Live data from Hacker News

Aaron Swartz hit with 9 more felony charges in MIT hacking case

dailydot.com

91–100 of 104 posts

Re: Aaron Swartz hit with 9 more felony charges in MIT hacking case

#91
post #84
post #79

Earlier quoted context omitted.

I don't follow, but then, we're not talking about wifi networks.

[deleted]

I still don't follow.

Look, if your issue here is that there's no apparent bright line that needs to be crossed to violate the CFAA --- that you don't have to break a 128 bit AES key for instance, or inject a ROP payload --- I guess that's a valid complaint, but it speaks to a pretty profound (and very common, especially with nerds) misunderstanding about the way the law works.

The prosecution does not need to produce a cryptographically signed unimpeachable notarized audit log spelling out exactly which parts of the US Code Swartz broke at each timestamped moment of the day.

Instead, they have to convince a jury that a reasonable person should believe that Swartz knew he was violating JSTOR's terms, took constructive steps to violate those terms, and did so purposefully to commit a fraud.

All we have to go on is the story laid out in the indictment; Swartz has a side to tell here too. But if you just go on the indictment, I think there's a pretty decent case to be made against him.

Re: Aaron Swartz hit with 9 more felony charges in MIT hacking case

#92
post #59

Earlier quoted context omitted.

Stealing a bar of chocolate from a website is also not a federal crime.

Actually, it may well be. Depends on where you are, where the website is hosted, and whether any of the fiber(etc) your packets traverse cross state lines...

No, stealing a candy bar across state lines is also not a crime under the CFAA.

(Wait, it might be. I misremembered what the dollar minimum in the CFAA applied to --- the dollar limit is why you can't be charged under the CFAA for stealing airplane wifi, but things of value other than computer service itself have no dollar minimum I can find.)

Anyways, don't steal candy bars.

Re: Aaron Swartz hit with 9 more felony charges in MIT hacking case

#93
post #83

Earlier quoted context omitted.

Yes it is because it is interstate commerce. Even if you are located in the same building as the server, just being connected to the internet raises the potential for it to be interstate commerce so it falls into the federal domain. 18 USC 1030(a)(4): (a) Whoever— ... 4. knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduc…

A "protected computer" has a specific definition, and "a website" doesn't necessarily meet it. tptacek knows the CFAA pretty well for a non-lawyer. It doesn't mean he's always right, but you should be careful if you're trying to trip him up.

I think he might be right.

Re: Aaron Swartz hit with 9 more felony charges in MIT hacking case

#95

Earlier quoted context omitted.

I'm not sure if I am interpreting your last sentence correctly. Can you rephrase it?

Courts have a very long history and lots of people have tried lots of really weird things over the years. Swartz will hopefully have a good lawyer, and a good lawyer won't even try to something along the lines of "there wasn't a preset limit on X therefore my client didn't do anything wrong" when his use of X was over a hundred times the combined consumption of all the legitimate users over two months. Judges are not…

You are jumping around a bit. We were talking about TOS and now we're in a court room and using the words "judge" and "dumb" in the same sentence. I was kidding about doing research. Humor. We all know what he was doing. But the truth is I'm serious about these types of TOS. And I'm looking at this mainlly from the end user's perspective. You see the same type of ambiguous TOS language everywhere on the web. Let's stay focused on TOS for a moment, and leave aside the Swartz case. Do you think ambiguous contracts (TOS) are "better"[1] than unambiguous ones? For example, would reducing ambiguity lower the probability of (costly) disputes?

1. better for who?

Re: Aaron Swartz hit with 9 more felony charges in MIT hacking case

#96

Earlier quoted context omitted.

Courts have a very long history and lots of people have tried lots of really weird things over the years. Swartz will hopefully have a good lawyer, and a good lawyer won't even try to something along the lines of "there wasn't a preset limit on X therefore my client didn't do anything wrong" when his use of X was over a hundred times the combined consumption of all the legitimate users over two months. Judges are not…

You are jumping around a bit. We were talking about TOS and now we're in a court room and using the words "judge" and "dumb" in the same sentence. I was kidding about doing research. Humor. We all know what he was doing. But the truth is I'm serious about these types of TOS. And I'm looking at this mainlly from the end user's perspective. You see the same type of ambiguous TOS language everywhere on the web. Let's st…

ToS might be interesting in some cases, but not in this one. JSTOR and MIT kept on denying access to Swartz and he kept on working around their defenses.

