5 ms·
This isn't blindly following the law. So someone hacks your site and we praise the hacker and condemn you? Someone breaks the lock to your front door and we app
by coderdude 15y ago
This isn't blindly following the law. So someone hacks your site and we praise the hacker and condemn you? Someone breaks the lock to your front door and we applaud the burgler and make fun of your lock? Get real. I'm sick of this attitude. Just because I understand right from wrong doesn't make me some kind of lackey for the law dogs. People with your attitude convey the wrong message. You don't like Sony, I get it. But you think it's OK to hack people and destroy property as long is it's against someone you don't like and that is not OK.
- bandushrew 15y agoIf I had taken the possessions of thousands of people, and promised to keep them safe in my house, and then a burglar broke in and stole everything. I deserve to be condemned. sure, the burglar should be punished for the simple crime of theft that he committed. but I took the possessions of thousands of people and failed to make them secure, despite promising to do so. Especially if I took all those possessions and then used a 5 dollar lock from the local shop, instead of investing in something that may actually make secure the possessions I promised to keep safe.
- coderdude 15y agoThat is a terrible analogy. It's as if you were given peoples' posessions but you had someone working around the clock to find a way into your home to deface you. You're condemning Sony's engineers for missing something, even if it was a "simple" something. This LulzSec guy, however, did act in malice. He's the one who leaked information, after all.
- bandushrew 15y agoit is a terrible analogy, I agree. I didn't choose it. anyway, lets keep beating on it. If I were to agree to keep the possessions of thousands of people safe under my roof, I would expect to have someone working around the clock to find a way into my home. I am not condemning Sony's engineers at all, I dont know any of them, but even so it is my absolute belief that they knew damn well how broken the system was, and that they told their management repeatedly that it needed to be fixed or customer data could be at risk. I am condemning Sony, if they agree to take my possessions and to keep them secure, they had better damn well expect to have a continuous stream of people deliberately attempting to break in.
- wnight 15y agoHe's, allegedly, the one who made the leak public. Yes. But that data was leaking for a long time and we have no way of knowing who else collected it. If I had thought Sony was secure I'd actually be better off now, with my card visibly leaked, than before where only the bad guys had access to it. If my card was fraudulently used I'd have been in a bad position before the leak was known - I'd be assumed to be a criminal until I proved that I didn't make the purchases. After the leak became public I'd be more likely to get reasonable treatment from my credit card company.
- sophacles 15y agoLet's play the "more appropriate analogy" game: Say you take your valuables to a bank to put in a safe deposit box. They position themselves as a leader in safe deposit box technology. Then one night a burglar notices that the boxes are protected simply by a piece of cardboard panted to look like a real door, and there are no other security systems. Further the locks on the boxes can be opened by merely tapping them in the right place with a screwdriver. He takes your stuff in the heist. Are you pissed at the burgler? Of course. Are you pissed ath the bank? You should be ... But by your logic, we should ignore the facts regarding the bank's complete lack of proper safe deposit box handling and security. Obviously they must have tried real hard, and their statements about good security are no match for the evil burglar.
- coderdude 15y agoThat was not my logic at all. Just because Sony should be held to higher standards and just because they should be in trouble maybe for having a security flaw (like they're the only ones? It's just fashionable to hate Sony's divisions), this doesn't discount my very first point that you shouldn't downplay the fact that this person committed a crime. A very real crime that you wouldn't be defending if you liked Sony instead of disliked them. My problem is we go to hold criminals accountable for real life crimes that you wouldn't want committed against yourself and then you get these online people whining that they are heroes somehow. It's ridiculous.
- sophacles 15y agoI never once declared there wasn't a crime. Nor did defend it. I didn't even declare it should be downplayed. I said it should not be overhyped. There is a difference. Please stop putting words in my mouth (erm.. fingers). You know what I don't want?: to be hacked or robbed. I think it is fine that we hold people accountable for it and punish their actions (provided it is appropriate for the crime). You know what else I don't want?: I don't want my supposedly secured info made available to the first guy with an sql-injection. I think the asshats who let this hacking-101 trick past should also be accountable and punished. It's kind of funny: you seem to think that Sony not be the only people with security flaws is somehow mitigating, but if someone said "Recursion isn't the only hacker your know" you would probably jump down their throat. I think that responsibility should go two ways and you are getting all sorts of worked up over it.
- wnight 15y agoUgh, physical analogies. That's my point. You're stuck in a world of things. Where things go missing or get broken. This is data. Physical laws apply badly, especially when applied in fear by people who hardly seem to understand the domain. A webserver is giving out data. "Hacking" it is just tricking it into not checking what it's handing out. Imagine a webserver as a really dumb employee. "Give documents in the first box, labelled 'public' to anyone. ..." If you've ended up telling that employee to give a copy of your financials to anyone who asks for it, because you forgot to tell them it wasn't a public document, it's your fault. Not only would preventing this in law involve criminalizing many protocol errors and mistakes but it merely serves to hide the real problem - trusting inherently weak security.