Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If SQL injections are illegal (if you use them to gain access to things you're not meant to access), how malicious User-Agent spoofing could be legal?


>if you use them to gain access to things you're not meant to access

Isn't this the only thing that matters? The actual technique you use to gain unauthorized access to a machine shouldn't matter legally.


Yes. This would also explain the other comments in this thread complaining about the ruling stating that bypassing a paywall would change their decision; the courts will not allow the legal question of whether access is authorized or not to be decided solely on what a hacker can convince a stupid computer server to do.

And, that's a good thing! I had the chance the other day to be in a legal training session, where the following quote from the Vice Chief of Naval Operations was mentioned:

"No set of rules can substitute for the exercise of sound judgment. Even when something is permissible under the rules, it may nevertheless be inappropriate in appearance." (emphasis mine)

This is also the same reason many hacktivists oppose the NSA's current surveillance programs, whether they're legal or not. Just because it is legal or technically possible for the NSA to do something doesn't mean they should be able to do it. But what's good for the goose is good for the gander, and such logic applies just as much to us as it does to them.


I like that quote. From my perspective, I've mostly seen people complaining about applications of the CFAA that lacked good judgement, in favor of a broadly applied, poorly-written set of rules.


Yes, there's definitely a tension between narrowly applying rules and leaving them too broad. IMHO the recent CFAA cases have correctly met the spirit of the law (save perhaps for Manning), the problem is that (especially in Aaron's case) the sentence is disproportionate.


This is what I meant.


There are many uses to spoof a user-agent that are not malicious though while SQLi is always intrusive (and thus in a way, malicious). Think about privacy or broken website compatibility sniffing etc.


Yes, and those are perfectly legal.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: