6 ms·
The question is whether the content is fair game (to access). Google has already proved it to be fair game and if anyone wants to argue otherwise, they would ne
by jsprogrammer 10y ago
The question is whether the content is fair game (to access). Google has already proved it to be fair game and if anyone wants to argue otherwise, they would need to then argue with the most flagrant offender, Google, who has much more than just "Confidential" PDFs.
Google would be guilty of any charge that could be levied against someone for accessing data that Google actively provides.
- IanCal 10y agoI'm sorry but I think this is rather ridiculous. Google's position is that they have automatically indexed everything that the server said it could, but will remove anything and provide websites a way of doing this. Your position would have to be that you searched for obviously confidential documents, found them and downloaded them without knowing you shouldn't.
- 13of40 10y agoGuys, I think we got out in the weeds a little bit with the google thing. The question is if someone puts up a web server on the internet with no authentication and no notice that it's not open for public use, can they get me for "unauthorized access" if I download content from it? If not, what makes HTTP special - why not SQL or SMB?
- comex 10y agoThe relevant question is not whether there is an explicit notice, but whether common sense suggests that you are intentionally making unauthorized accesses - as would be the case with the Google search you mentioned. See also: https://en.wikipedia.org/wiki/Goatse_Security#AT.26T.2FiPad_email_address_leak https://en.wikipedia.org/wiki/Goatse_Security#AT.26T.2FiPad_...
- jsprogrammer 10y agoCommon sense? If you send a valid HTTP GET to someone's server and they respond with a 200 OK and some content, the access was not unauthorized. The HTTP protocol actually makes authorization an explicit mechanism that may be disabled or loosened at the implementor's leisure.
- 13of40 10y agoThat's a good point. 401 Unauthorized... They even used the right word.
- comex 10y agoTo be fair, the EFF took a position in the case I linked that suggests they might agree with you in the present Google hypothetical too: https://www.eff.org/deeplinks/2013/07/weevs-case-flawed-beginning-end https://www.eff.org/deeplinks/2013/07/weevs-case-flawed-begi... Not only that, I was actually surprised to find that the New Jersey court cited a state precedent along similar lines: http://cdn.arstechnica.net/wp-content/uploads/2014/04/weevrulingvacation.pdf http://cdn.arstechnica.net/wp-content/uploads/2014/04/weevru... -> http://caselaw.findlaw.com/nj-superior-court/1508996.html http://caselaw.findlaw.com/nj-superior-court/1508996.html ...though that was interpreting a state law and brought up the fact that the state law has some subtle differences from the federal CFAA (despite very similar wording, quite vague in both cases). On the other hand, in Craigslist v. 3Taps, a district judge found that simply evading an IP ban, while otherwise accessing entirely (intentionally) public information, counts as unauthorized access under the federal law. And then there's the case of Aaron Swartz. But anyway, even under the more permissive of the possible standards, your logic is too simplistic. What if I send a HTTP GET like this? GET /viewarticle.php?title=x%27%20UNION%20ALL%20SELECT%20%2A%20FROM%20%27users HTTP/1.1 It's a perfectly valid and well-formed request according to the HTTP standard, and even valid at the application level, in the sense that you technically can't rule out that an article might exist titled "x' UNION ALL SELECT * FROM 'users", and a correctly written server-side script would interpret the request simply as searching for such an article. But suppose the script isn't correct, and instead of showing an article dumps its user table. Would you say that my access to user data is authorized? Well, I actually don't know how you'd answer the previous question, but I strongly doubt any court would answer yes. If you say no, then the implication follows that either the difficulty of constructing the dubious request, or perhaps the intent, or something else relatively wishy-washy and subjective can make the difference between authorized and unauthorized. It can't be reduced to some strict technical standard.
- jsprogrammer 10y agoDocuments are not obviously confidential if there is an established process for removing confidential documents, but the documents still show up in a simple search. Your position is that you viewed everything that Google thought it could publish in regard to your query. It is ridiculous that someone could be jailed as a result of clicking a link on a Google search result page.
- hluska 10y agoConsider the Google search that started this: "not for public release filetype:pdf" That's a pretty flagrant attempt at accessing confidential documents. It isn't like someone googles "how to catch a roadrunner" and accidentally downloads confidential Acme documents. This is a full on attempt to find poorly secured documents. Now, consider what Google does. It runs bots (that respect things like robots.txt) and then publish links to everything that they can find. Maybe I'm missing some subtlety, but I don't understand how these are similar. Can you explain yourself further?
- stale2002 10y agoBecause there isn't going to be anything confidential that the search result returns. And anything you access is something that was widely available. It'd be like googling, "Bank of America's Secret Backdoor Password to steal all it's money".
- hluska 10y agoIt's possible that I have missed some subtleties in your argument so let me ask for a bit of clarification. Because there isn't going to be anything confidential that the search result returns. Doesn't this assume that sysadmins are actually competent? And isn't there a ton of evidence that suggests that sysadmins have routinely allowed confidential data to be indexed by Google?? In that case, isn't this analogous to what would happen if I left my front door unlocked and you 'broke' in and stole my collection of Taylor Swift CDs. (I don't actually own any Taylor Swift CDs, but it makes my point easier). Granted, I did a shitty job of securing my valuable music collection, and Taylor Swift CDs are widely available. But fundamentally, you still came in without permission and took something that belonged to me. Recent history has shown that you can be prosecuted for all sorts of things in cyberspace. Accessing confidential directories, downloading poorly secured files, and exploiting poorly designed APIs have all been successfully prosecuted. I wish that we lived in a world where doing things like that would be considered a part of intellectual freedom, but the unfortunate truth is that laws are applied in such a way as to make this highly risky. The silly thing is that the state of the law actually benefits hard core criminals...