Earlier quoted context omitted.
It is interesting to note that, were they applied to physical private property, most of your arguments would clear the stealing of anything that is not bolted to the ground. So I'm trying to answer to you in this light. Who has legal property of the data in question : Obviously, Lyft. Does Uber, by accessing this data, benefit from it : obviously, yes. Do they, by accessing the data, deprive Lyft from the use of this…
>It is interesting to note that, were they applied to physical private property, most of your arguments would clear the stealing of anything that is not bolted to the ground. This is exactly the flawed analogy that incumbents use to keep anti-competitive legislation like the CFAA and extreme copyright regimes in place, but it doesn't work. >Well, our laws work like that for pretty much every other aspect of property…
These problems can all be discussed in the prism of restraining property rights for public benefit (e.g. restriction of copyright for quoting). In Uber's case, though, there is no public interest in restraining Lyft's rights.
> They don't universally work like that for public places or businesses. There are significant restrictions in how access to public businesses can be restricted, as well significant accessibility and regulatory requirements before such a place is authorized to open
None of these regulation relate to liability of potential thieves, but to public safety. In our case, this would mean Lyft may be on the hook for not protecting drivers' and users' data, not that the person appropriating these data is not also on the hook.
> The mere fact that Lyft could've hypothetically charged Uber for access to these bits is not really relevant.
Property laws very specifically state that the owner is entitled to the fruit of his property. You may criticize the whole ownership system, but this is a clear cut case of Uber appropriating data that they didn't create. The only question here is whether the terms of access Lyft gave to third parties was explicit enough for Uber to understand that it had no right to this data, and whether Uber also understood this fact.
> When you open for business, you're making a deal with the community.
The nature of that deal is codified in the terms of service. While most terms of service may be seen unfair towards customers, in this case, 1) Uber is not a customer and 2) the aspects of the terms that were violated are hard to consider unfair.
There are plenty of exceptions that could/should be discussed in the scope of CFAA : scientific/historian work, hacking that benefits the customer and/or the owner, work of arts, etc. I would welcome amending the law in this light.
Uber's action fits none of these legitimate uses, and is actually a good example of why CFAA was introduced in the first place.