Live data from Hacker News

Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking

motherboard.vice.com

51–60 of 67 posts

Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking

#51
post #50

Earlier quoted context omitted.

Picking the locks is breaking and entering, going through an open window is illegal trespass, assuming you don't have to move any parts of the window. At least where I live. It depends on whether or not you have to use even the slightest amount of force to gain access. It also depends on your intent to commit a crime inside. If I'm looking for you because I've found your toddler wandering around outside and I open an…

No, I don't think this is at all correct. Going through a window is breaking and entering.

Well, I didn't know, so I looked it up before posting. https://en.wikipedia.org/wiki/Burglary

> Although rarely listed as an element, the common law required that "entry occur as a consequence of the breaking".[7] For example, if a wrongdoer partially opens a window with a pry bar—but then notices an open door, which he uses to enter the dwelling, there is no burglary under common law.

There are more results if you search for "breaking and entering", it was all pretty consistent.

Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking

#52
post #50

Earlier quoted context omitted.

No, I don't think this is at all correct. Going through a window is breaking and entering.

Well, I didn't know, so I looked it up before posting. https://en.wikipedia.org/wiki/Burglary > Although rarely listed as an element, the common law required that "entry occur as a consequence of the breaking".[7] For example, if a wrongdoer partially opens a window with a pry bar—but then notices an open door, which he uses to enter the dwelling, there is no burglary under common law. There are more results if you s…

See for instance Massachusetts model jury instructions, which are explicit that opening an unlocked door constitutes "breaking".

Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking

#53
post #52

Earlier quoted context omitted.

Well, I didn't know, so I looked it up before posting. https://en.wikipedia.org/wiki/Burglary > Although rarely listed as an element, the common law required that "entry occur as a consequence of the breaking".[7] For example, if a wrongdoer partially opens a window with a pry bar—but then notices an open door, which he uses to enter the dwelling, there is no burglary under common law. There are more results if you s…

See for instance Massachusetts model jury instructions, which are explicit that opening an unlocked door constitutes "breaking".

Yes, but that's using force to open the door, which was in my original claim about no force on an open window.

Reading that WP article again, turns out I was just considering the common law part. It later says:

> The common law definition has been expanded in most jurisdictions, such that the building need not be a dwelling or even a building in the conventional sense, physical breaking is not necessary, the entry does not need to occur at night, and the intent may be to commit any felony or theft.

So I'll give it to you for "physical breaking is not necessary", even though I don't actually know about the jurisdiction in question. (I didn't rtfa.)

Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking

#54
post #52

Earlier quoted context omitted.

See for instance Massachusetts model jury instructions, which are explicit that opening an unlocked door constitutes "breaking".

Yes, but that's using force to open the door, which was in my original claim about no force on an open window. Reading that WP article again, turns out I was just considering the common law part. It later says: > The common law definition has been expanded in most jurisdictions, such that the building need not be a dwelling or even a building in the conventional sense, physical breaking is not necessary, the entry do…

What's your point, though? If opening an unlocked door is B&E, what does the lockpicking analogy teach us?

Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking

#55
post #54

Earlier quoted context omitted.

Yes, but that's using force to open the door, which was in my original claim about no force on an open window. Reading that WP article again, turns out I was just considering the common law part. It later says: > The common law definition has been expanded in most jurisdictions, such that the building need not be a dwelling or even a building in the conventional sense, physical breaking is not necessary, the entry do…

What's your point, though? If opening an unlocked door is B&E, what does the lockpicking analogy teach us?

Oh, I was literally just arguing the other side about going through an open window because I didn't know for sure if it was burglary. (Common law says no, but that's probably updated, but maybe not in some places, but I didn't check them all.)

I don't see how you could access a computer without using "force", any input from a human constitutes force in my opinion. So no disagreement as far as the actual crime is concerned, I'm just nitpicking for fun...

Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking

#56
post #47
post #46

Earlier quoted context omitted.

Liability can be shared and a tenant may greatly prefer going after an ex. landlord vs. some random person. Granted, this does not apply in your case, but Chicago does have mixed use Residential/Commercial leases which is covered. Now suppose a tenant goes back to retrieve their property the day after there lease ends. Which under some situations they are allowed to do. Key works, the enter building... IANAL, but wou…

Your concern here is over moral hazard. You're saying, the law makes landlords liable for theft so that they'll do their duty to secure their building. I'm not arguing this point; moral hazard makes a lot of sense. If you want to argue that Trib Corp should have some negligence liability here, fine. But there is no sense in which that kind of liability mitigates the criminal actions of others. If I go into a building…

Morale hazard does play into what they can clam as damages. If reverting the defacement using there CMS system costs 500$ and results in 2,000 in lost profit NP. If it takes someone a few hours to verify that was the only change, NP.

