Live data from Hacker News

Ticketmaster admits it hacked Songkick before it went out of business

arstechnica.com

231–240 of 337 posts

Re: Ticketmaster admits it hacked Songkick before it went out of business

#231

Earlier quoted context omitted.

IMO everyone related to a corporate crime should be responsible. If a company dumps toxic waste in to a river, the person who pressed the dump button, the person who told them to and any management that signed off on the idea should all be personally as responsible as if I just took a bucket and walked down to the local river. Perhaps some exceptions for people who could not be expected to understand the law, for exa…

I agree, and I would go slightly farther. One of the lessons the mortgage bubble taught us is how much executives benefit from plausible deniability. For corporate crime, I think the standard of "knew or should have known" should apply. If CEOs are going to hoover up a lot of the profits when things go right, they should hold at least as much responsibility when things go wrong on their watch.

For criminal behaviour from the organisation, the burden of proof needs to be reversed. The CEO should need to prove they did not know and did not endorse tacitally or otherwise and would have reacted strongly to prevent and effectively sanction those responsible if they had found out in advance.

It's their job to know. Only if they are a victim of a genuine criminal conspiracy performed by other employees and it can be shown without the CEO's knowledge should there be any defence.

CEO's are quite happy to tell people to do things without telling them to do the thing. That has been going on for centuries. Shakespeare wrote whole plays about it.

https://en.wikipedia.org/wiki/Will_no_one_rid_me_of_this_tur...

Re: Ticketmaster admits it hacked Songkick before it went out of business

#232
post #148

Compare this slap on the wrist to Aaron Swartz: Federal prosecutors later charged him with two counts of wire fraud and eleven violations of the Computer Fraud and Abuse Act,[15] carrying a cumulative maximum penalty of $1 million in fines, 35 years in prison, asset forfeiture, restitution, and supervised release. https://en.wikipedia.org/wiki/Aaron_Swartz

"Computer Fraud and Abuse Act,[15]" You could walk into a liquor store - pistol whip a clerk then rob the joint and do less time. AND at least if you pistol whip a clerk you get parole. You wont get federal parole if you try to guess a computer password [1]. https://www.nolo.com/legal-encyclopedia/is-federal-parole-sy...

There's absolutely 0 chance he ever would have done anywhere near the statutory maximum. Statutory maximum != sentencing guidelines.

Re: Ticketmaster admits it hacked Songkick before it went out of business

#233
post #231

Earlier quoted context omitted.

I agree, and I would go slightly farther. One of the lessons the mortgage bubble taught us is how much executives benefit from plausible deniability. For corporate crime, I think the standard of "knew or should have known" should apply. If CEOs are going to hoover up a lot of the profits when things go right, they should hold at least as much responsibility when things go wrong on their watch.

For criminal behaviour from the organisation, the burden of proof needs to be reversed. The CEO should need to prove they did not know and did not endorse tacitally or otherwise and would have reacted strongly to prevent and effectively sanction those responsible if they had found out in advance. It's their job to know. Only if they are a victim of a genuine criminal conspiracy performed by other employees and it can…

OT, but "Will no one rid me of this turbulent priest?" reminds me of a funny Mitchell and Webb sketch about evil villains using ambiguous phrases when ordering their henchmen to kill someone.

(NSFW) https://www.youtube.com/watch?v=U6cake3bwnY

Re: Ticketmaster admits it hacked Songkick before it went out of business

#234

Earlier quoted context omitted.

> ... but criminally don't face anywhere near the same levels of punishment. We generally do not punish corporations harshly for criminal wrongdoing because (1) punishing the corporation mostly harms the shareholders, who aren't responsible because they only have indirect control over the corporation, and (2) the individual employees who commit crimes face criminal prosecution and punishment. [Edit] I regret that my…

> [Edit] > I regret that my comment was taken as one endorsing corporations or their shareholders profiting from crimes. That was not my intent. Regardless of whether your intent was angelic, devilish, or neither, rampant corporate criminality (such as TicketMaster's) is the obvious consequence of building a system according to principles that advantage criminality so baldly.

> ... a system according to principles that advantage criminality so baldly.

As I wrote elsewhere, there is no advantage to criminality because there are many ways that a corporation can be brought to justice.

