestation of these chilling effects is “stockpiling,” in which researchers discover security vulnerabilities but choose not to disclose them out of fear of legal consequences. Instead, they hold onto this information, making it a prime target for hacking, bribery, and coercion. One researcher reported being approached by a mysterious individual offering a large sum of money to buy their stockpile and their silence. They said they did not sell, but shared that:<br>I did think about it though, right, like holy shit, that’s life-changing money. “I could move my entire family out of the ’hood” money, right—so it was an ethical debate for me.<br>Anti-hacking laws may be the most prominent source of concern, but they are not the primary one researchers named. Contract law was by far the most frequently cited area of legal risk; participants told us that essential research activities often involve possible violations of the terms of service of the systems studied, some of which contain extensive and onerous limitations on independent study of the systems and reporting of research findings. Explaining the importance of studying how these systems fail, one participant said: “Adversaries who are actually adversarial will not say, ‘Oh well it says in the terms of service we can’t do this and therefore we won’t do it.’”<br>The next most commonly mentioned sources of risk were the U.S. Computer Fraud and Abuse Act (CFAA), the U.S. Digital Millennium Copyright Act (DMCA), defamation, the U.K. Computer Misuse Act (CMA), and fraud, in that...