Live data from Hacker News

You May Not Like Weev, But Your Online Freedom Depends on His Appeal

wired.com

121–130 of 145 posts

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#121

Earlier quoted context omitted.

I was referring to tptacek's statement: "This is, literally, an argument that if you stumble across a text file full of credit card numbers, expiration dates, and CVV codes, it should be lawful for you to put it up on Pastebin." Which, when carders are caught on forums doing the above, they are charged with wire fraud. I agree with you completely that I don't think Weev's acts were wire fraud.

My impression is that the Pastebin'ed CC# example does not provide the charge, but evidence that helps prosecute the fraud through which they were acquired.

I'll walk back calling it a "textbook example" (because I suppose ultimately it's probably up to the quality of the lawyers involved), but the part of 18 USC 1343 that I think would be argued by the prosecution in the "pastebin cc numbers example" is:

"...or promises, transmits or causes to be transmitted by means of wire, radio, or television communication in interstate or foreign commerce, any writings, signs, signals, pictures, or sounds for the purpose of executing such scheme or artifice..."

I think the government would have a relatively easy time arguing that posting people's credit card information (specifically all the data necessary to make use of that person's funds) is a scheme for "obtaining money or property by means of false or fraudulent pretenses".

The defendant's attorney might argue that just posting the information isn't itself a scheme (in the same way that say, listing the home addresses of members of rival ethnic groups over the radio in Rwanda isn't an incitement to violence), but if I were that defendant, I wouldn't be sleeping easy.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#122
post #65

Earlier quoted context omitted.

Why does it have to be either/or? Why can't both people be responsible? Why can't AT&T be civilly liable for leaving a gaping hole on their application, and whoever abused that information be criminally liable? Incidentally, every time you blame AT&T for what happened, you tacitly acknowledge that wrongdoing actually occurred, which harms your argument that the data was "published". (In the interest of combating the…

"Information abuse" is some kind of cyber-PETA ethic and law I had not yet considered, and I'm not sure it's really a good road to start down.

If you think publishing people's credit card numbers implicates a PETA-like ethic.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#123

Earlier quoted context omitted.

"Information abuse" is some kind of cyber-PETA ethic and law I had not yet considered, and I'm not sure it's really a good road to start down.

If you think publishing people's credit card numbers implicates a PETA-like ethic.

You're changing the subject away from your own concept of "abuse of information."

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#124

Earlier quoted context omitted.

>>He was _absolutely_ doing this maliciously. It STILL SHOULD NOT BE CRIMINAL. What kind of reality do you live in where malicious intent to cause harm to someone or some group should not be a crime?

> What kind of reality do you live in where malicious intent to cause harm to someone or some group should not be a crime? It depends somewhat on what you class as malice. Starting a business is usually a deliberate attempt to cause harm to competitors, and success at it may well cause thousands of people to lose their jobs, etc.

The world is simply becoming too complicated, all these "trajedy of the commons" type economics are blowing up in ways that are so harmful all over. I feel it is wrong for Weev to be in jail, the same way I feel it was wrong for max hardcore (paul little) to have went to jail, and so many others. I have been writing weev, he says he wishes more people will write him, it is very lonely in solitary confinement, in this complicated world, writing a letter to another human being seems the least I can do. I hope more people here do so too, even though I hated looking at all those goatse buttholes over the years and condemned the person who was doing that to me - LOL! I don't wish a human being to be locked up for years for what Weev has done.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#125

Earlier quoted context omitted.

>> Please stop with the physical analogies. Locks and doors and physical space have well defined ways of indicating "authorized" and "unauthorized". We also have a social contract about entering spaces of others, even if there are no locks at all. The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_. -- Physical analogies may h…

Why must ATT's situation be compared to an unlocked house rather than a pile of papers lying on a street corner?

True, even Wozniak has recently said he doesn't like what the USA has become, that it is like former communist russia or stassi germany, and ever since the patriot act we have really been hosed, I wonder if the Woz can help do anything for WEEV personally if he really feels this way (it was apple ipad devices involved with this right?)

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#126
post #117
post #12

Earlier quoted context omitted.

It doesn't matter if they accessed one or a million - accessing information published on the web SHOULD NOT BE CRIMINAL. Whether you agree with his methods or not, there is no stretch of the imagination that makes prison for downloading (even 114k of) them make sense. It wasn't a hole or bug— it was an expressly implemented feature. ATT decided to do it this way to reduce resubscription friction. The iPad sends the s…

>>> It doesn't matter if they accessed one or a million - accessing information published on the web SHOULD NOT BE CRIMINAL. By this logic, any information stored on any computer accessible via the Internet is published, so no unauthorized access to any data not behind an air gap is illegal. Including breaking into your private mailbox or your online banking account. I don't think I'd be ready to accept this. Are you…

The NSA palantir types sure seem to think anything on any computer is free game - LOL! Email, phones, banks yah? Shouldn't things be just the opposite of how they are according to the founding fathers, the government types that hack us should be held to a FAR HIGHER standard than some arkansas boy like WEEV, yet they do worse, and get hookers in south america and lots of parties, while weev rots in jail for 4 years, something doesn't seem right to me about that situation.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#127
post #39

Earlier quoted context omitted.

