Pirate Bay founder Gottfrid Warg faces lengthy jail term
bbc.com
bbc.com
- CSC, that handles a large part of Danish infrastructure including social security numbers, police backend, etc. has dismal security. They don't even update their software as security patches become available. Warg had access to their mainframe for 9 months without them having a clue about it. The only reason they found out was because the Swedish police called them and told them.
- username/password pairs for CSC's server were readily available on one of their subsites(!)
- Warg turned off the logs on the CSC mainframe, and they didn't notice. It appears that logs were turned off for months. As a result CSC doesn't know whether data has been altered. We're talking about all police systems, social security systems, and more.
- The police have not had their own investigative team at CSC, and haven't looked at the technical evidence. This has been done by CSC, which is an obvious problem.
- The Danish police was contacted by Swedish police three times during 2012 because the evidence from a Swedish case turned up files from CSC, and the Danish police didn't respond as they apparently didn't find the information important. During the courtcase the Danish police's chief IT investigator was caught lying about this.
- The prosecutor and judge were clueless, bordering on the hilarious, about technical issues. For instance the prosecutor refused to acknowledge that other user accounts except Wargs existed on the computer (there were 5 accounts), tried to paint putty as a hacking tool that only criminals would use, tried to establish Jacob Applebaum and Warg as friends because Applebaum retweeted one of Wargs tweets (only friends do that!), etc. etc.
These are just the highlights...
I understand the ignorance displayed by the judge here, but did the judge also see being Applebaum's friend as a bad thing?
Assuming a retweet is the full extent of their "friendship", this is the real-world equivalent of dismissing an expert witness because the defendant quoted them in a paper once.
Something like a tweet is context dependent. Some people tweet mostly to their friends and a lot of retweets are in fact indicative of a personal relationship. It will often be easy to estimate for a twitter user, but very hard to make objective enough to work as evidence in court.
Do they have just 12 or 12000 followers? Are they tweeting personal tidbits or politics & jokes? etc. These things can add up to an very informed guess.
A retweet is certainly relevant. The evidence makes it more likely that two people are friends than the baseline where there is no retweet.
[1] http://en.m.wikipedia.org/wiki/Evidence_under_Bayes_theorem
The troubles the lawyers had with the tech is noted even by the lawyers themselves:
http://jyllands-posten.dk/indland/politiretsvaesen/ECE716092...
"Hacker case plagued by complex technical evidence" - all in Danish.
What is clear is that Warg's computer was used and contained the stolen records. And JT succesfully denied police access to his encrypted computer. The police were unable to prove his involvement beyond aiding.
- Anakata will get a sentence somewhere in the upper middle. My guess is 4-5 years of which he has already served some.
- JT will get a somewhat mild sentence of nothing higher than 1 year. The case against him is pretty weak, compared to Anakata.
- The case will almost instantly be appealed by Anakata.
- JT may not want to appeal if the sentence is somewhere in the middle of the 2 years window. The reason is the extra jail time he has served will be compensated by the state and the state might be seeking a sentence in the middle to "encourage" him not to appeal. Appealing might increase the sentence and you would be paid less.
The case might go all the way to højestreret, which is the highest court in Denmark. There is also a chance the case could end up in ECHR (European Court of Human Rights), though I feel that chance is slighter. It would depend on the sentence of JT. If it ends up being a conditional sentence, then the jail time he has served is definitely going to have been unfair. As for Anakata, it is a bit more bleak I feel, since the argument of flight from the country applies, like it did in Sweden.
What is really likely to push this to ECHR however, is the inhumane isolation jail treatment and harsh conditions they've both received. It is not at all clear in any way to me why they satisfied the criterion for that at all.
JT was sentenced to 6 months, so he's entitled to compensation.
Source: http://www.version2.dk/artikel/tre-et-halvt-aars-faengsel-ti...
Our prison system terrifies me.
Google: [popehat whale sushi]. One reason you're terrified is that our system (idiotically) goes out of its way to deceptively terrify people. It is in practice not as bad as it (idiotically) tries to make itself seem.
