Live data from Hacker News

Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

documentcloud.org

251–260 of 324 posts

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#251

JSTOR's statement http://about.jstor.org/news-events/news/jstor-statement-misu... JSTOR Statement: Misuse Incident and Criminal Case The United States Department of Justice announced today the criminal indictment of an individual, Aaron Swartz, on charges related to computer fraud and abuse stemming from his misuse of the JSTOR database. We have been subpoenaed by the United States Attorney’s Office in this case and…

"Our mission at JSTOR is supporting scholarly work and access to knowledge around the world. Faculty, teachers, and students at more than 7,000 institutions in 153 countries rely upon us for affordable and in some cases free access to content on JSTOR. Since our founding in 1995, we have digitized the complete back runs of nearly 1,400 academic journals from over 800 publishers. Our ultimate objective is to provide a…

50k is cheap as hell. UMass Boston had 125,000 JSTOR downloads last year. Let's assume we pay $50k (close enough), that's 40 cents an article. This is cheap as hell compared to other databases that charge more than that for a single search!

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#252

The repeated use of "stole" in the indictment is interesting, even beyond the usual metaphorical usage to discuss copyright infringement. In this case, the indictment alleges that the documents were stolen from JSTOR , which does not even own them! In the vast majority of cases JSTOR scanned documents whose copyright is owned by someone else, and acquired or was donated a non-exclusive license to distribute copies vi…

Let's try another analogy.

What if someone hacked into Netflix and downloaded copies of all of the media that Netflix offered?

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#253

This reminded me of Jacques Mattheij's list of ideas for startups (see http://jacquesmattheij.com/My+list+of+ideas+for+when+you+are... ): "(45) OpenPapers A place where all academic research that has been funded in part by public funds is published, journals be damned. Hopefully with deep pockets to fight off the lawsuits."

For NIH-funded studies, PubMed Central is actually doing a pretty good job. It would be great if PMC actually had a mandate to collect papers for all US federal grant-funded research, though.

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#254
post #87

Earlier quoted context omitted.

They are talking about theft of services, not copyright infringement. In any event these charges are going to be very difficult to beat since they're federal, even though there are some obvious holes in the indictment. It will be almost impossible to get any of the evidence thrown out even if there was an illegal search and seizure. His best bet is probably to get the Harvard legal team to go to bat for him, although…

> They are talking about theft of services if it's theft of service why measure it on number of works? it's like accusing you of using your neighbour wifi to steal over one thousand emails (which you read from your own email account)

My point being, i have no idea what service they provide, didn't read the fine article. But if they have an all-you-can-eat plan for like $300 a month per seat. Then the charges should have been "joe doe hacks MIT network and steals $300 worth of replaceable goods".

In the same lines that if someone break into a car-wash and use 5min of their water, he will hardly be convicted of organized crime and causing damages over $300 (because that's what they charge for the premium wash)... why it's so messed up when you put a computer in the middle?

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#255

Ignoring legality, Aaron's actions, case specifics, etc., I have to admit: I really wish that the data in question was free and publicly available.

And you have a right to demand it: by federal law, all publicly funded research should be in the public domain (unless national security blah blah blah...). Unfortunately this law isn't enforced except in some aspects through provisions of all recent NIH grants (and maybe others).

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#256
post #242

Earlier quoted context omitted.

I don't think hyperlinking is the crime in question for this case.

My post wasn't very clear. I was making two separate points.

There are two separate issues as well, whether or not a restriction is valid and the ease with which it is circumvented. Lots of EULA/TOS terms are unreasonably broad. But let's say the TOS says "use of service without a password is unauthorized". Seems reasonable.

Somebody runs a program to guess passwords until they find one that works. "Ah ha," they say, "I have a password, so my usage is now authorized." I don't think a judge or jury will buy that. Even if the password was easy to guess.

I believe that was SpikeGronim's point. Assuming the definition of unauthorized is legit, there's no such "it was too easy" defense. Or "I could do it, therefore I must have been allowed to do it."

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#257

Earlier quoted context omitted.

IANAL, but legally speaking unauthorized access is a crime regardless of how easy it was to gain access.

This is a very frightening belief. How long until posting a negative comment to a blog is "unautorized access" to that blog? Gaining access was easy: all you had to do was type a comment and hit submit. But some Powers That Be decided they didn't really want you to post that, so now it's a federal computer crime. Land of the free.

You're getting hung up on the "access" part, it's the "authorization" that's important. In your example it would likely be almost impossible for the blog owner to prove that someone intent on posting negative comments was not authorized to do so.

As a side note, I think we all should be more careful with "omg, we're losing our freedoms!" comments. They're usually not as clever as they feel at the time, and have the dangerous property of inuring us to such claims.

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#259

Earlier quoted context omitted.

"Our mission at JSTOR is supporting scholarly work and access to knowledge around the world. Faculty, teachers, and students at more than 7,000 institutions in 153 countries rely upon us for affordable and in some cases free access to content on JSTOR. Since our founding in 1995, we have digitized the complete back runs of nearly 1,400 academic journals from over 800 publishers. Our ultimate objective is to provide a…

50k is cheap as hell. UMass Boston had 125,000 JSTOR downloads last year. Let's assume we pay $50k (close enough), that's 40 cents an article. This is cheap as hell compared to other databases that charge more than that for a single search!

It's further harming the possibilities of being an independent scholar or even reading academic literature outside academia, though, which I think is a significant detriment to academia. I'm not as worried about the $50k a university library has to pay, but if you're an independent scholar for even one year, it becomes clear how harmful to the research community JSTOR is.

Journals that used to sell archive access to individuals for, say, $50 or $100 annually, now won't sell you a membership at all, because to save money on hosting they've moved their subscription infrastructure to JSTOR, and JSTOR refuses to sell individual subscriptions. So you end up "stealing" your access; at various times I've gotten my JSTOR access via ssh -D proxies to a friendly grad student. Now I try to return the favor by providing such access to independent scholars where needed. This sort of gaming shouldn't be necessary with a non-profit organization that is supposed to be working in the public interest, though. Hell, public domain journals from the 18th century that were scanned using public grant money are locked up behind a JSTOR paywall!

Re: Aaronsw indicted for hacking MIT network to download millions of JSTOR docs

#260
post #19
post #5

How did Aaron get access to the for-pay articles (page 9)? Also: nice going, Aaron! Drag research access into the 21st century, kicking and screaming! Does anyone think it's odd that an Acer laptop could write these files to disk faster than JSTOR could serve them?

Yeah, I was laughing about how an Acer laptop took down their service and did damage to their network. If I was JSTOR, I wouldn't prosecute just because it makes our company look ridiculous.

Because, of course, JSTOR plans for 100x usage spikes and performs neither logging nor accounting, so serving a file is just as simple for them as downloading it is for the client.
Post reply on HN