Live data from Hacker News

This hacker might seem shady, but throwing him in jail is bad for everyone

washingtonpost.com

51–60 of 213 posts

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#51
post #47
post #35

Everyone throws out analogies about walking into unlocked houses and such. Those are fairly poor analogies, so let me offer one which I think is far better at conveying what really happens. Imagine you walked into a public library and struck up a conversation with the librarian: You: Can you tell me general information about this library? Librarian: Certainly, this library was built in 1990, has a million books on it…

Really, you are going to give people crap for bad analogies, and then try to compare the actions of a conscious human being to an automated computer system?

An automated computer system can only do what it's told. It perfectly carries out the instructions it is given. A human being can really screw everything up using their judgement and coming to the wrong conclusion.

The problem here is that AT&T employed a human being to design an automated system who didn't know enough about the automated system to ensure that it was correct. And then this automated system did exactly what it was told to do and made AT&T look bad.

But the fact that the code running on the webserver didn't reflect the intent of some AT&T exec or their company policy isn't the fault of those accessing the webserver. It's AT&T's fault for doing a really terrible job of QA/QC on their own systems prior to a really big launch.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#52
post #6
post #3

Earlier quoted context omitted.

Throwing him in jail is an awful outcome for justice and for the precendent it sets. I'm very much hoping he walks out of court a free man. Once outside the court, he could get hit by a bus as far as I'm concerned. When we want weev free, we're fighting for law and society, for just principles, not for the individual.

I was with you up until wishing another human dead.

What is the greatest harm that someone has caused you? Just curious.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#53

Earlier quoted context omitted.

>This was a PUBLIC website... you are supposed to be able to visit it. If you make a request to a server without providing authentication and it returns data, that is not your fault. That is what you are SUPPOSED to do to servers. If it asks for authentication and tells you you are unauthorized, but you brute force the password or find an exploit, then THAT is a crime. There was not authentication in this case. Unfor…

If I find a $50 bill on a sidewalk I can INTEND to steal it as much as I want. But no matter how badly I WANT to steal it I cannot because at that point it's not a thing that can be stolen. There is no way to trace it back to it's former owner and as such, the first person to find it is legitimately the new owner. Weev might have said that he "stole" the information or that he "intented" to perform an unauthorized ac…

Of course intent matters. If I run over someone with my car and kill them and it was deemed just a terrible but unfortunate accident, that is 100% different than if I drove over them because I intended to run them down and kill them.

The same applies to this case. He intended to access something he knew he shouldn't have had access to. Thus why he is guilty.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#54
post #47
post #35

Everyone throws out analogies about walking into unlocked houses and such. Those are fairly poor analogies, so let me offer one which I think is far better at conveying what really happens. Imagine you walked into a public library and struck up a conversation with the librarian: You: Can you tell me general information about this library? Librarian: Certainly, this library was built in 1990, has a million books on it…

Really, you are going to give people crap for bad analogies, and then try to compare the actions of a conscious human being to an automated computer system?

Planning on doing any of the work to tell us how the analogy fails there?

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#55
post #30

It's worth reading the criminal complaint and indictment ( https://www.eff.org/cases/us-v-auernheimer ) to get some background. In particular: the discussions of using the email addresses for a phishing scheme, using them for spam, shorting AT&T stock and profiting off the data release, setting up WiFi routers so they can blame it on a third party, discussing how this was a federal crime, and how to spin themselves a…

It's not worth reading that, because it's taken completely out of context. As badly as it's taken out of context, you're actually taking it even more out of context in your comment here. Weev actually said that shorting stock would be illegal, and said something to the effect of "if you do it, I don't want to know about it" and discouraged many other "suggestions" from people who didn't appear to have any real part in it, but were cheerleading.

In any case, that is very typical IRC conversation for a large portion of that subculture. They joked about doing these things, but they didn't actually take steps to do them. He considers himself a satirist, so it's not much different than some comedians talking nonsense over beers and having it show up in an indictment.

