Live data from Hacker News

iPad Hack Statement Of Responsibility

techcrunch.com

91–100 of 119 posts

Re: iPad Hack Statement Of Responsibility

#91
post #39

Earlier quoted context omitted.

Wasn't it just email addresses that he published? I'm all for protecting personal information, but I find it hard to believe it's a felony for collecting a list of email addresses.

The crime in question was accessing a computer system in an unauthorized fashion to collect e-mail addresses. Yes, the distinction is relevant. Taking photos of my wife in public and publishing them? Creepy but not illegal. Walking through my door (locked or unlocked, it doesn't matter) to take photos of my wife in my house? You're lucky if you don't get shot.

Correct analogies help. Stuff in the internet doesn't just "exist", clients receive it by asking servers. So the analogy here would be a guy coming up to your door, asking for a photo of your wife. If you then hand it to him, and continue doing so as he keeps coming back for more photos, how can you claim it was unauthorized? You made the choice, after all!

Re: iPad Hack Statement Of Responsibility

#92
post #77

Earlier quoted context omitted.

And if weev had seen the exploit, thought to himself, "heh, that's funny," and not gone back, he would not be headed to prison. But, that isn't what happened.

If he found it and then sold it to a government agency, he'd be rich and not in jail. Selling exploits to the government is a lucrative business. Google "CIPAV", for one.

Are you suggesting that the government would have purchased a bug in AT&T's website?

Re: iPad Hack Statement Of Responsibility

#93

When you hear of horrible stores like that of Aaron Swartz and the author of this insightful article Andrew Auernheimer it really paints a picture of just how afraid the US government is of the Internet. People lament China for their great firewall and control over its people and yet the US is starting to look more and more like China everyday. This is how revolts against governments start, absurd laws and persecutio…

What he did was no different than turning the doorknob of an unlocked door, then getting accused of "breaking and entering". Not even a "Keep Out" sign posted anywhere.

Re: iPad Hack Statement Of Responsibility

#94
post #39

Earlier quoted context omitted.

The crime in question was accessing a computer system in an unauthorized fashion to collect e-mail addresses. Yes, the distinction is relevant. Taking photos of my wife in public and publishing them? Creepy but not illegal. Walking through my door (locked or unlocked, it doesn't matter) to take photos of my wife in my house? You're lucky if you don't get shot.

Correct analogies help. Stuff in the internet doesn't just "exist", clients receive it by asking servers. So the analogy here would be a guy coming up to your door, asking for a photo of your wife. If you then hand it to him, and continue doing so as he keeps coming back for more photos, how can you claim it was unauthorized? You made the choice, after all!

In your analogy, the only reason it's okay is the presumed consent that arises from my just handing you the pictures, and the fact that you can reasonably infer that I consent because I handed you the pictures.

You can't anthropomorphize the web server like that. You cannot say this guy reasonably inferred that AT&T intended him to have access to these e-mail addresses. It's a dumb piece of equipment--a broken door lock. An unlocked door does not mean you are invited to come in.

Re: iPad Hack Statement Of Responsibility

#95
post #39

Earlier quoted context omitted.

The crime in question was accessing a computer system in an unauthorized fashion to collect e-mail addresses. Yes, the distinction is relevant. Taking photos of my wife in public and publishing them? Creepy but not illegal. Walking through my door (locked or unlocked, it doesn't matter) to take photos of my wife in my house? You're lucky if you don't get shot.

But, in this case - didn't he just spoof a user agent and toss fairly guessable CCID numbers? Certainly hacking, and given that he doesn't work for, or is associated with AT&T - some type of criminal trespass - but, we're talking community service here, not a felony. Slap the hand, don't cut it off. I would hope we can all agree that there is a pretty big difference between a pervasive attack where someone spear-phis…

> Certainly hacking, and given that he doesn't work for, or is associated with AT&T - some type of criminal trespass - but, we're talking community service here, not a felony. Slap the hand, don't cut it off.

I agree, but he's not being charged with felonies for simply poking around. He's being charged with felonies for what he claims he was going to do with the information.

The defense seems to be that he wasn't actually going to do that, but it's the domain of the jury to decide his intentions based on his actions.

Re: iPad Hack Statement Of Responsibility

#96
post #18

Earlier quoted context omitted.

Yeah but prison time, followed by secret service, not allowed to use computers, not allowed to take jobs... for what, compiling a list of email addresses that an public API was happily returning to him? Despite his questionable handling of the situation, I don't support that kind of draconian punishment.

"That guy got life in prison all for moving a knife about two feet in a certain direction! The system is corrupt!" I wish people could be a little more honest in the way they describe computer crimes. He knew or should have known that that api was not meant for public use. He is being punished for using it despite this knowledge.

If AT&T didn't want to publish their users' data publicly, they didn't have to. But they did. Anything done with that data after that point is 100% their fault.

Re: iPad Hack Statement Of Responsibility

#97
post #39

Earlier quoted context omitted.

The crime in question was accessing a computer system in an unauthorized fashion to collect e-mail addresses. Yes, the distinction is relevant. Taking photos of my wife in public and publishing them? Creepy but not illegal. Walking through my door (locked or unlocked, it doesn't matter) to take photos of my wife in my house? You're lucky if you don't get shot.

The crime in question was accessing a computer system in an unauthorized fashion Via a URL accessible to anybody? If I poke around on your website and find your /hiddenstuff directory, am I guilty of a crime?

What good reason do you have to be poking around in my /hiddenstuff directory? If I leave my car door unlocked, do you take it as an invitation to look through my CD's?

Re: iPad Hack Statement Of Responsibility

#99

weev still thinks that AT&T 'published' this information. AT&T had no intention on 'publishing' this information, he abused their system in order to obtain it, then he leaked it. No weev, you found a bug in their web app, then _YOU_ willfully published other peoples personally identifying information for your own fame and glory. Unfortunately, someone who's name and details you leaked didn't like that, and called in…

But they did publish it. Just because they didn't _intend_ to publish it doesn't mean it wasn't published. Right now the URL I'm looking at has "id=5095821" in it. If I change that to "id=5095822", I'm looking at something else published by Hacker News. But by DoJ standards, I'm "hacking" and have broken the law if HN didn't deliberately publish it. weev is an ass. But he didn't hack anything. These cases are trying…

Another fairly common example is with facebook where you can access profiles with names, like facebook.com/lessnonymous.1 . I got fairly tempted to check other people in the world with the same name as I have so I incremented the number myself. I am not sure that facebook intended their website to be used that way

Re: iPad Hack Statement Of Responsibility

#100

From Wikipedia: "On 20 November 2012, Auernheimer was found guilty of one count of identity fraud and one count of conspiracy to access a computer without authorization. Auernheimer tweeted that he would appeal the ruling." Is the problem that the laws themselves are terrible, or that the laws are being misused by overzealous prosecutors? I mean, if changing a public URL is considered "conspiracy to access a computer…

- But if not: what can be done to change the law? -

That's an easy one! Just get congress to pass a law granting you retroactive immunity for breaking the law. http://www.guardian.co.uk/commentisfree/2012/oct/10/supreme-...

Post reply on HN