Live data from Hacker News

How Weev's prosecutors are making up the rules

blog.erratasec.com

31–40 of 97 posts

Re: How Weev's prosecutors are making up the rules

#31
post #19

Earlier quoted context omitted.

So? It is still illegal to commit fraud, use stolen identities to purchase goods, and arguably still illegal to attack a database.

Committing fraud: illegal. Using stolen identities to purchase goods: illegal. Attacking a database: not illegal without CFAA.

Attacking a database: not illegal without CFAA.

That's a big problem since we can't really even define clearly (and rationally) what an attack is.

Re: How Weev's prosecutors are making up the rules

#32
post #18

Earlier quoted context omitted.

I have trouble agreeing with this. I know nothing of the law around this, but also realise given the international nature of the internet, the law probably doesn't mean much in perspective. Would Aurenheimer be prosecuted if he were Chinese? The grandparent making the point about status 200 has a point, especially in regards to this case. If a website is returning 200s for a get request. Then you are implicitly 'auth…

In northern Maine, everyone I know keeps their house doors unlocked and their keys sitting in the ignition of their cars. However, it's still illegal to steal their cars and enter their houses. There doesn't even need to be a metaphor here: the data physically existed on a private server, and weev was not authorized to access it.

GET google.com

What's returned is data physically on a private server. I am not authorized to access that server.

But the internet would be a pretty crap place if that was against the law.

As I said, metaphors to locked/unlocked public/private don't make sense. But happy for you to keep stretching this analogy until it fits.

Re: How Weev's prosecutors are making up the rules

#33
post #29

But while they can edit the URL, most people don't. For that reason, prosecutors insists that it's illegal. On page 32, they describe a hypothetical "judicial law clerk" who is a "reasonably sophisticated computer user". They point out that this clerk would search in vain for hyperlinks, and thus, not be able to access the information since such hyperlinks don't exist. This is a clever trick of the prosecutors. It ex…

Do you think Rayiner is representative of law clerks in general?

Exactly, he isn't[1], thank goodness (nothing personal rayiner, but I disagree with quite a lot of your opinions).

[1] There is no question about his competence with computers.

Re: How Weev's prosecutors are making up the rules

#34
post #25
post #19

Earlier quoted context omitted.

Committing fraud: illegal. Using stolen identities to purchase goods: illegal. Attacking a database: not illegal without CFAA.

"Attacking" - are databases people? Do they have rights? I'm stumbling around trying to figure out what the right balance is too, but I think the existing laws we have around fraud and privacy are all that we need. That is, we don't need to criminalize accessing inadvertently public information; we just need to criminalize exploiting it.

Exploiting it is criminalized. Exploiting it is harder to detect and enforce. It is easy to read server logs and parse them for crimes. Lazy man's way to enforce the law.

Re: How Weev's prosecutors are making up the rules

#35
post #18

Earlier quoted context omitted.

I have trouble agreeing with this. I know nothing of the law around this, but also realise given the international nature of the internet, the law probably doesn't mean much in perspective. Would Aurenheimer be prosecuted if he were Chinese? The grandparent making the point about status 200 has a point, especially in regards to this case. If a website is returning 200s for a get request. Then you are implicitly 'auth…

In northern Maine, everyone I know keeps their house doors unlocked and their keys sitting in the ignition of their cars. However, it's still illegal to steal their cars and enter their houses. There doesn't even need to be a metaphor here: the data physically existed on a private server, and weev was not authorized to access it.

When you put data on a private server accessible via GET with no access control or firewall, it is published on the web to the public.

Comparing it to houses that have doors, locked or otherwise, is exceptionally disingenious.

Re: How Weev's prosecutors are making up the rules

#36
post #2

One of our many lawyers can relate to us how meaningful the complaint about the word count in the prosecution's brief is. Maybe it's a big deal; I have absolutely no clue about that point. But the central argument to me in this piece is that the DOJ is simply criminalizing URL editing. That is to me a gross oversimplification of what's happened. The CFAA is constructed not to criminalize accidental or reckless unauth…

There are plenty of sane arguments, sure. Weev is clearly scum; It's possible that he was doing this entirely maliciously. That's not the argument that the prosecutors are making, though, nor have they established any of his actions were illegal beyond reasonable doubt.

None of the arguments I think about have anything to do with who Weev is. I am almost solely concerned with precedent.

Re: How Weev's prosecutors are making up the rules

#37
post #19

Earlier quoted context omitted.

So? It is still illegal to commit fraud, use stolen identities to purchase goods, and arguably still illegal to attack a database.

Committing fraud: illegal. Using stolen identities to purchase goods: illegal. Attacking a database: not illegal without CFAA.

Why do we need the third? Why make downloading PII a crime when we already have felony laws for using such data to commit fraud?

Re: How Weev's prosecutors are making up the rules

#38
post #29

But while they can edit the URL, most people don't. For that reason, prosecutors insists that it's illegal. On page 32, they describe a hypothetical "judicial law clerk" who is a "reasonably sophisticated computer user". They point out that this clerk would search in vain for hyperlinks, and thus, not be able to access the information since such hyperlinks don't exist. This is a clever trick of the prosecutors. It ex…

Do you think Rayiner is representative of law clerks in general?

No, but nor do I think much of the author's snide dismissal of law clerks as 'people who use Facebook a lot,' (and who, by implication, are incapable of parsing the defense team's arguments). This is a popular trope on HN, but not a very well-founded one. There is intense competition for clerking assignments, which means they go mostly to the cream of the academic crop, and good law students and lawyers are the kind of people who are able to accurately assess their own level of knoweldge on a particular subject and rectify it through research, because their professional reputation depends on the ability to do so.

Frankly, I would trust a law clerk who knew nothing about computers to understand the subject better after study than I would a programmer who knew nothing about law.

Re: How Weev's prosecutors are making up the rules

#39
I'm still kind of boggled that they were unable to get Weev on criminal harassment. Or anything else, for that matter, given that IIRC he had no employment of record but was independently wealthy and bragged about doing computer crime for cash. He absolutely belongs in prison; just not, perhaps, for this specific charge.

Re: How Weev's prosecutors are making up the rules

#40
post #15
post #13

I love how it's illegal to adjust part of URL but perfectly legal to wiretap, decrypt personal communications and spy on billions of people.

Similarly: if I shoot you, it's murder. But if a cop shoots you...

Nope. Depending on the locality, the situations where a cop is allowed to shoot you and I'm allowed to shoot you are similar, having something to do with the perception of an immediate threat.
Post reply on HN