Abstract
Users, particularly amateurs, face uncertainties about technology law related to both interpretation and enforcement. This uncertainty can have a chilling effect on how users experiment with technology. However, little is known about the precise uncertainties that users face and what kind of advice is available. Our paper focuses on user questions and advice surrounding the legality of port scanning, a dual-purpose technique used in both defensive and offensive security. We identified and analyzed 414 pieces of advice, in response to questions about the legality of port scanning from 36 Reddit threads. We find that users ask two types of questions: (1) reactive questions in which they have scanned and are concerned by the consequences; and (2) proactive questions in which they ask about legality and seek ways to comply with the law. We found no consensus in the advice about legality or the likelihood of prosecution. In justifying advice, users deployed a range of anecdotes, analogies, and URLs. Subtle variations on the analogy between port scanning and physical building security are used to explain why it is both legal and illegal. Users also reason from individual cases, such as arguing prosecution is unlikely because the user had not personally been prosecuted or arguing prosecution is likely because Aaron Swartz was prosecuted. Finally, the most influential URL was a “Legal Issues” page maintained as part of an open-source project. We reflect on how these results can inform forum moderation and public-policy dissemination.
| Original language | English |
|---|---|
| Title of host publication | EuroUSEC '24 |
| Subtitle of host publication | Proceedings of the 2024 European Symposium on Usable Security |
| Editors | Farzaneh Karegar, Ali Farooq |
| Place of Publication | New York, NY, United States |
| Publisher | Association for Computing Machinery (ACM) |
| Pages | 322-336 |
| Number of pages | 15 |
| ISBN (Electronic) | 9798400717963 |
| DOIs | |
| Publication status | Published - 20 Nov 2024 |
| Event | The 2024 European Symposium on Usable Security - Karlstad, Sweden Duration: 30 Sept 2024 → 1 Oct 2024 https://eurousec24.kau.se/ |
Symposium
| Symposium | The 2024 European Symposium on Usable Security |
|---|---|
| Abbreviated title | EuroUSEC 2024 |
| Country/Territory | Sweden |
| City | Karlstad |
| Period | 30/09/24 → 1/10/24 |
| Internet address |
Keywords / Materials (for Non-textual outputs)
- cybersecurity law
- offensive security
- security and privacy discourse
- content analysis
Fingerprint
Dive into the research topics of '"Just a tool, until you stab someone with it": Exploring Reddit users' questions and advice on the legality of port scans'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver