Live data from Hacker News

You May Not Like Weev, But Your Online Freedom Depends on His Appeal

wired.com

51–60 of 145 posts

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#51
post #27

Earlier quoted context omitted.

>It should always be perfectly legal to access a remote computer system via a publicly accessible interface. It's up to that remote system to respond appropriately. In this case, it was working exactly as ATT intended. The law can never be this black and white, it is all about context. Just because you may somehow access something on the web, doesn't mean it is automatically ok to do so.

You're right, the law can't. That's why we should let the final verdict for authorized/unauthorized lie IN THE CODE DEPLOYED BY THE OWNER, not the law (or the owner's retroactive statements). It's pretty simple, really. This would be a non-issue if you programmed your cyborg to go pick up milk from the store and it started handing out $20s to strangers in the dairy aisle. Obviously that's no fault but your own. Why i…

> That's why we should let the final verdict for authorized/unauthorized lie IN THE CODE DEPLOYED BY THE OWNER, not the law

I'm surprised to see this much victim blaming from such a passionate defender of personal liberties.

There is a stark difference between "AT&T deliberately decided to allow public access through this URL" and "AT&T improperly coded the authentication scheme for this URL".

From the outside the end result would be indistinguishable, which is why your binary logic can't be used in general. If we had it your way the only choice a potential victim would be legally allowed to ever make is "as strong a technical control as available (and don't screw it up, otherwise it's your fault)".

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#52
post #39

Earlier quoted context omitted.

Please stop with the physical analogies. Locks and doors and physical space have well defined ways of indicating "authorized" and "unauthorized". We also have a social contract about entering spaces of others, even if there are no locks at all. The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_. It's up to that server, and no…

Physical analogies are perfectly appropriate in this context. Just because someone accidentally exposes a function via their website that divulges information that isn't supposed to be viewable doesn't mean it is ok. If I've never met someone in real life who left their door unlocked nor communicated with them before I rob them, just like the web, both are still illegal. >The social contract of the web is that "you c…

> Or was he doing this maliciously?

He was _absolutely_ doing this maliciously. It STILL SHOULD NOT BE CRIMINAL.

This is a fundamental misattribution of responsibility.

His intent was to defame AT&T as much as possible, using only factual information about their own (negligent) business decisions. This, too, should be legal (and I believe it is).

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#53
post #40

Earlier quoted context omitted.

So if a bank accidentally deposits $1bn in your account, that becomes yours? You're looking for a simple answer to a nuanced issue where one just doesn't exist.

That example is not at all the same as what's being discussed. The issue at hand is whether access to a public URL is authorized and who is responsible for determining that authorization.

Actually the analogy is OK, the interpretation is wrong. If you disagree with sneak you're saying the account holder should be prosecuted!

Claiming ownership of the money would be like weev selling the email list to spammers, which he didn't. What he did was reveal the defect - like the acoount-holder reporting the mis-deposit.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#54
post #12

Earlier quoted context omitted.

It doesn't matter if they accessed one or a million - accessing information published on the web SHOULD NOT BE CRIMINAL. Whether you agree with his methods or not, there is no stretch of the imagination that makes prison for downloading (even 114k of) them make sense. It wasn't a hole or bug— it was an expressly implemented feature. ATT decided to do it this way to reduce resubscription friction. The iPad sends the s…

Even if you left the door of your house open, it wouldn't be legal for me to go inside and take your TV in protest. Frankly, you're just torturing some unclearly defined terms ("Information Published on the Web", or "Expressly Designed Feature", or "it's up to a Remote System to respond appropiately") to make a point. Thing is, most of those terms are not legal, well defined terms; and when they are, your interpretat…

> But this "it was public information" angle is just bullshit. It's just badly reasoned.

AT&T admitted in court during the trial that they had published the email addresses on the web.

That's what "publishing" is, these days: putting stuff on a webserver without authentication in front of it.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#55

Earlier quoted context omitted.

"What if doing so killed a person for each ID at showdocument? Ok, that's pretty absurd. What if it wiped out their bank account?" Shouldn't you hold the people who created that system responsible, rather than the person who used it? If I rig up my cell phone to a gun, so that every time someone calls it it shoots at a crowd of people, should the people who call it go to prison while I walk free?

