Laws take into account indent (mens rea) and there is a lot of evidence in his indictment that he wanted to profit off this act. He shouldn't be compared to Aaron Swartz
Laws take into account indent (mens rea) and there is a lot of evidence in his indictment that he wanted to profit off this act. He shouldn't be compared to Aaron Swartz
He wasn't trying to profit from this. If that had been his goal, he would have been a lot more stealthy.
It's arguable that he had "cleaner" motives in his act than aaronsw -- some people say aaronsw wanted to release all the files he recovered to the Internet (although there's no proof of that); weev just wanted ATT to suck less.
weev has said things far worse than what's alleged in this case (that they wanted to compile a list and direct market the users); yet, if you judge him by what he's actually done, he's just an asshole at times, but basically reasonable. Fortunately just being an ass isn't a federal crime (although I guess conspiracy to be an ass is).
Perhaps it's true, but it's stupid and it's hard for me imagine anyone taking that explanation seriously, certainly prosecutors and judges.
If you walk into a bank with a gun and ask the teller for money, then say "just kidding", .... Good luck.
Weev has always taken anything and turned it into drama. That's the whole Internet Troll thing. A normal defendant wouldn't, when faced with a chance to reduce his sentence by 1-3 years by "accepting responsibility", post something like this to the press. It basically screams "upward departure" to a judge, while at the same time rallying people on the Internet, which doesn't really mean so much inside a federal ass-rape prison.
Whether this should be a felony should relate to how conspiratorial the intent and whether there's a reasonable expectation that the persons whose information is involved will be affected. It does sound like weev was doing something that would screw the AT&T customers involved -- a pretty nasty move.
I wish people could be a little more honest in the way they describe computer crimes. He knew or should have known that that api was not meant for public use. He is being punished for using it despite this knowledge.
And again, of wasn't just wrapping curl in a for loop. It was doing that with the knowledge that the target was not meant to be public, storing that information, and sharing it with the media.
Also, it wasn't murder, it was assault with a deadly weapon. The victim went on to make a full recovery but it was the defendant's third strike.
AT&T's intent isn't really relevant. The fact is, they published all of those emails publicly. They certainly didn't mean to, but I fail to see how accessing public websites can be considered a crime, even if you access lots of them when the company doesn't want you to. If I forget to close my blinds before having sex, that doesn't make anyone who walks by on the street and sees me a criminal. Nor are they criminals if they take a picture and post it on reddit. It's your job not to expose that material publicly if you want it to be private.
>storing that information, and sharing it with the media.
Neither of these are acts that should be considered criminal, just as the storing and uploading to reddit of an embarrassing photo is not criminal. Would it still have been criminal if he had passed the bash one-liner to the media, instead? What's the difference? The responsibility for the leak still resides with AT&T, and them alone.
Now, none of this is to say that I condone of weev's actions. I certainly would have handled the situation differently. But being rude and being a criminal are not synonymous.
In the meatspace it happens all the time that you can get in trouble for being somewhere you're not supposed to even if they forgot to hit the locks on the way out.
Or for a possibly more relevant example, what happens in real life if you find an ATM that has an error such that it gives you twice as much cash as you asked for? Is it still theft if you take it? (Hint: Yes)
Should that equate to a felony here, where no authentication shenanigans were employed? I don't think so, but I wish we'd quit with the victim blaming here on HN.
I also wish we'd separate the enforcability of something from its morality or legality. There's many, many minor things wrong that people can do that even the current state can't hope to fully enforce, but that doesn't make it right, it makes it a fact of life. But if you do somehow get caught doing something that 99% of the rest manage to get away with, shame on you.
By the way, that ATM example wasn't made up: http://investorplace.com/2012/11/faulty-atm-gives-out-extra-... (the Bank opted not to try to find out which customers took the money, due to the difficulty with getting accurate evidence, not because it was right to take the money)
That's definitely not legally true.
wget http://example.com/?id={1..10}In Texas, they don't convict homeowners who shoot trick or treaters trespassing on private property: http://wiki.answers.com/Q/In_Texas_can_you_shoot_someone_for....
Don't act so surprised and imposed upon that a culture that very much respects fences sees something wrong with intentionally poking your nose where it doesn't belong, online or offline.
Yes, the distinction is relevant. Taking photos of my wife in public and publishing them? Creepy but not illegal. Walking through my door (locked or unlocked, it doesn't matter) to take photos of my wife in my house? You're lucky if you don't get shot.
