“The AT&T Hacker” Sentenced To 41 Months In Prison
81–90 of 176 posts
Re: “The AT&T Hacker” Sentenced To 41 Months In Prison
#82Earlier quoted context omitted.
You don't "gather the evidence", you rather take the records for 100,000 citizens, put them on a truck and dump them in the frontyard for a local newspaper, after considering how much you could sell it for and deciding it's probably more fun to just cause public embarrassment. If you wanted just to show the system is insecure, 2 records would be enough. Stealing 100K of them is not something you do if your goal is ju…
There's definitely a "being an ass" component to this, no doubt... but one could argue that presenting two records to a journalist implies a small security hole. 100k of them is a giant security hole.
Re: “The AT&T Hacker” Sentenced To 41 Months In Prison
#83Earlier quoted context omitted.
There's definitely a "being an ass" component to this, no doubt... but one could argue that presenting two records to a journalist implies a small security hole. 100k of them is a giant security hole.
Yah, except for the part where he spends an extra 10 seconds explaining "here are 2 of hundreds of thousands, as an example". The headline would be the same: "X Company exposes N Number of user accounts in discovered security hole". So do you see where that doesn't make any sense? edit: agree with you @drhayes9, just responding to the OP's assertion that the number mattered.
I think the numbers helped sensationalize it, sure.
Re: “The AT&T Hacker” Sentenced To 41 Months In Prison
#84Earlier quoted context omitted.
Try making an honest comparison instead. This photo was taken at a restaurant, from the outside looking in, before it opened for the day: http://www.blogto.com/upload/2008/02/20080215_rats.jpg The restauranteurs were not informed about it; it went straight to the media and to the city health department. The restaurant was shut down later that day for health violations. Has a crime been committed? Did the photographer…
None. Notice that the photographer was OUTSIDE. He didn't remove any property from the restaurant. He did not physically enter the restaurant. Part of the problem, and I think you'll agree with me on this, is that these metaphors breakdown because, when talking about information and systems, the notions of property are much more complicated. What if, for example, the photographer photographed a sheet of paper with 10…
It's quite easy to casually condone three years in a cage for someone you don't like when that's your only involvement.
Re: “The AT&T Hacker” Sentenced To 41 Months In Prison
#85I really hope Jury nullification http://en.wikipedia.org/wiki/Jury_nullification becomes a bigger thing in this country..
Re: “The AT&T Hacker” Sentenced To 41 Months In Prison
#86It's going to cost approx $40,000 per year to keep this non-violent criminal off the streets. (From Wikipedia, California state prison, 2008)
The US should probably consider not putting people into prison unless they are violent offenders, or unless they are repeat offenders. (But even for repeat offenders it's probably cheaper to work out why they're offending and put something in place to stop that.)
(https://en.wikipedia.org/wiki/Incarceration_in_the_United_St...)
Re: “The AT&T Hacker” Sentenced To 41 Months In Prison
#87Earlier quoted context omitted.
I don't think this particular case is black and white. Judging by my Twitter feed, a number of security researchers and white hats feel the same way I do: the law as it stands is not good, but what Weev did was also really, really unhelpful and borderline stupid. Rather than disclosing to AT&T, he leaked it directly to Gawker, and discussed how to potentially abuse the data he had (by shorting the stock, selling the…
Sounds like a bunch of victim blaming to me. So the guy is an idiot, is that enough to go to prison now?
Ironic that you should say that, considering that Weev's defense is essentially "her parameters were all hanging out and it was just so easy."
Re: “The AT&T Hacker” Sentenced To 41 Months In Prison
#88Re: “The AT&T Hacker” Sentenced To 41 Months In Prison
#89Earlier quoted context omitted.
I think the thing is that weev genuinely doesn't care if he gets 41 months vs. 36 months. This is a long troll by him; by being a troll, he brings more attention to the case, maximizing lulz, and bringing bigger guns to bear in his defense. If he'd gotten 3-6 month suspended sentence, even if you thought that was a bit much for essentially incrementing numbers, you'd probably not care much. If he were facing life in…
If he doesn't care why should I? I know many security researchers who aren't trolls and they are doing fine. When it happens to somebody who isn't purposefully self-destructive, then it may be a better case for concern.
If you pay US taxes you're paying to keep him in jail. I think he's a vile idiot. I don't think he should be in prison.
There's a bunch of stuff that I think he did wrong, but I'll have to read the court documents to see if I agree with them.
For example: He could have written a proof of concept script, and only downloaded a sample 10 pages, rather than grabbing as many as possible.
I might think that would have prevented him going to jail, but would the court agree?
Re: “The AT&T Hacker” Sentenced To 41 Months In Prison
#90I've never seen an uglier IAMA on reddit: http://www.reddit.com/r/IAmA/comments/1ahkgc/i_am_weev_i_may...
Just when you think your opinion of Reddit can't get any lower... I can't believe how many people think you should go to jail for being mean.
First-hand experience in my case. He and his GNAA attacked my volunteer-run open source project and did many things, including calling Child Protective Services (CPS) and making false complaints -- leading one of my volunteers and his children to have to undergo interviews with CPS to suss everything out.
They emailed one person's professors at university and made false, damaging claims. Bosses were tracked down and jobs were contacted. Parents were found and harassed. Our web site was attacked and taken offline. Our business associates were contacted and they concocted a fictitious business persona to file spurious complaints with our payment processors, leading to us being dropped from two providers.
weev was not just "being mean", he transcended that to stalking, bullying, and harassment. He caused emotional harm to my volunteers and staff and fiscal harm to my business. All in the name of "trolling".
And yes: we pursued the legal route. The FBI is just not super interested in tracking down some random dude on the Internet for harassing a small business. They were happy to talk to us and very compassionate and gave us some advice, but that was the extent of it.