Live data from Hacker News

You May Not Like Weev, But Your Online Freedom Depends on His Appeal

wired.com

91–100 of 145 posts

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#91
so here's the solution. 1) Make a website called "freeweev.com" or something 2) Put some legal mumbojumbo at the bottom of the site that says something about unauthorized usage of this website is a crime. 3) Make the post-signup page URL look something like this: http://freeweev.com/?id=12

That simply says "Your email: ...@gmail.com will be updated when we have info on the case. Thanks for your interest" 4) Let people "find this" 5) Get lots of people to report on the problem 6) Fix the problem after the press gets it 7) Freeweev.com takes everyone to criminal court under CFAA. No lawyers necessary, just tell the Judge that there appears to be no difference in these cases as the AT&T case, all of these people that hacked our site should go to jail for 41 months. Also make sure that this involves MANY people. 8) Legal breakdown, no software development for anyone (like the screen-writers strike right?)

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#92
post #52

Earlier quoted context omitted.

> Or was he doing this maliciously? He was _absolutely_ doing this maliciously. It STILL SHOULD NOT BE CRIMINAL. This is a fundamental misattribution of responsibility. His intent was to defame AT&T as much as possible, using only factual information about their own (negligent) business decisions. This, too, should be legal (and I believe it is).

>>He was _absolutely_ doing this maliciously. It STILL SHOULD NOT BE CRIMINAL. What kind of reality do you live in where malicious intent to cause harm to someone or some group should not be a crime?

> What kind of reality do you live in where malicious intent to cause harm to someone or some group should not be a crime?

It depends somewhat on what you class as malice. Starting a business is usually a deliberate attempt to cause harm to competitors, and success at it may well cause thousands of people to lose their jobs, etc.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#93
post #52

Earlier quoted context omitted.

> Or was he doing this maliciously? He was _absolutely_ doing this maliciously. It STILL SHOULD NOT BE CRIMINAL. This is a fundamental misattribution of responsibility. His intent was to defame AT&T as much as possible, using only factual information about their own (negligent) business decisions. This, too, should be legal (and I believe it is).

>>He was _absolutely_ doing this maliciously. It STILL SHOULD NOT BE CRIMINAL. What kind of reality do you live in where malicious intent to cause harm to someone or some group should not be a crime?

The kind where squabbles between two private parties are civil matters until and unless someone commits (or conspires to commit) an actual crime?

Particularly when the "harm" here is harm of reputation due the target's public actions? If I assemble a bunch of potentially-reputation-harming data on a public figure and post it on the internet with the clear intent of convincing people that public figure is incompetent, should that be an act that can get me landed in jail? Or is that speech?

Is the automated collection of that data really a thing that should be criminalized? Should it be criminal because or only when it includes identifying information of innocent bystanders?

This is publicly-available information.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#94
post #63
post #12

Earlier quoted context omitted.

It doesn't matter if they accessed one or a million - accessing information published on the web SHOULD NOT BE CRIMINAL. Whether you agree with his methods or not, there is no stretch of the imagination that makes prison for downloading (even 114k of) them make sense. It wasn't a hole or bug— it was an expressly implemented feature. ATT decided to do it this way to reduce resubscription friction. The iPad sends the s…

That first sentence doesn't make sense. If a merchant screws up and manages to post a flat ASCII text file of credit card accounts with CVV numbers on a URL in a directory with an Apache index enabled, your argument says "well, sucks for the merchant and all their customers". There are clearly cases where the mere fact that someone has left something somehow exposed to a web browser does not connote authorization to…

I think the parent comment's first sentence makes sense -- simply accessing that information shouldn't be a crime. But if you then make a copy and either use or distribute that information illegally, that's something different.

To be clear, that's exactly what Weev did -- accessing AND keeping a copy for himself. But I think the parent comment's argument is talking specifically about access.

Creating a precedent where a "reasonable person" is expected to "understand" that the exposure was a mistake would create a huge legal gray area. Anything that's available on the public internet should be perfectly legal to access. What people do with that content is a different matter.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#95

Earlier quoted context omitted.

You and sneak seem to be proposing a legal regime under which no "hacking" of any kind is illegal. If the system will perform action B given request A, issuing request A, no matter the intent, cannot be a crime? If I'm missing an important distinction you'd make, I'd very much like to hear what it is.

I would prefer if the system punished people for what they did with their access to data, not simply for having that access; organizations that hold private or sensitive information should be punished if unauthorized people can access it by any means. Having email addresses or credit card numbers should not be the crime, regardless of how you obtained that information. Committing credit card fraud or selling credit c…

@betterunix-- seriously? It's OK with you if they get your private data, no matter how they acquire it? Spoken like someone who has never had exposure of private data used as a THREAT... something weev is known for. If someone uses illegal means to obtain your private data, they can exploit/weaponize that acquisition without having to then use the private data to commit a different crime. (different from the crime -- usually fraud -- in how they obtained it).

Weev has taught many of us that acquiring your private data is enough to make you wonder when, exactly, he will decide to use it. Or in my case, to publish it and encourage the whole WORLD to use it. And don't get me started on medical records... If you honestly believe that acquiring private data shouldn't be illegal until it is used in a crime, you have obviously never been threatened with exposure from someone who did just that. (but again, I don't think this applies to the AT&T case) -- Kathy Sierra

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#96
post #63

Earlier quoted context omitted.

