4 ms·
As an example: Take a look at the URL of this page (https://news.ycombinator.com/item?id=45261163 https://news.ycombinator.com/item?id=45261163). Add 1 to that
by kayge 1y ago
As an example: Take a look at the URL of this page (https://news.ycombinator.com/item?id=45261163 https://news.ycombinator.com/item?id=45261163). Add 1 to that ID value (45261164) in your address bar. Hit Enter, your browser will GET whatever exists at the next ID.
- rirze 1y agoOk, that makes sense but why is this so serious? Is this a grave crime in some context?
- tptacek 1y agoIt's not about the actual HTTP request. Per se unauthorized access is just one predicate in these kinds of cases. It's about what the prosecutors claim you were doing when you made the access.
- ecb_penguin 1y agoBecause people think they are clever and are trying to separate the act from the intent. Unlocked doors, open windows, any lack of security doesn't give you permission to enter. Just as "incrementing a GET request" doesn't mean anything outside of the intent. The intent was to do damage.
- Dylan16807 1y agoHe did have permission to "enter". He was authorized to use the server. His intent of releasing the data was bad (assuming he started with that intent!) but he wasn't committing any fraud when collecting it. He didn't bypass any authentication or damage the server. CFAA is the wrong law to use. If a restaurant puts a bunch of proprietary documents in a dusty corner of the public lobby, you shouldn't browse through them but you're not breaking and entering if you do so. No matter what your intent is.