Live data from Hacker News

This hacker might seem shady, but throwing him in jail is bad for everyone

washingtonpost.com

131–140 of 213 posts

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#131
post #113

Earlier quoted context omitted.

Whether it's the server's or the client's fault doesn't matter that much from a legal perspective. Intent plays a big role: if you knew that ending a URL with "\" causes `rm -rf /*` to be run, and intentionally run that on a server, you could likely be prosecuted and convicted if it were proven that you did it intentionally. If it were done accidentally by a client, they would (likely, and hopefully) not be convicted…

No, Weev did not "exploit" anything. He _requested_ information from a server. If the server owner had so desired, they could have made the data private by adding a password. They chose not to. In the end, the decision to offer Weev the data was made _by the server_ . And if you're going to bring up the UserAgent spoofing, let me remind you that most browsers have done something like that for > 15 years.

Did Weev think that the email addresses didn't count as personal information, and were perfectly fine for anybody to scrape?

> If the server owner had so desired, they could have made the data private by adding a password.

But the server is still just sending data in response to a request, even with a password. The only reason a password is a line we draw is intent. It's hard to say you didn't realise that guessing at someones password was wrong.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#132
post #69

Earlier quoted context omitted.

This is currently downmodded because people don't like the implication. And they shouldn't, because it quickly forces someone into either a) agreeing with the law or b) saying that SQL injections must be, ipso facto, legal. Including ones like: 1 AND ("1" = SUBSTRING(select social_security_number from employees where employee_name = 'Angela Smith', 1, 1)) You can use variations on this to... a) Ask our librarian for…

I approach this from a different angle. If someone broke into my web app by injecting SQL, I'd be mad that I allowed them to do so. If someone broke into my apartment by smashing the window with a brick, I wouldn't be mad at myself for not using thicker glass. Therefore, I see SQL injections as sloppy programming, but physical break-ins as sloppy ethics. IMHO YMMV IANAL KTHXBYE.

And if you were missing window panes altogether, is it open season on robbing your house?

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#133
post #59

Earlier quoted context omitted.

> Private property is private property Except in many cases the private property is being made accessible. Imagine going to an open house and the owner accidentally left the basement unlocked. You open the door and walk down, then get arrested for breaking and entering.

More applicably, imagine there is no door, not even hinges where a door should be; just an opening to the basement. But you get arrested for walking down there anyway. Then the police tell you you're under arrest because "The owner didn't intend for you to go there."

If you wander in shouting "Lol guys, we totally shouldn't be allowed in here! Their security is awful! Quick, take pictures of all their documents and we'll post them to a news site" then you've got a more reasonable analogy.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#134
post #87

Earlier quoted context omitted.

I don't think it is like walking into a private home because the door is unlocked... this is more like someone walking into a store, looking around, and then getting in trouble for looking at a specific display shelf that was in the back corner. The shelf wasn't labeled as off limits, you just were wondering around where you were supposed to and happen to see it. The store can't get mad and say "well yeah, but we put…

If we want to stretch analogies beyond sense, how about this. You walk into a cake shop that has cupcakes with names written on the icing: You say "Can I have a cupcake with 'Iain' written on it?" They say "200 OK, here's a cupcake with Iain on it." You say "Can I have that wedding cake?" They say "401 Unauthorized, Sorry that's someone elses' cake." You don't get a wedding cake. You say "Can I have a cupcake with 'A…

> Did you do anything wrong?

Possibly, it depends on intent. Add in:

    You: Hahaha, guys I can get anybodies cake!
    You: Looool their security is awful!
    You: Hahah, we could short this companies stock!
Then you clearly knew what you were doing and therefore did something wrong.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#135
post #35

Everyone throws out analogies about walking into unlocked houses and such. Those are fairly poor analogies, so let me offer one which I think is far better at conveying what really happens. Imagine you walked into a public library and struck up a conversation with the librarian: You: Can you tell me general information about this library? Librarian: Certainly, this library was built in 1990, has a million books on it…

Example is good, but not quite right as they weren't asking a neutral resource. The librarian (let's switch for clerk) was told that if someone looking like X came in and made a request they were allowed to hand over a Y to them, so each time the `You` came in you had to wear a disguise that convinced the clerk you were actually `X`.

