Student who hacked Bill O'Reilly gets 30 months
networkworld.com
networkworld.com
[1] http://www.justice.gov/usao/ohn/news/2010/Mitchell%20Frost%2...
The prosecution seeks the max, in this case 15 years, to persuade the defendant to plea the case out. His options are to try and defend himself with no resources (a public defender is worth next to nothing) or make a deal. The prosecutor and judge get to look "tough on computer crime" which will help their resume when looking to advance their careers, and the kid gets to have the end of his 20's. All that is left out is "justice", and by that I mean let the punishment fit the crime. And now society must carry the debt, both economically (housing the kid) and socially - will our streets be safer over the course of his lifetime once he gets churned out of prison.
You're also exaggerating. The defendant does get to have the end of his twenties. He's going to be out of jail when he's 26.
When they accuse him of "fraudulently obtaining user names and passwords and stealing personal identification and financial information" - does that mean he went after this information, or more likely one of the computers in the botnet happened to have such information residing on it. It's possible he didn't know of any financial information and they would throw the book at him anyway just to get the initial charge and work down from there. We all know there are differences in computer crime, that our legal system isn't able to make a distinction does not make an argument.
No it is not possible. Had you actually read the above references as you claimed you would know that after executing a search warrant the FBI found credit card numbers and SSNs on computers in his dorm room. It's in Section 12 of the FBI document. Sure, maybe that was a result of a chat room he was logging. Maybe he didn't specifically go after this information himself. But at the very least he still chose to retain that information on his computer and at worst he did indeed go after the information himself.
Maybe this punishment fits this crime and its the other that doesn't, but marcusbooster's indictment of the system as a whole having some skewed incentives still has some merit, i think.
Talk to businesses dealing with DDoS attacks sometime. They're tearing their hair out and losing real money because of some sociopath's vanity "attack". Why, exactly, are we supposed to look the other way?
Just because it is easy or common doesn't make it any less of a crime.
The reality is even worse than this, as the attacker in question also stole personal financial information (CC#s, SSNs, etc.) from his botnet victims.
Hacking should be something that gets fines only. Let the hacker pay back the cost of his damage, but there is no reason for taxpayers to bear hundreds of thousands of dollars in costs to warehouse these guys with actual hardened criminals whom they will have to make deals with in order to survive in the pen. Then, when they get out, they owe favors to actual criminal syndicates which they formerly had no relation to.
Sheesh.
The only difference between those crime and the crime committed here was the ease with which the Internet allowed it to be committed.
No doubt, the person running the botnet collecting credit card numbers and launching DDoS attacks didn't feel like a criminal. He felt like a prankster. But how is that relevant? I say it isn't relevant. At all. The Internet has a knack for making reality feel unreal. But there is a reality, and it does not give a shit about your message board posts.