Please stop with the physical analogies. Locks and doors and physical space have well defined ways of indicating "authorized" and "unauthorized". We also have a social contract about entering spaces of others, even if there are no locks at all. The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_. It's up to that server, and no…

>> Please stop with the physical analogies. Locks and doors and physical space have well defined ways of indicating "authorized" and "unauthorized". We also have a social contract about entering spaces of others, even if there are no locks at all. The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_. -- Physical analogies may h…

> Furthermore, he BRAGGED about rubbing it in AT&T's face, and wanting to cause as much damage as possible. He had malicious intent.

Malicious intent is not criminal.

> That said, weev KNEW for a fact that he was accessing information that should not have been public.

It is massively unfair to put the burden of inferring the intention of a remote system onto the requester.

In fact, he could not have known that he was accessing information that should not have been public (as you claim), because ATT expressly configured their systems to MAKE IT PUBLIC. It wasn't an accident or misconfiguration. Your basic premise doesn't hold up, and neither does the silly physical "unlocked house" analogy.

An unlocked house implies there are locks and doors present, neither of which were in this case.

It's not trespassing, and just because it's non-random doesn't make it criminal.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#128

Earlier quoted context omitted.

"Information abuse" is some kind of cyber-PETA ethic and law I had not yet considered, and I'm not sure it's really a good road to start down.

If you think publishing people's credit card numbers implicates a PETA-like ethic.

There were neither "people's credit card numbers" nor "publishing" in this instance. It seems like you're being intentionally confusing.

We're talking about a list of email addresses (which I don't think should be protected data in any way, they're just email addresses) and a journalist running a blacked-out screenshot of a dozen of them.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#129
post #39

Earlier quoted context omitted.

Please stop with the physical analogies. Locks and doors and physical space have well defined ways of indicating "authorized" and "unauthorized". We also have a social contract about entering spaces of others, even if there are no locks at all. The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_. It's up to that server, and no…

But by that logic, any kind of malicious web activity should be allowed. Once you remove all the abstractions, any kind of attack is just computers behaving how they've been instructed to. An injection attack is only a server processing a particularly strange request.

Yeah, that's basically my argument.

Don't plug shit into the internet you don't understand.

If that's a problem for you, hire someone who does understand it before you do.

I have no problem with complete deregulation of the exchange of information over the internet, as it's impossible to use violence to force anyone to do anything via an ethernet cable.

It's impossible for a packet to be the root cause of harm coming to another.

Negligence or recklessness when attaching not-fully-understood systems to the Internet, on the other hand, should expose people to liability when the personal information stored in those systems is publicized. The fundamental cause is "idiots plugged in a server without suitable authentication", not "somebody across the world sent it some electrons".

It is crystal-clear to me that all packet transmission should be protected speech, including buffer overflows and other so-called "malicious" traffic.

Just because it's obvious to you (because you are willing to make an assumption) what is malicious and what is not, that doesn't mean that it's anything resembling fair to force others to make those assumptions to avoid criminal liability.

The full text of War and Peace could be "malicious" traffic when sent to a machine that stupidly copies it into a fixed-size buffer. This is not a job for the law to decide. It's a blunt instrument.

(There's also the issue of the stupidity of allowing the receiver to retroactively declare "oh, that was not intended, and thus unauthorized".)

The responsibility must always lie with those who interpret the traffic, not those who send it.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#130
post #65
post #52

Earlier quoted context omitted.

> Or was he doing this maliciously? He was _absolutely_ doing this maliciously. It STILL SHOULD NOT BE CRIMINAL. This is a fundamental misattribution of responsibility. His intent was to defame AT&T as much as possible, using only factual information about their own (negligent) business decisions. This, too, should be legal (and I believe it is).

Why does it have to be either/or? Why can't both people be responsible? Why can't AT&T be civilly liable for leaving a gaping hole on their application, and whoever abused that information be criminally liable? Incidentally, every time you blame AT&T for what happened, you tacitly acknowledge that wrongdoing actually occurred, which harms your argument that the data was "published". (In the interest of combating the…

> Why can't AT&T be civilly liable for leaving a gaping hole on their application, and whoever abused that information be criminally liable?

What abuse of information are you referring to? The part where they sent it to a journalist?

I blame AT&T for being shitty and reckless, not for being criminal.

Post reply on HN