Live data from Hacker News

Accessing Publicly Available Information on the Internet Is Not a Crime

eff.org

131–140 of 299 posts

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#131
post #54

Earlier quoted context omitted.

No because that's not how computers work. Computers don't just emit radiation into the aether that anyone can capture. Accessing a website involves making a physical piece of property do something in response to your HTTP request.

It's a bit like shouting in through the doorway "Hey, how much is your coffee?"

It's closer to going into the store that had sent you a C&D, then browsing the racks to create a price list.

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#132
post #113
post #9

>good bots You mean, bots that obey robots.txt? https://www.linkedin.com/robots.txt very specifically prohibits scraping by any bot besides a small whitelist. robots.txt compliance is not difficult to build. I'm fine with robots.txt violations being considered hacking.

That file includes at least two non-standard syntax extensions[0]. Robots is just a de facto standard and respect of some directives varies[1]. So much for it being 'not difficult' while the task is not even clear because there isn't even a clear standard. Archive.org also dislikes how robots.txt is being used mainly for search engines and goes against their mission in particular[2]. Are they now hackers for not thro…

It contains

User-agent: * Disallow: /

I am pretty sure none of the standard libraries/ tools that respect robots.txt would continue after being fed that file.

>throwing away information

This is entirely irrelevant. If they receive data from someone they have no obligation to discard it because of the current status of robots.txt. The question would be if they should continue to actively scrape that website.

It seems like they've done that for gov sites, but nobody particularly cares about enforcing gov robots.txt. It would've been interesting if the government sued them, although if they cared they probably would've just told them to stop.

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#133
post #116
post #18

Earlier quoted context omitted.

I mean, it seems to have been cited in the lawsuit. See e.g. https://static1.squarespace.com/static/5803b57737c581885cbd0... and search for it.

Although it appears the court found for HiQ (against LinkedIn): https://regmedia.co.uk/2017/08/14/hiqlinkedintro.pdf

Temporary injunction, not final decision.

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#134
post #18

Earlier quoted context omitted.

I mean, it seems to have been cited in the lawsuit. See e.g. https://static1.squarespace.com/static/5803b57737c581885cbd0... and search for it.

I doubt a bot could legally agree to a license put into robots.txt, even if it were able to make sense of it, and a human is never expected to read it. The purpose of robots.txt is to guide bots away from circular links and such that would result in bogging down the site and causing undue amounts of nonsense traffic. The purpose of robots.txt not access control. EDIT: typo fix

The human is expected to use it to not scrape sites that prohibit it.

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#135

Earlier quoted context omitted.

> In this case, it's more like someone was looking in the store window from the public sidewalk and asked to stop. I think it's more like calling the store and asking them what their prices are 20 times a minute.

...and the coffee shop doesn't block your number. Also, a phone call consumes, as a percentage of available resources, vastly more than an HTTP request. Disregarding that though, I think you'd need a court order telling someone not to talk to you, and you'd have to take action to prevent them as well, blocking their number and tell them to stop before that would be granted. If they persisted after being told explicit…

> ...I think you'd need a court order telling someone not to talk to you, and you'd have to take action to prevent them as well, blocking their number and tell them to stop before that would be granted.

Like, for example, sending a C&D letter?

This whole hubbub is over them sending a C&D, they just made the mistake of trying to use the CFAA as a means to enforce it -- which, honestly, hiQ is fighting the good fight trying to stop.

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#136

Earlier quoted context omitted.

Is it even comparable to an unlocked door, though? To me it seems a lot more like leaving something on the front of your house and trying to prosecute when someone takes a picture of it. Nothing is removed or destroyed, and nothing was hidden or publicly unavailable.

Well, there is precedent for that at least in the EU. You are not legally allowed to take a photo of the Eiffel Tower at night, because the arrangement of bulbs are considered works of art, and thus copyrighted.

You mean, you're not allowed to distributed non-transformed copies of the photo?

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#137

Earlier quoted context omitted.

