Comment by pbasista

8 hours ago

Terms of service have no legal binding unless both parties agree to them.

In other words, if X has a public API and Nitter is using it, then neither Nitter themselves nor the Nitter users have to agree to any terms of service in order to do so.

X cannot expect anyone to behave in accordance with terms and conditions they never agreed to.

We need to revise the law around terms of service, we are allowing companies to impose all kinds of monopolistic, anti competitive, user hostile, privacy invasion, and other measures against the public interest simply by burying provision in a wall of text they know no one will understand even if they read it.

  • We don't need new laws--we just need existing courts to start finding these terms of service to be unconscionable and refuse to enforce them. They certainly fit the description:

    • Unequal Bargaining Power: A large gap in power or knowledge between a large corporation and an individual consumer or employee.

    • Lack of Meaningful Choice: "Take-it-or-leave-it" adhesion contracts where the weaker party cannot negotiate any terms.

    None of these so-called "agreements" should bind people. There is no actual agreement or "meeting of the minds." It's just one party writing one-sided rules that only they get to enforce.

> if X has a public API and Nitter is using it

Public as in being visible to all is not the same as public as in allowing use by all. You appear to be conflating the former definition with the latter. For example, my front door is visible to all, but a person isn't allowed to walk into my house without permission.

  • > Public as in being visible to all is not the same as public as in allowing use by all

    Where's the limit of that? Can I have port 443 open with a website behind it but sue anyone that accesses it because the fact that it being visible doesn't mean that I allow anyone to access it?

    • > Where's the limit of that?

      The very obvious answer is that penalty is commensurate with suitable advance notice of authorization limits. It's why there are rules about things like how to post "no trespassing" signs when access boundaries are not otherwise clear. But you're also allowed to notify and make someone leave your property if they wander in.

      > but sue anyone

      There are two very different kinds of "sue anyone". There's sue them to extract resources from them and there's sue them to make them stop. This is the latter not the former. Treating them as though they aren't wildly different is an error.

      You effectively just asked whether I should be allowed to escort someone off my property without harm if they accidentally enter it. Yes, because it doesn't harm them in relation to what they didn't know in advance.

  • The person is allowed to walk to your door. They are not allowed to walk through your door.

    It's a totally different thing.

    • Indeed. You can look at the shape of the API but not extract things through it. Look, sometimes seeing and using are the same thing, but calling an API, which causes the machine running the API to do work in response to the call, is not the same thing as looking at the API.

> In other words, if X has a public API and Nitter is using it, then neither Nitter themselves nor the Nitter users have to agree to any terms of service in order to do so.

That's not true. Publicly available source code with licenses dispute your claim.

  • (IANAL) That's copyright law and not contract law. Perhaps X could try to put a clause in its ToS that publishing content there grants the copyright to itself, but I'm pretty sure it won't be accepted well even if it's legal.

  • License != ToS

    Copyright law applies to all citizens whether or not they've agreed to a contract.

  • What are you talking about, specifically?

    Using software with specific licenses? Or making modifications to it?

    That is substantially different from reading the public APIs.

> Terms of service have no legal binding unless both parties agree to them.

Even if both parties agree to them, are there any legal consequences for breaking the terms of service?

Isn't it the entire premise of Nitter and the other scrapers, to use accounts in order to access the API, access non-public posts, and proxy them to the public?

If Nitter is creating accounts for access then it doesn't matter whether they use the API or the web client (which is also API). Because creating an account binds you to the Terms of Use. It's not rocket science.

Also, to further cement this comment's unpopularity: it's unconscionable and appalling that this Nitter team, these cheats and thieves, that they are now begging for money and attorneys to bail them out of this legal grave they've dug for themselves. I sincerely hope that they are dragged in court, that they lose, and that they are severely financially damaged by trying to fight this stupid battle.

There is no reason to bypass authentication just because you hate X or Musk or you think it's somehow unjust that people can't access shit without simply signing up and agreeing to contract terms. Most sane idiots would simply shut down, take their "L" and do something productive. Doubling down and begging for legal fee donations is brazen and shameless and, honestly, insane.

  • Wild to stare down the entire history of civil disobedience, close your eyes, and say "just because you think rules are unjust, that's no reason to ignore them". Some real "all the orders were on display at your local office in Alpha Centauri" energy.

    If you ever find yourself on the pointy end of an unjust system, I hope the people in a position to fight against it for you can see a little further.

  • Or maybe, just maybe, they have their principles and try to follow and defend them. Yes, it's difficult and you usually seems "the bad guy" when fighting against the status quo.

    I'm pretty sure that the ButlerianJihads of the beginning of the 20th century had the same opinion about the suffragettes (saving all the differences, for sure)

> Terms of service have no legal binding unless both parties agree to them.

Companies are perfectly entitled to tell people they aren't allowed to use their services anymore. That's what the C&D was. It's perfectly legal to say "here's an API anyone can use, except you, Anish Kapoor."

It's like if Reddit bans you, you aren't entitled to use the site after they've told you you're banned. Even if you can find a technical means around the ban, it's still trespass.

  • > if Reddit bans you, you aren't entitled to use the site

    I would say that you are not allowed to use their site as a logged in user (i.e. upvoting, downvoting, commenting, making posts).

    It does not seem logical to me that Reddit could "ban" anyone from using their public frontends as anonymous users.

    They could only do something like that, in my opinion, if access to all their content was gated behind a login.

  • IANAL, but if I were a lawyer, I would be making the case that Nitter is not using X's services. Nitter is no different than Firefox or Chrome, it's a user-agent acting on behalf of the user.

    • Completely different users! It's using authorized accounts of people who agreed to the Terms of Use. Not just those, but the Developer Terms apply to the API.

      https://docs.x.com/developer-terms/agreement

      But the "users" who are viewing Nitter content are not those same authorized users. They are unauthorized users. They are not authenticated by X. They are unknown, anonymous, and untraceable to X. That is unacceptable for any service--especially a service that's restricted to authorized users. Especially a service that puts forth Terms of Use that apply to the actual user using the service.

      It is patently absurd for someone to say that, since there are "public endpoints" hanging out there, that X has no right or authority to govern how they're used, and who uses them. Of course they do.

      When I access X with Chrome, I sign in... I'm the same user authenticated and authorized by them, and Chrome is my interface. It's not a proxy, a scraper, or an API gateway. It's my client and X knows exactly who I am. I agreed to use X properly, and conduct myself properly on their platform. Nitter did none of this.

      1 reply →

"Haha I used the API which I KNOW is governed by the ToS but I didn't agree to it"

Judge: "do you agree to the terms?"

"No"

Judge: "then you can't use the API"

"But look at all the downvotes this is getting! You're wrong Mr. Judge!"

  • There is no agreement you need to enter into in order to use public APIs.

    That is the purpose of public APIs. Usage without prior agreements.

    If the API providers want to restrict the usage of their APIs, they are free to make them non-public.

  • Nobody's forcing the operator of the api to respond to those requests. HTTP 401 is right there.