Redditor finds list of 47k email addresses with passwords
reddit.com
reddit.com
Google has phone verification now, I guess that's harder to overcome.
Either through automation software or (as you note) mturk style services, pretty much any anti-spam defence can be breached.
Presumably if the list of hotmail accounts was just for outbound spamming then one of the addresses on the list would have been used to send the original phishing email.
If you found a bunch of house keys, each one labled with the address of the house, would you go to each house and open each door? Stepping inside is not necessary.
That of itself, might not break any laws (without prior warning, or intent to cause harm, it might not be trespassing), but computer tresspass laws only require unauthorized access.
I'll agree that in legal terms he's almost certainly the wrong side of the tracks.
It's like the whole "would you download a pizza" statement.
The answer is always, yes, yes I would.
I hope our politicians and law enforcement officials do not treat the digital world like its the real world. Things are just not the same... We need separate rules and separate code of ethics for each.
If you found the keys to a room full of filing cabinets with other people's papers, it wouldn't be right to go open them all. Similarly, if you find a list of credentials that grant you access to the electronic documents of others, it's not right to use those credentials. Of course 'downloading a car' is a terrible metaphor, but comparing electronic documents to printed documents seems very straightforward.
Just assume the passwords work and move from there.
I'm so tired of these analogies. The Internet is not like the physical world. Why don't we talk about what actually happened, rather competing to come up with the worst analogies?
Maybe a seller split up a master list that way. "I'll sell you 50k hotmail accounts".
For a spammer, there's higher throughput to be had per account than going with Yahoo or GMail.
I suppose you could email all of the people on the list, but how effective would that be?
The spammers favorites are hotmail and msn as they are easy to create. Gmail has phone verification and other added stuffs that makes it difficult for bots to create accounts.
The server that redditer accessed could be the spammer's server where he stored the user name / passwd in plaintext format for the bots.