> How does a website put reasonable limits on access? 1) Blocking TCP connections 2) Returning a 4XX error, perhaps even "401 Authorization Required", "402 Payment Required", "403 Forbidden", or "429 Too Many Requests" > A regular B&M store can refuse service to disruptive people and trespass people who don't comply, why not servers? A Brick and Mortar store has to _tell_ you you're being banned. The mechanisms I lis…

LinkedIn sent HiQ a C&D. They were indeed told that they were banned. Let's try a thought experiment: you're at a supermarket, and you're abusing coupons to the point where you're holding up the line for everyone. Someone complains to the manager, and the manager escorts you out of the store and tells you you're banned for life (as an aside, I wish this would happen to extreme couponers). The supermarket also has aut…

Because of the minimal amount of LinkedIn resources utilized and this not apply to all robots/extreme couponers, wouldn't this be more like a competitor checking your weekly ads posted on your front window?

Walking into a store is a clear violation of private space. Is looking at their window?

So, if you had to have an account to view any linked in information, and you got a c&d and your account banned, and you sign up for a new account, I think it would be like entering a store you've been banned from. But we're talking about information available from a public space: on your window or without an account.

I also take issue with the CFAA being used here. I'm sure there are other laws more applicable to keeping someone from talking with you.

To recap: I don't think LinkedIn is wrong to ask them to stop, I just don't think they're using the appropriate means of forcing them to.

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#138
post #65

Earlier quoted context omitted.

And when hiQ shows up looking homeless and accepts the gift of coffee, they are committing a crime?

No, but when they ask them to leave and they still take a coffee cup they are. But that's not the point, the point is it's possible to give something for free and also refuse to give it to everyone under any circumstance. They didn't give me a free cup of coffee and someone could reasonably mistake me for a homeless person based on my (lack of) fashion sense but that doesn't mean I could just reach over the counter a…

When a server sends you a response you aren't taking something, you are being given something. If the server thought you shouldn't have it, it wouldn't give it to you.

How can you say that hiQ isn't allowed to have this, but everyone else is allowed to take as much as they like? All that will happen is hiQ will create a string of shell companies that accesses LinkedIn as their proxies, and you will be wasting the court's time. Step zero is to establish that no one can have access unless authorized, and LinkedIn refuses to do this.

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#139
post #131

Earlier quoted context omitted.

It's a bit like shouting in through the doorway "Hey, how much is your coffee?"

It's closer to going into the store that had sent you a C&D, then browsing the racks to create a price list.

Which they could probably get enforced. Could they prevent you from looking through the window to get prices or just the sale prices being posted in the window?

Re: Accessing Publicly Available Information on the Internet Is Not a Crime

#140

Earlier quoted context omitted.

I find this argument to be a poor fit for the actual situation. The person that owns a coffee shop needs to let people physically enter their coffee shop in order to purchase coffee, snacks, etc. LinkedIn has no such requirement, they can easily require people establish and log into registered accounts in order to access their data. As you have said, their servers are their property and they have the ability to block…

1. If a business offers me one product for free and I take two, that's theft, plain and simple. I'm not sure what your analogy was meant to prove but I think it actually makes a stronger case for the counterpoint to your argument. 2. LinkedIn has every right to define what the use policy is for information it makes available publicly through its own product. In this case, the policy was violated, and the violator was…

If you leave things out in an open, public space without any access controls, those things are likely to be taken. A note that says "please don't take this" isn't going to change anything and I find it unlikely that you could pursue anyone legally on the grounds of "but I left a note".

LinkedIn has every right to define their use policy through technical means. If they want to make it publicly available, then they understand part of that public is their competitors. In my opinion, website operators should not get any legal protections for things they can easily do themselves through readily available technical means.

I wholeheartedly disagree that LinkedIn has any right to define the use policy for data it makes publicly available. A wide variety of data is available to the public and you can't simply sue people who use that data in a way that you dislike. If you would like to keep that data private then do so.

Post reply on HN