Live data from Hacker News

“The AT&T Hacker” Sentenced To 41 Months In Prison

techcrunch.com

21–30 of 176 posts

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#21
post #13
post #5

For context, this guy used to be part of the GNAA. They don't care at all about exposing security holes. His goal probably wasn't to cause some sort of security improvement. Yeah, the punishment was harsh, but this guy isn't exactly a folk hero.

It doesn't really matter if the guy is an asshole. Harsher sentences for incrementing a URL than for rape or vehicular manslaughter are ridiculous.

Sure, but that's a question for the legislature, of course. Courts are going to give deference to the policy choices of what crimes deserve what punishments.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#23

Earlier quoted context omitted.

I'm not trying to be snarky here, but why do you blame AT&T?

Probably because they were the ones who royally screwed up in the first place, disclosing tons of customer details to literally anyone who wanted it (including automatic web spiders), and nobody from AT&T is going to spend a day in jail or pay restitution for that.

Precisely that. Sure, he made a mistake, but so did AT&T, and now because of it he's potentially going to spend 41 months of his life in jail. Life is too short as it is.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#24

Earlier quoted context omitted.

I'm not trying to be snarky here, but why do you blame AT&T?

Probably because they were the ones who royally screwed up in the first place, disclosing tons of customer details to literally anyone who wanted it (including automatic web spiders), and nobody from AT&T is going to spend a day in jail or pay restitution for that.

This is an important question for our industry. We have almost no liability for the software we produce or the services we provide.

Imagine, though, what the costs of getting a startup off the ground would be like if we did face civil liability for bugs and security flaws.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#25
post #3

Marcia Hofmann is joining his appeals team, so I suspect this is going to SCOTUS. Normally you pick the most compassionate defendant (like they did in Heller in DC) for a test case. Weev is probably the least sympathetic defendant. But I guess you go to war with the weev you have, not the aaronsw you wanted.

1. First, it's going to be appealed to an appeals court :) 2. Generally, if you are smart, you don't bring wildly unsympathetic defendants to SCOTUS at all (IE you don't go to war over them). There are cases it doesn't matter, but one of the reason we ended up with so many 4th amendment exceptions is, IMHO, because of the habit of bringing really unsympathetic people/facts to SCOTUS back when we had justices like O'C…

Obviously it goes through the process, but I think the feds will push to keep CFAA as well, so it's going to go all the way. 41 months is long enough for that; if he'd gotten a 3-6 month sentence the process wouldn't have had time, so maybe weev's "troll the courts" strategy had some merit.

While weev himself is highly unsympathetic, his actual "crime" in this case is quite sympathetic -- it was technically trivial and the results were given to the press, vs. used for financial gain (even though they talked about it). So maybe it's not the worst possible test case.

His biggest mistake was not being in the 9th circuit, though.

(IANAL though, of course)

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#26
Whether they've stated it publicly or not, I would imagine AT&T's main contention with weev is that he released the information publicly (to Gawker) without attempting to disclose the information to them first (please correct me if he did and I've overlooked that). Nonetheless, if he were to have gone to AT&T first I don't think there's anything that could have stopped AT&T from accusing him of hacking and pressing charges anyway since that wouldn't have changed the way he went about discovering the issue. That's scary. Even this particular case aside, how is a person supposed to ethically disclose an exploit to an organization without fear of prosecution?

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#27

If you are driving down the street, and notice that I put the deadbolt onto my house backwards (so that it locked from the outside), is the appropriate thing to do to let yourself in and walk around looking at all my stuff and then call the local news station and invite them in along with you, or is it to call the police or leave me a note letting me know I've got a problem?

I think a more useful analogy is this: there's a large municipal building in town that stores a lot of its citizen's vital records, and they've been slipshod on security. You gather evidence about just how slipshod they've been and turn it over to a journalist.

Conflating what weev did to someone walking around inside your house brings in too many emotional triggers about private property. He wasn't in someone's house, he was trying to demonstrate that the company you hired to keep your private property was doing a crappy job at it.

EDIT: Okay, yes, he was probably just trying to be an ass but fortunately that's not a crime.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#28
post #3

Marcia Hofmann is joining his appeals team, so I suspect this is going to SCOTUS. Normally you pick the most compassionate defendant (like they did in Heller in DC) for a test case. Weev is probably the least sympathetic defendant. But I guess you go to war with the weev you have, not the aaronsw you wanted.

I think somebody that publishes this: http://www.reddit.com/r/IAmA/comments/1ahkgc/i_am_weev_i_may... a day before his sentencing is either completely sure for some reason he gets away with it or is an idiot. Nothing more effective to prove you're not a criminal that saying in public "I only regret I didn't do more harm to whoever they accusing me of harming, next time will be worse". It's like saying "no, I didn't beat up this guy but my only regret is that I didn't break his other arm too". Smart move.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#29

If you are driving down the street, and notice that I put the deadbolt onto my house backwards (so that it locked from the outside), is the appropriate thing to do to let yourself in and walk around looking at all my stuff and then call the local news station and invite them in along with you, or is it to call the police or leave me a note letting me know I've got a problem?

Your private house - yes sure.

But if you are a bank, commercially offering "secure" services for profit, and the deadbolt is on the outside, then any public outing is to be expected.

Really this is abou a lack of understanding of software and architecture by the entire public - imagine a bank had actually put a million Dollar safe up and had forgotten to put a lock on it - the competitors CEO would expect to be fired if he did not take the press and cameras around to have a good laugh

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#30
post #26

Whether they've stated it publicly or not, I would imagine AT&T's main contention with weev is that he released the information publicly (to Gawker) without attempting to disclose the information to them first (please correct me if he did and I've overlooked that). Nonetheless, if he were to have gone to AT&T first I don't think there's anything that could have stopped AT&T from accusing him of hacking and pressing c…

That's my impression of the case as well. Whether or not AT&T would've continued to press charges is a worthless thought exercise. History seems to have shown if you make a good faith effort to keep the company in the loop, things turn out OK, and you at least remain sympathetic should they not.
Post reply on HN