Earlier quoted context omitted.
>In particular are comic cases of when companies fail to secure things at all and then someone gets prosecuted because they "hacked" that company and "stole" that data. If I leave my garage open, and somebody takes my golf clubs, is that not theft? Yes, the potential punishments are disproportionately harsh. Yes, the company is silly for leaving data exposed. No, it's not ok to take data because it's unprotected.
What about when you leave your garage door open, and someone comes in and makes a copy of your clubs. You still have yours. They now have a copy too. What did you lose in this other than the idea of "potential income"?
Why I Hope Congress Never Watches “Blackhat”
31–40 of 46 posts
Re: Why I Hope Congress Never Watches “Blackhat”
#32Earlier quoted context omitted.
What about when you leave your garage door open, and someone comes in and makes a copy of your clubs. You still have yours. They now have a copy too. What did you lose in this other than the idea of "potential income"?
What if you leave your door unlocked, someone walks into your bedroom, and looks at the sex photos you and your wife took. Or rifles through your personal letters, bank statements, etc. Still okay just because they took a copy?
Re: Why I Hope Congress Never Watches “Blackhat”
#33I don't understand how the Sony hack relates to the proposed changes to the CFAA. If the attacker was North Korea--as suggested by the administration (which I don't believe)--then how would increasing penalties for "hacking" or developing (or even sharing) "hacking tools" make a difference? As if we had any jurisdiction whatsoever over there or that the laws of the United States would somehow deter foreign attackers.…
> If the attacker was North Korea--as suggested by the administration (which I don't believe)--then how would increasing penalties for "hacking" or developing (or even sharing) "hacking tools" make a difference? This might be a bit off-topic, but there's potentially a distinction between North Korea being responsible for the hack of Sony, and whoever the people are who actually penetrated Sony's network and extracted…
I think a lot of the skepticism here and the general praise of autocratic states on HN, are mostly from a lot of people with an anti-US bone to pick or other political agenda. So to them, the US is always wrong, so they hold up NKorea, China, Russia, and Iran as bastions of liberty, honesty, and utopia. Its incredible how delusional these people are.
I also think a lot of people, especially right/libertarian leaning kids, lean toward autocracy and want a "decisive toughguy" leader for their own political and emotional reasons. Democracy, secular enlightenment, separation of powers, etc is seen as weak. Of course, they think the autocrats will be on their side, the same way, many think eugenics is a fine idea because, of course, "my people" will be allowed to procreate. There's a Fox News anchor who famously praised Putin and wished he had a Putin-like president during Russia's taking of Crimea. Of course, western sanctions have all but crippled Russia and the ruble today. I wonder if this anchor is still praising Russia's leadership.
1] http://www.forwardprogressives.com/fox-news-host-says-wants-...
Re: Why I Hope Congress Never Watches “Blackhat”
#34Earlier quoted context omitted.
Europe generally has fewer privacy and free speech protections than the US. And in some countries, the NSA and the national government will be spying on you. https://www.thewire.com/global/2013/10/france-not-happy-abou...
I don't need any "protections", I need to be left alone. That's how I actually can speak free, feel free and don't worry about my privacy too much (well, as long as I don't use skype, gmail, mobile phone… well, everything is relative, ok?). And honestly I thing that only fools believe in stuff like "free speech protections", although I usually don't try to persuade anybody about all these abstract matters. So, yeah,…
Re: Why I Hope Congress Never Watches “Blackhat”
#35Computer Crime laws are already insanely disproportionate. They were created during a moral panic when only a few individuals, large multinationals and, large governments had computers and the government were worried that "hackers" could break into the electricity grid or the communications system and shut it down. So right now you could literally break into someone's home, knock them unconscious, and then steal thei…
>In particular are comic cases of when companies fail to secure things at all and then someone gets prosecuted because they "hacked" that company and "stole" that data. If I leave my garage open, and somebody takes my golf clubs, is that not theft? Yes, the potential punishments are disproportionately harsh. Yes, the company is silly for leaving data exposed. No, it's not ok to take data because it's unprotected.
