Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Documents are not obviously confidential if there is an established process for removing confidential documents, but the documents still show up in a simple search.

Your position is that you viewed everything that Google thought it could publish in regard to your query. It is ridiculous that someone could be jailed as a result of clicking a link on a Google search result page.



Consider the Google search that started this:

"not for public release filetype:pdf"

That's a pretty flagrant attempt at accessing confidential documents. It isn't like someone googles "how to catch a roadrunner" and accidentally downloads confidential Acme documents. This is a full on attempt to find poorly secured documents.

Now, consider what Google does. It runs bots (that respect things like robots.txt) and then publish links to everything that they can find.

Maybe I'm missing some subtlety, but I don't understand how these are similar. Can you explain yourself further?


That is a perfectly legitimate query. I would expect to find all manner of historical documents. Further, it does not matter what a document says. Claiming to be not for public release doesn't make it a crime to release it. The only possible exception here is for national secrets, but even then many exceptions have been made.


Good answer - thanks very much for clarifying!


Because there isn't going to be anything confidential that the search result returns. And anything you access is something that was widely available.

It'd be like googling, "Bank of America's Secret Backdoor Password to steal all it's money".


It's possible that I have missed some subtleties in your argument so let me ask for a bit of clarification.

Because there isn't going to be anything confidential that the search result returns.

Doesn't this assume that sysadmins are actually competent? And isn't there a ton of evidence that suggests that sysadmins have routinely allowed confidential data to be indexed by Google??

In that case, isn't this analogous to what would happen if I left my front door unlocked and you 'broke' in and stole my collection of Taylor Swift CDs. (I don't actually own any Taylor Swift CDs, but it makes my point easier).

Granted, I did a shitty job of securing my valuable music collection, and Taylor Swift CDs are widely available. But fundamentally, you still came in without permission and took something that belonged to me.

Recent history has shown that you can be prosecuted for all sorts of things in cyberspace. Accessing confidential directories, downloading poorly secured files, and exploiting poorly designed APIs have all been successfully prosecuted.

I wish that we lived in a world where doing things like that would be considered a part of intellectual freedom, but the unfortunate truth is that laws are applied in such a way as to make this highly risky. The silly thing is that the state of the law actually benefits hard core criminals...




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: