The United States built the modern digital world, but a law born from the fear of a fictional teenage hacker helped ensure that the people most free to master its weaknesses would live somewhere else.
By Sid J.A. Hubbard
The Cold War had divided the world into two camps, each protected by nuclear weapons aimed at the other, when a teenage Matthew Broderick sat down at a computer and nearly ended civilization.
In the 1983 film WarGames, Broderick plays David Lightman, a bright, restless kid with a modem. He goes looking for unreleased computer games and finds a military system instead. Believing he is playing, he brings the United States and the Soviet Union to the edge of global thermonuclear war.
President Ronald Reagan watched the movie at Camp David. At a White House meeting soon afterward, he reportedly asked his national-security advisers whether something like it could really happen. The answer was alarming enough to accelerate work on federal computer-crime legislation.
The fear was understandable. Computers were leaving universities, corporations, and government facilities and entering American homes. Telephone lines connected them across distances that had once protected institutions from ordinary people. For the first time, a curious teenager could reach beyond his bedroom without physically going anywhere.
Congress responded first in 1984 and then more forcefully with the Computer Fraud and Abuse Act of 1986. The CFAA was intended to protect government, financial, and other sensitive systems from unauthorized access. But lawmakers were regulating a future they had not yet experienced. They placed enormous criminal weight on a word that would become less clear with every new network, service, account, device, license, and terms-of-use agreement.
Authorization.
The law divided people who knew how to use computers into two categories. One group was permitted to exercise its knowledge. The other could become felons for crossing a boundary defined by whoever controlled the machine.
Fraud, theft, destruction, extortion, espionage, and the disclosure of private information were already identifiable acts with identifiable consequences. The CFAA added a powerful federal charge at their common entrance: using a computer in a way the owner had not authorized. Prosecutors could then combine access charges with identity offenses, calculated losses, multiple counts, and the leverage of decades in prison.
America did not outlaw computer expertise. It did something more consequential. It made the unsanctioned acquisition of certain kinds of expertise extraordinarily dangerous for the people close enough to prosecute.
The rest of the world remained outside the boundary.
The Open Door
Imagine a bank at midnight. Its front door is standing open. A passerby notices, steps inside, calls out, takes nothing, and leaves. He telephones the bank to report the unlocked door.
The bank may object to his entry. Trespass law may have something to say about it. But he did not rob the bank. Robbery requires a robbery. Theft requires a taking. Burglary has its own elements. An open door does not erase the difference between noticing, entering, stealing, damaging, threatening, and reporting.
In computer law, that difference has often been much harder to preserve.
In 2010, Andrew Auernheimer, who called himself “weev,” and Daniel Spitler discovered that an AT&T web address associated with cellular iPads would return a subscriber’s email address when supplied with the device’s ICC-ID. The identifiers followed a predictable numerical pattern. There was no password to defeat. AT&T’s public server simply returned the information when asked the right numerical question.
Spitler wrote a script that asked repeatedly. The pair collected approximately 114,000 email addresses, demonstrating that the exposure was not an isolated mistake. Auernheimer eventually brought the problem to the press, and AT&T closed it.
The company received a repaired system. The public learned that prominent subscribers, including people in government and the military, had been exposed. Auernheimer received two felony convictions, a 41-month prison sentence, and an order to pay AT&T more than $73,000.
His conviction was later reversed because the government had prosecuted him in New Jersey, where no essential part of his conduct had occurred. By then, he had spent approximately a year in federal prison, including periods in solitary confinement.
Auernheimer is not a convenient martyr. His public life included vicious trolling, racist and antisemitic rhetoric, and later an enormous swastika tattoo across his chest. In a 2014 profile, he told journalist David Kushner that he had taught members of the Aryan Brotherhood in prison to sing “Springtime for Hitler.” His character does not resolve the legal question. Vulnerabilities are not distributed only to admirable people. A security system that can benefit only from discoveries made by agreeable, credentialed professionals is designed to ignore reality whenever reality chooses an objectionable messenger.
AT&T had left the door open. The outsiders who demonstrated how many people could be seen through it went to prison. The institution that created the exposure did not.
That teaches computer scientists something.
