The United States built the modern digital world, but a law born from the fear of a fictional teenage hacker helped ensure that the people most free to master its weaknesses would live somewhere else.
By Sid J.A. Hubbard
The Cold War had divided the world into two camps, each protected by nuclear weapons aimed at the other, when a teenage Matthew Broderick sat down at a computer and nearly ended civilization.
In the 1983 film WarGames, Broderick plays David Lightman, a bright, restless kid with a modem. He goes looking for unreleased computer games and finds a military system instead. Believing he is playing, he brings the United States and the Soviet Union to the edge of global thermonuclear war.
President Ronald Reagan watched the movie at Camp David. At a White House meeting soon afterward, he reportedly asked his national-security advisers whether something like it could really happen. The answer was alarming enough to accelerate work on federal computer-crime legislation.
The fear was understandable. Computers were leaving universities, corporations, and government facilities and entering American homes. Telephone lines connected them across distances that had once protected institutions from ordinary people. For the first time, a curious teenager could reach beyond his bedroom without physically going anywhere.
Congress responded first in 1984 and then more forcefully with the Computer Fraud and Abuse Act of 1986. The CFAA was intended to protect government, financial, and other sensitive systems from unauthorized access. But lawmakers were regulating a future they had not yet experienced. They placed enormous criminal weight on a word that would become less clear with every new network, service, account, device, license, and terms-of-use agreement.
Authorization.
The law divided people who knew how to use computers into two categories. One group was permitted to exercise its knowledge. The other could become felons for crossing a boundary defined by whoever controlled the machine.
Fraud, theft, destruction, extortion, espionage, and the disclosure of private information were already identifiable acts with identifiable consequences. The CFAA added a powerful federal charge at their common entrance: using a computer in a way the owner had not authorized. Prosecutors could then combine access charges with identity offenses, calculated losses, multiple counts, and the leverage of decades in prison.
America did not outlaw computer expertise. It did something more consequential. It made the unsanctioned acquisition of certain kinds of expertise extraordinarily dangerous for the people close enough to prosecute.
The rest of the world remained outside the boundary.
The Open Door
Imagine a bank at midnight. Its front door is standing open. A passerby notices, steps inside, calls out, takes nothing, and leaves. He telephones the bank to report the unlocked door.
The bank may object to his entry. Trespass law may have something to say about it. But he did not rob the bank. Robbery requires a robbery. Theft requires a taking. Burglary has its own elements. An open door does not erase the difference between noticing, entering, stealing, damaging, threatening, and reporting.
In computer law, that difference has often been much harder to preserve.
In 2010, Andrew Auernheimer, who called himself “weev,” and Daniel Spitler discovered that an AT&T web address associated with cellular iPads would return a subscriber’s email address when supplied with the device’s ICC-ID. The identifiers followed a predictable numerical pattern. There was no password to defeat. AT&T’s public server simply returned the information when asked the right numerical question.
Spitler wrote a script that asked repeatedly. The pair collected approximately 114,000 email addresses, demonstrating that the exposure was not an isolated mistake. Auernheimer eventually brought the problem to the press, and AT&T closed it.
The company received a repaired system. The public learned that prominent subscribers, including people in government and the military, had been exposed. Auernheimer received two felony convictions, a 41-month prison sentence, and an order to pay AT&T more than $73,000.
His conviction was later reversed because the government had prosecuted him in New Jersey, where no essential part of his conduct had occurred. By then, he had spent approximately a year in federal prison, including periods in solitary confinement.
Auernheimer is not a convenient martyr. His public life included vicious trolling, racist and antisemitic rhetoric, and later an enormous swastika tattoo across his chest. In a 2014 profile, he told journalist David Kushner that he had taught members of the Aryan Brotherhood in prison to sing “Springtime for Hitler.” His character does not resolve the legal question. Vulnerabilities are not distributed only to admirable people. A security system that can benefit only from discoveries made by agreeable, credentialed professionals is designed to ignore reality whenever reality chooses an objectionable messenger.
AT&T had left the door open. The outsiders who demonstrated how many people could be seen through it went to prison. The institution that created the exposure did not.
That teaches computer scientists something.
The Avalanche of Dumb
The federal government does not need to imprison every curious programmer to change how Americans learn. It needs only to demonstrate what it can do.
