Orin Kerr: Why I Am Representing Auernheimer Pro Bono on Appeal
volokh.com
volokh.com
As an aside, I actually think it's clear that Weev's case is a vastly larger injustice than Aaron Swartz's case.
Swartz clearly violated the law in an act of willing and knowing civil disobedience. The law restricts people from unauthorized access to a network; Swartz and the MIT network admins played a game of cat and mouse as they kept banning him, and he kept finding new ways of gaining access to the network. There's no way to argue Swartz didn't realize that he was gaining unauthorized access to a network. At one point he was hiding his face from security cameras; there's no way to spin that as "oh, he thought he was doing something perfectly allowable!" And once caught, he was offered a reasonable plea deal.
In contrast, Weev...fairly clearly did not gain unauthorized access to a network. It was a publicly available website, and no one ever tried to stop him. His actions were at worse borderline, and yet he ended up with a sentence MUCH higher than Swartz.
I have a lot of sympathy for Swartz (not least because of his tragic suicide), but at the end of the day he knowingly and wilfully violated the law in an act of civil disobedience, and was offered a plea deal of less than a year. Weev probably did not violate the law, and was sentenced to years in prison.
Weev needs and deserves help. I had to cheer a bit when I saw Kerr was going to be helping him.
A more apt analogy would claiming that having your phone number not published in the phone book constitutes a legally enforceable boundary against being contacted by phone.
I don't publish my address in the phonebook or anywhere, but because you know that 4001 Example streeet is a house and 4003 Example street is a house, you're still able to solicit me at 4005 Example street.
https://news.ycombinator.com/item?id=5419914
Into the URL bar? (One less than this article's URL)
There is no reason to reduce the world to absurd simplicities when even children would be able to distinguish between various courses of action.
The URLs were public to start with (so that the iPads could make use of it), he just went further than intended by AT&T, but that is not a crime (at least, that is what is argued).
However, scripting that to do it many thousands of times and then collecting the information that results is a qualitative change of behavior. That's not proving a point, or being a responsible security researcher, that's something else.
I agree with the rest of his analysis, but a sufficiently large quantitative change can become a qualitative change just by sheer size.
Still, it made a request to a webserver, and the webserver gave up the data. That's not the requester's fault.
What if you did it by hand? Where's the line between what's ok and what's not?
If we're going to give "security researchers" license to test other people's systems without consent, shouldn't we at least have some understanding that such actions will be narrowly tailored to prove the necessary point?
It takes no longer to write a script to scan an entire range and return all valid results as it does to scan a specific set, and it avoids having to pick known good IDs.
You aren't giving anyone license anyone than the tide needs license to use the beach. You need to recognize that unpassworded sequential URLs are a vulnerability even if you shoot the messenger.
And thus, shooting the messenger, and justifying it, is evidence of someone who doesn't get "it".
How is this different than using Facebook's graph URI endpoints ---- excepting the fact that Facebook publishes the schema?
What if Facebook had some URIs that were not covered in the schema? Are you then liable for a federal felony if you access them? Or are they liable for failing to protect personal information by not keeping it behind an encryption interface?
It may very well be the case that it should also not be illegal, or that we want the common sense solution where it's still "illegal" but not a criminal felony but rather a civil matter (illegal is not a binary flag, after all).
So, a search engine then. Let Google, Bing and DuckDuckGo know they're wanted for questioning.
Also, I've long been of the opinion that if we had somehow gotten to today with no search engines, and Google tried to start up today, that they would be slammed to the ground by lawsuits, which they would probably lose. I consider this a criticism of the law, not the search engines.
I'm not a lawyer so I can't speak directly to "legally" but I believe there shouldn't be a legal difference between a search engine loading a page and me doing it by hand. After all, how would I hand verify what my search engine is saying if doing so might be illegal?
>Also, I've long been of the opinion that if we had somehow gotten to today with no search engines, and Google tried to start up today, that they would be slammed to the ground by lawsuits, which they would probably lose. I consider this a criticism of the law, not the search engines.
You could be right and I would agree the law today is horribly screwed up.
