There are plenty of physical crimes that are easy to commit. For example, opening up someone's unlocked mailbox is technically a federal crime in the US (even if you don't take any thing and just put a leaflet there). Pointing out that a 'bad guy' could easily steal someone's mail by opening their mail box does not constitute security research.
Also: let's say someone accidentally exposes their password because it's on a post-it in the background of a photo. Clearly this is crappy security; clearly, at that point, information protected by that password is readily available until the password is changed.
The intent of the owner of the data does, in fact, count.
Sort of as if AT&T had chosen really bad, unchangeable default passwords for all their users.
The security on a ICCID is arguably better than any of these things. Unless it's transmitted in the clear? I don't know.
This is all silly.
Realistically, there isn't any legitimate reason for me to be doing this to AT&T's website anyways, other than idle juvenile curiosity (which I'll admit to having an abundance of).
I really don't see how. He used the exact same query that AT&T's own script used. The server did not break, or expose any unexpected behavior - in fact it worked exactly as AT&T designed and intended for it to work. I don't think you can pin any of this on weev when it's clearly AT&T who screwed up and provided all their customers' data for the asking.
Look, I'm not arguing that this should be criminal behavior, and it certainly doesn't merit a jail term. I can't tell you how many times I've done stuff exactly like this - probably in the hundreds of times. Is it hacking when I paid $15 for a 1 week pass and then used curl to download 11 gigabytes and 10+ years of the American Journnal of Clinical Nutrition? Probably. But, to give all due credit to the AJCN, they detected my repeated queries, and redirected me to a page that asked me to wait 30 seconds between each query when doing bulk downloads.
So, there is a case where I wasn't doing the obvious (downloading through the web interface), "hacking", if you will, but the AJCN was clearly fine with it, they just wanted me to ease up a bit, and instructed me how to do so in a friendly way.
If weev is guilty of anything, it was not realizing that posting high-profile individuals names onto gawker was probably a Really Bad Idea (TM).
I think the worst part about this is that it once again sends the message to companies that its OK to be this negligent. The law came in and fixed everything, the system works! Bad things were done, the bad people are in jail, full resolution.
I don't feel safer if every hacker ends up in jail. I feel safer when things are too hard to hack, or at the very least not brain dead easy to hack. This is very similar to Sony's response to repeated hackings of their customer's credit card numbers stored in plaintext: "We'll get those perpetrators!" instead of "oh we'll stop being ridiculously negligent now". The arguments of discouraging future hackers with harsh sentences don't work when 15 year olds are doing this all around the world. I want my information protected so that my money can't be stolen, not to receive retribution for it afterwards. If my bank left all the security boxes wide open for anyone to steal from, sure its still a crime to steal from them but I'd be much more pissed at the bank -- I pay them to keep that stuff safe!
I think we have too often come to accept crime followed by punishment as an ideal scenario, forgetting that sometimes there even exists the possibility of avoiding the initial crime in the first place.
Edit: To be clear, ICCID's are not private, they're printed on the outside of the SIM card.