A few points that stuck out: * "AT&T representative testified its reputation suffered as a result of the hack" No, their reputation suffered, because they were incompetent. Ironically, without this trial I would have never heard about this. * "At sentencing, instead of hearing about the effects of the iPad “hack,” the government recounted in detail Weev’s “attitudes” towards others on the internet." That is because o…
I don't think I go as far as others here. I am not sure an open door is an invitation to dig through someone's diary; that is, even if someone is incompetent in managing their security, there should probably still be a point at which abusing that crosses a line - though I am very open to discussing just where that point is (and some liability should certainly still sit with those who deployed an insecure system). All…
You May Not Like Weev, But Your Online Freedom Depends on His Appeal
101–110 of 145 posts
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#102Earlier quoted context omitted.
Yes, because organizations that use simple password-based authentication to secure important things (bank accounts, private messages, etc.) should be held responsible for the outcomes of such attacks. In such a world the state of computer security would not be so pitiful.
WRONG! "Brute force" is literally an attack. However what AT&T did was only use the equivalent of usernames just like http://www.mailinator.com/ does.
So why have we not deployed this "amazing" technology, or similar technology, everywhere? A lack of incentive. If a hacker successfully carries out a brute force attack, the company running the systems does not suffer at all; they just pass it off as "some dark wizard hacker pwned us, sorry!" Nobody is spending the money to deploy smartcards far and wide because nobody has any reason to. It is less expensive to pay the pittance required to clean up after a hack than to stop hacks in the first place. If banks had no legal recourse when some script kiddie hacked a customer account, they would be far more likely to give customers smartcards and use more secure authentication mechanisms.
To put it another way, making a brute-force attack a crime is placing responsibility for securing the system on the people who want to attack it. It should be obvious why that makes no sense.
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#103Earlier quoted context omitted.
It doesn't matter if they accessed one or a million - accessing information published on the web SHOULD NOT BE CRIMINAL. Whether you agree with his methods or not, there is no stretch of the imagination that makes prison for downloading (even 114k of) them make sense. It wasn't a hole or bug— it was an expressly implemented feature. ATT decided to do it this way to reduce resubscription friction. The iPad sends the s…
That first sentence doesn't make sense. If a merchant screws up and manages to post a flat ASCII text file of credit card accounts with CVV numbers on a URL in a directory with an Apache index enabled, your argument says "well, sucks for the merchant and all their customers". There are clearly cases where the mere fact that someone has left something somehow exposed to a web browser does not connote authorization to…
Since that would be a clear and basic PCI violation, yeah, it sucks for the merchant and their customers. Why have PCI compliance at all if the merchant can just throw up their hands and blame it on "hackers?"
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#104Earlier quoted context omitted.
True when you say that there can be data left out in public by mistake without public access authorization. However it is not the responsibility of the accessing entity to preserve this data private. An analogy is if your bank left your money easily accessible on a table in front of the bank without security. We are used to the idea of ownership, but this issue is a matter of blame. Here AT&T is the one to blame for…
This is, literally, an argument that if you stumble across a text file full of credit card numbers, expiration dates, and CVV codes, it should be lawful for you to put it up on Pastebin.
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#105Earlier quoted context omitted.
> Or was he doing this maliciously? He was _absolutely_ doing this maliciously. It STILL SHOULD NOT BE CRIMINAL. This is a fundamental misattribution of responsibility. His intent was to defame AT&T as much as possible, using only factual information about their own (negligent) business decisions. This, too, should be legal (and I believe it is).
Why does it have to be either/or? Why can't both people be responsible? Why can't AT&T be civilly liable for leaving a gaping hole on their application, and whoever abused that information be criminally liable? Incidentally, every time you blame AT&T for what happened, you tacitly acknowledge that wrongdoing actually occurred, which harms your argument that the data was "published". (In the interest of combating the…
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#106Earlier quoted context omitted.
> Or was he doing this maliciously? He was _absolutely_ doing this maliciously. It STILL SHOULD NOT BE CRIMINAL. This is a fundamental misattribution of responsibility. His intent was to defame AT&T as much as possible, using only factual information about their own (negligent) business decisions. This, too, should be legal (and I believe it is).
>>He was _absolutely_ doing this maliciously. It STILL SHOULD NOT BE CRIMINAL. What kind of reality do you live in where malicious intent to cause harm to someone or some group should not be a crime?
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#107Earlier quoted context omitted.
Please stop with the physical analogies. Locks and doors and physical space have well defined ways of indicating "authorized" and "unauthorized". We also have a social contract about entering spaces of others, even if there are no locks at all. The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_. It's up to that server, and no…
>> Please stop with the physical analogies. Locks and doors and physical space have well defined ways of indicating "authorized" and "unauthorized". We also have a social contract about entering spaces of others, even if there are no locks at all. The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_. -- Physical analogies may h…
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#108Earlier quoted context omitted.
I don't think I go as far as others here. I am not sure an open door is an invitation to dig through someone's diary; that is, even if someone is incompetent in managing their security, there should probably still be a point at which abusing that crosses a line - though I am very open to discussing just where that point is (and some liability should certainly still sit with those who deployed an insecure system). All…
What if the diary is left open on the kitchen table, the "kitchen table" being the internet?
Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal
#109Earlier quoted context omitted.
This is, literally, an argument that if you stumble across a text file full of credit card numbers, expiration dates, and CVV codes, it should be lawful for you to put it up on Pastebin.
What law would cover that, some implied duty to help protect something that could be intended to be kept secret? I'm pretty sure that duty doesn't exist.