8 ms·
Security Researchers tell court: We do what Andrew Auernheimer did
- casca 13y agoThis is really important to those of us in the infosec industry. A criminal sentence for changing a parameter in a GET tag is not appropriate. I wonder whether blocking tracking cookies could also be considered unauthorized modification. Unfortunately there's huge incentive for companies with a public reputation to make this sound like the work of evil hackers rather than their own unwillingness to perform basic security protection on their public-facing services. Money on lawyers and PR are only spent when there's a known threat whereas preventative security is successful when nothing happens.
- tptacek 13y agoNo, because CFAA isn't a strict liability crime and the prosecution is required to prove intent.
- pyre 13y agoChanging from: https://payroll.example.com/SSN=000-00-0000 to: https://payroll.example.com/SSN=000-00-0001 shows intent to gain access that you were obviously not authorized for, even if you immediately report what you find. Wasn't it ruled that accessing stuff that you aren't authorized to that is publicly (within a company) accessible to all on a shared drive violates the CFAA because you are exceeding your authorization?
- tptacek 13y agoI was referring the "wondering if blocking tracking cookies" question. I don't have a problem with criminalizing attempts to pull up random people by their SSN.
- pyre 13y ago> I don't have a problem with criminalizing > attempts to pull up random people by their > SSN. If I see that the URL contains my SSN, and want to investigate if they were stupid enough to have this as a security hole, what are my options? You seem to say that if I pull up the page of someone else, I am immediately a criminal and need to go to jail. Should I instead report the possible issue to the company? Will they actually take, "I see that SSN is in the URL and that might be security hole, but I don't know for sure because I haven't attempted to try it," seriously? Hopefully they would, but I find that hope to be way more optimistic than the 'real world' should get credit for.
- ceol 13y agoYou don't get to break into a bank because you want to see if you can exploit a security hole. What you're talking about is more akin to wiggling the bank's door handle and then leaving. What weev did is break in, steal a bunch of documents, and then talk about selling them.
- sneak 13y ago"Breaking in" suggests that there is access control (locks, doors, walls, etc) in place. ATT admitted in court to publishing this data on the web. Emitting email addresses in response to ICCIDs was a specific feature they explicitly implemented to reduce the number of steps required to resubscribe to service, not a "security hole". Your physical analogy is inappropriate, and serves to frame his actions as criminal when they are clearly not. Please read the brief.
- ceol 13y ago> "Breaking in" suggests that there is access control (locks, doors, walls, etc) in place. No, it doesn't. See, this is what happens when you start talking about crimes on the internet when you really shouldn't be. If I leave all my doors and windows opened, or if I put a box of valuables in the middle of an empty lot that I own, it doesn't suddenly make it legal for people to steal from me. AT&T leaving their doors and windows open does not suddenly authorize any ol' grody troll to walk in and take personal information. Whether you like it or not, his crime will be made into a physical analogy.
- darkarmani 13y agoYou are explicitly authorized by the specified policy that uses SSN to look up the data. If you aren't authorized, why is it sending you the data? If you make no effort to authenticate requests, I find it very unreasonable to act like any requests are unauthorized.
- mpyne 13y agoSo what about denial of service attacks going against just the public unauthenticated API? Just because AT&T does a boneheaded security implementation for which they deserve sanction, does not entitle weev or anyone else to go beyond ethical boundaries in discovering (and in weev's case, abusing) that security lapse.
- darkarmani 13y agoI think DoS is covered by clauses other than just authorized or unauthorized. You can't legally DoS people even if you are an authorized user. > that security lapse. I don't think you can call this a lapse. It's not like they had passwords but forgot to change them. They designed it without any security.
- mpyne 13y ago> They designed it without any security. Is that the only criterion now? You'll only do the ethical thing if someone else remembered to bake in technical safeguards?
- grey-area 13y agoWhat if someone makes a typo entering their SSN in the form that leads to this page, are they also a hacker? By your definition, they would be. If your data is on the internet and not secured, it is being scraped by robots constantly for a start, some of which might iterate counters, so some responsibility lies with those who maintain the website. There isn't a clear line like the threshold of a dwelling we can point to, because it's not always clear which urls are authorised for a user and which are not. Ultimately you're not going to stop the curious, and bots, from scraping the web, so if there are no access controls on your payroll you can expect data to leak, even if you come down hard on every single person you find accessing it without authorisation. I think the emphasis here should be on intent, as shown by the data taken, and what was done with it, not on trying public urls. If someone shows intent to steal information by changing urls, then downloads the info, then uses it for identity theft or sells it on, that's clearly a crime, and unless they have mitigating circumstances, perhaps it deserves a fine or a very short jail sentence for serious cases. I do think the sentences today are excessive for this sort of activity. If they simply access a URL as you propose above, I don't think you can show intent. Even if they access several urls, was their intent to explore, or to steal information, or did they just follow a bad set of links or make a mistake with their web crawler?
- mattmanser 13y agoYou've missed the point. Making a typo and accessing the page once with the wrong SSN using the submit buttons on the web page provided has absolutely no intent. Using an automated script bypassing the webform to cycle through as many as possible clearly shows intent to access something you're not supposed to. People don't just access urls at random, they will never type a url with query strings into the browser. They click links or submit forms. Someone pen testing a website will be deliberately circumventing those methods. It's like running wireshark on a public unsecured network, there's likely no good reason for you to be doing it and you know what you're doing if you're running that tool. That's intent. Note: I'm personally very pleased that they're fighting this. Just wanted to clarify what they mean by intent.
