Live data from Hacker News

You May Not Like Weev, But Your Online Freedom Depends on His Appeal

wired.com

11–20 of 145 posts

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#11
post #8
post #4

I, for one like Weev. He is a boundary pusher. Many even around here on hn might perceive his stuff as tasteless. But I sincerely wished more people were as dedicated to their "ideals" as Weev is. Defending free speech means standing up for people who have controversial views - no matter how unease you personally are with these views.

How do you make this a speech issue?

For example he got thrown into solitary for tweeting?

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#12

I agree with the sentiment that computer use crimes need to be reworked, and that weev shouldn't have been hoisted by the fact he is a colossal dick but the article seems to gloss over things for the sake of the argument. - `The spoofing was irrelevant; Spitler would have gotten the same email addresses if he had manually inputted the URLs on an iPad rather than a spoofed desktop browser.`, the spoofing is incredibly…

It doesn't matter if they accessed one or a million - accessing information published on the web SHOULD NOT BE CRIMINAL.

Whether you agree with his methods or not, there is no stretch of the imagination that makes prison for downloading (even 114k of) them make sense.

It wasn't a hole or bug— it was an expressly implemented feature. ATT decided to do it this way to reduce resubscription friction. The iPad sends the sim serial (ICCID), and ATT sends the HTML form with the email address already filled in, so all the user has to do is enter the password.

As it turns out, ICCIDs are sequential integers.

It should always be perfectly legal to access a remote computer system via a publicly accessible interface. It's up to that remote system to respond appropriately. In this case, it was working exactly as ATT intended.

Weev knew that the greater the number of records he got, the worse it would reflect upon ATT, and rightfully so.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#13

I agree with the sentiment that computer use crimes need to be reworked, and that weev shouldn't have been hoisted by the fact he is a colossal dick but the article seems to gloss over things for the sake of the argument. - `The spoofing was irrelevant; Spitler would have gotten the same email addresses if he had manually inputted the URLs on an iPad rather than a spoofed desktop browser.`, the spoofing is incredibly…

There's certainly a fairly well culturally established method of dealing with holes in corporate internet security which Weev did not follow in this case.

However as a third person it's also useful for me to know the scope of this hole and how liable my own information was. Weev here is guilty of exactly the same reasoning that AT&T realised in court which is that a message is irrelevant without impact. And which has more impact: an article about how a vulnerability in AT&T security could have resulted in some leaked emails or an article about 114 000 potentially leaked email addresses?

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#14
post #7
post #3

It is a terrible decision curl http://domain.com/showdocument?[00000-99999] should not be a crime!!

What if doing so killed a person for each ID at showdocument? Ok, that's pretty absurd. What if it wiped out their bank account? Don't you think that the consequences should depend on what the action actually accomplished, rather than the action itself? Flicking a lighter is generally pretty innocuous, but if done to light a house on fire, it means it's a bit different - right? Yes, it's their fault too for leaving i…

"What if doing so killed a person for each ID at showdocument? Ok, that's pretty absurd. What if it wiped out their bank account?"

Shouldn't you hold the people who created that system responsible, rather than the person who used it? If I rig up my cell phone to a gun, so that every time someone calls it it shoots at a crowd of people, should the people who call it go to prison while I walk free?

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#15
post #10
post #3

It is a terrible decision curl http://domain.com/showdocument?[00000-99999] should not be a crime!!

Should I be allowed to brute force passwords then?

Yes, because organizations that use simple password-based authentication to secure important things (bank accounts, private messages, etc.) should be held responsible for the outcomes of such attacks. In such a world the state of computer security would not be so pitiful.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#16
post #10
post #3

It is a terrible decision curl http://domain.com/showdocument?[00000-99999] should not be a crime!!

Should I be allowed to brute force passwords then?

Passwords are hashed in an attempt to conceal them.

Websites are served in an attempt to disseminate them.

There's a big difference here.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#17
post #7

Earlier quoted context omitted.

What if doing so killed a person for each ID at showdocument? Ok, that's pretty absurd. What if it wiped out their bank account? Don't you think that the consequences should depend on what the action actually accomplished, rather than the action itself? Flicking a lighter is generally pretty innocuous, but if done to light a house on fire, it means it's a bit different - right? Yes, it's their fault too for leaving i…

"What if doing so killed a person for each ID at showdocument? Ok, that's pretty absurd. What if it wiped out their bank account?" Shouldn't you hold the people who created that system responsible, rather than the person who used it? If I rig up my cell phone to a gun, so that every time someone calls it it shoots at a crowd of people, should the people who call it go to prison while I walk free?

If they know what happens when they call, yes, they should go to jail too.

He knew what he was doing once he'd pulled down a few records.

Also, yes, ATT should be held responsible for implementing lame security.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#18
post #8
post #4

I, for one like Weev. He is a boundary pusher. Many even around here on hn might perceive his stuff as tasteless. But I sincerely wished more people were as dedicated to their "ideals" as Weev is. Defending free speech means standing up for people who have controversial views - no matter how unease you personally are with these views.

How do you make this a speech issue?

Weev was surveilled and harassed by the feds for ages before they finally got this one to stick.

He'd been on their radar for years due to his unpopular speech.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#19
post #10
post #3

It is a terrible decision curl http://domain.com/showdocument?[00000-99999] should not be a crime!!

Should I be allowed to brute force passwords then?

Yes. You can't use force or coercion to rob a server of data, all you can do is ask nicely (or repeatedly).

In a just world, we would let full responsibility lie with those who deployed the machines without understanding the consequences of, e.g., no login failure rate limiting.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#20

I agree with the sentiment that computer use crimes need to be reworked, and that weev shouldn't have been hoisted by the fact he is a colossal dick but the article seems to gloss over things for the sake of the argument. - `The spoofing was irrelevant; Spitler would have gotten the same email addresses if he had manually inputted the URLs on an iPad rather than a spoofed desktop browser.`, the spoofing is incredibly…

If he were guessing passwords jail time might be appropriate.

It's fucking ridiculous that changing the user agent, even to circumvent server "protections", would be a crime worthy of any jail time whatsoever. What is he guilty of? Criminal misrepresentation of web browser?

Post reply on HN