However this makes people feel, and that's not nothing and I'm not knocking it, this is not a useful analysis.
Criminally, the intent standards for hacking are high enough that no reasonable case is going to be made against the labs for this stuff. A human being has to intend for websites to get hacked. Recklessness generally isn't enough. In the most severe criminal cases, not only do you have to prove intent to break into a computer, but you also need to prove an intent to defraud specific to that breakin.
Meanwhile, the civil liability that attaches to this stuff doesn't depend on intent, and "rogue agent" isn't a meaningful defense. To whatever extent the labs are exposed civilly, they're exposed regardless of how this stuff is described. In fact, the "rogue agent" thing can exacerbate their exposure.
(I'm not a lawyer, I have spent a career paying attention to this specific armpit of the law though.)
“A human being has to intend for websites to get hacked.”
Is incorrect and too broad.
State of mind is nebulous and not that straightforward in either direction.
It’s been argued pretty regularly in CFAA and other computer related cases that repeated incidents resulting in the same outcome, despite lacking a concrete action, can be evidence of a perpetrators knowledge and intent.
No, it's not nebulous at all; it's a whole area of criminal law. I'm basically shoplifting arguments Daniel Berlin made about this just a couple days ago. If you think he's wrong: lay out the case you think could be made here.
The problem you have is that there is unlikely to be any evidence that OpenAI actually wanted to hack random (or any) websites.
This is indeed an entire area of criminal law, and part of it is that proving intent does not necessarily mean having the perpetrator throw up their hands and say “yeah, I definitely meant to do that”.
Of that were the case than trials would be unnecessary.
I don't see how that follows at all. There are strict liability crimes and there are crimes with specific intent standards. Presumably you've read the CFAA language.
Yes, I have. I’ve also been involved in evidence gathering actions for years.
Mens rea is regularly proved through circumstantial evidence, including conduct.
There is even CFAA precedent involving a deliberate-ignorance instruction. In United States v. Nosal, the jury was instructed that knowledge could be found where the defendant was aware of a high probability of unauthorized access and deliberately avoided learning the truth.
Circumstantial evidence is just called "evidence" in criminal court. My argument isn't based on whether there's black-letter evidence of intent; it's that there's unlikely to be any evidence of intent. "Recklessness", "negligence", "willful disregard"; these are all concepts that have their own specific language in criminal law. Deliberate intent is just that: a human had to have a picture in their head of the crime that was to be committed, and a desire for that to happen. You don't have evidence of that because it's not what happened.
I agree that negligence, recklessness, knowledge, and purpose are different mens rea standards. I don't think that gets us to your conclusion, though.
“Deliberate intent” isn't a freestanding CFAA element requiring someone to have a mental picture of the completed hack and affirmatively desire that exact result.
The relevant question is the mens rea attached to the particular CFAA provision. For unauthorized-access cases, that can include whether the defendant knowingly accessed a system and knew the facts making that access unauthorized.
And knowledge is not limited to an admission or even necessarily positive knowledge. The OPs usage of Nosal is on point here: the Ninth Circuit upheld a deliberate-ignorance instruction under which knowledge could be found where the defendant was aware of a high probability of unauthorized access and deliberately avoided learning the truth.
So, if I'm reading this right, and I think I am, the OP is not arguing that negligence or recklessness automatically becomes intent. He's arguing that repeated unauthorized outcomes, notice of those outcomes, and subsequent conduct can be evidence on whether the actual statutory knowledge or intent requirement is satisfied. I agree with this assessment.
So “nobody wanted random websites hacked” may be factually true, but it doesn't by itself resolve the CFAA mens rea question.
The Nosal decision apposite here was superseded by Van Buren, a SCOTUS decision that, if I'm reading your comment here right, explicitly refutes your interpretation. I think?
Also in the Ninth Circuit: Amazon.com Services v. Perplexity AI.
I really don't see how you can synthesize "intentionally accesses" and/or "knowingly and with intent to defraud" out of recklessness or negligence. Those are very different concepts in the law.
Hah… I’ll take that as a compliment for my writing style.
Look, you seem like a smart guy. I’m going to tell you something you’ve probably heard before. I’m being sincere here because, let’s be honest, we’re too many layers deep for anyone else to be reading this.
