Is it even possible to "hack" an API that has no authorisation for any of its methods?
If you leave your front door open I don’t think you’d classifying someone walking in and taking your laptop as ‘not stealing’.
PS: in some countries
21–30 of 75 posts
Is it even possible to "hack" an API that has no authorisation for any of its methods?
If you leave your front door open I don’t think you’d classifying someone walking in and taking your laptop as ‘not stealing’.
PS: in some countries
Earlier quoted context omitted.
If you leave your front door open I don’t think you’d classifying someone walking in and taking your laptop as ‘not stealing’.
However walking through the door would not be a crime in itself, where I live anyway.
Just without the skin in the game.
...And with a fully grown adult requesting it to do so with zero care or due diligence. Just a whoopsie after the fact.
Why would they let media take photos of them?? I suppose as a "look this could've happened to anyone"? But it actually can't.
I guess they also must've realized that, given that the bbc interview was declined. So good on them I guess.
Is it even possible to "hack" an API that has no authorisation for any of its methods?
It's not straightforward: the conviction was eventually vacated (without really addressing the substantive point), and it is possible that the US authorities went particularly heavy in this case for other reasons.
But yes, attacking an unauthenticated API has previously met the threshold for conviction.
Earlier quoted context omitted.
Practically speaking, discovering that fact and taking advantage of it, is already "hacking".
We are used the interfaces being web interfaces. But say that the underlying api exposes some endpoint discoverability capabilities (eg. Exposing an openAPI spec), then arguably the action was invited: the actions was documented along with the auth model.
I am off to DeepSeek Flash now.
Is it even possible to "hack" an API that has no authorisation for any of its methods?
In a legal sense any unwanted intrusion can be considered hacking - i.e. a 'hack' is not contingent on penetrating authorization. In practice most APIs are secured by obscurity rather than any high quality rigorous authorization. The only thing it would make absolutely clear at a legal level is that you do not want the API to be publicly used, but for a jury/judge accessing an unadvertised API via browser tools is ha…
Surely surely there are apps that use AI to watch you while you do at-home pilates and tell you if you are doing it wrong, need to suck in that bit or straighten that bit?
Is it even possible to "hack" an API that has no authorisation for any of its methods?
In a legal sense any unwanted intrusion can be considered hacking - i.e. a 'hack' is not contingent on penetrating authorization. In practice most APIs are secured by obscurity rather than any high quality rigorous authorization. The only thing it would make absolutely clear at a legal level is that you do not want the API to be publicly used, but for a jury/judge accessing an unadvertised API via browser tools is ha…
We have laws, and LLMs should NEVER break them unless the user states its fine with some qualifying condition. Yes, every country has a different legal system, but I think there's a decent idea of what constitutes intrusion thats agreed on in most parts of the world.
In grey area scenarios, the user should be able to override this, with a warning of clear consequences of, and should they accept, users should be held criminally liable.
If the LLM does so unprompted, the responsibility should be the providers'.
LLMs should be considered tools, legally speaking.