Live data from Hacker News

This hacker might seem shady, but throwing him in jail is bad for everyone

washingtonpost.com

191–200 of 213 posts

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#191

Earlier quoted context omitted.

>For the same reason that it's OK for me to push in my door, but not to push in yours. Or why it's OK for me to type in my password, but not to type in your password. Okay, I'm confused by your analogy. I was thinking of the situation as having a single door at the entrance to the establishment. I don't think it makes any sense at all to treat each page as a separate household on private property. And I meant explici…

Er right, the analogy is bit confusing for me too; let me see if I can clear up what I meant here. > I don't think it makes any sense at all to treat each page as a separate household on private property. It's certainly true that some pages on a site might be private to someone else and others not. The page/site distinction is orthogonal to the authorized/unauthorized distinction. It's not clear to me why, in your st…

I'm talking about intentional design here. It is on purpose that the system has no authentication. It is on purpose that the system returns records solely in response to an ID request from any client. It is not on purpose that the system can be SQL injected.

Intention of use is entirely different. The high level intention of use / purpose is often opaque and contradictory. Using it as a threshold would be foolish. "it securely stores passwords but also mails you a reminder if you forget" "it sends marketing mails that don't get marked as spam" "it shows people images that they can't save" "people will stay signed up for 15 months and we will profit on the loss leader"

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#192
post #183

Earlier quoted context omitted.

If knowing that you are doing something immoral makes it a crime why isn't all of Wall Street in prison?

1) Generally they do things that are harder to prove illegal, harder to show were doing something they knew was wrong and don't send messages in IRC channels 'joking' about shorting stock when releasing bad news. In essence, they are smarter about it. 2) Some are. 3) Not everyone involved in investment is doing something immoral.

I know the US has decided to start prosecuting thoughtcrimes, such as jokes on FB, but that's actually unconstitutional. Accessing a server is not a crime, the user agent is not meant for authorization, and what he did was immoral, not illegal. The only difference between what weev and Aaron Swartz did is the type of content downloaded and the quality of the person downloading.

You're arguing to put this douchebag in prison, but not for an actual crime. Remember that the next time they use the CFAA to crucify someone who doesn't deserve it.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#193

Earlier quoted context omitted.

Ah wonderful, so now I have to worry about how my intentions might be perceived by the government when visiting a publicly accessible web page. But the company leaking consumer information to the public without any proper security at all is not punished.

Yes. If you accidentally stumble upon something you shouldn't and don't exploit it or sell it to someone when you know you clearly shouldn't be you will be fine. It is pretty straightforward. Everyone here keeps purposefully ignoring intent , but in the context of the law this is impossible. So no matter how much you hate it, this isn't something that can be a binary yes/no illegal/legal question based on some comput…

He didn't exploit it or sell it and he's fucked. We're ignoring intent because a crime has yet to be committed. Intent doesn't matter without a crime. If intent is the only dividing line, you are in favor of thoughtcrime.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#194
post #113

Earlier quoted context omitted.

No, Weev did not "exploit" anything. He _requested_ information from a server. If the server owner had so desired, they could have made the data private by adding a password. They chose not to. In the end, the decision to offer Weev the data was made _by the server_ . And if you're going to bring up the UserAgent spoofing, let me remind you that most browsers have done something like that for > 15 years.

dude what part of he gave the info away to a third party before reporting it do you not understand to put ur bullshit out there >

Apparently in the future they've all learned to write from browsing MySpace profiles.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#195
post #68

Earlier quoted context omitted.

What really is the line between tricked and asked? Deceit? Lets go with deceit. So is asking for book ISBN '1; DROP TABLE books; --' deceitful? Perhaps, that's not an ISBN after all. Is asking for book ISBN [some valid ISBN that you pulled out of your ass, but happens to exist] deceitful? I don't think so. If you are just asking for randomly chosen ISBNs and getting responses, I don't think there is any trickery invo…

I'd like to fix up the analogy a bit. The problem isn't that you're asking for a random ISBN numbers; it's that you don't have a library card. The library's electronic catalog won't let you log in without the card, so you just start asking the librarian for random ISBNs and accepting the books he gives you. He doesn't check on your card because no one trained him to do that, but you know that checking out books is me…

Sane people would point out that whoever trained that librarian was an idiot.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#196
post #134
post #87

Earlier quoted context omitted.

