Please seek better legal representation.
There's legislated protection for you and also already US case law as precedent.
21–30 of 54 posts
Please seek better legal representation.
There's legislated protection for you and also already US case law as precedent.
Earlier quoted context omitted.
This is a little different. This is akin to knocking on the door, asking if you can be let in, being invited in by the homeowner, and then having them give a tour around the house. It's entirely up to the owner of an S3 bucket as to who they serve their static assets to. If the policies are so lenient that anyone can request the resources, then that is a configuration error—not unauthorized access.
You are falsely assuming that allowing public access and serving the requested object constitutes an intentional act of invitation by a bucket owner. If the alleged victim sought the FBI's assistance, it seems pretty clear that they did not intend to extend such an invitation, regardless of the bucket's configuration. Or, to extend the metaphor I made earlier, just because I left the door unlocked, it doesn't mean I…
> Unauthorized access can occur whether the bucket is public or not. The law does not require that sufficient measures (or any measures, really) be taken to protect the assets in question. We can disagree as to whether it should, but that's not how it's written today.
Citation needed. Probably more than one. Web scraping is most certainly legal. Everything involved in the ridiculous "breaking and entering an unlocked residential door" is done a billion times a day by web scrapers as a matter of course. The act if doing GET / wraps up finding a home, evaluating its entrances, knocking, opening the door, and taking photos of the entryway. In 50ms.
I do agree with your last line. Definitely think about whether a judge would laugh at you or not...
https://en.m.wikipedia.org/wiki/Inline_linking
It seems Google saved its butt with that explanation. Can you do the same?
Earlier quoted context omitted.
You are falsely assuming that allowing public access and serving the requested object constitutes an intentional act of invitation by a bucket owner. If the alleged victim sought the FBI's assistance, it seems pretty clear that they did not intend to extend such an invitation, regardless of the bucket's configuration. Or, to extend the metaphor I made earlier, just because I left the door unlocked, it doesn't mean I…
Please don't attempt to equate internet traffic to door locking. It's a tired old argument that fails the moment critical thought is applied. > Unauthorized access can occur whether the bucket is public or not. The law does not require that sufficient measures (or any measures, really) be taken to protect the assets in question. We can disagree as to whether it should, but that's not how it's written today. Citation…
It's a useful metaphor that gets people convicted. You might not like it or agree with it, but that's the way it is.
> Web scraping is most certainly legal. Everything involved in the ridiculous "breaking and entering an unlocked residential door" is done a billion times a day by web scrapers as a matter of course
Unfortunately you, like others, are ignoring the crucial element of consent. Web scraping is done lawfully only with the consent of the website scraped. When scraping is done non-consensually -- even if the website is public -- it can be considered trespass to chattels and might even constitute a CFAA violation. I know this because my company scraped eBay without their consent in the late 1990s/early 2000s and was shut down by a lawsuit. See, e.g., eBay v. Bidder's Edge, 100 F. Supp. 2d 1058 (N.D. Cal. 2000) (not my specific employer at the time, but in the same business).
Ignore robots.txt at your peril, and treat the absence of one as a lack of consent. That's what Google and other search engines do.
Why are you facing any liability whatsoever for linking to public resources? If the owner of that S3 bucket is facing losses from serving files to the public, why don't they revoke public access? S3 prints big warnings that you are making things public, so it's unreasonable for a company to claim "We didn't mean to make this public" What was in the bucket? In any case, sounds like you need a better lawyer, I don't se…
Why are you facing any liability whatsoever for linking to public resources? If the owner of that S3 bucket is facing losses from serving files to the public, why don't they revoke public access? S3 prints big warnings that you are making things public, so it's unreasonable for a company to claim "We didn't mean to make this public" What was in the bucket? In any case, sounds like you need a better lawyer, I don't se…
It’s probably not about the contents being public but more about paying the bandwidth costs.
This story doesn’t really make sense. What would you risk by truthfully telling us what company and what kind of assets you’re talking about? You shouldn’t be having this conversation with the FBI anyway, these details are figured out in courts.
Most likely OP cannot afford the team of comprehensive legal advisors which would be necessary to achieve a truly fair outcome. I imagine OP has been dealing with this situation mostly silently for approximately a year by now. The "wheels of justice" turn slowly but generally inexorably. Once the FBI decides to bring charges, they almost always have already completely made up their mind and get exactly the outcome th…
As it stands his post doesn’t really provide any useful details beyond “I’m facing federal charges and am not happy with my lawyer”.
Earlier quoted context omitted.
Please don't attempt to equate internet traffic to door locking. It's a tired old argument that fails the moment critical thought is applied. > Unauthorized access can occur whether the bucket is public or not. The law does not require that sufficient measures (or any measures, really) be taken to protect the assets in question. We can disagree as to whether it should, but that's not how it's written today. Citation…
> Please don't attempt to equate internet traffic to door locking. It's a tired old argument that fails the moment critical thought is applied. It's a useful metaphor that gets people convicted. You might not like it or agree with it, but that's the way it is. > Web scraping is most certainly legal. Everything involved in the ridiculous "breaking and entering an unlocked residential door" is done a billion times a da…
It's a blatantly false metaphor. Burglary requires intent to commit a crime once inside.
This is not legal advice. IANAL. Please seek better legal representation. There's legislated protection for you and also already US case law as precedent.
That's how I see it. The government has obscene resources and power to prosecute you. Even if you win, you'll likely be screwed with the cost to defend. The law generally favors the victim and in many cases judges seem to accept any amount that can explained, even if it's not fair.