4 ms·
Except that's not at all what they did - they simply accessed files that had been made public by the service provider. To be able to login as BoBibbidyFooBar,
by strofcon 5y ago
Except that's not at all what they did - they simply accessed files that had been made public by the service provider.
To be able to login as BoBibbidyFooBar, and subsequently access ANY company's info in the system without changing their identity from BoBibbidyFooBar does not, in any way, constitute any sort of fraud. It literally cannot, by any sensible definition.
- kelnos 5y agoIntent matters. The service provider clearly did not intend that the files should be public. They screwed up, and they should take responsibility for that. But that doesn't make it ok to know about the security issue and download as many documents as you can in order to use them for your own purposes. Perhaps that wouldn't be "fraud" based on whatever definition you're using, but it's clearly unethical and immoral, and IMO hopefully illegal as well.