Law note · United States
Computer Fraud and Abuse Act (unauthorized access and the gates-based authorization test)
What it asks of an app
- Scraping a public, unauthenticated page does not by itself expose you to Computer Fraud and Abuse Act (CFAA) liability (hiQ Labs v. LinkedIn, 9th Cir. 2022).
- Do not continue accessing a site, or circumvent a technical block, after the operator has sent an individualized notice revoking your access (Facebook v. Power Ventures, 9th Cir. 2016).
- A CFAA win does not clear you of state-law exposure: hiQ itself was ultimately held liable under contract and trespass-to-chattels theories for the same conduct.
When LexLint raises it
crawls_web
What we found
The Computer Fraud and Abuse Act (CFAA) prohibits intentionally accessing a protected computer without authorization, or exceeding authorized access.
The Supreme Court held in Van Buren v. United States (593 U.S. 374, 2021) that exceeding authorized access is a gates-up-or-down inquiry into files or areas an existing permission structure puts off limits, not a purpose-based test, and the Ninth Circuit held in hiQ Labs v. LinkedIn (31 F.4th 1180, 2022) that without authorization does not reach a computer presumptively open to all comers, so a public, unauthenticated page has erected no gate at all.
The line runs through revocation: in Facebook v. Power Ventures (844 F.3d 1058, 9th Cir. 2016), discussed inside the hiQ opinion, liability attached once the scraper, after an individualized cease-and-desist, circumvented an IP block to keep reaching password-protected profiles. hiQ's own case did not end there: on remand it entered a stipulated consent judgment (N.D. Cal., filed Dec.
2022, secondary-sourced) holding it liable for breaching LinkedIn's User Agreement and for California trespass to chattels and misappropriation, for $500,000 and a permanent injunction, despite winning the CFAA claim outright. Section 1030 was added by the Counterfeit Access Device and Computer Fraud and Abuse Act of 1984, Pub.
L. 98-473, title II, § 2102(a); the without-authorization and exceeds-authorized-access language the courts above construe was already present in that original 1984 enactment, so this document dates the section to its original commencement rather than to the 1986 amendments that broadened its reach to protected computers generally.