Live data from Hacker News

Violating Terms of Use Isn’t a Crime, EFF Tells Court

eff.org

101–104 of 104 posts

Re: Violating Terms of Use Isn’t a Crime, EFF Tells Court

#101

Earlier quoted context omitted.

In Britain it's illegal for a website to store a cookie without informing you, so I have a feeling someone may have already tried this.

No, it isn't. That's not what the infamous "cookie law" says, nor how it's been interpreted in practice by official regulators across the EU.

What does it actually say?

Re: Violating Terms of Use Isn’t a Crime, EFF Tells Court

#102

Earlier quoted context omitted.

No, it isn't. That's not what the infamous "cookie law" says, nor how it's been interpreted in practice by official regulators across the EU.

What does it actually say?

The details are probably too complicated for an HN comment, but one point that sometimes gets missed is that you normally don't have the same disclosure/consent obligations for cookies that are essential to the normal operation of the site like login tokens or tracking what's in a shopping basket.

Re: Violating Terms of Use Isn’t a Crime, EFF Tells Court

#103
post #98
post #84

"Oracle sent Rimini a cease and desist letter demanding that it stop using automated scripts. It did not, however, rescind Rimini’s authorization to access the files outright. Rimini continued to use automated scripts, and Oracle sued. The jury found Rimini guilty under both the California and Nevada computer crime statues, and the judge upheld that verdict—concluding that, under both statutes, violating a website’s…

The federal law at issue here isn't contingent on the owner delivering a Cease & Desist letter or even taking any affirmative steps whatsoever. No court is going to read that into the law. At best a C&D is evidence of the rescission of authorization, but all the statute cares about is whether authorization existed or not. Importantly, Oracle didn't actually lock their account. And even more importantly, AFAIU this gu…

>all the statute cares about is whether authorization existed or not.

No, that's not all the CFAA cares about.

>(a)(2)(C) Whoever intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains information from any protected computer;

Thus my confusion. Why present the case as "without authorization" (based on the TOS) in the first place, when "exceed[ing] authorized access" (based on the C&D) seems like a much lower bar to clear and is less likely to provoke nonprofits complaining about precedent?

https://www.law.cornell.edu/uscode/text/18/1030#a_2

Re: Violating Terms of Use Isn’t a Crime, EFF Tells Court

#104
post #69

Earlier quoted context omitted.

Right, but how could anyone prove that you are the one who created the fake account?

Face recognition could also work. Note that this is rather hypothetical.

I'm not sure how this would work. You mean if Facebook started requiring people to login via webcam/facial recognition?
Post reply on HN