Everywhere else this garden explains how systems work, and since the standards section, how they are specified. This section covers what the law permits, forbids, and compels when those systems are attacked, defended, searched, or exported. It is US-centric by design, because that is the jurisdiction most of these notes describe. Three of them leave it: one for a European regulation that reaches American companies anyway, and two for the international law of armed conflict and state responsibility.

Every note here describes an instrument. It says what a statute, a regulation, a treaty, or a court opinion provides, quotes the operative language, and cites the document. None of them tells a reader what to do, whether something is legal in a particular situation, or how to respond to a legal event.

Scope

These notes are descriptions of legal instruments, written by an engineer for engineers. They are not legal advice, they do not establish an attorney-client relationship, and they are not a substitute for counsel. Statutes and regulations change, court opinions are superseded, and nothing here has been checked against the law of any particular jurisdiction on any particular day.

The technical subject matter behind every attack, defense, and control named here lives in Security. The normative arguments live in Ethics. Conformance and specification live in Standards. These notes link all three and restate none of them.

The core criminal statute

One federal statute, 18 U.S.C. 1030, is the one this section assumes a security practitioner can read cold. Start with the text, then the phrase that took the Supreme Court thirty-five years to construe, then the sentencing exposure, then the fifty state analogues that cover the same ground with different verbs.

Surveillance and stored data

The government’s access to communications and to data held by providers, sorted by statute and then by constitutional doctrine. The chapter structure is from 1986 and the technology is not, which is most of what makes this arc hard.

Research, disclosure, and the DMCA

The legal position of the person who finds the bug. Two prohibitions in copyright law, the exemptions that partially relieve them, and the two private instruments that do the rest of the work.

Export control

The rules that treat knowledge as a controlled item. Two regimes, a historical episode that shaped modern cryptography, and one multilateral entry that showed what happens when a control is written against a technique.

Compliance regimes that bind engineers

Obligations that arrive as requirements documents rather than as prosecutions. The federal baseline first, then the contract clauses that push it into industry, then the privacy regimes that reach commercial systems.

Conflict and authority

The hardest arc, because the material invites opinion and these notes decline to supply it. Each note here states what an instrument provides and attributes every contested position to whoever asserted it.


The full file listing follows below, generated automatically by Quartz.