the web is public, despite SV’s best attempts to subvert and exploit that. If you don’t want someone accessing information don’t publish it as a website that anyone can access.
Just because something is on the internet doesn't give you the holly right of getting it for free.
Correct. Others have the holy right to charge, and I have the holy right to try getting around it.
That said, you're free to try to get around easy "protections", Mozilla is free to take down your methods for doing that.
Ultimately businesses will always ruthlessly try to make more money, and software will ruthlessly seek a more efficient user experience.
Often these objective clash. Spotify is the obvious example that seemed to offer a solution in the music space. But we have yet to discover such a solution in online publishing.
Have you ever been in a conversation where someone talks about something and you said “hey I read this cool article on that, let me send it to you.” If so, guess what - you were the search engine for that conversation. Should you then have access to view the non-paywalled content?
So yeah, I have no issue with this add on. If they didn’t want the double standard - to allow free access for some and not others - it is easily possible and in their full control to prevent add ons like these (think of any admin site or service for which you have to login before seeing/do anything.)
Content producers have a choice and they’re choosing to be bullies. I have no moral or ethical qualms when it comes to dealing with bullies or double standards.
Just my two cents.
Why not?
You cannot reasonably expect to protect or restrict content with a flawed understanding of the medium in which that content is conveyed.
If you don’t want me access it don’t put it on the web.
No matter how easy is it for me to go into your backyard (bypass your paywall), it's still an offense.
More simple, if you don't want the user to have it then don't give it to them.
If it's legitimate for a bank to hide your data behind a username and password, how is a journalism-provider any different?
So is that's your fundamental issue with a paywall? Anything that's available to Google (and Bing, DDG, etc) should also be available to you at no cost?
Restating that from the other perspective: if the information isn't universally available for no cost, it cannot be looked up via a search engine?
It's crazy to send them the content but tell them not to read it... back to your example would you expect your bank to do that? Here's all the account details and transactions but oops thats not your account. I'm guessing no, you'd hold your bank to a high technical standard.
To be clear, if newspapers/journalists want to work out some special agreement with google (or partner/agreed upon indexers) so their requests are authenticated so that only they have access to the content - i think that is a better solution then pay walls and sending the article and saying "don't read this please"
But regardless of how crazy this scheme is, I don't think it justifies taking advantage of that craziness to unwrap such content.
I think it's reasonable to question the approach of banning the plugin too: the problem is the users' choice to use the plugin, not making it available. But ... when there's no justifiable use for the plugin, and the author clearly intends it to be used to view unauthorized content ... I can see that it's an attractive strategy to just ban it.
What kind of paywall are you thinking of?
In principle, I have reservations about exposing content to search engines but then requiring payment to read it. Especially if it's non-trivial to filter out the sources that require payment.
But a plugin which works around an attempt to restrict visibility of content to those who've paid for it ... I thnk the intent here is wrong.
I think it's ok to have information that's only accessible to a restricted set of viewers.
It's not that it's not possible. It's not that the implementations aren't dumb. It's that the principle of "if I want it, and I can do it, then it's ok" doesn't really hold up, IMO.
I would argue, from both legal and technology perspectives, the ability to easily break a paywall provides you the right to do so.
If you really REALLY want to make this about morality then I would argue restricting access to available content is the greater moral offense, because it is an inherent violation of liberty.
Writing news is work of perhaps a different subject, but it can’t be denied that like software development, a significant amount of real work goes into that. How can you justify that the authors shouldn’t be able to reasonably expect to have control over their work and expect to be paid for it, if their consumers deem it valuable?
Don't care because that is not the subject of this issue not matter how much you wish it were. The subject is whether or not a paywall is adequate for restricting access to content on a public medium. If that restriction is so easily bypassed it is clearly ineffective and inadequate. If you really cared about your business and revenue you would solve this problem instead of complaining about failed value assessments.
> control over their work
Journalists don't have control over their work. Publishers do. This is the same failed argument the music and movie industries peddled from around 1998-2008. Instead of wasting your energy on distribution control spend it on what you are good at and return superior value to your work.
That's just plain wrong. There's nothing special about technology that means you get to throw all your existing moral principles out the window. The ability to technically do something does not confer you the right do it, either legally or morally.
