Live data from Hacker News

Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

technologyreview.com

41–50 of 117 posts

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#41
Hi there - I'm the one who put up the $50k to bail weev out of jail.[1] (Otherwise he would have had to sit in Essex County Jail during these ~2 years since this started.)

There were some others in line to assist (I live in Europe), but they all feared various forms of retribution/harassment from the FBI/DoJ, so it fell to me (someone with comparatively little to lose, stateside). This only serves to underscore the truly chilling effects of these sorts of governmental abuses of power.

I also host his website, http://freeweev.info, where you can make donations to his case via both Paypal and Bitcoin. (He has various restrictions placed on his use of technology while out on bail.)

Please feel free to contact me directly if you have questions related to his case. Contact info can be found in my profile.

5539 AD00 DE4C 42F3 AFE1 1575 0524 43F4 DF2A 55C2

[1] https://twitter.com/rabite/status/270668883172671489

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#42

From my understanding all you had to do was pass the ICC-ID to a script on AT&T's servers to get back the user data. I can see the court interpreting the ICC-ID as a form of access control since you'd have to guess them similarly to passwords. What isn't quite clear to me is what they did with this data. It seems they reported the hole to AT&T who then fixed it. That's good. It also seems they passed the data off to…

The ICCIDs here are sequential integers. It wasn't brute force, just incrementation. They are not secret and are certainly not access credentials. There were no access controls surrounding the web service in question.

The prosecution is asserting that access to any system without authorization is "access to a protected system" in the legal sense, which is obviously bogus. This would make the Googlebot's operators criminally liable if I put up a site at "johndoessocialsecuritynumber.com".

In fact, authorization is built into HTTP. There were no protections in place surrounding this data. Regardless of what he did with the data, downloading something from a public website is not criminal. (Though irrelevant legally, it's worth noting that he did nothing with the data except shame AT&T.)

(I put up weev's bail and am handling some of his PR while his computer restrictions are in place.)

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#43

This is extremely dangerous. Condemning the whistle blowers results in a much less secure environment, since you'll scare away the white hats, and insecure systems will remain insecure. We need whistle blower protection laws in place, and we need them now.

What's further terrifying is that the courts have made restriction of his use of non-windows non-monitored computers part of his bail conditions - prior to a trial to determine guilt.

A person who's only marketable skill is on the Internet, completely prohibited from using ssh or virtualization, by nothing more than an error-riddled FBI complaint document. (This started prior to the grand jury indictment.) He's been without significant work for over two years as a result.

It's a scary thought that this could happen to any one of us.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#44

How about this. What if we have another section on websites called something like 'Submit a bug' next to 'About,' 'Contact Us' etc. If more and more sites make it easier to report these things to them, hopefully either the error will be fixed or if it is being ignored, the "hacker" will have some kind of proof to claim that he tried to tell the bank to fix their door.

How about this: We don't prosecute people for loading URLs on the public internet first and foremost.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#45

Earlier quoted context omitted.

You can format a link to be something like: http://username:password@members.example.com I wouldn't say that means the account in question is unprotected.

If you are going to nitpick, I will say that this is a feature that relies on browser-support. It's not fundamental to the web. Query-strings however by definition needs to be supported on the server-side. They are a part of the web. They are required for the web to work. Why is "browser-support" relevant? Your example is not supported in MSIE. I also thought it was removed from Chrome (in the name of "simplicity"),…

Huh, I had no idea that feature had been deprecated. I guess it's been a little longer since I used it than I thought.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#46
post #30

Earlier quoted context omitted.

As an information security professional, I see two different issues at play here. First, they got access. They were granted access by the admin who did not lock down the server. I am not a lawyer, but I see the unauthenticated web server, no matter how much of a mistake, as being implicit permission to access the site. A house, by default, implies privacy. A web server is more of a business in this metaphor. If the d…

You don't live in a world governed by machines and pure logic. You live in a world governed by human beings and their nature. You have the capacity to recognize where you should be and where you shouldn't be. What you should be seeing and what you shouldn't be seeing. Right from wrong. > A web server is more of a business in this metaphor. If the door is open and the lights are on, it's implied you can come in and lo…

The problem with metaphors is that they only resemble what they are describing. They'll always be imperfect. The problem with web servers is that anything that is public-facing is just that. Security through obscurity is no security at all.

