Live data from Hacker News

You May Not Like Weev, But Your Online Freedom Depends on His Appeal

wired.com

31–40 of 145 posts

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#31
post #12

Earlier quoted context omitted.

It doesn't matter if they accessed one or a million - accessing information published on the web SHOULD NOT BE CRIMINAL. Whether you agree with his methods or not, there is no stretch of the imagination that makes prison for downloading (even 114k of) them make sense. It wasn't a hole or bug— it was an expressly implemented feature. ATT decided to do it this way to reduce resubscription friction. The iPad sends the s…

So, if somebody has SSH open on port 22, root password login enabled, and a root password of Pa$$w0rd, and I guess that and log in, should that be legal? If so, what about a more complex password? Should we legalise other remote attacks on systems? It could very reasonably be argued that in the case of AT&T's system, device IDs count as passwords for accessing the system. Simplifying things a little, there was an API…

Just because there's an expectation of privacy doesn't mean that such an expectation is reasonable.

It is not reasonable to have an expectation of privacy if your root password is "password" and you have ssh open to the world, no.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#32
post #18
post #8

Earlier quoted context omitted.

How do you make this a speech issue?

Weev was surveilled and harassed by the feds for ages before they finally got this one to stick. He'd been on their radar for years due to his unpopular speech.

He claims they tried to frame him 5 times for terrorism, yet I can't find any articles which details what happened. Is there any solid evidence of this, or is it mainly speculation?

Also, if you're already on the FBI's radar, wouldn't you think it be smarter to lay low and wait until things cool down before you start hacking again?

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#33
post #3

It is a terrible decision curl http://domain.com/showdocument?[00000-99999] should not be a crime!!

How about curl http://domain.com/attemptlogin?username=[aaaaa-zzzzz]&passwo..., followed by curl http://domain.com/admin/wipeeverything?username=x&password=y ?

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#34
post #12

I agree with the sentiment that computer use crimes need to be reworked, and that weev shouldn't have been hoisted by the fact he is a colossal dick but the article seems to gloss over things for the sake of the argument. - `The spoofing was irrelevant; Spitler would have gotten the same email addresses if he had manually inputted the URLs on an iPad rather than a spoofed desktop browser.`, the spoofing is incredibly…

It doesn't matter if they accessed one or a million - accessing information published on the web SHOULD NOT BE CRIMINAL. Whether you agree with his methods or not, there is no stretch of the imagination that makes prison for downloading (even 114k of) them make sense. It wasn't a hole or bug— it was an expressly implemented feature. ATT decided to do it this way to reduce resubscription friction. The iPad sends the s…

"It should always be perfectly legal to access a remote computer system via a publicly accessible interface.", no it shouldn't, no more than it should be legal for me to walk into your house if you've not locked the door.

The system worked exactly as AT&T intended, in circumstances they'd clearly not planned for. If they'd bothered doing a risk assessment they'd have spotted it, they took the lazy option and it didn't work.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#35
post #18

Earlier quoted context omitted.

Weev was surveilled and harassed by the feds for ages before they finally got this one to stick. He'd been on their radar for years due to his unpopular speech.

He claims they tried to frame him 5 times for terrorism, yet I can't find any articles which details what happened. Is there any solid evidence of this, or is it mainly speculation? Also, if you're already on the FBI's radar, wouldn't you think it be smarter to lay low and wait until things cool down before you start hacking again?

Depending on which list you are talking about, there are tens of thousands, hundreds of thousands, or millions of Americans on "The List." You might be one.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#36

Earlier quoted context omitted.

You and sneak seem to be proposing a legal regime under which no "hacking" of any kind is illegal. If the system will perform action B given request A, issuing request A, no matter the intent, cannot be a crime? If I'm missing an important distinction you'd make, I'd very much like to hear what it is.

I would prefer if the system punished people for what they did with their access to data, not simply for having that access; organizations that hold private or sensitive information should be punished if unauthorized people can access it by any means. Having email addresses or credit card numbers should not be the crime, regardless of how you obtained that information. Committing credit card fraud or selling credit c…

Apologies for crossing threads, but aren't you pretty upset that the NSA simply has Verizon phone records, despite a lack of evidence they're planning on doing anything nefarious with them?

