Live data from Hacker News

Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

technologyreview.com

91–100 of 117 posts

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#91
post #36

Earlier quoted context omitted.

>> We live in a tech-filled world without a reliable means for responsible disclosure There are many avenues for responsible disclosure, Google that phrase.

As far as I know, following responsible disclosure practices does not waive any legal liability. It may make you look professional, but if someone who is friends with the FBI wants to fuck you, they can still fuck you.

Following the published disclosure guidelines that Google and Facebook created will in fact prevent the FBI from "fucking you", because any lawyer in the world can read the plain meaning of the statutes point out that a reasonable person would believe they had permission to conduct tests.

On the other hand, if you're dealing with an application for which you don't have any written permission to test, just stop. You are not entitled to conduct your own security tests of other people's applications. Leave them alone.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#92
post #90
post #83

Earlier quoted context omitted.

Those are the things they DISCUSSED doing - what ACTUALLY HAPPENED was that they sent excerpts to the media and deleted their own copies. It looks bad but I think it's more important to focus on the fact that they ended up doing the Right Thing with the data instead of fucking anyone directly - even when distinctly aware of the various opportunities available for misusing that data. Many greyhat researchers don't hav…

It's debatable whether or not they did the right thing. Many security researchers would say that the right thing would have been telling AT&T first, giving AT&T a reasonable amount of time to respond, and only then going to the media. This also speaks to motives. At the end of the day, I don't really care whether or not weev is a good guy. I do think it's important to be really clear about why he does the things he d…

I don't see 'sneak doing anything but saying that A.A. was hit very hard by the Justice Department, and that he deserves the best possible defense and, in the meantime, the least possible disruption to his life. I wouldn't have coughed up bail money, but I admire the hell out of 'sneak for doing that.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#93
post #41

Hi there - I'm the one who put up the $50k to bail weev out of jail.[1] (Otherwise he would have had to sit in Essex County Jail during these ~2 years since this started.) There were some others in line to assist (I live in Europe), but they all feared various forms of retribution/harassment from the FBI/DoJ, so it fell to me (someone with comparatively little to lose, stateside). This only serves to underscore the t…

I'm glad someone is taking on the task of defending Weev because the charges they have against him are ridiculous and stupid.

Sadly, Weev's nature is that of a rattlesnake, and he's basically burned every bridge he could on his way here. Thus, the EFF will have nothing to do with him.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#94
post #91

Earlier quoted context omitted.

As far as I know, following responsible disclosure practices does not waive any legal liability. It may make you look professional, but if someone who is friends with the FBI wants to fuck you, they can still fuck you.

Following the published disclosure guidelines that Google and Facebook created will in fact prevent the FBI from "fucking you", because any lawyer in the world can read the plain meaning of the statutes point out that a reasonable person would believe they had permission to conduct tests. On the other hand, if you're dealing with an application for which you don't have any written permission to test, just stop. You a…

> You are not entitled to conduct your own security tests of other people's applications. Leave them alone.

Your attitude is part of the problem and why we need a solution.

Let's create an analogy: I drop off my daughter at daycare, I've entrusted this place of business with something vital to me, as have numerous other customers. I get off work early to go pick up my daughter, upon arrival, I find the guardian eating lunch in an adjacent room and the children are left completely unattended. This is clearly a problem on numerous levels.

So what do I do? Do I politely inform the administration of the issue and hope they will fix things immediately? What if they blow me off and do not discipline nor change policy? Do I withdraw my child's enrollment and just blindly hope that other customers know of their utter disregard for the trust we've placed in them? Do I report them to the police or child protective services? Do I picket the business and attempt to inform other people of the issues? What if informing the public simultaneously informs some criminals of the ability to do some baby snatching?

In this scenario, a parent actually has some legal recourse options to ensure the problem is fixed. The issue in web security is there is no governing authority to report the problem to and if we take our findings public, we place other customer's information at risk and put ourselves in a position of legal risk as well. We get branded a "criminal hacker" and find ourselves off to jail.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#95
post #94
post #91

Earlier quoted context omitted.

Following the published disclosure guidelines that Google and Facebook created will in fact prevent the FBI from "fucking you", because any lawyer in the world can read the plain meaning of the statutes point out that a reasonable person would believe they had permission to conduct tests. On the other hand, if you're dealing with an application for which you don't have any written permission to test, just stop. You a…

> You are not entitled to conduct your own security tests of other people's applications. Leave them alone. Your attitude is part of the problem and why we need a solution. Let's create an analogy: I drop off my daughter at daycare, I've entrusted this place of business with something vital to me, as have numerous other customers. I get off work early to go pick up my daughter, upon arrival, I find the guardian eatin…

Two things.

First, you're responding to a factual argument with an argument about my attitude. It is not "my attitude" that people "shouldn't" be entitled to test applications. It is a fact that they are not allowed to do that. Unauthorized access to computer systems, which has a broad but actually very straightforward definition, is unlawful. If you cause damages when you do it, you're liable for civil damages. If you attempt in any way to profit from having done it, you're liable for a felony charge.

Second, arguing about this stuff by analogy is perilous. You can see that here, because it's immediately obvious that observing your child's caretaker eating lunch is not comparable to breaking into a web application to steal a database over the span of several days. To attempt to equalize the analogy, imagine that instead of simply observing your child's caretaker, you instead break into that caretaker's residence or place of work. You've now committed a felony.

