No, he wasn't kicked off, just the MAC address of his laptop was banned. As the article author wrote, if someone blocks your number, it's not illegal to call him/her from a different phone number.
Maybe they could make it illegal if they got a restraining order, but AFAIK MIT did not do that.
Perhaps its different for me since I work in information security, but if there's someone connected to our guest network (where we have no identity information) and their computer is misbehaving, the only recourse we have to demonstrate that they are not welcome anymore is to terminate their session and block their MAC address. There's literally no other way to get in contact with them.
I would say it's safe to assume that if your MAC address gets banned, it was for a reason. It means you're not welcome on the network anymore.
The retort would be : If you want to be able to address me, you don't have to have an open network, you can require registration and/or other physical verification first. You have chosen to run a network where you can't identify or talk to me, you should therefore know that I won't necessarily know what you're wanting. Some places have a policy that older versions of OSes aren't permitted on the network, and you'll get booted for that. Doesn't mean that you aren't welcome after you've updated your system or changed to another PC. But you haven't told me why you booted me, so I can't know for sure that I'm not welcome again.
The courts can and do, particularly when a particular crime specifies that you violate a specific placed prohibition. In Arrons case (without knowing precisely what went on), it may very well be possible to argue that he thought the banning of the mac address was e.g. a warning, an automated trip/response that the administration may not agree with in his deserving case, related to a period of overload on the system (i.e. temporary ban) etc. And the court would need to believe "beyond reasonable doubt" that none of those were the case.
The courts (usually) take a common sense approach like you suggest when your argument of "duuuhhhhhh, they didn't explicitly tell me not to do that" has very little to back it (i.e. no plausible explanation of why you thought it necessary for them to explicitly say it). But backed by a reasonable, or at least feasible, alternative, the courts often side with the defendant.
If you were able to access the network before, then you did something questionable, and now you're not able to access the network, I'd say that's a pretty good sign. At the very least, you should be able to guess why you were able to access the network again once your spoofed your MAC address. There are many layers of security on networks like these, and to be banned from an open network you have to be doing something you really know is questionable (even if you don't believe it's illegal or immoral).
The argument of "well I didn't know why you kept banning me" doesn't fly. After the first MAC filter, you should know you're no longer welcome, for whatever reason.
I like this idea, but there's a problem with it. His MAC address, which is meant to be specific to a machine, was banned. The intent is clear-- "your machine is no longer welcome on our network."
"His MAC address, which is meant to be specific to a machine"
The article (which I tend to agree with) tends to argue that a MAC address is exactly NOT that, especially in a technical sense (thus a technical user may indeed have more reason for the intent not to be "clear").
I think a better description in plain english is :
A MAC address is an address that a particular interface on a particular machine asks to be identified by in a particular session.
I.E. it's not an identity of a machine, its an identity of an interface. Its not an identity assigned by the network, its an identity offered by the machine/interface itself. Its not guaranteed to be unique, or stable beyond a session.
If it was meant to be a specific identifier for a machine, we would have many technical problems on the "legitimate" side of things, think multiple network cards and virtualised machines.
There was no agreement between Arron and MIT that arron would use a particular MAC address as an indentifier on their network. Its a downside of running an open network.
The meat of the question is how much legal weight a MAC filter should carry. To me the answer is not much. Attach the MAC filter to a simple advertisement of the network rules and it goes way up. This business about safe to assume is scary stuff.
I wouldn't say it's scary. Imagine you're in a club and you start a fight. The bouncer takes you outside. Every time you try to get back in, he's standing in your way. You can come back with a disguise and get in, but without the disguise you're banned. It's safe to assume that you got thrown out because you were fighting.
A lot of the US legal system is based on reasonable belief and reasonable assumption. If an average, reasonable person would believe X, then X is the interpretation the law is likely going to take. It doesn't matter if the rule was actually supposed to be Y, X is what is being communicated and a reasonable assumption would be that X is correct.
I don't like the bouncer analogy. The network people surely know that the MAC filter is ineffective and no bouncer would be fooled by a fake mustache.
I agree that it is clear enough that Aaron Swartz was intentionally circumventing their attempts to keep him off the network. Where I have trouble is that any notional security mechanism is apparently enough to make the circumvention a serious crime.
I suppose where I am going is that severe penalties should be for circumventing security features, and easily altered implementation details of network hardware should not qualify as security features.
Well I wasn't intending this as a debate of secure network practices. I was intending to voice my opinion that having your MAC address banned sends a very clear signal that you are no longer welcome. A signal that could be successfully argued in court. If you are banned from a network and you gain access back by changing your MAC address, no matter how trivial this exercise is you have to understand at some level that your machine address was purposefully blocked from the network.
