Hacker Newsnew | past | comments | ask | show | jobs | submit | arcfour's commentslogin

There are numerous services that will let you host static pages for free or nearly free. There are also numerous services that sit in front of your website that can block bots and reduce load on your origin server, many of which are also free, or very low cost relative to the service they provide.

The situation you are in is far less dire sounding when you consider that you have these options available to you.


Except that I don't have these options per employer policies.

So your employer is having a problem, and prevents you from using any of the available options to solve it? And you have asked them about all of them/told them about the problem? They don't like saving money?

Well, sounds like it's not your problem then.


Because you don't apply to a gun company to buy a gun. (You actually apply to the government...chew on that one for a while.)

Didn't need to chew, I already know the government doesn't do enough to curb gun violence.

Well, in my state, you don't "apply" for a gun like you apply for a license. It is just document that you purchased it after the seller runs a background check.

The government isn't attesting to your capabilities - that is still on you as a citizen.


> you don't "apply" for a gun like you apply for a license.

>... background check

Who requires these background checks? Because the seller wouldn't do them unless obligated. Obviously the check and paperwork around it constitutes at least a de facto application to the government for permission to purchase the firearm.


But that's an outlier. In normal countries you apply for a license, THEN after you get it, you're allowed to purchase a firearm.

Most of them are also easily pissed away if you have money. It cuts both ways.

Among other things, JavaScript in the browser has no way to even express "kill PID 1234 on the user's machine" or "list the contents of `C:\Users\Documents` and upload all of the files" or "spawn cmd.exe on the user's machine". How would you even do these things if you could run any JavaScript in the browser? You can't.

However, chrome.exe itself does because it's a native application, as is the sandboxed JavaScript interpreter inside of chrome.exe.

(This is a very oversimplified explanation but I think this is the disconnect people are having)


> JavaScript in the browser has no way to even express ... "list the contents of `C:\Users\Documents` and upload all of the files"

this is besides the point, but javascript has the file system api.

anyways to your broad point, i dont think this is convincing. What's the difference between not having an api vs having an api that is disabled (e.g. the syscall exists but is filtered). Either way you are not taking the action. RCE in the sandbox is an important step in the bigger exploit chain, but not because you can express things in the traditional syscalls inside the sandbox.


Okay, but we're still talking about running machine code inside the sandbox, where that functionality is still not available.

The functionality is restricted, but the capability of expressing the intent at all exists.

This really grinds my gears, way more than it should for some reason.

Use the system as it was intended, people!


Far from the most frustrating thing they did, trust me. I could tell you stories for days and never run out of more frustrating anecdotes.

Sometimes you don’t want everything hanging off the main domain, because if DNS gets horked everything goes down.

Very few are these days with the enormous amount of resources Valve has been pouring into Proton. The only truly Windows-only games I have encountered were online multiplayer with anticheat and that was almost always because the developer chose not to support Linux (e.g. EAC, Rust) and not for lack of support for Linux.

Perhaps that wouldn't happen if more people switched...


those are the vast majority of games that people play

and people won't switch if there is no way to switch, it's like asking people to go on a hunger strike


Speak for yourself, there are hundreds of thousands of people playing games that do not fall into this category on Steam right now.

Man, I could use $699. If this gets even a single sale, then maybe I need to try having less decency...

(I guess that is sort of a roundabout summary...)


Would you say that this is immoral? Since it’s data that’s public anyways, I don’t see why putting it in a table and selling it is a bad thing.

Because a lot of things is public online and can't be copied and sold e.g. due to copyright, patents and trademark. Also if you access a website you are bound to a ToS contract and this is a breach of that contract.

Breaching a contract isn’t a crime though, it’s a civil matter.

You asked if it was immoral, not if it was a crime.

What is "public" data? It admits to violating the ToS.

Something posted with the understanding that it could potentially be viewed by anyone on the Internet with minimal/no restriction.

ToS are just what you follow if you don't want to get banned off of the site. If you don't care about that, then you can go hog wild, though you're being a bit of a jerk/not playing nice obviously.


Any company could potentially be hacked, so by that standard all data is public. And no, the ToS is legally binding on the company as well.

You don’t see a difference between accessing data by hacking a service (which is illegal) and downloading/scraping data that’s not protected? The TOS are a contract and only a civil thing afaik.

That's a blatant strawman - that's not a reasonable position at all. A reasonable person does not expect their private medical records to be accessible to you or me just because they are stored in an EHR system.

They might be surprised that you or I looked at their TikTok video when we aren't the intended audience, but they still posted it publicly, with the understanding that it would be made freely available to others.


It's definitely not a strawman. Perhaps you meant that it's a false equivalency, but I don't think that's true either.

With how common data hacks are, why wouldn't a reasonable person expect their medical records to leak? I received at least two such breach notices just last year.


Obviously I meant that any data a person expects to be public, like a public post on a social media site... I was not referring to data exposed in data breaches, which is a different subject entirely...

If that was not obvious to you then I apologize; though it really should have been, since you are encouraged to interact with others in good faith on HN.

And if you expect your medical records to be public...then what is the point of this discussion?


The user only gave TikTok permission to use the videos according to the ToS. And considering the majority of TikTok users are children, I think it's hard to justify morally, even if you could make a legal case.

