4 ms·
What does "shouldn't have access to" mean? The web server has a permissions system that determines what access level to grant in response to any request. If y
by corey_moncure 5y ago
What does "shouldn't have access to" mean? The web server has a permissions system that determines what access level to grant in response to any request. If you are granted access to a valid request then what other interpretation can there be apart from the server decided you "should have" access?
- asdfasgasdgasdg 5y ago> What does "shouldn't have access to" mean? It means that the stakeholders of the system, normally its owners, do not mean for you to have access. Here's one way you can estimate whether the owners intend that you should have access: Imagine an in-person conversation with the owner or controller of the data, or their most knowledgeable representative. If you asked them verbally whether you may access the data, and they said "no," then you "shouldn't" have access to the data. > If you are granted access to a valid request then what other interpretation can there be . . . See above. This is also the interpretation that will be relevant in court if you are sued or arrested, so mark it carefully.
- rosndo 5y agoI remember an old HN comment about this, but can’t find it right now. It went something like this (but obviously worded far more eloquently): Hackers love to think that they’re captain Kirk outsmarting the computer, but real life isn’t Star Trek and judges are very much humans and don’t look kindly on such stunts. A reasonable person would know that you aren’t authorized to dump AT&Ts customer database by incrementing an integer on their site.
- corey_moncure 5y agoA reasonable person wouldn't build a house with no walls to store their secrets in, and then put the house in a public place and give access to the public. Or I guess I can just start up a website at "youre-unauthorized.com", so a every reasonable person is duly noticed that they aren't authorized to see it, put my secrets there, set the web server to allow access to all requests everywhere, and then file a criminal complaint on everyone who accesses my secrets that I put out in public. A reasonable person knows intuitively that only crime committed was that of embarrassing the rich and/or well connected.
- rosndo 5y ago> A reasonable person wouldn't build a house with no walls to store their secrets in, and then put the house in a public place and give access to the public. A reasonable person might fail to properly lock their door. Try that defense in front of a judge, odds are you’ll end up in prison.
- corey_moncure 5y agoDoes a reasonable person still have an expectation of privacy if not only does he leave the door open, he sits by while a supposed intruder walks in and out not once, not twice, but one hundred thousand times (in addition to unknown numbers of other intruders multiplied by unknown numbers of more times)? Not only was the organization so derelict in their affairs that they failed to protect sensitive customer data, they didn't even notice the "crime" had taken place (a hundred thousand times), and in fact, would never have noticed, and would prefer not to have noticed, had they not been forced by the threat of public disclosure.
- rosndo 5y agoNobody is sitting by these servers, looking at packets as they pass by. > Not only was the organization so derelict in their affairs that they failed to protect sensitive customer data, they didn't even notice the "crime" had taken place None of this would reduce the intruders liability. Perhaps the company should be tried separately for their failure to protect customer data, but that’s a different issue.
- asdfasgasdgasdg 5y ago> A reasonable person wouldn't build a house with no walls to store their secrets in, and then put the house in a public place and give access to the public. That's obviously true under some formulations, but it doesn't matter, because they won't be on trial. The person who performed the unauthorized access will be. > A reasonable person knows intuitively that only crime committed was that of embarrassing the rich and/or well connected. I consider myself a reasonable person and I'm perfectly happy to have unauthorized access punishable under the law. I value the fact that society takes an onion-like approach to information security. There are incentives for private organizations to secure data, but when they fail to, the risk of criminal sanctions probably prevent some breaches that would otherwise occur. I also do not value the ability to look at computer systems on an unauthorized basis -- i.e. I do not think it brings any value to society -- so by my lights, I lose nothing by it being illegal.
- jahewson 5y agoIt means the intent of the person who created or operates the system. If I forget to lock my front door that doesn’t mean you should have access to my house. Appropriately, it does at least mean you can’t be accused of breaking into it, so the analogy holds up fairly well.