Park, S., & Thomas, D. (2026). “Sticking their heads out above the parapets”: Lived Experiences of Legal Risks in Research. Strathprints: The University of Strathclyde institutional repository (University of Strathclyde).

View paper

Summary

This paper offers the first systematic qualitative study of how researchers experience the legal risks that arise from overbroad computer crime, intellectual property, and related laws — chiefly the US Computer Fraud and Abuse Act (CFAA), UK Computer Misuse Act (CMA), and DMCA. Drawing on interviews with 36 researchers (spanning 130 projects/incidents) and 8 supporting professionals, the authors document pervasive chilling effects, serious emotional and professional harms, and the coping strategies researchers deploy to navigate legal uncertainty. The central argument is that these laws fail to distinguish malicious hacking from good-faith public-interest research, deterring socially valuable work; the paper’s empirical documentation is offered explicitly as groundwork for law and policy reform.

Key Contributions

  • The first qualitative, systematic empirical study of researchers’ lived experiences of legal risk, moving beyond anecdote and “professional folklore.”
  • A big-picture view of the UK/US legal risk landscape across computer science subfields, including trends over time.
  • Naming and characterising the phenomenon of stockpiling undisclosed vulnerabilities as a systemic security consequence of legal fear.
  • Actionable strategies for researchers plus three unilaterally actionable recommendations: think through risks early; consider stakeholder incentives and public communication; build a trusted support network of colleagues and lawyers.
  • Documentation of the value of personal vs. institutional legal representation and the fragile reliance on pro bono support.
  • Empirical evidence to inform reform of computer crime, IP, and related laws.

Methods

Reflexive thematic analysis (following Mason and Saldaña), coded in NVivo, based on semi-structured interviews (30–120 min, ~54 hours total) conducted Nov 2024–Feb 2026. Two participant groups: 36 researchers with US/UK legal-risk experience and 8 supporting professionals (lawyers who had each helped 20+ researchers), N = 44. Recruitment combined public documents, professional networks, snowball sampling, and community outreach across academia, industry, independent, and government research. Project attributes were systematically documented and corroborated with privately shared emails and threats. Strong confidentiality mitigations were used (IRB/institutional approval, verbal consent, end-to-end encrypted communication, participant-approved anonymised quotes). The authors explicitly did not reach saturation and disclaim quantitative generalisability.

Findings

  • Research spanned over a dozen types; vulnerability research has the longest history of legal risk, while social computing research surged since 2020 — four times the projects and twice the legal threats of the next largest category.
  • 23 participants described legal risk as ubiquitous or unavoidable in their fields; many framed their work as a public service.
  • ~30% of projects involved actual legal threats; most did not escalate to prosecution or litigation, and some rested on legally tenuous grounds.
  • Emotional impacts were pronounced (90 expressions of fear, worry, frustration, stress); some reported all-consuming anxiety, weight loss, and sleeplessness. None found criminal risk exciting.
  • Chilling effects included abandoning or not publishing work and avoiding whole areas; stockpiling of undisclosed vulnerabilities occurred at scale, with three researchers offered “life-changing money” to buy and silence stockpiles.
  • Severe consequences included job loss, blacklisting, overturned criminal convictions, months of incarceration, and a collaborator likely unable to return home.
  • Researchers retained their own lawyer in only 30 of 130 projects; most access was free, predominantly pro bono (17 of 30), raising sustainability concerns. Personal counsel was experienced overwhelmingly positively; institutional/university support was mixed and more often negative.
  • Jurisdictional differences were smaller than expected — UK researchers often navigate US law; 15% of UK projects involved threats vs. 40% of US projects, partly because the UK CMA lacks a civil cause of action.
  • The second Trump administration and politically motivated (“McCarthy-esque”) threats, including Congressional investigations, made social computing risk more unpredictable, exposing the fragility of relying on norms rather than laws.
  • Conference ethics review was widely criticised as immature; IRB/Ethics Committee review was generally seen as reasonable. Terms of Service violations were often a necessary feature of essential social computing research, and bug bounty NDAs could heighten rather than reduce risk.

Connections

This paper speaks directly to the platform-governance and data-access literature that documents how ToS restrictions, platform enforcement, and legal uncertainty constrain independent research — a recurring theme in work on the difficulties and legal grey zones of collecting platform data, such as Freelon2024-sc, Davani… (not linked), and studies of the post-API and post-CrowdTangle access landscape like Ohme2026-nv, Rieder2025-ju, and Bruns2026-yv. The chilling effects it names on social computing research complement empirical accounts of platform data-access barriers such as Tonneau2025-bv and Murtfeldt2025-wu. Its focus on the lived, individual experience of legal risk is a distinct contribution rather than a duplication of these more infrastructural or methodological studies.

Podcast

A research-radio episode discusses this paper: 🎧 MP3 · Spotify · Apple Podcasts