It's Your Data, It's Your Bot: It's Not A Crime
eff.org
eff.org
Parsing and correctly interpreting pages upon pages of legalese presents an undue burden on a well functioning market economy. Corporations can slip clauses into agreements that can give them vast power over their customers who do not understand the full ramifications of what they are agreeing to. There is very little cost involved to the corporation that tries to get away with this. There is a very great cost to our society in tying up our court systems with stupid crap such as this.
The only solution is to make the cost of writing illegal provisions into contracts greater to the perpetrator than the potential reward. I know there will be unintended consequences to what I propose. But surely there must be a way to send a stronger signal to corporations who willfully push legal boundaries and seek to obfuscate exactly what it is that consumers are agreeing to?
When everyone is a lawbreaker selective enforcement gives law enforcement tremendous power beyond what's written in the law. A similar situation applies to contracts, and contracts for software and services are so impenetrable these days that you're bound to be violating something or other just in everyday use.
You give us the right to publish your data and you don't have access to
anything else other than what the Facebook UI and APIs provide.
There, problem solved. Of course, writing this in legalese isn't so straightforward ... otherwise legions of lawyers and judges would be jobless. And they wouldn't be able to ban crawlers, other than search-engines ... and where's the fun in that?Take, for example, the standard UK limitation of liability cut-and-paste block. (About half a page.)
It's that long because there is case history on each point suggesting that if you don't enumerate each of those the conditions separately then you may get nailed for it. And every time there's a new test case that isn't quite covered, the list gets longer.
The only way to correct that kind of mess is through legislation. And there are so many examples of that kind of crufty-for-a-good-reason language that the patchwork would take years to unravel and have many unexpected consequences (not to mention lots of uncertainty until five hundred years of new case law was established).
There are people working on this kind of thing (for example the new companies act, which makes incorporation documents much simpler and removes some of the 'peppercorn and two groats must be thrice weekly burned over a blue flame' anachronisms) but it takes time.
Wasn't the CTO of Facebook just saying less than a week ago that : "users have complete control over their data, and as long as [the] user gives an application explicit consent, Facebook doesn't get in the way of the user using their data in your applications beyond basic protections like selling data to ad networks and other sleazy data collectors?" [1]
I sure hope I'm missing something here.
As good web citizens we honor robots.txt, but these frivolous lawsuits make me think we shouldn't form a US corporation just to leave a much higher barrier to suing us. Which incidentally means no YC for us.
Being who I am, I write a bot that scans my FB profile and checks for birthdays in the family. If one is approaching, it flashes a light, yells at me, and calls me names until I buy a present.
According to FB, I'm a thief, no?
What if I'm a blind guy who made his own browser-helper because the standard tools don't work so well for me? Or I wrote a special FB access device that helps people with ADHD? Or I just like the color blue and want to see everything in the world in blue? Or what if i just write my automation on top of a standard browser that highlights any text that has my friends' names and downloads the surrounding paragraph to my desktop. Just because? Seemed like fun? What if I filmed myself (or a trained monkey) accessing my Facebook account? What if I took the film and extracted data from it?
I would argue that I am accessing FaceBook via HTTP and GET and POSTS. I use standard nomenclature and the standard stack from the O/S outward. Anything beyond that is none of their damn business. (Not trying to play to the crowd, but this is preposterous. The entire purpose of HTML is to separate the data from the way we access it)
Of course, facebook would not prosecute you, but this is not the point. Facebook has been going after services that make it easier to delete your account, or move information to another service. This is what FB does not like.
Of course, what they are doing is completely disgusting, but facebook seems to be able to do whatever they want, and their users do not mind, as long as they don't change the profile screen too much. Then there is an uproar.
Have a look at the article...
By the normal sense of the law up till now, you are not a criminal if one party in a contract considers you in violation of the contract. It has been a civil matter. Even the RIAA has had to sue people in civil court rather than being able to prosecute in criminal court. A criminal violates criminal law. Let's get clear on the concept, especial with Facebook trying to stretch it.
It's not just that it is non-intuitive. Lots of legal things are non-intuitive. It's not even that it completely breaks the idea of HTML, even though that's pretty huge. It's not even that somehow by using FB I have given up my right to purchase and use my own equipment to browse the web, thereby limiting competition, although that is huge also. FB is actually trying to reserve the right to criminally prosecute me unless I use tools that are on a list that they preselect, and presumably update. So, logically, the first thing I'd like to do is see this list and find out how it is created and updated.
