10 ms·
Jail Looms for Man Who Revealed AT&T Leaked iPad User E-Mails
- rcknight 14y agoThe article states "Weev and a fellow hacker who originally uncovered AT&T’s mistake and collected the e-mails didn’t ask the company for permission to access the Web addresses that shared iPad users’ private information" I really don't see how this argument holds up. From a technical point of view the very nature of HTTP includes asking for permission. You send a request "Please can I see the information at this URL" If the organisation running the server does not give that permission, it should not serve the data. These charges seem pretty odd to me, hopefully it gets resolved in a sensible manner.
- robmurrer 14y ago>> required visiting an AT&T web address with a particular – and easy to guess – code tagged onto the end. How is this different than a password?
- rapala 14y agoI guess this is exactly the thing that the court must decide on: whether guessing that code can be considered as a circumvention of security measures or not.
- josteink 14y agoFollowing that logic breeds bizarre results. What if you find this magic token because it was embedded in some client-side, javascript login-form? Are you a hacker for viewing the source? Securing content on the internet is easy. If you don't want it accessible to anyone, don't give the content to anyone who provides an unauthenticated HTTP request. Why are we putting the legal responsibility of maintaining security on that content on everyone except the ones actually in position to do so?
- robmurrer 14y agoIf I look under your doormat, and there is a key, and I use it to open your front door...
- josteink 14y agoRather if you leave a (possibly classified) document under your doormat, am I a criminal if I find them and read them?
- rapala 14y agoDepends on the document and jurisdiction. If I remember correctly, some levels of military classifications here in Finland require you to not read the document and return it to the officials. Of course the one who left the document would also get reprimanded at least. Using someones password without permission is as illegal whether you shoulder surfed it, cracked it or red it from a post-it note.
- nitrogen 14y agoA house's front door implies an expectation of privacy. A web server implies an expectation of public access.
- josteink 14y agoSomeone can provide you with a clickable link, as in for instance this submission, and you would never even know that the content you are accessing is supposed to be "protected".
- robmurrer 14y agoI see your point, but how does this apply to this case?
- gabemart 14y agoYou can format a link to be something like: http://username:password@members.example.com http://username:password@members.example.com I wouldn't say that means the account in question is unprotected.
- josteink 14y agoIf you are going to nitpick, I will say that this is a feature that relies on browser-support. It's not fundamental to the web. Query-strings however by definition needs to be supported on the server-side. They are a part of the web. They are required for the web to work. Why is "browser-support" relevant? Your example is not supported in MSIE. I also thought it was removed from Chrome (in the name of "simplicity"), but I may be wrong. A link with query-strings is guaranteed to work for everyone. http://support.microsoft.com/kb/834489 http://support.microsoft.com/kb/834489
- gabemart 14y agoHuh, I had no idea that feature had been deprecated. I guess it's been a little longer since I used it than I thought.
- josteink 14y agoIt was used for lots of http://famous-website.com:long-token-nobody-will-ever-read@phishing-site.com http://famous-website.com:long-token-nobody-will-ever-read@p... style attacks. Microsoft's solution to the problem may not have been ideal, but at least that was the reasoning behind it. Edit: And what do you see once you click post? Hacker news ironically proving Microsoft's point. It's a wonderful world we live in.
- maxerickson 14y agoA password at least makes it clear to a bystander that some access control is intended at that URL. Consider the silly case where I have a server responding to example.com/funny/ and then try to claim that it was secure simply because I had not published the link. People would be quite confused if they went to jail for visiting it.
- maratd 14y ago> From a technical point of view the very nature of HTTP includes asking for permission. A web server isn't an agent of the company and has no capacity to grant or deny permission. Think of it as a security system you install in your home. Now, if the security system is malfunctioning and you notice that it is malfunctioning ... do you call up the owner and let them know or do you go inside and look through their stuff? If you go inside and look through their stuff, it's trespassing. Obviously the two scenarios aren't the same, but I'd imagine that's the logic used in the argument.
- ams6110 14y agoA web server isn't an agent of the company and has no capacity to grant or deny permission. A web server certainly can grant or deny permission, but it seems that this one didn't.
- jrabone 14y agoThat is perhaps not the same as "capacity" in the legal sense. Is a web-server legally competent?
- freehunter 14y agoThe blame would rest on the admin who set the permissions. You can't blame a lock for not being locked, but you can blame the night watchman for not locking it. This doesn't remove blame from the intruder though.
- gknoy 14y agoA webserver that doesn't restrict access (not even obfuscating the URL) is more similar to a "Free reading material!" shelf at the bookstore. If you go and take one of everything, it's not your fault if the bookstore mistakenly put things there that they'd intended not to be freely available.
