https://www.justice.gov/usao-edny/pr/ticketmaster-pays-10-mi...
Telling the judge "but I wasn't wearing my black hoodie while listening to K-pop while doing it!" is going to be about as effective as telling the judge the legal code can't be trusted because it's not backed by a CI/CD system adhering to Agile practices. (Which a non-trivial number of Hacker News posters probably think would work.)
As far as credentials being intellectual property, that doesn't sound quite right but I'm not an IP lawyer and it doesn't really matter.
Like, what would make this hacking to you? The way an attacker gains credentials to access a system does not really matter. If he socially engineered these credentials, it'd still be hacking.
The term is appropriate, but it tends to evoke ideas of serious crimes, when hacking can be much more innocuous acts that often don't see much in the way of prosecution.
If he did that it'd be prosecutable as breaking and entering, and it's perfectly reasonable to use the term "hacking" as the digital counterpart for "breaking and entering".
EDIT: It also looks like you work at Ticketmaster, or at least used to? If that's the case, that's a rather weird thing not to mention in the context of this thread.
I used to work at Ticketmaster. I don't anymore and I didn't at the time of the incident, so it didn't seem relevant to the discussion.
People have been prosecuted and convicted under the CFAA for significantly less.
The CFAA is a terribly abused law, but that is a fair use of the word "hacking".
No, they'd have called it breaking and entering. I don't know what point you think you're making.
No, if someone retains a key to a location after their legal authorization to access the location has been rescinded, and then uses it to access that physical location, that is breaking and entering.
Regardless, "if they committed this crime with physical means instead of digitally, there would be a different criminal charge and a different word for it" is a point that is not particularly insightful, relevant, or interesting to discuss.
The claim was that individuals suffer bigger consequences than people. The person involved was not fined $10 million. AFAIK, they were not prosecuted criminally.
No. This is right up there with "you can't report a person missing until it's been 24 hours" for most common popular legal misconceptions. It would be prosecutable as breaking and entering.
> The claim was that individuals suffer bigger consequences than people. The person involved was not fined $10 million. AFAIK, they were not prosecuted criminally.
Yeah, and that's not the comparison OP was making. If that's what you took away, read again, because you missed their point entirely.
An individual did do this. They did not go to jail.
Trespass vs. B&E is nuanced, and I'm definitely oversimplifying it. The "misconception" is widespread enough that it includes lawyers: https://www.shouselaw.com/ca/blog/breaking-entering-vs-tresp...
Right, and that's not the point OP was making.
> Trespass vs. B&E is nuanced, and I'm definitely oversimplifying it. The "misconception" is widespread enough that it includes lawyers
I'm guessing you didn't bother to read the link you dropped, because it actually undermines your entire claim. Before you pat yourself on the back, you might want to look up what qualifies as "use of force". It's not the way you seem to be using the word.
The only lens through which what you're saying is even vaguely correct is that some states don't have a specific statute of "breaking and entering", instead prosecuting it as "criminal trespass", but even then it's a distinction without a difference: it's prosecutable as a charge for using force to gain unauthorized access to a location with the express intent of committing a felony.
In any case, this whole discussion is pretty pointless, because as I already said, the fact that there's a different word used when the crime happens in meatspace vs. cyberspace is wholly uninteresting and not relevant to the original topic, and - as I also already said - you have clearly misunderstood the crux of OP's statement and so there's no point in continuing down this rabbithole.
That's a good guess, but wrong.
> The only lens through which what you're saying is even vaguely correct is that some states don't have a specific statute of "breaking and entering", instead prosecuting it as "criminal trespass", but even then it's a distinction without a difference: it's prosecutable as a charge for using force to gain unauthorized access to a location with the express intent of committing a felony.
I mentioned that trespass vs. B&E is nuanced, and that I was definitely oversimplifying it. If someone was curious they might have investigated this matter for the relevant jurisdiction. They might even have some familiarity with the case. But that would indeed require more curiosity than someone who doesn't even read a link before they drop it.
> In any case, this whole discussion is pretty pointless, because as I already said, the fact that there's a different word used when the crime happens in meatspace vs. cyberspace is wholly uninteresting and not relevant to the original topic, and - as I also already said - you have clearly misunderstood the crux of OP's statement and so there's no point in continuing down this rabbithole.
Or maybe I just wasn't doing a good job of being clear on the point. There was both an individual and a corporation at fault in that specific case, so you don't have to speculate as to which party was more severely punished. The OP's assertion is flat wrong.