I'm sorry, but isn't that a major oversimplification of what he did?
I'm sorry, but isn't that a major oversimplification of what he did?
He’s certainly responsible for his actions, but they were not wrong, I think. And he was obviously unjustly persecuted for his actions.
I think it’s accurate for us to celebrate SCOTUS ruling that the way the feds prosecuted Swartz was wrong and recognize that it will help prevent future Swartz.
It doesn’t matter what the action of the equipment or the morality of it. It’s not like it would be bad for a student or professor to put up crypto miners, but then good if they donate them to charity.
And that is not to even mention the fact that his actions caused effectively a denial of service attack on jstor from MIT.
I’ve attended and visited quite a few universities and they all had liberal network access policies. So the idea of anyone caring about someone plugging a laptop into a lanport and downloading millions of text files is not remarkable and happens all the time, I expect.
There was no “denial of service” on jstor as it was still available during the whole time. And if jstor can’t handle a single laptop scraping every article, then that seems to be more of a problem with jstor.
Students scrape jstor and other journal sites frequently and seems like a pretty decent use case that I want to support at my university, if I had one.
Crypto miners are a different story as they consume resources and if Swartz had set up a hundred laptops or a bunch of gpus and used university resources, I’d have a different story.
But the idea that a single laptop running in a closet for a weekend had any material impact on MIT or jstor is so laughable that I don’t understand how anyone honestly presents it as an argument.
Swartz did not deserve to be driven to suicide for this. He did not deserve jail time, or to be arrested. At worst he deserved to be the defendant in a fairly low-stakes civil suit, and maybe even lose. But that's it.
In the Van Buren case, SCOTUS was very concerned with the potential for innocent actors to unwittingly run afoul of the CFAA. The website would likely have to take further steps to make the restrictions on access known to the user (such as a warning when trying to access [X], and probably also take actual steps to limit access to [X], such that one would only be able to access [X] deliberately knowing that they don't have authorized access to it.
Importantly, Swartz's prosecution would not have been blocked by the SCOTUS decision in Van Buren because they make a distinction between improper use of computer access and improper access of a computer: Swartz did not have authorized access to the networking switch.
However, if he had used Wifi, to connect to the MIT networking, the charges would have been unsustainable under the Van Buren decision because guests were permitted on the MIT wifi network (and he had a JSTOR account through his Harvard employee account), and his use of it would merely of been improper use at best (since he effectively DDOS'd JSTOR for other users and got MIT's IP range blocked) rather than improper access.
EDIT: Note: a friend pointed out that the DDOS'ing of JSTOR could technically constitute a crime under the CFAA, depending on intent. In Swartz' case, the DDOS was an unintentional side effect of trying to download too much data at once for archival purposes so malicious intent was missing, but someone doing the same thing for the purpose of preventing access to the system could still be guilty of a crime.
That's not clear to me, because MIT tried several times to revoke his permission to use their guest network by repeatedly banning him by IP address, and then by MAC address. He kept changing those to evade the revocation of permission.
That seems like it would be enough to distinguish from the Van Buren case.