AT&T should be rightly mocked for their poor security, but weev wasn't just stumbling through data, he'd made good attempts to impersonate the setup the server wanted. He'd put a pair of glasses and a funny moustache on and the server was alright with it, which is definitely ridiculous.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#136
post #77
post #35

Everyone throws out analogies about walking into unlocked houses and such. Those are fairly poor analogies, so let me offer one which I think is far better at conveying what really happens. Imagine you walked into a public library and struck up a conversation with the librarian: You: Can you tell me general information about this library? Librarian: Certainly, this library was built in 1990, has a million books on it…

Maybe we should just stop throwing around analogies altogether when it comes to politics. Analogies are useful in teaching since it allows people to relate concepts they already understand. However, it's just an abstraction, and is inevitably imperfect. In normative arguments, analogies are used to bend reality to make your position seem reasonable regardless of whether or not it actually is. It would be better to ju…

The problem is that there is no consensus on the correct way to regulate these kinds of interactions yet. When we try to work out what a reasonable way to regulate something new is, we usually do so by analogy to other things that we already know how to regulate. That way we can make a whole bunch of analogies with various current situations and try to work out which one is the best analogy in the relevant aspects so we can come up with a good starting point for regulation.

This doesn't always work (particularly not for truly disruptive technical or social changes), but it's a pretty good way of doing it.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#137
post #68

Earlier quoted context omitted.

Not if I tricked the librarian into setting fire to the library.

What really is the line between tricked and asked? Deceit? Lets go with deceit. So is asking for book ISBN '1; DROP TABLE books; --' deceitful? Perhaps, that's not an ISBN after all. Is asking for book ISBN [some valid ISBN that you pulled out of your ass, but happens to exist] deceitful? I don't think so. If you are just asking for randomly chosen ISBNs and getting responses, I don't think there is any trickery invo…

I'd like to fix up the analogy a bit. The problem isn't that you're asking for a random ISBN numbers; it's that you don't have a library card. The library's electronic catalog won't let you log in without the card, so you just start asking the librarian for random ISBNs and accepting the books he gives you. He doesn't check on your card because no one trained him to do that, but you know that checking out books is meant for card-carrying library members. I sense deceit there.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#138
post #69

Earlier quoted context omitted.

This is currently downmodded because people don't like the implication. And they shouldn't, because it quickly forces someone into either a) agreeing with the law or b) saying that SQL injections must be, ipso facto, legal. Including ones like: 1 AND ("1" = SUBSTRING(select social_security_number from employees where employee_name = 'Angela Smith', 1, 1)) You can use variations on this to... a) Ask our librarian for…

I approach this from a different angle. If someone broke into my web app by injecting SQL, I'd be mad that I allowed them to do so. If someone broke into my apartment by smashing the window with a brick, I wouldn't be mad at myself for not using thicker glass. Therefore, I see SQL injections as sloppy programming, but physical break-ins as sloppy ethics. IMHO YMMV IANAL KTHXBYE.

If someone broke into my apartment by smashing the window with a brick, I wouldn't be mad at myself for not using thicker glass.

OK, but did they do anything wrong with SQL-injecting/breaking-a-window? I mean, if someone smashes your window can you call the cops and/or sue them for damages? In order to call the cops on the window smasher, you have to acknoledge they did a wrong.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#139
post #102
post #72

Earlier quoted context omitted.

No, it is because lying about your user-agent is not explicitly trying to make an HTTP server perform an action it is not supposed to perform and is therefore not in the same category as SQL injections. HTTP servers are not supposed to use user-agent as authentication.

It's the equivalent of going to a Chinese restaurant and asking for the "Chinese menu" rather than the "American menu" even if you can't read Chinese.

Heh, I'm reminded of an anecdote of an elderly English relative who was in a chinese restaurant (in England), and was suprised that the English menu was chinese food but written in English, instead of steak, potatoes and veg that used to be on the "english menu" in chinese restauarants decades ago. :P

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#140
post #68

Earlier quoted context omitted.

Not if I tricked the librarian into setting fire to the library.

What really is the line between tricked and asked? Deceit? Lets go with deceit. So is asking for book ISBN '1; DROP TABLE books; --' deceitful? Perhaps, that's not an ISBN after all. Is asking for book ISBN [some valid ISBN that you pulled out of your ass, but happens to exist] deceitful? I don't think so. If you are just asking for randomly chosen ISBNs and getting responses, I don't think there is any trickery invo…

What really is the line between tricked and asked? Deceit?

What you (the asker/trickster) think the askee thought of it.

Post reply on HN