Man to pay $300k in damages for hacking employer
bbc.com
bbc.com
The phrase "hacking" doesn't quite sit right with me either but I guess it's close enough to the truth in this case. I'll personally give them a pass this time. ;)
See this clip from a 1983 film: https://www.youtube.com/watch?v=U2_h-EFlztY
Information security begins with confidentiality, which brings us to the concept of authorization and and the use of encryption. When Bob and Alice want to communicate in secret, they want to assure confidentiality, and they use encrypted messages. Then we also have integrity: when Bob and Alice are enjoying a confidential communication, they want to make sure no one has altered the messages even if they can't read them, so we get hash functions and MACs. Maybe Bob wants authentication: he wants to make sure the person who sent him the message really is Alice, even if he's already sure it's confidential and unaltered, so now we've got digital signature schemes. Eventually Alice decides she wants non-repudiation, or peer entity auth, etc.
Every technical security control can be modeled as the practical implementation of one of these desires for a particular type of assurance. This is neat, because it precludes pernicious questions like, "Well what if it's weak and the 'hacker' just incremented a value in a URL" - we shift the slippery-slope problem of ascribing malicious intent to the legal sphere without sacrificing the cleanly drawn technical definition.
Under this definition, I'd consider the individual in this story to have "hacked" their employer. A login interface is a technical security control designed to provide authorization/access control as a method of implementing confidentiality (among other things). The employee logged in as a user other than themselves, thereby undermining the control. Furthermore, he did it intentionally, which establishes the deliberation requirement. It was not a sophisticated hack, but then again real world hacking very rarely is technically sophisticated.
Despite the composition of Blackhat/DEFCON proceedings every year, the median company is far more likely to be compromised through a social engineering or endpoint failure (e.g. executive is phished, employee pirates media and gets a virus, etc).
EDIT: Apparently this is an unpopular answer, that's fine. But it's an answer that probably goes the farthest and with the fewest rabbit holes. Humans need to trust software in different ways, and if you deliberately break that trust by bypassing the implementation that assures it, you've hacked the software.
That sounds extremely broad, in the same way that calling jaywalkers criminals would be.
Moreover, laws can be broken unintentionally, and under this definition you cannot hack something unintentionally. Awareness can be tantamount to intentionality - I'd argue most people aren't even aware they're jaywalking when they do it. It stretches the boundaries of believability that someone would log in as someone else and not be aware that they did it. In a contrived scenario where they did somehow accomplish that, I wouldn't call it hacking.
I don't really follow your question in this comment and the other one though - what do you mean about CIA desires? You need to understand that a technical control represents a control in order to intentionally bypass it.
if theres a bunch of numbers in my url after i login, and i'm oh so curious what i'd see if i increment that number by 1, now i'm hacking? i mean, i believe the website simply didnt want to implement session control, if i saw someone else's account details, is that acceptable interpretation? there's no "rule of the internet" that says we must only navigate by provided links on a html page, is there?
Under the definition above, if you do it to deliberately bypass the control, then yes. If you do it out of curiosity without believing you might subvert any control, then no you're not hacking.
I draw the line here. If my username/password still work it should be lawful to continue to use. For example if I buy a subscription to a saas product and my card expires, if the service continues to allow me access I should be able to legally use the product until the saas restricts my access.
Logging into work servers after being fired is sorta like coming back into the office and looking at stuff because they didn't change their locks.
I would say yes it's okay.
Instead of "hacking", we need to use specific and correct terms.
No, using an old key that you have no permission to use doesn't convert B&E into mere trespass. About the only way to have mere trespass inside a building (rather than merely on the grounds) is to have your permission to stay revoked while you are in the building.
Nick Tsotsikyan is noted on the about page of the website you linked to.
That's just one of the things he did.
If you're going to be a criminal, at least be a smart criminal. He's going to be stuck with trying to pay off $300k on a fast food worker's wages which will take him the rest of his life unless he inherits a lot of money or plans on winning the lotto. He effectively removed himself from consideration from any decent job and thus his ability to pay the fine in a comfortable manner.
In cases like this, I would expect that $300K to drop later, or to be renegotiated at some point.
>he was found guilty and sentenced to five years of prison, with two years suspended, full restitution of the $6.7 billion which was lost
Good luck with that when
>permanent ban from working in financial services
However, it was pretty egregious, and several incidents. And the amount seems like it's not a horribly inflated number.
(Rockstar/10x dev hunters, come and get it...)