Live data from Hacker News

Using a VPN could become a criminal offence under new CFAA interpretation

news.ycombinator.com

51–60 of 98 posts

Re: Using a VPN could become a criminal offence under new CFAA interpretation

#51
post #45

Earlier quoted context omitted.

I really wish that every legal professional and judicial administrator had some rudimentary computer science knowledge. Having friends whom are lawyers, I can tell you that most of them don't have any meaningful understanding of technology becauae they spend so many years of their career heads down on what is effecctively paperwork. They know enough to realize how bass ackwards their industry is when it comes to tech…

It would start with us software engineers to be more exact in our communications. For an engineering discipline, we’re terrible at it. Take your example. I don’t know whether a web page is encrypted. I do however know whether the transmission of one request of some website contents to a specific web browser is. But that won’t yet tell me whether the communication between me and the website has stayed confidential bet…

Whether data through an encrypted channel remains confidential isn't really relevant to my point. I didn't say "confidential", I said "encrypted". The distinction you are making with encryption and confidentiality seems conflated; if the channel is uses encryption, then the data is by virtue encrypted. It's another story if we are talking about data arriving from any channel with another layer of encryption for confidentiality.

Re: Using a VPN could become a criminal offence under new CFAA interpretation

#52

>> VPN to get access to content that is otherwise blocked in your country through an IP Block for example could become a criminal offence as well. Yes. Accessing material that has been deemed illegal enough to be the subject of a country-wide block is generally going to be a criminal offense. We might all hate censorship, but the people who write the censorship laws are the same as the ones writing the criminal laws.…

From the context, (CFAA, a US law) "VPN to get access to content that is otherwise blocked in your country through an IP Block" wouldn't be referring to using a VPN to bypass blocks imposed by "your local government" or censorship-related issues, but rather circumventing blocks imposed by US-based content providers. Hypothetical scenario: User outside the United States uses a VPN to access US Netflix content. In doin…

Better hypothetical scenario:

User inside the United States uses a VPN to access foreign Netflix content.

Re: Using a VPN could become a criminal offence under new CFAA interpretation

#53
post #7

It's not being talked about because there's no evidence of "new CFAA interpretation" until the court says something like that. It's very common for parties to try and argue all kinds of extreme interpretations of law that might favor their case, with the expectation that it most likely will be refused but hey, it's worth to try; but they are not newsworthy until/unless the court actually considers the argument as val…

So only after it’s precedent and harder to undo then does it matter? This is basically saying there’s no point in testing software, ship every line to prod and see what happens. This is exactly the kind of political ennui the system purposely tries to inculcate. Not fine grain mind control, but indifference. Laws dictate acceptable social agency. One might think we’d take what ends up in them at least as seriously as…

It would be appropriate to start such a discussion once a single court ever has accepted such an argument and it gets appealed and starts a years-long process where it might become precedent for some wider area; it would be absolutely ridiculous to consider every theory put forth by a litigating lawyer as worth of a public discussion - I mean, there are so many of them and usually the judges shoot many of them down without a discussion because it's not worth a discussion even for the people it directly affects, much less general public.

Re: Using a VPN could become a criminal offence under new CFAA interpretation

#54
post #50

Earlier quoted context omitted.

So only after it’s precedent and harder to undo then does it matter? This is basically saying there’s no point in testing software, ship every line to prod and see what happens. This is exactly the kind of political ennui the system purposely tries to inculcate. Not fine grain mind control, but indifference. Laws dictate acceptable social agency. One might think we’d take what ends up in them at least as seriously as…

notTheAuth is a pedophile! What are you going to do to fight this? Maybe it's just not something worth pursuing?

I understand the point you're trying to make (e.g. making a hyperbolic claim and leaving the onus on the accused to disprove it), but I think if you wanted to avoid downvotes while making the same point, you might have better luck saying something like:

> How would you feel if I said " is a pedophile! What are you going to do to fight this? Maybe it's just not something worth pursuing?"

And then spend a bit of time explaining why this reasoning doesn't make sense to you. I'm a relative veteran of HN and even I had to do a double-take because I thought you were genuinely accusing the person of being a pedophile.

Re: Using a VPN could become a criminal offence under new CFAA interpretation

#55
post #7

It's not being talked about because there's no evidence of "new CFAA interpretation" until the court says something like that. It's very common for parties to try and argue all kinds of extreme interpretations of law that might favor their case, with the expectation that it most likely will be refused but hey, it's worth to try; but they are not newsworthy until/unless the court actually considers the argument as val…

So only after it’s precedent and harder to undo then does it matter? This is basically saying there’s no point in testing software, ship every line to prod and see what happens. This is exactly the kind of political ennui the system purposely tries to inculcate. Not fine grain mind control, but indifference. Laws dictate acceptable social agency. One might think we’d take what ends up in them at least as seriously as…

What do you think will happen if you start campaigning against a certain interpretation of the law now?

The court will still decide based on what is actually written down.

If it needs to be changed that has to come from the politicians.

