Live data from Hacker News

Taking action against scraping for hire

about.fb.com

41–50 of 240 posts

Re: Taking action against scraping for hire

#41
post #29

Of course, Facebook wants to make it sound like scraping is illegal, when it generally isn't. But account hijacking and mass-creation of accounts just to access private pages are clear violations of the Facebook and Instagram ToS, so they surely can sue for that.

Violation of ToS does not mean a violation of the law.

Most law suits aren't due to breaches of the law, but breaches of contract. Whether terms of service constitute an enforceable contact is another matter.

Re: Taking action against scraping for hire

#42

Earlier quoted context omitted.

In general I agree that harvesting public data is moral. I think that in these particular cases it's: 1) extracting data from profiles that opted for not being public (only available to logged in users) and 2) reposting scraped data (publicly?) as belonging to the guy who scraped it without users consent.

From the article, it seems to be service for scrapping data you have access anyway. As long as they only handle those data to the requesting customer, whose login they used, I don't see a difference between general public, and this users personalized "public". If access is still limited to the people who have the access-rights, then I don't see a difference between accessing through the official interface, or via scr…

Users make information available on facebook with the expectation that they are able to later control access to it (other than the obvious threat model of screenshotting, etc). This is violating that expectation and thus their privacy.

Re: Taking action against scraping for hire

#43
post #30

HN is hypocritical - most commenters here are against this because "Meta bad," but at the same time, most commenters wouldn't want their posts shared privately amongst friends to be scraped and made available publicly.

There are two cases they brought up, one being web scraping and the other is making a clone website publicly displaying content from Instagram.

I think Meta might be mixing up these two cases here on purpose to make it look like web scraping is as bad as stealing photos to publish it on a clone website.

Re: Taking action against scraping for hire

#44
post #29

Earlier quoted context omitted.

Violation of ToS does not mean a violation of the law.

I don't think I know the answer, but I'm curious: Does violating a website's TOS meant your accessing it beyond your authority, making it a violation of the US's Computer Fraud and Abuse Act?

Violating TOS no; Gaining access beyond your authority maybe https://www.eff.org/deeplinks/2010/07/court-violating-terms-...

Re: Taking action against scraping for hire

#45
post #9
post #7

Is this much different from LinkedIn vs hiQ?

Logged in vs not logged in data.

> Logged in

Is this actually private data, or is it public stuff that's become annoyingly hard to view anonymously because Meta chose to stick it behind a login box?

Re: Taking action against scraping for hire

#46
post #29

Earlier quoted context omitted.

Violation of ToS does not mean a violation of the law.

I don't think I know the answer, but I'm curious: Does violating a website's TOS meant your accessing it beyond your authority, making it a violation of the US's Computer Fraud and Abuse Act?

I don't have a source for this, but my recollection is that this has been successfully argued by a couple of companies—but then an appeals court found very firmly that it was not the case.

Essentially, having that be true would mean that any given website could create whole new classes of criminal behavior.

Re: Taking action against scraping for hire

#47
post #30

HN is hypocritical - most commenters here are against this because "Meta bad," but at the same time, most commenters wouldn't want their posts shared privately amongst friends to be scraped and made available publicly.

> most commenters wouldn't want their posts shared privately amongst friends to be scraped and made available publicly.

Where's the "posts shared privately amongst friends made public" part? There are two cases here:

1. A service that logs in as the customer (who voluntarily provide their credentials) and scrapes information visible to said customer on their behalf. Nothing about "made available publicly" is alleged.

2. An individual using a pool of bot accounts to scrape posts visible to any logged in user. Nothing about "shared privately" is alleged. To be clear I don't like the method, but I'll also have to admit I've used one of the Instagram "clone sites" in the past thanks to their login wall.

Unless I missed something, it sounds like you just made it up.

Re: Taking action against scraping for hire

#48
post #3

Data harvesting is moral for me, but not for thee.

In general I agree that harvesting public data is moral. I think that in these particular cases it's: 1) extracting data from profiles that opted for not being public (only available to logged in users) and 2) reposting scraped data (publicly?) as belonging to the guy who scraped it without users consent.

I agree with the moral argument against posting the scraped data publicly, but if someone gave my account access to their data, I don't think they have a moral right to say I can't use a script to do something private with it.

Scripts are tools, and like any tool they're extensions of the self. If it's morally okay to do it by hand, it's morally okay to do it with a script, so long as my script is respectful of server resources.

Re: Taking action against scraping for hire

#49
In the early days of FB, they convinced people that pages (or some content, sorry I do not know the FB terms) could be public for anyone to view without needing to login to FB. This was very helpful for small businesses and communities. In many countries this is still the quickest place to make a public page. Though now, every small business or community page I want to visit is locked out unless I login FB. Even if I do login it is impossible to copy paste the important details of a page or post, plus the UI is as ugly as it has always been.

Re: Taking action against scraping for hire

#50
> After paying for access to the scraping software, customers self-compromised their Facebook and Instagram accounts by providing their authentication information to Octopus

"self-compromised" lol

clearly these people just wanted an automated way to access their own data

Post reply on HN