Live data from Hacker News

“The AT&T Hacker” Sentenced To 41 Months In Prison

techcrunch.com

151–160 of 176 posts

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#151

Earlier quoted context omitted.

The sign is definitely copyrighted as a creative work, and some sort of argument based on competitive advantage would certainly be brought out in regards to why taking the photograph has wronged the restaurant owner. These things don't make constructive sense, they're just convenient to invoke when it's time to conjure up some justification for persecution of the undesirables. Fortunately for the photographer, that w…

You are right that the public understands rats in restaurants more than they understand insecure web apps. But the public also understands that things visible through the front window of a business on a street are not private or secret. (And I know someone is itching to type that AT&T is just a window and they just served up exactly what Weev wanted, but I'm too tired to respond to such nonsense.) "Bringing a serious…

The only people who think weev's actions aren't illegal are people stuck thinking the laws make sense and trying to reconcile them with their morals. The real question is whether what he did is wrong, and if so, what level of punishment is appropriate.

I'd say that a list of email addresses isn't actually private information worthy of legal protection. We've just got these ridiculous laws calling widely-available datums "sensitive" because banks (et al) are trying to pretend that your "identity" is somehow being "stolen" rather than that they're simply being defrauded. So a simple trespass with questionable intent has been turned into a several year felony based on these toxic bits that aren't actually important enough to necessitate serious audits or redundant controls.

Frankly the highly fucked up part of these laws are the amount of time involved, both what defendants are pressured to plea bargain with, and the actual amounts that get sentenced. It's very easy to say that three years in a cage is reasonable from the comfort of your chair. We can debate what should be ultimately illegal etc, but with these kind of sentences we're basically talking about destroying someone's existing life for a non-violent action with minor damages that a different company wouldn't even press charges for.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#152
I am curious: What is the right protocol about telling that you were able to locate an egregious security flaw on a public server?

Should I go ahead and tell the company? And possibly get sued anyway? Do I have a right to show it to my friends or journalists?

Or should I just shut up and pretend that I have never seen this security problem?

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#153
post #116

Earlier quoted context omitted.

Watching the prosecutor butcher pronouncing "regexps" in federal court was worth it. (Seriously, they read his AMA responses in court this morning. Weev's a shithead, but still: 't'was glorious. )

Technological ignorance from the law makers and the judicial system is in part why that law exists and why Weev is locked up. It's funny to hear them butcher technical words and to see the word "Goatse" on CNN. ..But I've stopped laughing. It's time that technologists step up efforts to change things in the favor of communication and free speech.

I put $50k on the line to bail him out and talked him out of aaronsw'ing himself several times during the last few years while this nightmare progressed.

I must've missed you at the sentencing this morning. I was the hungover one in the mirrorshades.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#154
post #64

Earlier quoted context omitted.

He didn't expose some flaw or weakness. ATT knew that information was there, they were the ones that put it there. Weev was pointing out a negligent mishandling of data. ATT already has shown that they suck at vendor response. I think he has a duty to inform the public when there is an issue like that. If he had gone to ATT first, they likely would have lawyered him into oblivion, and kept their shitty service online…

This argument is very commonly made, and that's unfortunate because it is fundamentally flawed. Just because AT&T left the information exposed is not sufficient justification for some random person to take it, especially when that person takes it with the explicit intent to cause harm AND profit from it.

First off, what profit? Weev can be described by many negative terms, but greedy has never been one of them.

Secondly, if a company posts something publicly, people in the public are going to see it. My mind is incapable of comprehending the logic of anyone who would say "Just because we posted it on our website doesn't mean we wanted anyone to see it."

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#155
post #132

It should be noted that he was convicted on two counts: conspiracy to access a computer system without authorization, and fraud in connection with personal information. The way the CFAA works is that it's a misdemeanor unless the illegal access is pursuant to some other crime, which bumps it up to a felony. Had weev simply stumbled upon AT&T's security flaw and reported it AT&T, the worst they could have gone after h…

Possessing email addresses should not be a crime. Identity fraud for a list of emails? Really? It's insane even if you assume they were pristine and never received any spam before weev came along and "stole" them. Furthermore, the list was never sold, distributed, or published. An excerpt was sent to the media. They kicked around the idea of spearphishing, of spamming, of pastebinning it, of selling it. In full knowl…

It's actually quite simple, but requires a lot of question asking to figure out.

Hackers move easily between different levels of abstraction and believe that things in general can and should be understood. They try to never stop asking 'why?' and this leads them to find places where the system is incongruent. Many of these realizations are benign or even progress the system, and the advantage gained just helps the hacker succeed within it (eg. pg's main use of the word hacker). But some realizations contradict a foundation of the system (like insecurities of its central nervous system!).