Aaron Swartz helped develop RSS, worked on Creative Commons, participated in the creation of Reddit, and became one of the most effective advocates for an open Internet. In the autumn of 2010, someone calling himself Gary Host, then Grace Host, and finally “ghost” began using MIT’s network to download academic articles from JSTOR.
MIT made that access unusually easy. A visitor could connect to its wired network as a guest for 14 days without identity verification. Staff had already expressed concern about weak or outdated controls around resources such as JSTOR. Swartz had a fellowship at Harvard and legal access to the archive there, but bulk downloading violated JSTOR’s terms. MIT, famous for openness and a culture of technically ambitious pranks called hacks, offered another route.
Swartz named his program keepgrabbing. Between the evening of September 25 and early the next morning, it downloaded approximately 450,000 articles. JSTOR blocked an address; the program returned from another. MIT disabled a device registration; Swartz changed the computer’s identifying information. He eventually acquired 4.8 million articles, approximately 80 percent of JSTOR’s archive.
The scale was immense. The institutional response was strangely slow.
MIT knew for roughly two and a half months which campus building contained the downloader before anyone searched for the machine, even while telling JSTOR it could not identify the person responsible. Staff speculated about a student experimenting with a robot and about foreign intruders using compromised credentials. JSTOR employees grew increasingly angry. MIT personnel sometimes regarded JSTOR’s reaction as excessive. A serious security event unfolded through delay, irritation, institutional mismatch, and guesses about a person nobody had tried very hard to find.
On January 4, 2011, a network engineer finally searched Building 16 and found a laptop beneath a cardboard box in a basement wiring closet. MIT police called a Cambridge detective assigned to an electronic-crimes task force. He arrived with a Secret Service agent.
They did not unplug the machine and close the incident. They installed a hidden camera and left the laptop operating so they could identify its owner and collect evidence. An MIT engineer monitored the traffic and accumulated approximately 70 gigabytes of it. Internal notes recorded that MIT was considered the victim and that what it provided investigators was voluntary rather than compelled by subpoena.
The camera identified Swartz. Police arrested him on January 6.
The revelation that the mysterious downloader was a famous programmer changed the tone but did not restore proportion. One MIT employee congratulated the prosecutor on the quality of the eventual indictment. Another circulated a fictional message mocking Swartz as though he were asking JSTOR to help him resume downloading, then added “LOL.”
Someone in MIT’s own IT security department saw the situation more clearly. Swartz, the employee wrote, was “a really intelligent kid that just got buried under an avalanche of dumb.”
The avalanche had no single author. It was built from an open guest network nobody had adequately secured, a database provider fearful for its business, months of delayed action, a police investigation allowed to gather momentum, voluntary institutional assistance, a federal statute broad enough to convert disputed access into felony leverage, and a university publicly committed to neutrality after its choices had already helped shape the prosecution.
The authorization question was not incidental. Swartz had entered MIT’s network through the guest access MIT offered visitors. MIT’s own posthumous review concluded that the institution paid little attention to whether this fact weakened the claim that his access was unauthorized. The defense raised the issue only near the end of Swartz’s life. A foundational element of the computer-crime case had almost disappeared beneath the machinery assembled to pursue it.
The conduct can be described accurately without pretending it was violence, espionage, or destruction. Swartz repeatedly evaded technical efforts to stop the downloading and placed equipment in a wiring closet. JSTOR recovered the files and ultimately said it had no interest in an ongoing legal matter. MIT did not ask prosecutors to seek prison time, but it also declined requests to oppose the prosecution.
Federal prosecutors continued. A superseding indictment charged Swartz with 13 felonies. The theoretical prison exposure was immense.
Swartz died by suicide in January 2013 before trial. His family and partner called his death the product of “a criminal justice system rife with intimidation and prosecutorial overreach.”
The avalanche did not stop when the case ended. Every student capable of understanding it learned that the difference between technical curiosity and federal ruin might be determined afterward, by institutions with resources the student could never match.
The most effective sentence is sometimes the one never imposed. It is the experiment not attempted, the vulnerability not confirmed, the independent researcher who chooses ordinary employment, and the technically gifted chil
Reader access
Human readers only beyond this point
This content is for human readers. To verify your humanity, enter an email address you have access to here.
Your email is stored only for this verification session. It is never used for spam or tracking, shared with anyone else, or treated as permission for anything beyond this single use.
Please open the email sent to and select
No profiles, behavioral tracking, or familiar login machinery: this small, original boundary protects writing from immediate collection by intelligent crawlers and preserves a place intended for human readers.