Maybe if I draw an analogy to patents it might make sense? It seems most people in technology agree that taking something unpatentable and adding "do it on a computer" shouldn't make it patentable. Morality is no different. Taking something immoral, like taking someone else's intellectual property without paying for it, and saying "but do it on a computer" doesn't suddenly make it moral. Taking someone else's IP isn't immoral because you're depriving them of the paper it's printed on (that part is just petty theft), it's immoral because you're depriving them of the right to control the distribution of their IP and the right to get compensated for the work they did in exchange for giving you the right to use the IP.
Are you directly giving it to Google via encrypted tunnel? I am not redefining how any technology works or making any alteration to your distribution or your service. Yet, you are still giving it to me free and anonymous.
Some people think taxes are immoral, but that doesn’t give them the right or ability to redefine the tax code. HTTP is not immoral.
The real issue here is you are lost and confused because you don’t know how to secure your product. Your negligence in accounting for your business, financial model, and IP is not my lack of morality. Fix your technology.
Because I am operating squarely within the specification, designs, and intentions of the technology. When this is not the case there are two possible outcomes: a defect or missing security.
The absence of security or warning thereupon is an implied invitation. This is why, at least in the US, a warning must clearly be stated before trespassing can be enforced. In this case it isn't even remotely confused with trespassing because you are giving me the prize simply by my asking for it without any regard for who or where I am.
We can invent all kinds of fictions as to why this is right or wrong. More important is whether I am violating security (there is none to violate) or violating technology (clearly I am using HTTP properly). Ultimately this distills down to one question:
If you don't want me to access a given content then why are you giving it to me anonymously?
The answer to that question determines why the use of a technology qualifies the usage behavior.
> Just because it's technically possible for you to trick me into thinking you're Google does not mean it's ok for you to do that.
Why is that not okay?
> You tricked me into giving you something I thought I was giving to someone else
I did no such thing, because you never asked who I was. Would you give your car keys to a complete stranger assuming they are a valet without any consideration as to whether they are who they claim? If in this case the car is stolen what is your expected recourse?
> that doesn't mean you have permission to do this
It is perfectly legal to modify my user agent identifier for any reason at any time. It is my computer, my software, and my settings.
> that just means you tricked me
How could I have tricked you? You never bothered to ask. This is how this technology qualifies its use in this way. You made a faulty assumption and are shifting the blame for that assumption. You can continue to be upset about this, but you will continue to hand me the content that you wish to protect without any legal recourse or restitution.
If this were my business I would abandon this irrational commitment to a failed idea and either secure my financial model or just open it up.
No you aren't. The intent is "Give Google the complete text, put up a paywall for everyone else". The fact that the technical implementation does not perfectly express this intent does not mean you can pretend the intent is different.
> The absence of security or warning thereupon is an implied invitation.
Nope.
> This is why, at least in the US, a warning must clearly be stated before trespassing can be enforced.
This is wildly incorrect when it comes to computers. The CFAA does not require any sort of warning in order to determine that a user has overstepped their authority.
This isn't even true in the physical world. Many states require notice that you're trespassing before you're criminally liable, but "many states" does not equal all states. And even in the states where this is true, the absence of a notice is not at all an "implied invitation", it just means you're not criminally liable if you weren't informed that you didn't have permission to be there.
> If you don't want me to access a given content then why are you giving it to me anonymously?
Because you tricked me.
The fact that you fooled me into thinking you're someone else does not give you the legal or moral right to the results. Neither legality nor morality is a game, where if you can just figure out the right loopholes you can get away scot-free. That's not how it works. Not in the real world, and not in computers either. The word that describes what you're doing is "fraud".
Just because it's easy to trick me does not make it right to do so. Your entire argument boils down to "if you didn't want to be tricked, you should have tried harder". That's not a moral argument. The ease of tricking me does not in any way affect whether it's ok.
