6 ms·
This is the most technically competent charging document I've ever read. I guess there must have been some hackers on the grand jury. Paragraph 35 & 36: which
by runningdogx 15y ago
This is the most technically competent charging document I've ever read. I guess there must have been some hackers on the grand jury.
Paragraph 35 & 36: which "protected computer" on MIT's network did he access? Certainly they're not trying to claim his laptop was a protected computer? Are they talking about the DHCP server or whatever registration frontend MIT has for the DHCP assignments? I have trouble with the concept that a violation of a computer use agreement (when there are no operative security barriers in place) constitutes a violation of the computer fraud and abuse act. Then again, I've always thought that act was vague and therefore overbroad.
Obviously what he did was bad in some sense (at least from the perspective of JSTOR and MIT), but even if it should be a crime rather than a civil dispute or internal disciplinary action at MIT, I don't like the fact that just about any misbehavior on the internet becomes a federal case because the probability of no interstate resources being used is very low.
Finally, I take issue with the notion that someone who is accessing a service through a public interface is criminally responsible for downtime if too high an access rate causes service degradation or an outage. The claims that JSTOR's servers were overloaded and (one?) even went down at some point are clearly there to set up a later claim of damages. Haven't they heard of rate limiting (in this case, since it was a rogue laptop stashed in a data closet, rate limiting by IP)? That wouldn't work against a concerted denial of service attack, but this was no denial of service attack. JSTOR seems to have been relying on manual intervention to stop article leeching that could lead to a (partial) outage. That's naive, and not a good idea.
- mbreese 15y ago> no operative security barriers in place I don't know... Even if my front door was open, you still aren't allowed to enter my house without my permission.
- johngalt 15y agoBut there is an element of permission inherent in DHCP. Your device is actively configuring my device specifically to allow network access. It's not an open door; it's a sign saying "This way please". That said, its obvious this was an attempt to circumvent access controls.
- mbreese 15y agoI'm unfamiliar with MIT's guest setup, but I assume they let you get an IP address, but before you can access anything, you have to acknowledge their terms of service / acceptable use policy. If you fail to abide by this, you'd be accessing the network without permission. You're right that (as alleged), this would be an obvious attempt to circumvent access controls. Given the way things are worded, I'm guessing that the MIT computer that was improperly accessed was a router or switch. Hell, just plugging into the switch directly could be construed as unapproved access to a computer device. I think the Federal law treats anything with a processor a computer.
- derekdahmer 15y agoThe MIT Guest network is actually pretty awesome, it doesn't ask you to acknowledge anything, it just grants instant access.
- pak 15y agoYeah, I think it's a bad argument to personify network protocols or imbue them with intent. Legally speaking, what is more important is the intent of the person using them.
- jholman 15y agoThere's an element of permission inherent in a door! I mean, it's a breach in a wall, specifically put there at great additional expense, just to allow people entry! In either case, an enabling technology isn't inherently an invitation. Again, just because you CAN use a technology to do something, doesn't mean you MAY. And with respect to the comment about "this way please", and the "actively configuring my device", please note that the client initiates the DHCP conversation with a Discovery message. Discovery: "Can anyone give me DC info so I can set up my H, please?", Offer: "Yes, I can, here's one configuration option!" Request: "Yes please, that sounds good, I'll take it" Ack: "Okay, you got it". Note that the DHCP Discovery
- deleted 15y ago[deleted]
- fleitz 15y agoA stranger would probably be allowed to enter the property unless you had posted No Trespassing signs. They'd be required to leave upon request but I'm not sure that simply entering your house via an open door would constitute a crime or tort. An open door could likely be construed as implied consent.
- jancona 15y agoDo you have any basis for claiming that "an open door could likely be construed as implied consent"? I would not advise that you try that in many parts of the US. You'll be risking getting shot, and the homeowner would not have committed a crime.
- 3pt14159 15y agoI suppose the router could be construed as a protected computer, since it had blacklisted his MAC address and it is a computer with an OS.
- rryan 15y agoI think 18USC1030 is pretty broad in its definition of a "computer". Back in the MBTA hacking case, MBTA claimed a magnetized piece of paper was a computer under this clause, and the first judge that looked at it bought that (sanity prevailed and that decision was later over-ruled). I wouldn't be surprised if they are considering the MIT network or at least the routers that were configured to prevent his access the protected computer in this case.
- tghw 15y agoYeah, the switch that he hard-wired into would certainly count as a "computer".
- wiredfool 15y agoMore than likely, the document was written by the prosecutors office. The procedure as I understand it is: * Prosecutor assembles evidence, writes indictment. * Prosecutor presents evidence to Grand Jury. This may include witnesses or documents. * Grand Jury votes on if there is enough there to approve indictment If they've got a computer crimes division, then they're going to have hacker types in the prosecutor's office to do this stuff and get the details right. The indictment is going to be the most slam dunk part of the evidence that there is, as it's written by the prosecutor and there's no counter to it. If it doesn't look airtight, then it's probably a very weak case. Though, looking at it here, It's not looking very good for aaronsw. The combination of mac address spoofing and a locked wiring cabinet show physical and electronic security that was bypassed, repeatedly. That's easy to explain to a jury.
- kragen 15y agoA funny omission is that the indictment never actually says that the wiring cabinet was locked, or how Aaron supposedly broke into it. I infer that it wasn't locked.
- nolite 15y agolocked doors are never a problem for MIT students.. (and apparently even some harvard students)
- kragen 15y agoBut, given the rest of the indictment, I'd think that the prosecutor would be sure to throw in "Swartz picked the lock on the restricted wiring closet in order to introduce the Acer computer," since it would incline the grand jury to be more likely to hand down an indictment — unless she knew this was false.
- redthrowaway 15y ago>This is the most technically competent charging document I've ever read. I'm guessing MIT had a hand in penning it, or at least provided someone who could easily explain the relevant material to the DA/Grand Jury.
- pak 15y ago>I take issue with the notion that someone who is accessing a service through a public interface is criminally responsible for downtime if too high an access rate causes service degradation or an outage Ah... well surely you've heard of people being prosecuted for denial of service attacks? Most recently, members of anon getting raided because they used LOIC? If you use a network in a way that is intended to degrade others' quality of service, even if you are just accessing things via normal protocols at a really high rate, you are breaking the law. In this case, it does not look like they are alleging that he intended to cause a service disruption, but they claim that he repeatedly circumvented measures that JSTOR put in place to halt his unauthorized activities, which caused service disruptions for other legitimate users and therefore denial of service.
- nitrogen 15y agoI don't like the fact that just about any misbehavior on the internet becomes a federal case because the probability of no interstate resources being used is very low. So is that why Comcast routes traffic to networks 30 miles away across three states and back?