I could do the same thing and write an app for, say, the tax agency by scraping its website but it would be a legal gray area.
I could do the same thing and write an app for, say, the tax agency by scraping its website but it would be a legal gray area.
See the Aaron Schwartz trial which was about essentially the same thing.
No, you may not in this case :) That is why people keep emphasising the way in which the data was published. This is Sweden, not the US.
> the city didn't publish their information through an API
Yes, they did.
> and also explicitly stated that they did not want Christian's app to access their information
If you cannot reasonably be said to have circumvented any technical measures to secure the data (cryptographic keys, some sort of login, IP range blocks, etc) it is not a breach. In that case, it is just you consuming what is there for everyone (like unencrypted wifi - harvesting those signals using SDRs is not an issue because you are not bypassing any security), which is okay.
Edit: Legally okay, that is. How you feel about it ethically is up to you, I'm not talking about that.
Here is the relevant paragraph:
"För dataintrång döms den som olovligen bereder sig tillgång till en uppgift som är avsedd för automatisk behandling eller olovligen ändrar, utplånar, blockerar eller i register för in sådan uppgift"
The requisites are: "olovligen", "bereder sig tillgång till", and "uppgift som är avsedd för automatisk behandling". Christian's app full fills the requisites.
API means "Application Programming Interface" and if you think the city created or intended to create such a thing you don't know what an API is.
> If you cannot reasonably be said to have circumvented any technical measures to secure the data (cryptographic keys, some sort of login, IP range blocks, etc) it is not a breach.
You have no idea what you are talking about. There are several precedents that show that circumventing technical measures is not required for data breach to have occurred.
>For data intrusion, a person who illegally prepares access to information that is intended for automatic processing or illegally changes, deletes, blocks or registers such information is sentenced
This app does not appear to meet this definition as the data they are exposing is not intended for automatic processing, but it is exposing manually consumed data (i.e. the parents were already consuming this data manually) in a different, more accessible way.
I agree the city obviously wasn't intending to expose an API.
Which precedents are you talking about. I don't know much of anything about Swedish law so any precedent you can show would be educational for me.
Given that you know significantly more than me perhaps you could give me some examples. I'm always interested to see countries in which such jurisprudence is different from the norm, especially in Europe. Thanks :)
If you don't want to make an API that exposes raw data just write a SSR app. If you want to deploy a SPA, well, you have to deploy an API as well and you need to plan around the fact that when you throw an API out into the wild and authorize people to use it (by handing out auth tokens), well, people are gonna use it.
If you want to stretch the terms, everything on and off the web that does communication is basically an API - it's just that some of those APIs use JSON to encode their data and make it really easy to access... and some of them bury it in mountains of HTML - but if the data is there the data is there. There really isn't a functional difference between a scraper that goes from TEXT => DATA and a json decoder that goes from TEXT => DATA except how easy it is to write and maintain it.
One outcome of this fight might be that government organizations are directed to use more proprietary communication methods which would be a poor outcome for everyone involved.
Would you consider `ls` an API for exposing your filesystem?
I don't see why not.
It has an interface for input and output, conforms to well known specifications and is publicly documented.
There's also multiple implementations behind the API.
I agree with the rest of your argument, but I think that this part is not necessarily a good example of the risks. Far easier would be to use a shared key between the app and the site, and thus use encryption to prevent reading the data, while still sending it in JSON over HTTPS. A pinned certificate would do the trick, at least on phones which prevent the user from inspecting app bundles.
We've seen such bizarre technical decisions from high courts before.
Uh, also, IANAL.
One implication of this project could be that government agencies in Sweden can not have private API:s.
To use more proprietary methods (private api:s) will have no effect on the constitutional law. You still have received a public document as a citizen.
If a spy is filling out an expense report via secure email after an undercover mission to Norway (trying to figure out if Norway is hording lutefisk, I assume) which ends up resulting in a bombshell report to the public about international lutefisk accessibility then that report is clearly public - but the spy's expense report (including, I'd assume, their identity) is something that should logically be kept secret. There's some press secretary in the middle that takes the raw information and turns it into the scandal we all know it would be.
The data being transmitted over an API is not intended to be directly consumed by the public - there is, instead, an application that exists to take that raw data and transform it into something that is publicly viewable. That application is the corollary for our press secretary here.
I am concerned this might be a bigger rabbit hole than you expect. I totally agree that the town shouldn't flip out and be stupid calling in legal authorities like it currently is - but I think this might be more complex.
I know technologists like to think that way but very often the law doesn't work like that. They will think about intent - was the intent to give you the raw data or was the intent to convey a specific representation of it that may omit some parts or further transform or presentation layer changes to achieve a different final result to what the raw data would have conveyed?
If it is the latter then that is the "public document" you have access to, not the raw data from the API.
Seems you're saying it might be illegal to convert a HTML file to PDF format, or to use a screen reader to read the text.
I wonder in which country you are (where apparently there can be laws like that)
Say the education department has a requirement that where ever a student's grades are displayed, the legend to explain their meaning and a disclaimer about limitations is included. It could even be a hard requirement (like, they got sued once for not doing it so their lawyers have told them they must enforce this). So they are careful that in their app, that requirement is always satisfied, since failing to do that could lead to harmful confusion that could impact a student.
So in their view the "document" they made public is the fully rendered version of that. If you print it out you are effectively doing a transformation that preserves its form and essential characteristics. If you screen shot it, cut out the disclaimers and legend and then paste it on a public web site ... you could create the same problems that you are by taking raw data out of the API.
Also it's easy to poke holes: does this mean that scraping data from html is always hacking, regardless of the expressed intent? (See recent Missouri case for what that might degenerate into.) What if it's "semantic web" and the html contains metadata specifically designed to aid data extraction?
I think the parents should own the data, and that's why it should be open. But I don't think drawing the line based on which kind of technology is used to deliver the content is a good method of adjudicating published intent.
Q) Are you able to retrieve a document using the credentials issued to you by the API? A) Yes: Then you're authorized to view it. No: You're not authorized to view it.
An API is the encoding of business rules around data access and modification. If your API is allowing access that you don't intend a user to have, fix your authorizations.
Apart from other reasons, it would almost certainly result in providers obfuscating data or reverting to SSR which is a perverse outcome.
The only way to not make an API out of publicly available data, is to encrypt it. Then nobody can read it unless they have the right keys.
Not if you're using a public key cryptosystem and the user generates their own private key. Only the public part is communicated (from the user to the source of the information), and that isn't enough to decrypt the document.