Earlier quoted context omitted.
Sergey Bratus[1] (of Langsec[2] fame) testified as an expert witness for the defense in this very way within the last few days. [1] http://www.cs.dartmouth.edu/~sergey/ [2] http://www.cs.dartmouth.edu/~sergey/langsec/
Do you really buy this line of argument? How many banking applications configure themselves so that they rely on the intended meanings of HTTP verbs and authorization headers as their primary overt security mechanism? And of those, how many do so correctly? I get why Bratus would testify. The defendant here needs all the help he can get and is morally entitled to the best case he can possibly present. I respect and a…
I don't think trafficking in any information should be a crime, though (unless it's the government - an asymmetry is necessary there), so I don't think a criminal trial is in any way justified.