USENIX Security2026Top-tier venue
"Sticking their heads out above the parapets": Lived Experiences of Legal Risks in Research
Sunoo Park, Daniel R. Thomas
Abstract
Overbroad computer crime, intellectual property, and other laws are well known to create legal risks for essential research. Notable examples include the US Computer Fraud and Abuse Act and the UK Computer Misuse Act. Because such laws fail to distinguish malicious hacking from goodfaith testing and research, researchers face serious legal risks for public-interest research activity like identifying vulnerabilities or scraping data. Despite the research community's broad awareness of these risks, our understanding of their practical impacts is limited, as most of the community's knowledge comes from anecdotal evidence rather than systematic study.
We conduct the first qualitative study focused on researchers' lived experiences, to empirically document the impacts of legal risks and threats on research and researchers, and how researchers navigate legal risk situations. Our study engages two groups: researchers (N R = 36), who discuss 130 projects and incidents, and professionals that offer support to researchers navigating legal risks (N S = 8), who have supported thousands of researchers. We thus provide an unprecedented big-picture view of researchers' experiences with legal risks. We synthesise actionable strategies for researchers, and our findings provide evidence to support policy reform.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3b1bc19e-0cff-4859-b7bc-398b5c53f594Builds on3
- Quantifying the Pressure of Legal Risks on Third-party Vulnerability ResearchAlexander Gamero-Garrido, Stefan Savage, Kirill Levchenko, Alex C. SnoerenCCS 2017 · 18 citations
- Bug Hunters' Perspectives on the Challenges and Benefits of the Bug Bounty EcosystemOmer Akgul, Taha Eghtesad, Amit Elazari, Omprakash Gnawali et al.USENIX Security 2023
- Ethics in Computer Security Research: A Data-Driven Assessment of the Past, the Present, and the Possible FutureHarshini Sri Ramulu, Helen Schmitt, Bogdan Rerich, Rachel Gonzalez Rodriguez et al.CCS 2025
Related papers
- SoK: Safer Digital-Safety Research Involving At-Risk UsersRosanna Bellini, Emily Tseng, Noel Warford, Alaa Daffalla et al.S&P 2024 · 48 citations
- SoK: A Framework and Guide for Human-Centered Threat Modeling in Security and Privacy ResearchWarda Usman, Daniel ZappalaS&P 2025
- Where Are the Red Lines? Towards Ethical Server-Side Scans in Security and Privacy ResearchFlorian Hantke, Sebastian Roth, Rafael Mrowczynski, Christine Utz et al.S&P 2024 · 17 citations
- "I'm a Professor, which isn't usually a dangerous job": Internet-facilitated Harassment and Its Impact on ResearchersPeriwinkle Doerfler, Andrea Forte, Emiliano De Cristofaro, Gianluca Stringhini et al.CSCW 2021 · 39 citations
- Human-Centered Threat Modeling in Practice: Lessons, Challenges, and Paths ForwardWarda Usman, Yixin Zou, Daniel ZappalaS&P 2026
