Live data from Hacker News

iPad Hack Statement Of Responsibility

techcrunch.com

101–110 of 119 posts

Re: iPad Hack Statement Of Responsibility

#101
post #93

When you hear of horrible stores like that of Aaron Swartz and the author of this insightful article Andrew Auernheimer it really paints a picture of just how afraid the US government is of the Internet. People lament China for their great firewall and control over its people and yet the US is starting to look more and more like China everyday. This is how revolts against governments start, absurd laws and persecutio…

What he did was no different than turning the doorknob of an unlocked door, then getting accused of "breaking and entering". Not even a "Keep Out" sign posted anywhere.

In most cases in the U.S., that would still be considered a crime.

Edit to add: The law is structured this way for a very specific reason--to account for human error. What if I always lock my front door, but this morning I was in a hurry and forgot? Should I give up all rights of private property because of this error? Obviously not, which is why someone walking into my house through my unlocked door would still be a crime (trespassing, at least). If they took anything, it would still be stealing--even though one could argue that if I "really" didn't want anyone to take my stuff, I would have locked my door.

We all know how hard it is to properly write totally secure web services. We read about the failures every day. The question, then, is similar. Should the rights of people and companies be completely dependent on their ability to write invulnerable code? I would submit that that is not a sustain way for the law to operate.

Note that I'm not addressing weev's case specifically, as I'm not familiar enough with the details. Just addressing the general case.

Re: iPad Hack Statement Of Responsibility

#102

Earlier quoted context omitted.

Why do you even ask that. Isn't it obvious from my post that I'm pointing out that overly charitable wordings are misleading? Do you honestly believe that someone could have the mental capacity to enter words into this site and be unable to perceive the distinction between these two crimes? Or were you just trying to score a cheap rhetorical point by intentionally misreading me? And again, of wasn't just wrapping cur…

>It was doing that with the knowledge that the target was not meant to be public AT&T's intent isn't really relevant. The fact is, they published all of those emails publicly. They certainly didn't mean to, but I fail to see how accessing public websites can be considered a crime, even if you access lots of them when the company doesn't want you to. If I forget to close my blinds before having sex, that doesn't make…

> AT&T's intent isn't really relevant. The fact is, they published all of those emails publicly. They certainly didn't mean to, but I fail to see how accessing public websites can be considered a crime, even if you access lots of them when the company doesn't want you to.

In the meatspace it happens all the time that you can get in trouble for being somewhere you're not supposed to even if they forgot to hit the locks on the way out.

Or for a possibly more relevant example, what happens in real life if you find an ATM that has an error such that it gives you twice as much cash as you asked for? Is it still theft if you take it? (Hint: Yes)

Should that equate to a felony here, where no authentication shenanigans were employed? I don't think so, but I wish we'd quit with the victim blaming here on HN.

I also wish we'd separate the enforcability of something from its morality or legality. There's many, many minor things wrong that people can do that even the current state can't hope to fully enforce, but that doesn't make it right, it makes it a fact of life. But if you do somehow get caught doing something that 99% of the rest manage to get away with, shame on you.

By the way, that ATM example wasn't made up: http://investorplace.com/2012/11/faulty-atm-gives-out-extra-... (the Bank opted not to try to find out which customers took the money, due to the difficulty with getting accurate evidence, not because it was right to take the money)

Re: iPad Hack Statement Of Responsibility

#103

Earlier quoted context omitted.

Good call. http://arstechnica.com/apple/2011/01/goatse-security-trolls-...

Ars Technica lost a lot of respect with me yesterday when they stated in the analysis of Mega's security that symmetric encryption is inherently less safe than asymmetric. Also the quoted article does not appear to show considerable insight on internet security. Sheer directory traversal should never be considered a criminal act. Of course if they had followed through with the stock manipulation, this would warrant c…

In the actual chat logs (which Ars ignores), another chatter brings up shorting the stock, weev explicitly says shorting the stock would be illegal and that if someone wants to do that, not to involve him. Aside from the fact that no one did it and this was obviously silly chat room banter to begin with, weev is actually showing intent of not running afoul of the law.

Later in the chat, another user says that weev should post the leaked data to a public mailing list, and weev says no because that could potentially be criminal.

Re: iPad Hack Statement Of Responsibility

#104

Earlier quoted context omitted.

But they did publish it. Just because they didn't _intend_ to publish it doesn't mean it wasn't published. Right now the URL I'm looking at has "id=5095821" in it. If I change that to "id=5095822", I'm looking at something else published by Hacker News. But by DoJ standards, I'm "hacking" and have broken the law if HN didn't deliberately publish it. weev is an ass. But he didn't hack anything. These cases are trying…

i think the semantics in the method in which weev retrieved this data is far overruled by the fact he LEAKED it afterward. Real people were hurt here by having their PII exposed. Don't forget that.

The problem with your argument is that he did not leak it afterward. None of this info was ever public. He demonstrated it to the media and then deleted it. I suggest you look into the case.

Re: iPad Hack Statement Of Responsibility

#105
post #94

Earlier quoted context omitted.

Correct analogies help. Stuff in the internet doesn't just "exist", clients receive it by asking servers. So the analogy here would be a guy coming up to your door, asking for a photo of your wife. If you then hand it to him, and continue doing so as he keeps coming back for more photos, how can you claim it was unauthorized? You made the choice, after all!

In your analogy, the only reason it's okay is the presumed consent that arises from my just handing you the pictures, and the fact that you can reasonably infer that I consent because I handed you the pictures. You can't anthropomorphize the web server like that. You cannot say this guy reasonably inferred that AT&T intended him to have access to these e-mail addresses. It's a dumb piece of equipment--a broken door l…

There is no lock, not even a broken one. There is a machine (the webserver) that is handing out private data to everyone who asks and then probably even makes a note that he did so. I'm not anthropomorphizing that part, that is how the protocol works. "GET .." ("200 OK" | "403 Forbidden")

Now the server provider is responsible for having not adequately secured the customers information, and the guy who asked for that information is responsible for what he does with that information. What I won't accept is that you criminalize the mere request for said information and the retrieval of whatever response is returned.

