You May Not Like Weev, But Your Online Freedom Depends on His Appeal
wired.com
wired.com
- `The spoofing was irrelevant; Spitler would have gotten the same email addresses if he had manually inputted the URLs on an iPad rather than a spoofed desktop browser.`, the spoofing is incredibly relevant, it's an important technical detail. Sure he could have sat and put each string in in a long laborious process, but they circumvented that and went straight to the faster option. Once they'd established there was a hole they could have stopped rather than going for the motherlode.
- `if there’s no technical barrier...`, there was a technical barrier, it was just very, very small.
Don't misunderstand me, AT&T are massive idiots for letting a security violation on that scale leak out into the wild, and they should't have been surprised for it to be discovered, but if you're doing live security research and find a hole is taking 114k email addresses a particularly good way to report it?He certainly didn't deserve the ridiculous amount of time that he got, but he's not an innocent in this example by any stretch of the imagination.
Whether you agree with his methods or not, there is no stretch of the imagination that makes prison for downloading (even 114k of) them make sense.
It wasn't a hole or bug— it was an expressly implemented feature. ATT decided to do it this way to reduce resubscription friction. The iPad sends the sim serial (ICCID), and ATT sends the HTML form with the email address already filled in, so all the user has to do is enter the password.
As it turns out, ICCIDs are sequential integers.
It should always be perfectly legal to access a remote computer system via a publicly accessible interface. It's up to that remote system to respond appropriately. In this case, it was working exactly as ATT intended.
Weev knew that the greater the number of records he got, the worse it would reflect upon ATT, and rightfully so.
The law can never be this black and white, it is all about context. Just because you may somehow access something on the web, doesn't mean it is automatically ok to do so.
It's pretty simple, really. This would be a non-issue if you programmed your cyborg to go pick up milk from the store and it started handing out $20s to strangers in the dairy aisle. Obviously that's no fault but your own.
Why is it different for a webserver?
It is massively unfair to expect someone to make assumptions about the intent of a remote system, programmed, configured, and deployed by people they have never met or communicated with, in order to avoid criminal liability.
I'm not sure what the problem is here. It seems like simple common sense to me.
Claiming ownership of the money would be like weev selling the email list to spammers, which he didn't. What he did was reveal the defect - like the acoount-holder reporting the mis-deposit.
I'm surprised to see this much victim blaming from such a passionate defender of personal liberties.
There is a stark difference between "AT&T deliberately decided to allow public access through this URL" and "AT&T improperly coded the authentication scheme for this URL".
From the outside the end result would be indistinguishable, which is why your binary logic can't be used in general. If we had it your way the only choice a potential victim would be legally allowed to ever make is "as strong a technical control as available (and don't screw it up, otherwise it's your fault)".
ATT's reputational damage was earned, and was the consequence of facts that were disclosed about their terrible customer data handling practices.
There's nothing criminal at all at any point here. Even what ATT did was shitty, and they should probably get sued for being so careless and negligent, but no crimes were committed by anyone at any point along this chain.
It could very reasonably be argued that in the case of AT&T's system, device IDs count as passwords for accessing the system.
Simplifying things a little, there was an API, which looked somewhat like this:
GET http://example.com/get-email?device-id=123456
> example@example.com
Now, if we replaced that with some sort of bespoke raw socket interface that somebody would have to reverse-engineer: CONNECT example.com:4567
> <somemessage>123456<somemessage>
< <someresponse>example@example.com<someresponse>
Would you still be arguing "it's on the web"?What if I added a field named "password" which always had to be the same value, which was distributed to all devices?
What if it wasn't email addresses, but instead credit card data, or sensitive data such as your race, religion, sexuality, political leanings, medical information...?
I'm not attacking you, simply stating that in my opinion, it's not as simple as "if you can access it, it's public". There's an expectation of privacy for many types of data, especially when the data owner is not explicitly intending to publish the data.
It is not reasonable to have an expectation of privacy if your root password is "password" and you have ssh open to the world, no.
The HTTP spec has a response code, 403, for indicating that a request (potentially without authentication information) is unauthorized. SSH has a similar defined response.
If there's _no authentication around it_, I would argue that it's published to the public web, regardless of the protocol in use to deliver it.
Additionally, the expectation of privacy, in my opinion, covers the data owners (the people who gave the company the data), not the company who is merely holding and processing the data. Although the US has rather messed up data laws compared to the EU, so I am not sure whether this would be true over there.
