3 ms·
You’re confessing to several actual felonies here, may want to change strategies.
by nativeit 7mo ago
You’re confessing to several actual felonies here, may want to change strategies.
- kstrauser 7mo ago“…and so I made him the owner of my account, and he used that to remove himself from it!” “We’ll be right over.”
- thatguy0900 7mo agoYou forgot the part where he reset their email he didn't own and change their passwords so they couldn't get back into it
- kstrauser 7mo agoI think you’re misreading this. OP has an email account. Someone else signed up for some website that doesn’t verify that you own the address before allowing you to log in and use the service. If the site did verify it, the user wouldn’t have been able to log in because OP would have been getting the verification emails, and not the user. Later, after OP told the user and they failed to change their address, OP logged into the site and changed their password, putting an end to the spam they were receiving from the user’s actions. I don’t have an ethical qualm with this. He didn’t want to sign up for the service. Someone else signed his email address up for it. Legally, I can’t imagine that being prosecutable.
- NikolaNovak 7mo agoOne thing I've found, occasionally the hard way, is that helpful bystanders are always offering advice based on "ethical", "intuitive", "logical" and "common sense", usually without any aspect of "legal". I got divorced a decade ago, and every well-wishing person in my life was strongly urging me to do things which were shockingly counter-productive / dangerous / wrong, based on their confident understanding (assumption, really) of the law which was completely and dangerously inaccurate. Hacker News audience is global. People start accounts for various purposes. Yet people still freely share the notion that logging in to some unknown website run by an unknown company from a hard to spell country and then touching things is universally safe. I miss the old "IANAL" tag which at least provided basic warning and self-awareness :-).
- altairprime 7mo agoIANYL, though! Offering legal advice with the disclaimer “I am not a lawyer” could be prosecuted as practicing law if a reasonably party could still infer a potential lawyer-client relationship from your message and/or intent. Instead, “I am not your lawyer” explicitly denies the lawyer-client relationship, which closes the door on both being accused of practicing law illegally and on being found as party to a lawyer-client relationship whether or not you have the appropriate certifications.
- technothrasher 7mo ago> closes the door on [...] being accused of practicing law illegally Does it? So I can say, "I'm not your lawyer, but I'm happy to go ahead and give you specific legal advice on your case." and I can't be accused of illegally practicing law? I was under the impression that this could still get you into hot water. But not being your lawyer, due to the fact that I am not a lawyer at all, I don't know if it is true or not.
- kstrauser 7mo agoIANAL, so take this with a grain of salt, but: As with all things, who are you going to get in trouble with? And what's so magical about legal practice as opposed to, say, giving shitty medical advice or telling someone how to build porch? Asking genuinely. No one falls all over themselves to say "I am not a doctor, but...", even though their next words could kill someone. The implication is that they don't have formal training but they saw something on Facebook that you should try. What happens next is on you, not on them.
- altairprime 7mo ago> No on falls all over themselves to say “I am not a doctor, but” This is precisely why I’m pointing this out: IANAL is a very curious case of people self-labeling their statements as “not trustworthy for the topic”. I can think of perhaps no other cases where it is so popular to claim to not be a professional in the relevant field, which suggests that IANAL is a ‘badge of honor’ rather than a proper legal disclaimer. Certainly few (if any) claim IANAD before writing about their experiences with medical issues, body things, or nutritional supplements here, even though those topics are (as you correctly indicate) potentially lethal. Thus, IANYL: if your goal is to ensure that the recipient of your advice / opinion / whatever does not have grounds to claim that you provided legal advice, and therefore are their lawyer, then you can either do so weakly with TINLA (“this is not legal advice”), which still leaves the door open for awkward claims by some desperate grifter-rando to reach a bench, or you can do so strongly with IANYL (“I am not your lawyer”), which closes that vulnerability in full. Not once in years of using IANYL have I seen anyone else properly protect themselves from this vulnerability; meanwhile, “IANAL but” remains in use as a badge of honor. So, yeah, I don’t think anyone considers the particular avenue of vulnerability a serious threat, and yeah, the general context of IANAL here is prideful rather than protective. But after twenty years of dealing with a stalker who was adept at internet and tried to fuck with my job at one point, I do now tend to value closing off legal vulnerabilities with certainty, and as a bonus it doesn’t imply insult to the professions of law. IANYL, YMMV :)
- ntoskrnl_exe 7mo agoI'm curious if this would really be considered unlawful access, since only pure idiocy and no hacking/scamming/etc were involved.
- volkercraig 7mo agoIt would be in Canada, but our "misuse of computer" charge is overly broad and never been well tested.
- charlieyu1 7mo agoOn the other hand, in Hong Kong it would be straight to jail. Someone was sent a link by the airlines, he changed a couple of characters and it ended up showing another person’s data. The guy voluntarily reported the vulnerability and all he got was a criminal charge and found guilty
- tracker1 7mo agoYou give someone ownership of something and they used that ownership...
- krickelkrackel 7mo agoIt's like leaving your bike in the street, with no lock. Still theft, but you'd be up for a part of the responsibility.
- c22 7mo agoIt's more like leaving your bike in someone else's garage.
- tracker1 7mo agoNo, it's like giving someone a set of keys to your car, and they take it for a drive.
- kstrauser 7mo agoI think it’s more like you registered the car in their name. Now they’re allowed to use it, and also responsible for the thing which they didn’t want. Consider that the “imposter” starts uploading child porn or something, and it’s on an account registered to your address. I think it’s perfectly A-OK to tell the service that it’s not me using the thing and I want them to close the account someone created in my name.
- jama211 7mo agoNo harm done no one is gonna prosecute this
- cft 7mo agoIn what jurisdiction? He's in Russia
- AlexeyBelov 7mo agoHe's in the US.
- NikolaNovak 7mo agoRight. Techies are always quick to suggest I do something naughty or funny with this "great power" I've unwittingly gained, but in reality it's just a liability. If I ignore it and they do something nasty and implicate me, it's a pain. If I touch it with a 10 ft pole, now I'm even more actively involved. Just include "not me!" In the verification email, dam it