- warfangle 14y agoOn the other hand, if Weev is sentenced: what does that mean for such things as Google's security flaw bounty?
- curiousdannii 14y agoYes, the 403 status code exists for a reason!
- meritt 14y agoWe live in a tech-filled world without a reliable means for responsible disclosure, no way to hold a company accountable for reacting to attempts of responsible disclosure, and any whistle-blowers are immediately branded as "criminals" and "hackers". This whole process, or lack thereof, needs some serious disruption. Edit: My comment is intended to be a general observation and not specifically about this case
- batgaijin 14y agoDisruption by who? Other sovereign entities?
- pbhjpbhj 14y agoPerhaps by the state in which a business or other entity is registered. In some states there are strict laws about maintaining privacy of customer data. But, AFAIK, where I am there's nothing specifically addressing negligence in failing to address a security breach that can be called "cracking". Government could, as part of their protection of their citizens offer a service of receiving security notices from third parties and passing them on to registered entities. The government run body could then check - and possibly advise on - the fixing of the [potential] data breach. In the UK the Information Commissioner's Office handle data protection issues (including legislational requirements placed on organisations). They have a form [a .doc, that tells me a lot TBH!] for companies to notify the ICO (http://www.ico.gov.uk/for_organisations/data_protection/lose.aspx http://www.ico.gov.uk/for_organisations/data_protection/lose...); it's not much of a stretch to have a form for third parties but there would need to be legislation to deal with enforcing responses and providing an amnesty for those making [non-malicious] reports.
- rquantz 14y agoPerhaps something like wikileaks for internet security? Located outside US jurisdiction?
- jebblue 14y ago>> We live in a tech-filled world without a reliable means for responsible disclosure There are many avenues for responsible disclosure, Google that phrase.
- Cieplak 14y agoAlthough we all know what 'hacker' means, I suspect that most people think the words means 'someone who does nefarious things with computers.' Calling him a hacker probably doesn't help his case, regardless of him being guilty or not.
- deleted 14y ago[deleted]
- moe 14y agoAnd who at AT&T faces jail for publicly exposing these Emails in first place?
- driverdan 14y agoFrom my understanding all you had to do was pass the ICC-ID to a script on AT&T's servers to get back the user data. I can see the court interpreting the ICC-ID as a form of access control since you'd have to guess them similarly to passwords. What isn't quite clear to me is what they did with this data. It seems they reported the hole to AT&T who then fixed it. That's good. It also seems they passed the data off to reporters, which may be bad for their case. It seems like they acted, at least mostly, responsibly. Assuming the data was never released to the public I don't think they should be prosecuting Auernheimer. That said, it does seem like they have a case based on the wording of the law. It's a very real possibility that he's facing jail time, especially when you consider the volume of data. He's charged with breaking 18 USC § 1028A (aggravated ID theft laws) which carries a mandatory minimum of 2 years. Federal judges have some control over this but generally stick with sentencing guidelines. He could fight it and win, get them to reduce the charges, or do some serious work for the gov and hope the judge goes easy on him. Note: I was convicted of violating 18 USC § 1028A (among other laws) so I have personal experience with this law, sentencing guidelines, and judge discretion but IANAL.
- sneak 14y agoThe ICCIDs here are sequential integers. It wasn't brute force, just incrementation. They are not secret and are certainly not access credentials. There were no access controls surrounding the web service in question. The prosecution is asserting that access to any system without authorization is "access to a protected system" in the legal sense, which is obviously bogus. This would make the Googlebot's operators criminally liable if I put up a site at "johndoessocialsecuritynumber.com". In fact, authorization is built into HTTP. There were no protections in place surrounding this data. Regardless of what he did with the data, downloading something from a public website is not criminal. (Though irrelevant legally, it's worth noting that he did nothing with the data except shame AT&T.) (I put up weev's bail and am handling some of his PR while his computer restrictions are in place.)
- tptacek 14y agoNo, it wouldn't expose Google to that liability, because Google would have no intent to access information of any sort, let alone information that Google would have reason to believe it shouldn't have access to. The crimes charged here aren't strict-liability; the prosecution is required to prove intent. Also: the authorization "built into" HTTP is used by a tiny minority of all web applications. Clearly, if you break into a retail brokerage and execute trades on behalf of other people, you're going to be liable, regardless of how that retail brokerage chooses to authenticate access to the site. (I don't have a position about this particular case; I know virtually nothing about it).
- manaskarekar 14y agoHow about this. What if we have another section on websites called something like 'Submit a bug' next to 'About,' 'Contact Us' etc. If more and more sites make it easier to report these things to them, hopefully either the error will be fixed or if it is being ignored, the "hacker" will have some kind of proof to claim that he tried to tell the bank to fix their door.
