Live data from Hacker News

Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

technologyreview.com

21–30 of 117 posts

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#22
post #8

Earlier quoted context omitted.

>> required visiting an AT&T web address with a particular – and easy to guess – code tagged onto the end. How is this different than a password?

I guess this is exactly the thing that the court must decide on: whether guessing that code can be considered as a circumvention of security measures or not.

Following that logic breeds bizarre results.

What if you find this magic token because it was embedded in some client-side, javascript login-form? Are you a hacker for viewing the source?

Securing content on the internet is easy. If you don't want it accessible to anyone, don't give the content to anyone who provides an unauthenticated HTTP request.

Why are we putting the legal responsibility of maintaining security on that content on everyone except the ones actually in position to do so?

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#23
He should totally have posted those on pastebin instead and shared on the net.

I think that if one finds an embarrassing security vulnerability, they should look up the offending company and upon finding that company ever took part in the crap like described in the article, they should publish the vulnerability wide open, goatse-style, anonymously via pastebin.

Those companies should suffer to the end of times and their clients should too.

Unless that company properly apologized, which they never do. Corporations don't seem to be capable of that. Not in their DNA.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#24
post #9

We live in a tech-filled world without a reliable means for responsible disclosure, no way to hold a company accountable for reacting to attempts of responsible disclosure, and any whistle-blowers are immediately branded as "criminals" and "hackers". This whole process, or lack thereof, needs some serious disruption. Edit: My comment is intended to be a general observation and not specifically about this case

Disruption by who? Other sovereign entities?

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#25
post #8

Earlier quoted context omitted.

I guess this is exactly the thing that the court must decide on: whether guessing that code can be considered as a circumvention of security measures or not.

Following that logic breeds bizarre results. What if you find this magic token because it was embedded in some client-side, javascript login-form? Are you a hacker for viewing the source? Securing content on the internet is easy. If you don't want it accessible to anyone, don't give the content to anyone who provides an unauthenticated HTTP request. Why are we putting the legal responsibility of maintaining security…

If I look under your doormat, and there is a key, and I use it to open your front door...

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#27

He should totally have posted those on pastebin instead and shared on the net. I think that if one finds an embarrassing security vulnerability, they should look up the offending company and upon finding that company ever took part in the crap like described in the article, they should publish the vulnerability wide open, goatse-style, anonymously via pastebin. Those companies should suffer to the end of times and th…

Why should I, as an innocent party to a companies security failings have my personal details revealed. This is exactly why we have laws protecting identity theft and fraud.

Naming and shaming the company and the extent of their security failing is enough. But only after they have patched the hole.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#28

He should totally have posted those on pastebin instead and shared on the net. I think that if one finds an embarrassing security vulnerability, they should look up the offending company and upon finding that company ever took part in the crap like described in the article, they should publish the vulnerability wide open, goatse-style, anonymously via pastebin. Those companies should suffer to the end of times and th…

Why should I, as an innocent party to a companies security failings have my personal details revealed. This is exactly why we have laws protecting identity theft and fraud. Naming and shaming the company and the extent of their security failing is enough. But only after they have patched the hole.

[deleted]

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#29

He should totally have posted those on pastebin instead and shared on the net. I think that if one finds an embarrassing security vulnerability, they should look up the offending company and upon finding that company ever took part in the crap like described in the article, they should publish the vulnerability wide open, goatse-style, anonymously via pastebin. Those companies should suffer to the end of times and th…

Why should I, as an innocent party to a companies security failings have my personal details revealed. This is exactly why we have laws protecting identity theft and fraud. Naming and shaming the company and the extent of their security failing is enough. But only after they have patched the hole.

"Why should I, as an innocent party to a companies security failings have my personal details revealed."

Because life is pain?

But of course you can always sue the company that leaked your data and then mistreated people who warned them. Hell, you should. Probably with a class action suit.

Re: Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails

#30
post #4

Earlier quoted context omitted.

> From a technical point of view the very nature of HTTP includes asking for permission. A web server isn't an agent of the company and has no capacity to grant or deny permission. Think of it as a security system you install in your home. Now, if the security system is malfunctioning and you notice that it is malfunctioning ... do you call up the owner and let them know or do you go inside and look through their stu…

As an information security professional, I see two different issues at play here. First, they got access. They were granted access by the admin who did not lock down the server. I am not a lawyer, but I see the unauthenticated web server, no matter how much of a mistake, as being implicit permission to access the site. A house, by default, implies privacy. A web server is more of a business in this metaphor. If the d…

You don't live in a world governed by machines and pure logic. You live in a world governed by human beings and their nature.

You have the capacity to recognize where you should be and where you shouldn't be. What you should be seeing and what you shouldn't be seeing.

Right from wrong.

> A web server is more of a business in this metaphor. If the door is open and the lights are on, it's implied you can come in and look around.

No.

If you're inside a business and you see a door open and it is evident by the design of the building that it is their storage space ... you do not have the right to waltz on in. You damn well know through your experience in hundreds of other stores that this area is used by employees and for employees only. You do not belong there.

Are you telling me he read those emails by accident? Just stumbled on them? Or did he know exactly what he was doing?

Enough of this white hat bullshit. I do not have the right to self-deputize myself and become a vigilante on the Internet. If these clowns don't know how to secure their own damn servers, let them pay the price that will be exacted by less scrupulous individuals. That's how the free market works. Stupidity is severely punished. They will very quickly learn how to properly set permissions on their server.

Post reply on HN