Live data from Hacker News

Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

technologyreview.com

1–10 of 117 posts

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#2
The article states

"Weev and a fellow hacker who originally uncovered AT&T’s mistake and collected the e-mails didn’t ask the company for permission to access the Web addresses that shared iPad users’ private information"

I really don't see how this argument holds up.

From a technical point of view the very nature of HTTP includes asking for permission. You send a request "Please can I see the information at this URL" If the organisation running the server does not give that permission, it should not serve the data.

These charges seem pretty odd to me, hopefully it gets resolved in a sensible manner.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#3
post #2

The article states "Weev and a fellow hacker who originally uncovered AT&T’s mistake and collected the e-mails didn’t ask the company for permission to access the Web addresses that shared iPad users’ private information" I really don't see how this argument holds up. From a technical point of view the very nature of HTTP includes asking for permission. You send a request "Please can I see the information at this URL…

>> required visiting an AT&T web address with a particular – and easy to guess – code tagged onto the end.

How is this different than a password?

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#4
post #2

The article states "Weev and a fellow hacker who originally uncovered AT&T’s mistake and collected the e-mails didn’t ask the company for permission to access the Web addresses that shared iPad users’ private information" I really don't see how this argument holds up. From a technical point of view the very nature of HTTP includes asking for permission. You send a request "Please can I see the information at this URL…

> From a technical point of view the very nature of HTTP includes asking for permission.

A web server isn't an agent of the company and has no capacity to grant or deny permission.

Think of it as a security system you install in your home. Now, if the security system is malfunctioning and you notice that it is malfunctioning ... do you call up the owner and let them know or do you go inside and look through their stuff? If you go inside and look through their stuff, it's trespassing.

Obviously the two scenarios aren't the same, but I'd imagine that's the logic used in the argument.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#5
post #2

The article states "Weev and a fellow hacker who originally uncovered AT&T’s mistake and collected the e-mails didn’t ask the company for permission to access the Web addresses that shared iPad users’ private information" I really don't see how this argument holds up. From a technical point of view the very nature of HTTP includes asking for permission. You send a request "Please can I see the information at this URL…

Yes, the 403 status code exists for a reason!

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#6
post #4
post #2

The article states "Weev and a fellow hacker who originally uncovered AT&T’s mistake and collected the e-mails didn’t ask the company for permission to access the Web addresses that shared iPad users’ private information" I really don't see how this argument holds up. From a technical point of view the very nature of HTTP includes asking for permission. You send a request "Please can I see the information at this URL…

> From a technical point of view the very nature of HTTP includes asking for permission. A web server isn't an agent of the company and has no capacity to grant or deny permission. Think of it as a security system you install in your home. Now, if the security system is malfunctioning and you notice that it is malfunctioning ... do you call up the owner and let them know or do you go inside and look through their stu…

A web server isn't an agent of the company and has no capacity to grant or deny permission.

A web server certainly can grant or deny permission, but it seems that this one didn't.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#7
post #6
post #4

Earlier quoted context omitted.

> From a technical point of view the very nature of HTTP includes asking for permission. A web server isn't an agent of the company and has no capacity to grant or deny permission. Think of it as a security system you install in your home. Now, if the security system is malfunctioning and you notice that it is malfunctioning ... do you call up the owner and let them know or do you go inside and look through their stu…

A web server isn't an agent of the company and has no capacity to grant or deny permission. A web server certainly can grant or deny permission, but it seems that this one didn't.

That is perhaps not the same as "capacity" in the legal sense. Is a web-server legally competent?

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#8
post #2

The article states "Weev and a fellow hacker who originally uncovered AT&T’s mistake and collected the e-mails didn’t ask the company for permission to access the Web addresses that shared iPad users’ private information" I really don't see how this argument holds up. From a technical point of view the very nature of HTTP includes asking for permission. You send a request "Please can I see the information at this URL…

>> required visiting an AT&T web address with a particular – and easy to guess – code tagged onto the end. How is this different than a password?

I guess this is exactly the thing that the court must decide on: whether guessing that code can be considered as a circumvention of security measures or not.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#9
We live in a tech-filled world without a reliable means for responsible disclosure, no way to hold a company accountable for reacting to attempts of responsible disclosure, and any whistle-blowers are immediately branded as "criminals" and "hackers".

This whole process, or lack thereof, needs some serious disruption.

Edit: My comment is intended to be a general observation and not specifically about this case

Post reply on HN