Live data from Hacker News

This hacker might seem shady, but throwing him in jail is bad for everyone

washingtonpost.com

71–80 of 213 posts

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#71
post #69

Earlier quoted context omitted.

So if I ask the librarian for a copy of the book with ISBN 1; DROP TABLE books; -- is that okay because, technically, the server let my request through?

This is currently downmodded because people don't like the implication. And they shouldn't, because it quickly forces someone into either a) agreeing with the law or b) saying that SQL injections must be, ipso facto, legal. Including ones like: 1 AND ("1" = SUBSTRING(select social_security_number from employees where employee_name = 'Angela Smith', 1, 1)) You can use variations on this to... a) Ask our librarian for…

This is currently downmodded because people don't like the implication. And they shouldn't, because it quickly forces someone into either a) agreeing with the law or b) saying that SQL injections must be, ipso facto, legal.

You're drawing a false dichotomy based on premises that nobody in this thread has actually raised. It's entirely reasonable to a) disagree with the law, b) believe that SQL injections can be illegal based on some other rationale, and c) disagree with others on the appropriate penalty for SQL injections.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#72
post #69

Earlier quoted context omitted.

So if I ask the librarian for a copy of the book with ISBN 1; DROP TABLE books; -- is that okay because, technically, the server let my request through?

This is currently downmodded because people don't like the implication. And they shouldn't, because it quickly forces someone into either a) agreeing with the law or b) saying that SQL injections must be, ipso facto, legal. Including ones like: 1 AND ("1" = SUBSTRING(select social_security_number from employees where employee_name = 'Angela Smith', 1, 1)) You can use variations on this to... a) Ask our librarian for…

No, it is because lying about your user-agent is not explicitly trying to make an HTTP server perform an action it is not supposed to perform and is therefore not in the same category as SQL injections. HTTP servers are not supposed to use user-agent as authentication.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#73
post #59

Earlier quoted context omitted.

> You can't be unauthorized if there is no authorization. This is really the main point to me and I'm really confused as to how the law doesn't agree with this. How can you claim unauthorized access to something when there are no systems in place to grant or deny authorization? Comparing this to walking into someone's home who left the door unlocked (as someone in this thread has done) is bogus to me. Private propert…

> Private property is private property Except in many cases the private property is being made accessible. Imagine going to an open house and the owner accidentally left the basement unlocked. You open the door and walk down, then get arrested for breaking and entering.

More applicably, imagine there is no door, not even hinges where a door should be; just an opening to the basement.

But you get arrested for walking down there anyway. Then the police tell you you're under arrest because "The owner didn't intend for you to go there."

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#74
post #35

Everyone throws out analogies about walking into unlocked houses and such. Those are fairly poor analogies, so let me offer one which I think is far better at conveying what really happens. Imagine you walked into a public library and struck up a conversation with the librarian: You: Can you tell me general information about this library? Librarian: Certainly, this library was built in 1990, has a million books on it…

You totally nailed it. 100% right. Distilled it down to the essentials of how the internet works and the nature of a protocol as a contract. Bravo.

His whole analogy only works because the librarian is a human, and if a human with some apparent authority lets you do something, you can reasonably infer that you have permission to do it. But you can't anthropomorphize a server like that. It's not a gatekeeper, capable of granting permission, just a dumb lock which may be flawed. Only humans can consent.

To repurpose his analogy, if you sneak into the staff room and the librarian doesn't notice and doesn't stop you, you can't use that to say it must have been okay.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#75
post #17

Earlier quoted context omitted.

> I would argue that if there are no technological access controls in place, there is no such thing as "unauthorized access" You can't be unauthorized if there is no authorization. The default on the internet is "can access" Or is it like walking into someone's private home because they left the door open? Or merely unlocked? The law likes to operate on analogies, because analogous situations are ones for which we ha…

Yeah that's the immediate counter analogy to what I'm suggesting. I think the way I would go about arguing against it is that people on the street/sidewalk have no expectation of privacy. There are literally no access controls of any kind. Anyone can walk on the street; billionaires and homeless alike. There are no societal conventions that privacy is assured on the street and if you end up in someone else's picture…

I don't understand your argument. You seem to agree that the reason the unlocked house is not like the street is shared social conventions. That house across the street is definitely private property whether it's signed that way or not, and I'm expected to know that because, duh, it's a house. At least, that's how I understood this:

> So the right of the owner of a house to control access to his house is fairly well understood and accepted even in the case where a house might be unlocked or a door left open.

