Live data from Hacker News

“The AT&T Hacker” Sentenced To 41 Months In Prison

techcrunch.com

121–130 of 176 posts

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#122

If you are driving down the street, and notice that I put the deadbolt onto my house backwards (so that it locked from the outside), is the appropriate thing to do to let yourself in and walk around looking at all my stuff and then call the local news station and invite them in along with you, or is it to call the police or leave me a note letting me know I've got a problem?

Your private house - yes sure. But if you are a bank, commercially offering "secure" services for profit, and the deadbolt is on the outside, then any public outing is to be expected. Really this is abou a lack of understanding of software and architecture by the entire public - imagine a bank had actually put a million Dollar safe up and had forgotten to put a lock on it - the competitors CEO would expect to be fire…

So why not, having discovered this major security breach, contact a lawyer and sue AT&T for negligently sharing your private information?

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#123
post #117
post #39

Earlier quoted context omitted.

If he doesn't care why should I? I know many security researchers who aren't trolls and they are doing fine. When it happens to somebody who isn't purposefully self-destructive, then it may be a better case for concern.

Because living at the mercy of the government only not prosecuting you simply because they think you're not a dick doesn't scale to 100% of a free society. This is why the ACLU defended the Klan.

The ACLU defended the right of the Klan to march.

This is different than a Klansman being on trial for his car crashing into a bus stop full of black kids, and then publicly announcing before sentencing that "I'm only sorry I didn't kill any of darkies."

The Klansman's own words are used to show intent. Without them, he might legitimately argue that it was a honest accident. Maybe believably, depending on other evidence.

Using someone's own words against them in court is not a violation of freedom of speech. Intent matters, and that doesn't mean we have thought-crime.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#124

Earlier quoted context omitted.

1. First, it's going to be appealed to an appeals court :) 2. Generally, if you are smart, you don't bring wildly unsympathetic defendants to SCOTUS at all (IE you don't go to war over them). There are cases it doesn't matter, but one of the reason we ended up with so many 4th amendment exceptions is, IMHO, because of the habit of bringing really unsympathetic people/facts to SCOTUS back when we had justices like O'C…

That's part of it, but it was a natural reaction to the total collapse of order and the explosion in crime in U.S. cities in the 1970's and 1980's. The fact is that most of the people invoking the 4th amendment were really unsympathetic. They still are.

Of course they're unsympathetic -- if they were merely good citizens who were hassled for no good reason, there wouldn't have been a charge.

Improper search and seizure leading to a trial is going to have found drugs/guns/whatever, by definition. That doesn't mean the rest of us should have our 4th amendment rights weakened.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#125
It should be noted that he was convicted on two counts: conspiracy to access a computer system without authorization, and fraud in connection with personal information.

The way the CFAA works is that it's a misdemeanor unless the illegal access is pursuant to some other crime, which bumps it up to a felony. Had weev simply stumbled upon AT&T's security flaw and reported it AT&T, the worst they could have gone after him for is a misdemeanor.

People are acting like the fact that he downloaded tens of thousands of pieces of personal information is totally irrelevant, but it's not. It's highly relevant. It's why he's been convicted of a felony rather than a misdemeanor. And it should make intuitive sense and it's mind-boggling to me that somehow people on here intellectualize the situation to the point where they write out this part of the facts.

In meat space, the crime of trespassing can range in severity from a nothing to a serious felony depending on what the surrounding circumstances says to a jury about the trespasser's intent. Here, it was totally reasonable for a dispassionate observer to conclude that weev's intent in downloading tens of thousands of pieces of personal information (not to mention the IRC conversations) was seriously malevolent.

It should finally be noted that the "fraud in connection with personal information" conviction would have been by itself sufficient to support the sentence.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#126
post #13

Earlier quoted context omitted.

It doesn't really matter if the guy is an asshole. Harsher sentences for incrementing a URL than for rape or vehicular manslaughter are ridiculous.

Sure, but that's a question for the legislature, of course. Courts are going to give deference to the policy choices of what crimes deserve what punishments.

They hit him with the maximum sentence, not the minimum -- this one's on the courts. If it was a case of someone going away for 10 years for shoplifting because of 3 strikes, then that's on the legislature.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#127

I keep seeing posts referencing that his actions were "technically trivial." How does anyone propose we write or enforce legislation based on that criteria?

How about, for unauthorised access to have occurred, the data accessed must have been 'secured', with 'secured' defined according to industry practices.

If I told a client that I had 'secured' their website, but access was available by incrementing an integer, they could sue me and they would win.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#128
post #90

Earlier quoted context omitted.

It wasn't just being mean. First-hand experience in my case. He and his GNAA attacked my volunteer-run open source project and did many things, including calling Child Protective Services (CPS) and making false complaints -- leading one of my volunteers and his children to have to undergo interviews with CPS to suss everything out. They emailed one person's professors at university and made false, damaging claims. Bo…

I have no trouble believing that weev did those things and worse, and it is probably criminal behavior, and if so it should be punished. But that has nothing to do with what the gov't. has just done. Just as defense atty's want sympathetic defendants, prosecutors are happy to exploit the unsympathetic response that most people have to learning about weev's behavior. If we let them do it to weev, we are inviting them…

Well, previous behaviour has everything to do with sentencing. Seriously, they don't just look at the case and go "41 months!", they weigh everything up and go from there. The likelihood is a security researcher with a spotless past wouldn't have gone through it, prosecution would have pushed for a hard sentence of course but the final judgement takes into account everything.

Basically, the prosecution wanted a harsh sentence to set precedent and weev gave them the ammo to do it.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#129
post #124

Earlier quoted context omitted.

That's part of it, but it was a natural reaction to the total collapse of order and the explosion in crime in U.S. cities in the 1970's and 1980's. The fact is that most of the people invoking the 4th amendment were really unsympathetic. They still are.

Of course they're unsympathetic -- if they were merely good citizens who were hassled for no good reason, there wouldn't have been a charge. Improper search and seizure leading to a trial is going to have found drugs/guns/whatever, by definition. That doesn't mean the rest of us should have our 4th amendment rights weakened.

I don't disagree with you. My point is that it's important to understand the context. The federal courts are absolutely clogged with appeals and habeas petitions from "bad people" who clearly did whatever they were charged with. People who are just trying to get off for serious crimes by grasping at technicalities (because they're in prison and have nothing better to do anyway). For all the skepticism about the police, they don't like losing prosecutions and as a result tend to go after slam-dunk cases.

For the courts charged with maintaining these protections, it can be hard to keep a hard-line stance in favor of 4th/5th amendment protections in face of a docket that is chock full of actual criminals who actually deserve their sentences.

It's an explanation, not a justification.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#130
post #100
post #74

Earlier quoted context omitted.

The first amendment makes no distinction between someone who says "Hey your shitty website is broken. And I'm telling everybody." and someone who sends a private email, hat in hand, saying; "Excuse me kind sirs, but I can't help but notice that your security procedures are somewhat lacking." And oddly, if one of those is a crime, so is the other.

Does the First Amendment make a distinction between a person in a crowded room shouting "I love U2" and the same person shouting "Fire"? I'm going to go ahead and suggest that the answer is "No, but we as a society make a distinction." Same princple here. I believe the general principle is that you have freedom of speech, but you do not have indemnity from the harmful consequences of your speech.

The judge who said that the 1st amendment doesn't cover shouting fire in a crowded theater used it as an argument to jail people for handing out anti-war fliers.

So it's not even appropriate for me to say that it's a slippery slope, because it started at the bottom.

Post reply on HN