> but the flamboyant way it was done scared the crap out of people who were both clueless and in a position to do stupid things. As a result we got the CFAA and the DMCA which are both some of the most ridiculous pieces of legislation after the so called "patriot" act.
> The damage that did to curious people growing up lost the US a significant fraction of their upcoming "innovation" talent.
The causal leap from flamboyant hackers to the DMCA/CFAA, and then to damaging the US's innovation talent feels... speculative.
> The causal leap from flamboyant hackers to the DMCA/CFAA
That isn't much of a leap. The penalties aren't rooted in the actual damages, because for most of this kind of curiosity-based intrusion, there isn't any real damage and the damage imputed to them is the cost of cleaning up after the vulnerability, which the "victim" ought to have paid regardless. Getting trolled by some kid isn't what costs you money, implementing a vulnerability that allows some kid to troll you is.
The reason the penalties are high is because of that embarrassment. Some major institution that ought to have done better gets pwned by some pranksters and they lose face. So they want to throw the book at the guy to deter anyone else, not from maliciously causing them undue harm, but from making a fool of them in public.
But blaming the youth for bragging about it is blaming the victim. The perpetrators are the institutions that abuse the law, and the process of creating the law, to severely punish not evildoers but the child who points out that the emperor has no clothes.
> and then to damaging the US's innovation talent
These are the laws they use to charge the likes of Aaron Swartz, are they not?
It'll make more sense when you realize that promoting the competence of American corporations is, in and of itself, an explicit policy goal of the American government.
If they wanted to promote competence then the damages would be applied to the corporation for implementing the vulnerability, not on the attacker for exposing it. This way, corporations are given a shield for being incompetent and can place the blame and damages upon an individual that brings them to light.
> The damage that did to curious people growing up lost the US a significant fraction of their upcoming "innovation" talent.
The causal leap from flamboyant hackers to the DMCA/CFAA, and then to damaging the US's innovation talent feels... speculative.