This analogy has been flawed from the beginning, but to extend it just for the fun of it, that's like pulling the trigger of a gun and then blaming the gun for having the mechanics to turn that trigger pull into a fired bullet that kills someone. The action being done is on your end, and the system, though possibly flawed, is not the cause of the results. It may be a factor and it may enable those results, but the ac…

It is more like blaming the owner of the gun, who loaded the gun, aimed it, set up the shot, and then left it up to the trigger man whether or not to pull the trigger.

Bringing things back to reality here, AT&T was entrusted with personal information but failed to properly secure it. They set up a system that automatically responded to requests for personal information. They gave unauthorized people access to that system. We should be blaming AT&T and making them pay punitive damages for their irresponsible behavior, not whining about how terrible Weev is for using the system they gave him access to. The fact that AT&T can just shrug it off is what allows the sorry state of security to persist.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#57
post #39

Earlier quoted context omitted.

Please stop with the physical analogies. Locks and doors and physical space have well defined ways of indicating "authorized" and "unauthorized". We also have a social contract about entering spaces of others, even if there are no locks at all. The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_. It's up to that server, and no…

Physical analogies are perfectly appropriate in this context. Just because someone accidentally exposes a function via their website that divulges information that isn't supposed to be viewable doesn't mean it is ok. If I've never met someone in real life who left their door unlocked nor communicated with them before I rob them, just like the web, both are still illegal. >The social contract of the web is that "you c…

Unless someone actually profits or acts illegally with the data obtained from their unintended access I think you should essentially be given a pass - to the extent that I'd want such cases ruled invalid.

Otherwise we end up in the bad situation of having a law which is going to be applied very unevenly, which opens it wide up to corruption.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#59
post #51
post #27

Earlier quoted context omitted.

You're right, the law can't. That's why we should let the final verdict for authorized/unauthorized lie IN THE CODE DEPLOYED BY THE OWNER, not the law (or the owner's retroactive statements). It's pretty simple, really. This would be a non-issue if you programmed your cyborg to go pick up milk from the store and it started handing out $20s to strangers in the dairy aisle. Obviously that's no fault but your own. Why i…

> That's why we should let the final verdict for authorized/unauthorized lie IN THE CODE DEPLOYED BY THE OWNER, not the law I'm surprised to see this much victim blaming from such a passionate defender of personal liberties. There is a stark difference between "AT&T deliberately decided to allow public access through this URL" and "AT&T improperly coded the authentication scheme for this URL". From the outside the en…

The only victims here are the people whose data ATT negligently mishandled, and even those are just civil claims.

ATT's reputational damage was earned, and was the consequence of facts that were disclosed about their terrible customer data handling practices.

There's nothing criminal at all at any point here. Even what ATT did was shitty, and they should probably get sued for being so careless and negligent, but no crimes were committed by anyone at any point along this chain.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#60

Earlier quoted context omitted.

So, if somebody has SSH open on port 22, root password login enabled, and a root password of Pa$$w0rd, and I guess that and log in, should that be legal? If so, what about a more complex password? Should we legalise other remote attacks on systems? It could very reasonably be argued that in the case of AT&T's system, device IDs count as passwords for accessing the system. Simplifying things a little, there was an API…

The expectation of privacy covers the company , not the hacker who downloads the information. What differentiates hooking up an insecure, password-authentication-based system to the Internet, and leaving a plaintext copy of the data on a hard drive on a park bench somewhere? Holding companies responsible, and more responsible than hackers, would improve the state of computer security in short order (to everyone's ben…

I would hold both responsible quite happily and independently of each other. AT&T obviously did not heed the user's expectation of privacy in this case - they could've done so using a challenge-response authentication system with the response algorithm protected by DRM on the iPad - but in addition, Weev could reasonably be expected to understand that this was not supposed to be public data.

Additionally, the expectation of privacy, in my opinion, covers the data owners (the people who gave the company the data), not the company who is merely holding and processing the data. Although the US has rather messed up data laws compared to the EU, so I am not sure whether this would be true over there.

Post reply on HN