Earlier quoted context omitted.
If I leave my front door to my personal residence unlocked, and someone comes to the front door, opens it, and walks inside without permission --- is that illegal? I'm actually not sure.
well, 'breaking and entering' in the US requires that something (i.e., the door) actually be broken in the process of entering the house...otherwise that charge doesn't apply.
Accessing Publicly Available Information on the Internet Is Not a Crime
101–110 of 299 posts
Re: Accessing Publicly Available Information on the Internet Is Not a Crime
#102Earlier quoted context omitted.
> How does a website put reasonable limits on access? 1) Blocking TCP connections 2) Returning a 4XX error, perhaps even "401 Authorization Required", "402 Payment Required", "403 Forbidden", or "429 Too Many Requests" > A regular B&M store can refuse service to disruptive people and trespass people who don't comply, why not servers? A Brick and Mortar store has to _tell_ you you're being banned. The mechanisms I lis…
> In this case, it's more like someone was looking in the store window from the public sidewalk and asked to stop. I think it's more like calling the store and asking them what their prices are 20 times a minute.
Also, a phone call consumes, as a percentage of available resources, vastly more than an HTTP request.
Disregarding that though, I think you'd need a court order telling someone not to talk to you, and you'd have to take action to prevent them as well, blocking their number and tell them to stop before that would be granted. If they persisted after being told explicitly and having their number blocked, then yes, I do think legal action would occure and be swift.
I would also assume, presumably, that "you" can be extended to be an automated phone system. (Which is still more limited in capacity than a server would be, but even disregarding that.)
FWIW, I'm not saying that "hiQ Labs" is blameless or acting in good faith. I'm saying that unimpeded access to publicly accessible information requires more than asking someone to stop and that the CFAA isn't the right tool for this.
I'm not an expert in this field, but I doubt the vast majority of anyone in this thread is. It also becomes interesting because I believe the CFAA has been used in similar situations before, but those were where the accessed knowlege could be assumed to be private, even if made public (client details at a phone company, or articles known to be behind a paywall) (and not that I agree with its usage there either, but the data accessed there could be assumed, by a reasonable person, to not be public).
So the key thing here is: if something is publicly available, can I ask you to stop looking at it, or do I need a more stringent court order to prevent you from viewing public information?
And in this case, I do think the capacity constraints disregarded above would come into play. I think the courts would look differently at someone calling your clerk 20 times a day vs looking at a menu you post on the window.
Re: Accessing Publicly Available Information on the Internet Is Not a Crime
#103Earlier quoted context omitted.
No because that's not how computers work. Computers don't just emit radiation into the aether that anyone can capture. Accessing a website involves making a physical piece of property do something in response to your HTTP request.
If you are notified in writing that you're banned from a coffee shop, but you walk up to the front door and the "server" (pun intended) greets you warmly and allows you to enter, is that "implied consent" that overrides the prior explicit anti-consent, and therefore undermines the legal authority of that ban?
Re: Accessing Publicly Available Information on the Internet Is Not a Crime
#104Earlier quoted context omitted.
No because that's not how computers work. Computers don't just emit radiation into the aether that anyone can capture. Accessing a website involves making a physical piece of property do something in response to your HTTP request.
If you are notified in writing that you're banned from a coffee shop, but you walk up to the front door and the "server" (pun intended) greets you warmly and allows you to enter, is that "implied consent" that overrides the prior explicit anti-consent, and therefore undermines the legal authority of that ban?
It becomes less clear where that delineation is not clear: a menu posted on a window or an automated phone system. These are both private things intended for at-large public consumption. My impression is that the EFF and hiq labs is taking the stance that it's a menu placed in the window, not being let in after being told you can't come in.
Re: Accessing Publicly Available Information on the Internet Is Not a Crime
#105Earlier quoted context omitted.
