6 ms·
User-agent string is not an authorization mechanism.
by jsprogrammer 11y ago
User-agent string is not an authorization mechanism.
- ignoramous 11y agoIt isn't. But I have seen top internet companies (Netflix and the like) use it to authorise requests. It boggles my mind.
- seanp2k2 11y agoCurious where Netflix is using this to authorize requests. Any more info on that?
- ignoramous 11y agoTheir Android app wouldn't let you through if the device is unrecognised, that is, if your user agent has strings which Netflix hasn't whitelisted. They also check model ID, and build fingerprint too, I believe. A standard practice in the Android world, for some unknown reason. I don't know if they have stopped doing that.
- zaroth 11y agoInterestingly, the CFAA does not define the term "without authorization" however it does define "exceeding authorization" exactly as I quoted above; - to access a computer with authorization and to use such access to obtain or alter information in the computer that the accesser is not entitled so to obtain or alter. So arguing User-agent is not an authorization mechanism probably won't help you, because exceeding authorization means, first, that you were authorized to access the computer (HTTP GET returns 200) but then that you used that access to obtain information in the computer that you were "not entitled so to obtain."
- jsprogrammer 11y agoIf the computer on the public Internet responds to a standard HTTP request, it has explicitly authorized my access to whatever information it sent me.
- zaroth 11y agoUnfortunately this will not help your defense. Andrew "Weev" Auernheimer was convicted of violating CFAA for exactly this (although the conviction was later overturned on a technicality). Again, exceeding authorized access means using your authorized access to obtain information you were not "entitled" to. So the question is not 'were you authorized' but rather it is 'were you entitled' to that information? WTF 'entitled' means is another question entirely, but likely it is in the eye of the beholder. A jury decided Weev was not 'entitled' to the email addresses he downloaded from AT&T, and it's safe to assume we are not 'entitled' to free access to WSJ's content. So I would not rest your hopes on the "200 OK".
- jsprogrammer 11y ago> Andrew "Weev" Auernheimer was convicted of violating CFAA for exactly this (although the conviction was later overturned on a technicality). So, your example is...not an example? >WTF 'entitled' means is another question entirely No, in this case it is very clear: a request containing a particular user agent string is entitled. I have not tried this myself, but presumably you could verify that is the case by sending a request with the appropriate user agent.
- zaroth 11y agoIt's the best example we got. The case was overturned (after he spent quite some time in federal prison) not because it was found that he didn't violate the CFAA but because the charges were brought in the wrong jurisdiction. Again I think you're confusing the fact someone could trick the server into delivering the content for free with WSJ intending to deliver their content to you for free. Since WSJ clearly intends their content to be delivered to only Googlebot for free and to users only if they pay, it is likely a jury would consider this a violation of CFAA. A web server returning 200 OK is not ipso facto a guarantee the person making the request is not committing a crime. To give a more obvious example, if the request header contains a stolen authorization token. The law does not require the access control be non-trivial to defeat. I don't like it, and I think the CFAA is seriously problematic, but it is the law and the Feds have been known to enforce it.
- njharman 11y agoGood luck arguing that in court. Esp against the multiple lawyers a corporation will be able to afford. If you don't get it, court doesn't care about what's reasonableness, technically correctness, etc. Only if your lawyers can convince jury/judge. Twinky made me crazy, It the gloves don't fit... and so forth.
- tajen 11y agoIf you don't set it for a particular website but generally browse the web with it, based on another legitimate purpose (I'm a developer, I had to test a website, I forgot the setting) could you oppose the court on "knowingly and with intent of defraud"? If you didn't see the paywall, how can it be "knowingly"?
- njharman 11y agoTrot out expert witnesses (on web dev). "Sir, have you ever "forgot" the setting?" No, and it's ridculous to think anyone would. "Is it generally know by web devs the dangers and circumvention ability of this setting" Absolutely. etc. "Here is a transcript of electronic forum detailing how to circumvent access controls and defraud the victim using the exact methods defendant used to access victim's website. A forum the defendent heavily traffics. Often multiple times per day." Ladies and gentlmen I ask you is it more likely that the defendent, a self professed developer, and expert in these circumvention methods, who reguralry participates on forums discussing hacking and defrauding companies such as the victim. I ask you is it reasonable to believe he "just forgot"? Lawyers man, Lawyers! Can you not understand that rationality, technicallity don't matter. Lawyering is like statistics/graphs. You can get the data to say whatever you want.
- jsprogrammer 11y agoUser agent string is not an access control mechanism.