That first sentence doesn't make sense. If a merchant screws up and manages to post a flat ASCII text file of credit card accounts with CVV numbers on a URL in a directory with an Apache index enabled, your argument says "well, sucks for the merchant and all their customers". There are clearly cases where the mere fact that someone has left something somehow exposed to a web browser does not connote authorization to…

I think the parent comment's first sentence makes sense -- simply accessing that information shouldn't be a crime. But if you then make a copy and either use or distribute that information illegally, that's something different. To be clear, that's exactly what Weev did -- accessing AND keeping a copy for himself. But I think the parent comment's argument is talking specifically about access. Creating a precedent wher…

The law is full of judgements based on the actions of a "reasonable person". And, I agree with your first paragraph, but then, so does the CFAA; CFAA doesn't define a strict-liability crime.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#97
post #39

Earlier quoted context omitted.

Please stop with the physical analogies. Locks and doors and physical space have well defined ways of indicating "authorized" and "unauthorized". We also have a social contract about entering spaces of others, even if there are no locks at all. The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_. It's up to that server, and no…

Physical analogies are perfectly appropriate in this context. Just because someone accidentally exposes a function via their website that divulges information that isn't supposed to be viewable doesn't mean it is ok. If I've never met someone in real life who left their door unlocked nor communicated with them before I rob them, just like the web, both are still illegal. >The social contract of the web is that "you c…

Consider the 50+ doors the FBI broke down in response to operation payback, yet 0 prosecutions have occurred in the US. Before that happened it was widely speculated that ddos was not a crime in the united states, and that appears to have been defacto agreed to by the US Attorney in this case.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#98

Earlier quoted context omitted.

>>He was _absolutely_ doing this maliciously. It STILL SHOULD NOT BE CRIMINAL. What kind of reality do you live in where malicious intent to cause harm to someone or some group should not be a crime?

Hypothetical scenario as an existence proof (not related to the situation currently at trial): Suppose you're an investigative reporter. You regularly investigate a person or company that you feel gets away with too much, whose public actions always skate right on the line, and figure they must be doing something wrong. You feel vindictive about it because you haven't managed to find anything about them in the past.…

>modulo changing it to ');drop table students;-- )

As an aside, about a year ago I made a simple web crawler that got (among other things) HTTP headers from all the servers it found. After an hour of crawling, I took the headers to start working on a parser for them, and found 7 attempts at an sql injection. Do I get to prosecute whoever set up those servers?

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#99

Earlier quoted context omitted.

I would prefer if the system punished people for what they did with their access to data, not simply for having that access; organizations that hold private or sensitive information should be punished if unauthorized people can access it by any means. Having email addresses or credit card numbers should not be the crime, regardless of how you obtained that information. Committing credit card fraud or selling credit c…

@betterunix-- seriously? It's OK with you if they get your private data, no matter how they acquire it? Spoken like someone who has never had exposure of private data used as a THREAT... something weev is known for. If someone uses illegal means to obtain your private data, they can exploit/weaponize that acquisition without having to then use the private data to commit a different crime. (different from the crime --…

Blackmail and harassment are both crimes, you know. If someone is threatening to expose your private data, it makes no difference how they acquired it -- it is a crime regardless of whether or not they were authorized to have it.

The problem with charging hackers for having information they are not supposed to have is that it takes the responsibility to keep data secure away from those who are entrusted with it. Take medical records as an example. Yes, we want them to be kept private, but that should be the responsibility of hospitals, doctors, etc. If some hacker downloads those files, the hospital should be punished for their failure to keep the files secure. If we want to believe that hackers are magicians and that any Internet-connected system can be compromised, don't connect systems with medical records to the Internet.

What is wrong with making it the responsibility of anyone who has private information to keep that information private? If a hacker downloads a hospital's records, I think it is fair to expect that hacker to keep those records private, and to prosecute the hacker if they are revealed to anyone for any reason (even if the hacker is himself a victim of another hacker).

People should not have to be afraid to run a web crawler out of their own house. Yes, a web crawler is going to find private information that was not properly secured. That should not make the person running the crawler a criminal.

Re: You May Not Like Weev, But Your Online Freedom Depends on His Appeal

#100
post #39

Earlier quoted context omitted.

"It should always be perfectly legal to access a remote computer system via a publicly accessible interface.", no it shouldn't, no more than it should be legal for me to walk into your house if you've not locked the door. The system worked exactly as AT&T intended, in circumstances they'd clearly not planned for. If they'd bothered doing a risk assessment they'd have spotted it, they took the lazy option and it didn'…

Please stop with the physical analogies. Locks and doors and physical space have well defined ways of indicating "authorized" and "unauthorized". We also have a social contract about entering spaces of others, even if there are no locks at all. The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_. It's up to that server, and no…

But by that logic, any kind of malicious web activity should be allowed. Once you remove all the abstractions, any kind of attack is just computers behaving how they've been instructed to. An injection attack is only a server processing a particularly strange request.
Post reply on HN