The system is built on abstractions, takes them for granted, and reacts extremely harshly when they are broken (for this is an existential threat). The system can only understand a broken abstraction in terms of the abstraction itself, rather than in terms of underlying reality. Hence we end up with phony blame-shifting terms like "identity theft" instead of reality-based "fraud". Meanwhile, hackers see the failure of the abstraction in terms of the underlying reality and have a hard time seeing what the big deal is - just reprogram the abstraction!

Most people's thoughts are contained mostly within the system, having been indoctrinated into it from birth (constant rote memorization in primary school, blind repetition of contradictory facts, scolded by adults with tenuous justifications every time they don't follow the pack, etc). So they take what they're told at face value and follow along, all the while never seeing the whole picture and hence remaining afraid of mysterious agents that can take advantage of them for what they don't understand. If they're told that a collection of email addresses is a threat to their way of life, they'll actually believe this because they lack the broad framework to analyze the truth of this statement. They'll instead trust the system and assume it's correct, feeling that if it were indeed wrong they would no longer be able to take anything for granted.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#156
post #89

Earlier quoted context omitted.

> If he doesn't care why should I? If you pay US taxes you're paying to keep him in jail. I think he's a vile idiot. I don't think he should be in prison. There's a bunch of stuff that I think he did wrong, but I'll have to read the court documents to see if I agree with them. For example: He could have written a proof of concept script, and only downloaded a sample 10 pages, rather than grabbing as many as possible.…

Most likely. He would at least have leverage to say he just needed proof the exploit worked after he notified AT&T (which he claims he did, but I didn't find any clear evidence he had). Once you download over 100,000 records, your intent becomes a lot clearer in the eyes of the law. Had he only downloaded a few records, chances are he might get some community service and probation. Also, his stupidity in taking to Re…

I believe from extensive conversations with weev that his intent is and was always to fuck with ATT as much as possible without targeting innocents.

Malicious? Sure. Criminal. Not a chance.

He loves manipulating press and media for his own entertainment. The bigger the number, the bigger of an asshole he makes ATT look like by their not protecting it, and the more anguish he causes their management by damage to their brand and stock price.

A valid effort, I think, as manipulating some shitty corporation's reputation with FACTUAL DATA is one of the least underhanded ways of achieving the goal of "fuck with ATT".

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#157
post #90

Earlier quoted context omitted.

It wasn't just being mean. First-hand experience in my case. He and his GNAA attacked my volunteer-run open source project and did many things, including calling Child Protective Services (CPS) and making false complaints -- leading one of my volunteers and his children to have to undergo interviews with CPS to suss everything out. They emailed one person's professors at university and made false, damaging claims. Bo…

That sort of behavior is disgusting. There are questions about the CFAA, and rightfully so. But on one level, I am 100% fine with this asshole being in jail.

Isn't that the whole problem though, that the CFAA is being used to put assholes and activists in jail? If he got arrested for fake calls to CPS or something, I could agree with it perhaps, but I'm not at all comfortable with him going to jail for bullshit reasons.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#158
post #132

Earlier quoted context omitted.

Possessing email addresses should not be a crime. Identity fraud for a list of emails? Really? It's insane even if you assume they were pristine and never received any spam before weev came along and "stole" them. Furthermore, the list was never sold, distributed, or published. An excerpt was sent to the media. They kicked around the idea of spearphishing, of spamming, of pastebinning it, of selling it. In full knowl…

It's actually quite simple, but requires a lot of question asking to figure out. Hackers move easily between different levels of abstraction and believe that things in general can and should be understood. They try to never stop asking 'why?' and this leads them to find places where the system is incongruent. Many of these realizations are benign or even progress the system, and the advantage gained just helps the ha…

You're inventing a religion in which your people are the only holy people, and everybody else is just an infidel.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#159
post #158

Earlier quoted context omitted.

It's actually quite simple, but requires a lot of question asking to figure out. Hackers move easily between different levels of abstraction and believe that things in general can and should be understood. They try to never stop asking 'why?' and this leads them to find places where the system is incongruent. Many of these realizations are benign or even progress the system, and the advantage gained just helps the ha…

You're inventing a religion in which your people are the only holy people, and everybody else is just an infidel.

Anybody can ask 'why?', it just takes constant effort.

I theorize that all religions begin with understandings of fundamental truths that are summarized to pass along. They then ossify into mechanical words and take on an oppressive life of their own :/.

Re: “The AT&T Hacker” Sentenced To 41 Months In Prison

#160
post #91

Earlier quoted context omitted.

The default subreddits have suffered from an eternal september, if you unsubscribe from them & find the more niche subreddits it gets a lot better.

That's very true, but some of the smaller sub reddits are also vile. Justiceporn (people getting their come uppance) and cringe (originally things that made you cringe in sympathy, but latterly videos of socially awkward youth that Reddit could bully and mock) are two examples, but there are others.

...and bass (for bassists), and talesfromtechsupport (a place for IT to vent and relax) are fantastic and supportive. Reddit is a big place.
Post reply on HN