Live data from Hacker News

How Weev's prosecutors are making up the rules

blog.erratasec.com

41–50 of 97 posts

Re: How Weev's prosecutors are making up the rules

#41
post #2

One of our many lawyers can relate to us how meaningful the complaint about the word count in the prosecution's brief is. Maybe it's a big deal; I have absolutely no clue about that point. But the central argument to me in this piece is that the DOJ is simply criminalizing URL editing. That is to me a gross oversimplification of what's happened. The CFAA is constructed not to criminalize accidental or reckless unauth…

My view, having read most of the prosecution's statement, as well has having chatted with weev about this, is that the system was open to the public.

Here's why. The prosecution details the steps Spitler took: downloading the iPad image, decrypting it, finding the url the system used (I'm guessing by running strings), and then spoofing an iPad browser request via the user agent string, and providing the userid to obtain an email address.

IANAL, but it seems that they are maybe trying to make the case that the user agent string was equivocal to a password, or that decrypting the image was the point of exceeding access. If decrypting the image was the issue, then I imagine this would be placed with all the other similar cases (DeCSS, etc), but it wouldn't constitute identity fraud. If the user agent string is seen as the password, then that is the weakest security system I've ever seen.

I haven't actually kept up with how AT&T apparently fixed it, but it seems that a rational response to this would be to make users authenticate with their own password BEFORE it spits out information like an email address. If you don someone's userid but have no password (or session id token, etc), I'd suggest that's impersonation, but not identity theft or fraud. If we're going to criminalize impersonation, I guess the Saturday Night Live cast needs to find a new career.

That said, I totally understand why weev contacted reporters and not AT&T. We're in an age where contacting large corporations about security fixes typically results in a gag order on the security researcher and no fix (hi Cisco). By contacting a reporter, he increased the chance that the story would get out and AT&T would fix the issue.

Finally, a lot of people have suggested that weev "deserved" to go to jail for other things he's done. I'm not denying he's a troll, and he has done some over the top things. However, it's not illegal to be a troll, and while one might say he should be in jail for other things he has done, he is currently in jail for this. IMHO, the punishment not only outweighs the crime, but in conjunction with the other abuses of CFAA prosecution we've seen lately (such as Aaron Swartz), I think it's time we stop allowing the government to use poster children like weev as punching bags for obvious career boosting agendas.

Re: How Weev's prosecutors are making up the rules

#42
I'm wondering why he even appealed this. Seemed pretty straight forward what he did. What exactly is he appealing on? He was only sentenced to 3 years. He'd be out in less than 2 if he stays out of trouble. For a hacker, I'd say he got off pretty light considering what others have gotten.

Re: How Weev's prosecutors are making up the rules

#43
post #37
post #19

Earlier quoted context omitted.

Committing fraud: illegal. Using stolen identities to purchase goods: illegal. Attacking a database: not illegal without CFAA.

Why do we need the third? Why make downloading PII a crime when we already have felony laws for using such data to commit fraud?

There are many things one can do with your PII besides using it for identity theft, including publishing it, which is NOT illegal in many states.

Re: How Weev's prosecutors are making up the rules

#44
post #2

One of our many lawyers can relate to us how meaningful the complaint about the word count in the prosecution's brief is. Maybe it's a big deal; I have absolutely no clue about that point. But the central argument to me in this piece is that the DOJ is simply criminalizing URL editing. That is to me a gross oversimplification of what's happened. The CFAA is constructed not to criminalize accidental or reckless unauth…

My view, having read most of the prosecution's statement, as well has having chatted with weev about this, is that the system was open to the public. Here's why. The prosecution details the steps Spitler took: downloading the iPad image, decrypting it, finding the url the system used (I'm guessing by running strings), and then spoofing an iPad browser request via the user agent string, and providing the userid to obt…

A security system's weakness does not grant permission to break it. That gets said every time we have this conversation, but I guess it needs to be said again.

Re: How Weev's prosecutors are making up the rules

#45

Earlier quoted context omitted.

My view, having read most of the prosecution's statement, as well has having chatted with weev about this, is that the system was open to the public. Here's why. The prosecution details the steps Spitler took: downloading the iPad image, decrypting it, finding the url the system used (I'm guessing by running strings), and then spoofing an iPad browser request via the user agent string, and providing the userid to obt…

A security system's weakness does not grant permission to break it. That gets said every time we have this conversation, but I guess it needs to be said again.

