Slashdot Mirror


Violating a Website's Terms of Service Is Not a Crime, Federal Court Rules (eff.org)

An anonymous reader quotes a report from the Electronic Frontier Foundation: Good news out of the Ninth Circuit: the federal court of appeals heeded EFF's advice and rejected an attempt by Oracle to hold a company criminally liable for accessing Oracle's website in a manner it didn't like. The court ruled back in 2012 that merely violating a website's terms of use is not a crime under the federal computer crime statute, the Computer Fraud and Abuse Act. But some companies, like Oracle, turned to state computer crime statutes -- in this case, California and Nevada -- to enforce their computer use preferences. This decision shores up the good precedent from 2012 and makes clear -- if it wasn't clear already -- that violating a corporate computer use policy is not a crime.

31 of 82 comments (clear)

  1. UA by bugs2squash · · Score: 3, Interesting

    I think I might put "I do not accept the terms of your user agreement" somewhere in the User Agent String of my browser, see what happens.

    --
    Nullius in verba
    1. Re:UA by Anonymous Coward · · Score: 3, Informative

      I think I might put "I do not accept the terms of your user agreement" somewhere in the User Agent String of my browser, see what happens.

      Nothing would happen.

      See violating a website's terms of service is not a crime, it is a terms of service violation. And under most website's terms of service, violations can be sufficient cause to remove your access to their service. Same as it always was.

      No one cares if you try to be cute on the Internet. But do something they don't like on their service will get your access removed.

      You just can not be charged with a crime under the Computer Fraud and Abuse Act for a terms of service violation.

    2. Re:UA by Anonymous Coward · · Score: 5, Insightful

      But you can still be dragged into court even if the court will eventually side with you.

    3. Re:UA by Anonymous Coward · · Score: 1

      I believe the logic goes this way:
      Computer Fraud and Abuse Act prohibits accessing a computer without authorisation.
      If a user accesses a computer service without agreeing to the user agreement, they have unauthorised access.
      Therefore, accessing a computer service (like a website) without agreeing to usage terms is in violation of the Act. I'm sure I remember this being used in regards to facebook and bullying somewhere around 2012.

      The interesting thing about this ruling is it is questioning what is allowed by the service agreement. This particular case appears to be that if the customer already has authorisation to view information, using a piece of software to automate the collection of the same information does not alter the authorisation, despite the use of such software being prohibited by the agreement. I find this interesting because it puts the onus back on the service provider to enforce their own limits, rather than using the law.

    4. Re: UA by Anonymous Coward · · Score: 3, Funny

      "By having your web server serve me the contents of your website, you are agreeing to my terms of service:
      1. You agree to consider your terms of service null and void
      2.-... (be creative)

      If you do not agree to my terms, then end the connection immediately and do not continue serving any content.

      For the avoidance of doubt: you are indicating agreement by maintaining the connection and continuing to serve content"

    5. Re:UA by Bert64 · · Score: 4, Interesting

      But where do you see the terms of the agreement before you've accessed the webserver?

      Also if they have publicly advertised the website anywhere, could that not be taken as authorisation?

      --
      http://spamdecoy.net - free throwaway anonymous email - avoid spam!
    6. Re:UA by mjwx · · Score: 4, Informative

      But you can still be dragged into court even if the court will eventually side with you.

      In the UK, the court will barely entertain this kind of bollocks. The company who sued you will then have to pay your legal fees, that cuts down on this kind of thing a lot.

      A EULA/T&C's/Shrinkwrap license has been ruled completely unenforceable before, even in the US however because the losing party still has to pay their own legal fees, its often profitable to threaten to sue or to go as far as to sue even though you'd lose.

      Its the same kind of "speculative invoicing" extortion racket the RIAA and MPIAA used to run.

      --
      Calling someone a "hater" only means you can not rationally rebut their argument.
    7. Re: UA by viperidaenz · · Score: 1

      2 - you grant an irrevocable, transferable license to all copyrighted material available on this website.
      3 - you grant an irrevocable, transferable license to any patents protecting any product, software or service available from this website.

