Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> the only possible convictions we should allow is over DoS and that is only if there is malicious intent.

What's 'malicious intent'? Is it what the 'reasonable person' decides it is? If so I don't see how what you're proposing is significantly different from what I've been saying.

Likewise a DoS is not the worst possible thing you could do to a website with an unauthenticated API. Why do you carve open an exception for DoS but not for e.g. identity theft or doxxing?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: