Live data from Hacker News

You May Not Like Weev, But Your Online Freedom Depends on His Appeal

wired.com

131–140 of 145 posts

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#131
post #130
post #65

Earlier quoted context omitted.

Why does it have to be either/or? Why can't both people be responsible? Why can't AT&T be civilly liable for leaving a gaping hole on their application, and whoever abused that information be criminally liable? Incidentally, every time you blame AT&T for what happened, you tacitly acknowledge that wrongdoing actually occurred, which harms your argument that the data was "published". (In the interest of combating the…

> Why can't AT&T be civilly liable for leaving a gaping hole on their application, and whoever abused that information be criminally liable? What abuse of information are you referring to? The part where they sent it to a journalist? I blame AT&T for being shitty and reckless, not for being criminal.

I'm responding to the zero-sum nature of your comment above, about how the company harboring the vulnerability should be the one penalized for security incidents. And all I'm saying is, there's no reason why we can't penalize both: companies, when they're negligent, and people who exploit that negligence.

Also: we both know there's more to the story with Auernheimer than simply sending material to journalists.

Once again, we probably agree that Auernheumer doesn't belong in prison over this particular incident. He was overcharged and oversentenced. But I find the exact philosophy that drives you to that conclusion challenging, which is why I called it out.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#132
post #128

Earlier quoted context omitted.

If you think publishing people's credit card numbers implicates a PETA-like ethic.

There were neither "people's credit card numbers" nor "publishing" in this instance. It seems like you're being intentionally confusing. We're talking about a list of email addresses (which I don't think should be protected data in any way, they're just email addresses) and a journalist running a blacked-out screenshot of a dozen of them.

I think you know I'm not being intentionally confusing; that's not who I am. I'm responding to part of your comment. I'm not writing a brief against Auernheimer. The way you know that is, my comments have repeatedly agreed with yours that his sentence is unjust.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#133
post #130

Earlier quoted context omitted.

> Why can't AT&T be civilly liable for leaving a gaping hole on their application, and whoever abused that information be criminally liable? What abuse of information are you referring to? The part where they sent it to a journalist? I blame AT&T for being shitty and reckless, not for being criminal.

I'm responding to the zero-sum nature of your comment above, about how the company harboring the vulnerability should be the one penalized for security incidents. And all I'm saying is, there's no reason why we can't penalize both: companies, when they're negligent, and people who exploit that negligence. Also: we both know there's more to the story with Auernheimer than simply sending material to journalists. Once a…

> Also: we both know there's more to the story with Auernheimer than simply sending material to journalists.

Uhh, excuse me? They discussed what could have been done maliciously with the data, and then DIDN'T DO ANY OF THOSE THINGS. I honestly don't know what else you're alluding to.

To answer your main point:

I figured it out yesterday. I believe that sending packets over the internet, of any kind, with any content, is protected speech.

We're allowed to say what we want. It's the responsibility of a listener to determine how they respond.

This is how the world works, and it should be how the internet works, too.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#134
post #118

Earlier quoted context omitted.

If you want to use a physical analogy, it would be more like I invite you into my home, then shoot you because you stepped in a spot that I didn't like.

AT&T invited weev to check their interfaces? Could I see a link with the text of that invitation?

Weev owned an iPad. His iPad checked a url on ATT without him doing anything. That's really more than an invitation.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#135
post #133

Earlier quoted context omitted.

I'm responding to the zero-sum nature of your comment above, about how the company harboring the vulnerability should be the one penalized for security incidents. And all I'm saying is, there's no reason why we can't penalize both: companies, when they're negligent, and people who exploit that negligence. Also: we both know there's more to the story with Auernheimer than simply sending material to journalists. Once a…

> Also: we both know there's more to the story with Auernheimer than simply sending material to journalists. Uhh, excuse me? They discussed what could have been done maliciously with the data, and then DIDN'T DO ANY OF THOSE THINGS. I honestly don't know what else you're alluding to. To answer your main point: I figured it out yesterday. I believe that sending packets over the internet, of any kind, with any content,…

That's not the way the world works. You have protected speech, but you can't rely on that protection when you use it to defraud someone.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#136

Earlier quoted context omitted.

If a merchant screws up and manages to post a flat ASCII text file of credit card accounts with CVV numbers on a URL in a directory with an Apache index enabled, your argument says "well, sucks for the merchant and all their customers". Since that would be a clear and basic PCI violation, yeah, it sucks for the merchant and their customers. Why have PCI compliance at all if the merchant can just throw up their hands…

Why does it have to be either/or? Shouldn't both the company and the "hacker" potentially be liable?

No, because then the collateral damage is everyone misidentified as a "hacker" because prosecutors don't know the difference between criminal actions and not because the internet is confusing to everyone who hasn't spent the last two decades staring at the underbelly. Also, prosecutors default to "criminal" because their job is to deal with criminals all day (c.f. aaronsw).

It's unreasonable for us to expect the legislature to get this right. Nothing here is criminal.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#137
post #118

Earlier quoted context omitted.

AT&T invited weev to check their interfaces? Could I see a link with the text of that invitation?

Weev owned an iPad. His iPad checked a url on ATT without him doing anything. That's really more than an invitation.

Really? So if you have a device that checks your email on gmail this is an invitation to browse any mailboxes stored on gmail? I have such device, you wouldn't mind me reading your gmail mailbox, right? Or would you?

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#138
post #136

Earlier quoted context omitted.

Why does it have to be either/or? Shouldn't both the company and the "hacker" potentially be liable?

No, because then the collateral damage is everyone misidentified as a "hacker" because prosecutors don't know the difference between criminal actions and not because the internet is confusing to everyone who hasn't spent the last two decades staring at the underbelly. Also, prosecutors default to "criminal" because their job is to deal with criminals all day (c.f. aaronsw). It's unreasonable for us to expect the legi…

The criminal justice system deals with fraud in more complicated settings than computer hacking. For instance, it convicted ADM executives for price-fixing lysine. I don't recall anyone being up in arms at the time about how the prosecutors didn't fully understand the lysine industry.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#139

Earlier quoted context omitted.

Definitely. Free speech stands or falls on the most offensive speech. It's easy to support free speech when all you say or hear is motherhood and apple pie. It's the things that make people uncomfortable that need protection from censorship.

It's the things that make people uncomfortable that need protection from censorship Agreed; things like "Fire!" when there isn't a fire.

I was thinking more about things that make people emotionally uncomfortable, rather than real-life trolling that has the potential to trigger a life-threatening stampede to the exits.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#140

Earlier quoted context omitted.

My impression is that the Pastebin'ed CC# example does not provide the charge, but evidence that helps prosecute the fraud through which they were acquired.

I'll walk back calling it a "textbook example" (because I suppose ultimately it's probably up to the quality of the lawyers involved), but the part of 18 USC 1343 that I think would be argued by the prosecution in the "pastebin cc numbers example" is: "...or promises, transmits or causes to be transmitted by means of wire, radio, or television communication in interstate or foreign commerce, any writings, signs, sign…

OK, so how does it reach Weev again?
Post reply on HN