Florida programmer arrested for gaining unauthorized access to kernel.org
justice.gov
justice.gov
Edit: A bit about the United States Sentencing Guidelines, linked from the lwn thread: https://popehat.com/2013/02/05/crime-whale-sushi-sentence-el...
Still though, a little disproportionate.
They're obviously angling toward a plea, though.
(I know you know this and that an upward departure from the Guidelines is very unlikely for this particular case--just stating for the record.)
"The government is recommending a guidelines sentence, meaning between zero and six months in jail... It's not sufficient to comply with the purposes of sentencing. It doesn't reflect the seriousness of the crime and the conduct surrounding it. It doesn't provide just punishment for the offense to give simply a guidelines sentence."
[1]: http://www.chicagotribune.com/news/nationworld/ct-pdf-transc...
It is as least as likely that I am wrong than that the reporting is wrong, but, there you go.
Are there even 100 people in prison for "cybercrime"?
Does "cybercrime", which includes credit card and identity theft, occur only rarely? Is that why almost nobody is in prison for it? No. The reason nobody is in prison for "cybercrime" is that despite what us message board nerds think, we are not in fact part of a persecuted class.
At this point people are being sentenced to decades for crimes they previously were sentenced to just years for.
The entire situation is disgusting.
So the short answer is "prosecutorial discretion".
The longer answer might be something like this:
During the crime wave from the late 70s through the early 90s, the American public demanded increasingly aggressive prosecution of crime. Prosecutors offices staffed up in response to it. People were elected on promises of increasing funding both to police and to prosecutors. Prosecutors themselves were incentivized to file more cases, again due to the public mood.
The crime wave passed, but once set in motion, the systemic increase in prosecutions didn't stop: in large organizations, headcount, once obtained, is only released dearly. Managed business objectives (like expectations on percentage of offenders for whom prosecutors will charge with felonies), once established, are only with great effort ever changed.
And so that's where we're at now: a prosecutorial system calibrated to the crime levels and hysterical public mood of the late 1980s.
In reality, for a non-remunerative first-time offense, even of this severity, the guidelines suggest low single-digits.
I would like to see a situation where the max penalty that can be issued by a judge can only exceed a plea offer by 20%.
Once again: 40 years is not in fact a sentence that is available to the judge; the judge would have to discard the sentencing guidelines entirely, and that sentence would fall apart on appeal.
Further, there is simply no relationship between the number "40 years" and the guidelines. It's not like the DOJ is marking up the guideline sentence by X0%. They're instead using a ridiculous process to add the sentences for every count of a crime up, which is simply not how federal sentencing works.
Swartz had the advice of some of the best attorneys in the field during his ordeal. Nobody doubts the stress of a federal prosecution contributed to his death. But nobody familiar with the case believes --- or believes that Swartz believed --- that he was facing a double-digit-years sentence. His own attorney, who advised him to take the case to trial, believed that if convicted on all counts, he might not even get a custodial sentence --- that his worst case would be a felony conviction with a probation sentence.
You can read the sentencing guidelines (they're public) and see why. First offense. Non-remunerative crime. Highly debatable damage. Reluctant, ambivalent victims.
Seems likely there's a little more to the story. (or they didn't find anything for 5 years until the guy bragged to someone)
However by far the strangest thing here is how very specific the charges are, one hack 5 years ago and no co-conspirators? How on earth didn't they find anything else to charge him with? [1]
[1] Of course this all could be explained away by them having a weak case, which they probably would have if they failed to seize his personal equipment
>What's the benefit?
Tons, having personally tried the same thing in the past :^) Being able to serve backdoored copies of the kernel to targeted users would be all kinds of useful, and you'd be in an unique position to target the kernel developers themselves, allowing you to actually insert a backdoor into the kernel.
[1] Phalanx is by far one of the most advanced pieces of publicly analysed linux malware https://volatility-labs.blogspot.de/2012/10/phalanx-2-reveal...
[2] Kernel.org folks claimed that they weren't the only target, which is to be expected (people with no prior hacking experience rarely decide to acquire/produce somewhat advanced linux malware and install it on kernel.org)
[2] ctrl+f credential-stealing https://lwn.net/Articles/464233/
The common example of parallel construction (because it's simple to explain, not because there's evidence it's happened) is: unauthorized electronic surveillance reveals that a drug transaction is going to happen at such-and-such corner at such-and-such time. The surveillance is shared with the police, who then station officers near the site of the transaction, and who are therefore able to observe the crime as it takes place --- giving them probable cause to effect the search themselves.
In other words, parallel construction is a way of allowing the police to be at the "right place and right time".
So, to move the ball forward on the conspiracy theory that some 27 year old doofus who rootkitted kernel.org with stolen credentials was so important to the NSA that they monitored him and conspired with the FBI to ensure he was charged, you must first come up with the set of circumstances in which the NSA could have shared something with the FBI that would have enabled FBI to de novo generate probable cause for a search.
Would this crime have been handled by the federal government 10 years ago? 20? Would an attack on your server get a response from the FBI and the DOJ?
That influence doesn't have to be the Linux Foundation; it could also be corporate or other powerful entities that are heavily invested in it, such as IBM.
As much as technical solutions to security are important, there, the legal aspect should not be forgotten
What if someone punches you in the face and steals your wallet, resulting in minor bruising, an adrenaline dump, the loss of $42 and at least three hours spent on the process of replacing your ID and credit cards?
1% of Americans are in the incarnation system or out on parole. That's more than all of the other high income countries.
Our legal system is hardly fair, and this is another example of it.
What I have a problem with is all of the tears for the white collar, educated criminals, and the insistence that the people who really deserve prison are those poor, uneducated, violent criminals. Somehow everyone seems to think that the criminals that they could most easily see themselves as deserve the least punishment, so middle-class crime is seen as less criminal by the middle-class.
As usual, there is no one size fits all and so Judges usually have leeway to decide severity of punishment.
Any such acts would be criminal on their own, not sure what point you're trying to make besides emotional appeal.
> Ability to say break into a say a Ubuntu or Red Hat binary server could server malware to hundreds of organizations including Governments.
If you actually did something with such access it shouldn't be very hard to find suitable crimes to charge you with other than breaking to the servers.
Seems fair to me, I really don't see why cybercrime deserves special treatment.
>Its also a potentially lucrative area which ought to be counterbalanced with high consequences.
Yeah, copyright infringement is even more lucrative. Does that mean we should start locking up people for whats currently civil copyright infringement?
You're probably talking about criminal charges anyway, in which case the answer is that they rarely do anything that illegal, and when they do it's not very easy to prove.
The sentencing guidelines make available remedies for those cases - and I can imagine large scale attacks which should be punishable by life in prison.
Do the merits of this case warrant max staycations in prison? I dunno, but the government should have the flexibility for the lulz.
So, B&E is a relatively minor offence, it's the crimes that follow (theft, destruction of property, etc) that are significant. The same should apply for a cyber-B&E. In fact do you even need a law for breaking into a computer? I wonder if we could simply revise the traditional B&E definition to apply to computers as well.
FWIW: 2-3 years is also too harsh for a first-time offense. There's no corrective outcome you get in year 2 that you don't already have by the end of year 1.
But regardless: the sentences in these press releases have absolutely no connection to reality.
Why do you need to hack in to access it?
Is there something in kernel that is hidden I wonder.