Hacker News new | past | comments | ask | show | jobs | submit login

So if a bank accidentally deposits $1bn in your account, that becomes yours? You're looking for a simple answer to a nuanced issue where one just doesn't exist.



That example is not at all the same as what's being discussed. The issue at hand is whether access to a public URL is authorized and who is responsible for determining that authorization.


Actually the analogy is OK, the interpretation is wrong. If you disagree with sneak you're saying the account holder should be prosecuted!

Claiming ownership of the money would be like weev selling the email list to spammers, which he didn't. What he did was reveal the defect - like the acoount-holder reporting the mis-deposit.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: