> The only "clear message" it sends is, "don't use that IP."
Are you saying with a straight face that anyone at Power thought it was a coincidence that suddenly they couldn't access Facebook from very specific IP addresses?
> The only "clear message" it sends is, "don't use that IP."
Are you saying with a straight face that anyone at Power thought it was a coincidence that suddenly they couldn't access Facebook from very specific IP addresses?
Then it should stop authorizing Power to do so. Why would it let the credentials work for Power unless those credentials authorized Power access? That's the problem. The simple solution is 2-factor authentication.
This is a solved problem. If you have "open access" of your web services and and access is non-disruptive, I don't know why this should be a criminal violation. It shouldn't be criminal just because it doesn't fit with your business model.
What if you tell me to stop doing it, but my friend is allowed and he types all of the commands that i tell him to type and then he sends me the data? That's why it doesn't quite make sense.
It doesn't make as much sense for a publicly accessible website and user tokens. It makes sense from a tort point of view, but not from a criminal point of view. The next step away would be for users to install an app that logs into facebook and forwards the data to the centralized server.