Chilling Effect of the Enforcement of Computer Misuse Act: Evidence from Publicly Accessible Hack Forums

成果类型:
Article
署名作者:
Wang, Qiu-Hong; Geng, Ruibin; Kim, Seung Hyun
署名单位:
National University of Singapore; Xi'an Jiaotong University; Yonsei University
刊物名称:
INFORMATION SYSTEMS RESEARCH
ISSN/ISSBN:
1047-7047
DOI:
10.1287/isre.2019.0346
发表日期:
2024
页码:
1195-1215
关键词:
deterrence uncertainty INFORMATION IDENTITY IMPACT RISK
摘要:
To reduce the availability of hacking tools for use in cybersecurity offenses, many countries have enacted computer misuse acts (CMAs) that criminalize the production, distribution, and possession of such tools with criminal intent. However, the dual-use nature of cybersecurity technology complicates the legal process of recognizing such computer misuse tools and of predicting harmful intent based on mere possession. This predicament introduces the possibility of unfounded prosecution that may produce a chilling effect on the provision of techniques otherwise valuable in maintaining cybersecurity and defending against hackers. This study establishes a theoretical foundation for the potentially chilling effect of such legal enforcement by adopting theories about choice under uncertainty. Leveraging an external shock in publicly accessible online hack forums, we examined the impact of CMA enforcement on users' contributions to cybersecurityrelevant topics that are not targeted by the law. We found that CMA enforcement reduces the quantity and the extent of relevance to cybersecurity in discussions in hack forums. We further identified the mechanisms of this chilling effect by delving into users' heterogeneity in responding to the uncertainty of false prosecution imposed by CMA enforcement as well as users' proactivity undertaken to alleviate such uncertainty. Our study reveals this chilling effect is not just about restraining individuals from lawful acts but also about how they refrain from acts not intended as targets of the law.
来源URL: