> My point is: companies stop making your product suck, and people won't have a reason to try and fix it for you.
That assumes the company's behavior is rooted in ineptitude rather than malice, which is too generous at this point.
> My point is: companies stop making your product suck, and people won't have a reason to try and fix it for you.
That assumes the company's behavior is rooted in ineptitude rather than malice, which is too generous at this point.
I'm not sure what Twitter's specific reasons are, but AFAIK the general trend of login-walling services over the past few years has happened due to a court decision saying that it's legal to scrape publicly available data ( https://en.wikipedia.org/wiki/HiQ_Labs_v._LinkedIn ). If they gate content behind a login wall and put a clause in the EULA forbidding scraping, this lets them use the CFAA to go after anybody who still scrapes the site.
Effectively it forces scrapers to become a party to the terms of service, which usually contains the "no programmatic access (other than via paid API)" or specifically prohibits automated scraping.
Breaking terms of service isn't a crime, at least, although the company is legally permitted to retaliate against it, such as by banning you.
cfaa has broad interpretations
AFAIK it's been interpreted that getting public data while being someone the data holder doesn't like is, unusually, one of the very few things that is not a CFAA violation. Bright Data vs X for example.
So long as the "getting" doesn't consist of circumventing something that is ostensibly a security mechanism, such as a URL that had never been presented to you by the server but is fairly easily guessed.
You mean vs Meta
How can an automated process be a party in the terms of services though?
> How can an automated process be a party in the terms of services though?
If it's auth-gated, it needs to be, well, authenticated.
The person who provides that, and the subsequent automated scraping, is the party, and would be the recipient of a civil suit.
> If it's auth-gated, it needs to be, well, authenticated.
AFAIK, there isn't an single auth scheme on earth that guarantee human intervention[1]. Anyone can set-up a robot creating new users on a whim using single-use email addresses and even phone numbers. In fact, we know that OpenAI's agent have been doing exactly that when attacking Rubygem. And all AI labs are likely doing it for scrapping social media as well.
Who are you gonna sue then?
[1] the closest thing is Altman iris scanning venture, but without a broad adoption it's remains functionally useless.
By setting that up, you take on the liability for it. The defendant is whoever set it up. No different from "if I roll a car down a hill and it hits something at the bottom, how can you hold the car liable?"
That's not how ToS work though. ToS are contracts. If you don't sign the contract nobody can sue you for violating it.
> No different from "if I roll a car down a hill and it hits something at the bottom, how can you hold the car liable?"
That's the difference between criminal and civil justice. You don't need to sign a law for it to bind you, but for contracts you do.
> If you don't sign the contract nobody can sue you for violating it.
But terms of service are contracts which you sign by agreeing.
Courts have looked somewhat favorably on "I didn't read that" defenses, but accepting the agreement is a legal contract between you and the service provider.
My point is that you don't have to accept anything.
Sure. But then you don't get credentials and can't scrape.
You keep saying that but unless company start doing KYC there's absolutely no link between auth and ToS.
The authentication mechanisms used by websites don't have a specific legal power, it's just a POST request among other GET requests sent during scraping. And we have jurisprudence saying scrapping is legal no matter what the ToS of the website says, because the scraping entity never signed up the contract.
The only protection against scrapping that auth is giving you isn't a legal one, it's a technical one (you can detect and ban the scraping user account).
*scraping
Even if you get the credentials via middle man?
> That's the difference between criminal and civil justice. You don't need to sign a law for it to bind you, but for contracts you do.
Patently false: https://en.wikipedia.org/wiki/Implied-in-fact_contract
The person who sets up that robot is the person responsible and effectively signing the contract by those actions.
> Who are you gonna sue then?
The person who set up the robot.
It seems that simple, I agree, but digging in we're winding up in a bit of a "responsible party" black hole, at least it seems from my non-legal engineer perspective. If I ask an AI to find me articles on some arbitrary things and it hacks the Gibson to do it; and I am not a computer expert, it will be a struggle a bit to honestly put the blame on me. It's always been that way I think.. in what reasonable world can a non-lawyer agree to 100+ pages of a ToS and actually understand it? No world. But that's the point I think. What if I modify every TOS in HTML before I submit it and then agree by checking the box under my "redlined" version of the contract? I think this stuff is going to become exponentially murkier as time goes on.
Completely agree that the world is full of absolute nonsense, but legally determining responsible parties appears to be relatively straightforward (but does involve a judge or jury)
Yes, agreed. Except "involve a judge or jury" is where the wildcard comes in. I believe there will be reasons to doubt culpability as we move further into the nonsense. Justified or not. My point is really just that we're in some weird territory, so I guess I'm going to make popcorn and watch. Some deeper legal questions lurk in this mess, and I don't think the obvious answers will always necessarily be right.