- sneak 14y agoHow about this: We don't prosecute people for loading URLs on the public internet first and foremost.
- lawnchair_larry 14y ago10 years in jail for incrementing an integer at the end of a URL. Wow. What a disconnect.
- guard-of-terra 14y agoHe should totally have posted those on pastebin instead and shared on the net. I think that if one finds an embarrassing security vulnerability, they should look up the offending company and upon finding that company ever took part in the crap like described in the article, they should publish the vulnerability wide open, goatse-style, anonymously via pastebin. Those companies should suffer to the end of times and their clients should too. Unless that company properly apologized, which they never do. Corporations don't seem to be capable of that. Not in their DNA.
- emmapersky 14y agoWhy should I, as an innocent party to a companies security failings have my personal details revealed. This is exactly why we have laws protecting identity theft and fraud. Naming and shaming the company and the extent of their security failing is enough. But only after they have patched the hole.
- deleted 14y ago[deleted]
- guard-of-terra 14y ago"Why should I, as an innocent party to a companies security failings have my personal details revealed." Because life is pain? But of course you can always sue the company that leaked your data and then mistreated people who warned them. Hell, you should. Probably with a class action suit.
- cloverich 14y ago> Because life is pain? lol... just a touch dramatic there.
- babarock 14y agoBecause you trusted the wrong people, and this has consequences. The customer has to suffer from the mistakes of the companies so that: 1. She stops trusting any company blindly with her data. 2. The market demands improvements from the service providers (and no, sacrificing a scapegoat in court is not an "improvement"). 3. Service companies react. Unless there's a major scandal, companies are slow to react to vulnerabilities. About that last point, it's a bit unfair to assume that the activist tried to contact AT&T and they didn't react. I honestly don't know if that's what happened in this case, and I hope it is. However there are several cases of companies "turning a blind eye" on the issue. As a customer, the only entity to blame when such a breach occur, is the provider that you entrusted with your data. Not the activists (regardless of their intents) nor the hackers or whatever monster you heard about in the media. If I entrust (and pay) someone with my bike and it gets stolen on his watch, who's to blame? The thief or the guardian?
- ssclafani 14y agoThe indictment filed against Weev by the DOJ in 2011: http://www.scribd.com/doc/113664772/46-Indictment http://www.scribd.com/doc/113664772/46-Indictment
- jcromartie 14y agoThe complaint cites "losses" > To date, AT&T has spent approximately $73,000 in remedying the data breach. Those costs include, among other things, the cost of contacting all iPad 3G customers to inform them of the breach and AT&T's response to it. BOO-#$%^ING-HOO. As if AT&T shouldn't have had to lock down their user's info, and it's some kind of injustice to them that they have to do things the right way now. This perfectly highlights the fundamental disconnect between the corporations, the (their) legal system, and the Internet-connected world.
- binarymax 14y agoThis is extremely dangerous. Condemning the whistle blowers results in a much less secure environment, since you'll scare away the white hats, and insecure systems will remain insecure. We need whistle blower protection laws in place, and we need them now.
- sneak 14y agoWhat's further terrifying is that the courts have made restriction of his use of non-windows non-monitored computers part of his bail conditions - prior to a trial to determine guilt. A person who's only marketable skill is on the Internet, completely prohibited from using ssh or virtualization, by nothing more than an error-riddled FBI complaint document. (This started prior to the grand jury indictment.) He's been without significant work for over two years as a result. It's a scary thought that this could happen to any one of us.
- DanBC 14y ago>What's further terrifying is that the courts have made restriction of his use of non-windows non-monitored computers part of his bail conditions - prior to a trial to determine guilt. How does he use a telephone? Or a suitably advanced toaster?
- sneak 14y agoAt first, we had to drive all over to find a phone that couldn't even MMS (because MMS can be used to send email). It was a nightmare. Eventually some of those restrictions were relaxed.
- sneak 14y agoHi there - I'm the one who put up the $50k to bail weev out of jail.[1] (Otherwise he would have had to sit in Essex County Jail during these ~2 years since this started.) There were some others in line to assist (I live in Europe), but they all feared various forms of retribution/harassment from the FBI/DoJ, so it fell to me (someone with comparatively little to lose, stateside). This only serves to underscore the truly chilling effects of these sorts of governmental abuses of power. I also host his website, http://freeweev.info http://freeweev.info, where you can make donations to his case via both Paypal and Bitcoin. (He has various restrictions placed on his use of technology while out on bail.) Please feel free to contact me directly if you have questions related to his case. Contact info can be found in my profile. 5539 AD00 DE4C 42F3 AFE1 1575 0524 43F4 DF2A 55C2 [1] https://twitter.com/rabite/status/270668883172671489 https://twitter.com/rabite/status/270668883172671489
- VonGuard 14y agoI'm glad someone is taking on the task of defending Weev because the charges they have against him are ridiculous and stupid. Sadly, Weev's nature is that of a rattlesnake, and he's basically burned every bridge he could on his way here. Thus, the EFF will have nothing to do with him.
