3 ms·
> trespassed into a room A room with an unlocked and unmarked door, off of a hallway that was open to the general public. An INCREDIBLY tame act compared to o
by greyface- 2mo ago
> trespassed into a room
A room with an unlocked and unmarked door, off of a hallway that was open to the general public. An INCREDIBLY tame act compared to other unprosecuted trespasses normalized and celebrated at https://hacks.mit.edu/ https://hacks.mit.edu/.
> rotated his MAC address
Not a crime; in fact now a widespread and default practice for consumer Wi-Fi/Bluetooth devices.
- FireBeyond 2mo agoWere those hackers MIT students? Was Aaron?
- greyface- 2mo agoBoth Aaron and "those hackers" were MIT community members.
- FireBeyond 2mo agoThat's an interesting spin that means precisely nothing. I'm not authorized to enter facilities or building maintenance spaces in buildings in my town because I'm a "community member".
- greyface- 2mo agoThe general public was authorized to enter the facilities 24/7. The exterior doors were unlocked and it was considered an "open campus". The access controls you see today have only existed since COVID. Whether he was a student at the time also means "precisely nothing".
- FireBeyond 2mo agoReally? The expectation was that they could go into facilities closets and plug into the core networking equipment?
- stonedivot 2mo agoDon't waste your time arguing with people like this. They can't admit the nuance of the situation: what Aaron did was blatantly wrong, and what the government did in response was disproportionate. They will only focus on the latter, and make endless irrational justifications for the former.
- harshreality 2mo agoThe expectation is that MIT doesn't go to the police when someone plugs a computer into a switch in an effectively unlocked data closet. The expectation is that such individual and laptop doing "unauthorized" scraping doesn't trigger a criminal investigation when the host university, and the target business, didn't implement any meaningful access controls or even rate limiting for any other person on campus. The expectation is that after an investigation of scraping at 11 req/s (450,000 over 11 hours according to the report), a further 8,000 requests (before JSTOR blocked MIT's /8) two weeks later would not have the effect that "Half the servers in one data center failed, and JSTOR engineers feared that the entire service might go down worldwide." The expectation based on that claim by JSTOR is that JSTOR was incompetent or lying. The expectation is that when MIT was able and willing to implement access control for JSTOR, and JSTOR declined because they want to develop a notice to MIT visitors who might be negatively affected by ending uncredentialed access, JSTOR would not then create a tempest in a teapot over the violator returning and continuing to download papers at a reduced speed that wasn't even detected for about a month. On Dec 26, when JSTOR again noticed the "abuse", they went to significant effort to route the violator's requests to a special server and serve them garbage instead of the real PDFs, all on short notice... yet they couldn't add the general notice to MIT visitors about the credentials requirement, on a much less urgent timescale; they had told MIT in October that they needed until after Dec 18th to add such a message. The expectation is that JSTOR's claims are self-serving lies. The expectation is that such a request pattern would not trigger a report, by the MIT libraries director, to the MIT academic council, that a "cyberattack" had been launched from MIT's network. The expectation is that you don't get arrested for felony B&E for entering a data closet that's effectively unlocked, connecting to a switch, and scraping a paper hosting site that offers free downloads from the entire institutional network. The expectation is that you don't get charged with larceny for downloading, in any quantity, papers that are freely available to anyone on the MIT campus or probably most other campuses in the U.S. The expectation is that sending web requests with a url parameter indicating T&C has been agreed to, and without saving cookies, might be a basis for a civil action, but is not "accessing a computer without authorization" under the CFAA. The entire situation, at most, should've been a minor local crime and a lawsuit by JSTOR against Swartz. Yet the state charges were dropped (feds didn't want to share required discovery material), and JSTOR settled with Swartz before the feds even indicted. MIT was caught in an awkward position of having the ability to block unauthenticated scraping to protect their contract with and access to JSTOR, but not doing so. So they proceeded to treat someone connecting to a switch in a data closet and doing what any MIT visitor could do, as a criminal offense. I don't believe anyone at MIT was genuinely concerned that there was some broader criminal conspiracy when the issue was downloading of papers from JSTOR. Certainly not based on some random Chinese IP pinging or scanning Swartz's laptop. When the data closet laptop was discovered in January, MIT could have left a note telling the owner that JSTOR is very upset and it would be better for everyone if the scraping stopped. Why didn't they? They could even, reasonably, have taken the laptop and external drive and noted that the data closet was insecure and please contact network staff to claim it.
- sillysaurusx 2mo agoI'm not sure if this is meant as some kind of "gotcha," but the legal system doesn't work that way. He wasn't rotating his MAC address as a default practice. He changed the last byte of his MAC only when he noticed he was banned from the network. Intent matters. Plugging your laptop into a router you normally don't have access to, with intent to download a large number of private articles, means something. And it means more than "I downloaded a lot of public files off the public internet," which is what Meta did. All of this is in the indictment, which is worth reading: https://www.documentcloud.org/documents/217117-united-states-of-america-v-aaron-swartz/ https://www.documentcloud.org/documents/217117-united-states... Personally I think it's a shame that digital crimes can result in prison time at all, except for e.g. crypto theft. But under US law, Aaron committed a crime back then, and it would still classify as a crime today.
- thomasjeff1 2mo agoFrom your sourced link. > JSTOR,founded in 1995, was and continued to be a United States-based, not-for-profit organization that provides an online system for archiving and providing access to academic journal. If it was online, could any one have access to it? So why him downloading them was breaking the law?
- sillysaurusx 2mo agoIt was free for MIT students but paid for everyone else, I believe. That's why he needed to jack into MIT's network.
- infinite_spin 2mo agoJSTOR was free for the public as well, but had a per-day download cap, which IIRC was 3 papers.
- tzs 2mo agoYou are greatly underestimating what was going on. Over the course of months they tried all kinds of blocking methods that would stop most people, but he kept evading them. It is impossible that he did not know his use of the free access was no longer authorized. Then he put his equipment on their wired network, which he had no permission to do so and had to trespass to do that. It is irrelevant that the door was unlocked and in a hallway the public could get to. It being unmarked just makes it worse, since doors the public is supposed to use generally are marked. He also repeatedly came back to that room to check his equipment. He was now grabbing data at such a high rate that JSTOR cut off all MIT JSTOR access for a few days while they tried to figure out what do next. At that point MIT research is being disrupted. MIT does a lot of government research and what was going on was indistinguishable at that point from a hostile attack, and police were called.