3 ms·
I’ve heard the “leaving your door open” thing before and I don’t think that’s a good analogy here. That’s not how the internet works. I send requests to other m
by makerofthings 4y ago
I’ve heard the “leaving your door open” thing before and I don’t think that’s a good analogy here. That’s not how the internet works. I send requests to other machines and ask them for stuff and whether they respond or not is on them. That some folks make terrible decisions when it comes to how they store their data isn’t really anyone else’s problem. A better analogy might be “In the uk, if you leave something on the pavement outside your house then you don’t want it anymore and it’s Ok if other people take it. I decided to leave a stack of personal data there and someone just took it.”
- lovehashbrowns 4y ago> I send requests to other machines and ask them for stuff and whether they respond or not is on them. So by this logic, SQL injection is perfectly fine? RCE is perfectly acceptable too? After all, my machine is just asking for stuff and the other machine is responding in a way its code tells it to. The open door analogy fits pretty well here, really. Just because you see an opening doesn’t mean you’re allowed in.
- makerofthings 4y agoI still disagree. Those other systems are not the web. If i can look at a url and get your secret data, that’s on you. I think the other reply who gave the analogy of leaving the blinds open was a better one than mine. [ and just off-topic slightly, yes, I think RCE and SQL injection are perfectly fine. ]
- dylan604 4y ago>I still disagree. Those other systems are not the web. If i can look at a url and get your secret data, that’s on you. I think the other reply who gave the analogy of leaving the blinds open was a better one than mine With you so far... >[ and just off-topic slightly, yes, I think RCE and SQL injection are perfectly fine. ] WTF?! Seriously? There's a huge difference by tweaking the content in a query string of a URL vs injecting known malicious code/content.
- makerofthings 4y agoYes, seriously, and I have thought about this a lot. I appreciate it’s not a popular position and I’m not likely to win any debates on the topic. If a computer is voluntarily connected to the internet then it’s there to explore and there should be no penalties for getting into those machines and looking around by connecting remotely. Malicious outcomes in the real world, obviously this is different. Hack in, look around, fine. Hack in, explode powerstation, not fine.
- SpikedCola 4y agoI am inclined to agree - intent matters. RCE/SQLi, then contacting the relevant company to notify them about the problem, shouldn't be a crime. RCE/SQLi, then dumping all the data and exorting the company with it, should definitely be.
- bentcorner 4y ago> Malicious outcomes in the real world, obviously this is different. I definitely agree with you on this point. If someone looked in my window from the street and saw me eating breakfast, no harm no foul. If I didn't want them to see me I should have closed the blinds. But if someone sets up a camera at the exact same spot and streams it to twitch, I feel like I should have some recourse. (I don't think, legally, I would, but ianal).
- yeetsfromhellL2 4y agoThis is silly. It was a publicly accessible URL. A better analogy would be leaving your window blinds open and being upset that your neighbors can see you inside your home. Your neighbors aren't at fault, you are, and you can face criminal charges if you do something lewd inside your home while visible from public property. AT&T is completely at fault here for publicly distributing private info.
- strulovich 4y agoFor an analogy who went all the way up to the Supreme Court see: https://news.artnet.com/market/arne-svenson-neighbors-photographs-supreme-court-286916/amp-page https://news.artnet.com/market/arne-svenson-neighbors-photog...
- yeetsfromhellL2 4y agoThis woman was not guilty after doing this with special equipment, a telephoto lens(!). There was also that guy in another case sitting in his kitchen naked while drinking coffee and reading the morning paper. Some woman decides to walk into his back yard with her kid, sees him, and called the police on him for indecency...it took years for him to get let off and cost him a ton of money to not get any penalties. He was nearly held liable for what someone saw inside his house when they had to be trespassing to see it!
- simiones 4y agoThis case should be held up as a troubling indictment of current legislation, not held up as an example of freedom of expression. It also happens to be irrelevant to the case above, as it seems to have been specifically decided on the merits of the photographs as Art. It would be hard to claim that leaking the emails to Gawker was a form of art, so it may well have ended up differently.
- ascagnel_ 4y agoAnother major difference is that Svenson intentionally omitted faces, so determining identity is very difficult. Leaking emails to Gawker for users' AT&T accounts is partially identifying its users, so it could even be considered a hostile action (against either AT&T, its customers, or both).
- djbebs 4y agoIn general, yes, absolutely.
- kuroguro 4y agoI wonder how this works with scraping. If I automatically scrape and store sensitive data by accident, surely that would be the site's fault?