When does accessing a system turn into breaking a security system? Let's say I am trying to access an Internet Explorer only website with Firefox, and it gives me an error. I change my user agent, and it lets me in. Did I just commit a crime?

Re: How Weev's prosecutors are making up the rules

#46

Earlier quoted context omitted.

A security system's weakness does not grant permission to break it. That gets said every time we have this conversation, but I guess it needs to be said again.

When does accessing a system turn into breaking a security system? Let's say I am trying to access an Internet Explorer only website with Firefox, and it gives me an error. I change my user agent, and it lets me in. Did I just commit a crime?

According to the law, and what seems like common sense to me, when you know or should have known that you were accessing something you weren't meant to.

Re: How Weev's prosecutors are making up the rules

#47

Earlier quoted context omitted.

When does accessing a system turn into breaking a security system? Let's say I am trying to access an Internet Explorer only website with Firefox, and it gives me an error. I change my user agent, and it lets me in. Did I just commit a crime?

According to the law, and what seems like common sense to me, when you know or should have known that you were accessing something you weren't meant to.

And who gets to define when you're "meant" to? The law we're talking about was written in 1986, before the web even existed. Haven't we already had this conversation with regards to Google (the debacle over the robots file) and other systems?

Finally, even if it is concluded that weev committed a crime, something with which I disagree, would you say it's ok to punish it by nearly 4 years in prison, denial to medical care, and solitary confinement for using email? All of those things have happened after he was indicted.

Re: How Weev's prosecutors are making up the rules

#48

Earlier quoted context omitted.

According to the law, and what seems like common sense to me, when you know or should have known that you were accessing something you weren't meant to.

And who gets to define when you're "meant" to? The law we're talking about was written in 1986, before the web even existed. Haven't we already had this conversation with regards to Google (the debacle over the robots file) and other systems? Finally, even if it is concluded that weev committed a crime, something with which I disagree, would you say it's ok to punish it by nearly 4 years in prison, denial to medical…

Same people who decide every other time the law calls for consideration of intent and mental state of defendants (which is a lot) -- the judge and jury.

Re: How Weev's prosecutors are making up the rules

#49
post #29

Earlier quoted context omitted.

Do you think Rayiner is representative of law clerks in general?

No, but nor do I think much of the author's snide dismissal of law clerks as 'people who use Facebook a lot,' (and who, by implication, are incapable of parsing the defense team's arguments). This is a popular trope on HN, but not a very well-founded one. There is intense competition for clerking assignments, which means they go mostly to the cream of the academic crop, and good law students and lawyers are the kind…

I agree with your opinion of law clerks as generally competent people, which probably extends somewhat to technology with the younger set.

That said, I know a lot of young, competent engineers and scientists who know next to nothing about the workings of computers and networks. They could figure out a lot if they had the time to put into it (I've seen a couple switch into development successfully), but usually they don't and their knowledge is of the surface-level stuff. That could still help with gut checks about what's reasonable behavior online for a casual user, but it's far from the nuanced understanding necessary to understand the ramifications of and make calls about things like the various applications of the CFAA in cases involving more advanced users.

Most people are not curious about technology and generally don't have a good understanding other people's curiosity about the subject. Should they be the ones to judge whether someone was just playing around or trying to attack something? Or should it be people with that curiosity who have had experience in playing around with security?

I would say that programmers' interpretation of the law via intent and current context in tech cases is frequently more consistent with what a just society needs than most judges' attempts at maintaining consistency with past rulings until a higher circuit corrects the precedent. I wouldn't dismiss the whole class as overenthusiastic amateurs.

I may just not be seeing the value in the judges' attempts at finding consistency, though, and I'm curious as to why they strive so hard for it versus trying to find the correct interpretation. My understanding is that that's just an attribute of the common law system. If someone could tell me why that's valuable (perhaps for consistency of enforcement/predictability of outcomes?), that'd be great. Sorry for the tangent, but it's something I'm curious about.

Re: How Weev's prosecutors are making up the rules

#50
post #10
post #9

Earlier quoted context omitted.

Point taken, intent does matter. But there is a large difference between taking the information you used to the black market and taking it to a media organization. e.g. Homakov's hack of github didn't deserve jail time as it was for publicity, not malevolance.

I agree. I think the case against Aurenheimer is ridiculous and the sentence a travesty. But I don't think it's reasonable to take that conclusion and work it back to "anything you can do with a URL that doesn't say user/password is fair game".

I think that is reasonable because that's the defined and expected interaction between HTTP clients and servers.
Post reply on HN