6 ms·
Any company could potentially be hacked, so by that standard all data is public. And no, the ToS is legally binding on the company as well.
by breezybottom 15d ago
Any company could potentially be hacked, so by that standard all data is public. And no, the ToS is legally binding on the company as well.
- arcfour 15d agoThat's a blatant strawman - that's not a reasonable position at all. A reasonable person does not expect their private medical records to be accessible to you or me just because they are stored in an EHR system. They might be surprised that you or I looked at their TikTok video when we aren't the intended audience, but they still posted it publicly, with the understanding that it would be made freely available to others.
- breezybottom 15d agoIt's definitely not a strawman. Perhaps you meant that it's a false equivalency, but I don't think that's true either. With how common data hacks are, why wouldn't a reasonable person expect their medical records to leak? I received at least two such breach notices just last year.
- arcfour 15d agoObviously I meant that any data a person expects to be public, like a public post on a social media site... I was not referring to data exposed in data breaches, which is a different subject entirely... If that was not obvious to you then I apologize; though it really should have been, since you are encouraged to interact with others in good faith on HN. And if you expect your medical records to be public...then what is the point of this discussion?
- breezybottom 15d agoThe user only gave TikTok permission to use the videos according to the ToS. And considering the majority of TikTok users are children, I think it's hard to justify morally, even if you could make a legal case.
- echoangle 15d agoIs it a data breach if I right click images in google search and save them to my disk?
- breezybottom 15d agoA data breach could leak into search engine results, sure.
- echoangle 15d agoI wasn’t asking if a data breach could be in the search results, I asked if saving search engine results in itself would be a data breach. Apparently you think that scraping publicly accessible data from tik tok is a data breach in itself, so does this apply in other cases too?
- arcfour 15d agoA "data breach" refers to unauthorized access to nonpublic or protected data. Scraping content that is publicly viewable without logging in - or even with logging in, since an account is effectively disposable - is not a "data breach" (as far as any typical usage of the term goes). In hiQ Labs v. LinkedIn, the 9th Circuit (US) ruled that scraping publicly accessible data does not violate the CFAA's "without authorization" clause (hiQ was bulk scraping public LinkedIn profile data - in violation of LinkedIn's ToS). The Supreme Court later specifically narrowed the CFAA in Van Buren v. United States saying "exceeds authorized access" applies to accessing areas of a system you aren't entitled to enter at all, not misusing access you legitimately have (regardless of ToS violations). Other CFAA cases have ruled similarly - being legitimately granted access (i.e. signing up for an account, or browsing publicly without logging in, since the site is intended to be available to the public) and then misusing it is not "hacking". So in the U.S., it's not a computer crime ("hacking"/"breach") to scrape data, and nobody uses the term "data breach" to refer to scraping publicly available data on a public site, except for apparently you.
- breezybottom 15d ago
- echoangle 15d agoYou don’t see a difference between accessing data by hacking a service (which is illegal) and downloading/scraping data that’s not protected? The TOS are a contract and only a civil thing afaik.
- deleted 14d ago[deleted]