Earlier quoted context omitted.
Yes, because organizations that use simple password-based authentication to secure important things (bank accounts, private messages, etc.) should be held responsible for the outcomes of such attacks. In such a world the state of computer security would not be so pitiful.
You and sneak seem to be proposing a legal regime under which no "hacking" of any kind is illegal. If the system will perform action B given request A, issuing request A, no matter the intent, cannot be a crime? If I'm missing an important distinction you'd make, I'd very much like to hear what it is.
You May Not Like Weev, But Your Online Freedom Depends on His Appeal
41–50 of 145 posts
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#42I agree with the sentiment that computer use crimes need to be reworked, and that weev shouldn't have been hoisted by the fact he is a colossal dick but the article seems to gloss over things for the sake of the argument. - `The spoofing was irrelevant; Spitler would have gotten the same email addresses if he had manually inputted the URLs on an iPad rather than a spoofed desktop browser.`, the spoofing is incredibly…
The question is after hearing AT&T prosecute Spitler for discovering such a simple security hole (it could have been a lot more complex) would you feel safe disclosing any security hole even with the best intentions? The answer is obviously no and if you can't make it public without risking being sent to prison the only option is selling it to some shady spammers. Which would you prefer happened? From my point of vie…
I think the industry basically needs to take the informal responsible disclosure rules and try and get them made a bit more formal, for everyones benefit.
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#43Earlier quoted context omitted.
"It should always be perfectly legal to access a remote computer system via a publicly accessible interface.", no it shouldn't, no more than it should be legal for me to walk into your house if you've not locked the door. The system worked exactly as AT&T intended, in circumstances they'd clearly not planned for. If they'd bothered doing a risk assessment they'd have spotted it, they took the lazy option and it didn'…
Please stop with the physical analogies. Locks and doors and physical space have well defined ways of indicating "authorized" and "unauthorized". We also have a social contract about entering spaces of others, even if there are no locks at all. The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_. It's up to that server, and no…
The social contract of the web is usurped by the legal contract of society, whether or not the way the legal framework is being applied in a just and fair manner is certainly up for debate.
And honestly can you say, hand on heart, that the intention of the AT&T developers was to purposefully leave that hole there? That'd be lunacy. Clearly it's a mistake, an 'oh crap, we didn't think of that'.
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#44Earlier quoted context omitted.
You're right, the law can't. That's why we should let the final verdict for authorized/unauthorized lie IN THE CODE DEPLOYED BY THE OWNER, not the law (or the owner's retroactive statements). It's pretty simple, really. This would be a non-issue if you programmed your cyborg to go pick up milk from the store and it started handing out $20s to strangers in the dairy aisle. Obviously that's no fault but your own. Why i…
So if a bank accidentally deposits $1bn in your account, that becomes yours? You're looking for a simple answer to a nuanced issue where one just doesn't exist.
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#45Earlier quoted context omitted.
"It should always be perfectly legal to access a remote computer system via a publicly accessible interface.", no it shouldn't, no more than it should be legal for me to walk into your house if you've not locked the door. The system worked exactly as AT&T intended, in circumstances they'd clearly not planned for. If they'd bothered doing a risk assessment they'd have spotted it, they took the lazy option and it didn'…
Please stop with the physical analogies. Locks and doors and physical space have well defined ways of indicating "authorized" and "unauthorized". We also have a social contract about entering spaces of others, even if there are no locks at all. The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_. It's up to that server, and no…
>The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_.
DDoS'ing a bank website is against the law, but you are just sending a request to a webserver right? The law will disagree...Again it is all about context. If weev made one request to the website, noticed he was looking at data that he knew shouldn't be available to him, then quit, I'm sure he would be just fine right now. But since he didn't this is why he is in trouble. Again the law isn't binary (to the major dismay and hang wringing it causes on this website), so it is up to the law to determine intent. Was he doing this by accident and should be slapped on the wrist? Or was he doing this maliciously?
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#46Earlier quoted context omitted.
What if doing so killed a person for each ID at showdocument? Ok, that's pretty absurd. What if it wiped out their bank account? Don't you think that the consequences should depend on what the action actually accomplished, rather than the action itself? Flicking a lighter is generally pretty innocuous, but if done to light a house on fire, it means it's a bit different - right? Yes, it's their fault too for leaving i…
"What if doing so killed a person for each ID at showdocument? Ok, that's pretty absurd. What if it wiped out their bank account?" Shouldn't you hold the people who created that system responsible, rather than the person who used it? If I rig up my cell phone to a gun, so that every time someone calls it it shoots at a crowd of people, should the people who call it go to prison while I walk free?
