Live data from Hacker News

Reporter may be prosecuted for using “view source”

stltoday.com

111–120 of 168 posts

Re: Reporter may be prosecuted for using “view source”

#111

We desperately need a law that says (or at least need people in power to understand that) if your server sends it (as an agent working on behalf of your interests), you decided it was ok for me to receive it! For HTTP this understanding is literally conveyed in the status code (200-OK). Once data is sent to the client, you can't say they are breaking the law by looking at it[0]. Anyone with a text-based browser would…

As someone who was thoroughly and intimately familiar with both the person weev was/is and the details surrounding the AT&T disclosure case, there is absolutely NO question that weev deserved to be incarcerated and for far longer than he ended serving. Multiple people are in federal prison on his account, multiple lives have been stained and essentially ruined on account of weev surrendering ("snitching") information, sometimes true and sometimes false, about other criminal events.

Don't believe what you have heard, I know it seems very hacker-y and noble, and he tried to do the right thing and disclose, so we should just cut him a break, blah blah blah. There's MILES of evidence against him seeing free life. He's been involved in financial fraud, harassment cases against minors, illegal pornography against minors, threats of harms against strangers on the internet, there's even (unfounded, though somewhat plausible) claims that he's developed spyware for profit. I don't want to be doxxed, so I'll leave it at that. I've known weev for a long time, and I'm sure glad he doesn't know me.

To clarify, I am in favor of laws defending those who receive data from a sender having immunity. It seems common-sense. If you give me a ten dollar bill, and ask for it back, I can just decline, and walk away. It's rude and wrong, but it's legal, and it ought to be. CFAA has put a lot of bright, young minds in jail, and they are subsequently extorted and abused by multiple state agencies in the name of "cyber defense." It's grotesque.

But don't make weev a hero. He's not.

Re: Reporter may be prosecuted for using “view source”

#112

> “If somebody picks your lock on your house — for whatever reason, it’s not a good lock, it’s a cheap lock or whatever problem you might have — they do not have the right to go into your house and take anything that belongs to you,” Parson said. The reporter did the equivalent of noticing a lock was rusted through and barely hanging on. He poked the lock and it crumbled to pieces. He didn't take anything, he reporte…

A better example is that you wrote a snail-mail letter to the government asking for some info (HTTP Request) and the written mail response (HTTP Response) included a sticky note stuck to it with secret info. Confused, you write another 2 letters and get another 2 sticky note (now you confirm its a problem). Realizing something is wrong, you tell the gov and they move the pile of sticky-noted confidential info away from the letter processing desk.

Re: Reporter may be prosecuted for using “view source”

#113
post #84

Earlier quoted context omitted.

I believe what we've got today in most countries is pretty ok, maybe ambiguous but it does the job as far as an ethically concerned person would go. In my country they classify it as "unauthorized access". That's perfectly fine with me. In other words, if your server sends it, and you intended to send it, then I can have a look at it. If your server sends it, but you never intended (sysadmin, programmer error, bureau…

> If your server sends it, but you never intended (sysadmin, programmer error, bureaucracy, unsecured servers etc), and it's clear for me the information was never meant to be public, then I'm committing unauthorized access. So if your server sends privileged data and I "View Source" to see how you implemented some unrelated part of your site and accidentally see that data, I'm now guilty of unauthorized access and s…

So if you left open the front door of a police station and I enter to see how an unrelated part of the building is built, and accidentally grab a gun I see on somebody's desk.. then I would most certainly expect to be prosecuted.

I understand you want to punish whoever forgot to close the door, and obviously the guy who abandoned his gun, I agree... but I have no business of being there whatsoever!

Re: Reporter may be prosecuted for using “view source”

#114

We desperately need a law that says (or at least need people in power to understand that) if your server sends it (as an agent working on behalf of your interests), you decided it was ok for me to receive it! For HTTP this understanding is literally conveyed in the status code (200-OK). Once data is sent to the client, you can't say they are breaking the law by looking at it[0]. Anyone with a text-based browser would…

We desperately need a law Why not just have a law against subverting the intent of existing laws, or against making bad-faith arguments? Laws are only as good as people's willingness to accept impartial assessment thereof. Absent that, they will just be exploited selectively for strategic leverage. Aristotle observed that laws tend to multiply under tyrannical regimes, as rulers impose ever more onerous conditions up…

This approach is inherently unclear. Intent is never completely recorded because doing so is fundamentally impossible--there's far too much minutiae and unwritten context to guarantee that jurists are following intent, and consistency is important in law (ideally, anyway--this ignores the real and present issues in US jurisprudence where consistency is thrown out the window for partisan benefit).