His case is more like a going into a store that is open and invites you in (this was a public website he went to). You are browsing around, looking at stuff for sale.. you then see an unmarked door in the middle of the store. It isn't locked, and doesn't say "Employees Only", so you walk in.
The store can't then turn around and have criminal charges brought against you just because you weren't supposed to go into the door. There were no locks or signs, and you were in a place you were supposed to be. Now, if there was any sort of lock at all (even a crappy, broken, one that was easy to bypass) you could argue that it is a crime.
If I send a standard request to a website, with no special forged auth or anything, and that website gives me back data, you can't blame the person who made the request. It is up to the website to tell me "no, you are not allowed to access that."
Re: Why I Hope Congress Never Watches “Blackhat”
#36Earlier quoted context omitted.
>In particular are comic cases of when companies fail to secure things at all and then someone gets prosecuted because they "hacked" that company and "stole" that data. If I leave my garage open, and somebody takes my golf clubs, is that not theft? Yes, the potential punishments are disproportionately harsh. Yes, the company is silly for leaving data exposed. No, it's not ok to take data because it's unprotected.
What about when you leave your garage door open, and someone comes in and makes a copy of your clubs. You still have yours. They now have a copy too. What did you lose in this other than the idea of "potential income"?
Re: Why I Hope Congress Never Watches “Blackhat”
#37Earlier quoted context omitted.
"The Hamptons Tourist Board: The wicker man" I'm curious; what you mean by this one?
I laughed hard at this one! The Hamptons is basically a vacation destination in eastern New York state for very very wealthy people, who don't want any riff-raff cluttering up their picturesque vacation views. 'The Wicker Man' is a film (+ a remake) about a police officer who goes to investigate a crime in a remote idyll where everyone knows everyone else and runs into...problems. Translation: let's ensure that the '…
Re: Why I Hope Congress Never Watches “Blackhat”
#38Earlier quoted context omitted.
>In particular are comic cases of when companies fail to secure things at all and then someone gets prosecuted because they "hacked" that company and "stole" that data. If I leave my garage open, and somebody takes my golf clubs, is that not theft? Yes, the potential punishments are disproportionately harsh. Yes, the company is silly for leaving data exposed. No, it's not ok to take data because it's unprotected.
Yes, stealing something is a crime whether the item is locked or not. However, cases like that of the Weev guy ( http://en.wikipedia.org/wiki/Weev ) are very different than someone coming into an unlocked garage and stealing your stuff. His case is more like a going into a store that is open and invites you in (this was a public website he went to). You are browsing around, looking at stuff for sale.. you then see an…
Re: Why I Hope Congress Never Watches “Blackhat”
#39Computer Crime laws are already insanely disproportionate. They were created during a moral panic when only a few individuals, large multinationals and, large governments had computers and the government were worried that "hackers" could break into the electricity grid or the communications system and shut it down. So right now you could literally break into someone's home, knock them unconscious, and then steal thei…
>In particular are comic cases of when companies fail to secure things at all and then someone gets prosecuted because they "hacked" that company and "stole" that data. If I leave my garage open, and somebody takes my golf clubs, is that not theft? Yes, the potential punishments are disproportionately harsh. Yes, the company is silly for leaving data exposed. No, it's not ok to take data because it's unprotected.
And that's exactly what publicly accessible URLs and a status code 200 are.
You had a chance to issue a 403 (ie, "You can't take my clubs") but instead you said "OK."
I think it's egregious that anybody anywhere can be held criminally liable for accessing information available as a the result of a 200, with no former contractual arrangements in place.
Re: Why I Hope Congress Never Watches “Blackhat”
#40What is being proposed for new laws scares me more than any hacker.
Contact your rep in congress and tell them that. They dont read hackerness unfortunately.