不滿被辭退,一程序員寫爬蟲程序侵入公司後臺刪庫泄憤,造成經濟損失10餘萬元

{"type":"doc","content":[{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"blockquote","content":[{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"使用爬蟲技術,不應逾越物理上的邊界,更應守得住內心的邊界。"}]}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"heading","attrs":{"align":null,"level":2},"content":[{"type":"text","text":"員工爲泄私憤,用爬蟲刪公司數據"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"11月8日,據檢察日報報道,北京某信息技術有限公司楊浦子公司一員工錄某某因被公司解僱心生不滿,爲泄私憤,他編寫了“爬蟲”程序植入控制平臺網站,刪除了公司的相關數據代碼,造成公司經濟損失10餘萬元。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"近日,錄某某因涉嫌破壞計算機信息系統罪,被上海市楊浦區檢察院提起公訴。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"據報道,錄某某自今年3月加入北京某信息技術有限公司楊浦子公司工作,負責某網購平臺優惠券、預算等系統的代碼研發。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"6月中旬,錄某某因工作不符合要求被公司解僱。錄某某對公司的決定頗爲不滿。“這些代碼是我起早貪黑參與編寫的,好好的工作就這樣黃了”,收到主管通知被解僱的消息後,錄某某十分氣憤,遂產生了報復的念頭。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"錄某某想到了利用爬蟲軟件刪除公司數據的報復方式。錄某某自己編寫了爬蟲程序,並趁着自己的公司賬戶還沒註銷,登錄上公司的代碼控制平臺,植入爬蟲程序,刪除了原先存檔在該平臺上的優惠券、預算系統和補貼規則。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"6月下旬,公司將預算系統上線時,發現來歷不明的“爬蟲”程序植入了該系統,很多數據和代碼被刪除了,線上系統無法交付商家使用。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"公司立即組織研發人員排查電腦系統,發現發現服務器日誌上顯示刪除時間正是錄某某離職當天,且當時錄某某正在工位上操作計算機,而刪除的數據也正是錄某某原先負責的三個部分的相關數據和代碼。公司認爲錄某某有重大作案嫌疑,便向公安機關報案。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"公安機關將該案移送楊浦區檢察院審查起訴後,檢察官走訪了多家計算機技術專業機構,瞭解抓取數據對計算機系統數據安全造成的影響,研討行爲人對研發該“爬蟲”程序植入系統的動機和造成的後果。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"辦案檢察官稱,如果行爲人將網絡“爬蟲”程序植入目標網站,會對目標網站的計算機信息系統功能和數據進行增加、刪除、修改、干擾,進而導致計算機信息系統產生大量不正常的數據,以致不能正常運行,也會對目標網站所存儲、運算或者傳輸的數據和應用程序進行刪除、修改、增加等處理,後果嚴重的,將構成破壞計算機信息系統罪。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"辦案檢察官認爲錄某某利用“爬蟲”程序刪除代碼,導致該公司優惠券等商業活動延期發佈6天,第三方數據公司恢復數據庫花費2.2萬餘元,支付員工加班費2萬餘元,活動延期導致經濟損失10萬餘元,應對錄某某以破壞計算機信息系統罪追究刑事責任。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"錄某某也將爲他的行爲付出代價。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"近幾年在國內外,程序員刪庫跑路的事件屢有發生。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"今年8月,美國 1-800-Accountant 在線會計師事務所的一名僱員Medghyne Calonge在該公司工作了6個月後,因表現不佳被公司解僱,員Medghyne Calonge心生怨懟,對公司系統文件進行了破壞。Calonge 登錄到公司用於管理就業申請的計算機系統,刪除了 17000 份求職簡歷,並在文件中留下髒話。最後,該員工被兩項損壞計算機的罪名成立,並面臨最多 15 年的監禁。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"這些案件也爲我們敲響了警鐘,刪庫一時爽,事後悔斷腸。切記,作爲成年人,要管理好自己的情緒,用理智約束自身行爲。"}]},{"type":"heading","attrs":{"align":null,"level":2},"content":[{"type":"text","text":"“爬蟲”可以爬,但不能亂爬"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"在錄某某案件中,被告人的主要“作案工具”之一是爬蟲技術。