Parler Wasn’t Hacked, and Scraping Is Not a Crime
lawfareblog.com
lawfareblog.com
> Public LinkedIn profiles, available to anyone with an Internet connection, fall into the first category. With regard to such information, the “breaking and entering” analogue invoked so frequently during congressional consideration has no application, and the concept of “without authorization” is inapt.
"visibility: hidden" is unlikely to meet that burden. It's not any kind of access control mechanism; the people who are able to see it are defined by their knowledge of the tool, not by being granted access.
This is the criteria they used:
> Put differently, the CFAA contemplates the existence of three kinds of computer information: (1) information for which access is open to the general public and permission is not required, (2) information for which authorization is required and has been given, and (3) information for which authorization is required but has not been given (or, in the case of the prohibition on exceeding authorized access, has not been given for the part of the system accessed).
Obfuscation does not require any kind of authorization. It makes it more difficult to extract information, but I think you would have a hard time arguing that other users are not authorized simply because they don't know the URL. There isn't even a list of who is allowed, so "granting" access in this case is nonsensical.
The only way I can see this being illegal is if Parler can successfully argue that they intended for this to require authorization, the scraper knew that Parler intended this to require authorization, and that it's a violation of the CFAA to do something that the provider didn't intend for you to be allowed to do. I don't see that as a remotely likely outcome.
Here’s a huge difference between the Swartz case and Parler, the data Swartz was scraping wasn’t public.
Scraping may not be a crime but unintended privilege escalation is a whole different story.
At an extreme you could fusk shared Google documents. Assuming there's a bug that brings it down from end of the universe timelines, basically you are brute forcing a shared password.
Or is this 'scraping' - ?login=myusername&password=mypassword
It's hard to see someone guessing 1000's of URLs that they have no public link to, to get material end users have deleted being straight forward legal.
This sounds like the resources were available by simply enumerating over autoincrementing primary key, so it didn't require much "guessing".
Weak security does not bestow the right to steal data.
It does not, but entirely absent security does give the public the right to view the data. HiQ vs LinkedIn [1] found that scraping of publicly available assets did not constitute a violation of the CFAA.
That court upheld that in order to trigger a CFAA violation, there needs to be some form of access control in place. Otherwise the data is considered public. Not only are you allowed to scrape it; Parler is not allowed to try to stop you from scraping it, unless they are willing to put the data behind a log in wall.
[1] https://www.eff.org/document/hiq-v-linkedin-ninth-circuit-de...