But, they can't claim time related to revoking his permissions because they should have done that in the first place. Ditto for performing a security audit ect.

This is a normal user using there CMS system, not an admin or developer messing with things.

Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking

#57
post #54

Earlier quoted context omitted.

What's your point, though? If opening an unlocked door is B&E, what does the lockpicking analogy teach us?

Oh, I was literally just arguing the other side about going through an open window because I didn't know for sure if it was burglary. (Common law says no, but that's probably updated, but maybe not in some places, but I didn't check them all.) I don't see how you could access a computer without using "force", any input from a human constitutes force in my opinion. So no disagreement as far as the actual crime is conc…

On reflection, perhaps this pointless diversion yields the following maxim:

  You can walk into a house through an open door,
  but you can't walk into a computer.

Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking

#58

Earlier quoted context omitted.

Oh, I was literally just arguing the other side about going through an open window because I didn't know for sure if it was burglary. (Common law says no, but that's probably updated, but maybe not in some places, but I didn't check them all.) I don't see how you could access a computer without using "force", any input from a human constitutes force in my opinion. So no disagreement as far as the actual crime is conc…

On reflection, perhaps this pointless diversion yields the following maxim: You can walk into a house through an open door, but you can't walk into a computer.

You can totally walk into a computer. I've done it. Hurts.

Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking

#59
post #56
post #47

Earlier quoted context omitted.

Your concern here is over moral hazard. You're saying, the law makes landlords liable for theft so that they'll do their duty to secure their building. I'm not arguing this point; moral hazard makes a lot of sense. If you want to argue that Trib Corp should have some negligence liability here, fine. But there is no sense in which that kind of liability mitigates the criminal actions of others. If I go into a building…

Morale hazard does play into what they can clam as damages. If reverting the defacement using there CMS system costs 500$ and results in 2,000 in lost profit NP. If it takes someone a few hours to verify that was the only change, NP. But, they can't claim time related to revoking his permissions because they should have done that in the first place. Ditto for performing a security audit ect. This is a normal user usi…

I'm only going on here because I'm worried I've been unclear about the nature of the damage here.

If you're objecting to the idea that, having caused a breach, the convicted attacker is now on the hook for securing the application they broke, so that the attack they used is no longer viable, I agree. That is in no way fair.

But that's not what's happening.

Instead, having been breached, and only because they've been breached, the victim is now in a position of needing to assess the extent of the damage done. They can't guess --- at least, not if they're a major corporation --- because continuing to operate when you have reason to believe you've been systemically compromised is unethical and dangerous.

That's the difference between a DF/IR audit and a security audit. A security audit tries to find all your vulnerabilities. A DFIR audit tries to scope the compromise and retain evidence. Of the two, the DFIR audit has a narrower scope and more specific purpose.

But, weirdly, it's also more expensive. There are more application security consultants than there are DFIR auditors, and DFIR auditors are often selected by insurance companies, not by the market.

At any rate: the costs we're talking about Keys having incurred are not a bonanza of free assessment work Trib gets to bill to Keys.

Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking

#60
post #45

Earlier quoted context omitted.

Responsive? I thought we were talking about the law . You asked, incredulously, if I thought a certain set of actions should be legal. I told you why I think they should. In short, the harms of inconsistently-enforced inherently-arbitrary only-for-bigcos laws such as these exceed those of not having such laws. I stipulated at the very top of the thread that the investigation was surely very expensive. Most citizens w…

No, investigations for very small tech companies also cost far more than $20,000. Source: I've been a party to those, too. Even if you adopt the position that we should have laws that treats victims differently depending on how big their companies are, that wouldn't have much bearing on this case.

I'll further stipulate that the costs of investigating vulnerabilities at tiny two-engineer firms far exceed the costs of investigating vulnerabilities at giant conglomerates like Tribune Media. When those vulnerabilities amount to "don't turn off credentials for fired employees", I still say they should pay for their own damn security work, and no criminal statute should say otherwise.
Post reply on HN