Live data from Hacker News

iPad Hack Statement Of Responsibility

techcrunch.com

51–60 of 119 posts

Re: iPad Hack Statement Of Responsibility

#51

weev still thinks that AT&T 'published' this information. AT&T had no intention on 'publishing' this information, he abused their system in order to obtain it, then he leaked it. No weev, you found a bug in their web app, then _YOU_ willfully published other peoples personally identifying information for your own fame and glory. Unfortunately, someone who's name and details you leaked didn't like that, and called in…

Okay, when I find a bug in your web app I will publish it anonymously, widely and embarrassingly for you. That's because you didn't want to be friendly. You wanted to be hard. You wanted DoJ. Now you will be forced to want class action suit from your customers and bankrupcy.

Responsible disclosure to the vendor is one thing. Taking the fruits of your exploits and publishing it for glory and a "I leaked all that information because you wouldn't fix it" attitude is quite another.

I would hope that if you discovered a vulnerability in one of my web applications you would contact me first and allow it to be resolved. Might even be lucrative for you.

If you used that vulnerability to steal my database and publish it to the public domain -- when it has no place in the public domain, i would expect the DoJ to hunt you down.

I never said anything about not being friendly. But if you are playing with peoples identities, their lives, this is not friendly at all.

Re: iPad Hack Statement Of Responsibility

#52
post #12

Earlier quoted context omitted.

People that describe themselves as trolls are generally bigoted idiots and I feel no sympathy. I'm sorry if that's a stereotype but I can't help myself, the internet hasn't been nice to me.

Whether they're bigoted or idiotic shouldn't affect how the law affects them, though. If the person committing this crime was a nice, inoffensive guy, would the law remain justified?

The law should treat both of them exactly the same. But if he was nice and unoffensive, I would go out of my way to help him.

Re: iPad Hack Statement Of Responsibility

#53
Twelve months ago on this very site it was discussed how a private company named Path was, without permission and certainly illegally, stealing the entire address books of users and uploading it to their own servers. The CEO of that company appeared right here on this board personally (not surprising he follows this board as he has invested in YCombinator projects [http://www.forbes.com/sites/nicoleperlroth/2011/08/25/yc-com...] ) and not only defended his actions but justified them, proud of the fine work of data theft he engaged in. [https://news.ycombinator.com/item?id=3563368] He also said in a comment on his blog that these actions of stealing entire address books was a common practice in industry: "This is currently the industry best practice" [https://news.ycombinator.com/item?id=3563639]. And in fact it turned out that companies as large as Twitter were also engaging in the same type and manner of data theft [http://articles.latimes.com/2012/feb/14/business/la-fi-tn-tw...].

At that time some HN members, possibly some of the same ones here attacking this hacker (perhaps with good reason), defended the data-theft-for-profit actions of these companies.

These two positions are not consistent. People may wish to pick a side of this issue and stick to their position if they wish to be taken seriously, or frame a coherent argument why it is acceptable for corporations to engage in data theft from individuals but the reverse should be severely punished with prison time and other penalties.

Those who genuinely believe that weev should be prosecuted and imprisoned for his actions may wish to consider if the same call should be made for criminal proceedings against the larger scale and more clearly profit driven data theft actions taken by large and well funded companies such as Twitter, Path, Facebook, Apple, and many others.

Re: iPad Hack Statement Of Responsibility

#55

weev still thinks that AT&T 'published' this information. AT&T had no intention on 'publishing' this information, he abused their system in order to obtain it, then he leaked it. No weev, you found a bug in their web app, then _YOU_ willfully published other peoples personally identifying information for your own fame and glory. Unfortunately, someone who's name and details you leaked didn't like that, and called in…

But they did publish it. Just because they didn't _intend_ to publish it doesn't mean it wasn't published. Right now the URL I'm looking at has "id=5095821" in it. If I change that to "id=5095822", I'm looking at something else published by Hacker News. But by DoJ standards, I'm "hacking" and have broken the law if HN didn't deliberately publish it. weev is an ass. But he didn't hack anything. These cases are trying…

More to it than that...

lets say you exploit that bug in the internet banking application and you access my account.

Then you start logging into other peoples accounts and copying their address, balance, transaction lists.

Then you publish all this information you have stolen and say "Oh dont use internet bank -- they don't protect your private information"

the bank should have done better to protect that information, granted, but you have also performed an unethical and criminal act by publishing this information.

both the bank and the person that leaked that information should be punished.

