3 ms·
If you had your own API exposed to the internet and someone made an HTTP call that "triggers a bug" in your server "and takes the whole system offline", would y
by javiercr 10y ago
If you had your own API exposed to the internet and someone made an HTTP call that "triggers a bug" in your server "and takes the whole system offline", would you sue the guy who made the HTTP call or would you assume it was a bug in your server / app?
And we're not talking about HTTP calls with SQL injection or things like that. We're talking about identical HTTP calls to the ones that the banks' mobile apps do. Same headers, same body.
- adrianN 10y agoIf they're identical to the official app, they likely won't trigger an unexpected case. If they're not identical (maybe your open source lib has a bug, or the API changed) I could see lawyers trying to sell it as a deliberate hacking attempt to a court.
- dandermotj 10y agoThe open source library simply helps a programmer put together HTTP requests. If an API crashes because it receives an unexpected HTTP request its certainly not the requesters fault.
- drvdevd 10y agoAlso, if it's their public API used by their mobile/web apps, it would likely be crashing all the time anyway from normal user interaction (if some OSS were able to crash it via HTTP).
- rhizome 10y agoNah, you can totally walk a tightrope where one's app is never crashes the API, but only because it has no input fields that allow you to try to transfer currency in the amount of "spaghetti" from one account to another.
- dfox 10y agoThat is reasonable technical approach to the problem, but not how the courts work. On the other hand in court also should ask and answer the question of whether you triggered such behavior intentionally or not.
- synctext 10y agoAt Delft University of Technology we're working on this also for about 2 years. Currently 8 (big) banks reverse-engineered, the smartphone way (no scraping). Besides universities there are not many non-profits that will have the legal and financial means to publish an open source lib. The legal landscape for managing a complete library with numerous banks is complex. As we see in this discussion thread, there are some fragmented solutions with limited coverage. https://github.com/Internet-of-Money https://github.com/Internet-of-Money (empty placeholder)
- javiercr 10y agoWhat's the best way to contact you guys? :)
- xorcist 10y agoYou make it sound silly. But the "unexpected HTTP request" may in fact be a SYN flood (yes, that has happened), or looping some non-trivial request for an ad-hoc DoS. That is indeed the requesters "fault", even if there is clearly no intent and hopefully no legal ramifications.