Federal Judge Says It's OK To Port Scan Networks
Alex Bischoff writes: "As noted in this Politech posting, a federal district judge says it's OK to do port scans on networks. 'The court concluded that an
imperceptible slowdown in performance was not damaged under
the Georgia law.'" Note that this is a very specific situation; only one data point out of many that will be required to figure out how various laws apply to the Internet.
Checking to see if doors and windows are locked normally requires an attempt to open them. That is often used as an analogy for portscans, but I really don't like it- Trying to open windows and doors is an attempt to gain access, but portscanning is purely informational.
A portscan is more like looking at a building, seeing where the doors and windows are, and maybe reading the make and model from the doors, windows, and locks. The "trying windows and doors to see if they're unlocked" analogy would be better applied to running actual exploits against a machine.
The police could arrest you for attempted murder. The legal standards for what is considered an attempt vary by location, but the police do not have to wait for you to pull the trigger before they can take action.
Mea navis aericumbens anguillis abundat
and the police would propably tell you that all they can do is charge him with trespass because he's on your property.. however, if he was say, checking the doors and windows on a bus station (a publicly owned bus station) the police couldn't do a damn thing.
How we know is more important than what we know.
entering a house even if the door is open is still breaking and entering, just as staggering down the road after you've been drinking is being drunk and disorderly, even if you're not disorderly.
How we know is more important than what we know.
no I think you totally missed my point, the infastructure of the Internet is more akin to a public bus station than private property. Even if you own said infastructure, by connecting it to the web you really are giving permision to come onto it. So maybe we need an even more elaborate analogy (because they just work so well) like maybe if you have put a sign up at your front gate which says "visitors welcome", thus allowing people onto your property but only allow people into your front living room (akin to your web server) but people start trying the doors to the bathroom and the bedroom. Even if they find one unlocked they're not trespassing until they actually go in there, and even then you're on shaky ground. But if they then start smashing stuff up or sleeping in your bed or using your shower, you've definitely got something to complain about.
How we know is more important than what we know.
No. Intent and event are balanced. Say I want to kill my high school gym coach. I go out to the local gun shop, and purchase a handgun to shoot them with. If only intent counted, I should be arrested the moment I forked over the money for the weapon on charges of 1st degree murder. I intend to kill him, I have the means to kill him. Do they? Nope.. Even if the cops are watching me like a hawk, 24/7/365, they can't do squat until I actually kill Mr. Stevenson..
I can port scan all day long, check for sendmail hacks all day long, but until I actually hit cr/lf after dd if=/dev/zero of=/dev/sda1 it ain't squat.
.sig: Now legally binding!
The statute requires damage. Either in the loss of data, or the loss of computing resource. Since a portscan takes minimal resources (generally speaking) there is no damage.
Given the way the the decision is written, it would not be a violation until after I hit the on the command line of rm -F -r
Fight Spammers!
Her in the cold north (Norway) it is allowed to port scan, i even heard a fellow say its allowd to try to hack a computer, its once you have done it its illegal.
'I sense much NT in you. NT leads to blue screen, blue screen leads to downtime, downtime leads to suffering.' -Uknown
Just seems that this would be an article best posted on the main page of Slashdot. This is of interest to everyone and deserved more than half dozen posts of discussion. It's certainly more widely interesting than Fandom Vs. Fandom or Read To Your Childre, Go To Jail.
---
seumas.com