5 ms·
weev still thinks that AT&T 'published' this information. AT&T had no intention on 'publishing' this information, he abused their system in order to obtain it,
by miw-sec-work 14y ago
weev still thinks that AT&T 'published' this information.
AT&T had no intention on 'publishing' this information, he abused their system in order to obtain it, then he leaked it.
No weev, you found a bug in their web app, then _YOU_ willfully published other peoples personally identifying information for your own fame and glory.
Unfortunately, someone who's name and details you leaked didn't like that, and called in a favor. The DoJ came after you hard.
Your little tech crunch article chooses to omit crucial facts, and you are riding on the back of AAron Swartz again. You are nothing like AAron.
- guard-of-terra 14y agoOkay, when I find a bug in your web app I will publish it anonymously, widely and embarrassingly for you. That's because you didn't want to be friendly. You wanted to be hard. You wanted DoJ. Now you will be forced to want class action suit from your customers and bankrupcy.
- miw-sec-work 14y agoResponsible disclosure to the vendor is one thing. Taking the fruits of your exploits and publishing it for glory and a "I leaked all that information because you wouldn't fix it" attitude is quite another. I would hope that if you discovered a vulnerability in one of my web applications you would contact me first and allow it to be resolved. Might even be lucrative for you. If you used that vulnerability to steal my database and publish it to the public domain -- when it has no place in the public domain, i would expect the DoJ to hunt you down. I never said anything about not being friendly. But if you are playing with peoples identities, their lives, this is not friendly at all.
- guard-of-terra 14y agoAs we saw from many and many articles, vendor disclosure often ends with threats, intimidation, your business interaction with them being canceled, and forcing you to sign a NDA on hostile terms. Once you contacted vendor it's not safe to go the pastebin route. So it becomes an unfeasible solution. On the other hand, try to "hunt down" a pastebin post original author. It would be the last of your worries.
- lessnonymous 14y agoBut they did publish it. Just because they didn't _intend_ to publish it doesn't mean it wasn't published. Right now the URL I'm looking at has "id=5095821" in it. If I change that to "id=5095822", I'm looking at something else published by Hacker News. But by DoJ standards, I'm "hacking" and have broken the law if HN didn't deliberately publish it. weev is an ass. But he didn't hack anything. These cases are trying to set a standard of "security by intent". There is no such thing. It's like my internet banking saying "To access your bank account, please type in your account number. Be careful to get it right or you'll be looking at someone else's account"
- miw-sec-work 14y agoi think the semantics in the method in which weev retrieved this data is far overruled by the fact he LEAKED it afterward. Real people were hurt here by having their PII exposed. Don't forget that.
- lawnchair_larry 14y agoThe problem with your argument is that he did not leak it afterward. None of this info was ever public. He demonstrated it to the media and then deleted it. I suggest you look into the case.
- miw-sec-work 14y agoMore to it than that... lets say you exploit that bug in the internet banking application and you access my account. Then you start logging into other peoples accounts and copying their address, balance, transaction lists. Then you publish all this information you have stolen and say "Oh dont use internet bank -- they don't protect your private information" the bank should have done better to protect that information, granted, but you have also performed an unethical and criminal act by publishing this information. both the bank and the person that leaked that information should be punished.
- ghshephard 14y agoHe certainly hacked it - but that's not necessarily pejorative. Your average individual couldn't just try entering the number into AT&T - weev had to spoof the user agent, and, make some intelligent guesses as to what valid CCID's would be. It's not the world's greatest hack, but it certainly was using the system in a manner that I'm certain AT&T did not intend. The IRC logs indicated that they knew what they were doing was likely criminal, and if AT&T discovered them, would "sue" them. Whereas I'm guessing PG would be fine with you incrementing the number on the HN URL. And I'm pretty certain that's not criminal behavior. It's important to note, that just because weev was hacking the AT&T site, didn't mean it was a criminal hack. In my mind it barely crosses the line - and he gets punished somewhat, but I'm thinking a week in jail and 30 days community service - not the silly levels that the feds are going to in this case.