The Avalanche of Dumb
The federal government does not need to imprison every curious programmer to change how Americans learn. It needs only to demonstrate what it can do.
Aaron Swartz helped develop RSS, worked on Creative Commons, participated in the creation of Reddit, and became one of the most effective advocates for an open Internet. In the autumn of 2010, someone calling himself Gary Host, then Grace Host, and finally “ghost” began using MIT’s network to download academic articles from JSTOR.
MIT made that access unusually easy. A visitor could connect to its wired network as a guest for 14 days without identity verification. Staff had already expressed concern about weak or outdated controls around resources such as JSTOR. Swartz had a fellowship at Harvard and legal access to the archive there, but bulk downloading violated JSTOR’s terms. MIT, famous for openness and a culture of technically ambitious pranks called hacks, offered another route.
Swartz named his program keepgrabbing. Between the evening of September 25 and early the next morning, it downloaded approximately 450,000 articles. JSTOR blocked an address; the program returned from another. MIT disabled a device registration; Swartz changed the computer’s identifying information. He eventually acquired 4.8 million articles, approximately 80 percent of JSTOR’s archive.
The scale was immense. The institutional response was strangely slow.
MIT knew for roughly two and a half months which campus building contained the downloader before anyone searched for the machine, even while telling JSTOR it could not identify the person responsible. Staff speculated about a student experimenting with a robot and about foreign intruders using compromised credentials. JSTOR employees grew increasingly angry. MIT personnel sometimes regarded JSTOR’s reaction as excessive. A serious security event unfolded through delay, irritation, institutional mismatch, and guesses about a person nobody had tried very hard to find.
On January 4, 2011, a network engineer finally searched Building 16 and found a laptop beneath a cardboard box in a basement wiring closet. MIT police called a Cambridge detective assigned to an electronic-crimes task force. He arrived with a Secret Service agent.
They did not unplug the machine and close the incident. They installed a hidden camera and left the laptop operating so they could identify its owner and collect evidence. An MIT engineer monitored the traffic and accumulated approximately 70 gigabytes of it. Internal notes recorded that MIT was considered the victim and that what it provided investigators was voluntary rather than compelled by subpoena.
The camera identified Swartz. Police arrested him on January 6.
The revelation that the mysterious downloader was a famous programmer changed the tone but did not restore proportion. One MIT employee congratulated the prosecutor on the quality of the eventual indictment. Another circulated a fictional message mocking Swartz as though he were asking JSTOR to help him resume downloading, then added “LOL.”
Someone in MIT’s own IT security department saw the situation more clearly. Swartz, the employee wrote, was “a really intelligent kid that just got buried under an avalanche of dumb.”
The avalanche had no single author. It was built from an open guest network nobody had adequately secured, a database provider fearful for its business, months of delayed action, a police investigation allowed to gather momentum, voluntary institutional assistance, a federal statute broad enough to convert disputed access into felony leverage, and a university publicly committed to neutrality after its choices had already helped shape the prosecution.
The authorization question was not incidental. Swartz had entered MIT’s network through the guest access MIT offered visitors. MIT’s own posthumous review concluded that the institution paid little attention to whether this fact weakened the claim that his access was unauthorized. The defense raised the issue only near the end of Swartz’s life. A foundational element of the computer-crime case had almost disappeared beneath the machinery assembled to pursue it.
The conduct can be described accurately without pretending it was violence, espionage, or destruction. Swartz repeatedly evaded technical efforts to stop the downloading and placed equipment in a wiring closet. JSTOR recovered the files and ultimately said it had no interest in an ongoing legal matter. MIT did not ask prosecutors to seek prison time, but it also declined requests to oppose the prosecution.
Federal prosecutors continued. A superseding indictment charged Swartz with 13 felonies. The theoretical prison exposure was immense.
Swartz died by suicide in January 2013 before trial. His family and partner called his death the product of “a criminal justice system rife with intimidation and prosecutorial overreach.”
The avalanche did not stop when the case ended. Every student capable of understanding it learned that the difference between technical curiosity and federal ruin might be determined afterward, by institutions with resources the student could never match.
