Working Through A Gift Of Fire Social Legal And Ethical Issues For Computing And The Internet 3rd Edition
The book sits somewhere between philosophy textbook and compliance manual. It covers the territory you would expect: intellectual property, privacy, workplace surveillance, AI ethics, digital divide. It also covers the stuff you usually discover too late, like how a software license you accepted quietly transferred your work product to someone else. Hoffman and Dutton organize the material around case studies rather than abstract principle. Each chapter opens with a real dispute. You get the facts, the relevant statutes or policies, and then a set of questions that force you to pick a side. The structure mirrors how these problems show up in practice. Nobody calls a lawyer because they read a definition of negligence. They call because something broke and someone is asking who pays. The third edition added material on algorithmic bias, platform moderation, and cross-border data flows. Those sections are stronger than the older chapters on copyright because the authors updated them with actual litigation outcomes instead of relying on outdated Fair Use doctrine from the 1990s.
How to use it without wasting time
The chapters are long. The most efficient path is to read the case study first, then the framework, then the questions. If you read the framework before the case you will forget the framework before you finish the case. That is just how dense legal-textbook prose works. I kept a two-column note system. Left column: the rule or standard the book presents. Right column: the exception or edge case the book barely mentions. The right column is usually where the actual work lives. For example, the book explains the DMCA safe harbor provisions in decent detail. It does not explain what happens when a platform's automated takedown system incorrectly flags a source code repository, which I encountered when a university IT department tried to pull a student's open-source project under a blanket policy misreading Section 512.
A specific problem I ran into and how I worked around it
We were drafting an internal acceptable-use policy for a mid-size software company. The book's chapter on employee monitoring gave us the legal baseline: Electronic Communications Privacy Act, state wiretapping statutes, notice requirements. The practical problem was that our engineering team used personal devices for work, and the device-enrollment policy we were writing could not reference the book's examples directly because they assumed company-owned hardware. Most of the textbook case studies predate BYOD at scale. The workaround was straightforward. I took the ECPA analysis from Chapter 6, cross-referenced it with CISA Section 704 on authorized testing, and built a tiered consent model: Tier 1 for company devices with full logging, Tier 2 for personal devices with application-level logging only, Tier 3 for remote access through a VPN with no endpoint monitoring. The book does not cover the BYOD tiering explicitly. It does give you the statutory references to build it.
Get the Full Details

Where the book falls apart
The international coverage is thin. If you are operating outside the US, the FERPA and COPPA chapters are not useful. The GDPR section exists but it is summary level. You will need to pair this with the official EU guidance documents if compliance is the goal. The book works fine as a concepts primer. It does not replace a jurisdiction-specific legal memo. The cryptography section is dated even for a third edition. Key management, certificate authorities, and zero-trust architectures have moved on. The book treats encryption as a philosophical debate rather than an engineering discipline. Read it for the ethics framing. Do not use it as a technical reference.
Counter-intuitive points beginners miss
Most people think the ethical frameworks in the book are the main takeaway. They are not. The main takeaway is learning to recognize when a technical decision is actually a legal decision in disguise. A caching strategy is not just a performance question. It is a reproductions question under copyright law. A logging retention period is not just a storage budget question. It is a discovery obligation question. The second missed point is that consent is the wrong question in most of these cases. The better question is allocation of risk. Who bears the cost when the system fails. The book frames many discussions around informed consent, but in enterprise computing that framework breaks down quickly because users do not read terms of service and cannot realistically negotiate them. Risk allocation gets you further.
How to get a copy
The official publisher is Pearson. You can find the print edition and the ebook through their site or any major bookseller. Third-party sellers on Amazon and eBay carry used copies, sometimes at steep discounts since the fourth edition has partially displaced demand. Make sure you are getting the correct edition if your institution requires it. The third edition covers different case law than the fourth, particularly around social media liability and algorithmic transparency. If cost is a factor, the library reserves at most universities carry it. Some instructors post case study excerpts online. The book is designed to be discussed rather than consumed passively, so reading it alone without the accompanying questions or a study group will leave most of the value on the table.
