Live data from Hacker News

Ticketmaster admits it hacked Songkick before it went out of business

arstechnica.com

261–270 of 337 posts

Re: Ticketmaster admits it hacked Songkick before it went out of business

#261

And nobody will change their behaviors because all but one of them suffer no personal consequences. They got the benefit of the crime and have to pay no price. Corporate crime needs to be prosecuted like personal crime, with 20-year-jail sentences in a jail full of Crips and Bloods and Aryan Brotherhood. Your Harvard MBA dude truly knows that he doesn't have a snowball's chance in hell of surviving a place like that.

The article says that an executive was charged with wire fraud and conspiracy to violate the CFAA, pled guilty, and is awaiting sentencing.

It's up to the judge whether he sees the inside of a jail cell.

Re: Ticketmaster admits it hacked Songkick before it went out of business

#262
post #235

At the very least, the manager who approved this hack should be charged with a criminal offence. This imbalance in the justice system is beyond disgusting. People need to protest this in front of DOJ offices. There are people in prison right now fur doing security research yet these criminals are off with a fine.

The executive who ordered the hack- Zaidi- literally was charged and plead guilty. It's mentioned in the article.

Re: Ticketmaster admits it hacked Songkick before it went out of business

#263
post #231

Earlier quoted context omitted.

I agree, and I would go slightly farther. One of the lessons the mortgage bubble taught us is how much executives benefit from plausible deniability. For corporate crime, I think the standard of "knew or should have known" should apply. If CEOs are going to hoover up a lot of the profits when things go right, they should hold at least as much responsibility when things go wrong on their watch.

For criminal behaviour from the organisation, the burden of proof needs to be reversed. The CEO should need to prove they did not know and did not endorse tacitally or otherwise and would have reacted strongly to prevent and effectively sanction those responsible if they had found out in advance. It's their job to know. Only if they are a victim of a genuine criminal conspiracy performed by other employees and it can…

I don't think CEO is the right level. It may be the top position with high pay, but a CEO is so high up the food-chain that they touch very little.

Any level of management with a direct responsibility is where blame should lie.

Re: Ticketmaster admits it hacked Songkick before it went out of business

#264

Earlier quoted context omitted.

And when that company commits a crime, it should be punished and its stock should lose value. It seems like you're arguing that shareholders should reap rewards for actions that a company takes but be shielded from negative financial repercussions that result from criminal actions it takes. This creates a moral hazard similar to to the "too big to fail" situation of banks. It incentivizes risky and potentially crimin…

> And when that company commits a crime, it should be punished and its stock should lose value. I agree. That is part of the risk investors take.

It’s not enough to lose your investment. You should lose your share of the penalty. The idea of limited liability is heinous.

Re: Ticketmaster admits it hacked Songkick before it went out of business

#265
post #186

Earlier quoted context omitted.

And with (financial) protection for those who refuse to partake and report the crime. I guess the person pressing the dump button would usually make just above minimum wage and would be considered unimportant enough to fire if he stood up for what's right so there is no incentive except for a moral one which I would argue is not enough for most people.

As much as the liberal-libertarian crowd on HN likes to be vocal against most forms of government licensure, protection from ethical breaches like this is one of the best things about them. You can tell your employer to pound sand because neither you nor anyone they could replace you with will be willing to risk their license to do something unethical. And even if they could find someone sketch to try and push it thr…

I'm not leftist and I haven't observed any strong bias here. HN crowd is leftist only by US standards but then US is a country where most people think public health care is communism.

Re: Ticketmaster admits it hacked Songkick before it went out of business

#266
post #148

Compare this slap on the wrist to Aaron Swartz: Federal prosecutors later charged him with two counts of wire fraud and eleven violations of the Computer Fraud and Abuse Act,[15] carrying a cumulative maximum penalty of $1 million in fines, 35 years in prison, asset forfeiture, restitution, and supervised release. https://en.wikipedia.org/wiki/Aaron_Swartz

It's a bloody miscarriage of justice.

Re: Ticketmaster admits it hacked Songkick before it went out of business

#267
post #231

Earlier quoted context omitted.

