Live data from Hacker News

iPad Hack Statement Of Responsibility

techcrunch.com

81–90 of 119 posts

Re: iPad Hack Statement Of Responsibility

#81
post #38
post #5

If anyone thinks weev deserves any sympathy, you don't know the full story. weev had malicious intent and wanted to harm AT&T by exposing users data. Instead of doing anything remotely rational he took all the data and wanted to sell it. Laws take into account indent (mens rea) and there is a lot of evidence in his indictment that he wanted to profit off this act. He shouldn't be compared to Aaron Swartz

I know weev personally. He's "an unsympathetic defendant", and probably the 9th level Internet Troll, but his goal was fundamentally speech -- he wanted to draw a lot of attention to the issue, and embarrass ATT (hopefully enough that they'd stop being such fuckups about security), etc. He wasn't trying to profit from this. If that had been his goal, he would have been a lot more stealthy. It's arguable that he had "…

Being an "an unsympathetic defendant" frankly makes it even more important to support him. One of the worst things with these out of proportion indictments/sentences is that they leave too much room for other factors, which can turn into things like political repression.

Re: iPad Hack Statement Of Responsibility

#82

Twelve months ago on this very site it was discussed how a private company named Path was, without permission and certainly illegally, stealing the entire address books of users and uploading it to their own servers. The CEO of that company appeared right here on this board personally (not surprising he follows this board as he has invested in YCombinator projects [ http://www.forbes.com/sites/nicoleperlroth/2011/08/…

Oh my God. Did you really just write a holier-than-thou post comparing Dave Morin to weev? Have you even bothered READING anything weev wrote?

A lot of people will never speak out against weev because of his scorched earth tactics. His list of enemies is a lot longer than a few Feds.

Re: iPad Hack Statement Of Responsibility

#83

Earlier quoted context omitted.

You aren't seriously equating wrapping curl in a for loop to murder, are you?

Why do you even ask that. Isn't it obvious from my post that I'm pointing out that overly charitable wordings are misleading? Do you honestly believe that someone could have the mental capacity to enter words into this site and be unable to perceive the distinction between these two crimes? Or were you just trying to score a cheap rhetorical point by intentionally misreading me? And again, of wasn't just wrapping cur…

>It was doing that with the knowledge that the target was not meant to be public

AT&T's intent isn't really relevant. The fact is, they published all of those emails publicly. They certainly didn't mean to, but I fail to see how accessing public websites can be considered a crime, even if you access lots of them when the company doesn't want you to. If I forget to close my blinds before having sex, that doesn't make anyone who walks by on the street and sees me a criminal. Nor are they criminals if they take a picture and post it on reddit. It's your job not to expose that material publicly if you want it to be private.

>storing that information, and sharing it with the media.

Neither of these are acts that should be considered criminal, just as the storing and uploading to reddit of an embarrassing photo is not criminal. Would it still have been criminal if he had passed the bash one-liner to the media, instead? What's the difference? The responsibility for the leak still resides with AT&T, and them alone.

Now, none of this is to say that I condone of weev's actions. I certainly would have handled the situation differently. But being rude and being a criminal are not synonymous.

Re: iPad Hack Statement Of Responsibility

#84
post #18

Earlier quoted context omitted.

Yeah but prison time, followed by secret service, not allowed to use computers, not allowed to take jobs... for what, compiling a list of email addresses that an public API was happily returning to him? Despite his questionable handling of the situation, I don't support that kind of draconian punishment.

Agreed - I can despise his behavior, and how he handled this situation, but at the same time say what he did should not be considered a felony, and, based on what I read on the ArsTechnica article, it's not even clear if I feel like it's criminal.

I think it should be illegal to commercially exploit personally identifying information if it is obviously not published intentionally or with permission. If my personal details were accidentally leaked, I'd prefer every law abiding company didn't suddenly use this information to focus me in their spam cannon sights.

Whether this should be a felony should relate to how conspiratorial the intent and whether there's a reasonable expectation that the persons whose information is involved will be affected. It does sound like weev was doing something that would screw the AT&T customers involved -- a pretty nasty move.

Re: iPad Hack Statement Of Responsibility

#85
As a person coming from a former Soviet satellite republic, I must say, that the more I read,the less and less difference I see between the countries that are well known for disregarding human rights and the "land of freedom" - the US. The only difference I can think of is that they probably won't shoot you in the broad daylight, like it happens in Russia. But other than that, the image is complete - if you do something the government doesn't like,they can absolutely destroy you. They can put you in prison without a court order, freeze your assets for indefinite amount of time, spy on you, send agents to follow you, deny you the information why they are doing this, and they do threaten journalists to not write about some cases or risk prosecution for violating "national security". I am honestly sorry for people who live in the US and happen to do something that their government perceives as wrong.

Re: iPad Hack Statement Of Responsibility

#86

Earlier quoted context omitted.