As an analogy, let's say I'm a baker, and to celebrate my dear mother Alice's birthday, I decide to give away a slice of cake today to anybody named Alice that comes into my shop. I'm not a suspicious soul by nature, so if someone walks up and says "Hi I'm Alice" I'm inclined to believe them. I'm not advertising this anywhere, there's no sign saying "If you introduce yourself as Alice you get free cake", it's just something I'm doing. If you hear about this (say, you have a friend named Alice and she tells you about the free cake she got), do you think you're morally justified in walking into my shop and saying "Hi I'm Alice"? Sure, the damages are pretty small, but you're still lying to get something you know you're not entitled to, with no justification other than you want it.
>> The absence of security or warning thereupon is an implied invitation. > > Nope.
You should consult an attorney. There is ample case law on this. This is how the military learned, the hard way, to impose warning banners.
> This is wildly incorrect when it comes to computers.
It still applies. There is legal precedent. CFAA does not apply in this case. In order for it to apply I, as a user, would have to knowingly overstep my authorized privilege level, which is commonly referred to as privilege escalation. This is explained in the Wikipedia article for CFAA.
> the absence of a notice is not at all an "implied invitation"
It is in the case where entry is anonymous and public, such as a store. HTTP is anonymous and public.
> Because you tricked me.
How could I have tricked you if HTTP is anonymous and public and was never asked to identify myself? I am an unknown stranger like every other requestor.
> The fact that you fooled me
I did no such thing. You never asked who I am. Had you asked I would tell you and then can you can decide if you would like to grant me access to the content. Instead you guessed incorrectly. Your bad judgement is not my fraud because HTTP is public and anonymous.
> Neither legality nor morality is a game
I keep trying to point this out to you but you would rather irrationally maintain your commitment to a failed idea and leave your business fully exposed. I did cyber security work for the military for about a decade, so I am fully aware of what the risks, technology, and laws are. If you were to serve me with a DMCA take down notice for anti-paywall software I would take you to court and I anticipate I would likely win. You really don't want that to happen. Why are you exposing yourself in this way?
> Just because it's easy to trick me does not make it right to do so.
Stupid is not a legal defense. Listen to the absurdity of this when rephrased to say the exact same thing: I am totally surprised that nice looking stranger drove away in my car after I voluntarily gave him the keys. Just who does he think he is? I know this will be all cleared up once the police find my car with the signed title in the glove box proving ownership. It was wrong for him to look like a banker. The imposter tricked me. How morally repugnant.
> Your entire argument boils down to "if you didn't want to be tricked, you should have tried harder".
That understates the absent mindedness of your position, but yes. It may or may not be moral, but it quite often the more legally valid point of view, particularly when there is a provable expectation of knowledge and risks.
> do you think you're morally justified in walking into my shop and saying "Hi I'm Alice"?
Yes, because free cake is great (since you're offering), and I think you will run out of cake. If I were the baker I would attempt to validate the person by asking for a phone number, address, or to see their ID. Stores already do this, which is why your scenario is absurd. If this scenario were a real thing it could backfire by resulting in a potential discrimination claim.
That has literally no bearing whatsoever on the morality of pretending to be someone else in order to get access to IP that you don't have the right to access. This is the second time you're calling me irrational, and it's not acceptable.
Rationality - https://en.wikipedia.org/wiki/Rationality
I used the word irrational in the context (both times) of commitment. This is an accepted description in behavioral health literature and does not address you as a person. It is also not polite to accuse people of tricky (fraud) when there is no evidence of such.
I'm not expecting a response (heck, I'm expecting this comment to be flagged for arguing with a moderator), I'm just hoping you'll pause for a moment and realize that heavy-handed moderation is counterproductive; if I'm punished for being on my best behavior, what incentive is there for me to care about my behavior at all?
Any time you find yourself writing things like "This is the second time you're calling me irrational, and it's not acceptable," you've passed the kind of discussion we want on HN. Even if it's true that the other person was behaving as badly or worse.
But really, it's not the fact that this comment was flagged that bothers me (though being accused of "tit-for-tat" behavior still rankles). What really gets me is my previous comment (https://news.ycombinator.com/item?id=18604446) is flagged as well, for no reason I can see.
As before, I'm not actually expecting a reply. I know you want this whole discussion to be over, and I'm fine with that. I just want you to spend a few seconds thinking about what I'm saying here.