Then you discuss the technical and interface features of websites that differentiate them as analogs of houses and streets, respectively, like whether they have access control (locks). But we just agreed that the technical and design features of the door aren't what make a house not like the street. The differentiating feature of a house is not the security of its door, or even whether it has one; it's that it's a house and we're expected to know it's private. I don't get how that difference is analogous to access controls on a website. What's the social convention that's appropriate for determining whether a piece of information on the internet can be fairly accessed or not?

To be clear, I'm not saying there aren't good answers here (e.g. a house has walls which imply privacy, so you need some analog for walls on your site [1]). Or you could argue that the analogy is bogus (e.g. houses and streets just aren't like the internet). Or you could even argue that technical safeguards are the analogous social convention to private homes (I don't get it, but it's noncrazy). Or you could argue those conventions simply haven't been established yet, and that we should consider there to be no such thing as unlocked houses on the web. I'm just saying you have haven't made any of those arguments.

[1] completely off-the-cuff and, like my other suggestions here, in need of some substance.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#76
post #63

Earlier quoted context omitted.

If you ask the librarian to hold a book-burning party, and they do, should you get off scott-free?

Not if I tricked the librarian into setting fire to the library.

Then that is a poor librarian. A good librarian should have just said:

400 BAD REQUEST

Whomever staffed that librarian, should interview or train their staff better.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#77
post #35

Everyone throws out analogies about walking into unlocked houses and such. Those are fairly poor analogies, so let me offer one which I think is far better at conveying what really happens. Imagine you walked into a public library and struck up a conversation with the librarian: You: Can you tell me general information about this library? Librarian: Certainly, this library was built in 1990, has a million books on it…

Maybe we should just stop throwing around analogies altogether when it comes to politics. Analogies are useful in teaching since it allows people to relate concepts they already understand. However, it's just an abstraction, and is inevitably imperfect.

In normative arguments, analogies are used to bend reality to make your position seem reasonable regardless of whether or not it actually is. It would be better to judge weev's case on it's own merits rather than try to justify a position using increasingly complex analogies.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#78
post #35

Everyone throws out analogies about walking into unlocked houses and such. Those are fairly poor analogies, so let me offer one which I think is far better at conveying what really happens. Imagine you walked into a public library and struck up a conversation with the librarian: You: Can you tell me general information about this library? Librarian: Certainly, this library was built in 1990, has a million books on it…

I challenge you to actually try to do this and see whether or not the librarian calls security.

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#79

Earlier quoted context omitted.

> You can't be unauthorized if there is no authorization. This is really the main point to me and I'm really confused as to how the law doesn't agree with this. How can you claim unauthorized access to something when there are no systems in place to grant or deny authorization? Comparing this to walking into someone's home who left the door unlocked (as someone in this thread has done) is bogus to me. Private propert…

There is a system in place. It's called HTTP status codes.

I wonder if there's some way to make a useful legal argument along the lines of: Since there's a well defined HTTP Status code for "Unauthorized" (401), then it's clear that ant request responded to with a Status code of "200 OK" is, by definition, being declared by the webserver (and it's operators) as "authorized".

Re: This hacker might seem shady, but throwing him in jail is bad for everyone

#80
post #16

Reading this article http://www.theverge.com/2013/9/12/4693710/the-end-of-kindnes... makes me feel not too terrible that he's being thrown in jail.

Weev's a right shithead, you're absolutely right. I still bailed him out of jail for the time leading up to and during his trial. Why? Because UNPOPULAR SPEECH SHOULD NEVER BE CRIMINAL, no matter how revolting. Indeed, it is the unpopular and revolting stuff that needs the most defending: "The trouble with fighting for human freedom is that one spends most of one's time defending scoundrels. For it is against scoundr…

I think most of society can live with death threats being criminal.
Post reply on HN