If we want to stretch analogies beyond sense, how about this. You walk into a cake shop that has cupcakes with names written on the icing: You say "Can I have a cupcake with 'Iain' written on it?" They say "200 OK, here's a cupcake with Iain on it." You say "Can I have that wedding cake?" They say "401 Unauthorized, Sorry that's someone elses' cake." You don't get a wedding cake. You say "Can I have a cupcake with 'A…

> Did you do anything wrong? Possibly, it depends on intent. Add in: You: Hahaha, guys I can get anybodies cake! You: Looool their security is awful! You: Hahah, we could short this companies stock! Then you clearly knew what you were doing and therefore did something wrong.

But an equally valid interpretation of what's going on is:

Cool, free cupcakes! They want you to pay for birthday cakes and pre-order wedding cakes, but they'll give you any cupcake you ask for if they've got one available!

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#197

Earlier quoted context omitted.

Yes. If you accidentally stumble upon something you shouldn't and don't exploit it or sell it to someone when you know you clearly shouldn't be you will be fine. It is pretty straightforward. Everyone here keeps purposefully ignoring intent , but in the context of the law this is impossible. So no matter how much you hate it, this isn't something that can be a binary yes/no illegal/legal question based on some comput…

He didn't exploit it or sell it and he's fucked. We're ignoring intent because a crime has yet to be committed. Intent doesn't matter without a crime. If intent is the only dividing line, you are in favor of thoughtcrime.

Well...his crime actually was that he intentionally accessed data he knew he should not have been accessing. That is a crime. Thus he was found guilty. I'm not sure why this is so hard to reconcile or is being purposefully ignored just because this crime is one of many that involves a computer.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#198
post #134

Earlier quoted context omitted.

> Did you do anything wrong? Possibly, it depends on intent. Add in: You: Hahaha, guys I can get anybodies cake! You: Looool their security is awful! You: Hahah, we could short this companies stock! Then you clearly knew what you were doing and therefore did something wrong.

But an equally valid interpretation of what's going on is: Cool, free cupcakes! They want you to pay for birthday cakes and pre-order wedding cakes, but they'll give you any cupcake you ask for if they've got one available!

Do the IRC transcripts sound like he thought that this information should have been shared by the server? Your interpretation would have weev thinking that AT&T intended to make this information public, that having it public was fine, and there was no complexity in what he did to get it.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#199
post #198

Earlier quoted context omitted.

But an equally valid interpretation of what's going on is: Cool, free cupcakes! They want you to pay for birthday cakes and pre-order wedding cakes, but they'll give you any cupcake you ask for if they've got one available!

Do the IRC transcripts sound like he thought that this information should have been shared by the server? Your interpretation would have weev thinking that AT&T intended to make this information public, that having it public was fine, and there was no complexity in what he did to get it.

You're right - weev was being a dick, and he knew he ws at the time.

BUT…

I personally think AT&T should also be held to account for their part in what happened. They put all that data up on the public internet, with no authentication required to get it. I think they're at least as culpable here as weev is. (and I don't think _either_ of them should get off scott free - they both played fast and loose with other people's data.)

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#200

Earlier quoted context omitted.

> Then, it seems, a good solution to solve the problem is to have server owner to declare in advance what are intended use and what's not. You mean like the Terms of Use for the AT&T website? http://www.att.com/gen/general?pid=11561#14

Sort of, but in machine-readable form and under well-known location (like /robots.txt) so you could read and comply with them before you access the site. As for those exact terms, I suspect (IANAL) those exact terms prohibit almost any access to the site, as, for example, they forbid any programmatic access to obtain the information, and I haven't heard of any non-software user-agent implementations.

You can translate "programmatic" as "automated" as in "someone coded a program/tool to, in a programmatic way, access the website and retrieve the data"

As opposed to a human being in a non-programmatic way, opening his browser and accessing the website.

What's so hard about it?

Post reply on HN