Live data from Hacker News

How Weev's prosecutors are making up the rules

blog.erratasec.com

21–30 of 97 posts

Re: How Weev's prosecutors are making up the rules

#21
post #2

One of our many lawyers can relate to us how meaningful the complaint about the word count in the prosecution's brief is. Maybe it's a big deal; I have absolutely no clue about that point. But the central argument to me in this piece is that the DOJ is simply criminalizing URL editing. That is to me a gross oversimplification of what's happened. The CFAA is constructed not to criminalize accidental or reckless unauth…

Add to that the multiple perverse incentives in every direction. Folks are discouraged to be curious, regardless of their intentions for harm. Meanwhile, the penalties for creating a system that fails to protect the most valuable details of customers is punished very lightly, if at all. Companies are only, in theory, obligated to disclose breaches that could reveal customer data if they learn of them. The easiest route for a company to take, is to take a lackadaisical approach to security and expend the bare minimum of effort on audits, with the hope that any breaches will be sophisticated enough to be imperceptible by them. We've seen this approach played out in the real world with lots of companies.

We should be thankful that braggarts and clowns like anonymous et al exist because they bring to light many breaches and weak security systems that would have been kept secret otherwise.

Re: How Weev's prosecutors are making up the rules

#22
post #13

I love how it's illegal to adjust part of URL but perfectly legal to wiretap, decrypt personal communications and spy on billions of people.

This seems like one of those things people say to score points, rather than to actually engage in the process of using their brains.

There are a myriad of things that are legal for the government to do that are illegal for a common citizen. There's no irony in that.

Re: How Weev's prosecutors are making up the rules

#23
post #6
post #3

they returned the http code 200. that means good to go. there is another code for access forbidden.

Congratulations, you just immunized probably 1/3rd of all the SQL injection exploiters on the Internet.

I think there is a clear distinction that you can make between an SQL injection attack and the unsecured API that weev accessed. SQL injection attacks depend on inserting malicious code into an application in order to traverse that application and access systems that stand behind it. The point of SQL injection is to circumvent restricted permissions that the owner of the server has attempted to impose.

What weev did was quite different in that he accessed this web service in exactly the way it was intended. Even if he was not the intended consumer of this data, his attempted access never exceeded the defined and expected parameters of the API he was accessing. Furthermore, he didn't circumvent [1] any access restrictions; rather, access restrictions were never imposed. weev had no information available to himself as to AT&T's intent to disclose or not disclose customer emails; as far as he was concerned, the existence of this API could have been a purposeful and not simply negligent disclosure on the part of AT&T.

I think that the reason that the weev case rankles is that web developers do this kind of thing all the time. What is the difference between what weev did here and Padmapper did when it built a product on top of Craigslist's data? Despite Eric DeMenthon's protests to the contrary, a strong argument to could be made that Padmapper's intent was to cause severe commercial harm to Craigslist, which is conceivably why he got sued. In spite of the civil case, however, criminal charges are almost unthinkable.

Also, how often do we read about someone's project being hampered when a private Google API is turned off? [2] Anyone that builds a commercial product on top of something like this would be deemed a fool, but I've never seen anyone accuse a developer who is using this kind of API of acting criminally.

What is the difference, under the law, between someone accessing a private Google API and the private AT&T API that weev accessed? As a web developer with zero documentation, zero information beyond simply knowledge of the API URL's existence, there is no apparent difference beyond what content was being served by these APIs. So, if that is the case, at what point should web developers accessing undocumented APIs begin to be concerned about their criminal liability?

[1] Shouldn't it be circumvention not authorization that that defines criminal access under the law?

[2] Just the easiest-to-find example: https://news.ycombinator.com/item?id=4441677

Re: How Weev's prosecutors are making up the rules

#24
post #17

Earlier quoted context omitted.

Certainly the conclusion can't be that the legality of your actions depends on the reaction of an automated system at the other end of a pipe that you don't control? I have no problem with basing it off intent, but the focus should be on prosecuting whoever put that data out there in the first place with gross negligence.

The legality of your actions depends on whether you know, as you interact with the automated system, that you have managed to find a path to data that you should not have had access to. So, if by incrementing ICC-IDs, you found random technical data about AT&T provisioning, it would be very hard to argue that you were knowingly accessing it without authorization. But when the information you find is so personal that…

Putting the burden on a user to "know" whether they are authorized or not, seems crazy. Even if they talked about selling to spammers.

