Live data from Hacker News

U.S. Arrests Paul Ceglia for Multi-Billion Dollar Scheme to Defraud Facebook

betabeat.com

71–77 of 77 posts

Re: U.S. Arrests Paul Ceglia for Multi-Billion Dollar Scheme to Defraud Facebook

#71
post #21

A few thoughts: 1. When Ceglia first filed his claims, I called it a "lawsuit full of holes [that was] built up by sensationalist reporting into a supposed major threat to Facebook and to Mr. Zuckerberg" and concluded that, "in the courts, this thing is going nowhere." ( http://news.ycombinator.com/item?id=1537158 ) My sense of this had nothing to do with any fraudulent tampering with evidence as alleged now in the c…

I think there's two villains. It's impossible for both of them to lose, but you can't blame people for being opposed to someone "winning" by being a villain.

Why was Zuckerberg going to Craigslist looking for work? Why did Zuckerberg want to do work for "known criminals"? The project Ceglia was trying to set up was an image database. Much like Facebook. I think if Paul Ceglia had a cleaner past and better judgment, he'd be collecting his (unearned?) share from Facebook in the same way that others, Winklevoss, etc., have collected.

The reason is the trail that Zuckerberg left behind him, screwing people over one after another, betraying their trust. The only person who could keep the damage under control is Zuckerberg. As others have said, other internet billionaires don't seem to have as many "forgotten co-founders" showing up for their "cut". The problem is particularly acute with Facebook. That's no coincidence.

The lesson here is you reap what you sow. Both Ceglia and Zuckerberg.

Re: U.S. Arrests Paul Ceglia for Multi-Billion Dollar Scheme to Defraud Facebook

#72
post #58

Can anyone give a reasonable argument for why mail fraud carries a maximum sentence of 20 years? That seems ludicrous in the extreme. Why does mail fraud incur a greater penalty than rape, kidnapping, and most forms of murder?

Because mail fraud cases address a very large spectrum of actual crimes. The typical sentence for a mail fraud case is 21 months; there exists a very large number of aggravating factors that increase mail fraud sentences, including the scale of the operation (if you mass-mail to perpetrate fraud, you'll do more time), the sophistication of the victims (if you try to defraud fixed-income seniors, you'll do more time),…

Maybe they fixate on maximums because those are what are used plea bargaining? Would you leave the possibility of 20 years in a federal prison (no matter how remote) to chance?

Re: U.S. Arrests Paul Ceglia for Multi-Billion Dollar Scheme to Defraud Facebook

#73

Earlier quoted context omitted.

I wonder about that too. As a firm with a reputation to guard, I assumed they had vetted their client to some degree, and relied heavily on what I assumed was their good judgment in trying to guess the future progress of the case. I wonder if they simply got $ signs in their eyes?

If he's presenting them with what looks to be evidence, then what's the problem? Hindsight is 20/20.

Lawyers aren't paid to be credulous. Allowing oneself to be enlisted in a fraud is a severe failure of professional judgment.

Re: U.S. Arrests Paul Ceglia for Multi-Billion Dollar Scheme to Defraud Facebook

#74

I was struck when we incorporated our company and raised financing how much we still use ink and paper to keep track of things like corporate ownership. When signing so many documents I wanted to seal them with paraffin wax and send them to our lawyers via carrier pigeon. In the case of Facebook, a multi-billion dollar company, it seems amazing that someone can come out of the woodwork and with a little effort in doc…

I used to write software for print manufacturing. Paper is high tech. It's also appropriate tech for many use cases.

In addition to privacy, paper is durable. Being physical, it's possible to safe guard the chain of custody. Paper is also largely tamper evident.

I'm still weirded out by digital signatures, both the crypto and fax kind. How are they challenged, verified, revoked? Electronic mediated transactions make sense when systems are double entry (credits and debits) so that each party has their own audit trail. But they seem rather virtual to me for things like transfer of ownership and voting.

Learning about the legalities of digital signatures is on my to do list.

Re: U.S. Arrests Paul Ceglia for Multi-Billion Dollar Scheme to Defraud Facebook

#75
post #71
post #21

A few thoughts: 1. When Ceglia first filed his claims, I called it a "lawsuit full of holes [that was] built up by sensationalist reporting into a supposed major threat to Facebook and to Mr. Zuckerberg" and concluded that, "in the courts, this thing is going nowhere." ( http://news.ycombinator.com/item?id=1537158 ) My sense of this had nothing to do with any fraudulent tampering with evidence as alleged now in the c…

I think there's two villains. It's impossible for both of them to lose, but you can't blame people for being opposed to someone "winning" by being a villain. Why was Zuckerberg going to Craigslist looking for work? Why did Zuckerberg want to do work for "known criminals"? The project Ceglia was trying to set up was an image database. Much like Facebook. I think if Paul Ceglia had a cleaner past and better judgment, h…

Except that this is not about Zuckerberg. Regardless of what Zuckerberg has done or has not done this guy tried to defraud others to the tune of several billion bucks. It doesn't require any other elements than him and his actions.

Re: U.S. Arrests Paul Ceglia for Multi-Billion Dollar Scheme to Defraud Facebook

#76
post #49

Earlier quoted context omitted.

A long time ago I posed md5's to usenet test groups when I wanted to prove I wrote something. You have to worry about people breaking things. Raw MD5 is considered useless today, since there are tools that make two documents with the same MD5. This would not necessarily invalidate all prior MD5s; if you published like that 10 years before people starting breaking MD5, that would be pretty good evidence you really did…

Spoofed MD5s are a vulnerability when you execute software blindly, but the padding is obvious if you examine the source data.

That's no reason not to use a better algorithm. Weaknesses in MD5 are already well enough understood to make it useless for many applications, and weak crypto algorithms only get weaker, as new attacks are discovered and as technology progresses to make a broader range of things feasible.

Re: U.S. Arrests Paul Ceglia for Multi-Billion Dollar Scheme to Defraud Facebook

#77
post #61
post #59

Earlier quoted context omitted.

I can imagine (and therefore we should assume that the attacker can imagine with far more craftiness) several ways of hiding junk in a PDF. E.g. How about in any binary content - embedded fonts, images etc. My big concern is that in this scenario an attacker may have years to create an attack. One small part of designing a security protocol is understanding timeliness constraints.

So just use plain text.

The wordiness of legalese may actually be a place to pad. Also, extraneous terms and clauses that might sound plausible and have no bearing on what's actually being claimed.

Collision attacks are mitigated by careful examination coupled with a forbidding of extraneous data and a skepticism about possibly extraneous data - but I am not comfortable assuming they are defeated by it.

Post reply on HN