The entire purpose of software in this setting is to automate the retrieval and display of HTML based on my particular preferences, and in the time and configuration of my choosing. That's the way the web has worked ever since there was a web. That's why the the web is structured the way it is. That's why the web can continue to expand and grow.
I'm growing tired of attorneys on fishing expeditions.
That's my understanding at least - am I in the wrong here?
You're wrong because Facebook has the money and will to sue you into poverty. :)
The devil's advocate argument is that you don't own the data, you uploaded it to Facebook to use in a limited capacity (e.g. they're not allowed to just broadcast it to the world without your permission or unless they trick you into exposing it with weird 'privacy' options).
To use their service, which happens to use data you gave them willingly, you need to access their server in a manner they are happy with. And they are claiming that using a third party option to access it is forbidden. This is perfectly normal.
In essence this is the EFF trying to establish some ground in a new field. It's nowhere near as cut and dry as they present it, you had the choice to never upload that data in the first place. It's not a safety deposit box where you own the contents, it's a online social site that you chose to use and provide some data in order to be able to use it.
I've got no legal expertise, but that would be my first attempt as a devil's advocate.
But the natural way people think about their personal information is that they own it. This needs to be codified into law. Perhaps activism along these lines is one of the most important things we should be doing as citizens of a digital age?
This isn't about data ownership but about computer ownership. If you're going to access Facebook's servers, then you need to do so in a way that complies with Facebook's rules. Power Ventures ignored robots.txt, and circumvented an IP address block. In concept, this is no different than bypassing the password of a password protected web site.
That said, I'm with the EFF on this one.
I think that argument holds as much water as Facebook's, if not more so.
For an analogy to the real world, think about lockpicking. Lockpicking should be legal. Picking locks isn't the real crime; it's theft, trespassing, destruction of property, etc. that we should prosecute.
In this case users authorized Power Ventures to access their Facebook accounts (in exactly the same way users authorize Facebook to access their GMail/Hotmail/etc. accounts), so no actual crime was committed after circumventing the access controls.
Then, when the user has Power perform automated access, Facebook claims that a criminal law violation has occurred, because that's unauthorized access under their terms. They want that to be treated just like other California Penal Code unauthorized access -- access like exploiting a bug or stealing someone's password to view or change info never intended for you.
EFF says only a contractual violation has occurred; violating some arbitrary company-chosen 'terms of use' shouldn't be enough to trigger criminal enforcement.
It's an interesting and difficult distinction. So many of these systems and terms are defined by the arbitrary choices of coders and lawyers. At one level of abstraction, it's against the will of the system provider -- Facebook -- so it could be seen like a break-in.
But at another level, it's just a contract, and Facebook has other contract-enforcement options short of criminal prosecution: cancel the account, sue for actual damages, and so forth. If Facebook can define what's a 'crime' via arbitrary clickthrough terms, suddenly users and Power staff could wind up in jail for a terms-of-use violation that had no other economic damages.
So the issues are tricky, but important.
Under Facebook's claims, people could get arrested for something as small as using a browser or operating system that Facebook didn't like. If this idea is accepted, then Facebook can pretty much say anything and if you violate that thing and then access Facebook, Facebook would seek criminal penalties for your violation. For instance, if Facebook says "no person that doesn't own a pair of Nikes can access Facebook, under our new Nike sponsorship deal", and someone who doesn't own Nikes still accesses Facebook, Facebook would consider this "unauthorized access" and get mad. Or, if Facebook decides it doesn't like born in Florida, and they write "No one born in Florida may access Facebook", and you still access Facebook after being born in Florida, Facebook will try to get the police to come and arrest you.
Open Graph API is not unauthorized access because Facebook allows people to use it.
Under Facebook's terms, you could retrieve some Facebook pages from your cache, write a parser to parse your data and use it to harvest your data to a CSV file, and even this would be a violation.
The clause in question currently says:
You will not collect users' content or information, or otherwise access Facebook, using automated means (such as harvesting bots, robots, spiders, or scrapers) without our permission.
So Facebook can give permission, and clearly have given permission via some interfaces.
If Power could have done everything they wanted to do via the official developer APIs, no doubt the case would be different.
Power continued even after Facebook asked them to stop (and further tried to block Power's IPs) -- so at least some of the access occurred when permission, if any, was clearly not given.
But is that a crime? Or a contractual violation or tort?
But isn't this viewpoint stark raving mad?