Six years is a long time for what this offense appears to be, though.
('at-fates-hands has more or less refuted this comment, though the whale sushi post is still very much worth reading.)
Here's a list for you: http://www.fierceitsecurity.com/story/hackers-chains-13-bigg...
Up until this week it was Albert Gonzalez for got 20 years for his role in the TJX retail break in. Remember, these are federal sentencing guidelines so no time off for good behavior. You get sentenced to 20 years, you do 20 years, period.
>>> Six years is a long time for what this offense appears to be, though.
This guy is also a repeat offender. In the US, I'm pretty sure with prior offenses with computers, they'd go for a 20-30 year sentence.
Even for completely BS stuff due to the "3 strikes" thing. So in general his fears are not unsubstantiated.
That's not correct. See 18 USC 3624. You can get up 54 days credit for good behavior toward your sentence per year served.
This is the main issue I have with "jail the bankers!" narratives: Just take away their money, putting them in jail doesn't accomplish anything.
This seems to be a big issue with American mentality in particular though. Such a big thirst for vengeance.
Really? Have you any studies to back that up or did you just extract it from your arse?
Seriously, this "do you have studies" BS is getting out of hand. He made an argument (which btw includes more context than what you quoted), and stated his opinion of what would happen in a hypothetical situation. And it's also obvious to everyone who has ever casually conversed that "everyone" in this context means "many people", not literally everyone.
You can disagree and say "That's not what's going to happen because ...", or even "Study such and such shows that this not necessarily happens...".
Asking for studies to back up his thinking is BS. This is not some peer reviewed journal, nor is he writing a thesis. This is a simple conversation. And even if he gave 4-5 studies there would be absolutely no guarantees that those studies aren't crap, aren't invalidated by subsequent studies, aren't only describing what works in some specific cultural context, etc.
This is sociology and human behavior, not physics or math to have some be all end all studies answering specific questions.
Prison, on the other hand, means that society spends a lot of money to make your live worse without any obvious advantage, at least for non-violent crimes.
Yes, and that's a nice solution.
Think about that for a bit.
> the pair downloaded police and social security files.
What exactly are those? and what would he even want them for?
> In a separate trial in 2013, Mr Warg and accomplice were found guilty of breaking into the computer systems of computer services firm Logica, which was doing work for Sweden's tax office and a bank.
Again, why would he hack into a bank knowing so many eyes are on him?
If you want to consider a different perspective: I'm an example of someone who does not have a hard time understand how someone who has enjoyed the rush of getting over on the entire media industry from behind a computer screen might find it harmless or at least personally safe to hack into some dumb server on the Internet and read documents off it.
I've been a pentester for the last 10 years and in my experience, taking advantage of the knowledge of how to break into an application is an urge that takes some energy to suppress.
That's obviously not a normative description. I don't think it's good that the world works like that, although I probably blame different people than most of HN.
Anyways, point being: the assumption that a very smart person wouldn't dream of breaking into a government server: does not at all square with my experience. Doesn't make the assumption wrong; it's just a data point.
Who do you blame, out of curiosity?
Having a capability and advertising it is already stupid in my book, and more the fool I am I slipped up there. But having such a capability, subsequently approaching machines that you have no permission for, repeatedly attempting to gain access, succeeding at that and then to actually retrieve data that you have no right to when you're already in a position of extreme suspicion with the authorities to me borders on the insane. I really can't understand even for one second why someone as gifted as this would act in this way, it is something I've been wondering about with a lot of these so called hackers. What drives them to do this, obviously the downsides of successfully showing off their skill end up in a head-on collision with forces they can't possibly hope to defeat.
It's all fun and games until the SWAT team arrives.
Have there been any studies on the psychology of people that are pathologically drawn to breaking in to other people's computer systems?
