3 ms·
> I think most people would assume that documents that can only be accessed by editing an ID were not meant to be accessed. And that really is the end of the an
by rootlocus 8y ago
> I think most people would assume that documents that can only be accessed by editing an ID were not meant to be accessed. And that really is the end of the analysis.
You do realize HN provides an API that allows you to request any item by using an ID? [1]
Stories, comments, jobs, Ask HNs and even polls are just items.
They're identified by their ids, which are unique integers, and
live under /v0/item/<id>.
If you really know better than everyone else who has replied to you on this story, why don't you point out the exact law that states accessing resources over HTTP is forbidden if not initiated from another resource originating from the target server? Otherwise, I'll assume your "analysis" is simply a subjective view on how you would like the web to work. A pretty limited and unrealistic view that wouldn't work in the real world.
For example: here is the link to the first story posted on HN: https://news.ycombinator.com/item?id=1 https://news.ycombinator.com/item?id=1
1. I don't think you can access that story by starting from the front page, because scrolling for more stories only gets you to page 25. Does that mean the intention is the story is private?
2. You can now access it by using the DOM element generated for my comment. Does that mean it's public?
[1] https://github.com/HackerNews/API https://github.com/HackerNews/API
- foldr 8y agoSure, and the fact that HN has a note to that effect on its website is evidence that all of these items are intended to be publicly accessible. It's also obvious in any case that stories, comments, jobs, ask HNs and polls are intended to be public. In the case we're talking about here, it was far less obvious that the relevant documents were intended to be publicly available.
- rootlocus 8y ago> It's also obvious in any case that stories, comments, jobs, ask HNs and polls are intended to be public. > it was far less obvious that the relevant documents were intended to be publicly available My browser and the respective HTTP servers consider them equally obvious publicly available.
- foldr 8y agoBut it's not your browser or the HTTP servers that are being prosecuted. Browsers and HTTP servers don't 'consider' anything.
- rootlocus 8y ago> HTTP servers don't 'consider' anything. Of course they do. They consider whether or not to give me access. If they respond with 200, they are effectively telling me that the information is public and the request is approved. There's no law moral or legal that stops me from asking for information. I could ask a law agent for classified information, but he's not going to prosecute me for asking questions. He could be suspicious and ask "how do you know a document with that number exists?". And I can reply "oh, I'm just asking for random numbers".
- foldr 8y agoYou can describe what a webserver does in anthropomorphic terms if you like, but it's not the webserver's "intentions" that are relevant. It's the intentions of the people who control the website and the intentions of the person who accesses it. >There's no law moral or legal that stops me from asking for information. I wouldn't be so confident of that if you haven't read up on the relevant laws. Many countries have prohibitions against unauthorized access that apply in circumstances where the access is not "unauthorized" in a technical sense relating to the details of the HTTP protocol. The law doesn't necessarily say what you would want it to say or what you would expect it to say. See e.g. the following example from the US. (I'm aware that the incident we're discussing occurred in Canada.) https://motherboard.vice.com/en_us/article/wnxg94/password-sharing-is-a-federal-crime https://motherboard.vice.com/en_us/article/wnxg94/password-s...
- rootlocus 8y ago> You can describe what a webserver does in anthropomorphic terms if you like, but it's not the webserver's "intentions" that are relevant. It's the intentions of the people who control the website and the intentions of the person who accesses it. And how do you prove intent? This is a technical problem with technical protocols involved. Intent should be provided via the protocol. If the protocol says resources are public, unless otherwise stated, you can't rely on a human to answer, post factum, what resource is private.
- CalRobert 8y agoNot to mention there's more to things than HTTP. could be plenty of other sources. Maybe I like using netcat just for kicks. Maybe I like hand-typing HTTP. While odd, `printf "GET / HTTP/1.0\r\n\r\n" | nc 104.20.44.44 80` gets you the HN home page as good as anything.
- rootlocus 8y agoUnfortunately, the main counter argument in this thread, from what I gathered, is "ordinary people wouldn't do that". Including someone claiming that if your mom wouldn't do it (in this case), it's not legal: https://news.ycombinator.com/item?id=16854087 https://news.ycombinator.com/item?id=16854087