Live data from Hacker News

Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

technologyreview.com

101–110 of 117 posts

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#101
post #89
post #85

Earlier quoted context omitted.

Sergey Bratus[1] (of Langsec[2] fame) testified as an expert witness for the defense in this very way within the last few days. [1] http://www.cs.dartmouth.edu/~sergey/ [2] http://www.cs.dartmouth.edu/~sergey/langsec/

Do you really buy this line of argument? How many banking applications configure themselves so that they rely on the intended meanings of HTTP verbs and authorization headers as their primary overt security mechanism? And of those, how many do so correctly? I get why Bratus would testify. The defendant here needs all the help he can get and is morally entitled to the best case he can possibly present. I respect and a…

I do. If there is any crime here (I don't think there is even one, FYI) it's AT&T not taking adequate measures to safeguard their customers' PII.

I don't think trafficking in any information should be a crime, though (unless it's the government - an asymmetry is necessary there), so I don't think a criminal trial is in any way justified.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#102
post #100
post #95

Earlier quoted context omitted.

Two things. First, you're responding to a factual argument with an argument about my attitude. It is not "my attitude" that people "shouldn't" be entitled to test applications. It is a fact that they are not allowed to do that. Unauthorized access to computer systems, which has a broad but actually very straightforward definition, is unlawful. If you cause damages when you do it, you're liable for civil damages. If y…

(To be clear, I'm speaking more broadly about the topic and absolutely not condoning the weev's alleged actions. Lack of responsible disclosure, discussion of profiting from the flaw and exploiting it far beyond simple validation tests are all going to make it very difficult for him.) Observing sequential identifiers in a URL and validating a gaping security hole is hardly something I'd classify along the lines of "s…

A.A. and his alleged coconspirator may be exonerated, so maybe you're right. But using a flaw like this to download 100,000 email addresses, and then select from those addresses those of prominent members of the media to do outreach for a PR campaign, all the while talking on IRC about selling the addresses to spammers --- that's something more than simply observing increasing numeric IDs.

Your last sentence is needlessly and pointlessly hostile. If I was arguing out of personal interest, I wouldn't be recommending that companies pre-consent to having strangers test their web apps by setting up thank-you pages, now would I?

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#103
post #30

Earlier quoted context omitted.

You don't live in a world governed by machines and pure logic. You live in a world governed by human beings and their nature. You have the capacity to recognize where you should be and where you shouldn't be. What you should be seeing and what you shouldn't be seeing. Right from wrong. > A web server is more of a business in this metaphor. If the door is open and the lights are on, it's implied you can come in and lo…

The problem with metaphors is that they only resemble what they are describing. They'll always be imperfect. The problem with web servers is that anything that is public-facing is just that. Security through obscurity is no security at all. Like I said, the guy went too far. But visiting a public-facing website is not a crime, no matter how you happen to discover the URL. There's no sign on the door saying "keep out"…

He demonstrated a proof of concept, collected data, and went to journalists. Cherry picking irc logs for things for possible uses of the data is weak because they have a weak case.

Arguing about methods of responsible disclosure, a very dead horse that has been beaten to dust, seems like a waste of time and not really relevant.

This is just the endgame of the chilling effect of arresting and hounding researchers which has been going strong ever since 2001 http://news.cnet.com/2100-1001-270082.html

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#104
post #100
post #95

Earlier quoted context omitted.

Two things. First, you're responding to a factual argument with an argument about my attitude. It is not "my attitude" that people "shouldn't" be entitled to test applications. It is a fact that they are not allowed to do that. Unauthorized access to computer systems, which has a broad but actually very straightforward definition, is unlawful. If you cause damages when you do it, you're liable for civil damages. If y…

(To be clear, I'm speaking more broadly about the topic and absolutely not condoning the weev's alleged actions. Lack of responsible disclosure, discussion of profiting from the flaw and exploiting it far beyond simple validation tests are all going to make it very difficult for him.) Observing sequential identifiers in a URL and validating a gaping security hole is hardly something I'd classify along the lines of "s…

That last sentence is incredibly lame. I've had problems with 'tptacek (from an incident several years ago that I'm finally over) but he argues for security policies that he believes work, not those that are in his interest.

A wild-west attitude, with every man for himself, no-holds-barred, no-legal-resource-when-you-are-hacked is the best possible thing for security people, who would be kingmakers in such a universe.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#105
post #100

Earlier quoted context omitted.

(To be clear, I'm speaking more broadly about the topic and absolutely not condoning the weev's alleged actions. Lack of responsible disclosure, discussion of profiting from the flaw and exploiting it far beyond simple validation tests are all going to make it very difficult for him.) Observing sequential identifiers in a URL and validating a gaping security hole is hardly something I'd classify along the lines of "s…

That last sentence is incredibly lame. I've had problems with 'tptacek (from an incident several years ago that I'm finally over) but he argues for security policies that he believes work, not those that are in his interest. A wild-west attitude, with every man for himself, no-holds-barred, no-legal-resource-when-you-are-hacked is the best possible thing for security people, who would be kingmakers in such a universe…

The security field in such a universe would be a gigantic, insanely lucrative shakedown racket. "I can help harden your systems against attacks — or I can just steal your customer database and sell their info to these nice Russian gentlemen. Whichever you prefer."

