On that note it seems like his lawyers are performing well, they have challenged absolutely everything in pre-trial motions and there have been some interesting rulings (they've lost almost all of them).
Warrantless surveillance of foreign servers plus the domestic "general warrants"[0], "bitcoin isn't money"[1], his hacking charge under the CFAA[2] and now a likely challenge to the server evidence that was found by "manipulating inputs" (which is interesting to contrast to Ulbricht's own hacking charge).
Both the motion to dismiss and the judges ruling are interesting reads:
http://www.scribd.com/doc/215745393/USA-v-Ulbricht-motion-to...
http://www.scribd.com/doc/233234104/Forrest-Denial-of-Defens...
I'd be interested to know what an experience lawyer or trial specialist thinks of how it has been going so far. I have yet to find a good opinion piece on the topic.
[0] http://freeross.org/feds-silk-road-investigation-broke-priva...
[1] http://www.wired.com/2014/07/silkroad-bitcoin-isnt-money/
[2] http://arstechnica.com/tech-policy/2014/07/judge-denies-silk...
They basically said his attorneys are doing the right thing by going after the warrant stuff. It's pretty standard in legal circles. Go at the base of their argument. If you can get the original warrant through out, it all goes. The only problem is they suspect this is the only real strategy his defense team has right now.
Once the judge rules on this - which my attorney friends believe will be on the FBI's side, his defense team won't have much to pivot on. All the evidence is now compounded and will stick. Which as the article pointed out, is pretty bad for him. It will also confirm his identity as 'Dread Pirate' which a lot of the case hinges on. Once the FBI get that point nailed down, the rest is pretty academic.
The only thing that would make this interesting is if the judge rules against the FBI and hence forth a majority of the FBI's case is destroyed. Both of my friends figured the FBI will drop that case and simply let the federal case on conspiracy to commit murder and hiring a hitman run its course.
Also, keep in mind there are still three other admins that have been indicted. If they get any of those guys to give them more information about Albrecht, it's all down hill from there. They might not even need most of the stuff they entered as evidence if they can get one of these three to roll over on Albrecht.
Pretty much any way you slice it - he's screwed.
This was ultimately to prevent stuff like burglars falling through skylights, then suing the owner of the house they were burgling in civil court while facing criminal prosecution.
I'd be staggered if it was possible to make a relatively weak "authorization" claim stick, seeing as how the police do have the right to investigate things left "in plain view" which you could argue a web server page which you accidentally sent compromising fuzz data too could fall under.
A court would also have little trouble allowing such a thing, since it's a narrow interpretation that doesn't legalize it for the ordinary citizen (though IMO I think it probably should be).
That doesn't make sense to me. You haven't "committed a crime" until you've been convicted.
You seem to be saying that you lose the rights merely by being suspected of a crime.
If that is the case, those rights don't actually exist in the first place.
In the US, they have successfully prosecuted people for "fiddling" just like the FBI did here.
To answer my own question, I guess you could say weev, but I think his troubles really began when he made the pivot from fiddling to mass scraping. I think it's harder to argue the FBI's access was unauthorized when what they were looking at was the "access is denied" page.
The point here is somewhat similar: trying to sue the FBI for unauthorized access to a server would hinge on the relative standing of that law compared to much more serious offences (i.e. conspiracy to murder being the big one) - since the case would have to come from DPR against the FBI, and would thus be subject I suspect to similar tests of standing.
Other people have made the wider point more thoroughly as well - you'd really struggle to prove wrongdoing when all that was acquired was an IP address.
CFAA talks about "unauthorized access", not about any "unwanted" interaction with a computer. Though I think FBI will simply claims that the steps used at that stage of the investigation were implicitly permitted by the fact that it was conducted for a lawful government purpose (there's some fancy legal term for this, but I forget what it is), and wasn't otherwise forbidden to the government since it didn't involve a search or seizure.
If accepted, that would mean that J. Random Hacker doesn't get to mess around with websites just because the FBI got to, even in situations short of CFAA violations.
edit: I guess they could have been providing incorrect passwords for an account that they created. I agree that is easier to call unwanted.
Basically all the analyst said he did was to load the SR website far enough until the captcha popped up, and notice in the wireshark (or equivalent) logs that a non-Tor IP address was reached from the SR website.
If the analyst tooled around on the website after that, then even if the court were to call foul on that subsequent access, the public IP address wasn't derived from tooling around so it (and the evidence derived from that) wouldn't be at risk either.
if i remember correctly an error page leaked an ip in 2012/2013. someone had to realize the captcha was leaking at some point? consider me confused ;)