Live data from Hacker News

You May Not Like Weev, But Your Online Freedom Depends on His Appeal

wired.com

111–120 of 145 posts

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#111
post #4

I, for one like Weev. He is a boundary pusher. Many even around here on hn might perceive his stuff as tasteless. But I sincerely wished more people were as dedicated to their "ideals" as Weev is. Defending free speech means standing up for people who have controversial views - no matter how unease you personally are with these views.

Definitely. Free speech stands or falls on the most offensive speech. It's easy to support free speech when all you say or hear is motherhood and apple pie. It's the things that make people uncomfortable that need protection from censorship.

It's the things that make people uncomfortable that need protection from censorship

Agreed; things like "Fire!" when there isn't a fire.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#112
post #63

Earlier quoted context omitted.

That first sentence doesn't make sense. If a merchant screws up and manages to post a flat ASCII text file of credit card accounts with CVV numbers on a URL in a directory with an Apache index enabled, your argument says "well, sucks for the merchant and all their customers". There are clearly cases where the mere fact that someone has left something somehow exposed to a web browser does not connote authorization to…

If a merchant screws up and manages to post a flat ASCII text file of credit card accounts with CVV numbers on a URL in a directory with an Apache index enabled, your argument says "well, sucks for the merchant and all their customers". Since that would be a clear and basic PCI violation, yeah, it sucks for the merchant and their customers. Why have PCI compliance at all if the merchant can just throw up their hands…

Why does it have to be either/or? Shouldn't both the company and the "hacker" potentially be liable?

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#113

Earlier quoted context omitted.

What law would cover that, some implied duty to help protect something that could be intended to be kept secret? I'm pretty sure that duty doesn't exist.

Wire fraud, for one. That's pretty much a textbook example of it.

Can you explain how Weev's acts reach wire fraud? I can see the wire, but the fraud eludes me.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#114

Earlier quoted context omitted.

What if the diary is left open on the kitchen table, the "kitchen table" being the internet?

It would be a violation of privacy to sit down and read it through. Whether this should be legally actionable (as opposed to just socially) is another question, of course, but nevertheless.

Is the particular violation of privacy you identify actually illegal?

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#115

Earlier quoted context omitted.

If a merchant screws up and manages to post a flat ASCII text file of credit card accounts with CVV numbers on a URL in a directory with an Apache index enabled, your argument says "well, sucks for the merchant and all their customers". Since that would be a clear and basic PCI violation, yeah, it sucks for the merchant and their customers. Why have PCI compliance at all if the merchant can just throw up their hands…

Why does it have to be either/or? Shouldn't both the company and the "hacker" potentially be liable?

I was vaguely implying that companies are basically never held responsible in this way.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#116

Earlier quoted context omitted.

Wire fraud, for one. That's pretty much a textbook example of it.

Can you explain how Weev's acts reach wire fraud? I can see the wire, but the fraud eludes me.

I was referring to tptacek's statement:

"This is, literally, an argument that if you stumble across a text file full of credit card numbers, expiration dates, and CVV codes, it should be lawful for you to put it up on Pastebin."

Which, when carders are caught on forums doing the above, they are charged with wire fraud.

I agree with you completely that I don't think Weev's acts were wire fraud.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#117
post #12

I agree with the sentiment that computer use crimes need to be reworked, and that weev shouldn't have been hoisted by the fact he is a colossal dick but the article seems to gloss over things for the sake of the argument. - `The spoofing was irrelevant; Spitler would have gotten the same email addresses if he had manually inputted the URLs on an iPad rather than a spoofed desktop browser.`, the spoofing is incredibly…

It doesn't matter if they accessed one or a million - accessing information published on the web SHOULD NOT BE CRIMINAL. Whether you agree with his methods or not, there is no stretch of the imagination that makes prison for downloading (even 114k of) them make sense. It wasn't a hole or bug— it was an expressly implemented feature. ATT decided to do it this way to reduce resubscription friction. The iPad sends the s…

>>> It doesn't matter if they accessed one or a million - accessing information published on the web SHOULD NOT BE CRIMINAL.

By this logic, any information stored on any computer accessible via the Internet is published, so no unauthorized access to any data not behind an air gap is illegal. Including breaking into your private mailbox or your online banking account. I don't think I'd be ready to accept this. Are you?

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#118

Earlier quoted context omitted.

"It should always be perfectly legal to access a remote computer system via a publicly accessible interface.", no it shouldn't, no more than it should be legal for me to walk into your house if you've not locked the door. The system worked exactly as AT&T intended, in circumstances they'd clearly not planned for. If they'd bothered doing a risk assessment they'd have spotted it, they took the lazy option and it didn'…

If you want to use a physical analogy, it would be more like I invite you into my home, then shoot you because you stepped in a spot that I didn't like.

AT&T invited weev to check their interfaces? Could I see a link with the text of that invitation?

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#119

Earlier quoted context omitted.

It would be a violation of privacy to sit down and read it through. Whether this should be legally actionable (as opposed to just socially) is another question, of course, but nevertheless.

Is the particular violation of privacy you identify actually illegal?

That depends on who's doing it, and under what circumstances. If it's a cop without a warrant, arguably.

My point was just that we respect and enforce limits by means other than technological, and it's correct that we do so.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#120

Earlier quoted context omitted.

Can you explain how Weev's acts reach wire fraud? I can see the wire, but the fraud eludes me.

I was referring to tptacek's statement: "This is, literally, an argument that if you stumble across a text file full of credit card numbers, expiration dates, and CVV codes, it should be lawful for you to put it up on Pastebin." Which, when carders are caught on forums doing the above, they are charged with wire fraud. I agree with you completely that I don't think Weev's acts were wire fraud.

My impression is that the Pastebin'ed CC# example does not provide the charge, but evidence that helps prosecute the fraud through which they were acquired.
Post reply on HN