Live data from Hacker News

Teenager facing prison for downloading unsecured files from government website

cbc.ca

271–280 of 502 posts

Re: Teenager facing prison for downloading unsecured files from government website

#271
post #256

Earlier quoted context omitted.

> In fact many resources can be discovered by programmatic access, and there is no inherent reason to think this is wrong. Just because an API isn't documented doesn't make using it illegal. The license to access private property is based on the intent of the property owner. Where the intent is made express (through a sign), that governs. Where the intent is not made express, we try to figure out what a reasonable pe…

I can see where you're coming from but you're also describing the purpose of an API, documented or not. Ultimately, if you want to secure the boundaries of your property (whether that's your app or your domain or your honest to god physical land) it's up to you. If you find yourself in the position where other people are revealing information you or your company should have protected then you are accountable. You hav…

The guy who found the problem or abused it is not accountable.

This is clearly wrong.

If I forget to lock my door when leaving my house one morning it's still trespassing if you enter the house without my permission.

Re: Teenager facing prison for downloading unsecured files from government website

#272
post #247

Earlier quoted context omitted.

A link is not someone giving you permission, it's merely telling you where something else is. I can't think of how you even came to this conclusion. It's like you have this incredibly restricted view of the internet, limited to people clicking on a browser, and think that's enough for protecting files. It's not. You don't seem to realize how bad of an idea this is. You're talking about making criminals of people. You…

I have a view of the Internet where “protecting files” has nothing to do with whether access to files is authorized or not. I shouldn’t have to lock my door, and I shouldn’t have to lock down my web server. (It may be prudent to do those things, but a trespasser shouldn’t escape penalty just because I didn’t do those things.)

Your view of the internet only applies to things that aren't the internet. There exists no real governance or real ownership on the internet. These things do exist in some capacity, for the most part, in the physical world within national boundaries. Even still, if this were the physical world and some house existed, with an open door and outside the generally agreed upon distinction of what private property is, then you'd bet your ass I'd walk in and snoop around. If the owner came by and said "Hey! This is private propertay. I'll have you arrested!" then he'd certainly have the right to do so. I could then argue that there was no reason to think that this was private property because the door was open and it looked like public facility.

Re: Teenager facing prison for downloading unsecured files from government website

#273

Earlier quoted context omitted.

A bit more complicated than that but I am sympathetic to this persons plight. What complicates this is if the website had a Terms of Use policy, if not then outside of existing statutes I can't see how he is guilty. Even if their are terms of use, I think these are useless if I have not agreed before entering the site. All very confusing. The blame truly lies on the government for allowing such porous security. They…

Violating Terms of Use is not a crime [1]. 1: https://www.eff.org/deeplinks/2010/07/court-violating-terms-...

I agree, however it is worth noting that this link probably only falls within the jurisdiction of the U.S.

Re: Teenager facing prison for downloading unsecured files from government website

#274

Earlier quoted context omitted.

Phones, bullhorns, billboards, postcards, bumper stickers, guitars, TV transmitters, etc. are dumb pieces of property that people use to communicate. (Why don't I have to get permission to look at your billboard?) Computing devices are different from most of these in a single respect: they can act autonomously, as their operators intend. In fact it is customary that they do so, just as it is customary that billboards…

> There's nothing anthropomorphic about recognizing that intent may be coded in such a way that a computer obeys that intent. What a computer does may be evidence of intent, just as a lock (or lack thereof) may be evidence of intent. But just like an unlocked door is not evidence of intent to make something accessible, neither is an unlocked computer. > Consider, if you will, whether your preferred position is one th…

I think your arguments are well-reasoned, but I also think that you, along with others here making analogies to libraries/filing cabinets/etc. are too eager to equate physical access to internet access.

In the physical world, one can accidentally walk into a room they shouldn't have, perhaps mistaking it for the bathroom, and then leave without having committed any transgression. Entering a room you shouldn't be in doesn't mean you've automatically taken the contents of the room. On the internet, however, visiting a URL means just that. There's no "oh, it looks like I shouldn't be here" opportunity.

URLs are not doors. They aren't rooms. The same reasoning can't be applied to them, as they behave in fundamentally different ways.

Re: Teenager facing prison for downloading unsecured files from government website

#275
post #224
post #212

Earlier quoted context omitted.

