I don't mean to be disparaging, but HTTP status codes have been well-documented. The only issue is that they are used poorly/incorrectly so often.
If you can't use HTTP status codes properly, then you simply aren't in a position to subjectively characterize someone's request as impermissible/unauthorized. This is especially the case when the server's choice to grant access conflicts with your intentions.
The problem with HTTP status codes is people usually use one of the few they know, instead of looking at the full list and choosing the most suitable from the options. I think a lot of people forget that there is 301 as well as 300.
What would you do in real life if you found a vending machine that was somehow locked into giving out free drinks if you pushed a button, despite listing a price for each soda?
For all I know it's a stunt by the vending machine company to make people addicted. Free stuff for 1 week, then people have to start paying.
Actually Telenor in Norway recently sold a few hundred tablets for 1,- kr a piece 16 cents US, and this without a contract. First they said, no, no, no, it was a mistake in our computer system, but they ended up having to sell them anyway because they would have such a hard time proving that every one of the customers knew well and right that there must be a mistake.
Anyway special case scenarios would never be covered by your server saying 200 OK.
However, day to day scenarios would. If your server gives people access to a file, and the user has no reason to believe the server is making a mistake. Then the 200 OK holds.
It's like walking into an unlocked building. Many buildings are supposed to be unlocked and people walk in and out as they please. If you put up a big sign saying public library, then you can't go to the police and say someone broke in when you made no attempt to hinder them, then 200 OK holds.
The server is giving the file away. Yes, I asked for it. But unless it's a very limited special case where I seriously went out of my way to trick the server (like a scam artist would in real life), then you can't put a little note under the doormat saying thief.
> Actually Telenor in Norway recently sold a few hundred tablets for 1,- kr a piece 16 cents US, and this without a contract. First they said, no, no, no, it was a mistake in our computer system, but they ended up having to sell them anyway because they would have such a hard time proving that every one of the customers knew well and right that there must be a mistake.
In this example the customers paid the listed price, did they not? It was for exactly this argument that I spelled out "price clearly listed" in my original argument.
I also chose a vending machine knowing full well that whatever someone says will be a personal choice. No legal system would waste its time on someone "stealing" $1.25 from a vending machine that gave you the soda.
It's a moral question, not a legal one. If someone accidentally sets themselves up to be taken advantage of, would you take advantage of them if no one is watching? All of these hacktivists like to talk about how evil and immoral the government, the business, etc. are. So I ask what would they do in a situation with nothing on the line but their integrity.
If they would take the soda then who are they to ride in on their high horse?
If they would not take the soda, then why is it still OK to tromp through a website knowing that you're not supposed to be there, just because the sysadmin is an idiot?
I'm not even saying there's one and only one right answer, but if there's one thing I hate it's hypocrisy, and I think this is true of most people. I don't think that people mean to be hypocritical either. But if we don't critically examine why we think something is right or wrong then do we really have a sense of morality or are we simply doing what we feel is right?
This is an interesting analogy. Let's see where it goes. So we've got this vending machine. Suppose the door is broken; it won't close. As a result, if you insert money, the machine credits you with having paid but the money falls out onto the floor instead of being held securely inside the machine.
So, can we justify having a law against "unauthorized access to a vending machine"? Let's see what we get based on what someone does.
Scenario A: Defendant takes a soda without paying for it. Defendant is going to argue that this isn't unauthorized access; maybe the prosecutor can argue that it is, but that doesn't even matter. What you're doing is stealing. That's what you should be prosecuted for. There is no call for a law against "unauthorized access" in order to prosecute in this case, what is needed is a law against taking what isn't yours. This scenario occurs in any case for which "unauthorized access" occurs in furtherance of anything which is actually wrong -- the wrong thing should already be illegal and have appropriate penalties for that conduct so there is no benefit in such cases of a separate prohibition on unauthorized access.
Scenario B: You want a soda but the machine won't take your money because the door won't close. So you open up the machine, put a $5 bill in the cash store and take your change and your soda. Here you aren't stealing anything; you've paid the asking price. Great, we've discovered a scenario where the prohibition on unauthorized access actually does something instead of being totally redundant -- you're not authorized to open up the vending machine, so even though you didn't steal anything or do anything to harm anyone, you still accessed it without authorization. So is this the scenario where we want to impose criminal liability? I don't think so. A law prohibiting that conduct is rubbish. You want laws to prohibit doing bad things, not to prohibit doing good things that are unanticipated.
But you don't know you're not supposed to be there, you must have at least visited their site first, clicked their terms of service, before you can find out.
Terms of service are typically very long documents and are time consuming to read. Do you read terms of service of every site you go to, to make sure you are permitted to be on that site?
If in real life that was the typical behavior of a vending machine, I doubt I would notice.
There probably needs to be a way to address the situation where someone knows the data they are accessing ought to be restricted, but your analogy throws away an awful lot of the context that is important to that discussion.
> There probably needs to be a way to address the situation where someone knows the data they are accessing ought to be restricted, but your analogy throws away an awful lot of the context that is important to that discussion.
Perhaps, but IMO it's really the core moral question.
But you are right that context is important, which is why these debates go so often into what "reasonable" persons would do.
So with weev, for instance, I think a "reasonable" person could probably say that they're not really supposed to have access to so much personal data, and that they probably shouldn't have gone way the hell out of their way to get 114,000 email addresses when 4 orders of magnitude less would have sufficed to prove the vulnerability.
Now, do I think that email addresses of any kind warrant 41 months in prison? Absolutely not! But I also don't see how it's a stretch to consider that weev stepped beyond the bounds of reasonable behavior.
Whole societies often end up with unpleasant moral opinions though (I don't mean to suggest that this sets aside the value of acting morally, I mean to suggest that moral intuition is not necessarily a good guide for setting the rules for a society).
A good trick would be massive civil penalties for disclosing personal data to third parties. That leaves us uncomfortable with weev scraping large amounts of data but able to punish him for any damage he causes by sharing it, and it makes some potential for innocent little AT&T to share the stick.
Edit: better to say that it leaves us able to punish weev for causing damage. There is easily potential for causing more damage than could be restored by a single person.
Ignoring the moral issue and treating it as a legal issue - why not?
If they wanted to give me a $100 bill, it is fully within their rights to do so. If I really entered $50, then I certainly did not authorize my bank to debit my account for $100.
They might have some legal grounds depending on the local legislation to request the $50 back due to their fault/mistake, but I can dispute that and the result is far from certain.
If we're debating what the 'taker' should do, then the moral issue applies.
But if we're debating if the 'taker' should be punished (as in the original post), then the legal question applies. It may be wrong to abuse the opportunity, depending on the circumstances, but it would be far more wrong to put the person in jail for doing something the vendor implicitly seemed to allow.
Under UK law, if you receive money in error, you have to have a good faith belief that the money is actually yours. To claim that you thought that the bank was deliberately choosing to give you more money than you asked for (rather than it simply being an error) stretches credulity a little too much.
If you can't use HTTP status codes properly, then you simply aren't in a position to subjectively characterize someone's request as impermissible/unauthorized. This is especially the case when the server's choice to grant access conflicts with your intentions.