Live data from Hacker News

iPad Hack Statement Of Responsibility

techcrunch.com

11–20 of 119 posts

Re: iPad Hack Statement Of Responsibility

#11

When you hear of horrible stores like that of Aaron Swartz and the author of this insightful article Andrew Auernheimer it really paints a picture of just how afraid the US government is of the Internet. People lament China for their great firewall and control over its people and yet the US is starting to look more and more like China everyday. This is how revolts against governments start, absurd laws and persecutio…

eh, this article doesn't paint the whole story.

Re: iPad Hack Statement Of Responsibility

#12
post #5

If anyone thinks weev deserves any sympathy, you don't know the full story. weev had malicious intent and wanted to harm AT&T by exposing users data. Instead of doing anything remotely rational he took all the data and wanted to sell it. Laws take into account indent (mens rea) and there is a lot of evidence in his indictment that he wanted to profit off this act. He shouldn't be compared to Aaron Swartz

People that describe themselves as trolls are generally bigoted idiots and I feel no sympathy. I'm sorry if that's a stereotype but I can't help myself, the internet hasn't been nice to me.

Re: iPad Hack Statement Of Responsibility

#14

From Wikipedia: "On 20 November 2012, Auernheimer was found guilty of one count of identity fraud and one count of conspiracy to access a computer without authorization. Auernheimer tweeted that he would appeal the ruling." Is the problem that the laws themselves are terrible, or that the laws are being misused by overzealous prosecutors? I mean, if changing a public URL is considered "conspiracy to access a computer…

The problem is that there is little consensus on what the boundaries in digital space should mean. Law makers, not without a certain logic, approach things from the principles of private property. Is changing a public URL considered "conspiracy to access a computer without authorization?" Well why would you do it, intentionally? Would you jiggle my door handle to see if that would unlock it? And if it was a crappy lock and jiggling it did unlock it, would it be unauthorized access to my property if you then walked in the door?

There is a line of thinking in the tech community that accessing data you're not supposed to access is only "bad" if you do something "bad" with it. But in meat space, we enforce fences in their own right, whether or not there is any other criminal activity involved. Arguably, doing so makes the larger problem of ensuring that their isn't associated criminal activity more tractable.

Actually, real world example: over the weekend someone stole my phone out of my (unlocked) car while it was parked in my apartment building's garage. Now, let's say he hadn't stolen the phone. Just rifled through the glove box and center console. No harm no foul, right? Of course not. We presume there is no good reason to be looking through someone else's car, even if you fully intend not to take anything.

Now, that doesn't mean we should treat digital boundaries the same as physical ones, but I don't think it's as obvious as some people in the tech community make it out to be that there shouldn't be penalties (of some sort--the magnitude of such penalties is a whole another debate) for intentionally violating digital boundaries, regardless of how well they are protected.

Re: iPad Hack Statement Of Responsibility

#15

I wasn't sure whether this is a spoof or not. Is he serious when he writes - "I did this because I despised people I think are unjustly wealthy and wanted to embarass them. " That was his admitted rationale - that he was seeking to embarrass people he despised because they were "unjustly wealthy?"

There are plenty of ways to embarrass people that are legal, and possibly moral. The question is: was this one of them?

Re: iPad Hack Statement Of Responsibility

#16
post #5

If anyone thinks weev deserves any sympathy, you don't know the full story. weev had malicious intent and wanted to harm AT&T by exposing users data. Instead of doing anything remotely rational he took all the data and wanted to sell it. Laws take into account indent (mens rea) and there is a lot of evidence in his indictment that he wanted to profit off this act. He shouldn't be compared to Aaron Swartz

There is no indication he wanted to sell it. He wanted to embarrass AT&T, and that isn't a crime. Changing the number in a URL is not identity fraud.

This is exactly the same thing that was thrown at Aaron, even if you don't find the target as sympathetic.

