MIT Closet Allegedly Used by Aaron Swartz
cryptome.org
cryptome.org
Instead, I saw a small carpeted room containing a half-full rack of telecom gear, featuring several Ethernet switches providing 100 or so switchports for end users, punchdown blocks for terminating phone service to a similar number of incoming lines, and a small number of switchports on what looks like an administratively privileged network via a second smaller switch.
The list price of the larger Cisco with all three power supplies and several 24-port GigE cards was at least $15,000 the last time I had to buy one.
The fiber uplinks to other rooms (provisioned like this one, or better, typically one per wing on each floor of a large building) are likely to carry some very interesting traffic -- not just between end users and their preferred servers, but between the large switches themselves, possibly even routing outbound traffic for the "administrative" switch, as well.
I sometimes use separate "control plane" switched media to access "remote power strips". These allow an admin to remain seated at a desk while rebooting machines all over the campus.
Allowing unrestricted access to a storage closet containing that much gear (uninstalled) is irresponsible. Theft is likely.
Allowing unrestricted access to a wiring closet containing that much gear (provisioned, configured, and running in production mode) is a hilarious wtf. The imagination soars ...
Allowing unrestricted physical access to any administrative switch that carries traffic for power-cycling campus equipment on and off remotely is a fairly serious oversight, and not in the least bit hilarious.
edit: It looks like the photos show two different rooms. The wiring closet itself has a bare concrete floor.
MIT is special in its openness, or at least the Medialab is (you can't really walk in any lab of the Physics department).
If you don't work in network security, you might find it unsettling to see just how much additional trouble a person can cause by having physical access to the hardware itself -- the cables and ports and LCD front panels and the like.
As an example, here's a dirty secret: in quite a few of the large, institutional settings I have had access to, the hash of the IOS enable password is stored on local flash inside the machine, and set to the same string across many core devices. This means that if you can compromise one switch (perhaps a small one in a basement closet), you could also have privileged access to larger switches deep inside data centers on the same campus.
Compromising the first switch is much easier if you can attach a serial console and reboot it at will. If I were serious about doing something like this, I might even bring an extra switch along to substitute in, so the regular users of the network would see no downtime.
Groups of switches inside a data center (when viewed with eyeballs) have a kind of tedious homogeneity to them. Generic faceplates all in rows, kudzu of brightly-colored generic cables fanning out in every direction, armies of green LEDs flashing with traffic, thick black ropes of power cables in back ready to wiggle loose from a stray nudge. Aloof. Opaque.
The traffic to and from each data center switchport, though, is often highly individual. Many times it is deadly dull for port after port after port. But sometimes, you see that you are watching a machine that appears to be processing payroll. Or saving a series of very expensive and proprietary chip masks to some huge file server. Or, best of all, you might see millions of rows of data describing those things and more, all being stored as tidy SQL.
So yes, I draw the line somewhere short of allowing homeless people into a space where they would be sleeping next to network devices with important roles.
MrEthiopian
It always has been.
[1] http://www.justice.gov/usao/ncw/pressreleases/Charlotte-2012... , among many other sources.
"Bank robbery carries a statutory maximum sentence 20 years in prison and a $250,000 fine. Bank robbery while armed with a firearm carries a maximum sentence of 25 years."
It also seems, in addition to armed bank robbery being a crime, having the firearm during a bank robbery is itself is a crime, and the maximum punishment for having the firearm, but not the bank robbery itself, is life.
It seems you are practically correct.
One thing seems fairly clear though: at least in many states stealing harddrives (without using a gun) is probably better than copying the contents of harddrives with a computer. The punishments we have decided that 'hackers' should get are out of proportion when compared to crimes committed 'in meatspace'.
For example, just since I'm already looking at the Californian penal code:
> (c) (1) Any person who commits rape in violation of paragraph (2) of subdivision (a) of Section 261 upon a child who is under 14 years of age shall be punished by imprisonment in the state prison for 9, 11, or 13 years.
>> This subdivision does not preclude prosecution under Section 269, Section 288.7, or any other provision of law.
>> 269: Any person who commits any of the following acts upon a child who is under 14 years of age and seven or more years younger than the person is guilty of aggravated sexual assault of a child [statute lists all conceivable forms of sexual gratification] ... Any person who violates this section is guilty of a felony and shall be punished by imprisonment in the state prison for 15 years to life.
Section 288 adds yet more penalties for using force, being in a position of trust, etc.
You keep using examples of "hackers get stronger penalties than these other crimes" (bank robbery, child rape), but the other crimes consistently have life in prison as a maximum sentence if you stop to read the full context of the law.
I think about security, so I know what you're talking about... but there is a real line between security and fearmongering.
It's just network access, or denial of service. Nothing more.
Then again at the time we had the IRA bombing London and we were told specific bomb threats against the uni from idiots every few months or so.
The alleged JSTOR archive torrent making the rounds is 35 GB. If Aaron went through the trouble of getting a HDD 1+ TB, it means the JSTOR files probably amassed to a size indeed to the tune of ~1 TB, (at least, if he in fact did have accurate foreknowledge of their true size).
It's actually looked down upon fairly heavily if a sign in is larger than a regular signature by very much - typically sign ins are lauded, graffiti isn't.
Just thought I'd clarify. :)
I honestly suspect that things will be better for hackers under Reif's administration. He does, in my humble opinion, "not suck."
EDIT: Also important of note is that Aaron wasn't a student at MIT - historically, MIT students were forgiven for things like hacking, but non-MIT students were typically handed over to Cambridge Police. Typically, when hacking with a non-MIT student, you would pretend they were a 'pre-frosh' if you could.
I assume this is a typo? or is there a recent renumbered bldg?
SIPB at least used to be pretty friendly about letting visiting "reasonable" people plug into the network, based on whoever was at the office at the time.
That's precisely what Swartz's defense team has pointed out -- there was precious little "hacking" involved because there was no defense to hack.
Perhaps Swartz should have chose smarter lawyers then, because he wasn't charged with "hacking" but with "intentional unauthorized access" and other similar things.
It's not as if he accidentally logged onto an open Wifi and accidentally downloaded terabytes of information from JSTOR, they specifically blocked Swartz's machine multiple times. They may not be trying to keep everyone out but they were definitely trying to keep Swartz out (and they didn't even know it was Swartz until he was arrested).
Which was exactly my point. That's why your original comment about "that laptop should've been discovered within 15 minutes" doesn't make sense.
Their network model deliberately doesn't care about an extra random laptop, until somebody complains.
But in general, it does an individual who was trespassing (in this case, on a network) no good to complain that other people were allowed in. There are exceptions to that for MIT since it's a university, but given that Aaron was both white and male, I don't think he'd have been able to play the minority discrimination card.