Live data from Hacker News

How to cause moral outrage from the entire Internet in ten lines of code

community.livejournal.com

41–50 of 113 posts

Re: How to cause moral outrage from the entire Internet in ten lines of code

#41
post #35

Earlier quoted context omitted.

Actually, it compares very well. Your typical consumer door lock might as well just not be there to a skilled lock picker.

I don't know... maybe this could fall into the category of 'spam' - using up resources of a remote computer without permission etc, but the fact is he wasn't the one using the resources. It was the users visiting the websites containing the iframe. At the end of the day, IMHO this shouldn't be illegal, and no action should be taken. Amazon was extremely silly to accept user flagging from a GET request in an iframe.

Whoa, this is smacking of rationalization.

How is what your're saying different from, "I didn't send those DDOS packets, the lusers executing my trojan program did!"

How about: "IMHO, that shouldn't be illegal. Mrs. Smith was extremely silly to believe that a consumer door lock and sticking her life savings under her mattress was a good way to secure money."

Re: How to cause moral outrage from the entire Internet in ten lines of code

#42
post #23
post #20

Earlier quoted context omitted.

I should certainly hope not. While he's certainly mischievous and possibly malicious, he didn't actually do anything that I think should be illegal. He merely used Amazon's flawed system against them, at considerably personal expense. He hacked them, in other words. I can't agree with his aims in this case but you've got to hand it to him really - you don't have to like trolling in general to admit that was an amazin…

> he didn't actually do anything that I think should be illegal. Registering multiple false user names? Giving false feedback? Restraint of trade? I'm not a fan of government prosecuting someone for registering on Facebook with the user name "Joe Schmoe" in order to blog anonymously about their crappy job at Microsoft. ...but I have no problem at all with the government enforcing laws against using aliases to log int…

"Registering multiple false user names?

Giving false feedback?"

Well then, unless your actual name is "tjic" then we are both criminals right off the bat. And since when is the government in the business of checking whether feedback is "false" or not? That's the company's job. It's not illegal to lie unless you are under oath, and nobody was.

"Restraint of trade?"

I don't see how Amazon's trade has been restrained in any way, shape or form. Unless you consider criticism or bad reputation to be restraint of trade, in which case any criticism is fair game. Very dangerous ground.

"but I have no problem at all with the government enforcing laws against using aliases to log into a system and inject bad data in order to create a public relations firestorm?"

Who says it's bad data? What's wrong with aliases? You're trying to legislate against intent.

And your example of how Joe Schmoe should be protected even though he's slagging off Microsoft - MS will say that's bad data bringing a PR firestorm. It just doesn't work.

"I'd be somewhat pissed if someone used my flawed front door lock (pickable by anyone with a set of picks, 60 seconds to spare, and decent picking skills) against me."

Dear god, not this argument again. Look, physical security is NOT the same as network security. It is impossible to totally guarantee physical security. It is possible, even easy, to create perfect network security. The two are totally at odds. Creating a few fake accounts and submitting some votes (which Amazon encourages) is not even remotely similar to breaking into your house and placing signs advertising your partiality to child molestation.

You are giving Amazon a free pass for their lax security practises, and placing all the blame on some random guy who had the balls to admit he did it. And if it was illegal, the only thing that would change is that he wouldn't have admitted it. You can't have laws like that. You may as well try to make a law that everyone has to be nice.

Re: How to cause moral outrage from the entire Internet in ten lines of code

#43
post #19

Wow. Anyone who owns, or hopes to own, an internet-based community of any type should read this, just to get a sense of the sophisticated methods and the lengths trolls will go to. While I have to hand it to this guy for deviousness and persistence, he is, after all, the "enemy" as far as the Web Site Owner is concerned. It boggles the mind that anyone would do this, but they evidently do, and you may well have to de…

History is littered with the blood of people fighting over social issues... We shouldn't be too surprised by the lengths, but the appeals for security concerns rings loud and true.

Re: How to cause moral outrage from the entire Internet in ten lines of code

#44
post #26

Earlier quoted context omitted.

Laws exist to deter people from doing things that are possible, so the fact that their system allowed him to do it is irrelevant. The quality of the troll is also irrelevant. The fact that you commit a crime really well doesn't make it any less illegal. That said, I'm not certain what he did should have been illegal. But I can't think of a single reason he shouldn't be sued. There's no way he didn't forsee loss of re…

How do you equate doing harm to another person with reducing revenue for a collection of entities (Amazon and its sellers)? Consider the small startup eating an established business's lunch; surely the startup isn't liable for the losses of the larger company.

Reducing income by out-competing another company in a transparent and open marketplace is one thing. Reducing income by manipulating information in a deceptive fashion (thereby making the marketplace less transparent) is another thing entirely.

There were ways Weev could've made his hacking skill known without such negative impacts. He cared more about the notoriety than preventing harm to bystanders. (Though to be fair, he probably has rationalizations for why these weren't "real" negative impacts.)

Re: How to cause moral outrage from the entire Internet in ten lines of code

#45
post #38
post #26

Earlier quoted context omitted.

