Ask HN: What's current U.S. law regarding building and deployment of honeypots?
1 comments
I remember discussing this in a Computer Crime Law class, and it might fall under Wiretap laws because you might be recoding real time user input.
Yes, I recall reading a few articles about that. I wasn't clear, however, whether if you can meet the criteria for the "exceptions" if there could be another law somewhere that you could still get hit with. If I am serious about this gig, I'd really have to lawyer up since my legal knowledge is only going to get me in trouble :-)
I have lots of links to information on the topic that I've gathered published since the mid-2000s and this SANS document has always been my goto:
http://www.sans.org/reading-room/whitepapers/legal/cyberlaw-101-primer-laws-related-honeypot-deployments-1746
However, I was wondering if there are more recent changes to the laws and/or a site that is more thorough in treatment of how private parties (contractors) factor into any legal issues that might arise from use of a honeypot deployment.
In other words, what are the references that folks experienced with the topic and/or deployment of honeypots rely of for updates and practical legal knowledge?