Like I said, the guy went too far. But visiting a public-facing website is not a crime, no matter how you happen to discover the URL. There's no sign on the door saying "keep out", even though the server is more than capable of displaying one. Do you have a right to walk into any business, or walk into their storage space? No, but any reasonable person (notice I keep using this phrase? It's going to come up in court) would assume if the lights are on and the door is open, you can walk in. You might be mistaken, and a clerk might show you out. Intent is a critical factor. Like I said, the guy went too far. He didn't enter by mistake, though someone could have. He entered with the intent of making unauthorized copies of private data. Walking into a store's storage space isn't illegal, but a reasonable person would know that taking pictures of customer data is.

It's not illegal to visit any public facing Internet site. It is illegal to make unauthorized copies of restricted data. It's also against The company is hugely to blame in this situation for leaking private information. So is the guy who broke the law by making unauthorized copies of this private information. I support him having criminal charges filed against him. My point was that there are two issues at hand, one illegal and one perfectly within the law. Implied consent at odds with intent. It should be an interesting case.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#48
post #30

Earlier quoted context omitted.

You don't live in a world governed by machines and pure logic. You live in a world governed by human beings and their nature. You have the capacity to recognize where you should be and where you shouldn't be. What you should be seeing and what you shouldn't be seeing. Right from wrong. > A web server is more of a business in this metaphor. If the door is open and the lights are on, it's implied you can come in and lo…

> If these clowns don't know how to secure their own damn servers, let them pay the price that will be exacted by less scrupulous individuals. AT&T will not be affected whatsoever by a security breech, only those people whose information is leaked will be affected. The whole point of a white hat is to show this vulnerability and have it fixed before damage is done by someone with malicious intent. > That's how the fr…

> AT&T will not be affected whatsoever by a security breech

That's naive. If my emails become public, trust me, I'll cancel my AT&T service. If AT&T becomes known for airing people's dirty laundry, they will quickly bleed customers.

> Further, it is very clear that companies make mistakes all the time with configuration their servers and tools in ways that makes data leaks and theft possible.

Yes, they do. And in cases where individuals are hurt, those individuals sue the company involved. Either individually or collectively. Those companies do pay for their mistakes.

Except, of course, in cases where no actual measurable harm was done by the security breach.

> We should demand that this flaws be exposed and fixed ASAP, there is nothing to be gained here by harassing those doing that exposure.

There is a reason we vest the authority to enforce laws and pursue criminals in only a select few trained individuals. It's naive to think random teenagers have a fine grasp of the law, civil rights, and a well-tuned moral compass.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#49
post #36
post #9

We live in a tech-filled world without a reliable means for responsible disclosure, no way to hold a company accountable for reacting to attempts of responsible disclosure, and any whistle-blowers are immediately branded as "criminals" and "hackers". This whole process, or lack thereof, needs some serious disruption. Edit: My comment is intended to be a general observation and not specifically about this case

>> We live in a tech-filled world without a reliable means for responsible disclosure There are many avenues for responsible disclosure, Google that phrase.

I guess that's why companies like Google, Facebook, Mozilla or Microsoft go to great lengths to publicize their disclosure platforms? This endless stream of avenues exist yet these companies feel the need to create their own? Right.

CERT-CC is the closest we have and that does little to ensure things are actually resolved nor does it afford any sort of protection to the reporter.

Care to link to one of these "many avenues" instead of just pointing me to Google?

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#50
post #30

Earlier quoted context omitted.

You don't live in a world governed by machines and pure logic. You live in a world governed by human beings and their nature. You have the capacity to recognize where you should be and where you shouldn't be. What you should be seeing and what you shouldn't be seeing. Right from wrong. > A web server is more of a business in this metaphor. If the door is open and the lights are on, it's implied you can come in and lo…

The problem with metaphors is that they only resemble what they are describing. They'll always be imperfect. The problem with web servers is that anything that is public-facing is just that. Security through obscurity is no security at all. Like I said, the guy went too far. But visiting a public-facing website is not a crime, no matter how you happen to discover the URL. There's no sign on the door saying "keep out"…

> Intent is a critical factor. Like I said, the guy went too far. He didn't enter by mistake, though someone could have. He entered with the intent of making unauthorized copies of private data.

We're in agreement here. I think we're both making the same point. Intent is the key here.

The problem is that if you just consider servers, configurations, permissions, and other technical aspects ... intent doesn't enter the picture. That's the wrong way to think about this.

Post reply on HN