Earlier quoted context omitted.
The question is after hearing AT&T prosecute Spitler for discovering such a simple security hole (it could have been a lot more complex) would you feel safe disclosing any security hole even with the best intentions? The answer is obviously no and if you can't make it public without risking being sent to prison the only option is selling it to some shady spammers. Which would you prefer happened? From my point of vie…
Yes I would, but I'd follow the standard responsible disclosure rules that are fairly common place. As far as the information that's been presented makes out, there was no responsible disclosure. In fact, weev attempted to say they were going down that route whilst at the same time discussing on irc how they could use the information for fairly black hat purposes. I think the industry basically needs to take the info…
You May Not Like Weev, But Your Online Freedom Depends on His Appeal
61–70 of 145 posts
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#62Earlier quoted context omitted.
Yes I would, but I'd follow the standard responsible disclosure rules that are fairly common place. As far as the information that's been presented makes out, there was no responsible disclosure. In fact, weev attempted to say they were going down that route whilst at the same time discussing on irc how they could use the information for fairly black hat purposes. I think the industry basically needs to take the info…
One of the ongoing issues in the security industry is that there is no standardized form of disclosure. There are frameworks that have been put together, but only some companies embrace them. Other companies are openly hostile towards any solution that doesn't leave the power entirely in their own hands. Basically, many large companies feel that the public should remain uninformed, which then leaves the company free…
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#63I agree with the sentiment that computer use crimes need to be reworked, and that weev shouldn't have been hoisted by the fact he is a colossal dick but the article seems to gloss over things for the sake of the argument. - `The spoofing was irrelevant; Spitler would have gotten the same email addresses if he had manually inputted the URLs on an iPad rather than a spoofed desktop browser.`, the spoofing is incredibly…
It doesn't matter if they accessed one or a million - accessing information published on the web SHOULD NOT BE CRIMINAL. Whether you agree with his methods or not, there is no stretch of the imagination that makes prison for downloading (even 114k of) them make sense. It wasn't a hole or bug— it was an expressly implemented feature. ATT decided to do it this way to reduce resubscription friction. The iPad sends the s…
There are clearly cases where the mere fact that someone has left something somehow exposed to a web browser does not connote authorization to access it. Those are the cases where a reasonable person, seeing what the data is after stumbling across it, would understand the exposure to have been a mistake, and not an authorization.
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#64It is a terrible decision curl http://domain.com/showdocument?[00000-99999] should not be a crime!!
How about curl http://domain.com/attemptlogin?username=[aaaaa-zzzzz]&passwo... , followed by curl http://domain.com/admin/wipeeverything?username=x&password=y ?
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#65Earlier quoted context omitted.
Physical analogies are perfectly appropriate in this context. Just because someone accidentally exposes a function via their website that divulges information that isn't supposed to be viewable doesn't mean it is ok. If I've never met someone in real life who left their door unlocked nor communicated with them before I rob them, just like the web, both are still illegal. >The social contract of the web is that "you c…
> Or was he doing this maliciously? He was _absolutely_ doing this maliciously. It STILL SHOULD NOT BE CRIMINAL. This is a fundamental misattribution of responsibility. His intent was to defame AT&T as much as possible, using only factual information about their own (negligent) business decisions. This, too, should be legal (and I believe it is).
Incidentally, every time you blame AT&T for what happened, you tacitly acknowledge that wrongdoing actually occurred, which harms your argument that the data was "published".
(In the interest of combating the fundamental attribution error: I'm not happy with Aurnheimer receiving a custodial sentence for what was pretty obviously just another dumb prank. We probably agree that the sentencing component of CFAA is absurdly constructed.)
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#66Earlier quoted context omitted.
"It should always be perfectly legal to access a remote computer system via a publicly accessible interface.", no it shouldn't, no more than it should be legal for me to walk into your house if you've not locked the door. The system worked exactly as AT&T intended, in circumstances they'd clearly not planned for. If they'd bothered doing a risk assessment they'd have spotted it, they took the lazy option and it didn'…
Please stop with the physical analogies. Locks and doors and physical space have well defined ways of indicating "authorized" and "unauthorized". We also have a social contract about entering spaces of others, even if there are no locks at all. The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_. It's up to that server, and no…
The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_.
--
Physical analogies may have their limitations when describing the web.
That said, weev KNEW for a fact that he was accessing information that should not have been public.
In other words, he KNEW that he was walking into someone's unlocked house.
Furthermore, he BRAGGED about rubbing it in AT&T's face, and wanting to cause as much damage as possible. He had malicious intent.
So no, his trespassing was not unintended. He didn't happen to just accidentally grab a bunch of email addresses from some web server he sent requests to randomly.
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#67Earlier quoted context omitted.
Physical analogies are perfectly appropriate in this context. Just because someone accidentally exposes a function via their website that divulges information that isn't supposed to be viewable doesn't mean it is ok. If I've never met someone in real life who left their door unlocked nor communicated with them before I rob them, just like the web, both are still illegal. >The social contract of the web is that "you c…
> Or was he doing this maliciously? He was _absolutely_ doing this maliciously. It STILL SHOULD NOT BE CRIMINAL. This is a fundamental misattribution of responsibility. His intent was to defame AT&T as much as possible, using only factual information about their own (negligent) business decisions. This, too, should be legal (and I believe it is).
What kind of reality do you live in where malicious intent to cause harm to someone or some group should not be a crime?
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#68* "AT&T representative testified its reputation suffered as a result of the hack"
No, their reputation suffered, because they were incompetent. Ironically, without this trial I would have never heard about this.
* "At sentencing, instead of hearing about the effects of the iPad “hack,” the government recounted in detail Weev’s “attitudes” towards others on the internet."
That is because of the adversarial legal system in the US. All that matters is to sway an uninformed jury. The specific matter of the case is almost irrelevant as long as the jury comes to a "guilty" verdict.
Lastly, this reminds of a civil version of the current Snowden debacle: Attempt to prosecute anybody who reveals wrong doing or incompetence.
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#69Earlier quoted context omitted.
Should I be allowed to brute force passwords then?
Yes. You can't use force or coercion to rob a server of data, all you can do is ask nicely (or repeatedly). In a just world, we would let full responsibility lie with those who deployed the machines without understanding the consequences of, e.g., no login failure rate limiting.
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#70Earlier quoted context omitted.
It doesn't matter if they accessed one or a million - accessing information published on the web SHOULD NOT BE CRIMINAL. Whether you agree with his methods or not, there is no stretch of the imagination that makes prison for downloading (even 114k of) them make sense. It wasn't a hole or bug— it was an expressly implemented feature. ATT decided to do it this way to reduce resubscription friction. The iPad sends the s…
That first sentence doesn't make sense. If a merchant screws up and manages to post a flat ASCII text file of credit card accounts with CVV numbers on a URL in a directory with an Apache index enabled, your argument says "well, sucks for the merchant and all their customers". There are clearly cases where the mere fact that someone has left something somehow exposed to a web browser does not connote authorization to…
An analogy is if your bank left your money easily accessible on a table in front of the bank without security. We are used to the idea of ownership, but this issue is a matter of blame. Here AT&T is the one to blame for the lack of security, not someone who saw that AT&T lacks security.
Back to the bank analogy, it is not the public's duty to guard your money for the bank. Nor should someone else be jailed for money literally left outside on the table.