Yeah this is ludicrous. AFAICT, AT&T effectively published this information to the web, this guy just pointed out where it was. Not a crime.
Andrew 'Weev' Auernheimer Faces Jail
11–20 of 71 posts
Re: Andrew 'Weev' Auernheimer Faces Jail
#12Re: Andrew 'Weev' Auernheimer Faces Jail
#13The government is just trying to maintain its power over the people, when federal reserve realizes there is no other alternative except to default on the US treasury, there is going to be a lot of unrest, and the internet will be a focus point of governmental rebellion, it's important everyone who accesses the internet is a felon. Especially the coders, like this one, who will be making the rebellion possible.
You got to put the fear in them. We may be the ones, like our founding fathers, who have to write up a new constitution, bill of rights, and spawn a new nation to break away from the defective one. Like the good men of old time broke away from Britain. The battlefield this time around will not be on the shores of Boston, the battlefield will be software, servers, clicks, and smart phones.
As with all battlefields, the side who wins is the one who prepares the most. This is why we are cracking down on website clicking by programmers, rather than cracking down on governmental corruption.
Re: Andrew 'Weev' Auernheimer Faces Jail
#14Earlier quoted context omitted.
[deleted]
...but it sounds as if he did neither of those things, so surely not that smart? (the parent I replied to has been deleted, but it suggested he was found guilty of 'being smart')
He is tackling the issue head-on, and he is verbose about it. This is the way many politicians are. Not very sophisticated, to say the least. This is his strategy, let's see how will he take the jail time though.
Re: Andrew 'Weev' Auernheimer Faces Jail
#15Yeah this is ludicrous. AFAICT, AT&T effectively published this information to the web, this guy just pointed out where it was. Not a crime.
Didn't he try to extort money out of them after spidering all the information?
Re: Andrew 'Weev' Auernheimer Faces Jail
#16Yeah this is ludicrous. AFAICT, AT&T effectively published this information to the web, this guy just pointed out where it was. Not a crime.
Didn't he try to extort money out of them after spidering all the information?
Re: Andrew 'Weev' Auernheimer Faces Jail
#17It blows my mind that someone could get 10 years for idempotent operations on what was essentially a public API. Put in any other context than "scary computer hacking", it would be obvious to most people that the insecure system was at least as much to blame as this kid.
The disclosure was totally botched. The IRC logs that came out during the case showed that Andrew and Dan (Spitler) talked about shorting AT&T stock (they ended up not doing this, but it's not the sort of thing you talk about), and going directly to news organisations, bypassing AT&T. They also considered (perhaps jokingly, but again, not something you joke about) selling the e-mail addresses to spammers.
Andrew also initially told Gawker he'd disclosed to AT&T, when in fact he hadn't (Ars has a good summary here[1]).
I am definitely not saying that a ten year sentence is warranted, or that any sort of custodial sentence is appropriate. In fact, I doubt he'll be given 10 years, more like 2-4 (since his fellow defendant, who plead guilty, got 12-18 months). But I do think the disclosure was handled really, really badly. I've found and disclosed very similar vulnerabilities - I would not leak the entire database out. That's just crazy.
Again, it's the old black/grey/white hat argument again. But to go public without even informing AT&T doesn't endear him to me.
[1]: http://arstechnica.com/apple/2011/01/goatse-security-trolls-...
Re: Andrew 'Weev' Auernheimer Faces Jail
#18Every piece I read about him made me like him less. But despite my deep feelings of antipathy the charges that are brought against him can NEVER warrant 10 years of prison. That's ridiculous.
In many countries simply accessing a public server without consent is illegal. Here in the UK the Computer Misuse Act contains the following gem: > It is an offense to make a computer perform a function and for that function to be deemed unauthorised by the owner of that computer This is fantastically broad. I believe it's similar in the US. It's led to convictions for things like directory traversal, XSS testing, an…
1) Set up a public server
2) Wait for google bot to show up
3) Press charges against google
4) Sue in civil court
5) Profit.
Re: Andrew 'Weev' Auernheimer Faces Jail
#19Earlier quoted context omitted.
"Andrew Auernheimer, 26, of Fayetteville, Arkansas, was found guilty in federal court in New Jersey of one count of identity fraud and one count of conspiracy to access a computer without authorization." [1] Those were the charges. Ridiculous in my opinion. [1] http://www.wired.com/threatlevel/2012/11/att-hacker-found-gu...
What is AT&T guilty of? Is it now legal to publish personal information without any authentication?
It seems clear that AT&T failed to protect their customer's personal details. Whether that makes them criminally liable depends on US law, about which I know almost nothing. This [1] article seems to imply that it is fairly weak compared to European data protection laws, so it may be that AT&T did nothing wrong in a strict legal sense.
While its tempting to think that he was just made an example of for embarrassing a corporation, he did write a script to harvest 120,000 email addresses from the AT&T server. I'd say that constitutes criminal intent, even if he had no intention of using the addresses for a criminal purpose.
There are two problems here: 1. absent or weak data protection laws, and 2. disproportionate sentencing guidelines (up 10 years) for what in this case is basically a victimless crime.
[1] http://www.nytimes.com/2013/02/03/technology/consumer-data-p...
Re: Andrew 'Weev' Auernheimer Faces Jail
#20It blows my mind that someone could get 10 years for idempotent operations on what was essentially a public API. Put in any other context than "scary computer hacking", it would be obvious to most people that the insecure system was at least as much to blame as this kid.
Firstly, the laws around this sort of thing are very stupid. But with that said...I'm not wholly sympathetic here. The disclosure was totally botched . The IRC logs that came out during the case showed that Andrew and Dan (Spitler) talked about shorting AT&T stock (they ended up not doing this, but it's not the sort of thing you talk about), and going directly to news organisations, bypassing AT&T. They also consider…