Actually that makes me like the analogy again! If all you do is put on a mustache or change your shirt and the bouncer lets you in, then you don't really know what the purpose of the bouncing is.
> It means you're not welcome on the network anymore.
I thought it meant, that specific MAC address is not welcome anymore. Otherwise, why would you allow that person to reconnect again just because they changed their MAC address?
No it's not. What if they blocked the MAC because they detected botnet activity? There is absolutely no desire in this case to ban the person, or even to ban the entire computer if it has multiple OSs.
There is really no way to tell just from a MAC ban what the intent is.
>"Otherwise, why would you allow that person to reconnect again just because they changed their MAC address?"
Because in some situations, this is literally the only means you have to get someone off your network. I'm arguing that it is possible and fairly straightforward to tell why your MAC address got banned. The most obvious is by looking back at your history on the network. You know if you've done something questionable. Another way is to call the helpdesk and ask why you've been banned.
At no point is "I didn't know why" going to be a valid reason for spoofing a MAC address to get around a network ban. If you have the know-how to spoof your MAC address, you have the know-how to understand why it's necessary.
If this happened on my company's network, the next step would be tracking the person down with physical security and letting them know the police would be enforcing the ban next time.
> Because in some situations, this is literally the only means you have to get someone off your network. I'm arguing that it is possible and fairly straightforward to tell why your MAC address got banned
Of course that might be the only means to remove someone from layer2 of your network. I don't disagree. I think there are reasons for spoofing MAC addresses (like having it randomized on startup) are complete legitimate and indicate nothing about intent.
> If this happened on my company's network, the next step would be tracking the person down with physical security and letting them know the police would be enforcing the ban next time.
Absolutely. I just don't think wire fraud should be tacked on to their other crimes on your network just because their MAC address changed.
In the law of property, there is a concept called "license." Basically, it encompasses the idea that you can give people permission to trespass, either explicitly or implicitly. If I invite you to my house for dinner, I'm giving you implicit permission to trespass.
Basically, the implied license has a scope defined by the rationale for the implication. If you invite a plumber to fix your toilet, they don't have license to use your jacuzzi (though a dinner guest might!) A license can be revoked in any manner that reasonably conveys the revocation to the licensee.
The law of property isn't directly applicable to computer networks, but is a source of guiding principles and analogy. If you're on an open network and the administrator bans your MAC address, I think a normal person would conclude that the message that you are no longer welcome has been reasonably conveyed. Moreover, MIT Net does have terms of use, and one of those terms (#4 of 6) is: "Don't misuse the intellectual property of others." You can also argue that these terms of use define the scope of the implied license to use MIT's open network.
I disagree.
If I call your phone and one day you don't answer and I try from a different phone number and you do I think you are ok to have me call you.
Had they notified him with a web page that his mac address wasn't welcome it would have been a different matter altogether.
What Aaron did was the equivalent of trying a different laptop to see if things resumed working.
The very first time that happens, maybe he could have thought it was a network error.
But Aaron kept on evading every single countermeasure MIT was putting in his place. By the time you get to going into a wiring closet, you have well passed the point where you know you are no longer welcome on the network.
The law cares very little about what tools you use, and they care a lot more about the actions you do and why you do them.
Aaron wasn't an idiot. He knew MIT was trying to keep him off. It wasn't just a network error.
Yeah, if they had just blocked his mac address then he could reasonably think "hmmm, I can't connect with this mac address, I'll try a different one" instead of "I am no longer authorized". But if you have to keep reconnecting with different IP addresses and mac addresses over and over again, and finally resort to connecting directly to a wiring closet, then the message is pretty clear that you (not just your mac address) are no longer allowed on the network.
It's clear that someone doesn't want you to have easy access, but it by no means gives a clear message that you aren't 'allowed'. If I set up a wifi portal that flips images upside down and misspells words and all that fun stuff it's clear that your access is being diminished but by no means says I want you off my network.
Calling someone isn't considered analogous to trespassing, while accessing someone's network is. I don't think that's a meaningless distinction at the technical level either. Calling someone is like issuing an HTTP GET on a public server. Putting a computer on their network is something quite different.
As for whether banning they MAC address conveys revocation of the license. The precise form of the communication is irrelevant, it's about whether it can be expected to get the message across in context. Do you think Aaron didn't know, after the various measures MIT took, that he was no longer welcome on the network? If he did know, then the message was conveyed.
You're basically attacking a straw man. You're acting like he was charged for trying to access the publicly-available MIT home page, getting a 404, and trying again with a different laptop to see if the problem was on his end. That's what would be analogous to your "calling someone who isn't answering then trying a different phone" example.
> The law of property isn't directly applicable to computer networks, but is a source of guiding principles and analogy. If you're on an open network and the administrator bans your MAC address, I think a normal person would conclude that the message that you are no longer welcome has been reasonably conveyed.