What exactly has changed in the law in the 15 years since Google started up? The CFAA is almost 30 years old...
https://news.ycombinator.com/user?id=paulgraham
https://news.ycombinator.com/user?id=RHashem
https://news.ycombinator.com/user?id=RayinerHashem
To see if I could get any personal information like email addresses, profile information, etc... What if instead of usernames, they were simply integers - I.E. https://news.ycombinator.com/user?id=000001, https://news.ycombinator.com/user?id=000002, etc...Was that unauthorized? How about illegal?
Seriously - I think Weev is a complete Troll, and he was totally hacking AT&T - but I don't think his actions came anywhere close to criminal. I"m really happy to hear he has competent representation.
Is dripping one solitary drop of soda the exact same crime as inundating your yard continuously with soda for, say, 24 hours?
Once is fine. 1000 times is harassment.
Are you purposefully ignoring the fact that the law relies on context to determine if you are acting in good faith or not? Or is everyone who reduces this issue to an either/or position doing so purposefully just because they hate the fact that there is nuance to the law which is much more subtle than the science most of us are schooled in?
Some people would say typing in their own article ID values into a URL bar is unauthorized, but not illegal. Some people would say that typing username ID values to get personal email addresses, is unauthorized, but probably not illegal. Some people might say writing a script to enter all combinations of userids to get username/email addresses on HN is illegal, but probably not a felony.
I was genuinely interested in hearing what people had to say, as I trust our audience here, and let their opinions shape mine.
So you consider it a felony to enter in a browser some URL that has not been been "published". What exactly counts as published? For instance, if I created another page that links to it, is that "published"? Is it still "published" if I later delete that other page? Is it "published" if someone else somewhere in the world creates a page linking to it, but I never create one? What if I print a riddle in the newspaper, which says that the answer to the riddle is the URL in question... is that "publishing" it? What if it's a really HARD riddle? What if I don't print the riddle in the newspaper, but it's a really easy riddle... something like "just add one"?
I honestly do not think that whether you "publish" a URL should be used as an indicator of whether access is authorized. Every web server I have ever heard of has the ability to return a "401 Unauthorized" error code, and to do so or not based on the credentials of the person connecting. If I were writing the law, I would say that guessing a password to put in such a box, or accessing it with a malformed request used a bug in the server to bypass such a credential check would certainly qualify as "unauthorized access", but that "AT&T didn't bother to require a check before returning the data to any browser that asked for it" would be evidence that it was explicitly authorized.
With Weev, you've also got two issues. He was not just convicted of downloading things from AT&T's network. If that was the beginning and end of it, it would have made for a good test case. Instead, he downloaded tends of thousands of pieces of personal information then bragged on IRC how he was going to sell it to scammers to damage AT&T. That's not "civil disobedience." That's malicious.
Note that this is on appeal, so the jury's verdict on the "fraud in connection with personal information" charge is to a degree locked in. On appeal, you don't get to argue: "the jury was wrong, he didn't really intend to sell the information to scammers or to use the information maliciously." The jury is empowered to decide whether they believe the defendant's story or not, and on issues of credibility it's almost impossible to overturn the jury's finding on appeal.
Thus, you're left arguing from a very weak position: yes, the guy did commit fraud in connection with personal information, but changing letters in a URL isn't "illegal access of a network" so the CFAA charge should be dropped. So at best you're hoping for a remand to re-sentence without the CFAA conviction, and the fraud charge by itself carries a maximum penalty of more than 41 months anyway.
However, I think that it's worth arguing from that weak position. I've had a hard time articulating why I think that a) weev's online actions aren't illegal, and yet b) why weev should still be punished. But arguing from that weak position and getting the CFAA charge dropped would actually resolve this issue. My problem with what weev did, and why I think he should be published, is because of his malicious intent. So getting the CFAA charge dropped would be a win for everyone, but leaving the fraud charge in place would still appropriately punish weev (although I think 41 months is too high).
That was discussed, and then not done.
Damaging ATT's reputation via demonstrating how insecure and careless they are, while malicious, is not criminal.
