Ticketmaster will pay $10M for hacking rival ticket seller
theverge.com
theverge.com
Isn't this a felony? Why aren't these people in jail?
> Live Nation hired a former CrowdSurge employee named Stephen Mead in 2013. Then, now-fired Ticketmaster executive Zeeshan Zaidi and other executives encouraged him to turn over his old employer’s secrets
You know, there are ongoing extradition cases from UK->USA for people who have done far, FAR less malevolent actions than these.
Why are these people not facing 10+ years in jail for hacking?
"The company admitted that it is responsible for the actions of its employees under United States law."
That was also my question why those employees are not in jail yet. I was thinking that company gets fine and employees get jail time but that must be some weird/interesting part of US law.
Indeed. We see time and time again that corporations can get away with almost anything they want without facing any real consequence compared to individuals. What part of US law is protecting these corporations and the people involved when they flagrantly break the law? It's sickening.
...except that corporations are literally just groups of people, the person who perpetrated the act (Zaidi) pled guilty to hacking and is awaiting sentencing?
[1] There are some exceptions, eg. if you're a teacher and you learn about child abuse
Er.... this is entirely the point of the law in the US -- to protect corporate interests. Who do you think are writing the laws? It's not some weird edge case or quirk in the system. Protecting and furthering corporate interests is the system. As always, the purpose of the system is what it does.
My company gets fined $X million, which it doesn't have so it folds. I skip off into the sunset
https://en.wikipedia.org/wiki/Piercing_the_corporate_veil#Fa...
You're going to have to be very careful to avoid that, and even then, you might still be personally liable, see my other comment: https://news.ycombinator.com/item?id=25593629
I agree: these people should be prosecuted. I'd also argue that Ticketmaster in this case was acting as a criminal conspiracy.
Also, the article states that Ticketmaster is under a deferred prosecution agreement for CFAA. So they get to pay a pittance of a fine, and make some internal "policies" and get off scot free.
Zaidi was prosecuted and he pleaded guilty, although his sentence has yet to be determined.
>Zaidi was terminated from Ticketmaster in 2017 and pleaded guilty in Brooklyn federal court in 2019 to one count of conspiring to access protected computers without authorization and to commit wire fraud, according to the deferred prosecution agreement. Zaidi's sentencing has been delayed, according to court filings. CNN has contacted his attorneys for comment.
https://www.cnn.com/2020/12/30/business/ticketmaster-plea-pa...
>Ticketmaster expressed satisfaction with the outcome in a statement
Crime pays off, in the end.
Sadly, this isn't true. As quickly as the old idiots realise that their actions are futile, new idiots are born to repeat their mistakes.
Sometimes, crime does pay. So there's a risk-reward strategy to being the kind of person prone to commiting crimes.
Two years ago, doing X might have been a net negative; now, maybe due to police cuts etc. it's viable. But it's hard to know this in advance; to find out, someone has to walk the territory.
I doubt you can be barred from running a small company (absent being incarcerated which may indirectly/practically bar that).
This is a silly idea if you think about it.
Companies are packets of assets and obligations. Liquidations usually involve shareholders pulling the plug. If the shareholders want the company to keep going but the government doesn’t, when you liquidate the assets, the old shareholders will simply re-purchase them and re-hire the same (or a similar) team. Not a lot done except hosing creditors and enriching lawyers.
Okay, so you ban former shareholders from buying. Who is most likely to be able to do the fire sale diligence? A competitor. Now you have a policy that promotes industrial concentration.
Fine, ban competitors. At this point, few deeply knowledgeable about the assets can bid. In most cases, a deep discount bid will take the cake. So a wealthy person will get assets at a discount from pension plans and individual investors.
Applying concepts like a “death penalty” to legal fictions is emotionally satisfying but economically dubious. I am actually surprised it hasn’t been suggested as a solution by large-company lobbyists. It creates lots of legal work. A back door for wiping out debts. And it enriches wealthy clients while sidestepping real consequences.
