Live data from Hacker News

Accessing Publicly Available Information on the Internet Is Not a Crime

eff.org

31–40 of 299 posts

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#31

How does a website put reasonable limits on access? I'm not saying what Linkedin is trying to do is right but it seems to me there needs to be a way to say "Dude, that's not cool." A regular B&M store can refuse service to disruptive people and trespass people who don't comply, why not servers? --edit-- Pretty much what rayiner is saying, they posted while I was typing.

They could add requisite code.

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#32
post #24

There is a difference between public property and private property that is made available to the public. Just because the cafe on the corner has its door open and lets you stroll in off the street doesn't mean that the property owner doesn't retain the right to exclude people. And if the property owner revokes your permission, then going onto the property again can be a crime (trespass).[1] Servers are no different.…

I find this argument to be a poor fit for the actual situation. The person that owns a coffee shop needs to let people physically enter their coffee shop in order to purchase coffee, snacks, etc. LinkedIn has no such requirement, they can easily require people establish and log into registered accounts in order to access their data. As you have said, their servers are their property and they have the ability to block access for anyone that they do not wish to serve.

This is entirely different. LinkedIn wants to make the data available on the public internet... Except sometimes. They can't figure out a technical solution so they are pushing for a legal solution. If you'd like to try to further your coffee shop argument, this seems more like a coffee shop giving away free coffee with a notice letting customers know that there's a limit of three free coffees per person and then being shocked when some customers take four or five. Or all of them.

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#34

Earlier quoted context omitted.

> I'd also note that these companies are barely (if ever) held liable for life-compromising hacks on their platforms. You do know it is impossible to stop all cyber attacks? Its always a matter of when, not if. Zero day attacks are developed everyday with not even the best funded cyber security systems able to thwart them. The geniuses are on the offensive side, if they want in, they will get in.

From my random perusal of the various reports of compromises over the last few years, my impression is not that organisations tend to get hacked using the latest zero-day vulnerability, but rather that organisations get hacked because they have glaring security holes that you could drive a double-decker bus through. For example, bcrypt has been around for how long now? And don't almost all the reports of hacks report…

I think most "hacks" have been the results of social engineering and misconfigurations rather than software/hardware vulnerabilities.

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#35
post #29
post #24

There is a difference between public property and private property that is made available to the public. Just because the cafe on the corner has its door open and lets you stroll in off the street doesn't mean that the property owner doesn't retain the right to exclude people. And if the property owner revokes your permission, then going onto the property again can be a crime (trespass).[1] Servers are no different.…

Trespass is not illegal until the owner informs you that you are not wanted. Private information that has accidentally been made public is like an unmarked field. It may be private, it may be public, but until the owner takes specific action it is not illegal to use the field. If the owner decides to take action, that action cannot be retroactively applied, even if there is a record of who used the field. Regardless,…

The difference is Linkedin knows they're scraping the site, asked them to stop and is now trying to force them to stop through the courts (in a really bad way).

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#36
post #24

There is a difference between public property and private property that is made available to the public. Just because the cafe on the corner has its door open and lets you stroll in off the street doesn't mean that the property owner doesn't retain the right to exclude people. And if the property owner revokes your permission, then going onto the property again can be a crime (trespass).[1] Servers are no different.…

That's not a great analogy. The store owner can't just get your arrested/charged with a crime if they don't tell you that you aren't allowed first. Http lacks such a human mechanism. The closest thing I can think of in the standard is the response code. So your server replying 200 OK should implicitly be considered permission to access that resource legally until it stops replying with that code.

But that's exactly what happened here:

> LinkedIn sent hiQ cease and desist letters warning that any future access of its website, even the public portions, were “without permission and without authorization” and thus violations of the CFAA.

The EFF's point about terms of service is a good one, but also irrelevant. Terms of service don't provide adequate notice that someone's implied license to access a website has been terminated. But here, hiQ had actual notice through "human" channels.

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#37

How does a website put reasonable limits on access? I'm not saying what Linkedin is trying to do is right but it seems to me there needs to be a way to say "Dude, that's not cool." A regular B&M store can refuse service to disruptive people and trespass people who don't comply, why not servers? --edit-- Pretty much what rayiner is saying, they posted while I was typing.

