5 ms·
I'm curious if this violates any laws. Perhaps the Computer Fraud and Abuse Act?
by was_boring 8y ago
I'm curious if this violates any laws. Perhaps the Computer Fraud and Abuse Act?
- ccday 8y agoInspecting JSON payloads that are returned during normal use of the app doesn’t seem like an illegal activity.
- throwawaymath 8y agoHow would it? The API endpoint is sending the data to the user's device anyway, because the mobile client initiates a request to the API by design.
- jonluca 8y agoThe real life equivalent would be if a company wrote their secrets on the back of a letter they sent you in the mail, and just relied on you not looking at the back. There's no security breach, or even unauthorized network request - their service is requesting this data to your machine, from within their client. I think they just aren't thinking about potential repercussions in their testing names.
- pmiller2 8y agoAaron Swartz didn't breach JSTOR's security or make any (technically) unauthorized network requests, either. https://en.wikipedia.org/wiki/United_States_v._Swartz https://en.wikipedia.org/wiki/United_States_v._Swartz