As you can see all emails are accessible without a password, just a username. This is what was required to get the customers' data from AT&T, serial numbers which are by definition serial and obvious to predict, just like anyone visiting http://www.mailinator.com/ would punch in their own name to see what was there and then try some other people's names.
To make Weev's access illegal there must be at least some form of security like a password that he should circumvent. That would be illegal. Placing data accessible through usernames without passwords is not an obstacle or security measure and should NOT be criminalized because it weakens the law and makes anyone a criminal.
More to the point, users using Mailinator do not have an expectation of privacy regarding the data they gave Mailinator (or that they told other services to give Mailinator). This is, therefore, a different situation.
If I find someone's personal information in Mailinator, that is most likely because a user agreed to allow a service to send their personal information there. In most cases, I wouldn't have any reason to believe any of this data was not intended to be there, unless there were other clues.
In the case of the AT&T breach, two things lead me to believe that Weev violated the privacy of the users:
* It is quite unlikely that users intended to have their email addresses published to the public through this endpoint, and it can easily be shown that Weev understood that - he would not otherwise have chosen the course of action he took.
* AT&T have never publicised this endpoint.
I am not holding AT&T as the victim here, but rather the customers of AT&T whose data was breached. AT&T and Weev were equally complicit in the breach, and AT&T should be held separately responsible.
The system worked exactly as AT&T intended, in circumstances they'd clearly not planned for. If they'd bothered doing a risk assessment they'd have spotted it, they took the lazy option and it didn't work.
The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_.
It's up to that server, and nothing else, to be the final arbiter of authorized/unauthorized. You don't get to move the goalposts after the fact, saying "oh, well we didn't INTEND for you to use it that way".
That's putting the burden to avoid jail on to the requester, who is now responsible for making assumptions and inferring the intent of programmers/admins they've never met or communicated with. It's lunacy.
The social contract of the web is usurped by the legal contract of society, whether or not the way the legal framework is being applied in a just and fair manner is certainly up for debate.
And honestly can you say, hand on heart, that the intention of the AT&T developers was to purposefully leave that hole there? That'd be lunacy. Clearly it's a mistake, an 'oh crap, we didn't think of that'.
Upon going to the wireless account management webpage on the iPad, it would already have the email address last associated with that ICCID (sim card) filled in in the form input element, so that the user would only have to type in their password, and not the email address as well.
It was an express design decision to reduce the number of steps taken by a user to reactivate service. They explicitly chose to weaken the authentication system to increase convenience, and didn't want to do credential management, so they just used the sequential integer ICCID to fetch the email address last associated with that SIM.
Afterward, they said "oh, well, we didn't INTEND for you to use it that way", despite the fact that this is very obviously gross negligence.
It's not a hole - it's a feature they chose to implement.
The bad law that lets anyone, retroactively, define "unauthorized access" by their own attitudes and whims, is the problem here.
>The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_.
DDoS'ing a bank website is against the law, but you are just sending a request to a webserver right? The law will disagree...Again it is all about context. If weev made one request to the website, noticed he was looking at data that he knew shouldn't be available to him, then quit, I'm sure he would be just fine right now. But since he didn't this is why he is in trouble. Again the law isn't binary (to the major dismay and hang wringing it causes on this website), so it is up to the law to determine intent. Was he doing this by accident and should be slapped on the wrist? Or was he doing this maliciously?
He was _absolutely_ doing this maliciously. It STILL SHOULD NOT BE CRIMINAL.
This is a fundamental misattribution of responsibility.
His intent was to defame AT&T as much as possible, using only factual information about their own (negligent) business decisions. This, too, should be legal (and I believe it is).
Incidentally, every time you blame AT&T for what happened, you tacitly acknowledge that wrongdoing actually occurred, which harms your argument that the data was "published".
(In the interest of combating the fundamental attribution error: I'm not happy with Aurnheimer receiving a custodial sentence for what was pretty obviously just another dumb prank. We probably agree that the sentencing component of CFAA is absurdly constructed.)
We're talking about a list of email addresses (which I don't think should be protected data in any way, they're just email addresses) and a journalist running a blacked-out screenshot of a dozen of them.
What abuse of information are you referring to? The part where they sent it to a journalist?
I blame AT&T for being shitty and reckless, not for being criminal.
Also: we both know there's more to the story with Auernheimer than simply sending material to journalists.