They have many options. They can rate limit access by IP address, they can keep information they'd like not to be scraped behind login screens. And so on.

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#38

> LinkedIn argues that imposing criminal liability for automated access of publicly available LinkedIn data would protect the privacy interests of LinkedIn users who decide to publish their information publicly, but that’s just not true Protect them from what, your unlocked front door ? [0][1] [0] "Hackers selling 117 million LinkedIn passwords" http://money.cnn.com/2016/05/19/technology/linkedin-hack/ind... [1] http…

> I'd also note that these companies are barely (if ever) held liable for life-compromising hacks on their platforms. You do know it is impossible to stop all cyber attacks? Its always a matter of when, not if. Zero day attacks are developed everyday with not even the best funded cyber security systems able to thwart them. The geniuses are on the offensive side, if they want in, they will get in.

The industry is held to no standards at all. You can keep plain-text passwords in your databases, do no tests at all, and be incompetent in a million other ways. I usually get downvotes when I say this, but by now there needs to exist certain regulation on commercial software and software-based services. It should be ensured that certain practices are followed in security and ethics (do you take the basic, well known precautions against the well-known attacks?, do you respect your users' privacy at least as much as the law requires you to, do you follow the terms and conditions you declare?). What we need is CE for software, and it's sad that I can ensure my cheese comes from a certain town and is produced from the milk from cows eating according to a certain diet, but not if Twitter (or any other commercial website) hashes and salts my password, and actually uses basic precautions against CSRF or what not. These companies should be obliged to get their stuff audited by third parties, and there should be a way to tell if they are really approved to maintain a certain standard in producing their software. I do understand and share the hacker culture, and appreciate how it's possible to spin off a start-up website business on the internet, but business is business. You don't become exempt from regulations when all you do is to run a tiny B&B with 2 rooms. Similarly, as soon as you're a company selling online services, regulations and standards should kick in. Because by now those online services are no less important than food business. You say it's impossible to stop all cyber attacks. Then, as it is impossible to stop all burglary attempts, should banks just deposit their money in some apartments, or in some random rooms where all the security is a wooden door? Fire all the security guards because it's impossible they survive all the guns out there? These companies like LinkedIn are no different in banks insomuch as they deposit not our money, but our personas. They should actually be more cautious because while money can be replaced, nobody can have a new self.

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#39

How does a website put reasonable limits on access? I'm not saying what Linkedin is trying to do is right but it seems to me there needs to be a way to say "Dude, that's not cool." A regular B&M store can refuse service to disruptive people and trespass people who don't comply, why not servers? --edit-- Pretty much what rayiner is saying, they posted while I was typing.

> How does a website put reasonable limits on access?

1) Blocking TCP connections

2) Returning a 4XX error, perhaps even "401 Authorization Required", "402 Payment Required", "403 Forbidden", or "429 Too Many Requests"

> A regular B&M store can refuse service to disruptive people and trespass people who don't comply, why not servers?

A Brick and Mortar store has to _tell_ you you're being banned. The mechanisms I listed above both tell you and lock the door whenever you attempt to access.

Edit: In this case, it's more like someone was looking in the store window from the public sidewalk and asked to stop. Can you really ask someone to stop looking at you from a public place?

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#40
post #24

There is a difference between public property and private property that is made available to the public. Just because the cafe on the corner has its door open and lets you stroll in off the street doesn't mean that the property owner doesn't retain the right to exclude people. And if the property owner revokes your permission, then going onto the property again can be a crime (trespass).[1] Servers are no different.…

That's not a great analogy. The store owner can't just get your arrested/charged with a crime if they don't tell you that you aren't allowed first. Http lacks such a human mechanism. The closest thing I can think of in the standard is the response code. So your server replying 200 OK should implicitly be considered permission to access that resource legally until it stops replying with that code.

robots.txt.

If all requests sent by robots would clearly identify themselves, the server would easily block all of them. But if they fake their user agent to look like a browser and ignore robots.txt, that's not a good faith request and they shouldn't be able to plead ignorance.

Post reply on HN