Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Notably, the court recently curtailed the definition of "unauthorized" use in van Buren [1], which to me was a completely and somewhat unexpected ruling.

A pedantic point: van Buren decided the interpretation of "exceeds authorized access", not "without authorization". (There is no "unauthorized" in the statute--it says "accesses a computer without authorization or exceeds authorized access" as the operative part.)



>A pedantic point: van Buren decided the interpretation of "exceeds authorized access", not "without authorization". (There is no "unauthorized" in the statute--it says "accesses a computer without authorization or exceeds authorized access" as the operative part.)

That's an excellent point. And something folks should keep in mind.

That said, I'm not sure how the restrictions in CFAA could apply here, as LinkedIn explicitly grants authorization to everyone by making the web content in question publicly accessible.

What's more, other content on LinkedIn's web platform is not publicly accessible. If LinkedIn wants to make a claim that someone can exceed authorized access, then the content shouldn't be publicly available, as that explicitly allows access by anyone.

I suppose they could make the argument that such automated scraping is some sort of DOS attack based on increased usage of their bandwidth/CPU from such activity, but that's a very different argument, IMHO.

N.B.: IANAL

Edit: Fixed typo




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: