Live data from Hacker News

You May Not Like Weev, But Your Online Freedom Depends on His Appeal

wired.com

81–90 of 145 posts

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#81

A few points that stuck out: * "AT&T representative testified its reputation suffered as a result of the hack" No, their reputation suffered, because they were incompetent. Ironically, without this trial I would have never heard about this. * "At sentencing, instead of hearing about the effects of the iPad “hack,” the government recounted in detail Weev’s “attitudes” towards others on the internet." That is because o…

I was a witness for a trial once and it's kinda bizzare. After all of the lawyers speeches and questions and explanations of the law - in the end it just boils down to how 12 random people feel about it. I left with the feeling that the process is fair only in the sense that it is equally random and unfair to everyone.

If the prosecutor is able to make you seem unlikable, or you do it to yourself, you most definitely increase your risk of being convicted. Mr. Auernheimer strikes me as somebody who enjoys being shocking and perhaps unlikable in the traditional sense, which is not an ideal situation in court.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#82
post #7
post #3

It is a terrible decision curl http://domain.com/showdocument?[00000-99999] should not be a crime!!

What if doing so killed a person for each ID at showdocument? Ok, that's pretty absurd. What if it wiped out their bank account? Don't you think that the consequences should depend on what the action actually accomplished, rather than the action itself? Flicking a lighter is generally pretty innocuous, but if done to light a house on fire, it means it's a bit different - right? Yes, it's their fault too for leaving i…

> I don't think the punishment fits the crime in this case, but I don't think he's entirely innocent either.

In this case there is no crime. And I repeat this again, AT&T was behaving like http://www.mailinator.com/

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#83
post #7
post #3

It is a terrible decision curl http://domain.com/showdocument?[00000-99999] should not be a crime!!

What if doing so killed a person for each ID at showdocument? Ok, that's pretty absurd. What if it wiped out their bank account? Don't you think that the consequences should depend on what the action actually accomplished, rather than the action itself? Flicking a lighter is generally pretty innocuous, but if done to light a house on fire, it means it's a bit different - right? Yes, it's their fault too for leaving i…

GET method should be Safe ( and Idempotent). The implementation is not respecting the RFC 2616.

The RFC says at the point 9.1.1 that: "Naturally, it is not possible to ensure that the server does not generate side-effects as a result of performing a GET request; in fact, some dynamic resources consider that a feature. The important distinction here is that the user did not request the effects, so therefore cannot be held accountable for them."

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#84
https://www.eff.org/deeplinks/2013/06/eff-access-public-webs...

A link to the Craigslist vs. 3Taps spat in this article brought back memories. Craigslist had also threatened me with a C&D letter suggesting they'd use the CFAA to lock me up. I contacted the EFF who promptly told me to go screw...

I assumed that was because Craig is on the board of advisers and CL was a major sponsor. I'm glad to see they're finally helping someone against the giant internet bully that is CL.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#85
post #16
post #10

Earlier quoted context omitted.

Should I be allowed to brute force passwords then?

Passwords are hashed in an attempt to conceal them. Websites are served in an attempt to disseminate them. There's a big difference here.

I wasn't saying passwords and websites are the same (I'm not even sure what that means) but was pointing out that saying it's fine to throw random stuff at a webserver would mean that it's fine to repeatedly throw user/pass combinations at a webserver.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#86

A few points that stuck out: * "AT&T representative testified its reputation suffered as a result of the hack" No, their reputation suffered, because they were incompetent. Ironically, without this trial I would have never heard about this. * "At sentencing, instead of hearing about the effects of the iPad “hack,” the government recounted in detail Weev’s “attitudes” towards others on the internet." That is because o…

I was a witness for a trial once and it's kinda bizzare. After all of the lawyers speeches and questions and explanations of the law - in the end it just boils down to how 12 random people feel about it. I left with the feeling that the process is fair only in the sense that it is equally random and unfair to everyone. If the prosecutor is able to make you seem unlikable, or you do it to yourself, you most definitely…

Well, as a defendant you can waive your right to a jury trial, and many people do for this reason.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#87
post #12

Earlier quoted context omitted.

