Earlier quoted context omitted.
That first sentence doesn't make sense. If a merchant screws up and manages to post a flat ASCII text file of credit card accounts with CVV numbers on a URL in a directory with an Apache index enabled, your argument says "well, sucks for the merchant and all their customers". There are clearly cases where the mere fact that someone has left something somehow exposed to a web browser does not connote authorization to…
True when you say that there can be data left out in public by mistake without public access authorization. However it is not the responsibility of the accessing entity to preserve this data private. An analogy is if your bank left your money easily accessible on a table in front of the bank without security. We are used to the idea of ownership, but this issue is a matter of blame. Here AT&T is the one to blame for…
You May Not Like Weev, But Your Online Freedom Depends on His Appeal
71–80 of 145 posts
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#72Earlier quoted context omitted.
That first sentence doesn't make sense. If a merchant screws up and manages to post a flat ASCII text file of credit card accounts with CVV numbers on a URL in a directory with an Apache index enabled, your argument says "well, sucks for the merchant and all their customers". There are clearly cases where the mere fact that someone has left something somehow exposed to a web browser does not connote authorization to…
True when you say that there can be data left out in public by mistake without public access authorization. However it is not the responsibility of the accessing entity to preserve this data private. An analogy is if your bank left your money easily accessible on a table in front of the bank without security. We are used to the idea of ownership, but this issue is a matter of blame. Here AT&T is the one to blame for…
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#73I agree with the sentiment that computer use crimes need to be reworked, and that weev shouldn't have been hoisted by the fact he is a colossal dick but the article seems to gloss over things for the sake of the argument. - `The spoofing was irrelevant; Spitler would have gotten the same email addresses if he had manually inputted the URLs on an iPad rather than a spoofed desktop browser.`, the spoofing is incredibly…
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#74A few points that stuck out: * "AT&T representative testified its reputation suffered as a result of the hack" No, their reputation suffered, because they were incompetent. Ironically, without this trial I would have never heard about this. * "At sentencing, instead of hearing about the effects of the iPad “hack,” the government recounted in detail Weev’s “attitudes” towards others on the internet." That is because o…
All of that said, I wholeheartedly agree that damage to reputation (where such damage comes only from revelation of the insecurity) is the fault of the people failing to live up to their reputation, not those exposing the reality of it.
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#75Earlier quoted context omitted.
It doesn't matter if they accessed one or a million - accessing information published on the web SHOULD NOT BE CRIMINAL. Whether you agree with his methods or not, there is no stretch of the imagination that makes prison for downloading (even 114k of) them make sense. It wasn't a hole or bug— it was an expressly implemented feature. ATT decided to do it this way to reduce resubscription friction. The iPad sends the s…
So, if somebody has SSH open on port 22, root password login enabled, and a root password of Pa$$w0rd, and I guess that and log in, should that be legal? If so, what about a more complex password? Should we legalise other remote attacks on systems? It could very reasonably be argued that in the case of AT&T's system, device IDs count as passwords for accessing the system. Simplifying things a little, there was an API…
As you can see all emails are accessible without a password, just a username. This is what was required to get the customers' data from AT&T, serial numbers which are by definition serial and obvious to predict, just like anyone visiting http://www.mailinator.com/ would punch in their own name to see what was there and then try some other people's names.
To make Weev's access illegal there must be at least some form of security like a password that he should circumvent. That would be illegal. Placing data accessible through usernames without passwords is not an obstacle or security measure and should NOT be criminalized because it weakens the law and makes anyone a criminal.
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#76Earlier quoted context omitted.
Should I be allowed to brute force passwords then?
Yes, because organizations that use simple password-based authentication to secure important things (bank accounts, private messages, etc.) should be held responsible for the outcomes of such attacks. In such a world the state of computer security would not be so pitiful.
"Brute force" is literally an attack. However what AT&T did was only use the equivalent of usernames just like http://www.mailinator.com/ does.
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#77I, for one like Weev. He is a boundary pusher. Many even around here on hn might perceive his stuff as tasteless. But I sincerely wished more people were as dedicated to their "ideals" as Weev is. Defending free speech means standing up for people who have controversial views - no matter how unease you personally are with these views.
http://www.reddit.com/r/IAmA/comments/1ahkgc/i_am_weev_i_may... I think he's despicable, but he's also my friend if only because he is willing to do whatever is necessary to stand up for what he believes in.
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#78I agree with the sentiment that computer use crimes need to be reworked, and that weev shouldn't have been hoisted by the fact he is a colossal dick but the article seems to gloss over things for the sake of the argument. - `The spoofing was irrelevant; Spitler would have gotten the same email addresses if he had manually inputted the URLs on an iPad rather than a spoofed desktop browser.`, the spoofing is incredibly…
If he were guessing passwords jail time might be appropriate. It's fucking ridiculous that changing the user agent, even to circumvent server "protections", would be a crime worthy of any jail time whatsoever. What is he guilty of? Criminal misrepresentation of web browser?
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#79Earlier quoted context omitted.
So, if somebody has SSH open on port 22, root password login enabled, and a root password of Pa$$w0rd, and I guess that and log in, should that be legal? If so, what about a more complex password? Should we legalise other remote attacks on systems? It could very reasonably be argued that in the case of AT&T's system, device IDs count as passwords for accessing the system. Simplifying things a little, there was an API…
Just because there's an expectation of privacy doesn't mean that such an expectation is reasonable. It is not reasonable to have an expectation of privacy if your root password is "password" and you have ssh open to the world, no.
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#80Earlier quoted context omitted.
One of the ongoing issues in the security industry is that there is no standardized form of disclosure. There are frameworks that have been put together, but only some companies embrace them. Other companies are openly hostile towards any solution that doesn't leave the power entirely in their own hands. Basically, many large companies feel that the public should remain uninformed, which then leaves the company free…
Which is why I think there should be some attempt at a formal body, the EFF is in the right place to spearhead an attempt at implementing something along those lines.