4 ms·
This, to me, is the totality of the case: AT&T said accessing that data was OK. If it wasn't they should have returned a 401 or challenged for further authenti
by lessnonymous 14y ago
This, to me, is the totality of the case: AT&T said accessing that data was OK. If it wasn't they should have returned a 401 or challenged for further authentication.
Incrementing a phone number by one doesn't make it illegal to call it. If the person at the end then says "who are you" and you lie, then that's fraud. But if they just tell you something, there's no way anyone can claim that you obtained that information unlawfully.
- nookiemonster 14y agoIncrement is the wrong word. They implemented the Luhn algorithm, which is not the same as i++
- antiterra 14y agoIncrement in the general sense just means to increase the amount. A more specific meaning is to increase using regular steps, that is, to select the next number in a sequence. The use of the word is not confined to i++ or i=i+1 or ++i. Luhn is just a check digit, so you could define an increment function that adds one to the base number and then calculates the last digit. Or, you could just iterate over every possible check digit from 0-9.
- AnthonyMouse 14y agoHere's the problem with all of this: If you send a sufficiently vulnerable server a specially crafted request, you can get it to come back with "200 OK" and a list of everybody's credit card numbers. Conversely, if you're an employee of Foo, Inc. and you sign in to a secure server with your personal account and try to do something privileged, it's going to come back with "401 Unauthorized" and not give you anything even though you are actually authorized, and if you then sign in with your employee account it will allow you to do that thing. As a general rule what the machine says has a very strong relationship with whether or not you're authorized to do something. The issue is that if you're not authorized then a properly functioning machine just won't let you do it, which means that it seems impossible for anyone to violate this law against a server that is working properly. The only way anyone can be capable of breaking this law is if the server is not working properly and allows them to gain access without authorization. Which is why "unauthorized access" is such a vague and hopeless disaster. Going by the normal mechanism for determining whether you have authorized access, namely whether the server allows you to do something, would mean that no one could ever commit the crime, because either you never actually gain unauthorized access since you're prevented by a server with sufficient security, or you succeed in convincing the server to let you do something which under normal circumstances implies that you're authorized. Seemingly the only way anyone would ever be convicted is based on a pile of circumstantial nonsense about how the defendant should have known they weren't authorized to do something that the server allowed them to do, even though normally you are authorized to do anything the server allows you to do. So it becomes a de facto law against "doing bad things with a computer" -- not a specific prohibition against anything in particular, just something you stick to anybody who you don't like, because hey, if you did something "bad" then it wouldn't be authorized, right?
- flyinRyan 14y ago> If you send a sufficiently vulnerable server a specially crafted request, you can get it to come back with "200 OK" and a list of everybody's credit card numbers. If, if, if, if. What Weev did was spoof what kind of client he was using. That's it. What you're suger coating here is using exploits to break into a secure system. That is, you encounter a secured system and find a way to circumvent that security. For the data Weev encountered was there any possible way to get a 401 response for the URLs?
- AnthonyMouse 14y ago>What you're suger coating here is using exploits to break into a secure system. No. Because using "exploits" (not a legally defined term AFAIK) doesn't necessarily mean that access was unauthorized. If you're the sysadmin for a remote server that you suddenly discover you can't login to with your account and that people are complaining that it's sending spam, and you smash the stack on a vulnerable application running on the server in order to regain control and shut it down, I should hope that wouldn't be "unauthorized access" and subject to criminal penalties. And then there's the fact that "exploit" is a fuzzy and undefined thing. Is changing "userid=4833" to "userid=4834" to get another user's account not an "exploit" but changing "userid=4833" to "userid=0" to get root access is? What if the maximum userid is 65535 and if you use "userid=65536" then it rolls back around and gives you root because it's equivalent to "userid=0" but doesn't get rejected like "userid=0" would? This is no way for a criminal law to operate. >For the data Weev encountered was there any possible way to get a 401 response for the URLs? Sure there was. If AT&T had configured their server properly then that's exactly what it would have given him. If I wanted to introduce some irony then I would have to ask you whether you were "blaming the victim" here.
- flyinRyan 14y agoI concede that it's a bit fuzzy at the moment, but my criteria would be that if a spider could have accidentally crawled this info then it can't be a crime. >Sure there was. If AT&T had configured their server properly then that's exactly what it would have given him. That's not a valid test. If a company decides they didn't want you to see something after the fact (as in this case) they can always just claim they didn't configured their servers how they meant to. >If I wanted to introduce some irony then I would have to ask you whether you were "blaming the victim" here. What blaming the victim? The victims were the people who's data got released. Since they trusted AT&T with it that would make AT&T responsible. Everyone is talking about Weev but chances are he wasn't the only person on the planet to know about this.