- olalonde 14y ago> Sadly, Weev's nature is that of a rattlesnake, and he's basically burned every bridge he could on his way here. Thus, the EFF will have nothing to do with him. Could you expand on that? Why doesn't the EFF want to help him?
- VonGuard 14y agoSorry, not going there. Suffice to say, he burned a bridge.
- deleted 14y ago[deleted]
- recursive 14y ago> "The more concerning charge to online activists watching Weev’s case is based on the Computer Fraud and Abuse Act, which forbids “unauthorized access” to a computer." There are HTTP codes to indicate lack of authorization. Presumably he didn't encounter those. How is this an argument?
- BryantD 14y agoBah, more weev hagiography? He's not a whistle blower, he's a troll. Look: first off, he didn't tell AT&T about the hack, he told a bunch of news organizations. See http://www.forbes.com/sites/firewall/2010/06/09/atts-ipad-hackers-ignored-by-reuters-other-mainstream-press/ http://www.forbes.com/sites/firewall/2010/06/09/atts-ipad-ha... for details. "we did a benefit analysis and decided they could take our story viral the fastest." One of those organizations presumably told AT&T; all AT&T has ever said is that they learned about the exploit from a business customer. Second, weev is the same guy who got up on stage at Toorcon and lied about finding an exploit in Firefox. Just flat out lied. One of the ways in which he's a great social manipulator is that he has no qualms about the big lies, and doesn't really care if they're noticed. Third, at the time, weev said "There is nothing in Apple’s SDK APIs that would allow an application to have this identifier [the ICC-ID] – it is a shared secret that should indicate physical proximity to the iPad." So while it's amusing to see his defenders talk about how unimportant ICC-IDs are, it's an interesting change of tune. Fourth, even if you believe weev when he says he forced the Amazon delist of gay-themed books (I never have), that goes over the line from activism to exploiting. Yeah, we do have to protect even unpleasant, obnoxious whistle blowers. I just don't see how weev counts as a whistle blower, and I think that any article on his situation should present the full picture rather than painting him as a misunderstood good guy.
- cullend 14y agoWeev is different. That's for sure. But what's at stake here is bigger than him. Anyone can be sued for going to a damn URL. That's the real problem here (as well as a myriad of others).
- sneak 14y agoOh, weev isn't a good guy. He's a right shithead. He's also a whistleblower. The emails were not sold, pastebinned, or mailed MobileSafari overflows. The media was contacted because he's a megalomaniac. One thing he is not is a criminal.
- DancingDeer 14y agoHe's no whistleblower; a criminal bum is all. He's a Freemason (wannabee or otherwise), enough said.
- jonknee 14y agoIt's pretty scary that you can go to jail (for a long time!) for something as simple as: > ~curl http://example.com/att/[1-100].html http://example.com/att/[1-100].html I understand what the lawyers are saying, but this is just beyond common sense. There should be liabilities for deploying software that publicly gives out information you do not intend to.
- danielweber 14y agoIf you've never deployed software without security flaws, it means you have never deployed software.
- jrockway 14y agoAt the same time, it's worth noting that running curl in a loop is slightly less difficult than factoring RSA keys. So if someone "hacks" you via an unauthenticated public web service, the courts should take that as less of a computer crime on the attacker's part and more of negligence on your part. But on the other hand, if someone breaks into your well-engineered system through some nearly-impossible attack, then you should not be liable.
- jonknee 14y agoSure, but why should who makes the software bear no responsibility? If a building is found to have a flaw the architect or an engineer are who get questions, not whoever noticed the flaw.
- danielweber 14y agoThe flaws in architecture are well-understood and there are rarely-changing building codes to describe exactly what should and should not happen. Software does not exist in any such stable world. There can be two pieces of software, each perfectly legitimate and doing exactly what they intend, that when both are present format a customer's hard drive. Who does the customer sue then? If you want to make developers responsible, I won't personally be hurt much, since I can make a shitload of money finding vulnerabilities in other people's code (and have done so in the past). The lawyers will make lots of money, too, as we have jury trials to figure out whether that SQL injection was really negligent or not.