Laws exist to deter people from doing things that are possible, so the fact that their system allowed him to do it is irrelevant. The quality of the troll is also irrelevant. The fact that you commit a crime really well doesn't make it any less illegal. That said, I'm not certain what he did should have been illegal. But I can't think of a single reason he shouldn't be sued. There's no way he didn't forsee loss of re…

Posting a message that you got food poising from a local restaurant will cause them to lose money without you breaking the law. Would you say it's reasonable for them to sue you if you where telling the truth?

It certainly would be reasonable for them to sue you if you had lied.

Re: How to cause moral outrage from the entire Internet in ten lines of code

#46

Earlier quoted context omitted.

keep in mind, he probably doesn't believe a third of that. if he'd do what he seems to have done to amazon for attention, then you know he's willing to make up inflammatory lies for an interviewer.

Trollers are sadists, period. Just because you are capable of the problem solving and coding required to pull stunts like this off doesn't justify deceiving others and causing them anguish. I have no idea if they believe the ideologies they spin to justify what they do as a perverse form of heroism. All of the worst assholes in history had ideology aplenty to justify their destructive behavior.

It's all justified as long as it is funny.

I guess it is easy to be a prick when you are only looking at pixels.

Re: How to cause moral outrage from the entire Internet in ten lines of code

#47
post #35

Earlier quoted context omitted.

I don't know... maybe this could fall into the category of 'spam' - using up resources of a remote computer without permission etc, but the fact is he wasn't the one using the resources. It was the users visiting the websites containing the iframe. At the end of the day, IMHO this shouldn't be illegal, and no action should be taken. Amazon was extremely silly to accept user flagging from a GET request in an iframe.

Whoa, this is smacking of rationalization. How is what your're saying different from, "I didn't send those DDOS packets, the lusers executing my trojan program did!" How about: "IMHO, that shouldn't be illegal. Mrs. Smith was extremely silly to believe that a consumer door lock and sticking her life savings under her mattress was a good way to secure money."

A company like Amazon should be able to deal with DDOS and CSFR in it's stride though. They should present absolutely no challenge.

The correct response IMHO is for Amazon to realize they were stupid, and fix it. If you sue etc you put out the signal that being stupid is fine - you'll be able to sue someone if they take advantage of your stupidity.

But then we live in an age where if someone doesn't tell you explicitly that your coffee is hot, and you spill it, you can sue them...

Re: How to cause moral outrage from the entire Internet in ten lines of code

#48
post #18

I'm mainly wondering if he can get his face sued off over this. I've got NO doubt that this is going to have a noticable negative impact on Amazon's profits. Not world shaking, but more than enough to make the lawyers angry. As another commenter mentioned, he's been in a NYT article, with his face and full name displayed. Amazon won't have any trouble finding him.

I for one hope he does. He's not some internet freedom fighter going up against the man, nor is he a legitimate security expert in any way. He did it for the lulz, I hope he gets his ass sued off. He's like the kid dropping rocks off the overpass for shits and giggles - pathetic.

What I do hope for is that one day when they get arrested that the officers let them know it's ok as they're going to prison for the lulz.

Re: How to cause moral outrage from the entire Internet in ten lines of code

#49
post #35

Earlier quoted context omitted.

I don't know... maybe this could fall into the category of 'spam' - using up resources of a remote computer without permission etc, but the fact is he wasn't the one using the resources. It was the users visiting the websites containing the iframe. At the end of the day, IMHO this shouldn't be illegal, and no action should be taken. Amazon was extremely silly to accept user flagging from a GET request in an iframe.

Whoa, this is smacking of rationalization. How is what your're saying different from, "I didn't send those DDOS packets, the lusers executing my trojan program did!" How about: "IMHO, that shouldn't be illegal. Mrs. Smith was extremely silly to believe that a consumer door lock and sticking her life savings under her mattress was a good way to secure money."

Well, actually, it is those "lusers" who executed the trojan, and their computers, capable of action and under their control, that sent the packets. Since when is "but I didn't know!" an excuse? Sounds like negligence to me; widespread perhaps, but negligence nonetheless.

It's like those people who buy those terrible cheap car alarms that go off at anything at all and then don't stop for an hour. Their car is sitting there, ruining everyone's quality of life with its incessant blaring. Can they just excuse themselves by saying "well it's not me, it's the car alarm"? Of course not. If you own something, and that something is capable of harm, it's your responsibility to ensure its integrity. Blithe ignorance is no excuse at all.

The door lock/money under the mattress analogy doesn't hold up. Mrs Smith did not invite millions of visitors from around the world into her house to walk around her bedroom, relying solely on the mattress to hide her treasure, and if she had no-one would have much sympathy when one of them eventually looked there. Amazon did invite such behaviour and should have taken appropriate safeguards. This is no-one's fault but their own.

Re: How to cause moral outrage from the entire Internet in ten lines of code

#50
post #19

Wow. Anyone who owns, or hopes to own, an internet-based community of any type should read this, just to get a sense of the sophisticated methods and the lengths trolls will go to. While I have to hand it to this guy for deviousness and persistence, he is, after all, the "enemy" as far as the Web Site Owner is concerned. It boggles the mind that anyone would do this, but they evidently do, and you may well have to de…

Apparently, this guy seems to be a long time troll:

http://valleywag.gawker.com/5032989/journalists-do-it-for-th...

http://www.nytimes.com/2008/08/03/magazine/03trolls-t.html

Post reply on HN