4 ms·
> Prosecutors Stephen Heymann and Carmen Ortiz didn't dispute that Aaron was allowed to access the articles he retrieved. Rather, they said that the WAY he acce
by ImpressiveWebs 5y ago
> Prosecutors Stephen Heymann and Carmen Ortiz didn't dispute that Aaron was allowed to access the articles he retrieved. Rather, they said that the WAY he accessed them (using a script instead of clicking on links) was a terms-of-service violation and hence a crime.
I'm sorry, but isn't that a major oversimplification of what he did?
- hosteur 5y agoShort answer: no it is not.
- formerly_proven 5y agoWhy would a terms-of-service violation be a crime, exactly? Since when is it the job of state attorneys to enforce ToS?
- cdot2 5y agoThat's what the article is about. Basically the federal hacking law defines computer crime as "exceeding your authorization" on a computer that didn't belong to you. Hence violating terms of service would be computer crime.
- jedimastert 5y agoEssentially, the Computer Fraud and Abuse act was being interprated waaaaaaaaaay too broadly, because it could be. Here's the discussion on the supreme court win https://news.ycombinator.com/item?id=27382752 https://news.ycombinator.com/item?id=27382752
- gamblor956 5y agoUnder Van Buren, merely saying in the ToS that [X] part of website is restricted access would not be enough to make it a crime under the CFAA. In the Van Buren case, SCOTUS was very concerned with the potential for innocent actors to unwittingly run afoul of the CFAA. The website would likely have to take further steps to make the restrictions on access known to the user (such as a warning when trying to access [X], and probably also take actual steps to limit access to [X], such that one would only be able to access [X] deliberately knowing that they don't have authorized access to it.
- Crontab 5y agoIt is. I feel that people are too ready to deify Aaron Swartz and act like he held no responsibility in what happened.
- kelnos 5y agoI think that's true of some people, but it's important to remember that all he did was violate the terms of service of a corporation that was (IMO) already behaving unethically and being poor stewards of the data given to it. (I am fundamentally opposed to allowing the result of scientific research -- especially when much of that research benefited from public funding -- to be locked behind paywalls.) Swartz did not deserve to be driven to suicide for this. He did not deserve jail time, or to be arrested. At worst he deserved to be the defendant in a fairly low-stakes civil suit, and maybe even lose. But that's it.
- prepend 5y agoI’m not sure how you think Swartz is diefied. He’s certainly responsible for his actions, but they were not wrong, I think. And he was obviously unjustly persecuted for his actions. I think it’s accurate for us to celebrate SCOTUS ruling that the way the feds prosecuted Swartz was wrong and recognize that it will help prevent future Swartz.
- sigzero 5y agoThey were absolutely wrong actually.
- boublepop 5y agoYou could argue what you want about the legality of his right to have a local copy of the entirety of JSTOR, but he hid equipment in a wire ring closet that was left unlocked on MITs network to carry out his scraping and that’s definitely not something that is “not wrong”. It doesn’t matter what the action of the equipment or the morality of it. It’s not like it would be bad for a student or professor to put up crypto miners, but then good if they donate them to charity. And that is not to even mention the fact that his actions caused effectively a denial of service attack on jstor from MIT.
- gamblor956 5y agoSwartz set up a laptop surreptitiously plugged directly into a networking switch in a controlled-access closet on the MIT campus to which he did not have authorized access. Importantly, Swartz's prosecution would not have been blocked by the SCOTUS decision in Van Buren because they make a distinction between improper use of computer access and improper access of a computer: Swartz did not have authorized access to the networking switch. However, if he had used Wifi, to connect to the MIT networking, the charges would have been unsustainable under the Van Buren decision because guests were permitted on the MIT wifi network (and he had a JSTOR account through his Harvard employee account), and his use of it would merely of been improper use at best (since he effectively DDOS'd JSTOR for other users and got MIT's IP range blocked) rather than improper access. EDIT: Note: a friend pointed out that the DDOS'ing of JSTOR could technically constitute a crime under the CFAA, depending on intent. In Swartz' case, the DDOS was an unintentional side effect of trying to download too much data at once for archival purposes so malicious intent was missing, but someone doing the same thing for the purpose of preventing access to the system could still be guilty of a crime.
- sigzero 5y ago100% agree. While the punishment didn't fit the crime it still was a crime.
- deleted 5y ago[deleted]
- tzs 5y ago> However, if he had used Wifi, to connect to the MIT networking, the charges would have been unsustainable under the Van Buren decision because guests were permitted on the MIT wifi network. That's not clear to me, because MIT tried several times to revoke his permission to use their guest network by repeatedly banning him by IP address, and then by MAC address. He kept changing those to evade the revocation of permission. That seems like it would be enough to distinguish from the Van Buren case.