Let's say Aaron's laptop gets its MAC address banned for doing whatever it is he did initially. Aaron then walks over to one of the available library computers and looks up directions to the train station. In your opinion, has he just committed a federal crime?
Let's say I normally let people cut through my lawn to get to the road behind it. But you come on my lawn and start yelling at my house. So I tell you to leave. Are you still welcome to cut through my lawn to get to the road?
I have no idea. As a non-lawyer, my answer would be yes, I'm still allowed. So the message is "we don't like what you're doing", not "you aren't allowed on this network".
By default, you have no right to be on or use private property without permission. MIT's network is private property. It might be "open" in the sense that MIT liberally gives out permission to use it, but that doesn't mean they give up the right to revoke your permission. This is the same as my lawn. Just because I let people cut through it doesn't mean I give up the right to single you out and keep you from walking on it.
The example you give is an edge case, but I think technically the "get off my lawn" revokes your right to cut across it as other people do. I don't think this is a pretty common sense definition.
Imagine I have a land that is for pissing. I.e. people are free to piss on my land. You piss. I don't like the smell of your piss. So I put some boxes where you piss and so I try to block you from peeing. Are you in the wrong to pee on a different part of my land?
Wouldn't a better recourse be to require people to sign up before they pee? Or to find you when you're peeing and tell you in person that you can't any more (then if you do it again, it's trespassing)?
Just because I have something that is open to the public doesn't mean I lose the ability to kick people out. I don't have to put security guards at every door to keep that person out.
It was crystal clear that MIT did not want Aaron on their network doing what he was doing. (This doesn't mean, of course, he should be in jail for 7 years.)
Really, a MAC address is a unique name. Now your pissing land requires people give their name. I find my name has been banned, so I make up a new name. I think it is clear I know yo don't want me there, but I give a new name to get in.
They don't have to be unique. MIT/JSTOR wouldn't have really cared about accidentally blocking people unfortunate enough to share Aaron's MAC address. And, the MAC address would have been perfectly reliable had Aaron not spoofed it.
With enough resources it's practically impossible to provide reliably unforgeable credentials without strong crypto, and strong crypto goes against the whole point of MIT's open network.
How do you kick an anonymous person off of a network? Other than blocking the MAC address, the only thing I can think of is to block non-HTTP access and redirect any HTTP requests to a page explaining what has happened with instructions for getting unblocked in case the block was due to a misunderstanding.
I find it odd to provide unlimited access to a network without any further form of authentication than just the IP address. There are enough alternatives out (e.g. Shibboleth) that could have been implemented if there were a needed for closer monitoring of access to journal databases.
I guess if he had purchased multiple laptops to circumvent the filter, the prosecutor would have argued along similar lines.
So the problem is that there is room to argue that the notion of unauthorized access exists on a network that doesn't do anything to identify or authenticate users.
Sure, but people at a mall are personally identifiable. This is more like a mall full of clones,whom you can individually address but collectively not differentiate.
They were intentionally not installing a security system at their "mall" while catering to a bunch of high risk consumers (i.e. high level of knowledge addiction, know track record of MIT "hackers", etc). Since they were having identification systems for other clients in place, one could even suggest, that they had given up restricting the access towards this specific crowd.
If you want to change the discussion to "was Aaron's crime worth 7 years in prison?" that's different. (Note: he wasn't just getting onto their network to play Nettrek. Walking into a closed store at night that happened to be unlocked to be out of the cold for a few minutes is different than doing the same thing in order to interfere with their business.)
I guess I'll need to put the "Ob: I'm not saying Aaron's crimes were worth 7 years in prison" on every comment again. Thanks.
I don't think you've really considered the practical effects of "unless someone has put in place measures to do identity and authentication of all people that enter, they don't have the rights to keep out unwanted parties."
Evading a MAC filter should be equivalent to criminal trespass (usually a misdemeanor). There isn't any such notion in the law.
So the problem I have is with the structure and application of the CFAA, not so much with people having the right to keep out unwanted parties.
I did not put it clearly above, but I specifically meant unauthorized access where the CFAA would apply (in my world view, for circumvention to be a felony, the network operator needs to have some expectation the security mechanism will effectively prevent access).
If all we were talking about was just getting onto their network, then I'd agree. Just walking into a store where I'm not allowed should be a misdemeanor. Charges could increase, possibly to the felony level, depending on what I do after I'm in the store.
If MIT were tracking down someone who kept on using the network to send out shitloads of spam, and that person kept on bypassing all of MIT's countermeasures, and that person dropped a physical box into a wiring closet at MIT, no one would be confused about this.
in my world view
I disagree with your world view, but for now we can leave it at us disagreeing.
Maybe they could make it illegal if they got a restraining order, but AFAIK MIT did not do that.