Live data from Hacker News

This hacker might seem shady, but throwing him in jail is bad for everyone

washingtonpost.com

161–170 of 213 posts

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#161

Earlier quoted context omitted.

Later, when I crack your bank password, Me: Can you provide me with all of guelo's money? Bank: Sure, here you go. Also, when I approach your house, Me: I have these lock picks. Will you let me in? Lock: Sure thing, boss!

Well in a private by default world, browsing the internet just became one hell of a lot scarier. Any page you visit could become a felony.

Not so, because as others in this thread have stated, the key is intent.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#162
post #131
post #113

Earlier quoted context omitted.

No, Weev did not "exploit" anything. He _requested_ information from a server. If the server owner had so desired, they could have made the data private by adding a password. They chose not to. In the end, the decision to offer Weev the data was made _by the server_ . And if you're going to bring up the UserAgent spoofing, let me remind you that most browsers have done something like that for > 15 years.

Did Weev think that the email addresses didn't count as personal information, and were perfectly fine for anybody to scrape? > If the server owner had so desired, they could have made the data private by adding a password. But the server is still just sending data in response to a request, even with a password. The only reason a password is a line we draw is intent . It's hard to say you didn't realise that guessing…

Then, it seems, a good solution to solve the problem is to have server owner to declare in advance what are intended use and what's not. Accessing information without providing the correct password is certainly unintended use, so is guessing passwords. And accessing knowing the password is definitely the intended mode of operation.

A logical step is to make that machine readable. Oh, wait, suddenly this is getting to the server software and configuration, that server developer/administrator had screwed up.

My question is - why we don't make that logical step and simplify things instead of relying on some "should be common sense" and "you should've known you wasn't supposed to do so" completely-gray-area?

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#163
I know this is not a position people over here like to support, but..

  But this technique, known as "scraping," is surprisingly common among
  technologically sophisticated users and has a number of legitimate
  applications.

  To get a list of sex offenders, Poulsen wrote an automated program to search the
  Department of Justice Web site for each zip code
  in the United States and then save the name and
  address of each registered sex offender in that
  zip code to a file.
Really? Really? That's a 'legitimate application'? Nevermind that the pure existence of that registry is a slap in the face for people with my understanding of Freedom and Liberty (in caps), scraping _that list_ is why we want to protect scraping? I haven't felt that disconnected to content on this site for a long time.

  Yet most people would agree that Poulsen's actions
  were a legitimate journalistic project. So we might
  want to be careful about subjecting this kind of
  technique to criminal penalties.
Most people?? In what world?

I'm sorry for the detour, but the whole article is trying to defend weev while linking to atrocious actions of that guy in the past and coming up with the most despicable (Thanks Hollywood, learned a new term) reason for scraping _ever_. Disgusting.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#164
post #56

Here is my analogy: 1. You just finished your workout and went to a locker room at your gym (he went to a public website) 2. You opened up your own locker and took your stuff from it (checked his account) 3. You found out that very few people are using locks in the gym locker room (figured the account id in url ) 4. You know that it is not your belongings in other people lockers, but they are not locked just because…

It's more like you meticulously wrote down the contents of the lockers without taking anything at all and then sold the information about what types of clothes people at your gym wear to a marketing firm.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#165

Earlier quoted context omitted.

Well in a private by default world, browsing the internet just became one hell of a lot scarier. Any page you visit could become a felony.

Not so, because as others in this thread have stated, the key is intent.

And we peer into the mind of a third party how?

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#166
post #102

Earlier quoted context omitted.

It's the equivalent of going to a Chinese restaurant and asking for the "Chinese menu" rather than the "American menu" even if you can't read Chinese.

Except for that the Chinese menu wasn't written in Chinese but in English. Moreover it contained an access card to the staff lounge where the customer records were open on the table.

Again completely wrong because trespassing on the staff lounge is nothing like receiving a response from an HTTP server. It is like asking for the Chinese menu and being given a list of customer records.

EDIT: and then noticing what happened you ask if they have a version in Korean.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#167
post #76

Earlier quoted context omitted.

Then that is a poor librarian. A good librarian should have just said: 400 BAD REQUEST Whomever staffed that librarian, should interview or train their staff better.

You shouldn't have to train your staff not to burn down the building they are working in...

Obviously. If the administrator locked access to matches, nothing could be burned. The admin is responsible for leaving matches open at the library, and allowing the librarian to do as they please.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#168
post #128

Earlier quoted context omitted.

As is often the case, and is often ignored, the key is intent . There is a difference between: You: Can you give me the email address of user 50? Librarian: Sure, here you go Librarian: Oh balls, I wasn't supposed to hand that over, that could have been anyone! And You: Can you give me the email address of user 50? Librarian: Sure, here you go You: Hmm You-irc: Hey guise! The librarian is giving out everyones email a…

This is the issue I have with all of this. Everybody is defending HOW he did what he did with no thought as to WHAT he actually did - as if it shouldn't matter. He knew what he was doing was illegal and didn't care, he got caught and tried to justify his actions by blaming AT&T for having a faulty configured server. Not good enough for me and the jury agreed.

How he did it absolutely does matter. He did not know what he was doing was illegal because that is the expected interaction with an HTTP server. He certainly knew it was immoral but we give Wall Street a pass on that.

Suppose I write a scraper with user agent "I am a teapot" and I discover AT&T emits personal data when I access with that user agent. What is the arbitrary cutoff for number of things downloaded before I am a criminal?

There are in fact actual criminal charges that can be brought for identity theft, we don't need the US courts to be more aggressive with the CFAA by considering thoughtcrime in their deliberations.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#169
post #35

Everyone throws out analogies about walking into unlocked houses and such. Those are fairly poor analogies, so let me offer one which I think is far better at conveying what really happens. Imagine you walked into a public library and struck up a conversation with the librarian: You: Can you tell me general information about this library? Librarian: Certainly, this library was built in 1990, has a million books on it…

What happens in the scenario where the librarian is instead a low IQ worker helping out? You: Can I have this book? Worker: No, sorry, not allowed. You: It's ok, the boss said so. Worker: I don't think so. You: We're friends, right? You don't say no to your friends, do you? Worker: Well, ok, I guess you can have it. Hey, the worker said it was ok, I guess you were authorized after all!

Sounds like you were authorized; if that happened and you read the book what crime would you be charged with? Seriously. Taking advantage of a worker with intent to learn secrets? Totally immoral, not illegal.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#170

Earlier quoted context omitted.

Not so, because as others in this thread have stated, the key is intent.

And we peer into the mind of a third party how?

There's a fairly large body of law that hinges on the intent of the individual.

http://en.wikipedia.org/wiki/Intention_(criminal_law)

Post reply on HN