If Google isn't interested in such a standard (because it reduces the quality of open search results) then that's the publishers' problem, not Google's or users'.
If you visit stuff on the web, you respect the concept of a social contract between you and the provide. Don’t try to circumvent their wishes.
That said anybody attempting to make parts of content non-pubic in HTTP without appropriate security restrictions are void the protections of law. The remedy for this is to ensure necessary security is in place so that non-pubic content is limited to account and session, which then puts part of the burden on the end user to ensure they restrict the credentials that provide access.
Content, not already covered, served over HTTP without the necessary security in place is not private.
There is a clause in the DCMA that makes it illegal to circumvent security controls. The stipulation there is that the security controls in question must be adequate and reasonable. Dropping a CSS model over some content is not a valid security control, and thus has no legal protection. Of course everything regarding DCMA is open to argument at legal expense.
It’s a common misconception that the word “effective,” as used in the respective legislation, was intended to mean “successful” or “always cause.” Rather, it’s always been interpreted to mean, “is designed to have the effect of.”
The fact that the measure is not always successful or is breakable does not make the law no longer applicable; that would be an absurd result. The law isn’t interpreted literally when the result would be absurd; this is doctrine that goes back to at least 1892 and even further back to English common law. See, e.g., Holy Trinity Church v. United States, 143 U.S. 457 (1892).
Engineers too often assume that the text of the law means what they think it means. This is one of those cases where a lack of legal education serves them poorly and leads them to incorrect conclusions.
I am of the bias that a space of technology cannot be summarily redefined by a single group interest merely to compensate their financial insecurity.
If I send a site an http GET request, and that site responds by giving me some data, then that site has given me implied consent to look at the data. If they don't want me to look at it, they shouldn't have given me it.
Man standing on the sidewalk outside a store yells into the store at the shopkeeper “hey there, can I have some free fish?”
Shopkeeper yells back “sure!” and tosses a fish to the man on the sidewalk.
Add more yelling back and forth for TLS handshake.
At this point, the man on the sidewalk can do whatever he wants with the fish. It was freely given.
Basically this example, if accepted in law, would mean that if you want your data to be private then Google would be expected to respect that, even if you sent them that data in the clear.
It's a ridiculous outcome.
Presumably, there's implied consent for me to to that? yes?
The analogy would be if the shopkeeper (i.e. web server) picks up an article and puts it in your pocket.
I'm not sure how the addon worked, if there's some trickery going on, but I'm long waiting for a lawsuit against ad blockers that could get heated.
That's what access control is for. If you don't secure your content, you don't get to whine that someone is reading without paying.
The site is free to not emit any content before payment is assured. The reason these add-ons are possible is that these sites are trying to have their cake and eat it to. They want to implement the paywall in the user agent so they can still get their content in Google. At the same time some of them are trying to argue for payments from Google for linking to their content. The situation is a mess but it's not about social contracts at all.
This doesn't necessarily prohibit the use of paywalls: the paywalled site just has to be designed so that it only sends content to clients that have provided evidence of payment rather than relying on the content being rendered in a way that prevents the reader from reading all of it.
Much as I'm for standards-compliant HTML rendering, I don't want any specific rendering encoded into law.
Basically it sounds like some publishers want to rewrite the rules of the web to neatly and conveniently serve their interests.
Browsers already have a mechanism for authorizing access to content. Many mechanisms, really. If a company chooses to use an unreliable mechanism, I don't think we are morally obligate to roll over and do what they want.
There is currently no way I know of allowing this functionality that is meaningfully "reliable". At least not without erecting new barriers such as mandatory registration (and verification).
So you, and everyone else, seem to be demanding publishers just switch to "absolute paywalls". You will then have strictly less access than before.
How is that supposed to be better?
But if publisher do want absolute control over who views their content, then they should make people log in. I think that would be a mistake, but it's their mistake to make. I'm just opposed to give them legal control over what I do with my computer and any data their servers freely give me.
Viewed under a magnifying glass, it seems like a good thing to ensure the publishing industry can use soft paywalls, but taking a broader view, I think that breaks the web. I don't think soft paywalls are worth breaking the web, and even more broadly, governments should only regulate what users can do with data willingly sent to their computers in very exceptional circumstances.
It may mean that without a harsh letigious method, publishers do not offer "soft paywalls". It's more likely they will continue to do so to not be shut out of the market, AND we won't have waves of frivolous harsh lawsuits bankrupting independent developers.
The alternative you're proposing is to in effect be held to ransom by content providers - your argument could equally be made for any form of drm or appeasement (without root how do we know you are not recording this, wothout your location how do we know you are within our licensing area, without direct retinal scans how do we know who is really watching, etc)
Compuserve paywalled all of their content way back in the 1980s.
Paywalls were used in adult industry even before the 2000's.
Edit: the link, for the willfully dense, is that some protocol specification does not imply its users’ acceptance of any and all (ab)uses possible. It’s completely different only in that you like one but not the other.
(This is mostly to show that I, too, can argue with invented “contracts”).
I pay for my internet connection and I expect others who make use of the same network to follow its protocols. I expect HTTP to work as HTTP. If a bad network node chooses to circumvent how it works and I find a way around their circumvention then I should not be punished. On the other hand, if I republish and break copyright it is an entirely different matter.
> There’s also a social contract about respect for the law.
Which law, and as it applies in which context?
In practice, American legislators have to raise large amounts of money just to say in office. So it's unsurprising that they listen mainly to the concerns of people with money: https://www.vox.com/2014/4/18/5624310/martin-gilens-testing-...
We are in an age where information distribution is approximately free. And where the costs of producing information-based products has declined drastically. Paywalls are not any sort of law; they're an attempt by information producers to have their cake and eat it too. They want the abundance of the new, computer-driven world. But they want artificial scarcity, so that they can charge like they did in 1970. My sympathy is with journalists here. But that doesn't mean I have to roll over and let them break the web.
The laws in question here, the DMCA and the CFAA, are both too new and too old to be reflexively bowed to with "OMG spirit of the law!" Too new because they are obviously part of society's attempts to deal with technology, and are equally obviously driven by the interests of people who have piles of money and are trying to protect those piles. And too old because both, but especially the CFAA which was written in 1984, reflect a very early understanding of what computers are, what they're for, and how society should treat them.
As far as I'm concerned, this is an ongoing negotiation. We need to find ways for journalists to get paid. We need to find ways to have a much more informed populace. We need to preserve as much as possible of the freedom computers and networks have given to every individual.
If we want paywalls to be a part of law, then we should have a national debate about whether publishers deserve a special protection so they make all of their content available, let it be downloaded to any computer in the world, and then have that computer enforce any restrictions they think are good ones. We are not obliged to just concede that debate right at the beginning just because you think reading an infinitely replicable article already on your computer is exactly the same thing as stealing a unique piece of fruit from a blind man's store.
Exactly. 99% arguments here are essentially the equivalent to "since Marriott/SPG are horrible at cyber security, I am ENTITLED to use stolen credit cards from their leaks."