5 ms·
If you can be prosecuted for guessing urls you can be prosecuted for sending garbage data in a way you know will be uploaded to a remote system.
by emidln 10mo ago
If you can be prosecuted for guessing urls you can be prosecuted for sending garbage data in a way you know will be uploaded to a remote system.
- mindslight 10mo agoAs a strictly logical assertion, I do not agree. Guessing URLs is crafting new types of interactions with a server. The built in surveillance uploader is still only accessing the server in the way it has already been explicitly authorized. Trying to tie some nebulous TOS to a situation that the manufacturer has deliberately created reeks of the same type of website-TOS shenanigans courts have (actually!) struck down. As a pragmatic matter, I do completely understand where you're coming from (my second paragraph). In a sense, if one can get to the point of being convicted they have been kind of fortunate - it means they didn't kill themselves under the crushing pressure of a team of federal persecutors whose day job is making your life miserable.
- monerozcash 10mo ago>(A) knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer; If your goal is to deliberately "poison" their data as suggested before, it's kind of obvious that you are knowingly causing the transmission of information in an effort to intentionally cause damage to a protected computer without authorization to cause such damage. >Trying to tie some nebulous TOS to a situation that the manufacturer has deliberately created reeks of the same type of website-TOS shenanigans courts have (actually!) struck down. This has very little to do with the TOS though, unless the TOS specifically states that you are in fact allowed to deliberately damage their systems. And no, causing damage to a computer does not refer to hackers turning computers into bombs. But rather specifically situations like this.
- Xss3 10mo agoAny reasonable programmer (a peer) would say an unencrypted system that doesnt validate data is an unprotected system.
- monerozcash 10mo agoIt's a legal term, has nothing to do with technical protections. Practically any device connected to the internet is a "protected computer". The only case I can think of where the defendant prevailed on their argument that the computer in question was not a "protected computer" was US v Kane. In that case the court held that an offline Las Vegas video poker machine was not sufficiently connected to interstate commerce to qualify as a "protected computer".
- mindslight 10mo agoA computer being supplied with false data which it then stores is not damaging the computer - hence there being a provision about fraud. But for this case it's not fraud either, as the person supplying the data is not obtaining anything of value from the false data.
- monerozcash 10mo ago>the term “damage” means any impairment to the integrity or availability of data, a program, a system, or information; Deliberately inserting bad data to mess with their analytics does in fact fit that definition.
- mindslight 10mo agoYou are construing "integrity" to mean lining up with their overarching desires for the whole setup of interconnected systems regardless of who owns each one. By that measure, stopping the collection of data is impairing its availability on their system. I would read that definition as applying only to their computer system - the one you aren't authorized to access. This means the integrity of data on their system has not been affected, even if the source of that data isn't what they'd hoped. As I said, the law contemplates a different call out for fraud. This would not be needed if data integrity was meant to be construed the way you're claiming. (For reference I do realize the law is quite unjust and I'll say we'd be better off if the entire law were straight up scrapped along with the DMCA anti-circumvention provisions)
- monerozcash 10mo agoWhy do you think the CFAA is unjust? What specific activities does it unjustly criminalize?
- mindslight 10mo agoI had assumed you were coming from a similar position, and your argument was more of a reductio-ad-absurdum. But if you're not - the fact it's putting a chilling effect on this activity right here is a problem. Another big problem is the complete inequity. It takes the digital equivalent of hopping over a fence and turns it into a serious federal felony with persecutors looking to make an example of the witch who can do scary things (from the perspective of suits). Another glaring problem is that if the types of boundaries it creates are noble, then why does it leave individuals powerless to enforce such boundaries against corpos, being easily destroyed by clickwrap licenses and unequal enforcement? Any surveillance bugs/backdoors on a car I own are fundamentally unauthorized access, and yet I/we are powerless to use this law to press the issue.
- vkou 10mo agoYou think criminalizing guessing URLs is unreasonable. What about guessing passwords? Should someone be prosecuted for just trying to bruteforce them until one works?
- nkrisc 10mo agoHow do I know which URLs of a website are legal to visit and which are illegal?
- vkou 10mo agoI can't say I've ever struggled to make this determination, but I don't make a habit of trying random ports, endpoints, car doors, or brute-force guessing URLs.
- sayamqazi 10mo agoBut it was very tempting when i saw that my national exam results were sent to us in a mail as nationalexam.com/results/2024/my-roll-number. Why would i not try different values in the last part.
- monerozcash 10mo agoTry it once to see if it works, you'll probably be fine. Find out that it works, and then proceed to look up various other people? Whether you're fine depends entirely on whether or not you genuinely believe that you're supposed to be accessing that stuff.
- wakawaka28 10mo agoPasswords are different from URLs because URLs are basically public, whereas passwords aren't supposed to be. Furthermore, this is not 1995. Everyone who is in the industry providing IT services is supposed to know that basic security measures are necessary. The physical analogy would be, walking through an unlocked and unmarked door that faces the street in a busy city, versus picking a lock on that door and then walking through it.
- rockskon 10mo agoThe DoJ lost the case they went after for someone guessing URLs.
- monerozcash 10mo agoThey lost it because they charged in the wrong jurisdiction. Also come on, you can't reasonable describe that case as being about "guessing urls". It's the associated chat logs that really make the case.
- red-iron-pine 10mo agolink me