Live data from Hacker News

Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

documentcloud.org

131–140 of 324 posts

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#131

Earlier quoted context omitted.

If you read the indictment you'll see that they very much are not interested in free transmission of knowledge. They charge >$50k/yr for access: " For a large research university, this annual subscription fee for JSTOR’s various collections of content can cost more than $50,000."

That price actually seems pretty reasonable for a large research university. The real question is how much they charge individuals who want to get an article. My first google search ( http://www.jstor.org/pss/27757488 ) results in $12/article. This is very steep when you're trying to do research and don't even know if the article is what you're looking for.

Well, you wouldn't want any old rabble getting access to valuable knowledge. Far better for that access to be safely controlled by the major research institutions, who can clearly be trusted to pursue knowledge in a responsible manner.

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#132
post #128
post #95

Earlier quoted context omitted.

Speaking of "TV drama levels of understanding of criminal justice"... :) With only a few exceptions, persons accused of crimes are not presumed to have mens rea . Statutory rape, for instance, has "strict liability"; even if you don't know you're committing a crime, you're liable. Most criminal offenses are not like this. The state is required to establish mens rea . A prosecutor could say that a ToS-infringing blog…

So where's the mens rea in this case?

Aaron's? I respectfully decline to lay out a case against Aaron on HN.

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#133

Wait a minute. All he needed was a guest account to access JSTOR? That's like saying, ANYONE IS ALLOWED TO DOWNLOAD FROM JSTOR. This isn't just bad security, this is no security.

Most academic journal repositories grant institutional access based on IP address blocks. Some institutions keep this narrow and force you to use an HTTP proxy, which gives them the ability to put additional institutional-level authentication in place. The upside is that you can access the journals from off-network, the downside is using the proxy can be a major pain. Other networks, e.g. MIT, are permissive with the IP restriction and don't mandate the use of one centralized proxy as long as you are on-network. I suppose that may change after this case.

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#134
post #50

http://blog.demandprogress.org/2011/07/federal-government-in... “It’s even more strange because the alleged victim has settled any claims against Aaron, explained they’ve suffered no loss or damage, and asked the government not to prosecute,” Segal added. Nowhere do they say he did not do it however. cached: http://webcache.googleusercontent.com/search?q=cache:http://...

JSTOR is being very vague about their role in this, so that might unfortunately be wrong about just how settled JSTOR considers things on their side. Their statement feels extremely carefully worded: http://about.jstor.org/news-events/news/jstor-statement-misu...

JSTOR knows they'd better be very vague if they don't want too many rather intelligent people wondering just how they actually add value to the chain.

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#135

Why the hell is MIT stashing information in closed systems in first place? I thought the idea (OCW etc.) was to enable more people to learn, participate and benefit from work of academics and researchers. Hell I even donate a few hundred bucks every now and then to OCW. It is mind boggling how the supposedly smart people are not getting their heads out of their asses so late in a world frighteningly short on distribu…

I donate to OCW as well (LOVE OCW) but I don't think any of this information is on a closed system. I believe JSTOR allowed all mit ip addresses access (for free) to every article in their system.

Aaron's downloads came from an MIT address to the JSTOR database.

I agree with you that knowledge needs to be more accessible, but this is not the method to achieve it.

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#136
What Aaron did sounds seriously sketchy (sneaking into MIT wiring closets, trying to download the entire database, etc.), a fact that Demand Progress and several commenters here seem to be ignoring.

Defending his actions would require a very strong, multi-pronged version of the argument "if it's physically / technologically possible, it must be ok." Can MIT legally limit guest access to its network? Can JSTOR limit access to its content? Well, technically, their software didn't limit it, right? He just changed his IP address and they let him right back on, gave him permission. And then he had to change his MAC address. And then physically move to a different building.

But it doesn't matter anyway, because legal restrictions are legal restrictions. It's impossible to enforce every legal restriction in software. Put another way, we don't have to read JSTOR's server code to figure out if there's a violation of policy here -- the policy is written out as a legal document.

In the hacker world, there's a tendency to think that if something's possible, even easy, then it shouldn't be considered "breaking in" or "stealing." If my Gmail password is "password," then of course you're going to read my email! I had it coming. In the real world, though, this is still a crime.

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#138

Wait a minute. All he needed was a guest account to access JSTOR? That's like saying, ANYONE IS ALLOWED TO DOWNLOAD FROM JSTOR. This isn't just bad security, this is no security.

No, he connected to MIT's wireless network using a guest account. JSTOR grants full access to all MIT IP addresses.

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#139

He posted on his blog yesterday that there would be a "major announcement" on blog.demandprogress.org today, but nothing has been posted. http://www.aaronsw.com/weblog/updates

He also wrote this yesterday: http://www.aaronsw.com/weblog/delegation

It doesn't seem directly related but still curious.

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#140
post #121

Earlier quoted context omitted.

> They do own the right to the composition of their collection This was the point I was trying to make. They own their database, even if they don't own the articles in it. The GP poster was trying to claim that they didn't "own their archive".

> the right to the composition of their collection Is this a right recognized under US law?

IANAL, but I found some testimony from the US Copyright office regarding this.

http://www.copyright.gov/docs/regstat092303.html

Excerpt: In the terminology of the copyright law, a database is a “compilation.” The Copyright Act defines a compilation as “a work formed by the collection and assembling of preexisting materials or of data....” (1) Compilations were protected as “books” as early as the Copyright Act of 1790.

Post reply on HN