[32972] in North American Network Operators' Group
Re: Port scanning legal
daemon@ATHENA.MIT.EDU (Shawn McMahon)
Tue Dec 19 19:19:05 2000
Date: Tue, 19 Dec 2000 19:12:38 -0500
From: Shawn McMahon <smcmahon@eiv.com>
To: nanog@merit.edu
Message-ID: <20001219191238.B11617@eiv.com>
Mime-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-md5;
protocol="application/pgp-signature"; boundary="ZfOjI3PrQbgiZnxM"
Content-Disposition: inline
In-Reply-To: <20001219222327.6FDB635DC2@smb.research.att.com>; from smb@research.att.com on Tue, Dec 19, 2000 at 05:23:27PM -0500
Errors-To: owner-nanog-outgoing@merit.edu
--ZfOjI3PrQbgiZnxM
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
On Tue, Dec 19, 2000 at 05:23:27PM -0500, Steven M. Bellovin wrote:
>=20
> As always, your mileage may vary. California law specifically
> states that costs incurred by the victim include
>=20
> any expenditure reasonably and necessarily incurred by the
> owner or lessee to verify that a computer system, computer
> network, computer program, or data was or was not altered,
> deleted, damaged, or destroyed by the access.
>=20
> So checking out a scan might qualify. As for "access", it's defined as
>=20
> "Access" means to gain entry to, instruct, or communicate
> with the logical, arithmetical, or memory function resources
> of a computer, computer system, or computer network
In other words, as written, it means that if you pull up my web page, I can
bill you for my time checking the apache logs to make sure you weren't doing
anything wrong.
And, if you send me email, I can bill you for my time spent making sure it
didn't contain a virus.
I'm thinking that law is easily challenged on the basis of vagueness.
--ZfOjI3PrQbgiZnxM
Content-Type: application/pgp-signature
Content-Disposition: inline
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.1 (GNU/Linux)
Comment: For info see http://www.gnupg.org
iD8DBQE6P/l2Ecl9bQ0RMt0RAiICAKCQ2l//mx3DgJvhNtoliJk4QqZGRACfdCKx
XxaIUglSDY3wQHuqJdGDVW8=
=dLP3
-----END PGP SIGNATURE-----
--ZfOjI3PrQbgiZnxM--