Re: Ticketmaster admits it hacked Songkick before it went out of business

#235
At the very least, the manager who approved this hack should be charged with a criminal offence. This imbalance in the justice system is beyond disgusting. People need to protest this in front of DOJ offices. There are people in prison right now fur doing security research yet these criminals are off with a fine.

Re: Ticketmaster admits it hacked Songkick before it went out of business

#236
So you're a CEO of a company. Other employees of the company commit crimes. You know about the crimes. The company profits from the crimes paying your salary &/or bonus. You do not inform the police.

How is this not a criminal conspiracy engaged in by the CEO (either before or after the fact) resulting in Jail time for the CEO?

Is it just because "with a computer" that the CEO isn't facing charges? What crimes committed and prior or subsequent knowledge of and then profit from those crimes would qualify in the CEO being charged with being involved in a criminal conspiracy? Does it have to be something that reads dramatically in a newspaper like armed robbery or assult or murder? Do the victims of the crime have to be elderly? Or are those crimes also fine as long as your title is CEO rather than "Don"?

Is this fixable?

Re: Ticketmaster admits it hacked Songkick before it went out of business

#237
post #232

Earlier quoted context omitted.

"Computer Fraud and Abuse Act,[15]" You could walk into a liquor store - pistol whip a clerk then rob the joint and do less time. AND at least if you pistol whip a clerk you get parole. You wont get federal parole if you try to guess a computer password [1]. https://www.nolo.com/legal-encyclopedia/is-federal-parole-sy...

There's absolutely 0 chance he ever would have done anywhere near the statutory maximum. Statutory maximum != sentencing guidelines.

Yes. If you pistol whip a clerk you would get 10. If you get caught hacking you will get 5 in federal (35ish year max). The guy pistol whipping will get parole in 5. Same same.

Re: Ticketmaster admits it hacked Songkick before it went out of business

#238
post #236

So you're a CEO of a company. Other employees of the company commit crimes. You know about the crimes. The company profits from the crimes paying your salary &/or bonus. You do not inform the police. How is this not a criminal conspiracy engaged in by the CEO (either before or after the fact) resulting in Jail time for the CEO? Is it just because "with a computer" that the CEO isn't facing charges? What crimes commit…

This was a criminal conviction. It says so in the article.

Are you commenting on the disparate sentencing for the company versus an individual?

It is a deferred prosecution agreement, which is definitely an aspect of corporatism: that is the pre -eminent rights of corporations over natural people.

However there was a criminal conviction of a natural person as well. The DPP was the criminal conviction of the corporation that benefited from the underlying crime.

DPPs exist to avoid collateral damage to innocents dependent on the corporation, whilst still criminally convicting the corporation itself. It’s a balancing game.

With it a bit nuanced I am curious to understand better what you meant by your comment.

Re: Ticketmaster admits it hacked Songkick before it went out of business

#239

Earlier quoted context omitted.

> [Edit] > I regret that my comment was taken as one endorsing corporations or their shareholders profiting from crimes. That was not my intent. Regardless of whether your intent was angelic, devilish, or neither, rampant corporate criminality (such as TicketMaster's) is the obvious consequence of building a system according to principles that advantage criminality so baldly.

> ... a system according to principles that advantage criminality so baldly. As I wrote elsewhere, there is no advantage to criminality because there are many ways that a corporation can be brought to justice.

The rational minds at ticketmaster seem to have disagreed with you in this instance.

Re: Ticketmaster admits it hacked Songkick before it went out of business

#240

Earlier quoted context omitted.

> [Edit] > I regret that my comment was taken as one endorsing corporations or their shareholders profiting from crimes. That was not my intent. Regardless of whether your intent was angelic, devilish, or neither, rampant corporate criminality (such as TicketMaster's) is the obvious consequence of building a system according to principles that advantage criminality so baldly.

> ... a system according to principles that advantage criminality so baldly. As I wrote elsewhere, there is no advantage to criminality because there are many ways that a corporation can be brought to justice.

Like TicketMaster was brought to justice? What a joke.

TicketMaster is not an outlier — corporate impunity is the rule, not the exception. The incentives you advocate have proven utterly inadequate to ensure either "justice" (for those who care about justice) or economic efficiency arising from legitimate competition.

Post reply on HN