Live data from Hacker News

This hacker might seem shady, but throwing him in jail is bad for everyone

washingtonpost.com

61–70 of 213 posts

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#61

Reading this article http://www.theverge.com/2013/9/12/4693710/the-end-of-kindnes... makes me feel not too terrible that he's being thrown in jail.

The reason to defend weev in this case is to ensure that the specific act for which he is being prosecuted is not treated as a crime in other cases.

If weev harassed this woman in the manner described in the article you reference, he probably should be prosecuted for that. But it's not ok for prosecutors to put him in jail for something that should be perfectly legal, just because they can't (or didn't) put him in jail for something else.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#62
post #35

Everyone throws out analogies about walking into unlocked houses and such. Those are fairly poor analogies, so let me offer one which I think is far better at conveying what really happens. Imagine you walked into a public library and struck up a conversation with the librarian: You: Can you tell me general information about this library? Librarian: Certainly, this library was built in 1990, has a million books on it…

A bit nitpicky on one portion over an otherwise good analogy. If they library is funded by a city, the list of employees and their salaries are public knowledge. I use to work for a small town library in high school. I could see all of my high school teacher/staff information along with co-workers and any other town staff salaries in the town record (publicly displayed in the library itself). Of course, what you may do with the information is another thing.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#63
post #35

Everyone throws out analogies about walking into unlocked houses and such. Those are fairly poor analogies, so let me offer one which I think is far better at conveying what really happens. Imagine you walked into a public library and struck up a conversation with the librarian: You: Can you tell me general information about this library? Librarian: Certainly, this library was built in 1990, has a million books on it…

So if I ask the librarian for a copy of the book with ISBN 1; DROP TABLE books; -- is that okay because, technically, the server let my request through?

If you ask the librarian to hold a book-burning party, and they do, should you get off scott-free?

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#64
post #62
post #35

Everyone throws out analogies about walking into unlocked houses and such. Those are fairly poor analogies, so let me offer one which I think is far better at conveying what really happens. Imagine you walked into a public library and struck up a conversation with the librarian: You: Can you tell me general information about this library? Librarian: Certainly, this library was built in 1990, has a million books on it…

A bit nitpicky on one portion over an otherwise good analogy. If they library is funded by a city, the list of employees and their salaries are public knowledge. I use to work for a small town library in high school. I could see all of my high school teacher/staff information along with co-workers and any other town staff salaries in the town record (publicly displayed in the library itself). Of course, what you may…

OH MY GOD ARE YOU SERIOUS.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#65
Kudos to the WP for ongoing coverage of this case. There are important issues being litigated here that could affect everyone, and I'd argue they are worth discussing without regard to this particular defendant and the sheer stupidity of his actions.

However, I find WP's use of Poulson's activities as an example of "legitimate" automated HTML retrieval ("scraping") to be an odd one. It seems an awkward a comparison to convey what should be a simple point, in my opinion.

How about something much more common? Googlebot. Imagine if we forbade Google from using automation and from scraping content and placing it in the Google cache. No more web search.

Alas, because of the ad hoc nature of the Web (i.e., there is no unifiying organizational scheme for locating content across all websites as there would be in, say, locating content in a library of books), you cannot access Web content until you first discover it. In order to discover content, you generally have to search. In order to create an index and cache of content to search, someone has to scan/crawl/scrape websites. The later three are activities that are routinely automated. As such, they will violate many website Terms of Service and may get you banned simply for being "automated".

In fact, to use Google as an example (not picking on them per se, it's just that they are a well-known example), crawling Google will "get you banned" from using Google, temporarily.

The irony of this has always intrigued me: Google may crawl your servers, but under Google's policies, you may not crawl Google's servers.

If I create an index of your website, at your expense (by aggressively running automated queries against your http server, as Google does, for example), am I obligated to share it with you?

In any event, attempts to criminalize automation should raise red flags with anyone who is even slightly tech savvy.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#66
post #63

Earlier quoted context omitted.

So if I ask the librarian for a copy of the book with ISBN 1; DROP TABLE books; -- is that okay because, technically, the server let my request through?

If you ask the librarian to hold a book-burning party, and they do, should you get off scott-free?

Not if I tricked the librarian into setting fire to the library.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#67
post #64
post #62

Earlier quoted context omitted.

A bit nitpicky on one portion over an otherwise good analogy. If they library is funded by a city, the list of employees and their salaries are public knowledge. I use to work for a small town library in high school. I could see all of my high school teacher/staff information along with co-workers and any other town staff salaries in the town record (publicly displayed in the library itself). Of course, what you may…

OH MY GOD ARE YOU SERIOUS.

Enjoy: http://www.mercurynews.com/salaries/bay-area/2012

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#68
post #63

Earlier quoted context omitted.

If you ask the librarian to hold a book-burning party, and they do, should you get off scott-free?

Not if I tricked the librarian into setting fire to the library.

What really is the line between tricked and asked? Deceit?

Lets go with deceit.

So is asking for book ISBN '1; DROP TABLE books; --' deceitful? Perhaps, that's not an ISBN after all. Is asking for book ISBN [some valid ISBN that you pulled out of your ass, but happens to exist] deceitful? I don't think so. If you are just asking for randomly chosen ISBNs and getting responses, I don't think there is any trickery involved.

In one case you are counting on the system to correctly understand your (validly constructed) request, in the other case you are counting on the system to misinterpret your request in a dangerous fashion.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#69
post #35

Everyone throws out analogies about walking into unlocked houses and such. Those are fairly poor analogies, so let me offer one which I think is far better at conveying what really happens. Imagine you walked into a public library and struck up a conversation with the librarian: You: Can you tell me general information about this library? Librarian: Certainly, this library was built in 1990, has a million books on it…

So if I ask the librarian for a copy of the book with ISBN 1; DROP TABLE books; -- is that okay because, technically, the server let my request through?

This is currently downmodded because people don't like the implication. And they shouldn't, because it quickly forces someone into either a) agreeing with the law or b) saying that SQL injections must be, ipso facto, legal.

Including ones like:

1 AND ("1" = SUBSTRING(select social_security_number from employees where employee_name = 'Angela Smith', 1, 1))

You can use variations on this to...

a) Ask our librarian for a series of about 50 books and hear whether or not she has them in stock.

b) Read Angela Smith's Social Security number right out of the database.

There apparently exist a lot of people on HN who would prefer to think that, despite my near-magical ability to correctly divine the SSN of any employee (or any other piece of data in the DB) with a SQL injection attack, the fact that I'm just looking at a book listing page in a totally authorized fashion means I must not be doing anything wrong.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#70
post #35

Everyone throws out analogies about walking into unlocked houses and such. Those are fairly poor analogies, so let me offer one which I think is far better at conveying what really happens. Imagine you walked into a public library and struck up a conversation with the librarian: You: Can you tell me general information about this library? Librarian: Certainly, this library was built in 1990, has a million books on it…

I upvoted immediately after your first two sentences, and wished I could do it again at the end of your post. Well done.

I've been trying to think of a proper analogy to changing your user agent. Wearing a fake mustache and requesting information from someone publicly giving information to only mustachioed persons?

    You: Can I borrow the book identified by ISBN 1234?
    Librarian: We restrict access to that book to only people who will read it with our page turning machine.
    You: Can I borrow the book identified by ISBN 1234? I am using your page turning machine now.
    Librarian: Sure, here you go.
Post reply on HN