Live data from Hacker News

iPad Hack Statement Of Responsibility

techcrunch.com

71–80 of 119 posts

Re: iPad Hack Statement Of Responsibility

#71
post #8

This is one side of the story. I'm not going to form an opinion, and then criticize the US government, weev, or AT&T, without seeing the other side.

Good call. http://arstechnica.com/apple/2011/01/goatse-security-trolls-...

Ars Technica lost a lot of respect with me yesterday when they stated in the analysis of Mega's security that symmetric encryption is inherently less safe than asymmetric.

Also the quoted article does not appear to show considerable insight on internet security.

Sheer directory traversal should never be considered a criminal act.

Of course if they had followed through with the stock manipulation, this would warrant criminal punishment.

Although of course stock manipulation is only punishable if you're not a bank or hedgefund which is sad.

Re: iPad Hack Statement Of Responsibility

#72
"I did this because I despised people I think are unjustly wealthy and wanted to embarass them." -- This is what makes weev "not Aaron". Aaron wanted to further the human race, not embarass people just for the sake of it.

Re: iPad Hack Statement Of Responsibility

#73
post #18

Earlier quoted context omitted.

Yeah but prison time, followed by secret service, not allowed to use computers, not allowed to take jobs... for what, compiling a list of email addresses that an public API was happily returning to him? Despite his questionable handling of the situation, I don't support that kind of draconian punishment.

"That guy got life in prison all for moving a knife about two feet in a certain direction! The system is corrupt!" I wish people could be a little more honest in the way they describe computer crimes. He knew or should have known that that api was not meant for public use. He is being punished for using it despite this knowledge.

So even though he didn't do anything illegal with the data, you think it is criminal that he didn't obey some unwritten rule about using an API in that way? If I wrote a script to scrape 10 million e-mail addresses from usenet, am I a felon because usenet isn't supposed to be used that way? What if I just want to analyze the patterns or show the world how easy it is to scrape?

Re: iPad Hack Statement Of Responsibility

#74
post #61
post #56

Earlier quoted context omitted.

Yes, weev is an idiot. Yes, weev is abrasive. Fortunately neither of those are themselves crimes. Weev has always taken anything and turned it into drama. That's the whole Internet Troll thing. A normal defendant wouldn't, when faced with a chance to reduce his sentence by 1-3 years by "accepting responsibility", post something like this to the press. It basically screams "upward departure" to a judge, while at the s…

There is a difference between being abrasive and openly declaring unlawful intent. While the latter is not (always) illegal, it is a legitimate factor for prosecutorial discretion and sentencing.

Where was he openly declaring unlawful intent? The court transcript is on the web.

Re: iPad Hack Statement Of Responsibility

#75
post #39

Earlier quoted context omitted.

Wasn't it just email addresses that he published? I'm all for protecting personal information, but I find it hard to believe it's a felony for collecting a list of email addresses.

The crime in question was accessing a computer system in an unauthorized fashion to collect e-mail addresses. Yes, the distinction is relevant. Taking photos of my wife in public and publishing them? Creepy but not illegal. Walking through my door (locked or unlocked, it doesn't matter) to take photos of my wife in my house? You're lucky if you don't get shot.

Remind me never to file a bug report to any company you work for.

Re: iPad Hack Statement Of Responsibility

#76
post #19

Earlier quoted context omitted.

There is no indication he wanted to sell it. He wanted to embarrass AT&T, and that isn't a crime. Changing the number in a URL is not identity fraud. This is exactly the same thing that was thrown at Aaron, even if you don't find the target as sympathetic. "He that would make his own liberty secure, must guard even his enemy from oppression; for if he violates this duty, he establishes a precedent that will reach to…

That does not appear to be true. From the Ars Technica article on the case: "Auernheimer then helped Spitler refine his script to harvest a large number of valid e-mail addresses of iPad 3G users, suggesting that a huge data set would be needed to "direct market iPad accessories" or start a "future massive phishing operation," noting that the data breach would be "huge media news."

Weev direct marketing iPad accessories? That's the funniest thing I've ever heard. Go read the IRC transcripts. It's so clearly a joke.

Re: iPad Hack Statement Of Responsibility

#77

Earlier quoted context omitted.

It's not likely that someone would get a long jail sentence for breaking into your car and not taking anything. If they had never committed a crime before, they'd probably get a fine or probation. There are usually monetary thresholds for a crime to be considered "grand theft" (a felony) vs. "petty theft" (a misdemeanor).

And if weev had seen the exploit, thought to himself, "heh, that's funny," and not gone back, he would not be headed to prison. But, that isn't what happened.

If he found it and then sold it to a government agency, he'd be rich and not in jail. Selling exploits to the government is a lucrative business. Google "CIPAV", for one.

Re: iPad Hack Statement Of Responsibility

#78
post #39

Earlier quoted context omitted.

Wasn't it just email addresses that he published? I'm all for protecting personal information, but I find it hard to believe it's a felony for collecting a list of email addresses.

The crime in question was accessing a computer system in an unauthorized fashion to collect e-mail addresses. Yes, the distinction is relevant. Taking photos of my wife in public and publishing them? Creepy but not illegal. Walking through my door (locked or unlocked, it doesn't matter) to take photos of my wife in my house? You're lucky if you don't get shot.

    The crime in question was accessing a computer system in an unauthorized fashion
Via a URL accessible to anybody? If I poke around on your website and find your /hiddenstuff directory, am I guilty of a crime?

Re: iPad Hack Statement Of Responsibility

#79

Earlier quoted context omitted.

Okay, when I find a bug in your web app I will publish it anonymously, widely and embarrassingly for you. That's because you didn't want to be friendly. You wanted to be hard. You wanted DoJ. Now you will be forced to want class action suit from your customers and bankrupcy.

Responsible disclosure to the vendor is one thing. Taking the fruits of your exploits and publishing it for glory and a "I leaked all that information because you wouldn't fix it" attitude is quite another. I would hope that if you discovered a vulnerability in one of my web applications you would contact me first and allow it to be resolved. Might even be lucrative for you. If you used that vulnerability to steal my…

As we saw from many and many articles, vendor disclosure often ends with threats, intimidation, your business interaction with them being canceled, and forcing you to sign a NDA on hostile terms.

Once you contacted vendor it's not safe to go the pastebin route. So it becomes an unfeasible solution.

On the other hand, try to "hunt down" a pastebin post original author. It would be the last of your worries.

Re: iPad Hack Statement Of Responsibility

#80
post #73

Earlier quoted context omitted.

"That guy got life in prison all for moving a knife about two feet in a certain direction! The system is corrupt!" I wish people could be a little more honest in the way they describe computer crimes. He knew or should have known that that api was not meant for public use. He is being punished for using it despite this knowledge.

So even though he didn't do anything illegal with the data, you think it is criminal that he didn't obey some unwritten rule about using an API in that way? If I wrote a script to scrape 10 million e-mail addresses from usenet, am I a felon because usenet isn't supposed to be used that way? What if I just want to analyze the patterns or show the world how easy it is to scrape?

Seems to be a little more of a gray area, considering using is a service that IS publicly available and labelled as such. I don't find the two to be analogous, if that is what you are asking.
Post reply on HN