Re: iPad Hack Statement Of Responsibility

#106
post #82

Twelve months ago on this very site it was discussed how a private company named Path was, without permission and certainly illegally, stealing the entire address books of users and uploading it to their own servers. The CEO of that company appeared right here on this board personally (not surprising he follows this board as he has invested in YCombinator projects [ http://www.forbes.com/sites/nicoleperlroth/2011/08/…

Oh my God. Did you really just write a holier-than-thou post comparing Dave Morin to weev? Have you even bothered READING anything weev wrote? A lot of people will never speak out against weev because of his scorched earth tactics. His list of enemies is a lot longer than a few Feds.

So that negates the overall point he was making? Are you on crack?

Re: iPad Hack Statement Of Responsibility

#107

Earlier quoted context omitted.

Why do you even ask that. Isn't it obvious from my post that I'm pointing out that overly charitable wordings are misleading? Do you honestly believe that someone could have the mental capacity to enter words into this site and be unable to perceive the distinction between these two crimes? Or were you just trying to score a cheap rhetorical point by intentionally misreading me? And again, of wasn't just wrapping cur…

>It was doing that with the knowledge that the target was not meant to be public AT&T's intent isn't really relevant. The fact is, they published all of those emails publicly. They certainly didn't mean to, but I fail to see how accessing public websites can be considered a crime, even if you access lots of them when the company doesn't want you to. If I forget to close my blinds before having sex, that doesn't make…

> AT&T's intent isn't really relevant.

That's definitely not legally true.

Re: iPad Hack Statement Of Responsibility

#108
Despite how similar cases of Swartz and Auernheimer seem, and despite later's appeal to social justice and freedom causes, I must admit I still have a hard time mustering sympathy for him. At least not even close to the sympathy I have to Swartz. I know justice has to be blind, but I'm not in the jury, so I have the luxury not to be. For me, the difference in approaches is striking. On one side, we have somebody who contributed to RSS and Reddit - I am not a big fan of Reddit, but one doesn't have do be a fan to recognize it's a major establishment in the Internet society - and on the other side, we have what? GNAA? I can't read minds, but to me, it just seems that while Swartz was moved by genuine concern and willing to overstep some boundaries, for Auernheimer it was much more about overstepping bounderies, creating mayhem and pissing people off, and the cause came just as a convenient channel to direct his destructive energies. That doesn't mean that I wish ill to Auernheimer - I wish that his sentence would be light and involve as little jail time as possible (by now realistically it looks like there would be some) - but I must say if we want to change public opinion about overprosecuting computer crimes, guys like Auernheimer don't exactly help the cause.

Re: iPad Hack Statement Of Responsibility

#109
post #93

Earlier quoted context omitted.

What he did was no different than turning the doorknob of an unlocked door, then getting accused of "breaking and entering". Not even a "Keep Out" sign posted anywhere.

In most cases in the U.S., that would still be considered a crime. Edit to add: The law is structured this way for a very specific reason--to account for human error. What if I always lock my front door, but this morning I was in a hurry and forgot? Should I give up all rights of private property because of this error? Obviously not, which is why someone walking into my house through my unlocked door would still be a…

> What if I always lock my front door, but this morning I was in a hurry and forgot? Should I give up all rights of private property because of this error?

You and me would both be alarmed if someone entered our house after we forgot to lock the door, but I wouldn't consider that persons entry into my house a crime in itself (obviously, its probably still a crime whether I agree or not). Do you forfeit rights to your private property for forgetting to lock your door? Not at all. If you wake up in the middle of the night and someone is in your house, and you shoot them, you did nothing wrong. Whether or not you locked the door, your life is at risk if you assess the situation incorrectly (goes for daytime too). When that person entered into somebody else's house uninvited, they made a decision to subject themselves to your discretion.

> If they took anything, it would still be stealing--even though one could argue that if I "really" didn't want anyone to take my stuff, I would have locked my door.

They would be wrong telling you that you forfeited your rights to your belongings for not locking your door. If that were the case, nobody would be obligated to pay for anything at the grocery store or mall.

> Should the rights of people and companies be completely dependent on their ability to write invulnerable code?

It is up to you to defend your rights, nobody else. If you are going to offer a service and want to protect the server, data, code, licenses, etc.. the burden is on you to protect it through whatever means you see fit. It is no one else's job to protect your product.

> I would submit that that is not a sustain way for the law to operate.

The reason for that may be because we shouldn't rely on the law to prevent a crime aside from being a visible deterrent. The purpose of law should be to enforce civil agreements when a crime is committed. If someone causes financial damage to your property, what good does it do to put that person in jail? Wouldn't a better solution be to have your property returned or receive financial compensation equivalent to the value of what was taken/damaged?

Re: iPad Hack Statement Of Responsibility

#110

Earlier quoted context omitted.

>It was doing that with the knowledge that the target was not meant to be public AT&T's intent isn't really relevant. The fact is, they published all of those emails publicly. They certainly didn't mean to, but I fail to see how accessing public websites can be considered a crime, even if you access lots of them when the company doesn't want you to. If I forget to close my blinds before having sex, that doesn't make…

> AT&T's intent isn't really relevant. That's definitely not legally true.

You're absolutely right, and I'd call that a failing of the law. Just because someone intends to create a system with some degree of security does not mean people who access said unsecured system should be considered criminals.
Post reply on HN