The Security Researcher’s Dilemma: When Legitimate Vulnerability Testing Starts Looking Like a Federal Computer Crime
The people who find flaws in software before criminals do occupy a strange legal space. Their work protects users, vendors, and infrastructure, and on a server log it looks almost identical to the work of the criminals they’re trying to beat. The Computer Fraud and Abuse Act was written broadly enough to reach both, and it’s been used against both.
Here’s where the line sits today: what the statute still covers, what the Supreme Court narrowed, what the Justice Department has said it won’t charge, and what a researcher can do to stay on the safer side of a blurry boundary.
Two Framings of the Same Keystrokes
A researcher and a prosecutor can look at the same packet capture and see very different things. The researcher sees a probe of a login flow that surfaced a broken authorization check. The prosecutor sees access to a system the researcher wasn’t invited into, followed by retrieval of data that wasn’t theirs.
Both framings can be technically accurate. What separates them is context. Was there permission? Was the scope respected? Was the intent to fix the flaw or to profit from it?
The CFAA doesn’t require malicious intent to charge unauthorized access. That’s the problem. Good work and bad work leave similar logs.
The Old Reading Versus the Van Buren Reading
Before 2021, some federal courts read the CFAA’s “exceeds authorized access” clause expansively, treating a violation of a written policy as a potential federal crime. Under that reading, clicking past a terms-of-service checkbox to scrape a public page could be charged the same as breaking into a server.
The Supreme Court narrowed that view in Van Buren. The Court adopted a gates-up-or-down approach: you exceed authorized access when you enter parts of a system that are off-limits to you, not when you use permitted access for a purpose someone dislikes. For researchers who stay within systems they were allowed to touch, that’s a meaningful narrowing. It offers little cover for someone who pivots into a database they weren’t given keys to.
Good-Faith Research Versus Everything That Looks Like It
The Department of Justice’s 2022 charging policy formalized something researchers had been arguing for years. The Justice Manual now instructs federal prosecutors not to bring CFAA charges when the conduct is genuinely good-faith security research. That’s a real change in posture. It isn’t a statute, it isn’t immunity, and a future administration can revise it.
The policy also draws a sharp line around what doesn’t qualify. Testing done to extort the owner of a device or service isn’t research, no matter what the person doing it calls it. The same goes when “research” is a cover story for selling access, dumping data, or embarrassing a company into paying a fee. Prosecutors read those signals the way anyone else would.
Bug Bounty Programs Versus Cold Testing
A published vulnerability disclosure policy or bounty program is the closest thing to a legal safe harbor a researcher gets. The scope document tells you which assets are in play, what techniques are allowed, and how to report. Federal agencies operate under a similar framework: CISA’s BOD 20-01 pushed civilian agencies to publish disclosure policies so outside researchers know where the fences are.
Cold testing, meaning probing a company that never invited you, is a different animal. Even a benign finding, reported politely, can land on a general counsel’s desk as unauthorized access. Some companies say thank you. Some send a cease-and-desist.
A few refer the matter to the FBI. The researcher can’t know in advance which type of company they’ve picked, and the CFAA doesn’t grade on intent.
When Each Path Wins
Working inside a written program is the safer path almost every time. The scope is your permission slip, the report channel is documented, and the company has already decided it wants outside eyes on the asset. If a dispute arises later, the paperwork exists.
Cold testing wins in one narrow case: a serious, time-sensitive flaw in a system with no disclosure channel, where sitting on the finding is worse than the risk of surfacing it. Even then, restraint pays. Confirm the flaw with the least intrusive proof, contact the vendor through counsel if the exposure is significant, and never touch user data.
If a federal agent shows up before the vendor responds, that is the moment to stop talking and call a cybercrime defense lawyer. Volunteering context to investigators without counsel is how good-faith researchers become defendants.
The Line Isn’t Technical, It’s Documentary
Two researchers can run identical tools against identical targets and end up in different places. The one with written authorization, a narrow scope, minimal data pulled, and a clean disclosure trail has a story that fits inside the good-faith framing. The one who improvised has a story that depends on a prosecutor’s charity.
The CFAA is still broad, the policy protecting researchers is still policy, and Van Buren didn’t erase the risk of an aggressive charging decision. Build the paper trail before you need it. That habit is what separates the work that keeps the internet safer from the work that becomes a federal case.