  2. Headline is misleading by Anonymous Coward · · Score: 5, Informative

    First, this is a civil case rather than a criminal one. Laws like the CFAA and the equivalent state laws allow for criminal and civil action. More importantly, the ruling is a narrow one, focused on the specific aspects of this case. The court ruled that Oracle made the data available for downloading from their website. Oracle's objection was the use of automated tools to download the data. The court agreed that Remini violated the terms of service in how they downloaded the data. However, because Remini was authorized to access and download the data, the court ruled that it did not violated the law. It is entirely possible that someone violations of the terms of service might also violate the law. The ruling is logical, but the scope is also narrower than is indicated by the summary.

    1. Re:Headline is misleading by Solandri · · Score: 5, Informative

      We went through this with Rambus. They joined JEDEC (a consortium of memory manufacturers setting future memory standards) and agreed to its terms of membership - mainly, members are not allowed to patent the memory standards being discussed. DDR was being discussed within JEDEC. Rambus went ahead and patented it, and sued the other JEDEC members for violating "their" patents.

      After years of legal battles, the courts found that yes Rambus was guilty of violating JEDEC's membership agreement, and they were subject to whatever punishment they agreed to when they joined JEDEC. But that had nothing to do with the law, so the patents were valid (Rambus being the first to file). Meanwhile, since the JEDEC membership agreement didn't outline any punishment for violating the agreement, the only thing JEDEC could do was kick Rambus out.

      Same thing here. An EULA or ToS is just a contract. If you violate it, you become subject to whatever punishment you agreed to when agreed to the contract. That does not automatically make it a violation of law however. It's only a violation of the law if the act was otherwise illegal. In Rambus' case, patenting stuff freely presented to you is not illegal. In Remini's case, downloading stuff you've been authorized to download is not illegal.

    2. Re:Headline is misleading by Hal_Porter · · Score: 2

      https://en.wikipedia.org/wiki/...

      In the early 1990s, Rambus was invited to join the JEDEC. Rambus had been trying to interest memory manufacturers in licensing their proprietary memory interface, and numerous companies had signed non-disclosure agreements to view Rambus' technical data. During the later Infineon v. Rambus trial, Infineon memos from a meeting with representatives of other manufacturers surfaced, including the line "[O]ne day all computers will be built this way, but hopefully without the royalties going to Rambus", and continuing with a strategy discussion for reducing or eliminating royalties to be paid to Rambus. As Rambus continued its participation in JEDEC, it became apparent that they were not prepared to agree to JEDEC's patent policy requiring owners of patents included in a standard to agree to license that technology under terms that are "reasonable and non-discriminatory",[8] and Rambus withdrew from the organization in 1995. Memos from Rambus at that time showed they were tailoring new patent applications to cover features of SDRAM being discussed, which were public knowledge (JEDEC meetings are not secret) and perfectly legal for patent owners who have patented underlying innovations, but were seen as evidence of bad faith by the jury in the first Infineon v. Rambus trial. The Court of Appeals for the Federal Circuit (CAFC) rejected this theory of bad faith in its decision overturning the fraud conviction Infineon achieved in the first trial (see below).

      Rambus deserved to go bust, the rat bastards.

      --
      echo -e 'global _start\n _start:\n mov eax, 2\n int 80h\n jmp _start' > a.asm; nasm a.asm -f elf; ld a.o -o a;
    3. Re:Headline is misleading by mjwx · · Score: 2

      We went through this with Rambus. They joined JEDEC (a consortium of memory manufacturers setting future memory standards) and agreed to its terms of membership - mainly, members are not allowed to patent the memory standards being discussed. DDR was being discussed within JEDEC. Rambus went ahead and patented it, and sued the other JEDEC members for violating "their" patents.