"He that would make his own liberty secure, must guard even his enemy from oppression; for if he violates this duty, he establishes a precedent that will reach to himself." -Thomas Paine

Re: iPad Hack Statement Of Responsibility

#17

When you hear of horrible stores like that of Aaron Swartz and the author of this insightful article Andrew Auernheimer it really paints a picture of just how afraid the US government is of the Internet. People lament China for their great firewall and control over its people and yet the US is starting to look more and more like China everyday. This is how revolts against governments start, absurd laws and persecutio…

eh, this article doesn't paint the whole story.

It doesn't need to paint the whole story. If the dude committed any overly serious crime, he'd still be in custody right now awaiting sentencing. They don't let you out on bail if you're a serious offender. I'm sure there is more than meets the eye here, but given the the spotlight being shined upon hacking cases like this of late, it's not hard to believe that what this guy says isn't what went down. Andrew was obviously a troll in every sense of the word, reckless and irresponsible but by no means did he have to bypass any security measures to get the email addresses. I would argue it's the equivalent of a bank leaving it's doors unlocked, alarm systems deactivated and lights on and someone walking in and taking money, then the bank complaining they got robbed, but this situation is blown way out of proportion and a metaphor like that would be over the top.

What he did is no different to someone writing a script that scours the web looking for email addresses (a tactic spammers have used and gotten away with for years), except no trickery was required to get the addresses AT&T were handing them over unknowingly without recourse. This can't even be considered a hack, more of an exploit if anything.

The stupidity of wanting to embarrass was no doubt a really stupid move to make, but definitely not some security defying hack. People shouldn't be jailed for acting like idiots, AT&T should be the ones being scalded for allowing this to happen in the first place. A company has a responsibility to keep customer data safe, AT&T should be no exception to that rule.

Re: iPad Hack Statement Of Responsibility

#18
post #5

If anyone thinks weev deserves any sympathy, you don't know the full story. weev had malicious intent and wanted to harm AT&T by exposing users data. Instead of doing anything remotely rational he took all the data and wanted to sell it. Laws take into account indent (mens rea) and there is a lot of evidence in his indictment that he wanted to profit off this act. He shouldn't be compared to Aaron Swartz

Yeah but prison time, followed by secret service, not allowed to use computers, not allowed to take jobs... for what, compiling a list of email addresses that an public API was happily returning to him? Despite his questionable handling of the situation, I don't support that kind of draconian punishment.

Re: iPad Hack Statement Of Responsibility

#19
post #5

If anyone thinks weev deserves any sympathy, you don't know the full story. weev had malicious intent and wanted to harm AT&T by exposing users data. Instead of doing anything remotely rational he took all the data and wanted to sell it. Laws take into account indent (mens rea) and there is a lot of evidence in his indictment that he wanted to profit off this act. He shouldn't be compared to Aaron Swartz

There is no indication he wanted to sell it. He wanted to embarrass AT&T, and that isn't a crime. Changing the number in a URL is not identity fraud. This is exactly the same thing that was thrown at Aaron, even if you don't find the target as sympathetic. "He that would make his own liberty secure, must guard even his enemy from oppression; for if he violates this duty, he establishes a precedent that will reach to…

That does not appear to be true. From the Ars Technica article on the case:

"Auernheimer then helped Spitler refine his script to harvest a large number of valid e-mail addresses of iPad 3G users, suggesting that a huge data set would be needed to "direct market iPad accessories" or start a "future massive phishing operation," noting that the data breach would be "huge media news."

Re: iPad Hack Statement Of Responsibility

#20
post #5

If anyone thinks weev deserves any sympathy, you don't know the full story. weev had malicious intent and wanted to harm AT&T by exposing users data. Instead of doing anything remotely rational he took all the data and wanted to sell it. Laws take into account indent (mens rea) and there is a lot of evidence in his indictment that he wanted to profit off this act. He shouldn't be compared to Aaron Swartz

There is no indication he wanted to sell it. He wanted to embarrass AT&T, and that isn't a crime. Changing the number in a URL is not identity fraud. This is exactly the same thing that was thrown at Aaron, even if you don't find the target as sympathetic. "He that would make his own liberty secure, must guard even his enemy from oppression; for if he violates this duty, he establishes a precedent that will reach to…

[deleted]
Post reply on HN