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"此前也曾有技術人員利用爬蟲技術非法獲利。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"今年6月,中國裁判文書網發佈的《逯某、黎某侵犯公民個人信息一審刑事判決書》顯示,做優惠券返利業務的湖南省瀏陽市泰創網絡科技有限公司的創辦人黎某及其僱用的技術員黎某利用爬蟲軟件攻陷國內某頂級互聯網公司的電商平臺,造成上述平臺十億餘條信息外泄。二人違法行爲共獲利 340187.68 元。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"其實網絡爬蟲是非常普遍的一種數據挖掘技術,它是一種按照一定的規則,自動地抓取網絡信息的程序或者腳本。爬蟲技術最早主要運用在搜索引擎中,它滿足了人們的數據獲取、分析需求。如今,爬蟲技術的應用已廣泛。有這樣一種說法,爬蟲貢獻了互聯網 50% 的流量,它對於互聯網的繁榮功不可沒。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"但這項技術也存在一定的爭議,因爲它常常被用作非法收集信息的工具,站上數據隱私、數據安全的對立面。在一些場景,爬蟲技術很容易遊走在違法邊緣。尤其在一些金融大數據公司中,爬蟲業務被廣泛應用。2019年,多家金融大數據公司因違規利用爬蟲技術被查。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"爬蟲可以爬,但應當遵守“邊界”。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"早在 1995 年,爲了不越“邊界”,互聯網搜索引擎與網頁持有者之間達成了一項“君子協定”— robot 協議,該協議規定了哪些信息該爬,哪些信息不該爬,20 多年來,該協議一直沿用至今。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"在遵循 robot 協議的前提下使用爬蟲技術是沒有任何風險的。但往往有些“作惡者”試圖越過紅線,一些大數據公司打着“大數據分析”的名頭違規違法爬取任何網頁及訪問用戶的數據,致使“蟲災”氾濫。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"現在的爬蟲似乎無所不能,只要有賬號密碼都可以爬,包括電商平臺、外賣平臺、地圖、旅行網站、共享單車、等平臺的個人信息,用戶的通訊錄、上網地址、收貨地址、聊天記錄、搜索記錄、支付記錄,甚至央行的徵信報告... 總之,一切皆可爬,還可進行定製化爬取。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"2019 年 5 月,“中國版 GDPR”《數據安全管理辦法》徵求意見稿發佈,第 16 條規定,網絡運營者採取自動化手段訪問收集網站數據,不得妨礙網站正常運行;如自動化訪問收集流量超過網站日均流量三分之一,網站要求停止自動化訪問收集時,應當停止。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"一位業內人士認爲,技術只是工具,在獲取數據時需要考慮數據到底有沒有獲得授權,需要幾方授權,在拿到用戶授權的情況下,有沒有拿到網站等數據來源方的授權,這其中涉及到的權責邊界應該更明確。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"隨着監管越來越嚴格,爬蟲技術的使用邊界也將更加明晰。互聯網從業者應當懷有敬畏之心,要時時注意不要觸碰邊界,畢竟,爬蟲只是技術,灰色的是“助惡者”。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"“爬蟲技術本身並無對錯,但要看怎麼用,用錯了肯定違法啊”,一位程序員向 AI 前線表示,“技術無罪,關鍵在於人”。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"使用爬蟲技術,不應逾越物理上的邊界,更應守得住內心的邊界。"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","marks":[{"type":"strong"}],"text":"參考鏈接:"}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"https:\/\/www.sogou.com\/link?url=6IqLFeTuIyhfYJ1Ai-ptaljpXp0hu3m0Mr8IhlJnxsDpxru-Tb1U5YkdHzVkgLz5uQyWWQ4mRDmt5pUc3zy0dg.."}]},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null}},{"type":"paragraph","attrs":{"indent":0,"number":0,"align":null,"origin":null},"content":[{"type":"text","text":"https:\/\/www.infoq.cn\/article\/NLc0AOU1U4lmiaDCFtZS"}]}]}
發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章