Live data from Hacker News

You May Not Like Weev, But Your Online Freedom Depends on His Appeal

wired.com

41–50 of 145 posts

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#41

Earlier quoted context omitted.

Yes, because organizations that use simple password-based authentication to secure important things (bank accounts, private messages, etc.) should be held responsible for the outcomes of such attacks. In such a world the state of computer security would not be so pitiful.

You and sneak seem to be proposing a legal regime under which no "hacking" of any kind is illegal. If the system will perform action B given request A, issuing request A, no matter the intent, cannot be a crime? If I'm missing an important distinction you'd make, I'd very much like to hear what it is.

Hacking as a crime is almost entirely an economic crime. So it is pretty easy to distinguish hacking that deserves to be a felony from hacking that, at worst, should be a low-grade misdemeanor, by requiring actual profit for the criminal or actual loss from loss of data or exploitation of data acquired by hacking (not what it costs to fix incompetent security).

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#42
post #38

I agree with the sentiment that computer use crimes need to be reworked, and that weev shouldn't have been hoisted by the fact he is a colossal dick but the article seems to gloss over things for the sake of the argument. - `The spoofing was irrelevant; Spitler would have gotten the same email addresses if he had manually inputted the URLs on an iPad rather than a spoofed desktop browser.`, the spoofing is incredibly…

The question is after hearing AT&T prosecute Spitler for discovering such a simple security hole (it could have been a lot more complex) would you feel safe disclosing any security hole even with the best intentions? The answer is obviously no and if you can't make it public without risking being sent to prison the only option is selling it to some shady spammers. Which would you prefer happened? From my point of vie…

Yes I would, but I'd follow the standard responsible disclosure rules that are fairly common place. As far as the information that's been presented makes out, there was no responsible disclosure. In fact, weev attempted to say they were going down that route whilst at the same time discussing on irc how they could use the information for fairly black hat purposes.

I think the industry basically needs to take the informal responsible disclosure rules and try and get them made a bit more formal, for everyones benefit.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#43
post #39

Earlier quoted context omitted.

"It should always be perfectly legal to access a remote computer system via a publicly accessible interface.", no it shouldn't, no more than it should be legal for me to walk into your house if you've not locked the door. The system worked exactly as AT&T intended, in circumstances they'd clearly not planned for. If they'd bothered doing a risk assessment they'd have spotted it, they took the lazy option and it didn'…

Please stop with the physical analogies. Locks and doors and physical space have well defined ways of indicating "authorized" and "unauthorized". We also have a social contract about entering spaces of others, even if there are no locks at all. The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_. It's up to that server, and no…

"Please stop with the physical analogies.", weev relied on one during his defence, so they're fair game.

The social contract of the web is usurped by the legal contract of society, whether or not the way the legal framework is being applied in a just and fair manner is certainly up for debate.

And honestly can you say, hand on heart, that the intention of the AT&T developers was to purposefully leave that hole there? That'd be lunacy. Clearly it's a mistake, an 'oh crap, we didn't think of that'.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#44
post #40
post #27

Earlier quoted context omitted.

You're right, the law can't. That's why we should let the final verdict for authorized/unauthorized lie IN THE CODE DEPLOYED BY THE OWNER, not the law (or the owner's retroactive statements). It's pretty simple, really. This would be a non-issue if you programmed your cyborg to go pick up milk from the store and it started handing out $20s to strangers in the dairy aisle. Obviously that's no fault but your own. Why i…

So if a bank accidentally deposits $1bn in your account, that becomes yours? You're looking for a simple answer to a nuanced issue where one just doesn't exist.

That example is not at all the same as what's being discussed. The issue at hand is whether access to a public URL is authorized and who is responsible for determining that authorization.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#45
post #39

Earlier quoted context omitted.

"It should always be perfectly legal to access a remote computer system via a publicly accessible interface.", no it shouldn't, no more than it should be legal for me to walk into your house if you've not locked the door. The system worked exactly as AT&T intended, in circumstances they'd clearly not planned for. If they'd bothered doing a risk assessment they'd have spotted it, they took the lazy option and it didn'…

Please stop with the physical analogies. Locks and doors and physical space have well defined ways of indicating "authorized" and "unauthorized". We also have a social contract about entering spaces of others, even if there are no locks at all. The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_. It's up to that server, and no…

Physical analogies are perfectly appropriate in this context. Just because someone accidentally exposes a function via their website that divulges information that isn't supposed to be viewable doesn't mean it is ok. If I've never met someone in real life who left their door unlocked nor communicated with them before I rob them, just like the web, both are still illegal.

>The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_.

DDoS'ing a bank website is against the law, but you are just sending a request to a webserver right? The law will disagree...Again it is all about context. If weev made one request to the website, noticed he was looking at data that he knew shouldn't be available to him, then quit, I'm sure he would be just fine right now. But since he didn't this is why he is in trouble. Again the law isn't binary (to the major dismay and hang wringing it causes on this website), so it is up to the law to determine intent. Was he doing this by accident and should be slapped on the wrist? Or was he doing this maliciously?

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#46
post #7

Earlier quoted context omitted.

What if doing so killed a person for each ID at showdocument? Ok, that's pretty absurd. What if it wiped out their bank account? Don't you think that the consequences should depend on what the action actually accomplished, rather than the action itself? Flicking a lighter is generally pretty innocuous, but if done to light a house on fire, it means it's a bit different - right? Yes, it's their fault too for leaving i…

"What if doing so killed a person for each ID at showdocument? Ok, that's pretty absurd. What if it wiped out their bank account?" Shouldn't you hold the people who created that system responsible, rather than the person who used it? If I rig up my cell phone to a gun, so that every time someone calls it it shoots at a crowd of people, should the people who call it go to prison while I walk free?

