6 ms·
Adding to this, in some countries he is already past the gray-area to what constitutes as computer fraud. Pissing off the company, whose systems you accessed w
by mainframed 2y ago
Adding to this, in some countries he is already past the gray-area to what constitutes as computer fraud.
Pissing off the company, whose systems you accessed without authorization, is one way of getting to experience the full force of the justice system.
- moralestapia 2y agoCurious. How is this, specifically, fraud?
- cornel_io 2y agoPeople have been convicted of hacking for merely editing URL strings, under the theory that were knowingly accessing systems in ways that they were not supposed to. This would be similar. Whether or not that seems reasonable to us is a different matter, but basically it boils down to the fact that "they left the door unlocked" doesn't make it legal to walk in.
- ensignavenger 2y agoI believe the conviction of which you are thinking was overturned on appeal, though.
- rvnx 2y agoHe is in India: If any person without permission of the owner or any other person who is incharge of a computer, computer system or computer network - (a) accesses or secures access to such computer, computer system or computer network or computer resource; - (b) downloads, copies or extracts any data, computer data base or information from such computer, computer system or computer network including information or data held or stored in any removable storage medium; [...] - (e) disrupts or causes disruption of any computer, computer system or computer network; [...] - (g) provides any assistance to any person to facilitate access to a computer, computer system or computer network in contravention of the provisions of this Act, rules or regulations made thereunder; If any person, dishonestly or fraudulently, does any act referred, he shall be punishable with imprisonment for a term which may extend to three years or with fine which may extend to five lakh rupees or with both. ==== Though, I prefer a lot the poster of the blog post than the company...
- mainframed 2y agoI don't know Indian laws. But this wikipedia page [1] gives a list of types of computer fraud in the US under the CFAA: Types of computer fraud include: * [...] * Accessing unauthorized computers * [...] He accessed their computers to access purchase information of other people (e.g. his friend) and business data. I guess making it public, thereby damaging the companies reputation and potentially getting sued by their lawyers is one way to find out, whether he was "unauthorized" to do so. [1] https://en.wikipedia.org/wiki/Computer_fraud https://en.wikipedia.org/wiki/Computer_fraud
- nkrisc 2y agoThe gist of some various laws around the world is that simply obtaining credentials does not authorize you to access the system, and accessing it without authorization is the illegal part.
- drdec 2y agoThis principle is clear if you apply a real world analogy. Just because you happen to have keys to a building doesn't mean you can enter without authorization from the owner. (E.g. you may have kept copies after a lease expires or a sale, it maybe you found them, etc.)
- whamlastxmas 2y agoConsidering it’s a API available without any authorization, the better comparison would be walking around on unfenced private land. There’s nothing to indicate they don’t want people on it but it’s also obvious it’s private land.
- hunter2_ 2y agoWalking around isn't usually a big deal until told to leave (verbally or by way of conspicuously posted signs), since that is a prerequisite to trespassing. Otherwise, delivery people would operate in a gray area which would be very problematic for them, since not all deliveries are requested by the recipient/owner. However, although you are free to walk around in search of the front door, you can't start eating the fruit off the trees. Perhaps that's the better analogy: the trees are happy to serve up a delicious treat for anyone requesting something of it, but that doesn't mean the tree sets the rules. Just because fences preventing this are popular doesn't make them compulsory.
- ryathal 2y agoIt doesn't matter. It's still just as illegal to get into an unlocked car or one with wide open doors without permission. The same premise applies to computers in a lot of places, access controls don't matter. If you access something on a computer not indented to be accessible, it's considered a crime.
- ceejayoz 2y agoBy the sensible definition, it isn’t. By the definition that killed Aaron Swartz, it probably is.
- AdamN 2y agoHe wasn't prosecuted for logging in and looking around. He overtly did copyleft type things like finding ways to take copyrighted journal articles and release them into the public domain. Overzealous prosecution for sure regardless.
- ceejayoz 2y agohttps://en.wikipedia.org/wiki/Aaron_Swartz#United_States_v._Aaron_Swartz_case https://en.wikipedia.org/wiki/Aaron_Swartz#United_States_v._... > On July 11, 2011, he was indicted by a federal grand jury on charges of wire fraud, computer fraud, unlawfully obtaining information from a protected computer, and recklessly damaging a protected computer. > On November 17, 2011, Swartz was indicted by a Middlesex County Superior Court grand jury on state charges of breaking and entering with intent, grand larceny, and unauthorized access to a computer network. > On September 12, 2012, federal prosecutors filed a superseding indictment adding nine more felony counts, increasing Swartz's maximum criminal exposure to 50 years of imprisonment and $1 million in fines. The only civil copyright proceedings were JSTOR settling with him out of court.