      After years of legal battles, the courts found that yes Rambus was guilty of violating JEDEC's membership agreement, and they were subject to whatever punishment they agreed to when they joined JEDEC. But that had nothing to do with the law, so the patents were valid (Rambus being the first to file). Meanwhile, since the JEDEC membership agreement didn't outline any punishment for violating the agreement, the only thing JEDEC could do was kick Rambus out.

      Same thing here. An EULA or ToS is just a contract. If you violate it, you become subject to whatever punishment you agreed to when agreed to the contract. That does not automatically make it a violation of law however. It's only a violation of the law if the act was otherwise illegal. In Rambus' case, patenting stuff freely presented to you is not illegal. In Remini's case, downloading stuff you've been authorized to download is not illegal.

      In other words, you dont know what a contract is. Rambus signed an agreement with JEDEC when they joined. The agreement was set out in full and agreed upon by all parties, Rambus had a chance to reveiw and negotiate that contract before signing and this included any penalty clauses. Beyond this, once signed the contract cannot be altered without all parties agreeing to it

      A EULA or ToS are not considered contracts because you cannot negotiate them beforehand, they are not signed (I.E. identity verified, someone can accept a EULA, ToS or shrinkwrap contract without your express consent on your behalf) and they can be altered by one party after the fact without your knowledge, agreement or permission. This is why courts have ruled them non-binding, especially when it comes to penalty clauses.

      I have an agreement with Vodafone that has terms and conditions, I pay them £10 and they give me phone service. They can update their ToS but will never be able to enforce it in law simply because I've never signed it.

      I have a contract with BMW Financial services. I pay them for the car I use, if I, in any way violate the contract (I.E. fail to insure the vehicle) then I can be penalised because I had a negotiated contract I signed in full accordance with the Financial Services Guidelines (I.E. the contract was explained to me in full before signing, cooling off periods and what not). This is enforceable in law.

      Vodafone would even have trouble terminating my service without me violating a law as they had agreed to provide a service. ToS's, EULA's and shrinkwrap contracts are not there to bind the customer to an agreement like a contract, they are there to cover the providers arse in case the customer does something wrong with their product. It's what protects gun manufacturers from being sued when some nutter goes on a rampage.

      --
      Calling someone a "hater" only means you can not rationally rebut their argument.
  3. Re: Then I want my cdreimer account back by Anonymous Coward · · Score: 1

    While claiming that an username violates the DMCA is an absurd claim, that's not relevant to this ruling. Websites are free to terminate your access for violating the terms of service. The court ruled that it's not against the law to use an automated download tool to access data when the terms of service prohibited automated downloading tools. It still violates the terms of service and Oracle was allowed to terminate access to their site. The court rejected that Oracle could claim damages under state laws for using an automated downloading tool in violation of the terms. Unless anyone has sued you to claim damages under state computer abuse laws for your Slashdot accounts, this is irrelevant.

  4. Kids, just “Say No” to Oracle by BLToday · · Score: 4, Insightful

    Once you’ve used Oracle they got you. If you try to leave, you can’t. If you stay, they’ll screw you more and more everyday. Best thing is not never start using Oracle.

    1. Re:Kids, just “Say No” to Oracle by grep+-v+'.*'+* · · Score: 1

      Once you've used Oracle they got you. If you try to leave, you can't. ...

      Sounds like they're selling drugs. "The first one's free -- here, try it!" OTOH how ELSE do you expect Larry to afford that island?

      https://youtu.be/Sm3b4_XLCOU?t...

