4 ms·
The relevant part of the CFAA, chopped up for readability: > Whoever ... intentionally accesses a computer without authorization or exceeds authorized access,
by skymt 11y ago
The relevant part of the CFAA, chopped up for readability:
> Whoever ... intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains ... information from any protected computer ... shall be punished as provided in subsection (c) of this section.
That requires both intent and access in excess of authorization. So since 1.html is a public page, you're authorized to read it. If 1.html was the personal information of the customer with ID #1, as in the AT&T case, that would violate CFAA.
Also notable is the definition of a "protected computer." It's any computer "which is used in or affecting interstate or foreign commerce or communication," which is every computer connected to the Internet.
- JustSomeNobody 11y agoSkeptic in me says this is just a nice way for AT&T to defer blame for not securing their customer's information. I've poked around websites, just to see what all is available, just by guessing URLs. I never had intention of getting anyone's personal data, of course. But, really, who hasn't done this?
- deleted 11y ago[deleted]
- dublinben 11y agoThe pages containing personal information of AT&T customers were publicly available though. We have already seen that an overzealous prosecutor will construe regular access as "without authorization or exceeds authorized access" whenever convenient.
- grkvlt 11y agoAs with everything in law, intent is key. Just because something can be accessed by the public, does not mean it is intended to be accessed by the public.
- Lawtonfogle 11y agoWhat makes a page public? Opening it up so that anyone who visits a link sees it? Or actually giving the link to someone to post in public. If the latter, I have a website that one could visit but which I have never given the link out for. It seems absurd that it would be considered hacking to just visit the front page of my website whose link I have never given out but which you can guess. (0 content website of which I never actually finished designing.)
- gph 11y agoI think that's why intent is the important part of the applicable law. If I went to your website without knowing I wasn't meant to access it, then I wouldn't be breaking the law. If however you could prove in court that my intention was to access the website without your permission than I would be breaking the law. Certainly it would be very difficult to prove my intent, and there's probably nothing about your website that would make it clear I wasn't meant to access it. But if you had a bunch of private user pages that I somehow figured out how to get to even though it's apparent that I'm not meant to have access to, then I could be prosecuted for that. I think it's a terrible grey area that this law leaves open, but alas that's how it is for now.
- delecti 11y agoI would question whether the AT&T case involved "access in excess of authorization". I feel like the merest attempt to implement some access control would be necessary for that. I think he was doing enough other things that I'm not crying a river that he got punished, but IMO it sets a bad precedent.