I think this case, along with Swartz's case, and the Alfred Anaya case that was on the HN front page last night [1] all serve to demonstrate that at this point, a criminal act is whatever a Federal prosecutor decides is a criminal act. In the Anaya case, the "crime" of which he was convicted wasn't even illegal under Federal law, and yet he's serving 24 years.
What is so hard to understand about the concept that something may or may not be a crime depending on context? Standing in front of a door? Not illegal in general. Standing in front of a door to keep police from being able to chase a bank robber? That's aiding and abetting and is and should be illegal.
Contrariwise, do you seriously believe that he deserves more than twice the sentence that the people who actually trafficked the drugs got? Do you actually think that your notional door-blocking person should have his case usurped by the Feds and get a stiffer sentence than the bank robber he aided and abetted?
(Edited)
It is now a matter of public record that HSBC, Wachovia, JP Morgan, and others have laundered huge sums of 'drug money' in operations ongoing for many years. So, for those individuals and companies who continue to do business with the banks involved, are they "consciously choosing to profit from facilitating criminal activity"?
Can a businessman refuse service to someone they suspect are involved in criminal activity?
Does a businessman have a duty to refuse service to someone they suspect are involved in criminal activity?
Yes or no: do you think the Feds' actions in this case were kosher? Do you think the Feds pulling shit like that is kosher in general?
Do you believe distributing BitTorrent and Tor should be illegal as well? After all, they're used for copyright infringement and other nefarious purposes, but also distributing Linux distibutions and avoiding totalitarian government surveillance.
If we considered providing everything that could possibly be used for illegal purposes "aiding and abetting" then nearly everyone would be criminals.
Did California have a law prohibiting transporting large sums of cash before? Can you link me please?
You are thinking of the $10k limit on undeclared currency at the border. That's pre-PATRIOT.
"Are you carrying > $10k in cash"
they also ask
"Are you a terrorist?"
and
"Are you a nazi war criminal?"
Has anyone ever checked the "Yes" box to either of those?!
If you refuse someone service because he's black, you are wrong. If you refuse someone service because you think he's a criminal, you are wrong again. If you provide someone service despite thinking he may be a criminal, you are also wrong. It's a lose-lose situation. Best not offer services that may be used for criminal activities. /s
That's a terrible standard. There are some pretty awful things said by Redditors, especially in Weev's recent thread.
I think Kerr's defense of Weev is less for Weev's personal sake than it is for the sake of Kerr's vocation. Either way I'm glad he is stepping up.
That leads me to suspect that Kerr is especially worried about the precedents here, much more than he's worried about Weev's own fate.
This excellent paper is by Karl N. Llewellyn and is called "Remarks on the Theory of Appellate Decisions and the Ruled or Canons about how Statutes are to be Construed"[1] I once read almost the whole thing, and the following quote from the first page sums up his main point pretty nicely.
"The major defect in [the legal system] is a mistaken idea which many lawyers have about it—to wit, the idea that the cases themselves in and of themselves, plus the correct rules on how to handle cases, provide one single correct answer to a disputed issue of law. In fact the available correct answers are two, three, or ten. The question is: Which of the available correct answers will the court select—and why? For, since there is always more than one available correct answer, the court always has to select."
IIRC, he discusses the role of precedent as an important aspect of deciding how to apply the law, but also the ability of a judge to decide to overturn a precedent for a wide variety of reasons. He also discusses the role played by the intention of law makers when passing law, which is ultimately a subjective judgment made by a person, and which is not spelled out in the actual written law itself.
The paper is considered something of a classic, and I would encourage everyone to take a look at it.
[1] http://mtweb.mtsu.edu/cewillis/Hermeneutics/Llewellyn%20on%2...
https://addons.mozilla.org/en-US/firefox/addon/user-agent-sw...
My friend also informed me:
" HTTP has an error code, 401, for unauthorized access. AT&T responded with code 200 meaning OK."
The more one finds out about this case the more incredible it is.
Incrementing a phone number by one doesn't make it illegal to call it. If the person at the end then says "who are you" and you lie, then that's fraud. But if they just tell you something, there's no way anyone can claim that you obtained that information unlawfully.
