Live data from Hacker News

“The AT&T Hacker” Sentenced To 41 Months In Prison

techcrunch.com

131–140 of 176 posts

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#131
post #91

Earlier quoted context omitted.

The default subreddits have suffered from an eternal september, if you unsubscribe from them & find the more niche subreddits it gets a lot better.

That's very true, but some of the smaller sub reddits are also vile. Justiceporn (people getting their come uppance) and cringe (originally things that made you cringe in sympathy, but latterly videos of socially awkward youth that Reddit could bully and mock) are two examples, but there are others.

No way, really? Are there small (sub)communities on the internet that are vile? ...

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#132

It should be noted that he was convicted on two counts: conspiracy to access a computer system without authorization, and fraud in connection with personal information. The way the CFAA works is that it's a misdemeanor unless the illegal access is pursuant to some other crime, which bumps it up to a felony. Had weev simply stumbled upon AT&T's security flaw and reported it AT&T, the worst they could have gone after h…

Possessing email addresses should not be a crime.

Identity fraud for a list of emails? Really?

It's insane even if you assume they were pristine and never received any spam before weev came along and "stole" them. Furthermore, the list was never sold, distributed, or published.

An excerpt was sent to the media.

They kicked around the idea of spearphishing, of spamming, of pastebinning it, of selling it. In full knowledge of the value and leverage that this data allowed, they contacted the media and deleted their own copies. It profited them nothing.

The idea that this is akin to trespassing is simultaneously both obtuse and dangerous. There were _no_ access controls; ATT themselves said in court that the information was published (by them) on the web.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#133
post #72
post #59

Earlier quoted context omitted.

You will when its your turn.

Somehow I'm not concerned yet. When I'd feel the urge to take personal data of 100K users from AT&T and publish them and then a day before my sentencing I'd feel it necessary to say my only regret is that I didn't do more harm - then I'd be concerned more. Don't foresee it happening soon, though.

The PII was never published by anyone except AT&T.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#134
post #132

It should be noted that he was convicted on two counts: conspiracy to access a computer system without authorization, and fraud in connection with personal information. The way the CFAA works is that it's a misdemeanor unless the illegal access is pursuant to some other crime, which bumps it up to a felony. Had weev simply stumbled upon AT&T's security flaw and reported it AT&T, the worst they could have gone after h…

Possessing email addresses should not be a crime. Identity fraud for a list of emails? Really? It's insane even if you assume they were pristine and never received any spam before weev came along and "stole" them. Furthermore, the list was never sold, distributed, or published. An excerpt was sent to the media. They kicked around the idea of spearphishing, of spamming, of pastebinning it, of selling it. In full knowl…

I was about to post a similar comment to yours until I clicked through to the linked AMA below and saw some of his GNAA history.

Given that history, it's really easy to claim that he was intending to do harm with that list of emails, and it's also pretty easy to think of ways for him to do harm. Idendity fraud might be a bit of a reach, but computer abuse with malevolent intent? Not too hard to get there from his public statements.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#135
post #89
post #39

Earlier quoted context omitted.

If he doesn't care why should I? I know many security researchers who aren't trolls and they are doing fine. When it happens to somebody who isn't purposefully self-destructive, then it may be a better case for concern.

> If he doesn't care why should I? If you pay US taxes you're paying to keep him in jail. I think he's a vile idiot. I don't think he should be in prison. There's a bunch of stuff that I think he did wrong, but I'll have to read the court documents to see if I agree with them. For example: He could have written a proof of concept script, and only downloaded a sample 10 pages, rather than grabbing as many as possible.…

Most likely. He would at least have leverage to say he just needed proof the exploit worked after he notified AT&T (which he claims he did, but I didn't find any clear evidence he had). Once you download over 100,000 records, your intent becomes a lot clearer in the eyes of the law.

Had he only downloaded a few records, chances are he might get some community service and probation. Also, his stupidity in taking to Reddit to proclaim next time he won't be so nice didn't help either.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#136
post #134
post #132

Earlier quoted context omitted.