Once again, we probably agree that Auernheumer doesn't belong in prison over this particular incident. He was overcharged and oversentenced. But I find the exact philosophy that drives you to that conclusion challenging, which is why I called it out.
Uhh, excuse me? They discussed what could have been done maliciously with the data, and then DIDN'T DO ANY OF THOSE THINGS. I honestly don't know what else you're alluding to.
To answer your main point:
I figured it out yesterday. I believe that sending packets over the internet, of any kind, with any content, is protected speech.
We're allowed to say what we want. It's the responsibility of a listener to determine how they respond.
This is how the world works, and it should be how the internet works, too.
What kind of reality do you live in where malicious intent to cause harm to someone or some group should not be a crime?
Suppose you're an investigative reporter. You regularly investigate a person or company that you feel gets away with too much, whose public actions always skate right on the line, and figure they must be doing something wrong. You feel vindictive about it because you haven't managed to find anything about them in the past. You fully intend to find something to report on that will cause their business harm; it's less about the story at this point, and more about you versus them. You find your story, you report on it (truthfully), and the result is serious enough that their business takes a major hit.
You had malicious intent to cause harm, and managed to cause the intended harm, and yet you've still done absolutely nothing wrong. (Remember that truth is an absolute defense against slander/libel accusations.)
Malicious intent to cause harm is frequently a necessary condition for a crime (leaving aside things like negligence), but never a sufficient one. You still have to do something inherently wrong.
In legal terms, see "mens rea" versus "actus reus".
Breaking into a computer system without permission by exploiting a security hole: generally a crime.
Accessing data made accessible to the general public: not wrong in the slightest, regardless of intent.
Changing your user-agent isn't exploiting a security hole (modulo changing it to ');drop table students;-- ), nor is automated access to a website (modulo DoSing). And embarrassing a company by showing that they made private user data publicly accessible definitely shouldn't be criminal.
As an aside, about a year ago I made a simple web crawler that got (among other things) HTTP headers from all the servers it found. After an hour of crawling, I took the headers to start working on a parser for them, and found 7 attempts at an sql injection. Do I get to prosecute whoever set up those servers?
It depends somewhat on what you class as malice. Starting a business is usually a deliberate attempt to cause harm to competitors, and success at it may well cause thousands of people to lose their jobs, etc.
Particularly when the "harm" here is harm of reputation due the target's public actions? If I assemble a bunch of potentially-reputation-harming data on a public figure and post it on the internet with the clear intent of convincing people that public figure is incompetent, should that be an act that can get me landed in jail? Or is that speech?
Is the automated collection of that data really a thing that should be criminalized? Should it be criminal because or only when it includes identifying information of innocent bystanders?
This is publicly-available information.
Otherwise we end up in the bad situation of having a law which is going to be applied very unevenly, which opens it wide up to corruption.
The social contract of the web is that "you can send a request to any webserver on the internet without permission". That's how the web _works_.
--
Physical analogies may have their limitations when describing the web.
That said, weev KNEW for a fact that he was accessing information that should not have been public.
In other words, he KNEW that he was walking into someone's unlocked house.
Furthermore, he BRAGGED about rubbing it in AT&T's face, and wanting to cause as much damage as possible. He had malicious intent.
So no, his trespassing was not unintended. He didn't happen to just accidentally grab a bunch of email addresses from some web server he sent requests to randomly.
Malicious intent is not criminal.
> That said, weev KNEW for a fact that he was accessing information that should not have been public.
It is massively unfair to put the burden of inferring the intention of a remote system onto the requester.
In fact, he could not have known that he was accessing information that should not have been public (as you claim), because ATT expressly configured their systems to MAKE IT PUBLIC. It wasn't an accident or misconfiguration. Your basic premise doesn't hold up, and neither does the silly physical "unlocked house" analogy.
An unlocked house implies there are locks and doors present, neither of which were in this case.
It's not trespassing, and just because it's non-random doesn't make it criminal.
Don't plug shit into the internet you don't understand.
If that's a problem for you, hire someone who does understand it before you do.
I have no problem with complete deregulation of the exchange of information over the internet, as it's impossible to use violence to force anyone to do anything via an ethernet cable.
It's impossible for a packet to be the root cause of harm coming to another.
Negligence or recklessness when attaching not-fully-understood systems to the Internet, on the other hand, should expose people to liability when the personal information stored in those systems is publicized. The fundamental cause is "idiots plugged in a server without suitable authentication", not "somebody across the world sent it some electrons".
