Comment by peter_d_sherman
6 hours ago
>"the difference is
intent."
>"but if i (or an agent working on behalf of me) use an API in an obviously
unintended
way to revoke other people's reservations..."
?
6 hours ago
>"the difference is
intent."
>"but if i (or an agent working on behalf of me) use an API in an obviously
unintended
way to revoke other people's reservations..."
?
i am not quite sure what your question is, as you simply quoted me and then put a question mark... i think you are confused that i used "intent" in one context, and "unintended" in a different context, is that right?
the first sentence: the difference is the intent of the person who caused the cancellations
the second sentence: but if i (or an agent working on behalf of me) abuse an API to do things it was not meant or designed to do, such as cancelling someone else's reservation
The point is, the law cares about your intent. If you ask an agent to abuse an API to do those things, then yeah, you are probably liable. If you ask an agent to do something reasonable (like make a booking), and then it accomplishes that by abusing the API, then you probably are not.
yes, that is the exact point that i have been making throughout my comments, including the one you are replying to. intent is the crucial factor in cfaa cases.
Double negative. An attacker using the API in an "obviously unintended" manner shows intent.