If you have a hard time believing anyone would do something like this, look at the 1990s: we got a book practically every year about one hacking group or another breaking into phone switches, credit reporting agencies, government and military networks, and financial institutions. If you can do it, and you're unlikely to get caught --- and you are very unlikely to ever get caught --- why not? Plenty of smart people did stuff like this. Plenty of them.
The most interesting stories from that era did not get written up. Kevin Mitnick didn't write the TCP sequencer. Kevin Mitnick couldn't sequence an ordered array of integers if it was #defined for him in advance.
I know, I know a couple of them. I just don't understand them. Why cross that line? Why risk jail, your career, a whole pile of hardship? The real life consequences is what I'm wondering about, it's as if there is some kind of disconnect there between action and subsequent consequences.
If it is only because it is 'unlikely that you're ever going to get caught' then that's a gamblers argument. (I don't understand gamblers either, so that might be an explanation right there.)
I think part of it is age, maybe. Or rather life-experience, if you will.
I remember back in my early 20s what always stopped me was basic paranoia about getting caught. But that's just how I'm wired personally (and I was probably slightly irrational about the odds). I love breaking, bending and toying with the rules, but too chicken to pull through if it involved anything more serious than a silly prank on friends.
Nowadays (mid-30s), the first thing that stops me is a much more solid sense of what's right and wrong. I prefer it that way, because unlike fear of getting caught, it's a much more solid foundation to depend on.
The mainframe logs show that a dataset containing a copy of the Schengen SIS was downloaded from the hacked mainframe. I don't know if the file was even found on mr Svartholm's computer. The prosecutors just concluded that they couldn't tell what happened with the datat that had been copied out from the system and therefore mr Svartholm probably did something evil with it.
So what's in Schengen SIS? It's a list of personal details for more than 1 million(!!) people that are either wanted by participating states, under surveillance or people that just lost their passports or other identity documents. You can read more here: https://en.wikipedia.org/wiki/Schengen_Information_System#Da...
The government of course would like to claim that the data managed in Schengen SIS is extremly sensitive. Meanwhile they ship this data over the internet with plaintext FTP to various entities participating in Schengen SIS on a monthly basis (updates etc).
>> In a separate trial in 2013, Mr Warg and accomplice were found guilty of breaking into the computer systems of computer services firm Logica, which was doing work for Sweden's tax office and a bank. > Again, why would he hack into a bank knowing so many eyes are on him?
He was completely acquitted of the charges involving Nordea Bank in the Court of Appeals (Hovratten).
I could link to it, but it's in Swedish and pseudonyms were used so you probably wouldn't get so much out of it.
My point is that complaining about your equipment being seized on an internet forum is not a smart thing to do.
They hand out 25 year sentences like candy.
Citation please.
Though I don't see anything definite on prison rates. Hard to get precise info out of N Korea. This absolute dismal circumstances the prisoners suffer is clear though.
On a per capita rate, they would be about even with the United States (around 700 per 100k[1]) at the top end of estimates - which is worrying considering North Korea also practice a policy of "three generations of punishment" where entire families are collectively punished and you have children being born in camps.
The land of the free and the most totalitarian state in the world with a horrible history of human rights abuses - it really shouldn't even be a contest as to who is worse, but unfortunately it is.
[0] http://www.goodreads.com/book/show/13618693-the-hidden-gulag
[1] Doesn't include territories, juveniles, military prison or immigration detention. Including those on parole or probation it increases to 3.2% of the population.
Now the person being tried here is not 21 anymore and he is actually guilty of something and should be punished... but 25 years, really?
http://www.wired.co.uk/news/archive/2013-04/18/social-animal...
CSC is a core part of the military industrial complex. They make mass surveillance databases and military systems and are active globally.
Gottfrid pissed off the both the MPAA and the US military/government. Look what they did to kimdotcom in total violation of law ... the NZ PM had to apologise personally. Gottfrid was illegally extradited from Cambodia. We're yet to see any evidence to the contrary, despite claims his visa was up apparently it wasn't, and this sort of put-on-plane-back-home treatment is not normal.. also, a fat Swedish aid package to Cambodia went through just after his extradition.