The most effective sentence is sometimes the one never imposed. It is the experiment not attempted, the vulnerability not confirmed, the independent researcher who chooses ordinary employment, and the technically gifted child whose parents advise him not to touch anything that might answer unexpectedly.
America retained excellent computer-science programs. It retained elite intelligence agencies, military units, security companies, and corporate red teams. But it made the unsanctioned path into adversarial mastery hazardous. Employers could hire only from the population that still arrived at the door.
The People Without a Door
Anonymous revealed another possibility.
The name emerged partly from the design of 4chan, where people who posted without identifying themselves appeared as “Anonymous.” On the /b/ board, the conversation could be juvenile, cruel, offensive, surreal, inventive, and brilliant in the same hour. No membership survived from one post to the next. The speaker disappeared, but the message remained.
In 2008, that form collided with the Church of Scientology.
Scientology had faced critics for decades. Former members, journalists, publishers, Usenet participants, and website operators had endured investigations, legal demands, and litigation. The organization knew how to make criticism expensive for the identifiable person or institution responsible for it.
Then it attempted to suppress circulation of a video featuring Tom Cruise. Anonymous responded with Project Chanology, first through online attacks and spectacle and then through worldwide street protests. Thousands of people appeared in Guy Fawkes masks.
Anonymous was not the first opposition to Scientology. It was the first opposition whose complete form did not have to survive litigation. Individual participants could still be identified, threatened, arrested, or sued. But Anonymous had no headquarters to raid, treasury to exhaust, leader to enjoin, or permanent legal body to drag through court. Litigation could reach a person. It could not finish the name.
The United States eventually found many of the bodies beneath Anonymous operations. Young participants were investigated, prosecuted, recruited as informants, sentenced, and separated from the communities where their skills had formed. Some operations caused real damage. Some exposed private information. Some involved fraud, threats, or destructive acts. Those offenses need not be romanticized to recognize what else was lost.
America had produced a generation of technically capable, politically motivated young people who believed computer systems could be made to answer to the public. The government developed a visible route for turning them into defendants and informants. It developed no equally visible route for retaining their adversarial ability as a public asset.
Some went silent. Some entered conventional jobs. Some continued from abroad. Some became more destructive. Others simply learned the lesson before participating.
The American hacker remained powerful in movies. In life, the most familiar hacker became Russian, Chinese, North Korean, or Iranian.
The Harvest
This geographical reversal is usually explained as a difference in state sponsorship, criminal markets, economic opportunity, or political tolerance. All of those matter. But another asymmetry sits in plain view.
The United States can impose American computer law upon people inside its reach. It cannot impose the same restrictions upon every person examining American technology from abroad.
The knowledge does not disappear when its domestic acquisition becomes dangerous. The machines remain available. The protocols still operate. The mistakes are still present. The financial and strategic rewards for finding them continue to grow.
Connected systems constantly regenerate valuable material: credentials, payment records, medical histories, industrial plans, private communications, intelligence, computational capacity, and access to other systems. Attackers search this expanding field for an opening. They do not need to defeat every defense. One sufficiently valuable success can pay for thousands of failures.
This is a harvest economy. The victim continually finances and regenerates what can be harvested. After a breach, the system is repaired, repopulated with data, expanded through new features, and connected to more services. The harvest grows back.
The defender must protect many boundaries continuously. The attacker needs one opening at the right time. Security therefore depends upon discovering flaws before the population seeking to exploit them. Restricting domestic experimentation does not reduce the global supply of experimentation. It changes who is most free to perform it.
The country that built the systems increasingly meets them from the victim’s side.
Dominion Without Mastery
In January 2012, armed New Zealand police arrived by helicopter and vehicle at Kim Dotcom’s mansion. The operation was conducted in response to a sealed American indictment against Megaupload, then one of the world’s largest file-storage services.
Megaupload was not a searchable catalogue like YouTube. Users uploaded files and received generated URLs. Another person generally needed to possess the URL to retrieve the file. Copyright owners used an abuse system to identify particular links and demand their removal, but the company received no cease-and-desist demand announcing that the United States considered the entire enterprise a criminal conspiracy. According to its outside counsel, Megaupload learned about the indictment through the Justice Department’s public announcement.
Helicopters and guns became the government’s first direct explanation.
