← Back to context

Comment by huatilla

5 years ago

The Computer Fraud and Abuse Act outlaws "unauthorized access". The website owner clearly did not authorize access to that, so the letter of the law may have been violated. Maybe the law should require malice, criminal intent, and actual harm to have happened for "unauthorized access" to be a crime.

If you mail me a letter, and on the back of the letter you write a secret in French, would you claim that I wasn't authorized to turn the paper over and that I wasn't authorized to know French? Maybe don't write secrets on things you mail me or don't get upset when I read them.

Didn't they grant them access? HTTPS has access control mechanisms in place, if that page wasn't meant to be accessed, that's one thing, but it was literally a public page on their website. Furthermore, if it wasn't data the user was meant to access, why did the website owner transmit it to them? (And not just the Journalist in question, but everyone who had gone to that page while this was there).

Where this page not meant to be public, I'd tend to agree with you, but it was meant to be public and was transmitting this data to use as an identifier. The encoding its in is irrelevant, encodings are not encryption and this journalist did nothing illegal.