This analogy has been flawed from the beginning, but to extend it just for the fun of it, that's like pulling the trigger of a gun and then blaming the gun for having the mechanics to turn that trigger pull into a fired bullet that kills someone. The action being done is on your end, and the system, though possibly flawed, is not the cause of the results. It may be a factor and it may enable those results, but the actor is the cause in that situation.

I honestly don't even know where I stand on the actual discussion point, but I do know where I stand in the weird analogy tree we've made.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#47

Earlier quoted context omitted.

I would prefer if the system punished people for what they did with their access to data, not simply for having that access; organizations that hold private or sensitive information should be punished if unauthorized people can access it by any means. Having email addresses or credit card numbers should not be the crime, regardless of how you obtained that information. Committing credit card fraud or selling credit c…

Apologies for crossing threads, but aren't you pretty upset that the NSA simply has Verizon phone records, despite a lack of evidence they're planning on doing anything nefarious with them? Anyway, as I understand it, weev did speculate about selling the information. And would you be so sanguine if this were health records or private photographs? I'm not seeing a plausible guiding principle here.

We hold the government to a different standard. I am free to forbid atheists from entering my home, and nobody can complain about it beyond calling me an asshole. The government cannot ban atheists from its buildings. Many people have pointed out that the NSA was collecting information that privacy industry already had -- yet we are still angry about the NSA having it.

I also draw a line between what makes me upset and what should be a crime. I do not think that everything that makes me upset should be illegal. Frankly, while I would be angry at Weev if he downloaded hospital records, I would be much more angry at the hospital that failed to secure those records. I believe that the law should draw the line at how the information is secured and how it is used, not how it is obtained.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#48
post #12

Earlier quoted context omitted.

It doesn't matter if they accessed one or a million - accessing information published on the web SHOULD NOT BE CRIMINAL. Whether you agree with his methods or not, there is no stretch of the imagination that makes prison for downloading (even 114k of) them make sense. It wasn't a hole or bug— it was an expressly implemented feature. ATT decided to do it this way to reduce resubscription friction. The iPad sends the s…

So, if somebody has SSH open on port 22, root password login enabled, and a root password of Pa$$w0rd, and I guess that and log in, should that be legal? If so, what about a more complex password? Should we legalise other remote attacks on systems? It could very reasonably be argued that in the case of AT&T's system, device IDs count as passwords for accessing the system. Simplifying things a little, there was an API…

The expectation of privacy covers the company, not the hacker who downloads the information. What differentiates hooking up an insecure, password-authentication-based system to the Internet, and leaving a plaintext copy of the data on a hard drive on a park bench somewhere? Holding companies responsible, and more responsible than hackers, would improve the state of computer security in short order (to everyone's benefit).

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#49
post #39

Earlier quoted context omitted.

Please stop with the physical analogies. Locks and doors and physical space have well defined ways of indicating "authorized" and "unauthorized". We also have a social contract about entering spaces of others, even if there are no locks at all. The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_. It's up to that server, and no…

"Please stop with the physical analogies.", weev relied on one during his defence, so they're fair game. The social contract of the web is usurped by the legal contract of society, whether or not the way the legal framework is being applied in a just and fair manner is certainly up for debate. And honestly can you say, hand on heart, that the intention of the AT&T developers was to purposefully leave that hole there?…

It was expressly to support autocomplete.

Upon going to the wireless account management webpage on the iPad, it would already have the email address last associated with that ICCID (sim card) filled in in the form input element, so that the user would only have to type in their password, and not the email address as well.

It was an express design decision to reduce the number of steps taken by a user to reactivate service. They explicitly chose to weaken the authentication system to increase convenience, and didn't want to do credential management, so they just used the sequential integer ICCID to fetch the email address last associated with that SIM.

Afterward, they said "oh, well, we didn't INTEND for you to use it that way", despite the fact that this is very obviously gross negligence.

It's not a hole - it's a feature they chose to implement.

The bad law that lets anyone, retroactively, define "unauthorized access" by their own attitudes and whims, is the problem here.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#50
post #12

I agree with the sentiment that computer use crimes need to be reworked, and that weev shouldn't have been hoisted by the fact he is a colossal dick but the article seems to gloss over things for the sake of the argument. - `The spoofing was irrelevant; Spitler would have gotten the same email addresses if he had manually inputted the URLs on an iPad rather than a spoofed desktop browser.`, the spoofing is incredibly…

It doesn't matter if they accessed one or a million - accessing information published on the web SHOULD NOT BE CRIMINAL. Whether you agree with his methods or not, there is no stretch of the imagination that makes prison for downloading (even 114k of) them make sense. It wasn't a hole or bug— it was an expressly implemented feature. ATT decided to do it this way to reduce resubscription friction. The iPad sends the s…

Even if you left the door of your house open, it wouldn't be legal for me to go inside and take your TV in protest.

Frankly, you're just torturing some unclearly defined terms ("Information Published on the Web", or "Expressly Designed Feature", or "it's up to a Remote System to respond appropiately") to make a point. Thing is, most of those terms are not legal, well defined terms; and when they are, your interpretation is lacking. You'd have a hard time convincing any judge that a company expressly desired to publish email directions of all of their customers, via some opaque and undocumented URL manipulation.

Disclaimer: I don't agree with weev's conviction, and some of its aspects are outrageous ("conspiracy to access a computer without authorization"?). But this "it was public information" angle is just bullshit. It's just badly reasoned.

Post reply on HN