Live data from Hacker News

9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

cdn.ca9.uscourts.gov

91–100 of 293 posts

Re: 9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

#91

Earlier quoted context omitted.

I think you've mischaracterized the state of things. In the underlying case, LinkedIn asserted that HiQ violated the CFAA and HiQ said LinkedIn tortiously interfered with its business. The trial court said LinkedIn couldn't assert the CFAA. LinkedIn appealed, asking the appellate court to overturn the trial court and also to hold that the tortious interference claim is preempted by the CFAA. The appellate court said…

LinkedIn tried to use the CFAA as an argument against the preliminary injunction HiQ was seeking at the start of the trial (which would force LinkedIn to continue to provide access to the profiles). They claimed that HiQ was likely to fail under the CFAA and so do not deserve the injunction to be granted. When the preliminary injunction was granted, LinkedIn appealed. This is the ruling on that appeal: > It is likely…

Are you saying the trial court never ruled on the preemption claim?

Re: 9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

#92

A good decision was reached, but it's a little worrying that the emphasis in the ruling was mostly about a weighing of business interests rather than affirming a right to access public information. If HiQ's business model had not been jeopardized by LinkedIn's business desire to block them, I fear this court could have easily gone the other way. I'd really love to see a ruling that solidifies the right of someone to…

> If HiQ's business model had not been jeopardized

I think this is more about validating hiQ's legal standing in the case.

Re: 9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

#93
On how this case relates to the CFAA:

We therefore conclude that hiQ has raised a serious question as to whether the reference to access “without authorization” limits the scope of the statutory coverage to computer information for which authorization or access permission, such as password authentication, is generally required. Put differently, the CFAA contemplates the existence of three kinds of computer information: (1) information for which access is open to the general public and permission is not required, (2) information for which authorization is required and has been given, and (3) information for which authorization is required but has not been given (or, in the case of the prohibition on exceeding authorized access, has not been given for the part of the system accessed).

Public LinkedIn profiles, available to anyone with an Internet connection, fall into the first category. With regard to such information, the “breaking and entering” analogue invoked so frequently during congressional consideration has no application, and the concept of “without authorization” is inapt.

Re: 9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

#94
post #86
post #53

Earlier quoted context omitted.

> There is no reason why your page should refuse to load plain text without Javascript enabled. Sure there is. You prefer writing javascript and you want to serve your site through a CDN. You might not think that's a good reason, but that's certainly a reason.

Until the ADA comes along and demands you create an accessible to the blind site. I've often wondered when the laws would start to be applied and I think its coming

I have a website that's a full page map. I care about accessibility - is there any way I can make this meaningfully accessible to the blind?

Re: 9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

#95
post #75

Earlier quoted context omitted.

To take the case at issue, when your immediate reaction to discovering an unprotected URL is to scrape it, discuss on an IRC channel how you're going to monetize it, and then go to the media to announce your security vulnerability discovery, you are going to find it difficult to make the argument that you believed you had authorized access.

By that same line of reasoning, one could argue that changing your url parameter in that twitter chatroom website is a privilege escalation attack that allows users to access protected information. Absence of authentication means all access is authorized, otherwise just typing in random urls is a crime.

The case referenced by the top-level comment of this chain (the one about 'weev') is a case where someone was prosecuted and imprisoned specifically because changing URL parameters was seen as an attack allowing access to protected information.

Re: 9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

#96

Earlier quoted context omitted.

this is bad comparison because when scraping a site, you don't cross any borders, you just send and receive information. You can compare this to a phone call or to talking to someone.

A website or server is property, just like land is. Accessing it is no different than accessing any other piece of property. Opening a website is, for all intents and purposes, the same as crossing a border. To take it a step further, the information on said website is also personal property, and accessing the information without permission is also trespassing. Specifically, this is called trespass to chattels [1] (t…

This analogy is faulty and congress really needs to clarify what they meant the CFAA to protect against.

Opening a website is making a request, technically speaking. That is not equivalent to breaking into someone's home and taking information. The equivalent would be if the head of the household told you not to stand outside and ask someone inside to give you something from the house. You haven't trespassed, you're asking someone in the house to do something for you. It's on them if they do what you request or not.

Re: 9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

#97

Earlier quoted context omitted.

A website or server is property, just like land is. Accessing it is no different than accessing any other piece of property. Opening a website is, for all intents and purposes, the same as crossing a border. To take it a step further, the information on said website is also personal property, and accessing the information without permission is also trespassing. Specifically, this is called trespass to chattels [1] (t…

This analogy is faulty and congress really needs to clarify what they meant the CFAA to protect against. Opening a website is making a request, technically speaking. That is not equivalent to breaking into someone's home and taking information. The equivalent would be if the head of the household told you not to stand outside and ask someone inside to give you something from the house. You haven't trespassed, you're…

A website isn't a person and the law doesn't expect them to act as such. It's a tool. Making a 'request' to a web server is more like turning the knob on a door: maybe the owner installed a lock, or maybe it just opens without there being a lock. But even if there isn't a lock, the law doesn't absolve you of trespassing against the door's owner just because the door itself didn't have the sentience to refuse your request.

Re: 9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

#98

Considering the kind of private scraping and selling tactics LinkedIn has been chronically guilty of (and not just the ordinary "growth hack" stuff: "LinkedIn violated data protection by using 18M email addresses of non-members to buy targeted ads on Facebook" [1]), it's satisfying to see LinkedIn lose this. [1] https://techcrunch.com/2018/11/24/linkedin-ireland-data-prot...

I feel like this is a really common theme I've seen several times. Something like "Music Lyric site X sues Google for embedding their lyrics in the results directly" which is funny because site X got the lyrics by scraping them from other sites. Plus Google only exists from scraping content, but I believe their TOS includes "don't scrape our content". I find it really funny that the scrapers are battling scrapers - l…

[deleted]

Re: 9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

#99

> LinkedIn has taken steps to protect the data on its website from what it perceives as misuse or misappropriation. The instructions in LinkedIn’s “robots.txt” file—a text file used by website owners to communicate with search engine crawlers and other web robots—prohibit access to LinkedIn servers via automated bots, except that certain entities, like the Google search engine, have express permission from LinkedIn f…

A friend of mine from grad school was very involved in legal issues related to cfaa stuff. According to him, weev really got screwed because he failed "the punk test", which discouraged lawyers from wanting to use him as a test case.

Re: 9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

#100

Earlier quoted context omitted.

A website or server is property, just like land is. Accessing it is no different than accessing any other piece of property. Opening a website is, for all intents and purposes, the same as crossing a border. To take it a step further, the information on said website is also personal property, and accessing the information without permission is also trespassing. Specifically, this is called trespass to chattels [1] (t…

Lol really? I'm not "on" your site when I browse there. I asked your server to send me some data and it did so. Its real life equivalent to social engineering. Its so far not illegal for me to ask you things and for you to disclose them to me even if you weren't supposed to. I'm allowed to lie to you even to persuade you to tell me things.

um, seems in this case the court specified that it is NOT on them - if the info is public, the website/house-people are required to return it and create no obstacles to doing so.
Post reply on HN