You are making a lot of unwarranted assumptions. For one thing: If you publicly deface a website you advertise the existence of an exploit which someone else might then use for evil purposes. But, more importantly: Who says that an edit to a user profile is always harmless? People have lost relationships, job leads, careers, and reputations over such "trivial" things. Remember the poor teacher whose Windows box got infected by a virus and spewed porn links all over the screen in front of the students? The woman who lost her job and narrowly missed being convicted as a sex offender by a crazy prosecutor?
These people are using the website with no warranty. It says so in the Terms of Service. Myspace, Twitter, Facebook, etc, guarantee nothing about the security of their website, and whether or not their technology even works correctly. Even if they did say in their warranty: "Your information is guaranteed to be secure," does that magically make it illegal to make a worm?
Two: "What defines the line between legal and not?" The answer, ultimately, is judges and juries. These people have a wide range of discretion and are often surprisingly reasonable. (Although certainly not always. And they cost a lot to convince, and they can be randomly unreasonable, which is why there are a lot of jury-trial horror stories and why lawyers prefer to avoid jury trials whenever possible.)
If I leave a loaded gun lying around and you pick it up and shoot me dead, the legality of your action is going to depend crucially on what you can make the prosecutor and the jury believe. If you convince them that you did it by accident -- that you were honestly just playing around with the gun on the assumption that nobody would be dumb enough to leave a loaded gun around -- you might be found innocent. If you had a documented motive for killing me, or were arguing with me at the time in front of witnesses, or if there were no witnesses... well, good luck.
Good points. Especially the loaded gun thing.
But in the Myspace example -- what harm was done to Myspace that warranted any punishment? Is it because they're such a successful website, that it matters more? I mean, let's say the kid made this worm for a site with like 1,000 users... is it any less of a crime? And why is it not Myspace's fault for not securing the website?
Another thing I'm confused about... how responsible do the website owners have to be? Let's say they allow javascript in profiles. The worm was nothing more than javascript.. I'd argue that somebody was just getting creative with their profile! If they made an endless loop of alerts, is that a "virus" because in most browsers (ridiculously) you have to force quit them?
And, finally, how in the world does any of this technology stuff get explained to the people making the decisions, eg, the judge and jury. It seems it's nearly impossible for it to be adequately explained to them to the point of them understanding enough to make a fair judgment.
These people are using the website with no warranty
I think you will find that a jury will have no trouble telling the difference in value between something that has no warranty, something that has no warranty and is broken thanks to an error by its vendor, and something that is broken because some third party broke it. Warranty law is about the first two cases. It has nothing to do with the third case. If you break a company's product, you are going to be liable, whether the product is under warranty or not.
Incidentally, we have reached the point where it's important to point out that I am not a lawyer.
I'd argue that somebody was just getting creative with their profile!
If you get creative with your own profile, and it brings down your browser, you have found a bug. Indeed, if you get creative with your own profile, and it brings down Twitter, you have merely found a bug. (Though one that could obviously be used to perform a DOS attack on Twitter. If you exploit the bug to bring down Twitter over and over for your own amusement, you're getting into shakier legal ground. The responsible thing to do is report the bug.)
If you "get creative with your profile" to create a XSS attack that deliberately defaces other profiles? Hire a lawyer, pronto.
how responsible do the website owners have to be?
The truthful answer is "not very". You can be convicted for breaking into an account that has little or no actual security on it. You can be convicted for searching for an exploit on your employer's computer, even if you don't exploit it. (Ask Randal Schwartz. You should probably Google up his case. Sounds like you need some legal briefings.)
Don't impersonate other people on computer systems. Even if the system owners are begging for it. (Especially if the system owners are begging for it.) And don't "test" people's security without specifically getting their permission in advance.
Comments
You are making a lot of unwarranted assumptions. For one thing: If you publicly deface a website you advertise the existence of an exploit which someone else might then use for evil purposes. But, more importantly: Who says that an edit to a user profile is always harmless? People have lost relationships, job leads, careers, and reputations over such "trivial" things. Remember the poor teacher whose Windows box got infected by a virus and spewed porn links all over the screen in front of the students? The woman who lost her job and narrowly missed being convicted as a sex offender by a crazy prosecutor?
These people are using the website with no warranty. It says so in the Terms of Service. Myspace, Twitter, Facebook, etc, guarantee nothing about the security of their website, and whether or not their technology even works correctly. Even if they did say in their warranty: "Your information is guaranteed to be secure," does that magically make it illegal to make a worm?
Two: "What defines the line between legal and not?" The answer, ultimately, is judges and juries. These people have a wide range of discretion and are often surprisingly reasonable. (Although certainly not always. And they cost a lot to convince, and they can be randomly unreasonable, which is why there are a lot of jury-trial horror stories and why lawyers prefer to avoid jury trials whenever possible.)
If I leave a loaded gun lying around and you pick it up and shoot me dead, the legality of your action is going to depend crucially on what you can make the prosecutor and the jury believe. If you convince them that you did it by accident -- that you were honestly just playing around with the gun on the assumption that nobody would be dumb enough to leave a loaded gun around -- you might be found innocent. If you had a documented motive for killing me, or were arguing with me at the time in front of witnesses, or if there were no witnesses... well, good luck.
Good points. Especially the loaded gun thing.
But in the Myspace example -- what harm was done to Myspace that warranted any punishment? Is it because they're such a successful website, that it matters more? I mean, let's say the kid made this worm for a site with like 1,000 users... is it any less of a crime? And why is it not Myspace's fault for not securing the website?
Another thing I'm confused about... how responsible do the website owners have to be? Let's say they allow javascript in profiles. The worm was nothing more than javascript.. I'd argue that somebody was just getting creative with their profile! If they made an endless loop of alerts, is that a "virus" because in most browsers (ridiculously) you have to force quit them?
And, finally, how in the world does any of this technology stuff get explained to the people making the decisions, eg, the judge and jury. It seems it's nearly impossible for it to be adequately explained to them to the point of them understanding enough to make a fair judgment.
These people are using the website with no warranty
I think you will find that a jury will have no trouble telling the difference in value between something that has no warranty, something that has no warranty and is broken thanks to an error by its vendor, and something that is broken because some third party broke it. Warranty law is about the first two cases. It has nothing to do with the third case. If you break a company's product, you are going to be liable, whether the product is under warranty or not.
Incidentally, we have reached the point where it's important to point out that I am not a lawyer.
I'd argue that somebody was just getting creative with their profile!
If you get creative with your own profile, and it brings down your browser, you have found a bug. Indeed, if you get creative with your own profile, and it brings down Twitter, you have merely found a bug. (Though one that could obviously be used to perform a DOS attack on Twitter. If you exploit the bug to bring down Twitter over and over for your own amusement, you're getting into shakier legal ground. The responsible thing to do is report the bug.)
If you "get creative with your profile" to create a XSS attack that deliberately defaces other profiles? Hire a lawyer, pronto.
how responsible do the website owners have to be?
The truthful answer is "not very". You can be convicted for breaking into an account that has little or no actual security on it. You can be convicted for searching for an exploit on your employer's computer, even if you don't exploit it. (Ask Randal Schwartz. You should probably Google up his case. Sounds like you need some legal briefings.)
Don't impersonate other people on computer systems. Even if the system owners are begging for it. (Especially if the system owners are begging for it.) And don't "test" people's security without specifically getting their permission in advance.