Re: iPad Hack Statement Of Responsibility

#56
post #48
post #38

Earlier quoted context omitted.

I know weev personally. He's "an unsympathetic defendant", and probably the 9th level Internet Troll, but his goal was fundamentally speech -- he wanted to draw a lot of attention to the issue, and embarrass ATT (hopefully enough that they'd stop being such fuckups about security), etc. He wasn't trying to profit from this. If that had been his goal, he would have been a lot more stealthy. It's arguable that he had "…

So he committed a crime and wrote words that characterize the intent behind crime in such a way as to increase prosecutorial interest and sentencing. Now you are saying he was just joking around when he said those things? Perhaps it's true, but it's stupid and it's hard for me imagine anyone taking that explanation seriously, certainly prosecutors and judges. If you walk into a bank with a gun and ask the teller for…

Yes, weev is an idiot. Yes, weev is abrasive. Fortunately neither of those are themselves crimes.

Weev has always taken anything and turned it into drama. That's the whole Internet Troll thing. A normal defendant wouldn't, when faced with a chance to reduce his sentence by 1-3 years by "accepting responsibility", post something like this to the press. It basically screams "upward departure" to a judge, while at the same time rallying people on the Internet, which doesn't really mean so much inside a federal ass-rape prison.

Re: iPad Hack Statement Of Responsibility

#57
post #18
post #5

If anyone thinks weev deserves any sympathy, you don't know the full story. weev had malicious intent and wanted to harm AT&T by exposing users data. Instead of doing anything remotely rational he took all the data and wanted to sell it. Laws take into account indent (mens rea) and there is a lot of evidence in his indictment that he wanted to profit off this act. He shouldn't be compared to Aaron Swartz

Yeah but prison time, followed by secret service, not allowed to use computers, not allowed to take jobs... for what, compiling a list of email addresses that an public API was happily returning to him? Despite his questionable handling of the situation, I don't support that kind of draconian punishment.

"That guy got life in prison all for moving a knife about two feet in a certain direction! The system is corrupt!"

I wish people could be a little more honest in the way they describe computer crimes. He knew or should have known that that api was not meant for public use. He is being punished for using it despite this knowledge.

Re: iPad Hack Statement Of Responsibility

#58
post #30
post #23

Earlier quoted context omitted.

Seriously? That you actually believe his punishment fits the crime is incredibly saddening. If even the top voted comment on a site that understands the issue believes the punishment is appropriate, imagine the discussion in a law firm or in parliament. Anybody in the USA touching a computer will be in trouble soon. Can't wait for the next batch of laws.

Punishing people for purposefully disclosing private information that is clearly not intended to be public is the path to "everyone touching a computer will be in trouble soon?" You act as if he was just playing around on his own computer minding his own business when the big bad government broke his door down. In Texas, they don't convict homeowners who shoot trick or treaters trespassing on private property: http:/…

For the purpose of federal sentencing guidelines, this doesn't count as "acceptance of responsibility", right?

Re: iPad Hack Statement Of Responsibility

#59
post #14

Earlier quoted context omitted.

The problem is that there is little consensus on what the boundaries in digital space should mean. Law makers, not without a certain logic, approach things from the principles of private property. Is changing a public URL considered "conspiracy to access a computer without authorization?" Well why would you do it, intentionally? Would you jiggle my door handle to see if that would unlock it? And if it was a crappy lo…

It's not likely that someone would get a long jail sentence for breaking into your car and not taking anything. If they had never committed a crime before, they'd probably get a fine or probation. There are usually monetary thresholds for a crime to be considered "grand theft" (a felony) vs. "petty theft" (a misdemeanor).

And if weev had seen the exploit, thought to himself, "heh, that's funny," and not gone back, he would not be headed to prison. But, that isn't what happened.

Re: iPad Hack Statement Of Responsibility

#60
post #18

Earlier quoted context omitted.

Yeah but prison time, followed by secret service, not allowed to use computers, not allowed to take jobs... for what, compiling a list of email addresses that an public API was happily returning to him? Despite his questionable handling of the situation, I don't support that kind of draconian punishment.

"That guy got life in prison all for moving a knife about two feet in a certain direction! The system is corrupt!" I wish people could be a little more honest in the way they describe computer crimes. He knew or should have known that that api was not meant for public use. He is being punished for using it despite this knowledge.

You aren't seriously equating wrapping curl in a for loop to murder, are you?
Post reply on HN