Live data from Hacker News

Ticketmaster admits it hacked Songkick before it went out of business

arstechnica.com

151–160 of 337 posts

Re: Ticketmaster admits it hacked Songkick before it went out of business

#151

So Anthony Levandowski got 18 months in prison for stealing self driving car secrets from Waymo (Alphabet) and passing them to Uber. Live Nation did $10B in revenue in 2017 and they're fined 0.1% of annual revenue for a CFAA violation which has sentences up to 20 years for individuals.

In China, the CEO would probably disappear for a few months

Only if you stole it from the CCP

Re: Ticketmaster admits it hacked Songkick before it went out of business

#152

Earlier quoted context omitted.

I didn't realize paying criminal penalties was supposed to be fun and easy ;) this is literally restitution for a crime. "Uh, no Judge, I don't think I should be forced to go to prison, that's hard " [edit] Maybe this is controversial, I dunno, I might just be old fashioned that way, but my opinion is if you find the punishment too onerous maybe don't do crime .

It is not restitution if the money doesn’t go the harmed party

You are correct, I misspoke. Thanks!

Re: Ticketmaster admits it hacked Songkick before it went out of business

#153

A corporation criminally hacked a rival for profit and got away with a small fine. A person doing the exact same thing would be heading to prison. Seems like the same crime has a very different outcome when a corporation commits it.

The article notes that Zeeshan Zaidi, a Ticketmaster exec, plead guilty to violating the CFAA and to wire fraud in 2019, and is apparently still awaiting sentencing. You can read the criminal complaint: https://www.courtlistener.com/recap/gov.uscourts.nyed.439451...

> still awaiting sentencing

Aside from the usual explanation (white collar crime), any idea why someone can be found guilty and then still not given a sentence for more than a year. AFAICT he isn't even incarcerated at the moment.

Re: Ticketmaster admits it hacked Songkick before it went out of business

#154
post #25

Earlier quoted context omitted.

Discussing the length of a prison sentence strictly in terms of income lost is also greatly understating the actual severity of the punishment. I would gladly give up say 10% of my lifetime earnings for all sorts of things, but I wouldn't trade 4.5 years of my healthy adult life for anything.

> I wouldn't trade 4.5 years of my healthy adult life for anything But you probably do, just not on purpose. It's smaller decisions that you don't realize involve trading 'healthy adult life' for money/convenience/pleasure/release. And of course, the work hours you put in are very directly trading healthy adult life for money. Opportunity cost is not something that we, as humans, are particularly good at. It is of co…

You're correct, I should have been more precise. 4.5 years lost all at once is what is unacceptable. I recognize work and all of life's "chores" take time, and that every decision I make cuts off an infinitude of other choices. Though most chores have a positive reward for doing them, while prison has very little.

The larger point I intended was that for most people (especially handsomely-paid professionals like software devs) time is a more constrained resource than money.

Lastly, time lost all at once is worse than time loss incrementally, i.e. if I could serve my 4.5 year sentence 40 hours a week, that doesn't sound so bad, or that unfamiliar... ;)

Re: Ticketmaster admits it hacked Songkick before it went out of business

#155
post #148

Compare this slap on the wrist to Aaron Swartz: Federal prosecutors later charged him with two counts of wire fraud and eleven violations of the Computer Fraud and Abuse Act,[15] carrying a cumulative maximum penalty of $1 million in fines, 35 years in prison, asset forfeiture, restitution, and supervised release. https://en.wikipedia.org/wiki/Aaron_Swartz

It is one of the great imbalances in the justice system where technically corporations are people, but criminally don't face anywhere near the same levels of punishment.

Re: Ticketmaster admits it hacked Songkick before it went out of business

#156
post #148

Compare this slap on the wrist to Aaron Swartz: Federal prosecutors later charged him with two counts of wire fraud and eleven violations of the Computer Fraud and Abuse Act,[15] carrying a cumulative maximum penalty of $1 million in fines, 35 years in prison, asset forfeiture, restitution, and supervised release. https://en.wikipedia.org/wiki/Aaron_Swartz

and then 10 years later web scraping is fully legal and CFAA cannot be abused to go after them.

Re: Ticketmaster admits it hacked Songkick before it went out of business

#157
post #148

Compare this slap on the wrist to Aaron Swartz: Federal prosecutors later charged him with two counts of wire fraud and eleven violations of the Computer Fraud and Abuse Act,[15] carrying a cumulative maximum penalty of $1 million in fines, 35 years in prison, asset forfeiture, restitution, and supervised release. https://en.wikipedia.org/wiki/Aaron_Swartz

It is one of the great imbalances in the justice system where technically corporations are people, but criminally don't face anywhere near the same levels of punishment.

They get all of the benefits of personhood but literally none of the drawbacks.

Re: Ticketmaster admits it hacked Songkick before it went out of business

#158
post #116

Earlier quoted context omitted.

We're not there yet, but at some point we will be. It probably won't be within the next 5 years, maybe even 10. All that matters is that the # of deaths from automated driving ends up less than the # of deaths from human driving. If 1,000 people a year die from software glitches, that's still a 30x+ improvement from the current situation. I really don't see how people focus so much on "potential glitches" and not the…

> If 1,000 people a year die from software glitches, that's still a 30x+ improvement from the current situation. This isn't true. The odds of me dying in a car crash is lower than the average as a result of precautions I take to be safe. For me 1,000 deaths/year might be a improvement (or it might not) but to say it's a 30x+ improvement just by looking at the total number of deaths is just false. The focus on potenti…

> The odds of me dying in a car crash is lower than the average as a result of precautions I take to be safe.