Certainly hacking, and given that he doesn't work for, or is associated with AT&T - some type of criminal trespass - but, we're talking community service here, not a felony. Slap the hand, don't cut it off.
I would hope we can all agree that there is a pretty big difference between a pervasive attack where someone spear-phishes a user inside a company, plants a trojan, and uses that to acquire sensitive intellectual property for financial gain, and/or do damage - versus what weev did - trying some pretty obvious numbers on the public website with an iPad user agent.
I agree, but he's not being charged with felonies for simply poking around. He's being charged with felonies for what he claims he was going to do with the information.
The defense seems to be that he wasn't actually going to do that, but it's the domain of the jury to decide his intentions based on his actions.
When you send packets to an internet-connected device, and that device sends some packets back to you, that is not "trespass". You haven't "gone" anywhere, and you certainly didn't cross any "property lines". Much in the way that the copyright mafia wants to redefine "piracy" from "murder and plunder on the high seas" to "listening to a friend's MP3", numerous other bad people will be thrilled when the public accepts "SYN,SYN-ACK,ACK" as a new meaning of "trespass".
The crime in question was accessing a computer system in an unauthorized fashion
Via a URL accessible to anybody? If I poke around on your website and find your /hiddenstuff directory, am I guilty of a crime?You can't anthropomorphize the web server like that. You cannot say this guy reasonably inferred that AT&T intended him to have access to these e-mail addresses. It's a dumb piece of equipment--a broken door lock. An unlocked door does not mean you are invited to come in.
Now the server provider is responsible for having not adequately secured the customers information, and the guy who asked for that information is responsible for what he does with that information. What I won't accept is that you criminalize the mere request for said information and the retrieval of whatever response is returned.
Please clarify. Are you trying to say that there exists any justification for this idiotic Texanity? Because there isn't, and therefore you can't logically use it to justify this other unjustifiable thing.
Also, sending packets to an internet-connected device, and then reading the packets it sends back to you, is in no sense "trespassing". Trespass is being physically present in a physical location in which you aren't welcome. You can't trespass while you're physically in your mother's basement. Please don't mangle the English language.
http://arstechnica.com/apple/2011/01/goatse-security-trolls-...
If accessing published information (and incrementing a number in an url cannot be considered breaking in ...) is against the law, there is something terribly wrong with the law.
That said if he tried to use the data to extort money from AT&T that would of course be a criminal offense (even if the "intent" was robinhoodian).
To illustrate with an analogy: If someone takes a picture of a hapless drunk girl dancing topless in a bar (AT&T), that is not criminal. If this person approaches the girl and asks for money to delete the incriminating pictures, that is extortion. If the person sells the picture to an interested third party, this might constitute the case for a civil lawsuit (see the texxxan case...)
In any case no special laws are needed for judging behaviour in the virtual world.
This is exactly the same thing that was thrown at Aaron, even if you don't find the target as sympathetic.
"He that would make his own liberty secure, must guard even his enemy from oppression; for if he violates this duty, he establishes a precedent that will reach to himself." -Thomas Paine
"Auernheimer then helped Spitler refine his script to harvest a large number of valid e-mail addresses of iPad 3G users, suggesting that a huge data set would be needed to "direct market iPad accessories" or start a "future massive phishing operation," noting that the data breach would be "huge media news."
This might be offensive, juvenile, or unfunny, but it's nothing remotely close to criminal. The feds took a private IRC log out of context and pasted it into the indictment.
This is not what the prison system exists for, and we are all worse off for using it this way.
Really, if you confess to a crime, and then turn around and say "ha ha, only kidding!" don't be surprised if people find it hard to trust anything you say.
Note: I'm taking what you've said here at face value and otherwise know very little about this case.
Do you guys always know the full story behind the news and comment accordingly? If you do based on the articles you read around, I want to remind you that in Aaron's case what you could read about the case was less than half the truth and there are still things we're not sure.
Unless you know something everyone else doesn't then what is published about the Schwarz case is on the record and in the books. So you're saying that the prosecutors were correct in the charges they brought?
It's really not that hard to compile a list of email addresses from a public API in a way that doesn't violate the law.
That should be "intent", fyi. Legal code is not nearly as whitespace-sensitive as is Python.
I did this because I despised Guido van Rossum, whom I think is unjustly beardy[1], and wanted to embarass him.
I was convicted of two consecutive five-year felonies, and am now awaiting sentencing.
[1] https://dl.dropbox.com/u/14204175/screencaps/AwesomeRossum.j...