>I concede that it's a bit fuzzy at the moment, but my criteria would be that if a spider could have accidentally crawled this info then it can't be a crime.
I don't think that works as a test either. Spiders index whatever other websites link to. The URLs may have been trivial but if there were no public links to them then a spider wouldn't have followed them. And then on the other hand they would be on another website if anyone (like weev) had linked to them, which you can do just as easily with a link that will cause a buffer overrun, and the spider will then follow it and overrun the buffer. It's completely plausible for a search engine to provide you with a search hit which if you click on it will cause a buffer overflow on the destination server and give you root access to the machine, because some "hacker" posted such a link on their site and the search engine indexed it and put it in the database.
>That's not a valid test. If a company decides they didn't want you to see something after the fact (as in this case) they can always just claim they didn't configured their servers how they meant to.
That's what I'm saying. All prosecutions for "unauthorized access" are like that, because if the server had been configured properly then unauthorized access would be impossible, so when it's discovered that it was misconfigured after the fact, the server operator wants to go back and retroactively label the conduct as unauthorized even though their computer allowed it.
There is certainly a matter of degree as to how far you had to go out of your way to get the server to do something you want it to do, but that is such a hopelessly vague and meaningless line between legal and illegal actions that (as Prof. Kerr has argued) it's potentially unconstitutional, to say nothing of whether it makes for good policy.
>What blaming the victim? The victims were the people who's data got released.
Again, that's the point. The law is stupid. The culpable party here is AT&T for putting its customers' info at risk. The party being imprisoned is the one who publicized the vulnerability rather than the ones responsible for putting it into production. I don't know if I support actual criminal penalties just for operating a vulnerable server, but I certainly take issue with the idea that if you do that and then someone publicizes your incompetence, you should have the right to put them in prison for it based on some vague notion of having gone too far in proving the point.