Anyway, as I understand it, weev did speculate about selling the information. And would you be so sanguine if this were health records or private photographs? I'm not seeing a plausible guiding principle here.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#37
post #12

Earlier quoted context omitted.

It doesn't matter if they accessed one or a million - accessing information published on the web SHOULD NOT BE CRIMINAL. Whether you agree with his methods or not, there is no stretch of the imagination that makes prison for downloading (even 114k of) them make sense. It wasn't a hole or bug— it was an expressly implemented feature. ATT decided to do it this way to reduce resubscription friction. The iPad sends the s…

So, if somebody has SSH open on port 22, root password login enabled, and a root password of Pa$$w0rd, and I guess that and log in, should that be legal? If so, what about a more complex password? Should we legalise other remote attacks on systems? It could very reasonably be argued that in the case of AT&T's system, device IDs count as passwords for accessing the system. Simplifying things a little, there was an API…

Also, both SSH and HTTP have defined authentication mechanisms built into the protocol.

The HTTP spec has a response code, 403, for indicating that a request (potentially without authentication information) is unauthorized. SSH has a similar defined response.

If there's _no authentication around it_, I would argue that it's published to the public web, regardless of the protocol in use to deliver it.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#38

I agree with the sentiment that computer use crimes need to be reworked, and that weev shouldn't have been hoisted by the fact he is a colossal dick but the article seems to gloss over things for the sake of the argument. - `The spoofing was irrelevant; Spitler would have gotten the same email addresses if he had manually inputted the URLs on an iPad rather than a spoofed desktop browser.`, the spoofing is incredibly…

The question is after hearing AT&T prosecute Spitler for discovering such a simple security hole (it could have been a lot more complex) would you feel safe disclosing any security hole even with the best intentions?

The answer is obviously no and if you can't make it public without risking being sent to prison the only option is selling it to some shady spammers.

Which would you prefer happened? From my point of view what they are doing is basically pushing the hackers to the "dark side". If we disclose it we get arrested if we sell it we might get caught and arrested or make a lot of money. I'll take option 2.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#39
post #12

Earlier quoted context omitted.

It doesn't matter if they accessed one or a million - accessing information published on the web SHOULD NOT BE CRIMINAL. Whether you agree with his methods or not, there is no stretch of the imagination that makes prison for downloading (even 114k of) them make sense. It wasn't a hole or bug— it was an expressly implemented feature. ATT decided to do it this way to reduce resubscription friction. The iPad sends the s…

"It should always be perfectly legal to access a remote computer system via a publicly accessible interface.", no it shouldn't, no more than it should be legal for me to walk into your house if you've not locked the door. The system worked exactly as AT&T intended, in circumstances they'd clearly not planned for. If they'd bothered doing a risk assessment they'd have spotted it, they took the lazy option and it didn'…

Please stop with the physical analogies. Locks and doors and physical space have well defined ways of indicating "authorized" and "unauthorized". We also have a social contract about entering spaces of others, even if there are no locks at all.

The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_.

It's up to that server, and nothing else, to be the final arbiter of authorized/unauthorized. You don't get to move the goalposts after the fact, saying "oh, well we didn't INTEND for you to use it that way".

That's putting the burden to avoid jail on to the requester, who is now responsible for making assumptions and inferring the intent of programmers/admins they've never met or communicated with. It's lunacy.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#40
post #27

Earlier quoted context omitted.

>It should always be perfectly legal to access a remote computer system via a publicly accessible interface. It's up to that remote system to respond appropriately. In this case, it was working exactly as ATT intended. The law can never be this black and white, it is all about context. Just because you may somehow access something on the web, doesn't mean it is automatically ok to do so.

You're right, the law can't. That's why we should let the final verdict for authorized/unauthorized lie IN THE CODE DEPLOYED BY THE OWNER, not the law (or the owner's retroactive statements). It's pretty simple, really. This would be a non-issue if you programmed your cyborg to go pick up milk from the store and it started handing out $20s to strangers in the dairy aisle. Obviously that's no fault but your own. Why i…

So if a bank accidentally deposits $1bn in your account, that becomes yours? You're looking for a simple answer to a nuanced issue where one just doesn't exist.
Post reply on HN