      --
      If the universe is someone's simulation -- does that mean the stars are just stuck pixels?
  5. Re:Oracle is such a piece of shit... by gl4ss · · Score: 5, Interesting

    normal big company(tm)(c) 3rd world story:

    make huge dev centers in India and China.
    then fire a bunch of developers in country of origin of said company, because they don't have good projects to work on(they didn't before either).

    product gets developed in reality by remaining developers in country of origin. the developers in the 3rd world dev centers drink tea and work on some fluff projects. sometime later the 3rd world center gets shuttered for saving money, possibly as the company folds.

    nokia did just this for example, ibm did this.

    with in case of nokia, the thing is, that they had already way too many developers in the country of origin that they had jack all shit to work on that mattered to the company - making the extra dev centers was purely political and useless(nokia had thousands of people working on symbian, but only 5% of them did anything that went to the products and half of those were subcontractors).

    development work does not scale above a certain limit prettily. but big companies can't scale back either so they try to scale up and scaling up in 3rd world countries is cheaper even if it doesn't provide results. note that the problem itself isn't really using 3rd world developers either, it's that you can't just make a product better by hiring thousands of developers - it just makes making the product better vastly more complicated political affair, even when talking about changing few lines of code to add some functionality the executives actually want in.

    --
    world was created 5 seconds before this post as it is.
  6. Re:Oracle is such a piece of shit... by BLToday · · Score: 2

    You probably can do a good product with third world developers if you seek the really skillful ones, but i don't think that companies going to the third world do have skill as any sort of priority.

    While that’s true in theory, I’ve only seen it happen if you keep a really keen eye on those developers. Implement more QA/QC than you normally. The problems with good 3rd world developers there are not a lot of them, they’re not that cheap and they don’t generally want to rewrite or debug their code.

  7. Computer Fraud and Abuse Act is a crime by Anonymous Coward · · Score: 2, Informative

    No, Computer Fraud and Abuse Act is a criminal act, and rejecting the notion that violating a website EULA is a violation of the Computer Fraud and Abuse Act is to say it's not a crime.

    So headline is spot on: "Violating a Website's Terms of Service Is Not a Crime, Federal Court Rules"

    " It is entirely possible that someone violations of the terms of service might also violate the law."

    If they violated the law, violating the EULA or not is irrelevant. It comes down to "do you have the right to access the website" yes/no. Not "are you accessing it within the terms of the EULA".
    So yeh, hacking into a private website might be a crime, and it might also violate or not the EULA, but the EULA doesn't define the crime, the law does.

  8. The philosophy of the contract... by Anonymous Coward · · Score: 1

    Contracts are weird things.

    Agreements very often made with intentionally confusing terms, which are simultaneously:

    1) Virtually always signed without actually reading in their full meaning, but rather verbally summarized by a biased beneficiary of the contract - and usually not even that. Indeed, the very idea of reading a contract is almost a faux pas, and is only tolerated with a raised eyebrow.

    2) Somehow also considered an almost sacred agreement that must be upheld at great cost - often more important than most forms of important morality or personal needs. Breaking a contract is a completely valid reason to shun a person, or do things to them that would be considered ruining their life.

    Indeed - much of the law is considered to be a loose substitute for contract logic, rather than the other way around.

    To me, as a programmer, this entire set of logic is absurd. And I've worked extensively with lawyers, and other notable rule-keeping organizations - the way people allow contracts to act as if they were a genie's wish, when they are such sloppy, crude documents, masked behind vague catch-all phrases, in virtually all cases just gives me pause whenever I look into them.

    Contracts are a very poor way of reaching an agreement, though I can see how they're the best folks know how to use in general.

    The odd thing is how folks tend to be cynical about statistics and accounting - but then accept contracts as if they were a real assurance that someone is willing to truly work with them.

    It's also what bothers be about libertarian idealism - the thought of governance as a system replaced with a hyper-religious use of contracts. Like economics, contracts only mean what they say, as long as the system can't be stretched by a group to hold values that said group wants to force them to hold after the fact.

    The value of contracts flows, the same as currencies - the same as relationships.

  9. Re:Oracle is such a piece of shit... by Anonymous Coward · · Score: 1

    The problems with good 3rd world developers there are not a lot of them, they’re not that cheap and they don’t generally want to rewrite or debug their code.

