Whether it’s negligent isn’t terribly relevant. Is it illegal? It is not, they aren’t bypassing access controls. No different than using Shodan, scanning public IPs, crawling open directories, etc.
It would be different if they were attempting to brute force credentials to access an endpoint, but they aren’t.
Comments
My concern is more in relation to trying to use an endpoint from non-public source code, it seems negligent to randomly try endpoints like this
Whether it’s negligent isn’t terribly relevant. Is it illegal? It is not, they aren’t bypassing access controls. No different than using Shodan, scanning public IPs, crawling open directories, etc.
It would be different if they were attempting to brute force credentials to access an endpoint, but they aren’t.
Weev went to jail for accessing public api's, https://en.wikipedia.org/wiki/Weev#AT&T_data_breach
It was argued that he didn't circumvent, but it didn't stop them from putting him in jail initially.
His conviction was vacated and Amazon has deep pockets and diffusion of internal liability. The illicit state drug charges did not help his case.