Internet troll “weev” sentenced to 41 months for AT&T/iPad hack
arstechnica.com
arstechnica.com
If I were the judge, I would have sentenced him to maybe 1 year (for releasing the info publicly), maybe made him serve 6 months of the sentence and given him a 3 year good behaviour bond with some conditions on getting some counselling for his obvious narcissism problem. The justice system really needs to get with the times, because these computer related hacking/cracking/exploiting incidents are only going to continue being a more common occurrence. The justice system is riddled with judges in their mid to late 60's who were raised in a non-Internet world and thus cannot truly understand the depth cases like these have or comprehend the extent as to how these defendants should be prosecuted.
Libel, I'm not sure, but I'm American so we have no such laws anyways.
DUI is interesting: its like randomly shooting into a crowd of people and just missing to hit someone.
There is a difference between going to jail for 4 years and just going bankrupt. The first you lose your freedom, the second you just lose your property but can at least keep living. Many people would never recover mentally from being incarcerated for 4 years, but many can recover from bankruptcy.
1. http://www.law.cornell.edu/uscode/text/18/2385?quicktabs_8=1...
http://www.nolo.com/legal-encyclopedia/defamation-law-made-s...
>"I think just banning him from investment-related jobs and imposing some kind of probationary oversight would be sufficient to keep him from reoffending."
Would the ban guarantee he could never re-offend, or would it just limit the scale of any potential future fraud?Given the level of his past fraud and allegations of possible fraud going back as far as the 70s imprisonment doesn't sound inappropriate to me.
The problem is with the wealth he probably has hidden somewhere. If not in prison, he would still be living a very rich life. He wouldn't need any job.
Consider something like $10,000 over 10 years. Enough to notice, but it's not going to make a software engineer homeless. (I think that's too much in this case, but consider non-violent criminals in general.)
If we were to fine weev, for a crime that was otherwise punishable with jail, it should be done as a percentage of his income. 15% would be hurtful enough, I think.
Tons of americans are already swimming in well-intentioned debt that's far worse than the "punishment" suggested above.
The emails were never distributed except to Gawker, who did not publish them - just a redacted screenshot of a few dozen of the .mil and .gov ones with the username and second level domain part blacked out.
Any technical person of course understands that what AT&T did is akin to dumping money on the sidewalk, but you would never know from the cloud of uncertainty and ignorance that permeates these articles. We can't get more specific laws if the understanding of journalists can't rise above the word "hacking".
The reasons why this statement is true would make for a very interesting investigation, methinks.
I have 2 emails: public, and semi-public. My public email is used to register for all sorts of things. My semi-public is only used to register for the most important things, and is posted on several internet profiles as a way to contact me.
Sure, we can say that AT&T is a telecommunications company that should try to protect the customers that pay for their service, but we all know that AT&T is actually a government intelligence agency with all the expected bureaucracy of a military sect. Protecting their customers is #1, and their customer is US Gov.
If AT&T gave a single fuck about its customers, Weev wouldn't have been able to access another user's account by incrementing a number in the URL.
If AT&T gave a fuck about its customers, they wouldn't have destroyed any chance of having a white hat point out security flaws to them in the future, before the black hats find them.
If AT&T gave a fuck about its customers, they wouldn't charge customers $20 a month for texting capabilities that cost them a nickel to provide, or $40 a month for $2 worth of bandwidth.
Should I continue? There are a million other reasons why your statement makes no sense whatsoever.
If they cared about customers, they would be open to criticism when security experts are ready to offer it behind closed doors.
It's sort of a corollary to the idea that all of these convictions are intended to set the precedent that all Internet users are criminals.[0] If the primary purpose of telecos is to serve the US government, and the US government wants to criminalize Internet use, then it would make sense for them to serve "hackers" with hefty sentences in cooperation with the department of justice.
Either that, or you're serious and also an idiot.
ATT is very much overseen by the US military/CIA.
http://www.amazon.com/Shadow-Factory-NSA-Eavesdropping-Ameri...
This book details some of the backroom agreements big telecoms have had for decades that "relieve" them of legal responsibility.
As far as I understand it, the data was publicly accessible and merely visiting the URL output the data he found. I don't view that as hacking.
If you use the word "hack" in front of normal people, they would probably view it as some neckbeard breaking passwords and bypassing electronic safeguards in a dangerous fashion. They would view it as equivalent to that scene from Mission Impossible where Tom Cruise is dangling from wires to break into the CIA or that scene in Terminator 2 where young John Connor gets easy money from the ATM. I use those popular references because that's what most people think is involved when you use the word "hack" when that's not the case here.
This case, if I understand it correctly, literally involved somebody visiting a URL. Whether he did so by typing it into his browser or using an automated program or not doesn't change the nature of the action to me.
However, breaking into someone's car in order to roll up their windows and leave them a note telling them not to do it is perfectly good in my book. So I think it's better when people focus more on the severity of the actual crime committed, rather than on the ease of committing it.
So maybe the analogy works better like this: You're blind and walking around. Suddenly you get to some random car. Being a curious person you touch it to feel what kind of car it is and, in doing so, discover that the windows are rolled down. Reaching inside you also feel that the key is in the ignition. Then the question is, should you go to jail for attempting to steal the car (imagine that blind people are excellent drivers). You certainly did the exact same motions that a car thief would. Which are the exact same motions that a car enthusiast and curious person would do. The analogy breaks down about here, since the guy in the story copied the car by touching it, which we can't do yet.
1. walking away, maybe telling someone
2. sucking up as much private data as you can
Obviously this "hack" was simpler, and AT&T's security was lousy. But the simplicity of an attack is not an excuse for mounting it.
I've written a lot of loops, and incremented a lot of numbers, and none of them have ever become properly escaped XSS exploits, or malformed YAML, etc. If your bar for "hack" is so low that we're training pre-schoolers to accomplish it, it may lack all descriptive power.
URLs are by design human readable and human editable. Simple discovered usage of these resources is not hacking, it is intended.
Imagine you're reading a story at example.com/stories/bears-part_1_of_3.html and just as it gets good, it's done. Without so much as a "The End".
Do you sit dumbfounded, or do you hack the bejeezus out of the website?
See how silly that sounds. So lets just say you "went to the next page".
But it's not the "hack" that you're worried about, it's the stealing. And stealing is separately illegal. Not all stealing is hacking just because a computer is involved, and something that isn't otherwise hacking shouldn't become hacking just because it involves theft or some other malicious activity that would itself be against the law.
Here we have a person accessing publicly available data on a public server. Its analogous to ATT posting customer information in a public alleyway (maybe not intended for public viewing, but within the legal possibility of the public to view), and having someone take a picture of the information.
No violence, no trespassing. Disseminating information left sitting around == Jail. This kind of crap needs to stop.
Him being an asshole doesn't mean he deserves jail time for what he did.
How about rather than deciding he deserves punishment because you don't like him, and then getting upset when anyone disagrees with you, judge his "crime" and decide whether it deserves jailtime. After that, feel free to separately to judge him as a person and decide you won't lose any sleep over his punishment.
So really the proper analogy is that if you've got your windows wide open and are dancing in front of them naked when some perv takes a photo from the road there's really not any legal recourse for you.
Knowing that, why not do it like he did?
The corporations and government can get away with what amounts to murder, yet this troll gets locked up for harming no one?
Where is the victim? Where is the harm?
Does the punishment fit the crime?
Looks like every article on the net about it will get separate topic.