Re: Aaron Swartz hit with 9 more felony charges in MIT hacking case

#97
post #85

Earlier quoted context omitted.

"Materially harm" is such a broad term (it's been used to escape one-penny raises in phone bills) that, in the context of CFAA, it might as well be strict liability. Depending on how big of a dick legal is feeling like on a given day, they could make the argument that having the sysadmin dig up logs was materially harming.

Harm has nothing to do with strict liability.

Please read my post again. (Why do I find myself saying this to you in almost every interaction? Do I just fail at communicating?)

The point was that the bar for "material harm" is so low that an infant couldn't trip over it. So much that it's barely even worth consideration. Basically, if you violate a ToS, the company on the other side could make it a federal case if they choose to.

From the company's standpoint, there's no reason not to, unless they've already committed their lawyers elsewhere.

So it might as well be strict liability. If they choose to pursue you, you're in for a bad time. Note that a prosecutor still has to choose to come after you, even for strict liability offenses.

Re: Aaron Swartz hit with 9 more felony charges in MIT hacking case

#98
post #85

Earlier quoted context omitted.

Harm has nothing to do with strict liability.

Please read my post again. (Why do I find myself saying this to you in almost every interaction? Do I just fail at communicating?) The point was that the bar for "material harm" is so low that an infant couldn't trip over it. So much that it's barely even worth consideration. Basically, if you violate a ToS, the company on the other side could make it a federal case if they choose to. From the company's standpoint, t…

You're not failing at communicating so much as failing at understanding what "strict liability" is about. Strict liability pertains to intent, not to the magnitude of the offense.

Statutory rape is an example of a strict liability crime, because you can be convicted of it without even knowing you committed it (at the time).

Re: Aaron Swartz hit with 9 more felony charges in MIT hacking case

#99

Earlier quoted context omitted.

You are jumping around a bit. We were talking about TOS and now we're in a court room and using the words "judge" and "dumb" in the same sentence. I was kidding about doing research. Humor. We all know what he was doing. But the truth is I'm serious about these types of TOS. And I'm looking at this mainlly from the end user's perspective. You see the same type of ambiguous TOS language everywhere on the web. Let's st…

ToS might be interesting in some cases, but not in this one. JSTOR and MIT kept on denying access to Swartz and he kept on working around their defenses.

What if we looked beyond the Swartz case? Then what do you think about these types of TOS?

Maybe another example would be more interesting. Say you have a choice between an API that allows a "reasonable" number of requests in any 24 hour period and one that allows n number of requests in any 24 hour period. Which one would you prefer?

First assume you're an API user. Then assume you're the API provider.

Anyway, this kind of question is what I was getting at. What is reasonable? I don't know what their server capacity is.

I like using automation, I prefer non-interactive to point and click, and I have always found TOS on academic databases, not to mention most websites, interesting. Because they fail to account for anyone who might want to use automation (reasonably, having respect for the resources of the server). But maybe I'm the only one who finds this question interesting.

Re: Aaron Swartz hit with 9 more felony charges in MIT hacking case

#100
post #98

Earlier quoted context omitted.

Please read my post again. (Why do I find myself saying this to you in almost every interaction? Do I just fail at communicating?) The point was that the bar for "material harm" is so low that an infant couldn't trip over it. So much that it's barely even worth consideration. Basically, if you violate a ToS, the company on the other side could make it a federal case if they choose to. From the company's standpoint, t…

You're not failing at communicating so much as failing at understanding what "strict liability" is about. Strict liability pertains to intent, not to the magnitude of the offense. Statutory rape is an example of a strict liability crime, because you can be convicted of it without even knowing you committed it (at the time).

I understand that much - holding onto underage porn is a strict liability crime for example

What I'm getting at here is that, the "harm" thing is not a good bar. The only difference between breaking a ToS in this condition and breaking a strict liability law is that it's a corporation instead of a prosecutor initiating the case.

*ed

Dropped "unwittingly", since you have to have been proven to know you're breaking the ToS.. still a broken law..

Post reply on HN