Possessing email addresses should not be a crime. Identity fraud for a list of emails? Really? It's insane even if you assume they were pristine and never received any spam before weev came along and "stole" them. Furthermore, the list was never sold, distributed, or published. An excerpt was sent to the media. They kicked around the idea of spearphishing, of spamming, of pastebinning it, of selling it. In full knowl…

I was about to post a similar comment to yours until I clicked through to the linked AMA below and saw some of his GNAA history. Given that history, it's really easy to claim that he was intending to do harm with that list of emails, and it's also pretty easy to think of ways for him to do harm. Idendity fraud might be a bit of a reach, but computer abuse with malevolent intent? Not too hard to get there from his pub…

Edited to add paragraph beginning "They kicked..." to clarify.

They could have been really bad guys. That didn't happen.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#137
post #132

It should be noted that he was convicted on two counts: conspiracy to access a computer system without authorization, and fraud in connection with personal information. The way the CFAA works is that it's a misdemeanor unless the illegal access is pursuant to some other crime, which bumps it up to a felony. Had weev simply stumbled upon AT&T's security flaw and reported it AT&T, the worst they could have gone after h…

Possessing email addresses should not be a crime. Identity fraud for a list of emails? Really? It's insane even if you assume they were pristine and never received any spam before weev came along and "stole" them. Furthermore, the list was never sold, distributed, or published. An excerpt was sent to the media. They kicked around the idea of spearphishing, of spamming, of pastebinning it, of selling it. In full knowl…

> Possessing email addresses should not be a crime.

Collecting lists of e-mail addresses from private databases without authorization should be.

> Identity fraud for a list of emails? Really?

Weev said in IRC conversations that he was going to sell the e-mail lists. Maybe you don't believe him, but it's hard to argue that no reasonable person could have believed that he was going to do what he said he might do.

> Furthermore, the list was never sold, distributed, or published.

If someone breaks into your house with safe-cracking tools in his possession, he doesn't have to actually break into your safe to be charged with and convicted of burglary.

> There were _no_ access controls;

I don't lock the door to my apartment. That doesn't mean you're welcome to walk in and look around. If we were in Florida or Texas, I could shoot you in the face for walking into my unlocked house and nobody would convict me.

Society charges you with being a normal functioning human being and respecting obvious boundaries. Obviously this is too high of a bar for people like Weev.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#138
post #126

Earlier quoted context omitted.

Sure, but that's a question for the legislature, of course. Courts are going to give deference to the policy choices of what crimes deserve what punishments.

They hit him with the maximum sentence, not the minimum -- this one's on the courts. If it was a case of someone going away for 10 years for shoplifting because of 3 strikes, then that's on the legislature.

No it isn't The minimum/maximums are legislatively defined (In this case, through the US sentencing guidelines, which came through the Sentencing act of 1984)

If they didn't want the maximum to be the maximum, they shouldn't have put it in the range?

For the most part, the actual calculation is mechanical. Unless the judge performed an upward departure (which i can't find any evidence of), he was just following the guidelines.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#139
post #134
post #132

Earlier quoted context omitted.

Possessing email addresses should not be a crime. Identity fraud for a list of emails? Really? It's insane even if you assume they were pristine and never received any spam before weev came along and "stole" them. Furthermore, the list was never sold, distributed, or published. An excerpt was sent to the media. They kicked around the idea of spearphishing, of spamming, of pastebinning it, of selling it. In full knowl…

I was about to post a similar comment to yours until I clicked through to the linked AMA below and saw some of his GNAA history. Given that history, it's really easy to claim that he was intending to do harm with that list of emails, and it's also pretty easy to think of ways for him to do harm. Idendity fraud might be a bit of a reach, but computer abuse with malevolent intent? Not too hard to get there from his pub…

Those emails we're exposed to the public. Weev's security company exposed "gaping holes". AT&T are at fault for exposing their customers information in the first place.

Anybody COULD have done harm with those emails. He didn't. He used them as a fodder for public discussion about internet security.

AT&T should owe him a "thank you".

AT&T customers owe AT&T a boycott for being irresponsible with their information.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#140
post #107
post #76

Earlier quoted context omitted.

>If he'd gotten 3-6 month suspended sentence, even if you thought that was a bit much for essentially incrementing numbers, you'd probably not care much. And to be fair, if he didn't do things like the AMA, he probably would have gotten the 3-6 month sentence.

His comrade got 12-15mo, so I think there was little chance of weev getting less (and probably 24mo was the most likely). I predicted 3y before his last little bit of trolling.

Trolling isn't illegal, and should not be a factor in this discussion.

They didn't sentence him for previous trolling, name calling, or tom foolery.

Post reply on HN