Gottfrid's mother is an academic and has documented the strange behaviour of her own (Swedish) government around his arrest and treatment.
Denmark is a place where it's almost impossible to use cash, where the ex-king kept a harem (it's now a bakery/hotel: I stayed in it), and where the authorities don't need a warrant to track your phone's location over the last year.
The accusation is that, sitting in Cambodia, Gottfrid broke in to some computers for no apparent reason causing zero harm. The reality is that he was mistreated against any notion of personal rights, dragged halfway around the world and locked up in solitary confinement which is generally considered torture under UN definitions. He has been passed from state to state being mistreated. There is still no proof he did anything wrong or harmed anyone. However, there seems to be evidence he helped Assange decrypt the embarassing US military video 'collateral damage'.
The only thing I conclude from this ruling is that the west in general is only a downward spiral in to totalitarianism, and that there is now an inter-state, overt attempt to suppress resistance (Assange, Dotcom, Anakata, etc.) with extreme media coverage to try to influence the rest of us.
Where are we to go? How are we to resist? There is the west and its fall-in-line economic treadmill, or the hinterlands and their available extra-judicial means of extradition (ala Anakata) or oppression. Assange's warning about a transnational dystopia seems ever-more pertinent. You know what I think after having met him? Anakata was trying to understand what's going on in Europe and the world at large, and his heart was in the right place. It fits with his character. After all, his mother is an academic, he was raised to ask questions.
Those who question are unjustly treated... the system is the problem. We can use the internet to create change. Don't let cryptocurrency abort as a foetus: it's being regulator-challenged to death. Don't let nominal democracy convince you to be placid. Ask your own questions, force some coverage for your discoveries, and change the world. Do it for Gottfrid.
what ex-king are you talking about?
>and where the authorities don't need a warrant to track your phone's location over the last year.
not anymore the EU court said in April that it was illegal[0]
[0]http://www.b.dk/tech/kaempe-overvaagning-af-danskerne-kendt-...! (in danish)
Given the circumstances, this claim seems obviously true. People who break into computers usually use broken-into computers as proxies.
Often when cases like this are reported, the evidentiary details don't make it into the story. It's easy to understand why someone would have a problem with a conviction when all the information they have is the BBC's 10,000ft summary.
What's worse is, that 10,000ft summary can bias you by framing the whole story in your mind. You're skeptical right off the bat. That's probably always healthy! But it's good to know how your mind is being primed to digest new information, too.
Obviously, sometimes you get the details and the case doesn't get less murky. The Aurenheimer case is an example; I don't have a clue what to think about it, and would like to think that whatever my prejudices are, I'd have been a not-guilty vote in a jury based on that doubt.
There are kinds of evidence that I would find convincing. Testimony from police that he had certain things open on the screen at the moment of arrest (as in the Silk Road case). Or hidden-camera video of him at a terminal, doing something bad. Or an audio recording of a voice call in which he tries to do social engineering.
I haven't found anything like that. If someone posts a link, I'll certainly change my mind. But for know, all the evidence I know of is of a sort that one person could've forged.
That is kind of a serious problem. It's like the "open WiFi" defense. It's completely plausible that someone else actually used your WiFi or compromised your computer, but at the same time some people have this visceral reaction to allowing it as a defense because it's so hard to disprove and can be used by anyone.
That's possibly [1] true, but aren't those broken-into computers almost always the computers of ordinary users? How often do the people breaking into computers use broken-into computers belonging to a computer security expert who knows how to protect their systems from such break-ins?
[1] Not sure about the "usually" part.
I know it's counterintuitive, but all the time. Until only a few years ago, it was almost as if every security expert was being publicly owned constantly. Hackers hack each other.
The dirty secret that explains why they would hack those who can protect their systems: nobody knows how to protect their systems. The best firewall is not pissing off hackers.
https://www.mitnicksecurity.com/about/kevin-mitnick-worlds-m...