Re: Using a VPN could become a criminal offence under new CFAA interpretation

#56
post #9

Well… first it’s not a « public » website; like Facebook and Google, you connect to a privately owned server and, while the « path » is public, the server you contact isn’t. So they are well within their right to block anyone. But trying to make illegal a way to bypass their security is a really dangerous way and if they win, then many, many, privacy tech would have a problem. Hope the judge know how to use a compute…

I really wish that every legal professional and judicial administrator had some rudimentary computer science knowledge. Having friends whom are lawyers, I can tell you that most of them don't have any meaningful understanding of technology becauae they spend so many years of their career heads down on what is effecctively paperwork. They know enough to realize how bass ackwards their industry is when it comes to tech…

I don't like this line of thinking at all. Legal professionals are supposed to know the law and to ask experts for other things. Just like a judge and jury in a murder case are unable to understand how DNA analysis works, they don't have to understand how computer systems work.

The only thing worse than a judge who doesn't understand the first thing about computers would be a judge who thinks they understand computers but doesn't.

Re: Using a VPN could become a criminal offence under new CFAA interpretation

#58
post #54
post #50

Earlier quoted context omitted.

notTheAuth is a pedophile! What are you going to do to fight this? Maybe it's just not something worth pursuing?

I understand the point you're trying to make (e.g. making a hyperbolic claim and leaving the onus on the accused to disprove it), but I think if you wanted to avoid downvotes while making the same point, you might have better luck saying something like: > How would you feel if I said " is a pedophile! What are you going to do to fight this? Maybe it's just not something worth pursuing?" And then spend a bit of time e…

Honestly, I really hope that I don't need to explain the logic behind my comment. It should be obvious to anyone willing to spend more than a couple of seconds thinking about it. I would hope that on HN we'd actually try to read and understand the comment we're voting on.

Of course I'm being overly optimistic, but I'd prefer to be naive and wrong than cynical and right.

Re: Using a VPN could become a criminal offence under new CFAA interpretation

#59
It's just not that dire yet.

For one, the court hasn't ruled yet. This is purely LinkedIn's argument, and they're allowed to argue anything they want. They could argue that hiQ isn't allowed to access their service because the company name doesn't start with a capital letter if they wanted to. They wouldn't win, but they could make the argument.

Secondly, if you read the context of the case, this is not a situation a normal person is at all likely to find themselves in. hiQ was specifically sent a cease and desist, which is why "bypassing an IP block" is couched in "intentionally and knowingly". IANAL, but a follower of the law, and my layman's reading of that is that LinkedIn is intentionally scoping this to only target subjects that have previously been sent a cease and desist.

And finally, even if they did do that, it's unlikely to impact VPNs for streaming. I severely doubt that any first world country would extradite one of their citizens to the US to face charges for bypassing an IP block.

Within the US, I still doubt the charges would be used like that even if they could. I don't think this is something the FBI is going to spend resources on proactively tracking, so it would be up to Netflix et al to push the cases. I really strongly doubt they would do that. "Paying Netflix customer sued by Netflix for watching content he wasn't supposed to" is a really bad PR headline, and it's mainstream-adjacent enough to get picked up by major news networks. That's a really hard story to spin, and I strongly suspect the bad PR would cost much, much more than people try to avoid region-locks (who are likely to just pirate it if VPNs become CFAA-able).

Re: Using a VPN could become a criminal offence under new CFAA interpretation

#60
post #9

Well… first it’s not a « public » website; like Facebook and Google, you connect to a privately owned server and, while the « path » is public, the server you contact isn’t. So they are well within their right to block anyone. But trying to make illegal a way to bypass their security is a really dangerous way and if they win, then many, many, privacy tech would have a problem. Hope the judge know how to use a compute…

>But trying to make illegal a way to bypass their security is a really dangerous way and if they win, then many, many, privacy tech would have a problem. IIUC, there was no attempt to "bypass security." Rather, HiQ Labs was scraping unrestricted (i.e., not restricted by user ACLs) portions of Linkedin's web platform. If any random user can access a particular web page, it's (IMHO) publicly available and using automat…

> IP blocks (I'm thinking geo-blocks[0] for sites like Netflix) are sometimes necessary for the site to at least attempt to stay in contractual compliance with the content owners.

The entire thing is a farce. There has never been any way to know where an endpoint device is

And VPNs are often necessary to prevent the service from detecting it wrong.

Suppose I'm currently near an international border and my phone picks up a tower on the other side of the border. Now the IP address my phone gets is listed as being in the wrong country.

A lot of companies route all their traffic through a head office somewhere so they can inspect the traffic in a central location. It's not always in the same country where the users are.

Suppose I'm using a VPN for privacy reasons, not to bypass geographic restrictions, but I want it to be in a different country to maximize the inconvenience to anyone trying to violate my privacy, so now the country listed is the wrong one. I would have to use another VPN to get it back to being where I actually am.

The obvious solution to all of this is to forget about trying to tie locations to IP addresses, since that has never worked, and just ask the user's device what country it's in. The user can set it to a different one but that's no different than the status quo.

Post reply on HN