Andrew 'Weev' Auernheimer Faces Jail
businessinsider.com
businessinsider.com
The disclosure was totally botched. The IRC logs that came out during the case showed that Andrew and Dan (Spitler) talked about shorting AT&T stock (they ended up not doing this, but it's not the sort of thing you talk about), and going directly to news organisations, bypassing AT&T. They also considered (perhaps jokingly, but again, not something you joke about) selling the e-mail addresses to spammers.
Andrew also initially told Gawker he'd disclosed to AT&T, when in fact he hadn't (Ars has a good summary here[1]).
I am definitely not saying that a ten year sentence is warranted, or that any sort of custodial sentence is appropriate. In fact, I doubt he'll be given 10 years, more like 2-4 (since his fellow defendant, who plead guilty, got 12-18 months). But I do think the disclosure was handled really, really badly. I've found and disclosed very similar vulnerabilities - I would not leak the entire database out. That's just crazy.
Again, it's the old black/grey/white hat argument again. But to go public without even informing AT&T doesn't endear him to me.
[1]: http://arstechnica.com/apple/2011/01/goatse-security-trolls-...
LOL. If you mean literally nothing than no. But the war on poverty, war on drugs, and 3-strikes means the US justice system is handing out long sentences for black and hispanic males 3x the rate of white criminals.
Even though this guy is no role model, it makes me deeply uneasy to see AT&T get away so easily with reframing their own incompetence as innocent victimization.
The list was never made public.
I doubt they were joking when discussing selling the list, or spearphishing, or spamming it, or pastebinning it. Turns out, though, that that would have been harmful to innocent people - which is why it was not done.
There was no crime here. ATT said as much before the indictment.
But despite my deep feelings of antipathy the charges that are brought against him can NEVER warrant 10 years of prison.
That's ridiculous.
> It is an offense to make a computer perform a function and for that function to be deemed unauthorised by the owner of that computer
This is fantastically broad. I believe it's similar in the US. It's led to convictions for things like directory traversal, XSS testing, and even people looking for vulnerabilities with good intentions. If you're doing stuff like this, be aware of the risk. Some companies are very good about it (Facebook, Google, etc). Others take a far dimmer, litigious view (AT&T?).
These are not laws that are taught in a civics class. I think it's important that until the laws can be changed (and they definitely should be changed) that people in this field know the risks, and weigh them up accordingly.
I agree with you that Andrew's approach is quite...antagonistic. I wouldn't, for example, go on the record saying I think "a sane society would lynch [...] Carmen Ortiz". Personally, I'm not in favour of public lynchings. This isn't going to endear you to the court, or to those who could help change the law for the better.
1) Set up a public server
2) Wait for google bot to show up
3) Press charges against google
4) Sue in civil court
5) Profit.
By altering the number and repeatedly querying the server, Auernheimer and Spitler were able to obtain hundreds of thousands of email addresses, which they then released to Gawker."
===
Amazing that something as simple as that landed him 10 years. This is something even I have done with some servers for telecoms in my country. And trust me, I'm no hacker. I just know basic HTTP GET request parameters, and what asshole doesn't know about those?
The laws in the US are terrible.
Auernheimer crossed a line. The punishment seems excessive, but then again I don't know all the details of what he tried to do with the data.
The fact that he obtusely refuses to recognize that he crossed a line doesn't exactly make me feel sorry for him.
When Sony was hacked and user data was leaked, they received quite a bit of blame. At least they had some semblance of security. AT&T was wide open.
I'm not even going to try to adapt that to your rape scenario. I feel like there should be an equivalent of Godwin's law that I could appeal to in this context.
Let's roll with your scenario -- Do you systematically go through all the cars in the lot? Do you collect personal information from those cars, like names on the insurance? Do you get busted making on-the-record comments about exploiting the use of that data for your own personal gain?
Seriously, weev was hardly being a good samaritan. He was doing something he shouldn't have been doing, made some stupid/incriminating comments in a public forum, then didn't handle the data properly. Worst of all, he's facing serious jail time and is too obnoxious to even admit that what he did might have been inappropriate.
Personally, I'm all for living in a world where you can leave your car door unlocked and not be blamed when someone opens the door. Call it a Godwin-esque move if you want, but I'm just not into blaming victims.
Yeah, and women wearing sexy dresses walking alone without mace deserve to get raped?
Auernheimer crossed a line. Just because AT&T was stupid doesn't make what he did right.
Customers' and the legal systems' dealing with AT&T's incompetence/negligence is a separate matter.
The problem is where the line is drawn, not whether he crossed it.
What Auernheimer did, with intent, was to bypass AT&T's intended use of the system.
What AT&T did was incompetent or perhaps even negligent by a reasonable notion of corporate coding standards. You'd need to dig a bit more to learn how systemic the incompetence/negligence was before attempting to sign appropriate blame, though. Maybe some contractor got into the system and made the change that made that exploit possible the day before and deployed it without following AT&T release guidelines. I dunno. Knowing that kind of info matters, though.
Let's not twist the facts of what happened in order to justify different outcomes.
As to your other point, AT&T is responsible for the actions of its contractors as well as for its full-time employees.
