>
Collecting lists of e-mail addresses from private databases without authorization should be.Unauthorized I can see, but "private"? What was "private" about this database he accessed? It was a public API on a public server with no authentication required.
> Weev said in IRC conversations that he was going to sell the e-mail lists.
Yes, but he didn't. Is he being prosecuted for doing something he said he would do, but did not do? That seems dangerous.
> If someone breaks into your house with safe-cracking tools in his possession, he doesn't have to actually break into your safe to be charged with and convicted of burglary.
This is death by bad analogy. He wasn't breaking into a house, no safe-cracking tools were required (nor, probably, on his person).
Why not argue to the actual point? The list was not sold, distributed, or published -- why is it necessary to fall back to analogy there?
> I don't lock the door to my apartment. That doesn't mean you're welcome to walk in and look around. If we were in Florida or Texas, I could shoot you in the face for walking into my unlocked house and nobody would convict me.
Death by bad analogy, again. Surely you don't think that downloading publicly available data is analogous to B&E? And if the email addresses are so precious as to warrant a 41-month prison sentence merely for accessing them, shouldn't the idiots at AT&T be held at least partially responsible for making the data publicly accessible?
> Obviously this is too high of a bar for people like Weev.
Ah: guilty people are lesser people?
I'm not even sure what Weev's crime was here, in layman's terms. Was it accessing the public API in the first place? Was it sending the list of email addresses to Gawker? Was it talking about doing nefarious things with the list of email addresses? Was it not contacting AT&T first?
If I had to describe this case to someone who knew nothing of computer systems and explain why the 41-month prison sentence was justified, how would I do that?