It is crystal-clear to me that all packet transmission should be protected speech, including buffer overflows and other so-called "malicious" traffic.
Just because it's obvious to you (because you are willing to make an assumption) what is malicious and what is not, that doesn't mean that it's anything resembling fair to force others to make those assumptions to avoid criminal liability.
The full text of War and Peace could be "malicious" traffic when sent to a machine that stupidly copies it into a fixed-size buffer. This is not a job for the law to decide. It's a blunt instrument.
(There's also the issue of the stupidity of allowing the receiver to retroactively declare "oh, that was not intended, and thus unauthorized".)
The responsibility must always lie with those who interpret the traffic, not those who send it.
Frankly, you're just torturing some unclearly defined terms ("Information Published on the Web", or "Expressly Designed Feature", or "it's up to a Remote System to respond appropiately") to make a point. Thing is, most of those terms are not legal, well defined terms; and when they are, your interpretation is lacking. You'd have a hard time convincing any judge that a company expressly desired to publish email directions of all of their customers, via some opaque and undocumented URL manipulation.
Disclaimer: I don't agree with weev's conviction, and some of its aspects are outrageous ("conspiracy to access a computer without authorization"?). But this "it was public information" angle is just bullshit. It's just badly reasoned.
AT&T admitted in court during the trial that they had published the email addresses on the web.
That's what "publishing" is, these days: putting stuff on a webserver without authentication in front of it.
There are clearly cases where the mere fact that someone has left something somehow exposed to a web browser does not connote authorization to access it. Those are the cases where a reasonable person, seeing what the data is after stumbling across it, would understand the exposure to have been a mistake, and not an authorization.
An analogy is if your bank left your money easily accessible on a table in front of the bank without security. We are used to the idea of ownership, but this issue is a matter of blame. Here AT&T is the one to blame for the lack of security, not someone who saw that AT&T lacks security.
Back to the bank analogy, it is not the public's duty to guard your money for the bank. Nor should someone else be jailed for money literally left outside on the table.
"This is, literally, an argument that if you stumble across a text file full of credit card numbers, expiration dates, and CVV codes, it should be lawful for you to put it up on Pastebin."
Which, when carders are caught on forums doing the above, they are charged with wire fraud.
I agree with you completely that I don't think Weev's acts were wire fraud.
"...or promises, transmits or causes to be transmitted by means of wire, radio, or television communication in interstate or foreign commerce, any writings, signs, signals, pictures, or sounds for the purpose of executing such scheme or artifice..."
I think the government would have a relatively easy time arguing that posting people's credit card information (specifically all the data necessary to make use of that person's funds) is a scheme for "obtaining money or property by means of false or fraudulent pretenses".
The defendant's attorney might argue that just posting the information isn't itself a scheme (in the same way that say, listing the home addresses of members of rival ethnic groups over the radio in Rwanda isn't an incitement to violence), but if I were that defendant, I wouldn't be sleeping easy.
We already have laws to prosecute people who misuse credit card numbers for gain. Either attack the edge (ppl who use the cc nums for fraud) or the root (the people who posted them on the public web).
To be clear, that's exactly what Weev did -- accessing AND keeping a copy for himself. But I think the parent comment's argument is talking specifically about access.
Creating a precedent where a "reasonable person" is expected to "understand" that the exposure was a mistake would create a huge legal gray area. Anything that's available on the public internet should be perfectly legal to access. What people do with that content is a different matter.
Since that would be a clear and basic PCI violation, yeah, it sucks for the merchant and their customers. Why have PCI compliance at all if the merchant can just throw up their hands and blame it on "hackers?"
It's unreasonable for us to expect the legislature to get this right. Nothing here is criminal.
By this logic, any information stored on any computer accessible via the Internet is published, so no unauthorized access to any data not behind an air gap is illegal. Including breaking into your private mailbox or your online banking account. I don't think I'd be ready to accept this. Are you?
However as a third person it's also useful for me to know the scope of this hole and how liable my own information was. Weev here is guilty of exactly the same reasoning that AT&T realised in court which is that a message is irrelevant without impact. And which has more impact: an article about how a vulnerability in AT&T security could have resulted in some leaked emails or an article about 114 000 potentially leaked email addresses?
It's fucking ridiculous that changing the user agent, even to circumvent server "protections", would be a crime worthy of any jail time whatsoever. What is he guilty of? Criminal misrepresentation of web browser?