Where I live it is 100% legal to shoot them with no questions asked. 100% legal (castle doctrine) to shoot them, think about that for a minute, not generally legal to shoot someone engaging in a legal activity. --edit-- Also legal to shoot them through the door but probably not such a good plan...
No, you just think it is. The intruder must be there to commit a further crime, usually a violent one. An intruder must be making (or have made) an attempt to unlawfully or forcibly enter an occupied residence, business, or vehicle. The intruder must be acting unlawfully (the castle doctrine does not allow a right to use force against officers of the law, acting in the course of their legal duties). The occupant(s) o…
Here, unless you give them a reason they're just like "yeah, dude opened the wrong door, heh?"
Re: Accessing Publicly Available Information on the Internet Is Not a Crime
#106Earlier quoted context omitted.
If I leave my front door to my personal residence unlocked, and someone comes to the front door, opens it, and walks inside without permission --- is that illegal? I'm actually not sure.
It is legal until you inform them they are trespassing and ask them to leave.
https://www.law.cornell.edu/wex/trespass
So it's illegal to, for example, go door to door looking for one that somebody forgot to lock and then spend the night there.
Re: Accessing Publicly Available Information on the Internet Is Not a Crime
#107Earlier quoted context omitted.
But that's exactly what happened here: > LinkedIn sent hiQ cease and desist letters warning that any future access of its website, even the public portions, were “without permission and without authorization” and thus violations of the CFAA. The EFF's point about terms of service is a good one, but also irrelevant. Terms of service don't provide adequate notice that someone's implied license to access a website has b…
The poster is arguing that if you make a request from LinkedIn's website and it returns a "200" along with data, then you've accessed that data lawfully and LinkedIn has agreed to serve it to you; I tend to agree. If they don't want to provide data to hiQ, they should, well, stop providing data to hiQ. There are many ways to do this short of claiming that hiQ doesn't have permission or authorization, an argument stri…
Re: Accessing Publicly Available Information on the Internet Is Not a Crime
#108> LinkedIn argues that imposing criminal liability for automated access of publicly available LinkedIn data would protect the privacy interests of LinkedIn users who decide to publish their information publicly, but that’s just not true Protect them from what, your unlocked front door ? [0][1] [0] "Hackers selling 117 million LinkedIn passwords" http://money.cnn.com/2016/05/19/technology/linkedin-hack/ind... [1] http…
If I leave my front door to my personal residence unlocked, and someone comes to the front door, opens it, and walks inside without permission --- is that illegal? I'm actually not sure.
If you don't have a legal right to be on a piece of property, in a given structure, or in a vehicle, you're trespassing.
If you used force to gain access to the property, vehicle or structure, it will often be considered breaking and entering. Typically, these laws use a very loose definition of "force" which includes opening an unlocked door.
If you leave your door ajar, it's just trespassing. If you had to open the door, it's probably B&E even if you didn't break anything to do it.
Re: Accessing Publicly Available Information on the Internet Is Not a Crime
#109Earlier quoted context omitted.
Larger organizations use ISO-27001 and SOC-2 to audit this kind of stuff. But even so, sometimes the devil is in the details and it's possible to comply with the letter of the regulation while still being unprepared for the kinds of attacks that your service attracts.
Thanks, I'll look into them, but are there any compulsory standards anywhere? AFAIK this is entirely optional, i.e. left to the good will of the company.
Re: Accessing Publicly Available Information on the Internet Is Not a Crime
#110> LinkedIn argues that imposing criminal liability for automated access of publicly available LinkedIn data would protect the privacy interests of LinkedIn users who decide to publish their information publicly, but that’s just not true Protect them from what, your unlocked front door ? [0][1] [0] "Hackers selling 117 million LinkedIn passwords" http://money.cnn.com/2016/05/19/technology/linkedin-hack/ind... [1] http…
Is it even comparable to an unlocked door, though? To me it seems a lot more like leaving something on the front of your house and trying to prosecute when someone takes a picture of it. Nothing is removed or destroyed, and nothing was hidden or publicly unavailable.