I'm not specifically accusing you of this, but consider that more people than is numerically possible believe that they're better/safer than the average driver. There are a lot of people who believe they are much safer drivers than they actually are.

Regardless, just because you believe that you personally will be a safer driver than a computer, we should scrap the whole thing? What about all the people who aren't better drivers than the computer? Let's assume for a moment that you actually are safer than the eventual self-driving systems that are approved for general use -- which is by no means a certain assumption to make -- then maybe you just don't use or ride in a self-driving car? It's your choice, after all (especially in a place like the US, where I imagine manual-drive car ownership in a self-driving world will end up nearly as closely protected as firearm ownership). And sure, maybe someone else's self-driving car might hit you and kill you, but someone else's human-driven car might do the same. And if self-driving cars are doing that at lower rates than humans are, it's still a net win.

I think many people are taking this weird view that even though a self-driving car might make fewer mistakes (and cause fewer deaths) overall, it's somehow a worse situation that they'll likely make different mistakes than a human would; that is, a self-driving car might kill you in a situation where a human driver would save you. And that somehow makes the whole thing not worth it. I just find that line of reasoning to be flat-out wrong. It's an emotional appeal to some illusion of control. (Of course, unfortunately, logic doesn't write laws when it comes to contentious issues... emotion does.)

> The focus on potential glitches is because it's something the driver has no control over.

This is pretty short-sighted, because there are a ton of things that you have no control over when you drive your own car, and yet you've decided (in many cases likely unconsciously) that those things are acceptable risks.

I'm not saying you should ignore the possible risk of glitches, but focusing on a number that we don't even know yet, and immediately assuming that it will be too high for your risk tolerance is... a bit weird?

And that's the thing: I don't expect self-driving systems that have equal or worse crash records than humans do will be approved for use. And if they are, people will (rightly!) reject them. So any approved, accepted self-driving system will end up causing fewer deaths. Some of those deaths will be caused by outright bugs, and others will be caused by situations that a human driver would not be able to recover from either. All deaths are tragic, but fewer deaths overall is what we should be -- must be -- aiming for. Not playing games with control illusions. Not arbitrarily deciding that certain failure modes are somehow less acceptable than others when they cause the same (or even fewer!) deaths.

My position -- and what I believe to be the only logical, community minded position -- is that the glitch rate does not matter one bit. The only thing that matters is the overall death rate, and if self-driving cars have a lower death rate than human drivers, that should be enough. And if they don't, they should not be approved for use, and people will rightly reject them anyway.

I do agree with you that companies building self-driving systems need to be liable for mistakes and negligence to the same degree as human drivers are. Unfortunately that's harder to prove, but it's a necessary thing to figure out.

Re: Ticketmaster admits it hacked Songkick before it went out of business

#159
post #96
post #45

> Ticketmaster has agreed to pay a $10 million criminal fine Live Nation is worth $16 Billion. This is like a person with a $100k net worth having to pay a $62 fine, basically an expensive parking ticket. They might as well tell them to write "I will not hack my competitors" on the blackboard 100 times.

Fines for corporations should be a percentage of revenue, otherwise massive companies will keep doing heinous shit and write it off as a cost of doing business. The GDPR penalties in the EU are done this way (up to 4% of revenue).

That still just seems like a band-aid (sorry, I don't have a constructive alternative in mind).

If Massively-Evil-Plan™ increases profits from 10% to 20% then even after a 4% fine on revenue, real profits are still 15%. A company only motivated by profits and fines (which seems like a reasonable assumption if we're using laws like GDPR to deter "heinous shit") would be crazy not to continue with MEP™.

It's really the same kind of calculation as with fixed fines or fines based on damage done. When profitable, they're still written off as the cost of doing business. The only material difference would be that a fixed fine effectively allows large companies to do "heinous shit" while imposing fines so large that a small company can't compete, whereas with a revenue calculation you instead just need to make sure that your "heinous shit" is scalable. That doesn't apply in practice though, since GDPR has an alternative €20M fine which would go into effect, so in reality GDPR just says that to do "heinous shit" you need to be able to do a lot of it scalably and profitably.

The natural direction one might take this is just to say that the fines must not be big enough, but until you approach 100% of revenue the potential always exists for a new form of profitable "heinous shit" to crop up. If fines of that scale are on the table then that brings us to the other side of the coin: A single violation of any anti-MEP™ law will nearly certainly end the business. If a violation of an anti-MEP™ law necessarily meant that a corporation was doing "heinous shit" then that could plausibly be acceptable (definitely up for debate), but merely not appointing a data protection officer in the EU violates GDPR and potentially subjects a business to a 2% of revenue fine. The law will not perfectly align with what a reasonable person would consider "heinous shit," and too severe of a penalty in such situations seems prone to abuse.

Re: Ticketmaster admits it hacked Songkick before it went out of business

#160
post #43

Earlier quoted context omitted.

you've described crimes and bad decision making processes (humans drive tired, drunk, while texting, etc, and sometimes just make mistakes). The outcomes of those choices are known and have causes which are preventable; they are by definition not accidental in nature. I know it's not intentional but words matter. Crash is a better word 99% of the time than "accident".

An accident is just something that occurs without intention. In the cases you're describing people don't intend to hit another car or person. That makes accident a reasonable label.

I agree with that, but I think "accident" in this particular context has the undesirable property of allowing people to weasel out of taking responsibility. Just because you didn't intend to do something, it doesn't make it not your fault if you do. But the system and culture around this is set up to try to disclaim blame, even to the point that insurance companies tell you to never ever admit you were at fault after a crash.
Post reply on HN