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#106
post #65

Bah, more weev hagiography? He's not a whistle blower, he's a troll. Look: first off, he didn't tell AT&T about the hack, he told a bunch of news organizations. See http://www.forbes.com/sites/firewall/2010/06/09/atts-ipad-ha... for details. "we did a benefit analysis and decided they could take our story viral the fastest." One of those organizations presumably told AT&T; all AT&T has ever said is that they learned…

Weev is different. That's for sure. But what's at stake here is bigger than him. Anyone can be sued for going to a damn URL. That's the real problem here (as well as a myriad of others).

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#107
post #89
post #85

Earlier quoted context omitted.

Sergey Bratus[1] (of Langsec[2] fame) testified as an expert witness for the defense in this very way within the last few days. [1] http://www.cs.dartmouth.edu/~sergey/ [2] http://www.cs.dartmouth.edu/~sergey/langsec/

Do you really buy this line of argument? How many banking applications configure themselves so that they rely on the intended meanings of HTTP verbs and authorization headers as their primary overt security mechanism? And of those, how many do so correctly? I get why Bratus would testify. The defendant here needs all the help he can get and is morally entitled to the best case he can possibly present. I respect and a…

I think it's reasonable for them to argue that AT&T's server's willingness to give them the e-mail addresses means that obtaining the addresses was not illegal, and that despite mulling over the darker possibilities available to them, by choosing not to put the e-mail addresses to illegal use they committed no crime. They could argue that they should not be convicted of conspiracy because they ultimately decided not to abuse the list of addresses.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#108
post #89

Earlier quoted context omitted.

Do you really buy this line of argument? How many banking applications configure themselves so that they rely on the intended meanings of HTTP verbs and authorization headers as their primary overt security mechanism? And of those, how many do so correctly? I get why Bratus would testify. The defendant here needs all the help he can get and is morally entitled to the best case he can possibly present. I respect and a…

I think it's reasonable for them to argue that AT&T's server's willingness to give them the e-mail addresses means that obtaining the addresses was not illegal, and that despite mulling over the darker possibilities available to them, by choosing not to put the e-mail addresses to illegal use they committed no crime. They could argue that they should not be convicted of conspiracy because they ultimately decided not…

I would like it to be harder than it seems to be to prove conspiracy to commit fraud.

I don't think I'd like it to be harder than it seems to be to prove unauthorized access.

I know that's the opposite of what most nerds like me want, but I think we're well served by a very broad definition of unauthorized access, and we're poorly served by vague conspiracy laws in more places than just online.

Note that under the US Code, you need both elements. Just plain unauthorized access isn't a federal crime; you need an intent to defraud.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#109

Earlier quoted context omitted.

I think it's reasonable for them to argue that AT&T's server's willingness to give them the e-mail addresses means that obtaining the addresses was not illegal, and that despite mulling over the darker possibilities available to them, by choosing not to put the e-mail addresses to illegal use they committed no crime. They could argue that they should not be convicted of conspiracy because they ultimately decided not…

I would like it to be harder than it seems to be to prove conspiracy to commit fraud. I don't think I'd like it to be harder than it seems to be to prove unauthorized access. I know that's the opposite of what most nerds like me want, but I think we're well served by a very broad definition of unauthorized access, and we're poorly served by vague conspiracy laws in more places than just online. Note that under the US…

I know that's the opposite of what most nerds like me want, but I think we're well served by a very broad definition of unauthorized access, and we're poorly served by vague conspiracy laws in more places than just online.

I do agree with you regarding conspiracy, but you are right that I would in principle prefer to have every Internet-facing system as robustly secured as if it had been independently reviewed by you, cpercival, and the people who wrote the space shuttle's software. A small part of the reason I want this is so that absolutely anybody can confidently write and deploy scraping software that collects and analyzes information in new ways (e.g. IBM Watson, better search engines, or some other as yet undiscovered idea).

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#110
post #59

Earlier quoted context omitted.

I understand where you're coming from, but that logic doesn't really work, does it? I can tell you that somewhere there is indeed an application that will respond to an unauthenticated GET request by transferring funds between accounts. You and I both know that. Deliberately loading that URL on planet Earth to effect funds transfers will get you charged. So it's obviously more complicated than just "any unauthenticat…

That sounds like a pretty dubious assertion to me, especially given the nature of $$$. Care to provide some evidence?

I am currently employed in the banking industry, and live in Charlotte, NC–a major banking center. I can confirm that bugs of this nature exist, and are in fact, not even uncommon.
Post reply on HN