5 ms·
If the computer on the public Internet responds to a standard HTTP request, it has explicitly authorized my access to whatever information it sent me.
by jsprogrammer 11y ago
If the computer on the public Internet responds to a standard HTTP request, it has explicitly authorized my access to whatever information it sent me.
- zaroth 11y agoUnfortunately this will not help your defense. Andrew "Weev" Auernheimer was convicted of violating CFAA for exactly this (although the conviction was later overturned on a technicality). Again, exceeding authorized access means using your authorized access to obtain information you were not "entitled" to. So the question is not 'were you authorized' but rather it is 'were you entitled' to that information? WTF 'entitled' means is another question entirely, but likely it is in the eye of the beholder. A jury decided Weev was not 'entitled' to the email addresses he downloaded from AT&T, and it's safe to assume we are not 'entitled' to free access to WSJ's content. So I would not rest your hopes on the "200 OK".
- jsprogrammer 11y ago> Andrew "Weev" Auernheimer was convicted of violating CFAA for exactly this (although the conviction was later overturned on a technicality). So, your example is...not an example? >WTF 'entitled' means is another question entirely No, in this case it is very clear: a request containing a particular user agent string is entitled. I have not tried this myself, but presumably you could verify that is the case by sending a request with the appropriate user agent.
- zaroth 11y agoIt's the best example we got. The case was overturned (after he spent quite some time in federal prison) not because it was found that he didn't violate the CFAA but because the charges were brought in the wrong jurisdiction. Again I think you're confusing the fact someone could trick the server into delivering the content for free with WSJ intending to deliver their content to you for free. Since WSJ clearly intends their content to be delivered to only Googlebot for free and to users only if they pay, it is likely a jury would consider this a violation of CFAA. A web server returning 200 OK is not ipso facto a guarantee the person making the request is not committing a crime. To give a more obvious example, if the request header contains a stolen authorization token. The law does not require the access control be non-trivial to defeat. I don't like it, and I think the CFAA is seriously problematic, but it is the law and the Feds have been known to enforce it.
- jsprogrammer 11y agoAs far as the law is concerned, he did not violate anything. You do not have to prove yourself innocent, the burden is on the prosecutor to prove a violation. In the example you cite, no violation has been shown. It is not at all clear that WSJ intends Googlebot to get their content for free while others must pay. Thus is actually against Google's policies, which would actually call into question whether WSJ's behavior is felonius. WSJ may not be entitled to be incorporated into Google's index, yet they are manipulating the Googlebot to the contrary.
- jsprogrammer 11y agoIf you will down mod, at least show how I am wrong!
- geofft 11y ago> So, your example is...not an example? At least in the US, the law doesn't work that way. Decisions will quite often cite some other similar case which reached the opposite conclusion, but under different circumstances, because that other case's decision says something like "X, if it weren't for Y" or "Fortunately for the defendant, they didn't Z, so not X", or something. That isn't binding precedent for the judge to apply X, but it's a very strong sign that X would be reasonable. A court case that says "Yes, this violates CFAA but we have to throw out the case because A, B, and C" is very strong reason to believe that, if the next prosecutors avoid A, B, and C, the next judge will say "Yes, this still violates CFAA." (IANAL but I read court cases because I find it useful to understand my jurisdiction's legal system.) > a request containing a particular user agent string is entitled. The phrasing of the law is very clear that the word "entitled" applies to a person, not to a request. Stealing someone's password and using their account is definitely a violation of CFAA (see e.g. http://www.wiggin.com/16332 http://www.wiggin.com/16332). In such a case, the account used to log in is quite plainly "entitled" / "authorized;" that's how you get the data. But the person logging in is not "entitled".
- jsprogrammer 11y agoWe aren't talking about user names and passwords, but user agent strings. The other decision was vacated. The jury was not appropriate and their decision is irrelevant.
- Spare_account 11y agoYour request wouldn't be 'standard', it would be deliberately malformed to bypass a paywall. You guys are performing linguistic gymnastics to get around that fact.
- oldmanjay 11y agoAs you've indicated, a request can only be considered malformed if it doesn't conform to the standards. Here is what the relevant RFC[0] has to say about the User-Agent header: > Likewise, implementations are encouraged not to use the product tokens of other implementations in order to declare compatibility with them, as this circumvents the purpose of the field. If a user agent masquerades as a different user agent, recipients can assume that the user intentionally desires to see responses tailored for that identified user agent, even if they might not work as well for the actual user agent being used. That sure sounds like impersonating other user agents is allowed, but not encouraged. That is a clear distinction from being malformed. [0] https://tools.ietf.org/html/rfc7231#section-5.5.3 https://tools.ietf.org/html/rfc7231#section-5.5.3
- Spare_account 11y agoUnless you were being tongue-in-cheek, you've completely sidestepped the intent of my comment and continued with the linguistic silliness. Obtaining paywall-protected content by faking your user agent to purport yourself to be a Google Crawler is quite clearly fraudulent. This isn't a point for debate. PS. To play along with the linguistic theme, can you provide a source for the definition of a malformed request? My original intent when using the word malformed was not to invoke it's technical definition but rather it's dictionary definition. But, having said that, I just had a 30 second Google hunt and couldn't find anything to corroborate your position.
- oldmanjay 11y agoI wasn't playing a linguistic game. You mentioned standards and malformed requests, and I pointed out that you misused those terms. I am not bothering to track down definitions for you to play, as you say, linguistic games. You are free to find something that proves my position wrong, as I used the RFC to cite my position as correct. If you meant to put forth that faking a user agent is a technique to exceed authorization, that's fine, and I'm glad to have helped you clarify it. Just be clear, it's not what you said with your detour into malformed requests.
- compiler-guy 11y agoYou are confusing an engineering process with a legal one. Unfortunately, when the prosecutors come, they will only care about the legal process.
- CyberDildonics 11y agoIt's not engineering, it's common sense.
- compiler-guy 11y agoCommon sense is not a set of legal procedures and rules either. The legal world cares about how the law applies to the facts of the case, not about how common sense applies. Not saying I like it.
- jsprogrammer 11y agoThe facts are dictated by the engineering. Is a lawyer a computer networks expert? Not by default. They will need to defer to the engineers.
- compiler-guy 11y agoCertainly, some of the facts are dictated by the engineering. However, the set of people "authorized" is not, at least not from a legal perspective. This is what the case law says. The fact that the set of people who technically _can_ access the data is different from the set of people legally authorized to access the data. That might not be what the engineers who designed the system, run it, and produce the content intended, but that is what the law says. It's a bummer the two disagree. But only one of the two systems put you in jail if you cross them. You and I may wish it were otherwise, but wishing isn't going to make it so.