TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Scan the Internet and Screenshot All the Things

45 pointsby ssclafanialmost 11 years ago

1 comment

tptacekalmost 11 years ago
Wow.<p>I read Tentler&#x27;s follow-up post on this, where he abruptly declares that what they&#x27;re doing isn&#x27;t unlawful. Presumably, he&#x27;s saying that because a competent lawyer told him that. If that&#x27;s not the case, he should retain one.<p>There are a number of problems with his logic:<p>* The fact that AV vendors have done things like this in the past (or even do them today) almost definitely won&#x27;t inoculate <i>this particular team</i> from civil or criminal actions which will cost them a fortune to defend.<p>* There is no provision in CFAA, or in any unauthorized access statute I&#x27;ve ever read, that has a safe-harbor provision for scanners that do &quot;opt-out&quot;. Providing a block-list is good, and neighborly, but it probably doesn&#x27;t protect them.<p>* &quot;But the server never asked for a password&quot; is not going to be an effective defense. It&#x27;s actually even less compelling in this case than it was in the Aurenheimer case, because a web server normally exists to publish documents to the world, but virtually all VNC servers do not.<p>* Most importantly: what they&#x27;re doing is so non-minimal. They appear to really be pushing the boundaries of what it means to do an Internet survey. If they wanted to map open VNC servers, they could do that without <i>screenshotting people&#x27;s open servers</i>.<p>This team starts that scanner process knowing that they&#x27;re going to reap hundreds of screenshots that the owners of those systems don&#x27;t want them to have. If you can describe your project reasonably in a sentence that includes the words &quot;knowing&quot; and &quot;unauthorized&quot;, get a lawyer to sign off on it first.<p>Hopefully, they already did, and I&#x27;m just being noisy!
评论 #8196902 未加载
评论 #8195627 未加载