If you visit stuff on the web, you respect the concept of a social contract between you and the provide. Don’t try to circumvent their wishes.
If you visit stuff on the web, you respect the concept of a social contract between you and the provide. Don’t try to circumvent their wishes.
That said anybody attempting to make parts of content non-pubic in HTTP without appropriate security restrictions are void the protections of law. The remedy for this is to ensure necessary security is in place so that non-pubic content is limited to account and session, which then puts part of the burden on the end user to ensure they restrict the credentials that provide access.
Content, not already covered, served over HTTP without the necessary security in place is not private.
There is a clause in the DCMA that makes it illegal to circumvent security controls. The stipulation there is that the security controls in question must be adequate and reasonable. Dropping a CSS model over some content is not a valid security control, and thus has no legal protection. Of course everything regarding DCMA is open to argument at legal expense.
It’s a common misconception that the word “effective,” as used in the respective legislation, was intended to mean “successful” or “always cause.” Rather, it’s always been interpreted to mean, “is designed to have the effect of.”
The fact that the measure is not always successful or is breakable does not make the law no longer applicable; that would be an absurd result. The law isn’t interpreted literally when the result would be absurd; this is doctrine that goes back to at least 1892 and even further back to English common law. See, e.g., Holy Trinity Church v. United States, 143 U.S. 457 (1892).
Engineers too often assume that the text of the law means what they think it means. This is one of those cases where a lack of legal education serves them poorly and leads them to incorrect conclusions.
I am of the bias that a space of technology cannot be summarily redefined by a single group interest merely to compensate their financial insecurity.
If I send a site an http GET request, and that site responds by giving me some data, then that site has given me implied consent to look at the data. If they don't want me to look at it, they shouldn't have given me it.
Man standing on the sidewalk outside a store yells into the store at the shopkeeper “hey there, can I have some free fish?”
Shopkeeper yells back “sure!” and tosses a fish to the man on the sidewalk.
Add more yelling back and forth for TLS handshake.
At this point, the man on the sidewalk can do whatever he wants with the fish. It was freely given.
Basically this example, if accepted in law, would mean that if you want your data to be private then Google would be expected to respect that, even if you sent them that data in the clear.
It's a ridiculous outcome.
Presumably, there's implied consent for me to to that? yes?
The analogy would be if the shopkeeper (i.e. web server) picks up an article and puts it in your pocket.
I'm not sure how the addon worked, if there's some trickery going on, but I'm long waiting for a lawsuit against ad blockers that could get heated.
That's what access control is for. If you don't secure your content, you don't get to whine that someone is reading without paying.
The site is free to not emit any content before payment is assured. The reason these add-ons are possible is that these sites are trying to have their cake and eat it to. They want to implement the paywall in the user agent so they can still get their content in Google. At the same time some of them are trying to argue for payments from Google for linking to their content. The situation is a mess but it's not about social contracts at all.
This doesn't necessarily prohibit the use of paywalls: the paywalled site just has to be designed so that it only sends content to clients that have provided evidence of payment rather than relying on the content being rendered in a way that prevents the reader from reading all of it.
Much as I'm for standards-compliant HTML rendering, I don't want any specific rendering encoded into law.
Basically it sounds like some publishers want to rewrite the rules of the web to neatly and conveniently serve their interests.
Browsers already have a mechanism for authorizing access to content. Many mechanisms, really. If a company chooses to use an unreliable mechanism, I don't think we are morally obligate to roll over and do what they want.
Paywalls were used in adult industry even before the 2000's.
Compuserve paywalled all of their content way back in the 1980s.
There is currently no way I know of allowing this functionality that is meaningfully "reliable". At least not without erecting new barriers such as mandatory registration (and verification).
So you, and everyone else, seem to be demanding publishers just switch to "absolute paywalls". You will then have strictly less access than before.
How is that supposed to be better?
Viewed under a magnifying glass, it seems like a good thing to ensure the publishing industry can use soft paywalls, but taking a broader view, I think that breaks the web. I don't think soft paywalls are worth breaking the web, and even more broadly, governments should only regulate what users can do with data willingly sent to their computers in very exceptional circumstances.
It may mean that without a harsh letigious method, publishers do not offer "soft paywalls". It's more likely they will continue to do so to not be shut out of the market, AND we won't have waves of frivolous harsh lawsuits bankrupting independent developers.
The alternative you're proposing is to in effect be held to ransom by content providers - your argument could equally be made for any form of drm or appeasement (without root how do we know you are not recording this, wothout your location how do we know you are within our licensing area, without direct retinal scans how do we know who is really watching, etc)
But if publisher do want absolute control over who views their content, then they should make people log in. I think that would be a mistake, but it's their mistake to make. I'm just opposed to give them legal control over what I do with my computer and any data their servers freely give me.