American authorities could assert power over a foreign computational system, but they could not surgically separate every lawful file from every alleged infringement while preserving the service and the property of innocent users. They could take the domain names, freeze or seize infrastructure, arrest the founder, and make the system disappear.
It was dominion expressed through force rather than technical mastery.
The distinction matters because power over a computer system and knowledge of a computer system are not the same thing. A government may be capable of destroying a platform it cannot preserve, separating a programmer from a keyboard it cannot fully understand, or frightening students away from experiments its foreign adversaries perform every day.
Enforcement can create the appearance of control while knowledge moves elsewhere.
Artificial Intelligence Is Next
The same mistake is now forming around artificial intelligence.
American companies and universities built much of the hardware, software, research, and industrial capacity behind modern AI. But these systems cannot be understood solely through their intended uses. They must be prompted adversarially, connected to tools, induced to fail, and examined under conditions their designers did not anticipate.
The most important capability may appear first to someone behaving in a way the operator did not approve.
There are legitimate reasons to restrict access. AI systems can expose private information, facilitate intrusion, manipulate users, and act through connected services. But foreign laboratories, intelligence agencies, criminal groups, independent communities, and curious individuals will not all accept the same limits.
If Americans are permitted to invent AI but not to explore it with comparable freedom, invention and operational understanding will separate again.
America may invent the intelligence. Someone else will learn what it can do.
Return the Computer
The CFAA is politically difficult to repeal, and repeal is not necessary to change the incentive it created.
The intervention can be much narrower: unauthorized computer access, standing alone, should not expose an American citizen to a federal felony under the CFAA. If the person steals, destroys, extorts, spies, threatens, defrauds, or commits another felony, prosecute that felony. The serious punishment should belong to the serious act, not automatically to the use of a computer that preceded it.
Foreign actors would remain exposed to the statute’s full felony reach. The purpose is strategic and unapologetically domestic: restore Americans’ freedom to acquire practical knowledge of American systems without giving every act of curiosity the potential to end a life and career.
This would not create an official corps, registration program, disclosure portal, or government-managed hacker reserve. The domestic red team already exists wherever Americans test the systems around them, exceed intended uses, find unplanned behavior, and force machines to reveal what they can do. It is organic because no institution selected its members. It is anonymous because anonymity is often the only protection available before an institution decides whether to welcome a discovery or prosecute its discoverer.
Professional red teams are expensive because adversarial thought is difficult to produce on command. Outside those contracts, the networked world generates adversarial pressure continuously and without an invoice. Some of it is careless. Some is malicious. Some is more original than a paid test precisely because it is not limited by the assumptions of the organization commissioning it.
The law should stop converting that entire domestic capacity into presumptive criminality at the moment it becomes useful.
America invented the computers. It built the networks, operating systems, cloud platforms, and artificial intelligence. Then it confused control of the user with control of the machine.
The machines continued doing things their makers had not anticipated.
The people with the greatest freedom to follow them learned where they went.
Reporting Notes and Principal Sources
- Computer Fraud and Abuse Act of 1986, H.R. 4718, 99th Congress; current 18 U.S.C. § 1030.
- Congressional Research Service, Cybercrime and the Law: Primer on the Computer Fraud and Abuse Act and Related Statutes.
- Electronic Frontier Foundation, United States v. Andrew Auernheimer case archive.
- David Kushner, “We All Got Trolled,” Matter, July 22, 2014.
- United States Department of Justice, United States v. Aaron Swartz, superseding indictment.
- Family and partner of Aaron Swartz, “Official Statement from Family and Partner of Aaron Swartz,” January 12, 2013.
- Marcella Bombardieri, “The Inside Story of MIT and Aaron Swartz,” The Boston Globe, March 30, 2014; republished by Linux Security Blog.
- Gabriella Coleman, Hacker, Hoaxer, Whistleblower, Spy: The Many Faces of Anonymous.
- Electronic Frontier Foundation, “EFF Opposes Scientology Censorship and Attacks on System Operators,” 1995.
- United States Department of Justice, Megaupload indictment announcement, January 2012.
- High Court of New Zealand, Dotcom v Minister of Justice [2025] NZHC 2634.