Live data from Hacker News

iPad Hack Statement Of Responsibility

techcrunch.com

41–50 of 119 posts

Re: iPad Hack Statement Of Responsibility

#41
post #30

Earlier quoted context omitted.

Punishing people for purposefully disclosing private information that is clearly not intended to be public is the path to "everyone touching a computer will be in trouble soon?" You act as if he was just playing around on his own computer minding his own business when the big bad government broke his door down. In Texas, they don't convict homeowners who shoot trick or treaters trespassing on private property: http:/…

Wasn't it just email addresses that he published? I'm all for protecting personal information, but I find it hard to believe it's a felony for collecting a list of email addresses.

He didn't even publish it. He reported it to the media, so they saw it in order to verify, and he deleted the list.

Re: iPad Hack Statement Of Responsibility

#42
post #14

From Wikipedia: "On 20 November 2012, Auernheimer was found guilty of one count of identity fraud and one count of conspiracy to access a computer without authorization. Auernheimer tweeted that he would appeal the ruling." Is the problem that the laws themselves are terrible, or that the laws are being misused by overzealous prosecutors? I mean, if changing a public URL is considered "conspiracy to access a computer…

The problem is that there is little consensus on what the boundaries in digital space should mean. Law makers, not without a certain logic, approach things from the principles of private property. Is changing a public URL considered "conspiracy to access a computer without authorization?" Well why would you do it, intentionally? Would you jiggle my door handle to see if that would unlock it? And if it was a crappy lo…

It's not likely that someone would get a long jail sentence for breaking into your car and not taking anything. If they had never committed a crime before, they'd probably get a fine or probation. There are usually monetary thresholds for a crime to be considered "grand theft" (a felony) vs. "petty theft" (a misdemeanor).

Re: iPad Hack Statement Of Responsibility

#43

weev still thinks that AT&T 'published' this information. AT&T had no intention on 'publishing' this information, he abused their system in order to obtain it, then he leaked it. No weev, you found a bug in their web app, then _YOU_ willfully published other peoples personally identifying information for your own fame and glory. Unfortunately, someone who's name and details you leaked didn't like that, and called in…

Okay, when I find a bug in your web app I will publish it anonymously, widely and embarrassingly for you.

That's because you didn't want to be friendly. You wanted to be hard. You wanted DoJ. Now you will be forced to want class action suit from your customers and bankrupcy.

Re: iPad Hack Statement Of Responsibility

#44
post #14

Earlier quoted context omitted.

The problem is that there is little consensus on what the boundaries in digital space should mean. Law makers, not without a certain logic, approach things from the principles of private property. Is changing a public URL considered "conspiracy to access a computer without authorization?" Well why would you do it, intentionally? Would you jiggle my door handle to see if that would unlock it? And if it was a crappy lo…

It's not likely that someone would get a long jail sentence for breaking into your car and not taking anything. If they had never committed a crime before, they'd probably get a fine or probation. There are usually monetary thresholds for a crime to be considered "grand theft" (a felony) vs. "petty theft" (a misdemeanor).

I don't think that violating digital boundaries without anything else should warrant long jail sentences (or any jail sentences at all). But I think there is value in enforcing borders in their own right, even if the punishment is nominal.

Re: iPad Hack Statement Of Responsibility

#45

weev still thinks that AT&T 'published' this information. AT&T had no intention on 'publishing' this information, he abused their system in order to obtain it, then he leaked it. No weev, you found a bug in their web app, then _YOU_ willfully published other peoples personally identifying information for your own fame and glory. Unfortunately, someone who's name and details you leaked didn't like that, and called in…

But they did publish it. Just because they didn't _intend_ to publish it doesn't mean it wasn't published.

Right now the URL I'm looking at has "id=5095821" in it. If I change that to "id=5095822", I'm looking at something else published by Hacker News. But by DoJ standards, I'm "hacking" and have broken the law if HN didn't deliberately publish it.

weev is an ass. But he didn't hack anything.

These cases are trying to set a standard of "security by intent". There is no such thing. It's like my internet banking saying "To access your bank account, please type in your account number. Be careful to get it right or you'll be looking at someone else's account"

Re: iPad Hack Statement Of Responsibility

#46
post #15

I wasn't sure whether this is a spoof or not. Is he serious when he writes - "I did this because I despised people I think are unjustly wealthy and wanted to embarass them. " That was his admitted rationale - that he was seeking to embarrass people he despised because they were "unjustly wealthy?"

