3 ms·
The problem comes when we've normalized the idea of exploring public endpoints as "yeah, this is probably exceeding authorized access".
by angersock 8y ago
The problem comes when we've normalized the idea of exploring public endpoints as "yeah, this is probably exceeding authorized access".
- harryh 8y agoThe problem comes when we've normalized the idea of exploring buildings with unlicked doors as "yeah, this is probably exceeding authorized access". People on here talk all the time about how their digital possessions are just as important as their physical possessions (if not more-so). Given that it seems perfectly reasonable to have the same cultural norms about exploring digital spaces as physical ones.
- kps 8y agoThe internet is not a building, but to follow the analogy, HTTP by design has no unlocked closed doors — only open doors and locked doors, with an explicit and clear distinction between them.
- rayiner 8y agoThe Internet is comprised of physical servers, owned by humans. Those servers are accessed by other humans, who are perfectly capable of predicting how the human owners of the servers would want those servers to be used. The protocol isn’t what defines those human interactions and expectations.
- angersock 8y agoThe protocol explicitly has mechanisms for protected and non-protected. If the owners don't want something public, it's trivial to lock it down--they might as well freak out when somebody uses the wrong door to enter the front of their shop.
- harryh 8y agoPeople make mistakes. Making a mistake doesn't relieve one of legal protection from trespass (physical or digital).
- rayiner 8y agoAt the end of the day, laws govern the interactions between humans. The law imposes on everyone an obligation to think about the intentions and expectations of other humans. (This is what separates us from animals--the ability to reason about the mental states of others!) The protocol is relevant, because it conveys information. Just as unlocked doors generally indicate permission to access, unsecured HTTP generally indicates the same. But the protocol is only one piece of the puzzle. It is not dispositive. It does not conclusively decide rights and responsibilities. If a reasonable human would discern that the protocol allowing access was probably the result of a mistake rather than intent on the part of the property owner, that is what matters.
- pdkl95 8y agoA protocol - originally the diplomatic customs, procedures, conventions, and etiquette for relations between states - is by definition one of the ways of expressing intent. If I broadcast a request for an IPv4 address and your DHCP server proffers an IPv4 address that I can use for the next 15min, the address of a nameserver, and the address of a router that will forward packets to the global internet, I can reasonably conclude that you intended to allow me to exchange packets on your LAN and at least attempt to use your gateway to interact with the internet. On the other hand, depending on the situation, a "403 Forbidden" could reasonably be interpreted as a request to not send that type of HTTP request anymore. The protocol isn't the only place to look for intent, but it absolutely does express intent in some situations.
- tptacek 8y agoThis is the kind of argument you'd expect to see from a writer at Slate, not from technologists who actually understand applications. Practically by definition, almost all application-layer vulnerabilities, from remote code execution through SQL injection through remote file access, involve requests that HTTP "allows" and processes. In fact, one of the most lethal bug classes --- SSRF --- simply involves getting an HTTP server to accept and pass on a request somewhere else! The premise that a request is authorized so long as it doesn't generate a 403 implies that virtually all modern application vulnerabilities can be exploited lawfully. And that's a ridiculous proposition.
- sathackr 8y agoIf I go to Disney World, and, being a curious person, see something interesting and wander into an unmarked restricted area while checking it out. Have I committed a crime? There were no doors, no locks, no signs to tell me that this area was restricted. Just because it wasn't on the map and may have not had a clearly marked entrance, doesn't mean that I should have known it was a restricted area. Most criminal tresspass laws require at least clear signage or a previous communication, and even then, the area has to be clearly defined. You can't just wave your hand and say 'if you go over there, you're tresspassing' There are some large(20,000+ acres) areas near me that are used as ATV playgrounds. The ATV riders are not authorized to be there, and the land owners have taken some steps to put up signs. They are not consistent or ubiquitious, and the properly lines are not clearly marked or identified. Being that the area is not surveyed, law enforcement is very reluctant to charge anyone with criminal tresspass because they can't even tell themselves where the legal property lines are. Imagine trying to convince a jury beyond a reasonable doubt?
- deleted 8y ago[deleted]