Live data from Hacker News

Accessing Publicly Available Information on the Internet Is Not a Crime

eff.org

121–130 of 299 posts

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#121
post #88

Earlier quoted context omitted.

If you are notified in writing that you're banned from a coffee shop, but you walk up to the front door and the "server" (pun intended) greets you warmly and allows you to enter, is that "implied consent" that overrides the prior explicit anti-consent, and therefore undermines the legal authority of that ban?

I think almost any judge or jury would find it implausible if you told them you thought the written ban didn't apply anymore because the server still let you into the coffee shop. We intuitively understand that written notice from a property owner carriers more weight than the actions of one of their workers. I think the same exact reasoning applies where the "worker" is a computer server.

I agree with you, but I think an even better analogy would be a supermarket with automatic doors.

If someone was walked out of a supermarket and explicitly told that they were banned for life, and they tried to claim that the ban was lifted because the automatic doors opened for them, they'd be laughed out of court.

You could extend that further and say that the supermarket has a self-checkout. You may very well be able to walk through the automatic doors, grab something off the shelf, check it out yourself, and leave without anyone noticing you, but it's still trespassing if you've been banned from the store.

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#122

Earlier quoted context omitted.

> I'd also note that these companies are barely (if ever) held liable for life-compromising hacks on their platforms. You do know it is impossible to stop all cyber attacks? Its always a matter of when, not if. Zero day attacks are developed everyday with not even the best funded cyber security systems able to thwart them. The geniuses are on the offensive side, if they want in, they will get in.

While I agree, as a CTO I would be terrified if a data breach could hold me personally liable. It'd be like a Director of Security at a bank being liable for their bank being robbed with a tank. But at the same time there is a line. I would be for holding companies liable if, for instance, the data gets out there and you find it is entirely unencrypted and the passwords are MD5 hashed or plain text. There has to be a…

> While I agree, as a CTO I would be terrified if a data breach could hold me personally liable.

Personal liability is going too far, IMO.

> Mistakes should not be punished as long as there is not also negligence.

The problem with this is that you'd have to enshrine, in law, what "negligence" is. Technology changes too fast to put that into law.

"How many people got hurt and how badly?" is a question attorneys can reasonably address. "Was there sufficient input sanitization?" is not.

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#123

Earlier quoted context omitted.

Is it even comparable to an unlocked door, though? To me it seems a lot more like leaving something on the front of your house and trying to prosecute when someone takes a picture of it. Nothing is removed or destroyed, and nothing was hidden or publicly unavailable.

And, technically, you did essentially request access. An anonymous HTTP request doesn't have to be honored by the web server.

This right here folks. This is how I would prefer government worked. Imagine putting the liability back on the corporation for confirming access because in place "protocols" that approved it?

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#124
post #65

Earlier quoted context omitted.

The Whataburger I went to for breakfast this morning gives some homeless people free coffee and asks others to leave...

And when hiQ shows up looking homeless and accepts the gift of coffee, they are committing a crime?

No, but when they ask them to leave and they still take a coffee cup they are.

But that's not the point, the point is it's possible to give something for free and also refuse to give it to everyone under any circumstance.

They didn't give me a free cup of coffee and someone could reasonably mistake me for a homeless person based on my (lack of) fashion sense but that doesn't mean I could just reach over the counter and grab a cup because I saw them give one to somebody else when I walked through the door.

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#125
I mentioned this before in a previous thread on this topic, but I can't support the EFF on this. This is, at the end, an argument against control over ones own data: LinkedIn might be doing sketchy things with your data, but it's all stuff you voluntarily agreed to in exchange for their service. If any shady data aggregator can vacuum it up and do whatever, I didn't consent to that and I'm not getting any benefit from it. The EFF shouldn't be defending that right.

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#126
post #89
post #9

>good bots You mean, bots that obey robots.txt? https://www.linkedin.com/robots.txt very specifically prohibits scraping by any bot besides a small whitelist. robots.txt compliance is not difficult to build. I'm fine with robots.txt violations being considered hacking.

> I'm fine with robots.txt violations being considered hacking Really?? That would mean private corporations, or private citizens, can write laws.

You can put up a "no trespassing sign" on your property (although there's some debate as to how much that actually counts for - a quick search pulls up https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...)

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#127
post #70

Earlier quoted context omitted.

It is legal until you inform them they are trespassing and ask them to leave.

Not if it's a personal residence. Entering someone else's property is trespass unless you have license. When private property is open to the public, there is an implied invitation to the public to enter, so you have license to do so unless it's revoked. With a personal residence, however, there is no implied license for strangers to enter (though there might be based on the parties' relationships or prior dealings).

There are some states with specific rules for personal residence, but it's inconsistent.

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#128
post #107

Earlier quoted context omitted.

The poster is arguing that if you make a request from LinkedIn's website and it returns a "200" along with data, then you've accessed that data lawfully and LinkedIn has agreed to serve it to you; I tend to agree. If they don't want to provide data to hiQ, they should, well, stop providing data to hiQ. There are many ways to do this short of claiming that hiQ doesn't have permission or authorization, an argument stri…

How is that any different than walking up to a store entrance with automatic doors and a sign that says "Welcome" on it?

Those doors get turned off at night, just like a server can ignore an HTTP request

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#129

How does a website put reasonable limits on access? I'm not saying what Linkedin is trying to do is right but it seems to me there needs to be a way to say "Dude, that's not cool." A regular B&M store can refuse service to disruptive people and trespass people who don't comply, why not servers? --edit-- Pretty much what rayiner is saying, they posted while I was typing.

> How does a website put reasonable limits on access? 1) Blocking TCP connections 2) Returning a 4XX error, perhaps even "401 Authorization Required", "402 Payment Required", "403 Forbidden", or "429 Too Many Requests" > A regular B&M store can refuse service to disruptive people and trespass people who don't comply, why not servers? A Brick and Mortar store has to _tell_ you you're being banned. The mechanisms I lis…

LinkedIn sent HiQ a C&D. They were indeed told that they were banned.

Let's try a thought experiment: you're at a supermarket, and you're abusing coupons to the point where you're holding up the line for everyone. Someone complains to the manager, and the manager escorts you out of the store and tells you you're banned for life (as an aside, I wish this would happen to extreme couponers).

The supermarket also has automatic doors and a self-checkout. They're also pretty understaffed, so there's a good chance you won't run into anyone stocking the shelves as you're shopping. A few days after you've been banned, you waltz in through the automatic doors, grab some items off the nearest shelf, go through the self-checkout, and leave without a single employee getting a good look at your face. At the end of the day, the manager starts fast-forwarding though the day's security camera footage looking for anything odd and notices you've been in the store. They call the police and have you charged with trespassing.

Do they have a case, yes or no?

I say yes.

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#130
post #95
post #69

Earlier quoted context omitted.

If I leave my front door to my personal residence unlocked, and someone comes to the front door, opens it, and walks inside without permission --- is that illegal? I'm actually not sure.

well, 'breaking and entering' in the US requires that something (i.e., the door) actually be broken in the process of entering the house...otherwise that charge doesn't apply.

Fun aside: breaking and entering is referred to as such in English Common Law because criminals used to bust through the wattle and daub walls to break in, thus housebreaking, or breaking and entering. [1]

[1] https://books.google.com/books?id=77y2AgAAQBAJ&pg=PA229&lpg=...

Post reply on HN