Because it seems in the realm of possibility that if a large botnet hits you and your responses crash a bunch of computers you could do serious time for trying it. I'm hoping there's precedent against this...
Because it seems in the realm of possibility that if a large botnet hits you and your responses crash a bunch of computers you could do serious time for trying it. I'm hoping there's precedent against this...
Microsoft doesn't take the fall for malware, even if its a fault in SMB or the like.
The intent is damage.
He bases this attack on IP addresses. IPv4 addresses are regularly shared between consumers. He's tossing a knife into a crowd because he thought he saw someone.
> you could make a pretty good fleeing felon argument.
In a nation that allows you to attack, not just restrain, a fleeing felon.
But his attack may hit a nation that doesn't allow that.
You ask for something a vulnerability scanner would ask for? You get a gzip bomb.
[0] https://www.reddit.com/r/PHP/comments/6lfl6p/i_have_created_...
Let's be frank.
He's serving up malware to potential users who hit too many 404s.
> Awesome! My production implementation of the bomb also looks at 404's and 403's per IP and if there are too many of those it will send the bomb. [0]
This could be exploited by a third party, which makes him complicit.
He targets IP addresses, and as the IPv4 world often shares those, he can attack innocent bystanders who happen to be in the same allocation as a miscreant.
Finally, self-defence is established as denial or dropped connections. As he's intentionally avoided established practice, and developed an attack instead, it becomes undue harm.
Let alone if he attacks someone in a nation that has an extradition treaty, but no concept of this sort of "fighting back".
[0] https://www.reddit.com/r/PHP/comments/6lfl6p/i_have_created_...
A farmer here in UK stirred up a whole load of shit when he shot two burglars [1] trying to escape from his property.
Some places in the USA have "stand your ground" laws. These say you aren't required to retreat, that you can "stand your ground", that you can use (legally) leathal force without requiring that your back is against the wall.
As for people running away, the only way I see self defence working is when they still pose an 'imminent threat to life' which seems rather hard to argue.
I've read but couldn't find again the story of someone shooting a tief to get back his VHS player and walk free.
I'm not arguing for actually using the law to shoot people: I don't ever want to be in that situation myself, but I'm saying depending on the situation you do in fact have the law on your side.
That isn't normal, though. It's likely that you were already feuding, and so the law will look askance at you for not bringing authorities into it much earlier.
I think all of those cases are covered by any imminent threat clause, and thus do not need special exemptions. Just like there isn't an exemption that you are not allowed to shoot a retreating person. It simply follows because (with exceptions) retreating people aren't imminent threats.
Florida [1], for example, says:
> ... A person who uses or threatens to use deadly force in accordance with this subsection does not have a duty to retreat and has the right to stand his or her ground if the person using or threatening to use the deadly force is not engaged in a criminal activity and is in a place where he or she has a right to be.
In section 0776.013, the castle doctrine is also noted, but is more expansive, and includes the use of deadly force even if there is no threat of imminent harm.
[1] http://www.leg.state.fl.us/statutes/index.cfm?App_mode=Displ...
The US tends to be a little more prescriptive, leaving a situation where different jurisdictions have more specific requirements for defining what constitutes self-defense.
Juries in the UK tend to have significantly more responsibility for making judgments like these, leading to a system where evolving views of what is right and wrong can result in standards naturally evolving over time, rather than being fixed by what people thought was okay thirty years ago.
Connecting to a server...( A lot)
Putting random strings into forms...( A lot)
Moving your money between banks... (In different countries)
Buying stocks... (With insider knowledge)
A simple act doesn't spell the whole story, and fraud, computer crime, etc laws are written vaguely enough for a country to prosecute someone " sending large files."