Shareholders, who the Board of Directors claim to be beholden to, would lose everything. The company would get liquidated to the highest buyer. Shareholders would be incentivized to not support crimes or strategies that would lead to corporate execution and Board members would be legally bound and liable if that happened.
It doesn't support industrial concentration. All the company needs to do to avoid executation is to not commit the most egregious crimes. Is that really such a hard ask? No, it isn't.
Who do you think gets the liquidation proceeds? If not the shareholders, one, that’s expropriation, which rule-of-law countries try to avoid. And two, that’s easier achieved with a fine.
For businesses requiring a license, suspending licenses could kill a business. Otherwise, “death penalty” is, at best, an expensive way to levy a fine and, at worst and most likely, inchoate.
A fine can be paid and the organization simply continues. But the point of the corporate death penalty is that the organization ceases to operate; executives and board members lose their plum positions in ignominy; shareholders lose enormous value; and the rotten people and incentive structures in the organization are scattered into the wind.
I would be much more amenable with the idea of destroying them.
Any trademarks are revoked, any copyrighted works are now PD, etc. Physical assets are destroyed and put in landfills. If they own a building, tear it down, make it a park.
There are countless names of “hackers” that have sat in prison and are currently sitting in prison for lengthy terms regardless of their intent. A Ticketmaster exec should have to do the same.
https://en.m.wikipedia.org/wiki/List_of_computer_criminals
RIP Aaron Swartz.
Lawlessness will continue until the government starts charging individuals.
I just noticed that the word "master" is in ticket master. With every one renaming git branches etc. why hasn't ticket master been attacked for its "racist name"? Not that I personally give a shit.
More like, taking all the heat so everyone else can keep their hands clean.
>BUDISH: So Ticketmaster takes all the P.R. hit for these egregious service fees. But actually a lot of that money spreads its way around the rest of the food chain.
>MARCUS: It’s actually historically kind of part of Ticketmaster’s business model to take on the burden of that negative sentiment.
https://freakonomics.com/podcast/live-event-ticket-market-sc...
I worked in the space for awhile. Nobody ever mentioned that take in those years. Ticketmaster is good at dividing and conquering the different stakeholders. They aren’t doing anyone any favors imo.
My only idea.
Group-think and blind zealotry have gotten so bad there, even the few pieces of actual journalism they put out are tainted with it. Hard to trust anything they say when you know how many lies they've pushed in bad faith.
https://www.justice.gov/usao-edny/pr/ticketmaster-pays-10-mi...
Same should happen to Anthony Levandowski, but of course things are tricky when you're world leading Self-Driving Cars Expert
There are two sets of laws in that country: those that apply to them, and the other set that applies to you.
Then here's Ticketmaster caught literally hacking into their competitors systems and they get a slap on the hand. No one going to jail, no one becoming a felon, no one's life ruined.
It does nothing to stop what matters: corporations or nation states. Horrible corporations like LinkedIn try to use it. Having the CFAA is literally worse than not having any laws about this. Not only must WE repeal it, the US must go around the world helping people understand that other countries must not enact or must scrap such laws.
Oh come on, I find it difficult to have sympathy for a company that does this.
It's a ticking time bomb, and certainly not hacking.
> Ticketmaster expressed satisfaction with the outcome in a statement. “Ticketmaster terminated both Zaidi and Mead in 2017, after their conduct came to light. Their actions violated our corporate policies and were inconsistent with our values. We are pleased that this matter is now resolved,” a spokesperson told The Verge.
> Today’s judgment defers prosecution under the Computer Fraud and Abuse Act. Ticketmaster must pay the fine in question, maintain clear policies to detect and prevent unauthorized computer intrusion, and present annual reports on its conduct for the next three years.
Revoking credentials of employees after they leave and doing regular audits of the access list, are controls that would be relevant here.
Cyber crime pays.
(I'm bitter, but that wasn't hyperbole - that was the actual award of their last class action settlement for fixing the consumer market)
Surprised it took so long for one of the dirtiest players to get a little slap on the wrist.