I honestly don't even know where I stand on the actual discussion point, but I do know where I stand in the weird analogy tree we've made.
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#47Earlier quoted context omitted.
I would prefer if the system punished people for what they did with their access to data, not simply for having that access; organizations that hold private or sensitive information should be punished if unauthorized people can access it by any means. Having email addresses or credit card numbers should not be the crime, regardless of how you obtained that information. Committing credit card fraud or selling credit c…
Apologies for crossing threads, but aren't you pretty upset that the NSA simply has Verizon phone records, despite a lack of evidence they're planning on doing anything nefarious with them? Anyway, as I understand it, weev did speculate about selling the information. And would you be so sanguine if this were health records or private photographs? I'm not seeing a plausible guiding principle here.
I also draw a line between what makes me upset and what should be a crime. I do not think that everything that makes me upset should be illegal. Frankly, while I would be angry at Weev if he downloaded hospital records, I would be much more angry at the hospital that failed to secure those records. I believe that the law should draw the line at how the information is secured and how it is used, not how it is obtained.
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#48Earlier quoted context omitted.
It doesn't matter if they accessed one or a million - accessing information published on the web SHOULD NOT BE CRIMINAL. Whether you agree with his methods or not, there is no stretch of the imagination that makes prison for downloading (even 114k of) them make sense. It wasn't a hole or bug— it was an expressly implemented feature. ATT decided to do it this way to reduce resubscription friction. The iPad sends the s…
So, if somebody has SSH open on port 22, root password login enabled, and a root password of Pa$$w0rd, and I guess that and log in, should that be legal? If so, what about a more complex password? Should we legalise other remote attacks on systems? It could very reasonably be argued that in the case of AT&T's system, device IDs count as passwords for accessing the system. Simplifying things a little, there was an API…
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#49Earlier quoted context omitted.
Please stop with the physical analogies. Locks and doors and physical space have well defined ways of indicating "authorized" and "unauthorized". We also have a social contract about entering spaces of others, even if there are no locks at all. The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_. It's up to that server, and no…
"Please stop with the physical analogies.", weev relied on one during his defence, so they're fair game. The social contract of the web is usurped by the legal contract of society, whether or not the way the legal framework is being applied in a just and fair manner is certainly up for debate. And honestly can you say, hand on heart, that the intention of the AT&T developers was to purposefully leave that hole there?…
Upon going to the wireless account management webpage on the iPad, it would already have the email address last associated with that ICCID (sim card) filled in in the form input element, so that the user would only have to type in their password, and not the email address as well.
It was an express design decision to reduce the number of steps taken by a user to reactivate service. They explicitly chose to weaken the authentication system to increase convenience, and didn't want to do credential management, so they just used the sequential integer ICCID to fetch the email address last associated with that SIM.
Afterward, they said "oh, well, we didn't INTEND for you to use it that way", despite the fact that this is very obviously gross negligence.
It's not a hole - it's a feature they chose to implement.
The bad law that lets anyone, retroactively, define "unauthorized access" by their own attitudes and whims, is the problem here.
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#50I agree with the sentiment that computer use crimes need to be reworked, and that weev shouldn't have been hoisted by the fact he is a colossal dick but the article seems to gloss over things for the sake of the argument. - `The spoofing was irrelevant; Spitler would have gotten the same email addresses if he had manually inputted the URLs on an iPad rather than a spoofed desktop browser.`, the spoofing is incredibly…
It doesn't matter if they accessed one or a million - accessing information published on the web SHOULD NOT BE CRIMINAL. Whether you agree with his methods or not, there is no stretch of the imagination that makes prison for downloading (even 114k of) them make sense. It wasn't a hole or bug— it was an expressly implemented feature. ATT decided to do it this way to reduce resubscription friction. The iPad sends the s…
Frankly, you're just torturing some unclearly defined terms ("Information Published on the Web", or "Expressly Designed Feature", or "it's up to a Remote System to respond appropiately") to make a point. Thing is, most of those terms are not legal, well defined terms; and when they are, your interpretation is lacking. You'd have a hard time convincing any judge that a company expressly desired to publish email directions of all of their customers, via some opaque and undocumented URL manipulation.
Disclaimer: I don't agree with weev's conviction, and some of its aspects are outrageous ("conspiracy to access a computer without authorization"?). But this "it was public information" angle is just bullshit. It's just badly reasoned.