There are plenty of ways to embarrass people that are legal, and possibly moral. The question is: was this one of them?

Another question would be is: does harvesting emails embarrass the, in his words, the "unjustly wealthy"? Is it the CEO or one of the board members that is responsible for web server configurations?

Obviously pure speculation (mixed with cynicism) recalling this story of the email harvesting I have no problems imagining a conversation like this occurred:

PR Flack: "Sir, we had a little PR snafu today and millions of email addresses of paying customers were exposed."

CEO: "So what?"

PR Flack: "Well it looks bad sir."

CEO: "Fine, shitcan some 50K a year nerd in one of data centers and then issue a press release indicating how seriously we take customer privacy".

Re: iPad Hack Statement Of Responsibility

#47
post #5

If anyone thinks weev deserves any sympathy, you don't know the full story. weev had malicious intent and wanted to harm AT&T by exposing users data. Instead of doing anything remotely rational he took all the data and wanted to sell it. Laws take into account indent (mens rea) and there is a lot of evidence in his indictment that he wanted to profit off this act. He shouldn't be compared to Aaron Swartz

So what? The reaction suggests that the next time he will pastebin his next hack all right. Is this what we as a society want?

Absolutely not, he should have checked with a lawyer first about how to accomplish his objectives within the framework of the law. Then he would not be in jail but instead making lots of money.

It's really not that hard to compile a list of email addresses from a public API in a way that doesn't violate the law.

Re: iPad Hack Statement Of Responsibility

#48
post #38
post #5

If anyone thinks weev deserves any sympathy, you don't know the full story. weev had malicious intent and wanted to harm AT&T by exposing users data. Instead of doing anything remotely rational he took all the data and wanted to sell it. Laws take into account indent (mens rea) and there is a lot of evidence in his indictment that he wanted to profit off this act. He shouldn't be compared to Aaron Swartz

I know weev personally. He's "an unsympathetic defendant", and probably the 9th level Internet Troll, but his goal was fundamentally speech -- he wanted to draw a lot of attention to the issue, and embarrass ATT (hopefully enough that they'd stop being such fuckups about security), etc. He wasn't trying to profit from this. If that had been his goal, he would have been a lot more stealthy. It's arguable that he had "…

So he committed a crime and wrote words that characterize the intent behind crime in such a way as to increase prosecutorial interest and sentencing. Now you are saying he was just joking around when he said those things?

Perhaps it's true, but it's stupid and it's hard for me imagine anyone taking that explanation seriously, certainly prosecutors and judges.

If you walk into a bank with a gun and ask the teller for money, then say "just kidding", .... Good luck.

Re: iPad Hack Statement Of Responsibility

#49

weev still thinks that AT&T 'published' this information. AT&T had no intention on 'publishing' this information, he abused their system in order to obtain it, then he leaked it. No weev, you found a bug in their web app, then _YOU_ willfully published other peoples personally identifying information for your own fame and glory. Unfortunately, someone who's name and details you leaked didn't like that, and called in…

But they did publish it. Just because they didn't _intend_ to publish it doesn't mean it wasn't published. Right now the URL I'm looking at has "id=5095821" in it. If I change that to "id=5095822", I'm looking at something else published by Hacker News. But by DoJ standards, I'm "hacking" and have broken the law if HN didn't deliberately publish it. weev is an ass. But he didn't hack anything. These cases are trying…

i think the semantics in the method in which weev retrieved this data is far overruled by the fact he LEAKED it afterward.

Real people were hurt here by having their PII exposed. Don't forget that.

Re: iPad Hack Statement Of Responsibility

#50
post #47

Earlier quoted context omitted.

So what? The reaction suggests that the next time he will pastebin his next hack all right. Is this what we as a society want?

Absolutely not, he should have checked with a lawyer first about how to accomplish his objectives within the framework of the law. Then he would not be in jail but instead making lots of money. It's really not that hard to compile a list of email addresses from a public API in a way that doesn't violate the law.

That's a nice idea actually. We should have this "I have found a vulnerability, now what" kind of lawyer service around.
Post reply on HN