You can't have laws whose interpretation is "don't do things you shouldn't" because parties in legal disputes clearly disagree about what "shouldn't" means, else they wouldn't fucking be resolving them through expensive and lengthy legal action.

There's a meaningful distinction between clarification of and expansion of the law. Legislators are responsible for both. OP may not have phrased it precisely, but they're saying the CFAA needs to be _clarified_. This doesn't mean it expands in scope--if anything, its scope would be narrowed.

Re: Reporter may be prosecuted for using “view source”

#115

We desperately need a law that says (or at least need people in power to understand that) if your server sends it (as an agent working on behalf of your interests), you decided it was ok for me to receive it! For HTTP this understanding is literally conveyed in the status code (200-OK). Once data is sent to the client, you can't say they are breaking the law by looking at it[0]. Anyone with a text-based browser would…

Powerful Hacking Tool view source Even the FBI agent quoted in the article got it wrong, stating “allowed open source tools to be used to query data that should not be public.” - as if proprietary browsers don't provide a View Source feature, only "evil" open source tools. Maybe I'm reading too much into it and it's a minor mistake but given the context even a potentially innocuous statement like that rubs me the wro…

No post body was provided.

Re: Reporter may be prosecuted for using “view source”

#116

Earlier quoted context omitted.

I agree that both of those shouldn't be punished. I'm not sure how one would properly define the law tho - for ex. an SQL injection could also be "just a query parameter" and the server would haply reply with a 200.

SQL injection is probably malformed input in lots of cases and should return a 400 Bad Request. If you are returning a 200 maybe you really did want to take SQL (think of Mode or PHPMyAdmin).

That assumes that the server recognized it as invalid. It it had, then it should take measured to block the input, but if the attack succeeded then the server would not be recognizing the attach and would respond with a 200

Re: Reporter may be prosecuted for using “view source”

#117

Earlier quoted context omitted.

That would make a lot of companies responsible for the data they keep and should be responsible for protecting. SQL injection can be (and probably is) malicious though, so I suppose it becomes a unclear line for that example. Maybe punishment of both parties would be appropriate but I'm not a lawyer so don't have expertise in law punishments. But I could see this as incentivizing data security. Even if a 0 day is dis…

Honestly, I'd want to see strict liability for data breaches, with revealing of personal information included as a type of injury, and not merely something that must be shown to have led to other forms of injury. Right now, the most I can do is reduce the amount of personal information that is collected about me, and I have no ability to ensure that it is stored in a secure manner. Companies that record personal info…

I’m not sure I believe in 100% strict liability. Imagine if someone were to perform a B&E or armored robbery at a physical location to steal hard copies of records.

Clearly if someone uses a zero day to steal personal information from an otherwise secure server than the server’s owners were not negligent.

In addition, often times the only people that know there was a data breach is the organization that had their data breached and the attackers that stole the data. None of the parties could report the data breach without violating their 5th amendment rights if they both had legal liability.

Re: Reporter may be prosecuted for using “view source”

#118

Someone - a particular political party - is attacking the free press and freedom generally. The only answer is to be heard, loudly, and vote them out of office. The cavalry isn't coming - nobody will save us but us. It's not a partisan statement. I'm not saying it to favor one party or another (though unavoidably the other party would benefit - we'd be better off with multiple parties committed to democracy). We agre…

Unfortunately, it's actually both political parties.

Re: Reporter may be prosecuted for using “view source”

#119
post #118

Someone - a particular political party - is attacking the free press and freedom generally. The only answer is to be heard, loudly, and vote them out of office. The cavalry isn't coming - nobody will save us but us. It's not a partisan statement. I'm not saying it to favor one party or another (though unavoidably the other party would benefit - we'd be better off with multiple parties committed to democracy). We agre…

Unfortunately, it's actually both political parties.

That and expansion of surveillance authority is the one thing they seem to agree on.

Re: Reporter may be prosecuted for using “view source”

#120

We desperately need a law that says (or at least need people in power to understand that) if your server sends it (as an agent working on behalf of your interests), you decided it was ok for me to receive it! For HTTP this understanding is literally conveyed in the status code (200-OK). Once data is sent to the client, you can't say they are breaking the law by looking at it[0]. Anyone with a text-based browser would…

Powerful Hacking Tool view source Even the FBI agent quoted in the article got it wrong, stating “allowed open source tools to be used to query data that should not be public.” - as if proprietary browsers don't provide a View Source feature, only "evil" open source tools. Maybe I'm reading too much into it and it's a minor mistake but given the context even a potentially innocuous statement like that rubs me the wro…

As anyone could probably guess, LEOs that do actual technical work are rarely the same ones talking to the public about that technical work. Thus what gets said to or published for the public is rarely reflective of the actual internal understanding.
Post reply on HN