Regarding AT&T, it's not a question of responsibility - it's a question of a level of fault that is negligent. At some level, it's your responsibility because you gave AT&T your data, right? At some level, it's your responsibility because you have an email address, right?
Without a detailed assessment of many factors, just throwing out there that AT&T is negligent seems to be fairly irresponsible.
i don't think he should be imprisoned for exploring at&t's god awful security but i also don't think he should be worshipped.
Those were the charges. Ridiculous in my opinion.
[1] http://www.wired.com/threatlevel/2012/11/att-hacker-found-gu...
It seems clear that AT&T failed to protect their customer's personal details. Whether that makes them criminally liable depends on US law, about which I know almost nothing. This [1] article seems to imply that it is fairly weak compared to European data protection laws, so it may be that AT&T did nothing wrong in a strict legal sense.
While its tempting to think that he was just made an example of for embarrassing a corporation, he did write a script to harvest 120,000 email addresses from the AT&T server. I'd say that constitutes criminal intent, even if he had no intention of using the addresses for a criminal purpose.
There are two problems here: 1. absent or weak data protection laws, and 2. disproportionate sentencing guidelines (up 10 years) for what in this case is basically a victimless crime.
[1] http://www.nytimes.com/2013/02/03/technology/consumer-data-p...
Criminal intent...to do what exactly? Email people? Was he planning to send them spam?
Why are we punishing someone who writes a script? Do we really want to live in a society where programming your own computer is a crime?
Intent to commit a criminal act: "conspiracy to access a computer without authorization". If he'd just accessed a few accounts then that could be attributed to user error or a technical fault, if anyone ever even noticed. Put what he did shows persistent intent to do something which is illegal in the US, even if he wasn't aware of the illegality.
Look, I agree with you. Jailing this guy is manifestly absurd, stupid, and cruel. I was just trying to explain who other people, who may hold differing opinions to you and I and happen to write the law, might see things. Doesn't mean I agree.
If he had sold the data to the Russians, that would have been the criminal intent we're seeking.
Not a crime.
The government is just trying to maintain its power over the people, when federal reserve realizes there is no other alternative except to default on the US treasury, there is going to be a lot of unrest, and the internet will be a focus point of governmental rebellion, it's important everyone who accesses the internet is a felon. Especially the coders, like this one, who will be making the rebellion possible.
You got to put the fear in them. We may be the ones, like our founding fathers, who have to write up a new constitution, bill of rights, and spawn a new nation to break away from the defective one. Like the good men of old time broke away from Britain. The battlefield this time around will not be on the shores of Boston, the battlefield will be software, servers, clicks, and smart phones.
As with all battlefields, the side who wins is the one who prepares the most. This is why we are cracking down on website clicking by programmers, rather than cracking down on governmental corruption.
How exactly do you think uninformed people are voting for what they want? The USA is a country where people are surprised by what is illegal.
Secondly, although I think HN-readers would make great voters on subjects we care about, eg. how the Internet should be regulated, yet I'm sure we'd be mostly stupid and ill-informed about things that we don't know or care about, eg. farming regulations, or sickness benefits for elderly mentally-ill patients, or a thousand other specialized subjects.
That is not the issue. The issue is whether or not we are expected to follow laws that we know nothing about, particularly since ignorance of the law is not considered a valid defense in this country. If you are not running a farm, you are not expected to adhere to farming regulations and you could not violate those regulations. On the other hand, if you use a computer -- and the majority of US citizens do -- you are expected to abide by computer laws.
Right now, there are a lot of laws that everyone is expected to follow but that few people are aware of. Most Virginia residents had no idea that opposite-sex cohabitation was illegal when that law was repealed -- millions of people in that state could have faced prosecution for a law they were never aware of (and in the 90s a woman was threatened with prosecution as part of an attempt to shut down her business). Typically, the police are unaware of these laws and so most people will never be arrested even if they are in violation. On the other hand, when the government wants to prosecute someone (e.g. Alexander Shulgin), all they need to do is look hard enough to find a law the person violated. Sometimes the government seeks nothing more than to set a precedent (Aaron Swartz) that would allow them to prosecute others. That is where the real danger lies: the government is limited not by the lack of criminal laws but by its own inefficiency in searching the legal code.
Most people are entirely unaware of this situation and believe that as long as they are not harming anyone they are safe. It is hard to raise awareness, because most people do not see anyone being prosecuted in this way, and even when they see it they usually have a hard time feeling sympathy for the defendant (e.g. Lori Drew). After all, who can feel sorry for someone who collects this sort of artwork:
http://www.japanator.com/man-arrested-for-manga-collection-t...
Sounds like one of those trite propaganda-esque phrases that don't really mean anything.
Government in the US is far from perfect, but it's not some big conspiracy theory either.
If you want to see a real rebellion, look at Syria. It's people shooting each other with guns to take and hold territory, not some dipshit who finds an inept megacorp's trowsers down and grabs the data he finds and then crows about it.
Reality is too complex to fit into a narrative. Our system manages to be both corrupt and democratic at the same time, with money, fame and influence all helping to distort outcomes, both on behalf of private interests and We The People.
Hard work means "getting out of the building" though.
And ~especially~ in a complete and total police state :)
The amount of felonies and misdemeanors is overwhelming, as is often the severity of the punishments.