Luhn is just a check digit, so you could define an increment function that adds one to the base number and then calculates the last digit. Or, you could just iterate over every possible check digit from 0-9.
As a general rule what the machine says has a very strong relationship with whether or not you're authorized to do something. The issue is that if you're not authorized then a properly functioning machine just won't let you do it, which means that it seems impossible for anyone to violate this law against a server that is working properly.
The only way anyone can be capable of breaking this law is if the server is not working properly and allows them to gain access without authorization. Which is why "unauthorized access" is such a vague and hopeless disaster. Going by the normal mechanism for determining whether you have authorized access, namely whether the server allows you to do something, would mean that no one could ever commit the crime, because either you never actually gain unauthorized access since you're prevented by a server with sufficient security, or you succeed in convincing the server to let you do something which under normal circumstances implies that you're authorized.
Seemingly the only way anyone would ever be convicted is based on a pile of circumstantial nonsense about how the defendant should have known they weren't authorized to do something that the server allowed them to do, even though normally you are authorized to do anything the server allows you to do.
So it becomes a de facto law against "doing bad things with a computer" -- not a specific prohibition against anything in particular, just something you stick to anybody who you don't like, because hey, if you did something "bad" then it wouldn't be authorized, right?
If, if, if, if. What Weev did was spoof what kind of client he was using. That's it. What you're suger coating here is using exploits to break into a secure system. That is, you encounter a secured system and find a way to circumvent that security. For the data Weev encountered was there any possible way to get a 401 response for the URLs?
No. Because using "exploits" (not a legally defined term AFAIK) doesn't necessarily mean that access was unauthorized. If you're the sysadmin for a remote server that you suddenly discover you can't login to with your account and that people are complaining that it's sending spam, and you smash the stack on a vulnerable application running on the server in order to regain control and shut it down, I should hope that wouldn't be "unauthorized access" and subject to criminal penalties.
And then there's the fact that "exploit" is a fuzzy and undefined thing. Is changing "userid=4833" to "userid=4834" to get another user's account not an "exploit" but changing "userid=4833" to "userid=0" to get root access is? What if the maximum userid is 65535 and if you use "userid=65536" then it rolls back around and gives you root because it's equivalent to "userid=0" but doesn't get rejected like "userid=0" would? This is no way for a criminal law to operate.
>For the data Weev encountered was there any possible way to get a 401 response for the URLs?
Sure there was. If AT&T had configured their server properly then that's exactly what it would have given him. If I wanted to introduce some irony then I would have to ask you whether you were "blaming the victim" here.
>Sure there was. If AT&T had configured their server properly then that's exactly what it would have given him.
That's not a valid test. If a company decides they didn't want you to see something after the fact (as in this case) they can always just claim they didn't configured their servers how they meant to.
>If I wanted to introduce some irony then I would have to ask you whether you were "blaming the victim" here.
What blaming the victim? The victims were the people who's data got released. Since they trusted AT&T with it that would make AT&T responsible. Everyone is talking about Weev but chances are he wasn't the only person on the planet to know about this.
I don't think that works as a test either. Spiders index whatever other websites link to. The URLs may have been trivial but if there were no public links to them then a spider wouldn't have followed them. And then on the other hand they would be on another website if anyone (like weev) had linked to them, which you can do just as easily with a link that will cause a buffer overrun, and the spider will then follow it and overrun the buffer. It's completely plausible for a search engine to provide you with a search hit which if you click on it will cause a buffer overflow on the destination server and give you root access to the machine, because some "hacker" posted such a link on their site and the search engine indexed it and put it in the database.
>That's not a valid test. If a company decides they didn't want you to see something after the fact (as in this case) they can always just claim they didn't configured their servers how they meant to.
That's what I'm saying. All prosecutions for "unauthorized access" are like that, because if the server had been configured properly then unauthorized access would be impossible, so when it's discovered that it was misconfigured after the fact, the server operator wants to go back and retroactively label the conduct as unauthorized even though their computer allowed it.
There is certainly a matter of degree as to how far you had to go out of your way to get the server to do something you want it to do, but that is such a hopelessly vague and meaningless line between legal and illegal actions that (as Prof. Kerr has argued) it's potentially unconstitutional, to say nothing of whether it makes for good policy.