One of the chatters observing said they should post the list to full-disclosure. Weev replied saying "no, don't do that, its potentially criminal." He then talked about how he gets to spin it in the media and he's won. That says pretty clearly that he was only out to make a scene, which is what he has always done.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#56
Here is my analogy:

1. You just finished your workout and went to a locker room at your gym (he went to a public website)

2. You opened up your own locker and took your stuff from it (checked his account)

3. You found out that very few people are using locks in the gym locker room (figured the account id in url )

4. You know that it is not your belongings in other people lockers, but they are not locked just because people are just lazy or don't want to spend money on the lock (he knew that those accounts do not belong to him, and were accidentally not locked by by at&t)

5. You decided if those lockers are not locked - that means that clothes inside of those lockers are public property and you can easily borrow them (tried to browser to other urls and get private account info)

6. You go ahead and try opening every single locker in a room and put all the belongings you find in opened lockers on ebay to make profit and sell it, BEFORE letting know the owners or the gym that those belongings are not locked. (sold private data to somebody)

I think thats not legal behavior, as long as you understand that the property you are taking is not yours - you are making a crime by taking it (stealing)

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#57

Earlier quoted context omitted.

If I find a $50 bill on a sidewalk I can INTEND to steal it as much as I want. But no matter how badly I WANT to steal it I cannot because at that point it's not a thing that can be stolen. There is no way to trace it back to it's former owner and as such, the first person to find it is legitimately the new owner. Weev might have said that he "stole" the information or that he "intented" to perform an unauthorized ac…

Of course intent matters. If I run over someone with my car and kill them and it was deemed just a terrible but unfortunate accident, that is 100% different than if I drove over them because I intended to run them down and kill them. The same applies to this case. He intended to access something he knew he shouldn't have had access to. Thus why he is guilty.

Yes, but in your example (where someone is killed) there is rather obviously an underlying act that may or may not be criminal depending on the intent. There are infinitely many acts that cannot be considered crimes regardless of how malicious the intent behind them may be.

Furthermore, just because someone feels that they have done something wrong does not make what they have done a crime. The law also must consider that action to have been illegal.

Hopefully, the appeals court will determine that accessing a public unrestricted URL cannot be considered illegal, regardless of the mindset of the person who might choose to access it.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#58
post #35

Everyone throws out analogies about walking into unlocked houses and such. Those are fairly poor analogies, so let me offer one which I think is far better at conveying what really happens. Imagine you walked into a public library and struck up a conversation with the librarian: You: Can you tell me general information about this library? Librarian: Certainly, this library was built in 1990, has a million books on it…

Oh man, an analogy which actually makes sense! This has got to be a first. Please spread it far and wide.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#59

If you visit and internet cafe and someone's forgotten to log out of their bank account and you fiddle with it, that's probably a crime. Since in nearly all cases they probably didn't intend to do such a thing. We can surmise this by observing the banking website had a password to protect the account holder. This is evident by virtue of the "log out" link that's clearly visible and that the website is served over HTT…

> You can't be unauthorized if there is no authorization. This is really the main point to me and I'm really confused as to how the law doesn't agree with this. How can you claim unauthorized access to something when there are no systems in place to grant or deny authorization? Comparing this to walking into someone's home who left the door unlocked (as someone in this thread has done) is bogus to me. Private propert…

> Private property is private property

Except in many cases the private property is being made accessible. Imagine going to an open house and the owner accidentally left the basement unlocked. You open the door and walk down, then get arrested for breaking and entering.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#60
post #35

Everyone throws out analogies about walking into unlocked houses and such. Those are fairly poor analogies, so let me offer one which I think is far better at conveying what really happens. Imagine you walked into a public library and struck up a conversation with the librarian: You: Can you tell me general information about this library? Librarian: Certainly, this library was built in 1990, has a million books on it…

So if I ask the librarian for a copy of the book with ISBN

    1; DROP TABLE books; --
is that okay because, technically, the server let my request through?
Post reply on HN