It doesn't matter if they accessed one or a million - accessing information published on the web SHOULD NOT BE CRIMINAL. Whether you agree with his methods or not, there is no stretch of the imagination that makes prison for downloading (even 114k of) them make sense. It wasn't a hole or bug— it was an expressly implemented feature. ATT decided to do it this way to reduce resubscription friction. The iPad sends the s…

"It should always be perfectly legal to access a remote computer system via a publicly accessible interface.", no it shouldn't, no more than it should be legal for me to walk into your house if you've not locked the door. The system worked exactly as AT&T intended, in circumstances they'd clearly not planned for. If they'd bothered doing a risk assessment they'd have spotted it, they took the lazy option and it didn'…

If you want to use a physical analogy, it would be more like I invite you into my home, then shoot you because you stepped in a spot that I didn't like.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#88
post #52

Earlier quoted context omitted.

> Or was he doing this maliciously? He was _absolutely_ doing this maliciously. It STILL SHOULD NOT BE CRIMINAL. This is a fundamental misattribution of responsibility. His intent was to defame AT&T as much as possible, using only factual information about their own (negligent) business decisions. This, too, should be legal (and I believe it is).

>>He was _absolutely_ doing this maliciously. It STILL SHOULD NOT BE CRIMINAL. What kind of reality do you live in where malicious intent to cause harm to someone or some group should not be a crime?

Hypothetical scenario as an existence proof (not related to the situation currently at trial):

Suppose you're an investigative reporter. You regularly investigate a person or company that you feel gets away with too much, whose public actions always skate right on the line, and figure they must be doing something wrong. You feel vindictive about it because you haven't managed to find anything about them in the past. You fully intend to find something to report on that will cause their business harm; it's less about the story at this point, and more about you versus them. You find your story, you report on it (truthfully), and the result is serious enough that their business takes a major hit.

You had malicious intent to cause harm, and managed to cause the intended harm, and yet you've still done absolutely nothing wrong. (Remember that truth is an absolute defense against slander/libel accusations.)

Malicious intent to cause harm is frequently a necessary condition for a crime (leaving aside things like negligence), but never a sufficient one. You still have to do something inherently wrong.

In legal terms, see "mens rea" versus "actus reus".

Breaking into a computer system without permission by exploiting a security hole: generally a crime.

Accessing data made accessible to the general public: not wrong in the slightest, regardless of intent.

Changing your user-agent isn't exploiting a security hole (modulo changing it to ');drop table students;-- ), nor is automated access to a website (modulo DoSing). And embarrassing a company by showing that they made private user data publicly accessible definitely shouldn't be criminal.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#89

Earlier quoted context omitted.

I was a witness for a trial once and it's kinda bizzare. After all of the lawyers speeches and questions and explanations of the law - in the end it just boils down to how 12 random people feel about it. I left with the feeling that the process is fair only in the sense that it is equally random and unfair to everyone. If the prosecutor is able to make you seem unlikable, or you do it to yourself, you most definitely…

Well, as a defendant you can waive your right to a jury trial, and many people do for this reason.

That's interesting. I actually didn't know that you could do that for a criminal crime except in the case of a plea bargain.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#90
post #75

Earlier quoted context omitted.

So, if somebody has SSH open on port 22, root password login enabled, and a root password of Pa$$w0rd, and I guess that and log in, should that be legal? If so, what about a more complex password? Should we legalise other remote attacks on systems? It could very reasonably be argued that in the case of AT&T's system, device IDs count as passwords for accessing the system. Simplifying things a little, there was an API…

A perfect implementation of what AT&T did is this service: http://www.mailinator.com/ As you can see all emails are accessible without a password, just a username. This is what was required to get the customers' data from AT&T, serial numbers which are by definition serial and obvious to predict, just like anyone visiting http://www.mailinator.com/ would punch in their own name to see what was there and then try some…

Ah, but AT&T did not publicise the endpoint in any way either, unlike Mailinator.

More to the point, users using Mailinator do not have an expectation of privacy regarding the data they gave Mailinator (or that they told other services to give Mailinator). This is, therefore, a different situation.

If I find someone's personal information in Mailinator, that is most likely because a user agreed to allow a service to send their personal information there. In most cases, I wouldn't have any reason to believe any of this data was not intended to be there, unless there were other clues.

In the case of the AT&T breach, two things lead me to believe that Weev violated the privacy of the users:

* It is quite unlikely that users intended to have their email addresses published to the public through this endpoint, and it can easily be shown that Weev understood that - he would not otherwise have chosen the course of action he took.

* AT&T have never publicised this endpoint.

I am not holding AT&T as the victim here, but rather the customers of AT&T whose data was breached. AT&T and Weev were equally complicit in the breach, and AT&T should be held separately responsible.

Post reply on HN