Live data from Hacker News

Courts: Violating a Website’s Terms of Service Is Not a Crime

eff.org

41–50 of 174 posts

Re: Courts: Violating a Website’s Terms of Service Is Not a Crime

#41
post #17

IANAL, but violation of terms of service seems like a breach of contract, not a crime. For that sort of thing there is always the civil court system if the plaintiff feels like their loss due to the violation is high enough to warrant pursuing the legal case. But maybe the actual loss caused by the automated downloads in this case wasn't high enough and they pushed the criminal angle to make some kind of point.

Oracle, not being the state government of either California or Nevada, could not and did not “push the criminal angle”, they filed a civil action charging violation of both federal copyright law and two. states anti-hacking laws; the latter allow both civil and criminal actions.

They also, it may be worth noting, won on the copyright claims.

Re: Courts: Violating a Website’s Terms of Service Is Not a Crime

#42
post #18
post #2

This is positive news. It seems like the more liberal approach taken when protocols were written is being challenged more by young users who grew up under more stable rules that accepted terms of service as very strong. When I was growing up you went by what the protocol allowed. If an http response came back you have access, if it prompted for credentials, then you didn’t have access. The mere idea that a web server…

I continue to be shocked that Twitter convinced an entire generation of software developers that you need to obtain something called an "API key"--which can somehow be refused or even revoked once granted--in order to write a client for their protocol. "Back in my day", we just reverse engineered the official client and used whatever algorithm it used to talk to the server and called the war won :/.

I dunno about that.. controlling access to your server is much more important today because tech is ubiquitous, and a big target for bad actors. In the old days very few people would know enough and care enough to reverse engineer your protocol.. when a service has billions of users and valuable data, that changes.

If Twitter did not have an API key, they would spend 2x the money on absorbing & defending against DDoSes and security vulnerabilities. That cost would get passed on to us with frequent outages and many more ads in our feeds. Or a leak of someones DMs.

Re: Courts: Violating a Website’s Terms of Service Is Not a Crime

#43
post #18

Earlier quoted context omitted.

I continue to be shocked that Twitter convinced an entire generation of software developers that you need to obtain something called an "API key"--which can somehow be refused or even revoked once granted--in order to write a client for their protocol. "Back in my day", we just reverse engineered the official client and used whatever algorithm it used to talk to the server and called the war won :/.

Is this system of "API keys" why Pidgin doesn't handle all these new IM protocols, and why there's no other good old-fashioned multi-protocol clients for them (that I'm aware of)?

Because reverse engineering some IM protocols is far from trivial. Skype, in particular, is a nightmare of obfuscation, as I understand (second hand knowledge from having wanted to replace it with Pidgin in the past, I haven't tried reverse engineering it myself).

Re: Courts: Violating a Website’s Terms of Service Is Not a Crime

#45
post #2

This is positive news. It seems like the more liberal approach taken when protocols were written is being challenged more by young users who grew up under more stable rules that accepted terms of service as very strong. When I was growing up you went by what the protocol allowed. If an http response came back you have access, if it prompted for credentials, then you didn’t have access. The mere idea that a web server…

It's not that young people grew up with stable rules. It's that young people grew up under the influence of industrial information warfare tactics and propaganda. As someone that was prevented from distributing Linux at high school because the administrators thought that any copying was piracy (thanks to the Software Publishers Association and the friendly local Microsoft rep), this conditioning to get kids (and less…

It might be that...

I also like to think that young people just don't really understand the full picture of how all of this actually works...they just think they do and that google/SO/wikipedia contains the answers they they don't have to know.

Our abstraction layers are that good. You can write code in a framework, ship and make millions and suddenly you're a tech genius!

In fairness to them though, when I was starting out 20 years ago, if you could sling a few lines of HTML and make things appear in a browser, people certainly treated you like one.

Re: Courts: Violating a Website’s Terms of Service Is Not a Crime

#46

Earlier quoted context omitted.

Is this system of "API keys" why Pidgin doesn't handle all these new IM protocols, and why there's no other good old-fashioned multi-protocol clients for them (that I'm aware of)?

Because reverse engineering some IM protocols is far from trivial. Skype, in particular, is a nightmare of obfuscation, as I understand (second hand knowledge from having wanted to replace it with Pidgin in the past, I haven't tried reverse engineering it myself).

Skype I know is infamously hard, but I'm wondering about the more general case -- are the problems there similar to the problems with Skype, or are they due to something else?

Re: Courts: Violating a Website’s Terms of Service Is Not a Crime

#47

Earlier quoted context omitted.

It's not that young people grew up with stable rules. It's that young people grew up under the influence of industrial information warfare tactics and propaganda. As someone that was prevented from distributing Linux at high school because the administrators thought that any copying was piracy (thanks to the Software Publishers Association and the friendly local Microsoft rep), this conditioning to get kids (and less…

I don't think that it warrants a name so grand-sounding as 'industrial information warfare tactics and propaganda'. I don't even believe it was done entirely intentionally. When I was going to school in the 90s, schools were locking down more and more each year. Eventually, that produced Columbine and several other school shootings, intensifying their efforts (they were blind to the fact that they were the cause). Ev…

wow, so if you believe there is systemic 'infliction of learned helplessness' on pre-adolescent children, then it does warrant a 'grand-sounding name'.

Re: Courts: Violating a Website’s Terms of Service Is Not a Crime

#48
post #2

This is positive news. It seems like the more liberal approach taken when protocols were written is being challenged more by young users who grew up under more stable rules that accepted terms of service as very strong. When I was growing up you went by what the protocol allowed. If an http response came back you have access, if it prompted for credentials, then you didn’t have access. The mere idea that a web server…

yes, we young people are a completely uniform group. Thanks.

Re: Courts: Violating a Website’s Terms of Service Is Not a Crime

#49
The EFF write up requires a bit of a caveat. The EFF states: "Oracle sent Rimini a cease and desist letter demanding that it stop using automated scripts, but Oracle didn’t rescind Rimini’s authorization to access the files outright."

That's true, but it would be incorrect to infer that the Ninth Circuit's holding in this case means that such a cease and desist is ineffective to revoke notice for purposes of the CFAA. To the contrary, the Ninth Circuit has held that where a defendant, "after receiving the cease and desist letter from" the plaintiff, "intentionally accessed [plaintiff's] computers knowing that it was not authorized to do so," the defendant was "liable under the CFAA." Facebook, Inc. v. Power Ventures, Inc., 844 F.3d 1058, 1069 (9th Cir. 2016).

The cease-and-desist letter dropped out of this case, because Rimini was accessing Oracle's website under delegated authority from Oracle customers, who had a contractual right to access the site. Oracle chose not to press the argument that it could limit the delegated authority from the customers by virtue of the cease and desist, I suspect because the wording of the cease and desist did not actually revoke Rimini's authorization to access the files. Oracle thus was stuck arguing that violating the TOS, despite otherwise having authorization to access the data, was enough to violate state-law counterparts to the CFAA. That latter argument was a losing one in light of United States v. Nosal, 676 F.3d 854 (9th Cir. 2012), where the Ninth Circuit held that a terms of service provided insufficient notice to alleged offenders to create liability under the CFAA.

Re: Courts: Violating a Website’s Terms of Service Is Not a Crime

#50
post #2

This is positive news. It seems like the more liberal approach taken when protocols were written is being challenged more by young users who grew up under more stable rules that accepted terms of service as very strong. When I was growing up you went by what the protocol allowed. If an http response came back you have access, if it prompted for credentials, then you didn’t have access. The mere idea that a web server…

[deleted]
Post reply on HN