3,263 karma · joined March 3, 2013
I like it because I can use discord on even a pretty untrusted computer without providing it any credentials or access to my passkey, and then later when I'm done I can revoke the session.
This news segment goes into more detail about how he downloaded the documents (by incrementing the document id in the url) https://x.com/Brett_CBC/status/984751373525901313
> (a) Whoever— (2) intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains— (C) information from any protected computer; shall be punished as provided in subsection (c) of this section.
https://www.law.cornell.edu/uscode/text/18/1030
So if it can't be proven that you intended to access a computer without authorization, or exceed your authorized access, then you can't be found guilty of the crime.
Consider the possible consequences of the law not requiring intent, if simply accidentally exceeding your authorized access could be a criminal act.
I presume this is the extra obligation starting in 2027 that wikipedia mentions.
In fact federal law provides that accessorys can't be sentenced to more than 15 years if the principal crime is punishable by life imprisonment (like terrorism is).
> or if the principal is punishable by life imprisonment or death, the accessory shall be imprisoned not more than 15 years.
> For OpenAI GPT-5.4 and GPT-5.5, classifier-flagged traffic will be retained for up to 30 days for automated offline abuse detection
https://docs.aws.amazon.com/bedrock/latest/userguide/abuse-d...