Is Computer Hacking a Crime? (1989) [pdf]
faculty.weber.edu
faculty.weber.edu
> When they joined the discussion on the WELL, Phreak and Optik immediately set off a culture clash. The conflict could be seen clearly in the edited version of the forum eventually printed in Harper's. Like the online forum, and like it's predecessor, The Hackers' Conference of 1984, the conversation opened with a discussion of the hacker ethic. WELL regulars described the ethic in cybernetic and countercultural terms familiar to their online colleagues. Lee Felsenstein compared hackers to the "Angelheaded hipsters" of Allen Ginsberg's poem "Howl." John Perry Barlow described them as solitary inventors designing a system through which humans woule acquire the simultaneous unity of other "collective organisms." Acid Phreak would have none of it. "There is no one hacker ethic," he wrote. "Everyone has his own. To say that we all think the same way is preposterous." Among WELL regulars like Felsenstein and Barlow, hackers were cybernetic counter-culturalists, creatures devoted to establishing a new, more open culture by any electronic means necessary. For Acid Phreak, the hackers were break-in artists devoted to exploring and exploiting weaknesses in closed and especially corporate systems.
I would be really interested to hear how the perspectives of the surviving participants in this conversation have evolved.
Biggest change is probably threat models. In 1990 main concern was individuals hacking systems for challenge, curiosity, etc. Today it's nation-states and organized crime using hacking for financial gain, espionage, even kinetic attacks.
Other change is commercialization/professionalization of hacking. Now huge industry around cybersecurity, ethical hacking, bug bounties. Hacking skills lead to lucrative careers, not just hobby or activism.
More diversity today too - no longer just male techies. But part of cyberpunk spirit remains, even as hacking's become bigger business and political issue.
No hacker context, but a truism.
The law expands to allow capitalism to grow.
Home security has no perfectly secure state.
Were hacking legal, the risk/reward calculation still encourages huge amounts of effort spent on hacking. No matter how robust your programming security culture, mistakes will happen. And the people who exploited them could have HUGE gains. All for only risking having wasted their time in failure.
It’s likely the risk/reword would actually be worse in such a world as fewer things would be possible to exploit for meaningful gain.
Do consider "we're hacking legal" or "hacking the legal system", which is widely practiced by corporatae everywhere. Why should it be OK to hack the legal rules set in place by regulators and not the business rules set in place by a business or individual?
In both cases it typically involves finding loopholes that allow you to get what you normally wouldn't, while complying with de-facto implementation of rules. (E.g. rooting an Android phone you bought, or requesting data from a publicly readable but probably misconfigured S3 bucket).
If someone leaves their front door unlocked, does that give you permission to enter and take whatever you want?
There is this insane notion that if you can accomplish something in cyber space, then you are allowed to. That's not how society works.
There's a big difference when you start talking about destruction of data for others, faking credentials in interactions with a third-party, and/or knowingly causing remote unavailability.
> There is this insane notion that if you can accomplish something in cyber space, then you are allowed to. That's not how society works.
What my previous comment is trying to challenge is the rules-for-thee-and-not-for-me dogma which means that publicly exposing private records of others on an unprotected S3 bucket is an oopsie-daisie while an individual doing a request for it risks ending up in jail.
https://arstechnica.com/tech-policy/2022/02/missouri-governo...
> Gov. Parson's office continues to insist that the journalist committed a crime. "The hacking of Missouri teachers' personally identifiable information is a clear violation of Section 569.095, which the state takes seriously."
> "It is unlawful to access encoded data and systems in order to examine other people's personal information, and we are coordinating state resources to respond and utilize all legal methods available," Parson said in October.
People might not want to use something that disqualified them from legal protection if they used it. It would make tech look unsafe if we just straight up said "This will be hacked and we're not even going to do anything about it".
Early 2000a culture was amazing but I'm not sure I'd want to go back to using cash and not having tile trackers.
Maybe if you had extremely tight limits on what you can do, you can break in but not alter anything for any reason.
But then again, maybe it would have the opposite effect, like in the 90s when we still tried to move to doing as much as possible digitally even though it was almost never secure. Maybe people would just accept it.
It's not worth the risk.
That’s not illegal
What’s illegal is accessing a computer system without the authorization of the owners of the computer system. Technically speaking, port scanning the internet is illegal hacking, as you are not authorized to scan each port number on any of those machines. Ever find a random ip and give port 22 a few random tries over ssh to see if the root password is “guest”, you just committed a federal offense, because you were not authorized to access and attempt to login to that system. Is anyone going to report port scans to the fbi? Failed ssh loggin attempts? (Use a vpn/tailscale and don’t expose ssh to the internet anyway).
I often wonder where “knowing” someone’s password and “hacking” their social accounts falls in this discussion. You see or hear about it all the time. “So and so hacked my page” If you have someone’s FB login info and they have no idea that you do, you may have permission to access FB, as everyone does if you accept their TOS, but you don’t have the account owner’s permission to access their account, and if FB knew it wasn’t the account owner, they would not allow that either. So if they don’t allow that, you’re likely violating their TOS, and no longer allowed to access their systems, so maybe it could technically be able to be prosecuted as illegal hacking, idk.
It sounds to me like you're describing whitehat. Greyhat do these things without authorization, but also without malicious intent.
Somewhat related, the hackers submitting a vulnerability disclosure to the companies are in a very “extortion-y” dynamic. I wonder how often companies get something like “pay us X amount or we let the world know today instead of waiting for you to fix it”.