Hypothetically the police give me a Police report number that I can access at police.gov/crimes/:reportno I discover if I increment/decrement these I can get ALL reports. I then build a cool mashup of crimes in the area on a google map. It turns out the police didn't intend that, am I now a criminal (because of the polices intent)?

Re: How Weev's prosecutors are making up the rules

#25
post #19

Earlier quoted context omitted.

So? It is still illegal to commit fraud, use stolen identities to purchase goods, and arguably still illegal to attack a database.

Committing fraud: illegal. Using stolen identities to purchase goods: illegal. Attacking a database: not illegal without CFAA.

"Attacking" - are databases people? Do they have rights?

I'm stumbling around trying to figure out what the right balance is too, but I think the existing laws we have around fraud and privacy are all that we need. That is, we don't need to criminalize accessing inadvertently public information; we just need to criminalize exploiting it.

Re: How Weev's prosecutors are making up the rules

#26
post #20
post #18

Earlier quoted context omitted.

I have trouble agreeing with this. I know nothing of the law around this, but also realise given the international nature of the internet, the law probably doesn't mean much in perspective. Would Aurenheimer be prosecuted if he were Chinese? The grandparent making the point about status 200 has a point, especially in regards to this case. If a website is returning 200s for a get request. Then you are implicitly 'auth…

No, he would not have been prosecuted if he were Chinese. The point about "200" error codes is sophistry. We all know that every 200 code is not actually a deliberate authorization. If you believe otherwise, then any SQL injection attack that uses GETs and generates 200 must be authorized.

SQL injection wasn't used here. The URL scheme being used was used exactly as intended (by developers).

Seems the sophistry here is applying another clear cut version of hacking to say that this 'not clear cut at all' version is also wrong.

Re: How Weev's prosecutors are making up the rules

#27
post #18
post #10

Earlier quoted context omitted.

I agree. I think the case against Aurenheimer is ridiculous and the sentence a travesty. But I don't think it's reasonable to take that conclusion and work it back to "anything you can do with a URL that doesn't say user/password is fair game".

I have trouble agreeing with this. I know nothing of the law around this, but also realise given the international nature of the internet, the law probably doesn't mean much in perspective. Would Aurenheimer be prosecuted if he were Chinese? The grandparent making the point about status 200 has a point, especially in regards to this case. If a website is returning 200s for a get request. Then you are implicitly 'auth…

In northern Maine, everyone I know keeps their house doors unlocked and their keys sitting in the ignition of their cars. However, it's still illegal to steal their cars and enter their houses.

There doesn't even need to be a metaphor here: the data physically existed on a private server, and weev was not authorized to access it.

Re: How Weev's prosecutors are making up the rules

#28
post #13

I love how it's illegal to adjust part of URL but perfectly legal to wiretap, decrypt personal communications and spy on billions of people.

This seems like one of those things people say to score points, rather than to actually engage in the process of using their brains. There are a myriad of things that are legal for the government to do that are illegal for a common citizen. There's no irony in that.

It doesn't require a wall of text to point out the sheer lunacy of the prosecution. Sometimes a simple analogy is sufficient.

Weev didn't hack anything. He committed data theft and possibly attempted extortion. Those should be the the basis of his trial.

Also, just to be clear, those things are actually quite illegal for the government to do both on a national and international scale.

Re: How Weev's prosecutors are making up the rules

#29

But while they can edit the URL, most people don't. For that reason, prosecutors insists that it's illegal. On page 32, they describe a hypothetical "judicial law clerk" who is a "reasonably sophisticated computer user". They point out that this clerk would search in vain for hyperlinks, and thus, not be able to access the information since such hyperlinks don't exist. This is a clever trick of the prosecutors. It ex…

Do you think Rayiner is representative of law clerks in general?

Re: How Weev's prosecutors are making up the rules

#30
post #2

One of our many lawyers can relate to us how meaningful the complaint about the word count in the prosecution's brief is. Maybe it's a big deal; I have absolutely no clue about that point. But the central argument to me in this piece is that the DOJ is simply criminalizing URL editing. That is to me a gross oversimplification of what's happened. The CFAA is constructed not to criminalize accidental or reckless unauth…

There are plenty of sane arguments, sure. Weev is clearly scum; It's possible that he was doing this entirely maliciously. That's not the argument that the prosecutors are making, though, nor have they established any of his actions were illegal beyond reasonable doubt.
Post reply on HN