6 ms·
If Google has already accessed, indexed, and published it, you are in pretty good company. At the least, you have the lawyers of a multi-billion $$$ company bac
by jsprogrammer 10y ago
If Google has already accessed, indexed, and published it, you are in pretty good company. At the least, you have the lawyers of a multi-billion $$$ company backing you.
- owenmarshall 10y agoGoogle isn't going to back you in any way - why would they?
- e12e 10y agoI think the parent alludes to Google being named as accomplices along with you. I do however think you're right that that might not mean much for your case. If nothing else, if two parties commit a crime, and one has a major legal team, it seems like the most probable outcome is that the other party will take the fall.
- owenmarshall 10y agoThat's beyond a fantasy - Google isnt party to a conspiracy because they have a built in affirmative defense: our actions weren't taken to further a conspiracy, they were incidental.
- jsprogrammer 10y agoThe question is whether the content is fair game (to access). Google has already proved it to be fair game and if anyone wants to argue otherwise, they would need to then argue with the most flagrant offender, Google, who has much more than just "Confidential" PDFs. Google would be guilty of any charge that could be levied against someone for accessing data that Google actively provides.
- IanCal 10y agoI'm sorry but I think this is rather ridiculous. Google's position is that they have automatically indexed everything that the server said it could, but will remove anything and provide websites a way of doing this. Your position would have to be that you searched for obviously confidential documents, found them and downloaded them without knowing you shouldn't.
- 13of40 10y agoGuys, I think we got out in the weeds a little bit with the google thing. The question is if someone puts up a web server on the internet with no authentication and no notice that it's not open for public use, can they get me for "unauthorized access" if I download content from it? If not, what makes HTTP special - why not SQL or SMB?
- comex 10y agoThe relevant question is not whether there is an explicit notice, but whether common sense suggests that you are intentionally making unauthorized accesses - as would be the case with the Google search you mentioned. See also: https://en.wikipedia.org/wiki/Goatse_Security#AT.26T.2FiPad_email_address_leak https://en.wikipedia.org/wiki/Goatse_Security#AT.26T.2FiPad_...
- jsprogrammer 10y agoCommon sense? If you send a valid HTTP GET to someone's server and they respond with a 200 OK and some content, the access was not unauthorized. The HTTP protocol actually makes authorization an explicit mechanism that may be disabled or loosened at the implementor's leisure.
- dragonwriter 10y agoNo, you don't. Knowledge and intent are key factors in many crimes, and you and Google aren't similarly situated.
- jsprogrammer 10y agoIf google is providing you illegal knowledge, that is Google's problem.
- dragonwriter 10y agoThe law doesn't work that way: knowledge is rarely illegal. Knowingly gathering without permission may be. Using a Google product as a tool in a crime doesn't make Google responsible for the crime and relieve your responsibility.
- jsprogrammer 10y agoCan you construct a hypothetical situation where clicking a link on a Google result page (or, any page, for that matter) would be a crime? If such a thing were possible, I would view it as the ultimate betrayal of the browser's "sandbox". Certainly it would be a top priority to categorize links into "known safe to click" and "clicker beware". Who knows, maybe Google's successor will be such an engine.
- Zancarius 10y ago> Can you construct a hypothetical situation where clicking a link on a Google result page (or, any page, for that matter) would be a crime? I'm not sure that's even necessary, and there's no point getting into a debate about the browser (you commanded it to do something, after all). IANAL, but I don't think you need to be one to appreciate the potential for legal trouble. Depending on your interpretation of the CFAA and whether or not you agree with the assertion that the Ninth Circuit limited the scope of the CFAA's reach by requiring a certain degree of intent [1], unauthorized access alone could be construed as a crime. If you want a particularly extreme interpretation of the statute, you can find such almost anywhere you look (here's one from 2005 [2]). In the latter case, it's notable that if you access material it 1) need not be trademarked, copyrighted, a trade secret, or even particularly sensitive--it need only be "valuable" and 2) unauthorized access is defined rather loosely as accessing "information in the computer that the accessor is not entitled so to obtain." One could argue that password protected resources or databases that are not publicly advertised are not considered something for dissemination to the public and therefore protected by statute. So, if we apply the CFAA in a manner similar to what you might expect of a prosecutor who is up for re-election this year, let's look at the abuses the article's author committed: Unauthorized access - check? There's no obvious revocation of the right to access Unilever's MongoDB database, but it probably passes the "reasonable person" test that this information isn't intended to be public. Playing the game of "intent" is a bit risky, so this might be another option in mounting a defense. "Valuable" information - definite check (the author stated rather plainly: "Within the databases I found personal details like names, e-mail addresses and also private chat logs;" I suspect this would be considered "valuable" information). I don't think this is something I would have admitted. I certainly wouldn't have posted screen captures. I admit the timing of this is funny, because I was just about to watch a few videos on bosnianbill's Youtube channel earlier when I got to thinking about how inconsistent lockpick possession laws are in the US, and it's interesting how it applies to this story. In some states (notably Tennessee), simply owning a lockpick without the appropriate license can land you a misdemeanor (fine, maybe jail time, depending on my memory of their law), while other states (like my own) require intent and/or possession of multiple "burglary tools" (e.g. a crowbar in addition to a lockpick). While intent alone is insufficient protection from particularly enthusiastic prosecutors, it does at least afford some defense if you wind up in front of a jury. Hoping for the same under the framework of the CFAA is a bit like playing with fire even if you successfully mount a defense (legal costs, opportunity costs from the time wasted on defense, etc). Not worth it. [1] http://www.bullivant.com/Computer-Fraud-Abuse-Act http://www.bullivant.com/Computer-Fraud-Abuse-Act [2] https://www.dorsey.com/newsresources/publications/2005/02/cfaa-as-a-civil-remedy-national-law-journal https://www.dorsey.com/newsresources/publications/2005/02/cf...