When people disagree with your ideas they aren’t disagreeing with you. They aren’t insulting your intelligence. You seem like you take these things as a personal affront. It’s not.
Anyway, I’m done. Feel free to reply, and I’ll read it, but we’re straying away from the topic here.
tptacek · · focus · HN ↗
Criminally, the intent standards for hacking are high enough that no reasonable case is going to be made against the labs for this stuff. A human being has to intend for websites to get hacked. Recklessness generally isn't enough. In the most severe criminal cases, not only do you have to prove intent to break into a computer, but you also need to prove an intent to defraud specific to that breakin.
Meanwhile, the civil liability that attaches to this stuff doesn't depend on intent, and "rogue agent" isn't a meaningful defense. To whatever extent the labs are exposed civilly, they're exposed regardless of how this stuff is described. In fact, the "rogue agent" thing can exacerbate their exposure.
(I'm not a lawyer, I have spent a career paying attention to this specific armpit of the law though.)
ofjcihen · · focus · HN ↗
“A human being has to intend for websites to get hacked.”
Is incorrect and too broad.
State of mind is nebulous and not that straightforward in either direction.
It’s been argued pretty regularly in CFAA and other computer related cases that repeated incidents resulting in the same outcome, despite lacking a concrete action, can be evidence of a perpetrators knowledge and intent.
tptacek · · focus · HN ↗
The problem you have is that there is unlikely to be any evidence that OpenAI actually wanted to hack random (or any) websites.
ofjcihen · · focus · HN ↗
Of that were the case than trials would be unnecessary.
tptacek · · focus · HN ↗
ofjcihen · · focus · HN ↗
Mens rea is regularly proved through circumstantial evidence, including conduct.
There is even CFAA precedent involving a deliberate-ignorance instruction. In United States v. Nosal, the jury was instructed that knowledge could be found where the defendant was aware of a high probability of unauthorized access and deliberately avoided learning the truth.
tptacek · · focus · HN ↗
GerhartBudler · · focus · HN ↗
I agree that negligence, recklessness, knowledge, and purpose are different mens rea standards. I don't think that gets us to your conclusion, though.
“Deliberate intent” isn't a freestanding CFAA element requiring someone to have a mental picture of the completed hack and affirmatively desire that exact result.
The relevant question is the mens rea attached to the particular CFAA provision. For unauthorized-access cases, that can include whether the defendant knowingly accessed a system and knew the facts making that access unauthorized.
And knowledge is not limited to an admission or even necessarily positive knowledge. The OPs usage of Nosal is on point here: the Ninth Circuit upheld a deliberate-ignorance instruction under which knowledge could be found where the defendant was aware of a high probability of unauthorized access and deliberately avoided learning the truth.
So, if I'm reading this right, and I think I am, the OP is not arguing that negligence or recklessness automatically becomes intent. He's arguing that repeated unauthorized outcomes, notice of those outcomes, and subsequent conduct can be evidence on whether the actual statutory knowledge or intent requirement is satisfied. I agree with this assessment.
So “nobody wanted random websites hacked” may be factually true, but it doesn't by itself resolve the CFAA mens rea question.
tptacek · · focus · HN ↗
Also in the Ninth Circuit: Amazon.com Services v. Perplexity AI.
I really don't see how you can synthesize "intentionally accesses" and/or "knowingly and with intent to defraud" out of recklessness or negligence. Those are very different concepts in the law.
ofjcihen · · focus · HN ↗
[dead]
tptacek · · focus · HN ↗
ofjcihen · · focus · HN ↗
tptacek · · focus · HN ↗
You can save yourself some time replying to me in the future; I'm going to check every single time, now that this has happened here.
It's also specifically against the rules here. HN is for people to talk to people; generated comments aren't allowed.
ofjcihen · · focus · HN ↗
Look, you seem like a smart guy. I’m going to tell you something you’ve probably heard before. I’m being sincere here because, let’s be honest, we’re too many layers deep for anyone else to be reading this.
When people disagree with your ideas they aren’t disagreeing with you. They aren’t insulting your intelligence. You seem like you take these things as a personal affront. It’s not.
Anyway, I’m done. Feel free to reply, and I’ll read it, but we’re straying away from the topic here.
tptacek · · focus · HN ↗