The answer is obviously no and if you can't make it public without risking being sent to prison the only option is selling it to some shady spammers.
Which would you prefer happened? From my point of view what they are doing is basically pushing the hackers to the "dark side". If we disclose it we get arrested if we sell it we might get caught and arrested or make a lot of money. I'll take option 2.
I think the industry basically needs to take the informal responsible disclosure rules and try and get them made a bit more formal, for everyones benefit.
* "AT&T representative testified its reputation suffered as a result of the hack"
No, their reputation suffered, because they were incompetent. Ironically, without this trial I would have never heard about this.
* "At sentencing, instead of hearing about the effects of the iPad “hack,” the government recounted in detail Weev’s “attitudes” towards others on the internet."
That is because of the adversarial legal system in the US. All that matters is to sway an uninformed jury. The specific matter of the case is almost irrelevant as long as the jury comes to a "guilty" verdict.
Lastly, this reminds of a civil version of the current Snowden debacle: Attempt to prosecute anybody who reveals wrong doing or incompetence.
All of that said, I wholeheartedly agree that damage to reputation (where such damage comes only from revelation of the insecurity) is the fault of the people failing to live up to their reputation, not those exposing the reality of it.
My point was just that we respect and enforce limits by means other than technological, and it's correct that we do so.
If the prosecutor is able to make you seem unlikable, or you do it to yourself, you most definitely increase your risk of being convicted. Mr. Auernheimer strikes me as somebody who enjoys being shocking and perhaps unlikable in the traditional sense, which is not an ideal situation in court.
Defending free speech means standing up for people who have controversial views - no matter how unease you personally are with these views.
It's easy to support free speech when all you say or hear is motherhood and apple pie. It's the things that make people uncomfortable that need protection from censorship.
Agreed; things like "Fire!" when there isn't a fire.
He'd been on their radar for years due to his unpopular speech.
Also, if you're already on the FBI's radar, wouldn't you think it be smarter to lay low and wait until things cool down before you start hacking again?
I think he's despicable, but he's also my friend if only because he is willing to do whatever is necessary to stand up for what he believes in.
If you're already familiar with the background of the case, for the meat of the argument on appeal, skip to p. 15 (26th page of the PDF), starting with "Summary of Argument". That section lays out the five objections being raised on appeal, and is then followed by five sections making the detailed arguments.
edit: direct link, https://www.eff.org/file/37297#page/26/mode/1up
A link to the Craigslist vs. 3Taps spat in this article brought back memories. Craigslist had also threatened me with a C&D letter suggesting they'd use the CFAA to lock me up. I contacted the EFF who promptly told me to go screw...
I assumed that was because Craig is on the board of advisers and CL was a major sponsor. I'm glad to see they're finally helping someone against the giant internet bully that is CL.
That simply says "Your email: ...@gmail.com will be updated when we have info on the case. Thanks for your interest" 4) Let people "find this" 5) Get lots of people to report on the problem 6) Fix the problem after the press gets it 7) Freeweev.com takes everyone to criminal court under CFAA. No lawyers necessary, just tell the Judge that there appears to be no difference in these cases as the AT&T case, all of these people that hacked our site should go to jail for 41 months. Also make sure that this involves MANY people. 8) Legal breakdown, no software development for anyone (like the screen-writers strike right?)
http://att.com/email?phone=555-1212
And Weev noticed this and wrote a for loop to try all phone numbers. curl http://domain.com/showdocument?[00000-99999]
should not be a crime!!Don't you think that the consequences should depend on what the action actually accomplished, rather than the action itself? Flicking a lighter is generally pretty innocuous, but if done to light a house on fire, it means it's a bit different - right?
Yes, it's their fault too for leaving it open, but you had a choice when you decided to access it N000 times, rather than saying "oops, that does something bad, I think I'll stop".
I don't think the punishment fits the crime in this case, but I don't think he's entirely innocent either. Once you've shown that someone stupidly left their door open, the polite thing is to let them know, rather than walking around in their house looking at all their things to show them the error of their ways. IMO a fine would more than suffice as a punishment, though.
Shouldn't you hold the people who created that system responsible, rather than the person who used it? If I rig up my cell phone to a gun, so that every time someone calls it it shoots at a crowd of people, should the people who call it go to prison while I walk free?
He knew what he was doing once he'd pulled down a few records.
Also, yes, ATT should be held responsible for implementing lame security.
