9 ms·
That's not a great analogy. The store owner can't just get your arrested/charged with a crime if they don't tell you that you aren't allowed first. Http lacks s
by cybwraith 9y ago
That's not a great analogy. The store owner can't just get your arrested/charged with a crime if they don't tell you that you aren't allowed first. Http lacks such a human mechanism. The closest thing I can think of in the standard is the response code. So your server replying 200 OK should implicitly be considered permission to access that resource legally until it stops replying with that code.
- rayiner 9y agoBut that's exactly what happened here: > LinkedIn sent hiQ cease and desist letters warning that any future access of its website, even the public portions, were “without permission and without authorization” and thus violations of the CFAA. The EFF's point about terms of service is a good one, but also irrelevant. Terms of service don't provide adequate notice that someone's implied license to access a website has been terminated. But here, hiQ had actual notice through "human" channels.
- cmiles74 9y agoThe poster is arguing that if you make a request from LinkedIn's website and it returns a "200" along with data, then you've accessed that data lawfully and LinkedIn has agreed to serve it to you; I tend to agree. If they don't want to provide data to hiQ, they should, well, stop providing data to hiQ. There are many ways to do this short of claiming that hiQ doesn't have permission or authorization, an argument strikes me as wholly without merit. If the data is publicly available on the internet then how is permission or authorization required?
- rblatz 9y agoHow is that any different than walking up to a store entrance with automatic doors and a sign that says "Welcome" on it?
- mrguyorama 9y agoThose doors get turned off at night, just like a server can ignore an HTTP request
- yorwba 9y agoThe store owner could have told you that are not welcome at any time of day. I don't think a generic "Welcome" sign or automatic door would override that.
- rblatz 9y agoThey can turn the servers off at night too. Some places still choose to do that. But that is unrelated to the point, if you are told that you are no longer welcome at a business, you can’t come in without it being considered trespassing. The doors automatically opening for you (200 Ok) doesn’t matter. If you wear a disguise (change ip) doesn’t matter. You can’t go in. Also I would agree that absent a specific order to stop accessing publiclly available server resources, there is an explicit permission to do so. So I’m the case of Weev I think he did nothing wrong, AT&T were the ones in the wrong.
- cmiles74 9y agoWell, for one it's not a physical store nor a physical entrance and there is no sign that says "Welcome". I don't think the analogy is helping to make anything more clear... It's possible it's making things more confusing. In my opinion, the bottom line is that if LinkedIn doesn't want to serve data to this company, then they should immediately cease doing so using the many well established means available to them. For LinkedIn to claim that following a URL and downloading the data is somehow "hacking their website" is entirely ludicrous. I understand they had a lawyer tell this company that they didn't want them to visit the URL, but I don't see how that somehow turns lawful web browsing into illegal hacking.
- jimktrains2 9y agoIn the coffee shop example, would this be like trying to sue someone who is banned from your shop from looking in the window at your price list? In this case, it's more like LinkedIn is attempting to get a PFA order, but I think they need to show abuse, not just looking in the window at the menu you posted on the window?
- rayiner 9y agoNo because that's not how computers work. Computers don't just emit radiation into the aether that anyone can capture. Accessing a website involves making a physical piece of property do something in response to your HTTP request.
- jimktrains2 9y agoSo, I can't shine a flashlight in your store window to look at the menu in the middle of the night? I have to send photons into your "physical piece of property do something".
- rayiner 9y agoI don't think anyone who understands how computers work would compare the active process of a server responding to an HTTP request to the entirely passive phenomenon of shining light into a window and capturing the photons that bounce off.
- jimktrains2 9y agoI could just as easy say "I don't think anyone who understands how computers work would compare the active process of a server responding to an HTTP request to a coffee shop". But to respond directly, the paper and tape had to be bought, printed, &c. Capital was expended to place the paper there. Sure there is not the ongoing cost of maintaining this paper in the window, and if that's where your argument lies, then you should be less condescending about it. Moreover, we're not talking about the costs associated with access, we're talking about the permission granted to access. As such, ignoring the cost of serving an HTTP request is a valid comparison, because it is not at issue here. LinkedIn's argument is just as strong even if their only argument is they denied permission with no reason given. Thanks for the ad hominem, by the way. Your childishness and inability to conduct a civil discussion has caused this discussion to end.
- cybwraith 9y agoAgain: > your server replying 200 OK should implicitly be considered permission to access that resource I do see your point and how you could disagree with my statement above. However, if the store owner forgets you next time and says "Come on in! Oh and here is a take-home menu with all our items and prices" but then calls the police to have you removed, there is a problem. Now imagine said store owner actually owns several locations possibly even with different public names and doesn't want to serve said customer. They could provide a list of all addresses of stores they run explicitly banning permission. Otherwise, that customer walking into store B would need to be told again they would not be served at time of entry. Assuming the CFAA C&D from LinkedIn does have legal standing here... If hiQ were using IP addresses and not DNS resolution to crawl, how would they know a particular IP is a LinkedIn resource they aren't allowed to access? Did the C&D provide all addresses they are not permitted to access? My point is that its not black and white, and certainly not clear that this should be covered by the CFAA under "hacking". Edit: You could also make the argument and analogy to a restraining order which places the responsibility for compliance on the banned party. However those don't just happen because one entity sends a letter to another entity, it needs to be explicitly granted via the legal process.
- rayiner 9y agoI think the more accurate comparison is that the owner sent you a C&D saying you're banned from the restaurant, and then you try to say "oh, I though the C&D didn't apply any more because the waitress let me in." Would anyone seriously believe that? The law applies to people, not computers. The only question is: did Linked In convey its revocation of hiQ's implied license in a way a reasonable person would understand? The computer code is only relevant if a reasonable person would take the HTTP status code to take precedence over the C&D letter.
- ikeboy 9y agorobots.txt. If all requests sent by robots would clearly identify themselves, the server would easily block all of them. But if they fake their user agent to look like a browser and ignore robots.txt, that's not a good faith request and they shouldn't be able to plead ignorance.
- cmiles74 9y agoI don't believe there's a law requiring the honoring of the robots.txt file. People and services honor the file out of a sense of good manners, not a legal requirement.
- ikeboy 9y agoIt doesn't have to be a specific law. It is a rebuttal to a claim of "I had no idea I shouldn't have requested millions of pages from that site". If you scrape a site that prohibits it in robots.txt, that should be considered notice that they don't want that, for whatever relevant law. (I don't know if this argument would hold up in court, IANAL.)
- cmiles74 9y agoI think I see what you're saying, but I disagree that the robots.txt file should have any legal ramifications. Web site operators have many tools that they can use to limit traffic or protect data and they should make good use of those tools. LinkedIn wants to make their data available publicly, except under certain conditions. In my opinion, if they can't find a technical solution, they should stop making the data available publicly.
- jimktrains2 9y agoWhat is a robot? Why is the User Agent even important? It's not a standardized value. I could send "User-Agent: ikeboy" and it's perfectly valid.