For criminal behaviour from the organisation, the burden of proof needs to be reversed. The CEO should need to prove they did not know and did not endorse tacitally or otherwise and would have reacted strongly to prevent and effectively sanction those responsible if they had found out in advance. It's their job to know. Only if they are a victim of a genuine criminal conspiracy performed by other employees and it can…

I don't think CEO is the right level. It may be the top position with high pay, but a CEO is so high up the food-chain that they touch very little. Any level of management with a direct responsibility is where blame should lie.

This is the same argument that tech corporations say should apply to them. They should be allowed to grow uncontrollably to make as much money as possible but it's actually impossible for them to know the details (moderate content in this specific iteration of the argument) of what they have grown. The point of this thread is the same argument against that very idea.

If the organization is so big that the CEO believes that, it shouldn't matter. They should be ultimately responsible for the entire organization. No one forced the company to be that big and no one made them take the job.

Re: Ticketmaster admits it hacked Songkick before it went out of business

#268

Earlier quoted context omitted.

I agree, and I would go slightly farther. One of the lessons the mortgage bubble taught us is how much executives benefit from plausible deniability. For corporate crime, I think the standard of "knew or should have known" should apply. If CEOs are going to hoover up a lot of the profits when things go right, they should hold at least as much responsibility when things go wrong on their watch.

One of the things I found incredible about the antitrust hearings this past year was how heavily every Big Tech CEO relied on "I don't know", "I don't recall", or "I'll have to get back to you". Often about things I, an outsider, know of. It strains plausibility they didn't know, they're just punting to a time they aren't under oath.

If it’s a crime for you to misspeak wouldn’t you err on the side of caution?

Anti trust hearings of 4 tech companies at once... ridiculous... All 4 of you have a monopoly on... something!

Bullshit politics. You aren’t being forced to use ANY services from big tech in the US there is HEAPS of competition. Just US lawmakers shoring up constituents

Re: Ticketmaster admits it hacked Songkick before it went out of business

#269
post #5

What terribly worded and confusing as fuck title. In case anyone was wondering, who, specifically went out of business: > Court documents didn’t identify the rival company, but Variety reported it was Songkick, which in 2017 filed a lawsuit accusing Ticketmaster of hacking its database. A few months later, Songkick went out of business.

I thought I was going crazy or that my English has gotten worse. Thank you. I initially read this as Ticketmaster going out of business and was shocked.

Re: Ticketmaster admits it hacked Songkick before it went out of business

#270

Earlier quoted context omitted.

I don't think CEO is the right level. It may be the top position with high pay, but a CEO is so high up the food-chain that they touch very little. Any level of management with a direct responsibility is where blame should lie.

This is the same argument that tech corporations say should apply to them. They should be allowed to grow uncontrollably to make as much money as possible but it's actually impossible for them to know the details (moderate content in this specific iteration of the argument) of what they have grown. The point of this thread is the same argument against that very idea. If the organization is so big that the CEO believe…

But you can't know all of that.

Imagine some local wallmart having an issue with something (eg. a bunch of expired chemicals, that have to be disposed as dengerous), and they don't want to deal with that in a proper way, and some local manager tells some local worker, to just dump the chemicals into a stream behind the wallmart. Usually noone notices stuff like that, if the chemicals are not "too bad" (=fish die), the worker will lose his/her job if (s)he doesn't do it, and the manager will get someone else to do it. If the worker reports it, it's his word against the managers, the manager will just say it was leaked rainwater, and that they asked the worker to spill it in the gutter, so the worker has no real choice, if they want to feed the kids that night. People above the manager have no idea about that local wallmart, and that one time issue.

Then, the worker dumps the chemicals into the stream, the chemicals just happen to be very dangerous, and a million fish die in the river downstream. Is the CEO really the guilty on here? Did he really know?

On the other hand, you have the VW dieselgate, where a whole team had to work on the software, and atleast a few level of mangers had to have known about the issue. But on the corporate ladder, where every level is squeezing the level below it to "do more", "bring in more profits", it's possible that some manager in charge of something actually didn't tell the people above him, just how exactly he solved the exhaust issue, just that he solved it, and saved millions of euros (and got a huge bonus). On the other hand, coordinating a big team of coders, and such info not getting to higher ups or to members of different teams in the same company (with different managers) is probably unlikely.

What i'm trying to say is, that blaming the CEO by default is bad, because in the first case, it's unrealistic to expect the CEO to even know that that local walmart exists.... and in the second case, that there should be a very thourough investigation just how high the knowledge went, and have the whole chain of comand held responsible.

Post reply on HN