No one here is. I'm not sure why no one has done anything to them, legally. It'd be interesting if someone who actually knows what they're talking about in terms of the legal system about could comment on it.
(a) Even altering a parameter once in the address could be considered illegal under the current laws.
(b) The access of information in and of itself would not be illegal alone. Say I kept a bunch of people's information in paper files in file cabinets. Then I gave you access to retrieve yours from the file drawer yourself. It is sleazy, but not necessarily illegal to look at other files in the drawer, as I have given you access to their container.
(c) Even if you want to make the action in (b) illegal, the reasonable punishment is almost certainly not a double digit prison sentence.
I honestly don't even know where I stand on the actual discussion point, but I do know where I stand in the weird analogy tree we've made.
Bringing things back to reality here, AT&T was entrusted with personal information but failed to properly secure it. They set up a system that automatically responded to requests for personal information. They gave unauthorized people access to that system. We should be blaming AT&T and making them pay punitive damages for their irresponsible behavior, not whining about how terrible Weev is for using the system they gave him access to. The fact that AT&T can just shrug it off is what allows the sorry state of security to persist.
But giving them to a responsible journalist for whistle-blowing purposes is not a crime. It's a public service.
In this case there is no crime. And I repeat this again, AT&T was behaving like http://www.mailinator.com/
The RFC says at the point 9.1.1 that: "Naturally, it is not possible to ensure that the server does not generate side-effects as a result of performing a GET request; in fact, some dynamic resources consider that a feature. The important distinction here is that the user did not request the effects, so therefore cannot be held accountable for them."
If I'm missing an important distinction you'd make, I'd very much like to hear what it is.
So Weev should not be punished for downloading the email addresses. AT&T should be punished for making the list available to him (and likewise, if Weev made the list available to others, he should be punished for that).
Anyway, as I understand it, weev did speculate about selling the information. And would you be so sanguine if this were health records or private photographs? I'm not seeing a plausible guiding principle here.
I also draw a line between what makes me upset and what should be a crime. I do not think that everything that makes me upset should be illegal. Frankly, while I would be angry at Weev if he downloaded hospital records, I would be much more angry at the hospital that failed to secure those records. I believe that the law should draw the line at how the information is secured and how it is used, not how it is obtained.
Weev has taught many of us that acquiring your private data is enough to make you wonder when, exactly, he will decide to use it. Or in my case, to publish it and encourage the whole WORLD to use it. And don't get me started on medical records... If you honestly believe that acquiring private data shouldn't be illegal until it is used in a crime, you have obviously never been threatened with exposure from someone who did just that. (but again, I don't think this applies to the AT&T case) -- Kathy Sierra
The problem with charging hackers for having information they are not supposed to have is that it takes the responsibility to keep data secure away from those who are entrusted with it. Take medical records as an example. Yes, we want them to be kept private, but that should be the responsibility of hospitals, doctors, etc. If some hacker downloads those files, the hospital should be punished for their failure to keep the files secure. If we want to believe that hackers are magicians and that any Internet-connected system can be compromised, don't connect systems with medical records to the Internet.
What is wrong with making it the responsibility of anyone who has private information to keep that information private? If a hacker downloads a hospital's records, I think it is fair to expect that hacker to keep those records private, and to prosecute the hacker if they are revealed to anyone for any reason (even if the hacker is himself a victim of another hacker).
People should not have to be afraid to run a web crawler out of their own house. Yes, a web crawler is going to find private information that was not properly secured. That should not make the person running the crawler a criminal.
"Brute force" is literally an attack. However what AT&T did was only use the equivalent of usernames just like http://www.mailinator.com/ does.
So why have we not deployed this "amazing" technology, or similar technology, everywhere? A lack of incentive. If a hacker successfully carries out a brute force attack, the company running the systems does not suffer at all; they just pass it off as "some dark wizard hacker pwned us, sorry!" Nobody is spending the money to deploy smartcards far and wide because nobody has any reason to. It is less expensive to pay the pittance required to clean up after a hack than to stop hacks in the first place. If banks had no legal recourse when some script kiddie hacked a customer account, they would be far more likely to give customers smartcards and use more secure authentication mechanisms.
To put it another way, making a brute-force attack a crime is placing responsibility for securing the system on the people who want to attack it. It should be obvious why that makes no sense.
Websites are served in an attempt to disseminate them.
There's a big difference here.
In a just world, we would let full responsibility lie with those who deployed the machines without understanding the consequences of, e.g., no login failure rate limiting.