A "data breach" refers to unauthorized access to nonpublic or protected data. Scraping content that is publicly viewable without logging in - or even with logging in, since an account is effectively disposable - is not a "data breach" (as far as any typical usage of the term goes).

In hiQ Labs v. LinkedIn, the 9th Circuit (US) ruled that scraping publicly accessible data does not violate the CFAA's "without authorization" clause (hiQ was bulk scraping public LinkedIn profile data - in violation of LinkedIn's ToS). The Supreme Court later specifically narrowed the CFAA in Van Buren v. United States saying "exceeds authorized access" applies to accessing areas of a system you aren't entitled to enter at all, not misusing access you legitimately have (regardless of ToS violations).

Other CFAA cases have ruled similarly - being legitimately granted access (i.e. signing up for an account, or browsing publicly without logging in, since the site is intended to be available to the public) and then misusing it is not "hacking".

So in the U.S., it's not a computer crime ("hacking"/"breach") to scrape data, and nobody uses the term "data breach" to refer to scraping publicly available data on a public site, except for apparently you.


You still haven't checked the ToS:

"use automated scripts to collect information from or otherwise interact with the Services" — this covers the entire scraping operation.

"make unauthorised copies, modify, adapt, translate, reverse engineer, disassemble, decompile or create any derivative works of the Services... or determine or attempt to determine any source code" — e.g. reverse-engineering the X-Argus/X-Gorgon/X-Ladon signing scheme.

"interfere with or attempt to interfere with the proper working of the Services... or bypass any measures we may use to prevent or restrict access to the Services" — TLS-fingerprint spoofing, the empty-200 soft block, and the proxy IP rotation to get around rate limiting.

"use or attempt to use another's account, service or system without authorisation from TikTok, or create a false identity on the Services" — this covers the forged device registrations (fake Android handset + carrier profiles)

"use the Services, without our express written consent, for any commercial or unauthorized purpose" — the website is monetizing the dataset and selling the code itself.


Still not a hack or a breach. Still "public" data. Still a TOS violation. Your up-thread claim that potential hack is the same as public is still incorrect.

And who cares about ToS? That’s a purely civil thing, surely hacking (which is a crime) is worse than breaching a contract?

Is it a data breach if I right click images in google search and save them to my disk?

A data breach could leak into search engine results, sure.

I wasn’t asking if a data breach could be in the search results, I asked if saving search engine results in itself would be a data breach. Apparently you think that scraping publicly accessible data from tik tok is a data breach in itself, so does this apply in other cases too?

I could get the same data in principle by downloading the app and accessing the post. There’s no hacking or circumventing access controls. That’s what I meant by public data.

No, I don't care at all, but I recognize that my morals might be lower than others here. To me it's just public data...whatever.

My criticism was basically - this is trying to sell an AI slop project for $699 a pop - I could get this out of a few Claude Code sessions if I had the storage and network bandwidth to run such a scraper. The value proposition is questionable when the writing shows that the entire project was AI generated, and clearly Claude understands the way the TikTok Android app internal API works quite well...


The AI giants got where they are by pushing similar limits and setting aside moral (and legal) issues to be settled later in court, so the idea seems to fit the general zeitgeist we're living in. Not really criticism, just an observation.

Yeah, I make song remixes in the style of a particular video game and while the music is completely human written (by me), I'll often have AI generated or edit the "cover art" for me so people have something to look at/chuckle at.

These videos are still marked as AI, and fairly so; however I don't think that means people should want them hidden :-(


With music it’s especially bad because people will assume the music itself is AI generated, when in your case it isn’t.

Yes, I'm thinking I'll stop doing it from now on since YouTube doesn't make the distinction.

I figured that LLMs saving me the 20 mins in GIMP making a silly joke filler album cover was the perfect use case... ¯\_(ツ)_/¯


> however I don't think that means people should want them hidden :-(

Sorry but no, even if the music is great I don't want to hear it if the cover was AI generated, at this point I'd happily accept even a crudely drawn cover because it is human :)


What's the difference between me pasting a face over a body in GIMP manually and me prompting an LLM to make the same edit, faster, and better than I would by hand? They aren't particularly high-effort. The artwork isn't really the point, but I can't just upload a black video...

AI-generated anything sends a message of 'I do not care about quality'. You might feel that that's unfair, but it's the impression you're making on a large segment of your potential audience.

So if I uploaded a black screen, or a black screen with text (the title of the song), that would be sending a message...that I do care about quality...? Since there was no AI?

As opposed to thinking of a play on words between the game/the original song and having an AI make the joke cover per my directions, instead of me just doing it (worse) by hand, which is "I don't care about quality?"

The whole point of the video is not the visual component, it's really just about sharing the non-AI music.


Pretty much, yes. People read no visuals or poor visuals as 'hobbyist who really cares about [other aspect]'; years of experience make it a familiar schema.

They read AI as 'grifter who probably doesn't care about any aspect'.


No it doesn't. This reads like someone who hasn't touched a non-apple Laptop in 15-20 years.

I don't think it's possible to create a Linux machine with no volunteer-built software on it.

> IMHO, capitalism and FOSS are fundamentally incompatible.

A bold statement to make given the world we live in today contains plenty of both, working together, in harmony.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: