British teenager suspected of being mystery hacker who stole CIA boss emails
telegraph.co.uk
telegraph.co.uk
It's the same with banks lending to countries who are unable to repay, or CEOs never going to jail for aiding and abetting Mexican drug cartels. No one takes responsibility for their own stuff any more.
Just because you can throw a stone into a storefront and steal stuff, does not mean you are free to do that.
Or are you arguing that just because it's the evil CIA, it's fine to hack them and leak tons of personal info (which potentially puts lifes in danger)
>Just because you can throw a stone into a storefront and steal stuff, does not mean you are free to do that.
There are parts of the world where tourists are warned about pickpockets.
Of course pickpockets shouldn't pick pockets. But that's not the world we live in.
Only a fool goes walking in those parts of the world without taking good precautions. And if you're an intelligence agent, that goes at least double.
Personally I don't think drafting a new law for that is a good idea, but I can see how it could fall under gross negligence.
If he isn't arguing that's a valid reason, allow me. Or are you arguing that the CIA is not "evil"?
For anyone outside the US, or anyone inside who can set blind patriotism aside, the CIA has spent its entire existence doing very bad things, up to and including including murder, torture, coups d'etat and other violence and atrocities against countless people and nations.
Given this role the CIA takes upon itself around the world - ruining or taking actual lives, using the excuse of theoretically saving lives - maybe leaking names (and AFAICS all this kid has done is access a Verizon email account) puts fewer people's lives in danger.
And the two examples you gave are quite different from this one, in those cases the perpetrator is actually let off scott free
Sure, I don't think a kid trying to show off should face the same punishment as an adult doing something purely malicious, but "it was actually a surprisingly easy crime to carry out" should never be a reason not to prosecute.
If you sell dangerous food you should take responsibility for that and not just blame the bacteria. But if someone intentionally infects food they should also take responsibility. Those two perspectives are not incompatible.
But the lesson is that bacteria and hackers will always exist!
Same goes for the criminal.No matter how lax the security precautions of the bank are, an individual is judged for his crime.
The problem with cybercrimes and digital-rights related material (piracy, etc.) is that punishments are usually disproportionately severe. I believe that the fault lies to lawyers who over-sensationalize these crimes and judges who are totally unable to understand the real vs possible damage. For example, a 15 year old hacker who found a 5-years old XSS and hacked (as in copied 15 MySQL databases) from a CIA/NSA/FBI website and post his IRC nick on the page to brag about on his friends vs a 35-year old spy who sold these info to some other country for huge profits. These are different situations but are most of the time treated equally by judges.
Give me 15s with a crowbar and I will be able to enter almost any house. Crowbars are like 10 dollars at your local hardware store.
Physical security is almost always based on expected risk of detection and subsequent penalties, not prevention of ability to intrude, yet we somehow don't accept the same reasoning for digital security?
There is literally trillions of dollars worth of assets sitting around the world protected by nothing more than the idea of a closed door and some sort of expectation that a sheet of glass represents a barrier. Our society relies on a system where people respect the laws and have penalties enacted on them if they dont.
And yes, I also think that the weight of criminal penalties should generally place more emphasis on deterring people from trying to steal stuff rather than deterring people from working in infosec or security cleared professions. Not that I don't think there are potentially people who should no longer be working for the CIA as a result of this.
There shouldn't have been anything classified in the AOL account, but it looks more like a breach of his personal privacy.