Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails
technologyreview.com
Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails
1–10 of 117 posts
Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails
#2"Weev and a fellow hacker who originally uncovered AT&T’s mistake and collected the e-mails didn’t ask the company for permission to access the Web addresses that shared iPad users’ private information"
I really don't see how this argument holds up.
From a technical point of view the very nature of HTTP includes asking for permission. You send a request "Please can I see the information at this URL" If the organisation running the server does not give that permission, it should not serve the data.
These charges seem pretty odd to me, hopefully it gets resolved in a sensible manner.
Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails
#3The article states "Weev and a fellow hacker who originally uncovered AT&T’s mistake and collected the e-mails didn’t ask the company for permission to access the Web addresses that shared iPad users’ private information" I really don't see how this argument holds up. From a technical point of view the very nature of HTTP includes asking for permission. You send a request "Please can I see the information at this URL…
How is this different than a password?
Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails
#4The article states "Weev and a fellow hacker who originally uncovered AT&T’s mistake and collected the e-mails didn’t ask the company for permission to access the Web addresses that shared iPad users’ private information" I really don't see how this argument holds up. From a technical point of view the very nature of HTTP includes asking for permission. You send a request "Please can I see the information at this URL…
A web server isn't an agent of the company and has no capacity to grant or deny permission.
Think of it as a security system you install in your home. Now, if the security system is malfunctioning and you notice that it is malfunctioning ... do you call up the owner and let them know or do you go inside and look through their stuff? If you go inside and look through their stuff, it's trespassing.
Obviously the two scenarios aren't the same, but I'd imagine that's the logic used in the argument.
Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails
#5The article states "Weev and a fellow hacker who originally uncovered AT&T’s mistake and collected the e-mails didn’t ask the company for permission to access the Web addresses that shared iPad users’ private information" I really don't see how this argument holds up. From a technical point of view the very nature of HTTP includes asking for permission. You send a request "Please can I see the information at this URL…
Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails
#6The article states "Weev and a fellow hacker who originally uncovered AT&T’s mistake and collected the e-mails didn’t ask the company for permission to access the Web addresses that shared iPad users’ private information" I really don't see how this argument holds up. From a technical point of view the very nature of HTTP includes asking for permission. You send a request "Please can I see the information at this URL…
> From a technical point of view the very nature of HTTP includes asking for permission. A web server isn't an agent of the company and has no capacity to grant or deny permission. Think of it as a security system you install in your home. Now, if the security system is malfunctioning and you notice that it is malfunctioning ... do you call up the owner and let them know or do you go inside and look through their stu…
A web server certainly can grant or deny permission, but it seems that this one didn't.
Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails
#7Earlier quoted context omitted.
> From a technical point of view the very nature of HTTP includes asking for permission. A web server isn't an agent of the company and has no capacity to grant or deny permission. Think of it as a security system you install in your home. Now, if the security system is malfunctioning and you notice that it is malfunctioning ... do you call up the owner and let them know or do you go inside and look through their stu…
A web server isn't an agent of the company and has no capacity to grant or deny permission. A web server certainly can grant or deny permission, but it seems that this one didn't.
Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails
#8The article states "Weev and a fellow hacker who originally uncovered AT&T’s mistake and collected the e-mails didn’t ask the company for permission to access the Web addresses that shared iPad users’ private information" I really don't see how this argument holds up. From a technical point of view the very nature of HTTP includes asking for permission. You send a request "Please can I see the information at this URL…
>> required visiting an AT&T web address with a particular – and easy to guess – code tagged onto the end. How is this different than a password?
Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails
#9This whole process, or lack thereof, needs some serious disruption.
Edit: My comment is intended to be a general observation and not specifically about this case