- `The spoofing was irrelevant; Spitler would have gotten the same email addresses if he had manually inputted the URLs on an iPad rather than a spoofed desktop browser.`, the spoofing is incredibly relevant, it's an important technical detail. Sure he could have sat and put each string in in a long laborious process, but they circumvented that and went straight to the faster option. Once they'd established there was a hole they could have stopped rather than going for the motherlode.
- `if there’s no technical barrier...`, there was a technical barrier, it was just very, very small.
Don't misunderstand me, AT&T are massive idiots for letting a security violation on that scale leak out into the wild, and they should't have been surprised for it to be discovered, but if you're doing live security research and find a hole is taking 114k email addresses a particularly good way to report it?He certainly didn't deserve the ridiculous amount of time that he got, but he's not an innocent in this example by any stretch of the imagination.