    Quality costs now matter where you go. The cheap guys can always move on to another cheap contract if you hassle them too much and since you don't really know who they are and could be doing business under a different name one day to the next or even one contract to the next, complaining is useless. Dealing with Indian developers is a fitting punishment for PHBs who are cheap and stupid. They deserve each other, liars and cheaters both of them.

  10. Re:Oracle is such a piece of shit... by mad-seumas · · Score: 1

    they’re not that cheap and they don’t generally want to rewrite or debug their code.

    i.e. useless.

  11. Having read the case by guruevi · · Score: 5, Informative

    It seems two things are at play here: the fact that a EULA cannot limit the publicly or contractually available Information.

    The other thing reading further into the case is the fact that Oracle seems to argue that it's copyright does not permit any third parties to obtain any part of the closed source system and the courts agreed with that. The court also holds that any modifications to closed source software are illegal unless you hold an explicit license.

    So let's say you are a company and want maintenance work done on your Oracle system, the third party cannot download copies of eg software updates for you because the license does not include that third party.

    This should be a big warning for anyone using Windows and other closed source software, the software license does not extend to anyone else therefore even just downloading the patches could get you into copyright infringement.

    --
    Custom electronics and digital signage for your business: www.evcircuits.com
  12. Re: Oracle is such a piece of shit... by Anonymous Coward · · Score: 2, Informative

    Well Oracle and Cisco are basically pure evil.

    Even if Oracle was in the right, Website TOS should never be legally enforced beyond simple authentication. If a site makes no effort to prevent unauthorized access/data scrapes, then every thing on the site is considered public and free to access (not redistribute.)

  13. Re:Oracle is such a piece of shit... by Tablizer · · Score: 2

    Oracle used to advertise they could run on a large list of OS's. In practice, they either never bothered to tune many ports: got it running just good enough to not crash (too often), and/or were many versions behind on less-used OS's. They're master spinners.

  14. public site so... by arbiter1 · · Score: 1

    If its a Public available site as anyone can load up the site and see then it should be same as walking down side walk and looking in to a store window. If oracle wants they could ban and block the companies bot from accessing their site, they would be allowed to do that but it would be like a store saying you can walk on public side walk OUTSIDE their store least that is what Oracle is trying to make case on.

  15. Re:Oracle is such a piece of shit... by MadKeithV · · Score: 3, Informative

    That sounds like a variation on Brook's Law - adding more people to a late project makes it later.

  16. Aaron Swartz by QuadEddie · · Score: 1, Flamebait

    ...will be relived that they're starting to reign in that act. Somebody go back in time and call off the suicide - he would have only had to spend a few years, not what he was sentenced.

  17. Re:So can I scrape Facebook? by arbiter1 · · Score: 1

    If its public yea, as courts have ruled "you have no expectation of privacy in public" same thing.

  18. Re:Oracle is such a piece of shit... by Gojira+Shipi-Taro · · Score: 1

    Add to that "Lay x% of developers in country of origin off every quarter for "performance reasons" relative to the rest of their team, even if they're more productive than the rest of the company. Team spends time "competing" rather than producing.

    Watch executive bonuses soar, and actual GOOD developers run to the fucking hills.

    --
    "Oh my God. This is terrible. This is the end of my Presidency. I'm fucked."; ~ Donald J. Trump
  19. Oracle is just retarded by nehumanuscrede · · Score: 1

    I have no other way to describe it when a company thinks that any TOS or EULA it has written is law.

    There is a process true laws must go through before becoming valid. They might want to refamiliarize themselves with that concept.

    Hell, they can just go watch the episode of School House Rock for the simple version.

    Sings: I'm just a bill. . .

  20. Re:Happy Australia Day by jnork · · Score: 1

    I think I'm not planning to follow that link to find out what's there.

    Also have to wonder about "fellow yank" in a thread titled "Happy Australia Day." Does not lull suspicion.

    --
    Cleverly disguised as a responsible adult.