> The person who sets up that robot is the person responsible and effectively signing the contract by those actions.
If that was true, then all scraping of a website with a ToS would be illegal, yet it's established by jurisprudence that it's not. And “authentication” doesn't change the picture here in Amy way, because it's not actually authentication.
Good luck finding them or proving it, esp. if done via third party contractors in another jurisdiction
It's much easier when they release huge PR whitepapers about how many felonies they've committed recently, I think. Makes the civil suit much more straightforward in my opinion.
>I'm not sure what Twitter's specific reasons are
as I recall it was the large number of bot accounts not scraping but commenting.
Both can cause a product to suck.
A company can make their produce suck, on purpose (out of malice), because it fits their bottom line better (at least, in the short term) vs. a better UX.
OP may simply be asking companies to put their customers ahead of their (short-term) profit.
Reddit is another great example of this, where users have been looking for workarounds to their (increasingly more) hostile login wall since they started pressuring people to use their app years ago.
It's ineptitude. Of course it is. Otherwise it would be indefensible.
EDIT in which I clumsily express my weariness at hearing some of the smartest people in the world claim they “didn’t know” because they have arbitrated foolishness against liability
The decision to force you to sign in to view replies is clearly not by accident or ineptitude. It's probably not malice either - just a business decision.
A system that makes "business decisions" indistinguishable from malice is an interesting one.
If I have something you want and I could give it to you but instead charge you money, is that malice? If so, what system wouldn't make malice indistinguishable from business decisions? If not, what distinguishes that from a login wall in exchange for viewing content?
It's pretty much the standard to either soft-block or hard- block access into silos. Facebook, Reddit, YouTube, Instagram, Tiktok, etc ... all do it. Of course it's an openly anti-consumer practice, but it's one they get away with when they're big enough to flip the service burden to the client.
how is it anti-consumer? Claiming you should be able to freely access the content on some service feels like claiming you should be able to walk into any fast-food place and help yourself to their soda machine.
A business is free to choose that you must login to access their content and you are free to choose not to do business with them if you don't like it. I generally chose the latter
Your analogy does not work since they can still show ads to logged-out users, nobody is getting anything for free. Meta even creates shadow-profiles of users without accounts to track them across the internet.
It's all about getting people locked into walled gardens. I wish the EU DMA had taken a harder stance on this and required all social media to federate to some extent.
You’re absolutely right. I can just choose to not participate. If I’m lucky enough, enough people realize that they have the agency to not give into this, but if they don’t it doesn’t affect me at all.
Either way, I don’t care. The Internet has become so hostile to users that the only moral and rational choice is to not participate on platforms that have become so hostile that threatening legal action is the only way that they can protect their relevancy in facilitating social discourse.
So business decisions are absolved of morality?
No. “Malice” isn’t the only possible descriptor with moral weight. There’s many more ways this decision could be immoral without malice.
Do you consider a login-wall immoral?
My biggest pet peeve is when people on sites like HN assume software should be tailor made for their objectives and not the company's objectives.
Sometimes the objectives align, but not always. And yes, the world would be a better place if they were better aligned, but we don't live in that world.
I'm sure X's motivation is something along the lines of forcing logins creates more users, or the downside of scraping outweighs the benefits.
I don't really understand this comment. The simplest way to put pressure on companies to align with their user's objectives is to complain loudly. It's not that HN "assumes" anything, it's just that people call shitty things as they are, in the hope that if enough people agree, it'll create enough pressure for the company to change course.
Will it work? Probably not. But not even trying would be self-defeating.
I don't think it's effective though because you're not actually addressing the reality on the ground. To pursuade someone you need to start with their assumptions.
If your argument doesn't even seem aware of them, then they won't listen.
I guess you could say "who cares, X is evil anyway, might as well try" but it just seems ineffective and frankly a little naive.
On the other hand, it is fair to be upset when the objectives seemingly used to align and you had put significant work into creating content for the company as well as providing bootstrapping network effects only to have them change the software against your previously aligned objectives.
This is the same as being mad at sports fans for complaining about the owners. No one would be anywhere near twitter, especially since it got covered in Elon’s ketamine cologne, if not for the users. Thinking the corporation profiting from those users should be free to change the deal on a whim is not a good look.
One of the problems is that many companies motives are so incredibly misaligned with society at large.
Google, Facebook, X are all explicitly designed to be addictive and provide as little value as possible. Because they want to give everything away for free in a way that keeps you on the site to maximise scraping your data so they can screw you over more later.
They are not even aligned at the most basic level. Everyone needs to stop using it. Or at least circumvent their measures.