11 ms·
But they did publish it. Just because they didn't _intend_ to publish it doesn't mean it wasn't published. Right now the URL I'm looking at has "id=5095821" in
by lessnonymous 14y ago
But they did publish it. Just because they didn't _intend_ to publish it doesn't mean it wasn't published.
Right now the URL I'm looking at has "id=5095821" in it. If I change that to "id=5095822", I'm looking at something else published by Hacker News. But by DoJ standards, I'm "hacking" and have broken the law if HN didn't deliberately publish it.
weev is an ass. But he didn't hack anything.
These cases are trying to set a standard of "security by intent". There is no such thing. It's like my internet banking saying "To access your bank account, please type in your account number. Be careful to get it right or you'll be looking at someone else's account"
- miw-sec-work 14y agoi think the semantics in the method in which weev retrieved this data is far overruled by the fact he LEAKED it afterward. Real people were hurt here by having their PII exposed. Don't forget that.
- lawnchair_larry 14y agoThe problem with your argument is that he did not leak it afterward. None of this info was ever public. He demonstrated it to the media and then deleted it. I suggest you look into the case.
- miw-sec-work 14y agoMore to it than that... lets say you exploit that bug in the internet banking application and you access my account. Then you start logging into other peoples accounts and copying their address, balance, transaction lists. Then you publish all this information you have stolen and say "Oh dont use internet bank -- they don't protect your private information" the bank should have done better to protect that information, granted, but you have also performed an unethical and criminal act by publishing this information. both the bank and the person that leaked that information should be punished.
- ghshephard 14y agoHe certainly hacked it - but that's not necessarily pejorative. Your average individual couldn't just try entering the number into AT&T - weev had to spoof the user agent, and, make some intelligent guesses as to what valid CCID's would be. It's not the world's greatest hack, but it certainly was using the system in a manner that I'm certain AT&T did not intend. The IRC logs indicated that they knew what they were doing was likely criminal, and if AT&T discovered them, would "sue" them. Whereas I'm guessing PG would be fine with you incrementing the number on the HN URL. And I'm pretty certain that's not criminal behavior. It's important to note, that just because weev was hacking the AT&T site, didn't mean it was a criminal hack. In my mind it barely crosses the line - and he gets punished somewhat, but I'm thinking a week in jail and 30 days community service - not the silly levels that the feds are going to in this case.
- gambiting 14y agoSo what you are saying is, that AT&T could have made a webpage with all user data in plain text,and just write at the top in capital letters: "YOU ARE ONLY INTENDED TO LOOK AT YOUR OWN DATA, DISREGARD EVERYTHING ELSE" and it would be magically ok, because you know, if you look at other people data then you are not using the webpage as it was intended to? Because this is basically what they did. Yes, an average American individual would not know how to change the URL,but that does not mean that the data was secure. And AT&T has all legal obligation to keep their customer data secure.
- ghshephard 14y agoI'm not saying AT&T was in the clear. Obviously just requiring a reasonably easy to guess number to secure an email address is amateur hour. But, at the same time, just because web security is easy to break into, doesn't give people free reign to go traipsing through and pull out what they can. Keep in mind - 99% of the population wouldn't have been able to figure out how to spoof the user-agent to get into the AT&T site, and most of those that could, wouldn't have gone beyond extracting a couple IDs, and then notifying AT&T. Weev's sin (if not felony behavior) was extracting 100,000+ personal email addresses, and the exposing them for the sheer purpose of embarrassing people he despised. Do I believe he engaged in illegal behavior? Yes. Do I believe it merits years in Jail? No. With regards to legal obligations - In California, the closest I can find is Bus. & Prof. Code §§ 22575-22578 [1]. It is a requirement for site collecting personal information to "conspicuously post its privacy policy on its Web site" I can't find any laws in California that require the securing of this information beyond that, though. [1] http://www.leginfo.ca.gov/cgi-bin/displaycode?section=bpc&group=22001-23000&file=22575-22579 http://www.leginfo.ca.gov/cgi-bin/displaycode?section=bpc...
- Zarathust 14y agoAnother fairly common example is with facebook where you can access profiles with names, like facebook.com/lessnonymous.1 . I got fairly tempted to check other people in the world with the same name as I have so I incremented the number myself. I am not sure that facebook intended their website to be used that way