I believe an exception is if you've posted "NO TRESPASSING" signs, making it clear that it's private property to which all entry is prohibited. But if you've invited the general public in subject to conditions, and someone violates a condition, they haven't yet committed a crime, unless they also refuse to leave when you try to eject them.
In Facebook's case, I'd say they've invited the general public to use their service, subject to some conditions, and so no law should be involved unless they've specifically asked the person involved to stop using their service and the person continues anyway.
If you keep data on your local machine and facebook comes and takes it from you, that's a problem. But if you voluntarily send it to them, then they're going to do whatever they want with it. How else would you expect it to work?
All we're asking is for symmetry. If I send them data, they can do whatever they want with it inside the law, their ToS and privacy policy. If they send me data (even the data I previously sent them), I can do whatever I want with it inside the law.
> I would say that it ceased to be "your" data once you
> typed it into facebook. Common sense should say that
> anything you send to a remote server is no longer under
> your control. I don't understand what the other side
> of this issue is.
It is your data under the law. Sure you may have handed it to someone else, but to say it is no longer your data just because it was handed to Facebook is like saying that you no longer have a Social Security Number when you provide it on a form to a bank (for example) or that when you are the victim of identity theft that you literally no longer have an identity.Now, one should probably act as if handing their data to one person was like handing it to the world, but there are obviously limits. If I purchase hosting from a company and host my data 'myself,' does my data now belong to the hosting company?
> If you keep data on your local machine and facebook comes
> and takes it from you, that's a problem. But if you
> voluntarily send it to them, then they're going to do
> whatever they want with it. How else would you expect it
> to work?
The basis for your entire argument seems to be: "If you trust people, you shouldn't be surprised if they in turn stab you in the back." While possibly true, society would be non-functional if everyone were like that.A competitor would never gain enough traction to reach critical mass (defined as when the average person has an account on both) without some help from facebook in the form of a stupid business decision. Or if they managed to think of some killer feature.
But simply a copy will never work.
And BTW, the main reason you hate facebook is because they are big. So adding a competitor will not help you - eventually they will get big too, and you will hate them as well.
Two big competitors are much better than just one.
In one sense - facebook becomes a natural monopoly. Back in say 2007/8 I had to log in to both facebook and myspace to see what my friends were up to. Now I just have to use facebook. That is much simpler and easier for me as a user.
Be better in some way than facebook (not selling users private information would be an easy one) Make it so that you could see what you friends were upto on facebook, but without being a user yourself.
Suddenly you cracked the chicken and egg problem, which is exactly why facebook goes after this with the force of the law.
A monopoly based on technology never lasts, but if you can build one on some kind of legal issue, you are golden.
Incorrect.
What I miss is some website where I can choose who gets to read what I write: this post is for everbody, this is only for my family, this is for my work mates, this is for the general public, this is for my brother.
The advantage of this would be that you could move groups over one at a time (since they would get some benefit from it, people would want to use it) and it is something facebook can't do and don't want to.
Try this site out: http://www.facebook.com/ - they have a nifty feature that does exactly that.
(1) You share your birthday with a friend Bob.
(2) Your friend Bob installs a facebook game from the Sleazo Company.
(3) Sleazo Company now knows your birthday.
That's how I understand it works. Your friends can share your information with third-party facebook applications. Please correct me if I am wrong.
Unless we're willing to consider DRM for social networks, this won't change with Diaspora or any other kind of software that puts your birthday on Bobs computer in any kind of standardized format.
At the same time he makes huge mental leaps that I completely disagree with (he said basically the same thing about open source/open culture) but there are several gems in the book.
And the marketing would be easy, as facebook isn't branded as the nice guy, but as the jerk.
It all comes down to what precisely am I allowed to do with a publicly available web page? I'm allowed to use a web browser to access it (presumably), but when does something stop being a web browser and start being an automated tool? I'm not familiar with the tool in question here, but could it be argued that in some ways it's no different than a web browser that pre-fetches linked content?
"Collecting Facebook usernames and passwords is at the heart of the dispute. Power.com impersonates a Facebook user after collecting their username and password."
I would still side with power BUT a TOS that says "you can't give your password to third parties" is a bit different from "you can't use any automated processes at all".
a) They are going after the third party, not the people that gave them their passwords, and
b) I believe Facebook also harvest passwords for other sites (hotmail etc)
c) In practice, there's not much difference between "Nobody can create a service that uses user's passwords to automate their Facebook access" and "You can't use any automated processes to access Facebook".
I forgot the Facebook harvesting passwords thing...
NOW that's rich... my qualms are gone....