Careful, this could legitimize things like accidental denial of service. Depending on circumstances, even basic scraping could cause problems.
(I need to be vague to avoid violating an NDA.) A major internet site had a URL that went something like somedomain/group?id=xxxxx. It turns out that a simple scraper, that called id=1, id=2, id=3, ect, ect, caused a major problem! This was because rendering these pages required significant resources; so most active pages were kept in RAM. Of course, the scraper tried to read everything.
Of course, no one thought the scraper was malicious in any way!
You're still culpable if your actions break your neighbor's window, even if it was accidentally while you were opening it.
Yes, if my crappy software costs you money by knocking your site offline by accident, I should make you whole.
I think it has to be something substantially more impactful, clearly intentionally malicious, or in some other way much worse than aggressive timeouts before we start thinking criminal penalties.
After doing something that pisses a lot of people off, they start getting 1000X calls per day on the same number, almost all complaints.
This cases actual damages (no "normal" customers can get through) and is also clearly outside the scope of "normal" usage.
Do you think the same rules apply?
I must've responded while he was editing it, and I didn't catch the change.
This is a failure on the part of the developers at that "major internet site". Using a guid instead of consecutive IDs, a rate limiter, hell even just a cache...or all of the above. There are lots of solutions here.
You have to take robot scraping and indexing into consideration, and assume people will ignore robots.txt. (Certain bots, i.e. msnbot/bingbot are quite aggressive!)
It’s not easy to craft a law that will punish bad behaviour without blocking innovation.
Of course, some sense is more than welcome, but if my scraper makes one request every 2 sec knocks down your server, it's your fault, not mine.
You are right, but few organizations are sophisticated.. or wealthy enough to employ all of that. I mean, a couple years ago there was a thing that Google's Docs could be enumerated.
And that's Google, they can obiously afford to get competent people working on that, yet they made a mistake (and who doesn't?).
Who owns LinkedIn again?
Are you saying that the writers of a bot that causes accidental issues with a site due to poor development standards on that site should spend years in prison with a federal felony conviction?
- the password verification form to access the admin area did the verification check in JavaScript, not on the backend. So if you have JS disabled and click "Submit" on the Admin login form, you're into the admin area.
- the "delete" button in the admin area was implemented as an <a href=...> that simply did a GET request (violating the idempotent nature of GET requests).
Looking at the logs, it was pretty clear who the "hacker" was: Google. They'd come, follow all of the links, make their way into the admin site, and follow all of the delete content links.
I consider the work that the original developers did to be grossly negligent, and I certainly don't fault Google for anything.
[0]: https://arstechnica.com/gadgets/2010/06/ipad-3g-user-e-mail-...
Otherwise you get situations like Uber paying out an enormous "bug bounty" totally-not-in-exchange for having their stolen data destroyed. If that person had simply pointed out that they had credentials published in a public repository, how much would they have been paid? Probably somewhere within an order of magnitude of the program's stated maximum payout.
I have to "deal" with that problem every day. Misconfigured scrapers are dealt with by apache as are idiots who try to DoS the site (an intelligent attack still needs manual intervention, though).
I am not saying that the trouble with the law enforcement in the internet is a neither a good nor a bad thing. Actually, it depends and in the 'real' world I am pretty happy that the law enforcement works quite good where I live. I think the thin line is somewhere where I start to fear my own governments more than the bad guys (while not having any evil intentions or plans at all).
No. It's only been ahead of most laws for a while, as all frontiers are while they remain frontiers. But all frontiers eventually close, and laws catch up with them as they do so. That is what we're seeing now, and have been for a decade or more.
cf. for example the law on trade secrets. If you take "reasonable steps" to safeguard the secret, and impose NDAs on the people you do grant access, then courts will punish competitors who steal them, even if your security happens to suck.
Linkedin is not trying to prevent access. They want to prevent information from being scraped, and then used to their detriment.