United States v. Robert Tappan Morris, 928 F.2d 504 (2d Cir. 1991) was decided by the United States Court of Appeals for the Second Circuit on March 7, 1991 (No. 774, Docket 90-1336). The Second Circuit affirmed the conviction. The Government did not have to prove that Morris intended to prevent authorized use or to cause loss; intent ran only to the access. Sufficient evidence supported the jury's finding that he accessed federal interest computers without authorization rather than merely exceeding authorised access, and the district court was not required to define 'authorization' for the jury or to instruct on an 'exceeding authorized access' theory.
The question before the court
Does 18 U.S.C. § 1030(a)(5)(A) require proof that the defendant intended the resulting damage as well as the access, and does a user authorised on some networked computers 'access without authorization' when he exploits program defects to propagate a worm onto other computers?
The governing rule
Section 2(d) of the Computer Fraud and Abuse Act of 1986, codified at 18 U.S.C. § 1030(a)(5)(A) (1988), punished one who 'intentionally accesses a Federal interest computer without authorization' and by that conduct alters, damages or destroys information or prevents authorized use, thereby causing loss of $1,000 or more in a one-year period. 'Federal interest computer' was defined in § 1030(e)(2)(A). The subsection was read against § 1030(a)(3), the misdemeanor trespass offence, and § 1030(a)(1), which states two separate mens rea standards for its access and results phrases. Neither § 1030(a)(3) nor § 1030(a)(5) reached conduct merely 'exceeding authorized access'.
How the court applied it
The court took the two questions in turn. On scienter, Morris argued that 'intentionally' modified both the access phrase and the damage phrase; the Government argued the comma confined it to access. The court declined to treat punctuation as decisive and instead compared the 1986 subsection with its 1984 predecessor, which had expressly placed 'knowingly' before both the access phrase and the results phrase. That deliberate departure, together with the subsection's wording, structure and purpose, persuaded the court that intent attached only to the access. On authorisation, the court accepted that Morris held accounts at Cornell, Harvard and Berkeley, all on the INTERNET, so he was authorised to send mail and to query users through the finger demon. But the jury could find that he used neither feature for its intended function: he located defects in SEND MAIL and the finger demon that opened a special route into machines where he held no account. The court added that the worm was also designed to propagate through the trusted hosts feature and by guessing passwords on computers where he had no account at all. The Senate Report's description of the subsection as aimed at 'outsiders' did not confine its coverage to people lacking access to every federal interest computer, since Congress plainly did not mean to immunise a State Department user who damages Defense Department machines.
What the court concluded
The Second Circuit affirmed the conviction. The Government did not have to prove that Morris intended to prevent authorized use or to cause loss; intent ran only to the access. Sufficient evidence supported the jury's finding that he accessed federal interest computers without authorization rather than merely exceeding authorised access, and the district court was not required to define 'authorization' for the jury or to instruct on an 'exceeding authorized access' theory.
From the opinion
- “the "intentionally" standard applies only to the "accesses" phrase of section 1030(a)(5)(A), and not to its "damages" phrase” — Closing sentence of Part I, resolving the scienter question after comparing the 1986 subsection with its 1984 predecessor.
- “He did not send or read mail nor discover information about other users; instead he found holes in both programs” — Part II, explaining why Morris's use of SEND MAIL and the finger demon was access without authorization rather than exceeding authorised access.
- “Since the word is of common usage, without any technical or ambiguous meaning, the Court was not obliged to instruct the jury” — Part II, rejecting Morris's argument that the district court had to define 'authorization' for the jury.
Why it matters for cyber conflict
This is the first appellate construction of the Computer Fraud and Abuse Act, and it fixed at the outset that self-propagating code reaching military, NASA and university systems is unauthorised access even when the author held legitimate credentials somewhere on the network. Every later argument about where authorisation ends — including those over state-linked intrusion — starts from that division between the access element and the damage element.
Editorial note: this case note was drafted with AI assistance by the JLCW Research Desk, checked against the text of the opinion, and reviewed by a human editor before publication. Every quotation above is carried through from the opinion itself. See our editing policy.
Read the opinion: United States v. Robert Tappan Morris on CourtListener. This note is a summary prepared by the Journal, not legal advice, and not a substitute for the opinion itself.
More on Cyber Weapons · All case notes · Peer-reviewed scholarship