I am for many obvious reasons pro- security testing, and I'm happy to speak glowingly of the companies that have set up policies to make it safer for researchers to test their sites. In advice I've provided on HN and to startups, I've consistently told companies to create pages to thank security researchers.

Having said all that: if you don't have permission to test someone's web app, don't do it. The law very reasonably says that if a company doesn't want to submit itself to unauthorized intrusive testing by strangers, it is entitled to treat its applications, its servers, and the data it holds as private property. Not every case in which a stranger pokes for flaws in someone's app will be open- and- shut, and that's for the best too. But the rule of thumb is very simple: leave other people's apps alone.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#96
post #94
post #91

Earlier quoted context omitted.

Following the published disclosure guidelines that Google and Facebook created will in fact prevent the FBI from "fucking you", because any lawyer in the world can read the plain meaning of the statutes point out that a reasonable person would believe they had permission to conduct tests. On the other hand, if you're dealing with an application for which you don't have any written permission to test, just stop. You a…

> You are not entitled to conduct your own security tests of other people's applications. Leave them alone. Your attitude is part of the problem and why we need a solution. Let's create an analogy: I drop off my daughter at daycare, I've entrusted this place of business with something vital to me, as have numerous other customers. I get off work early to go pick up my daughter, upon arrival, I find the guardian eatin…

"I showed up early and saw something really bad" is hardly the same category as "I decided to test the security of someone else's webapp." If weev did nothing and randomly got someone else's private data sent to him (and people have reported similar incidents here on HN), that would be similar.

Is the list of questions in your 4th paragraph meant to say that weev had no hope to get this fixed besides writing a tool that pulled down the information of thousands of users and then taking it to the press?

We get branded a "criminal hacker" and find ourselves off to jail.

It's not that hard to avoid landing in jail for computer crimes.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#97
post #92
post #90

Earlier quoted context omitted.

It's debatable whether or not they did the right thing. Many security researchers would say that the right thing would have been telling AT&T first, giving AT&T a reasonable amount of time to respond, and only then going to the media. This also speaks to motives. At the end of the day, I don't really care whether or not weev is a good guy. I do think it's important to be really clear about why he does the things he d…

I don't see 'sneak doing anything but saying that A.A. was hit very hard by the Justice Department, and that he deserves the best possible defense and, in the meantime, the least possible disruption to his life. I wouldn't have coughed up bail money, but I admire the hell out of 'sneak for doing that.

He did also claim that weev did the Right Thing. I don't think that assertion is clearly accurate.

It's entirely possible that I'm focusing too much on motive; possibly the end effect (hole fixed) matters more than why weev did it in the first place.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#98
post #82

Earlier quoted context omitted.

If you've never deployed software without security flaws, it means you have never deployed software.

Sure, but why should who makes the software bear no responsibility? If a building is found to have a flaw the architect or an engineer are who get questions, not whoever noticed the flaw.

The flaws in architecture are well-understood and there are rarely-changing building codes to describe exactly what should and should not happen.

Software does not exist in any such stable world. There can be two pieces of software, each perfectly legitimate and doing exactly what they intend, that when both are present format a customer's hard drive. Who does the customer sue then?

If you want to make developers responsible, I won't personally be hurt much, since I can make a shitload of money finding vulnerabilities in other people's code (and have done so in the past). The lawyers will make lots of money, too, as we have jury trials to figure out whether that SQL injection was really negligent or not.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#99
post #43

This is extremely dangerous. Condemning the whistle blowers results in a much less secure environment, since you'll scare away the white hats, and insecure systems will remain insecure. We need whistle blower protection laws in place, and we need them now.

What's further terrifying is that the courts have made restriction of his use of non-windows non-monitored computers part of his bail conditions - prior to a trial to determine guilt. A person who's only marketable skill is on the Internet, completely prohibited from using ssh or virtualization, by nothing more than an error-riddled FBI complaint document. (This started prior to the grand jury indictment.) He's been…

>What's further terrifying is that the courts have made restriction of his use of non-windows non-monitored computers part of his bail conditions - prior to a trial to determine guilt.

How does he use a telephone? Or a suitably advanced toaster?

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#100
post #95
post #94

Earlier quoted context omitted.

> You are not entitled to conduct your own security tests of other people's applications. Leave them alone. Your attitude is part of the problem and why we need a solution. Let's create an analogy: I drop off my daughter at daycare, I've entrusted this place of business with something vital to me, as have numerous other customers. I get off work early to go pick up my daughter, upon arrival, I find the guardian eatin…

Two things. First, you're responding to a factual argument with an argument about my attitude. It is not "my attitude" that people "shouldn't" be entitled to test applications. It is a fact that they are not allowed to do that. Unauthorized access to computer systems, which has a broad but actually very straightforward definition, is unlawful. If you cause damages when you do it, you're liable for civil damages. If y…

(To be clear, I'm speaking more broadly about the topic and absolutely not condoning the weev's alleged actions. Lack of responsible disclosure, discussion of profiting from the flaw and exploiting it far beyond simple validation tests are all going to make it very difficult for him.)

Observing sequential identifiers in a URL and validating a gaping security hole is hardly something I'd classify along the lines of "stealing a database" nor should it be considered "unauthorized access", however the judicial system clearly feels different and that's the sort of changes I'm advocating that need to be adjusted.

Of course, discussing legislation changes that would allow anyone to execute security testing is probably not a very lucrative topic with the founder of a company that provides security research & testing.

Post reply on HN