But they did publish it. Just because they didn't _intend_ to publish it doesn't mean it wasn't published. Right now the URL I'm looking at has "id=5095821" in it. If I change that to "id=5095822", I'm looking at something else published by Hacker News. But by DoJ standards, I'm "hacking" and have broken the law if HN didn't deliberately publish it. weev is an ass. But he didn't hack anything. These cases are trying…

He certainly hacked it - but that's not necessarily pejorative. Your average individual couldn't just try entering the number into AT&T - weev had to spoof the user agent, and, make some intelligent guesses as to what valid CCID's would be. It's not the world's greatest hack, but it certainly was using the system in a manner that I'm certain AT&T did not intend. The IRC logs indicated that they knew what they were do…

So what you are saying is, that AT&T could have made a webpage with all user data in plain text,and just write at the top in capital letters: "YOU ARE ONLY INTENDED TO LOOK AT YOUR OWN DATA, DISREGARD EVERYTHING ELSE" and it would be magically ok, because you know, if you look at other people data then you are not using the webpage as it was intended to? Because this is basically what they did. Yes, an average American individual would not know how to change the URL,but that does not mean that the data was secure. And AT&T has all legal obligation to keep their customer data secure.

Re: iPad Hack Statement Of Responsibility

#87

Earlier quoted context omitted.

He certainly hacked it - but that's not necessarily pejorative. Your average individual couldn't just try entering the number into AT&T - weev had to spoof the user agent, and, make some intelligent guesses as to what valid CCID's would be. It's not the world's greatest hack, but it certainly was using the system in a manner that I'm certain AT&T did not intend. The IRC logs indicated that they knew what they were do…

So what you are saying is, that AT&T could have made a webpage with all user data in plain text,and just write at the top in capital letters: "YOU ARE ONLY INTENDED TO LOOK AT YOUR OWN DATA, DISREGARD EVERYTHING ELSE" and it would be magically ok, because you know, if you look at other people data then you are not using the webpage as it was intended to? Because this is basically what they did. Yes, an average Americ…

I'm not saying AT&T was in the clear. Obviously just requiring a reasonably easy to guess number to secure an email address is amateur hour. But, at the same time, just because web security is easy to break into, doesn't give people free reign to go traipsing through and pull out what they can.

Keep in mind - 99% of the population wouldn't have been able to figure out how to spoof the user-agent to get into the AT&T site, and most of those that could, wouldn't have gone beyond extracting a couple IDs, and then notifying AT&T.

Weev's sin (if not felony behavior) was extracting 100,000+ personal email addresses, and the exposing them for the sheer purpose of embarrassing people he despised. Do I believe he engaged in illegal behavior? Yes. Do I believe it merits years in Jail? No.

With regards to legal obligations - In California, the closest I can find is Bus. & Prof. Code §§ 22575-22578 [1]. It is a requirement for site collecting personal information to "conspicuously post its privacy policy on its Web site"

I can't find any laws in California that require the securing of this information beyond that, though.

[1] http://www.leginfo.ca.gov/cgi-bin/displaycode?section=bpc&#3...

Re: iPad Hack Statement Of Responsibility

#88
post #36
post #5

If anyone thinks weev deserves any sympathy, you don't know the full story. weev had malicious intent and wanted to harm AT&T by exposing users data. Instead of doing anything remotely rational he took all the data and wanted to sell it. Laws take into account indent (mens rea) and there is a lot of evidence in his indictment that he wanted to profit off this act. He shouldn't be compared to Aaron Swartz

Yeah yeah. He should "man up" or something like that. Those bastard hackers, self declared trolls, activists and stuff... Do you guys always know the full story behind the news and comment accordingly? If you do based on the articles you read around, I want to remind you that in Aaron's case what you could read about the case was less than half the truth and there are still things we're not sure.

Well, go on.

Unless you know something everyone else doesn't then what is published about the Schwarz case is on the record and in the books. So you're saying that the prosecutors were correct in the charges they brought?

Re: iPad Hack Statement Of Responsibility

#89
post #36
post #5

If anyone thinks weev deserves any sympathy, you don't know the full story. weev had malicious intent and wanted to harm AT&T by exposing users data. Instead of doing anything remotely rational he took all the data and wanted to sell it. Laws take into account indent (mens rea) and there is a lot of evidence in his indictment that he wanted to profit off this act. He shouldn't be compared to Aaron Swartz

Yeah yeah. He should "man up" or something like that. Those bastard hackers, self declared trolls, activists and stuff... Do you guys always know the full story behind the news and comment accordingly? If you do based on the articles you read around, I want to remind you that in Aaron's case what you could read about the case was less than half the truth and there are still things we're not sure.

Well, go on.

Unless you know something everyone else doesn't then what is published about the Schwarz case is on the record and in the books. So you're saying that the prosecutors were correct in the charges they brought?

Re: iPad Hack Statement Of Responsibility

#90

Earlier quoted context omitted.

Agreed - I can despise his behavior, and how he handled this situation, but at the same time say what he did should not be considered a felony, and, based on what I read on the ArsTechnica article, it's not even clear if I feel like it's criminal.

I think it should be illegal to commercially exploit personally identifying information if it is obviously not published intentionally or with permission. If my personal details were accidentally leaked, I'd prefer every law abiding company didn't suddenly use this information to focus me in their spam cannon sights. Whether this should be a felony should relate to how conspiratorial the intent and whether there's a…

If this were the case there would be a large number of corporate executives behind bars tonight. The biggest problem as I see it is that there is one rule for well heeled, connected, corporate types and another for poor, zany, out there types. What happened to all created equal and justice for all?
Post reply on HN