What is so special about a cease and desist letter? So now 1 company can destroy the business model of another company by simply sending out a letter? Power was using a public API with user permission. If Facebook did not like that then change the API, or introduce a different security model.
If I created a business sending unsolicited snail mail to your address, and you asked me to stop using a cease and desist letter, should I comply, and allow you to destroy my business model?
In the US, people have the right to decide a sender may no longer send them snail mail if the sender has sent them obscene materials.
It's my understanding that case laws has led to obscenity in this context being 100% as defined by the recipient. If you believe content type X is obscene, and someone sends you content type X, you can follow the procedure for reporting obscenity. They are obligated to stop sending you anything.
but in this case, the users, through the Power website, did give permission to receive, or send, the "snail mail".
From the article "Power users also authorized the software to send Facebook messages to other Facebook users for them"
So in your analogy. I created a business of sending snail mail to addresses I already had in my possession on my list of contacts. My contacts might not appreciate my snail mail, but I am not sending snail mail to the Facebook corporate Office -Or- if I am sending to the Facebook Corporate Office, then only though its mail routing department, which was set up to handle these very packages.
The C&D, I think, is equivalent to preventing contacts from communicating with each other, or, Postal Censorship[1], which I suppose is more a policy issue than a legal one. Which I suppose extends FB to be a governing body, which I guess leads us to CFAA...
Yes, if your business model revolves only and completely around sending these unsolicited pieces of mail to my address, I think there would be no problem in getting a court to uphold the cease-and-desist letter, thus destroying your business. Quite how your business was going to produce revenue just sending mail to one person is a mystery though, anyway...
I don't understand this analogy. Do most people have the legal ability to prevent letter-sending without working with the Post Office? Did the company have many other sources of revenue besides Facebook?
There are EU data protection directives that have that effect. (Saying "Europe" to mean "the EU" is technically "wrong" in the same sense as saying "America" to mean "the USA", but it's common enough to be widely understood. Language is a tool for communication)
It isn't a "public" API, it's Facebook's API that they're making available to the public. They have the right to control access to their API, be it by password authentication or telling someone to stop using it.
Not that I necessarily agree with how this case turned out, but Facebook is under no obligation to support the business model of another company...
> "Facebook is under no obligation to support the business model of another company..."
Agreed, but neither should they have the ability to destroy a business by the single act of sending out a letter. Pretty much from that point on the company can't legally operate.
If you build a company that is a) fully dependent on another company to exist and b) reliant on that company providing you service it doesn't have any business reason to provide, then you the founder of the company destroyed it.
If a business is flimsy enough to be destroyed by a letter, it was toast anyway.
Not to mention this argument that someone else's business is this precious thing that can't be destroyed. Its totally bizarre. How often does Apple release features that eat another company's lunch? Better yet, think of all the disruptive SV business models that are purely based on destroying businesses and replacing them with alternatives.
> "If a business is flimsy enough to be destroyed by a letter, it was toast anyway."
Completely disagree. In the early stages of its life, almost any business is very vulnerable. If Microsoft had irritated IBM just the slightest bit in the early days, they would have been toast, or at best a small niche company, because they were completely dependant on IBM's goodwill. An IBM executive could have decided they preferred the boys at Apple instead. no letter even required. Yet look at Microsoft today. Who is to say that a business starting out using a Facebook API today, could not diversify and be a powerhouse and industry leader, tomorrow?
The point is that this ruling allows one company to make illegal, the business activity of another just by sending out a letter irrespective of whether that company's activity is actually illegal
It became illegal when Power circumvented the C&D letter to continue accessing systems they had expressly been forbidden to access. Their conduct was fine until FB decided they wanted no part in it.
This is how it should be. If I, as a company, decide I don't want to do business with you, either individually or corporately, barring discrimination rules, why shouldn't I have that right?
Facebook has the right to determine who can and cannot access their systems, barring a court order. You seem to be suggesting they should not have that right.
But Power was using its customers' fb users' credentials with their permission, so it was fb users "who" accessed fb. Only they did it through other computers that were owned by Power. Should fb have the right to determine what and which computer you use to access fb?