Maybe we need to shift the metaphor. A situation like this (security wise) isn't like leaving a window unlocked and having someone rob your house it's like 1. Leaving a pie on the window sill overhanging the side walk with paper plates and plastic utensils beside it. 2. A man knocking on your door, asking you for your bank account number without impersonating anyone of authority, you offering it up freely, then suing…

The problem is the metaphor itself. The metaphor avoids the problem by providing a more trivial or palatable debate, it takes the attention away from the teen in trouble to the definition of the problem and at that point you've stopped caring about the person, you're caring about the problem. This guy facing prison doesn't give a shit about it feeling like a man stealing a pie from your window. It's nothing close to…

Reframing is a favorite tool of authoritarians. They just turn a knob and the new frame gets parroted by the media for weeks.

Re: Teenager facing prison for downloading unsecured files from government website

#276
post #173
post #19

And this is why I'm going to route all my kids traffic through an offshore VPN by default and whitelist low latency stuff.

I've been thinking I wanted a router with two wi-fi networks. One that goes through the ISP and one that goes out over a proxy. I haven't found a solution just yet. I guess a raspberry pi with iptables and routing based on device ID could do the trick too.

I have just set this up a week ago at my apartment. I use hostapd and dnsmasq on a raspberry pi to make it a wireless AP. It is connected to the primary router via ethernet and uses iptables to route wifi traffic via ethernet. Then I just installed OpenVPN to route traffic via a VPN. I haven't tested for DNS leaks yet as this is an ongoing project.

There are a couple of other things on my todo list still. Such as easier switching of VPN node (current method is to ssh in and restart OpenVPN with a new config...) and ad blocking.

Hope this can help you although it's still a bit immature and quite hacky IMO

Re: Teenager facing prison for downloading unsecured files from government website

#277

Earlier quoted context omitted.

I disagree, because the analysis is faulty. Computers always do what you _tell_ them to do, not what you want them to do. The onus for keeping computerized material private is on the owner, and the owner screwed up royally by wrongly allowing sensitive material to be placed unprotected on a _public_ web site. Whether or not it was indexed is irrelevant - it was on a publicly accessible site, permissions set to public…

> The onus for keeping computerized material private is on the owner I don’t think that’s a sensible rule and at the end of the day, it’s not the one that’s going to prevail. The Internet will be sanitized and made safe for all the people who forget their passwords and write them in their monitors. The Internet is for ordinary people now, not curious teenager hackers. And ordinary people will make the rules to suit t…

Ordinary young people already laugh at this sort of ignorance. Ordinary old people will die soon.

Re: Teenager facing prison for downloading unsecured files from government website

#278

Earlier quoted context omitted.

The computer is not a person and what it does only matters insofar as you may infer that the owner of the property programmed it to do what the owner intended. As you admit, the property owners did not intend those documents to be accessible. So the only relevant question is: would a reasonable person infer that documents which could only be accessed by editing a URL (by "tricking the HTTP server," if you insist on a…

I disagree, because the analysis is faulty. Computers always do what you _tell_ them to do, not what you want them to do. The onus for keeping computerized material private is on the owner, and the owner screwed up royally by wrongly allowing sensitive material to be placed unprotected on a _public_ web site. Whether or not it was indexed is irrelevant - it was on a publicly accessible site, permissions set to public…

Dumpster diving is legal (in most places but not all) because the owners has, by putting something in the trash, expressed their intent to not own the item in question anymore.

A website isn't a trash can though.

If I accidentally leave a diamond ring (or personal files) in public somewhere and you take them that is absolutely theft.

Re: Teenager facing prison for downloading unsecured files from government website

#279
post #64

Earlier quoted context omitted.

Since it helps the older generation to think about digital content in metaphors, I'd argue that the kid was entering through an open window of a public building. Although a bit strange, no one would give this hypothetical person a third look.

>the kid Is a 19 year old a kid?

yes

Re: Teenager facing prison for downloading unsecured files from government website

#280
post #247

Earlier quoted context omitted.

A link is not someone giving you permission, it's merely telling you where something else is. I can't think of how you even came to this conclusion. It's like you have this incredibly restricted view of the internet, limited to people clicking on a browser, and think that's enough for protecting files. It's not. You don't seem to realize how bad of an idea this is. You're talking about making criminals of people. You…

I have a view of the Internet where “protecting files” has nothing to do with whether access to files is authorized or not. I shouldn’t have to lock my door, and I shouldn’t have to lock down my web server. (It may be prudent to do those things, but a trespasser shouldn’t escape penalty just because I didn’t do those things.)

And I shouldn't have to pay an attorney to write legal contracts, while we're on the subject of fictional, idealized, romanticized, and imaginary realities.

This conversation has devolved into arguing against the analogy. This is the internet: everything on it is public unless care is taken to make it not so.

You may choose to argue whether or not that should be, but that's the way it is.

Post reply on HN