Live data from Hacker News

Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

documentcloud.org

211–220 of 324 posts

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#211
post #149
post #96

Earlier quoted context omitted.

There is no non-exclusive copyright. J-STOR is not the copyright owner, period. They do own the right to the composition of their collection, so someone who got the whole collection would be liable to infringing their right on the composition of the collection; in contrast, a random sample of articles would infringe on the publishers' IP rights rather than J-STOR's. The subtle point is that J-STOR is absolutely not i…

Notice on the first page of every JSTOR pdf: Your use of the JSTOR archive indicates your acceptance of JSTOR's Terms and Conditions of Use, available at . http://www.jstor.org/page/info/about/policies/terms.jsp . JSTOR's Terms and Conditions of Use provides, in part, that unlessyou have obtained prior permission, you may not download an entire issue of a journal or multiple copies of articles, and you may use conten…

"you may not download an entire issue of a journal"

I didn't know this. It's as if the New York Times told paid subscribers they can only read 90% of any one issue.

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#212

When someone risks 35 years in jail for something like this, you know your justice system is broken. I know he won't get 35 years, but it's nevertheless outrageous that it could happen.

Do you think he'd get life in Italy?

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#213

The indictment asserts that Mr. Swartz intended to distribute the files downloaded but did not substantiate this claim. I wonder what proof they have of this? (There are, of course, a great many laws dealing with probable intent that need only convince a jury of said intent without demonstrating it's validity.)

That is what he normally does. http://www.nytimes.com/2009/02/13/us/13records.html

That was what he did in that case, but it wasn't what he did with the four hundred thousand law review articles he analyzed for conflicts of interest more recently.

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#214
post #43

Earlier quoted context omitted.

> no operative security barriers in place I don't know... Even if my front door was open, you still aren't allowed to enter my house without my permission.

But there is an element of permission inherent in DHCP. Your device is actively configuring my device specifically to allow network access . It's not an open door; it's a sign saying "This way please". That said, its obvious this was an attempt to circumvent access controls.

There's an element of permission inherent in a door! I mean, it's a breach in a wall, specifically put there at great additional expense, just to allow people entry! In either case, an enabling technology isn't inherently an invitation. Again, just because you CAN use a technology to do something, doesn't mean you MAY.

And with respect to the comment about "this way please", and the "actively configuring my device", please note that the client initiates the DHCP conversation with a Discovery message.

  Discovery: "Can anyone give me DC info so I can set up my H, please?", 
  Offer: "Yes, I can, here's one configuration option!"
  Request: "Yes please, that sounds good, I'll take it"
  Ack: "Okay, you got it".
Note that the DHCP Discovery

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#215
post #49
post #25

Earlier quoted context omitted.

> Does anyone think it's odd that an Acer laptop could write these files to disk faster than JSTOR could serve them? Why would that be odd? SATA = 3 Gbps throughput with minimal overhead, Ethernet = 1 Gbps with lots of overhead (IP headers, Ethernet headers, HTTP headers)

SATA = 3 Gbps throughput with minimal overhead USB HD's top out about 200Mbit/s. JSTOR's RAID arrays should be able to drown his laptop without breaking a sweat.

It sounds like JSTOR's servers aren't really optimized for high article download rates, to the point that his one laptop accounted for a significant part of normal continental US load. They probably had some bottleneck in the system that they never noticed before — maybe their logging infrastructure was absurdly slow or something.

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#216
post #205
post #171

Earlier quoted context omitted.

Most public libraries have relationships with JSTOR that allow members to access the articles online. I use the Boston Public Library and look up articles via Google Scholar. All free.

Some public libraries do, but the vast majority of public libraries in the world do not.

Are you sure? Maybe not in the world, but I'm pretty sure all large public libraries in the US do subscribe to these kinds of databases.

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#217

JSTOR's statement http://about.jstor.org/news-events/news/jstor-statement-misu... JSTOR Statement: Misuse Incident and Criminal Case The United States Department of Justice announced today the criminal indictment of an individual, Aaron Swartz, on charges related to computer fraud and abuse stemming from his misuse of the JSTOR database. We have been subpoenaed by the United States Attorney’s Office in this case and…

This seems contrary to Demand Progress's statement:

“It’s even more strange because the alleged victim has settled any claims against Aaron, explained they’ve suffered no loss or damage, and asked the government not to prosecute,” Segal added.

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#218
post #176

Earlier quoted context omitted.

This was struck down by the courts by the way. Why? If unauthorized access is a federal offense, and unauthorized access can be determined by (e.g.) a EULA, then it basically allows a business to dictate criminal law. For example: 1. This would allow all of those 'You agree that you are not a law enforcement official' B.S. 'terms of use' on warez servers to actually have teeth. 2. "If you are a {black,hispanic,gay,et…

That's because those restrictions are illegal themselves. "Don't download the whole database" is not an illegal restriction.

* How about "You are not allowed to hyperlink to this page?"

* How about that 'MySpace Hacking' case? From Wikipedia:

  Judge Wu summed up his opinion by stating that allowing a violation of a
  website's Terms of Service to constitute an intentional access of a computer
  without authorization or exceeding authorization would "result in
  transforming section 1030(a)(2)(C) into an overwhelmingly overbroad enactment
  that would convert a multitude of otherwise innocent Internet users into
  misdemeanant criminals." For these reasons, Judge Wu granted Drew's motion
  for acquittal.  Government eventually decided not to appeal [16].
http://en.wikipedia.org/wiki/United_States_v._Lori_Drew

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#220
post #151

I don't understand why the US Attorney is suggesting he be charged with such ridiculously inflated charges. Reviewing the Indictment report, "JSTOR did not permit users... to download all of the articles from any particular issue of a journal." Further, "JSTOR notified its users of these rules, and users accepted these rules when they chose to obtain and use JSTOR’s content." So basically JSTOR is claiming Aaron viol…

Frankly, I think most of the claims in your post are bonkers, but this one sticks out:

This inconveniencing of other users could have been avoided and the blame for how JSTOR allocates resources lies with the architects of JSTOR.

"During November and December, 2010, Swartz used the "ghost laptop" (i.e., the Acer laptop) at MIT to make over two million downloads from JSTOR. This is more than one hundred times the number of downloads during the same period by all the legitimate MIT JSTOR users combined."

So we're entirely clear on this: you are saying this is reasonable and that the majority of the blame for any disruption lies with JSTOR. You are saying that JSTOR should have anticipated that a single legitimate user would have placed a hundred times the demand on the system than the entire population of a major university.

Post reply on HN