>What blaming the victim? The victims were the people who's data got released.
Again, that's the point. The law is stupid. The culpable party here is AT&T for putting its customers' info at risk. The party being imprisoned is the one who publicized the vulnerability rather than the ones responsible for putting it into production. I don't know if I support actual criminal penalties just for operating a vulnerable server, but I certainly take issue with the idea that if you do that and then someone publicizes your incompetence, you should have the right to put them in prison for it based on some vague notion of having gone too far in proving the point.
Interesting that a court has already opined this. I don't see any other basis on which one can define what constitutes unauthorized access, than whether the website owner would dislike it. I think, as you have argued, that a court looking for some more technical definition will find there isn't any that holds up under scrutiny.
At the trial stage, you can argue matters of fact. Stuff like "my client was at home in bed when the events occurred" or "those teeth marks don't evem match his dog!"
Since we are now at the appeal stage, barring something huge, all the facts the trial court decided were true have to be assumed true. So he can't now argue that Weev didn't actually access AT&Ts servers. All he can discuss now is whether the court correctly applied the law to the facts it determined at trial, and that means...
...that it won't hamper Kerr at all. The facts here aren't disputed; everyone agrees on what Weev did, how AT&Ts servers were configured, where Weev was, where the servers were, how AT&T responded to the breach. The dispute is entirely down to how the court applied the law (or indeed, whether it was even in the right court), and that's stuff which is best addressed (in some ways, only addressable) at the appeal level.
TL;DR: It doesn't make Kerr's job harder at all; in fact he can only do his job at the appeal stage, as his concerns are very much with the trial courts decision, not with the facts the court based that decision on.
Normally appeals courts only handle the question of whether the lower court applied the law correctly, and assume that the lower court interpreted the facts right. This is because normally (there are a few VERY rare exceptions) it is not legally permitted to appeal on the grounds that the court or the jury got the facts wrong... only on the grounds that the law was applied incorrectly.
All this said, Kerr is only consulting/helping out AFAIK. He is not the arguing attorney (I hope). He's not really a litigator (he has about 3 years of experience in it, most of it from very early days of his career).
I am doubtful that his expertise would have really mattered at the trial stage. You can either convince a judge of something, or you can't.
Why has the federal government turned into such a bully? This feels like a threat to all honest citizens.
I'm all for the representation, but I'm against the trolling nature of HN and alike.
Look at the comments posted the other day. You hated this kid. And still hate him. Only because he claimed to be bigger than he thought he was, which is true.
But, an injustice was still done. Yes, the guy is a tool. A big tool. And he's lucky to have this opportunity. But grow some balls HN. Either flame him again, or apologise, because now saying "Yes he was mistreated" is just flawed.
Where's the flaw in thinking both of these things?
This is not a sustainable power structure and it's going to change. Let's hope the transition is peaceful and gradual for everybody's sake.
Why is it important? If, as Orin Kerr claims, emails were public information, so were names and passwords, if stored under the same scheme. So if he accessed names and passwords, it would be also authorized access by the same logic. But it seems to me somehow Orin Kerr feels the weakness in this argument. Since he doesn't really expects people to believe that if you find a hole in a site that allows downloading account passwords via exploiting some vulnerability in HTTP server sending it some specially crafted data - he feels that it is necessary to emphasize that passwords weren't accessed. But many people consider their personal email no less private than their password - so if it wasn't OK to take the password (and by emphasizing that no passwords were taken Orin Kerr seems to implicitly admit it would be important if the passwords were taken) then it also wasn't OK to take the emails.
On the question of felony though he may have a point. Felony is a grave crime that renders the criminal second-class citizen long after the prison term has been served. I think for non-violent crime that did not result in actual grave harm it is too much, and while I remain unsympathetic to Auernheimer's person, I think if Orin Kerr succeeds in somehow reducing it to lesser grade (or cause a change in the law that leads to that) it would be great.
Do not sentence him to 41months for the fact that AT&T breached its customers privacy and Weev let the press know or for accessing unprotected URLs.