← Back to context

Comment by FireBeyond

11 days ago

That's an interesting spin that means precisely nothing. I'm not authorized to enter facilities or building maintenance spaces in buildings in my town because I'm a "community member".

The general public was authorized to enter the facilities 24/7. The exterior doors were unlocked and it was considered an "open campus". The access controls you see today have only existed since COVID. Whether he was a student at the time also means "precisely nothing".

  • Really? The expectation was that they could go into facilities closets and plug into the core networking equipment?

    • Don't waste your time arguing with people like this. They can't admit the nuance of the situation: what Aaron did was blatantly wrong, and what the government did in response was disproportionate. They will only focus on the latter, and make endless irrational justifications for the former.

    • The expectation is that MIT doesn't go to the police when someone plugs a computer into a switch in an effectively unlocked data closet.

      The expectation is that such individual and laptop doing "unauthorized" scraping doesn't trigger a criminal investigation when the host university, and the target business, didn't implement any meaningful access controls or even rate limiting for any other person on campus.

      The expectation is that after an investigation of scraping at 11 req/s (450,000 over 11 hours according to the report), a further 8,000 requests (before JSTOR blocked MIT's /8) two weeks later would not have the effect that "Half the servers in one data center failed, and JSTOR engineers feared that the entire service might go down worldwide." The expectation based on that claim by JSTOR is that JSTOR was incompetent or lying.

      The expectation is that when MIT was able and willing to implement access control for JSTOR, and JSTOR declined because they want to develop a notice to MIT visitors who might be negatively affected by ending uncredentialed access, JSTOR would not then create a tempest in a teapot over the violator returning and continuing to download papers at a reduced speed that wasn't even detected for about a month. On Dec 26, when JSTOR again noticed the "abuse", they went to significant effort to route the violator's requests to a special server and serve them garbage instead of the real PDFs, all on short notice... yet they couldn't add the general notice to MIT visitors about the credentials requirement, on a much less urgent timescale; they had told MIT in October that they needed until after Dec 18th to add such a message. The expectation is that JSTOR's claims are self-serving lies.

      The expectation is that such a request pattern would not trigger a report, by the MIT libraries director, to the MIT academic council, that a "cyberattack" had been launched from MIT's network.

      The expectation is that you don't get arrested for felony B&E for entering a data closet that's effectively unlocked, connecting to a switch, and scraping a paper hosting site that offers free downloads from the entire institutional network.

      The expectation is that you don't get charged with larceny for downloading, in any quantity, papers that are freely available to anyone on the MIT campus or probably most other campuses in the U.S.

      The expectation is that sending web requests with a url parameter indicating T&C has been agreed to, and without saving cookies, might be a basis for a civil action, but is not "accessing a computer without authorization" under the CFAA.

      The entire situation, at most, should've been a minor local crime and a lawsuit by JSTOR against Swartz. Yet the state charges were dropped (feds didn't want to share required discovery material), and JSTOR settled with Swartz before the feds even indicted.

      MIT was caught in an awkward position of having the ability to block unauthenticated scraping to protect their contract with and access to JSTOR, but not doing so. So they proceeded to treat someone connecting to a switch in a data closet and doing what any MIT visitor could do, as a criminal offense.

      I don't believe anyone at MIT was genuinely concerned that there was some broader criminal conspiracy when the issue was downloading of papers from JSTOR. Certainly not based on some random Chinese IP pinging or scanning Swartz's laptop. When the data closet laptop was discovered in January, MIT could have left a note telling the owner that JSTOR is very upset and it would be better for everyone if the scraping stopped. Why didn't they? They could even, reasonably, have taken the laptop and external drive and noted that the data closet was insecure and please contact network staff to claim it.