4 ms·
They didn't access any Lyft systems. They ran Lyft software on their own devices and collected and analyzed the data Lyft provides. One can argue that they br
by stass 9y ago
They didn't access any Lyft systems. They ran Lyft software on their own devices and collected and analyzed the data Lyft provides. One can argue that they broke EULA, but it's not necessarily unethical, and I'm ready to bet the majority of this site users broke at least one software EULA in their lifetime.
- tuyguntn 9y agoAssuming they did like you said the main point is > collected and analyzed the data Lyft provides they did it without permission
- deleted 9y ago[deleted]
- pluma 9y agoSure, the fake accounts just violated the ToS. But they then used an enumeration attack to find existing accounts and retrieve information not intended to be available to them. That it's not technologically sophisticated doesn't mean it's not a criminal offense. If someone doesn't lock their front door and you enter their building, you're still trespassing. Especially if it's your competitor's front door and you're repeatedly entering the building to scout the place out for financial gain.
- nikcub 9y agoI don't use any service without having a basic understanding oh how secure and private their systems are - the CFAA makes that all illegal "You wouldn't open an unlocked door" is the "you wouldn't download a car" of infosec. The later redefined theft as not requiring anybody to be deprived of a good while the former has the same flaw, you arent deprived of any good, you aren't harmed, you haven't been coerced or forced - i.e. It meets none of the common law definitions of trespass[0] [0] but it does explain why ddos attacks, spam and stealing user data are trespass because they do meet those definitions
- pluma 9y agoFWIW, I wouldn't walk through an unlocked door I'm clearly not meant to walk through. There's a difference between "opening an unlocked door" and opening it, walking through it, making notes of everything behind it and repeating this room for all the other unlocked doors and then doing that pretty much continuously for days, weeks, months or however long Uber did it.
- nikcub 9y agoMy point was that walking through an unlocked door is a terrible analogy for accessing a resource URI that isn't directly linked from a page
- pdpi 9y ago> FWIW, I wouldn't walk through an unlocked door I'm clearly not meant to walk through. I would totally open an unmarked unlocked door in a public space that has locked doors clearly marked "restricted access", especially if the layout of the place I'm visiting suggests that there would be something interesting there. That's pretty much what it boils down to, no? Just because you didn't document an endpoint doesn't necessarily mean it's restricted access. In fact, if the end point is accessible, and you have other sections of your service that require authentication, then it's very much the exception that proves the rule — the fact that you specifically forbid access to some routes reasonably means that, in general, I'm allowed access to unauthenticated endpoints.
- UncleMeat 9y agoEnumeration attacks are clearly covered by CFAA based on current law. See weev for example.