- angersock 13y ago
- TeMPOraL 13y agoDoes it? Maybe it shows intent to see what kind of fancy 403 page payroll.example.com is employing? I think one of the reasons people (including me) have problems with penalizing GET parameter change is that they are obviously visible and trivial to change. They are a part of URL and pretty much designed to be modified by hand. Growing up on the Internet we learned that if we want to see e.g. the next page of the gallery or board, we don't have to look for "next" button. We just change /0/ to /1/, or ?start=100 to ?start=150 in the address bar and press ENTER. It's easier. It's quicker. It's more natural. I can't feel that there's anything wrong with changing a GET parameter. It doesn't register on an emotional level. My personal feelings are that on the Internet you're supposed to use HTTP codes like 403 or 404 to mark places user is denied to access. IMO the space of legally accessible addresses for given user should be defined by a superspace of all URLs that return 200 Ok when that user tries to access them. If you screw up and serve sensitive data without proper access check, it should be your (legal) responsibility, not the person's who (accidentally or not) discovers this.
- rmc 13y agoJust because you're used to it, and because you find it easy and natural doesn't mean it is or should be legal. There are people who, upon seeing the good laid out in a shop, will find it easy and natural to just pick it up and walk out. They find it easy and natural. It's right there.
- angersock 13y agoCan we please refrain from trying to make analogies to stealing? Or really, any analogies to the physical world?
- testbro 13y agoI'd analogise it to an open book in a public space. The information is there for you to see when you walk up to it, and you have to interact with it (turning the page) to see the other information. On being caught turning the pages on the book, you get yelled at and imprisoned, despite your contention that it's the book owner's fault for not making sure turning pages was prevented.
- pasbesoin 13y agoTo some extent, I disagree. It can set a pretty high de facto bar especially for the independent researcher. Sure, eventually -- if the world and the court you land in are a fair and decent place -- you may be absolved. But you may spend a lot of time and money getting to that point. Facing what appears to be frequently very if not overly aggressive government prosecution, and/or private prosecution (so far, civil -- although see e.g. privately driven criminal prosecutions in the U.K.) by very well funded, perhaps overwhelmingly funded legal teams motivated by parties who as often as not seem to want to bury any and all bad publicity while discouraging any efforts that might -- even when justifiably -- dig it up... I guess I view the top level Internet IP address space as a public space. If you can't put onto and manage your resources on it in a responsible and secure fashion, you deserve what you get. Going from memory, as I understand it, there was no "subverting an authentication system", here. He merely iterated a public parameter. Granted, he apparently stepped through a lot of iterations, but a script can do that, even inadvertently, as IIRC was alleged to have occurred in this instance. Ultimately, he didn't sell or otherwise misuse the resulting data. My personal inclination would be to argue that at a minimum, benefit of the doubt should mitigate against a felony-level conviction. Also personally, my own dealings with AT&T have left me with absolutely no sympathy for them. The SBC culture from which their senior management devolves I have found to be atrocious. They should spend less time looking for scapegoats to fry and wave in front of the next person to find one of their shortcomings, and instead "man up" and fix their own processes and systems. Finally, in many such cases, it does seem to be the individual who is finding these problems and therefore causing them to be fixed. As the holder of online accounts and data, I don't want to abandon that field to some combination of lackadaisical corporate process along with un-prosecutable malicious entities in Eastern Europe, China, or wherever. I know you're the expert in this field. And I don't mean to disrespect your work nor your commitment to excellence. Nonetheless, my own not insignificant experience has shown me repeatedly and taught me how, absent independent pressure, entities often don't get around to fixing such problems and can actually create de facto strong internal disincentives to doing so. I've seen this, repeatedly and at many organizations including very large and successful multi-national firms, myself. I've seen it from the inside, where I've had to take damage and career risks in order to get things addressed. Even as a well-meaning employee of an organization with such a problem, I worry what "doing the right thing" may cost me. We are increasingly forced to rely on them -- banking records, medical records, etc., etc. The onus should be on them -- to get this right. If nothing else, I can argue that economically it is they who can afford the risk (that is, the responsibility and cost of pro-actively mitigating it). And that should be a factor that is considered when determining where the balance in the law rests. One argument that I've seen made, is that European credit and debit cards have chip and pin because the European banks bore a greater risk for and cost of fraud. Economic incentives can be an important factor in creating and maintaining security. Criminal risks can be, as well, but perhaps in a different fashion than we are talking about for this case. For both the economic and the criminal liability, the weight needs to rest more heavily on the parties blatantly leaving personal data vulnerable. Such entities seem to demand ever more of the resources society has at hand -- financial, legal, etc. They should bear the responsibility, along with this. If one guy and his laptop can catch them out, and particularly if he's not doing evil with the results, well, then, shame on them. Stop focusing so much on "the hacker".
- PhasmaFelis 13y agoI kind of got the impression that Weev getting sent up for identity fraud was a lot like Al Capone getting it for tax evasion. Which is to say, he was a sadistic monster of a troll who delighted in ruining people's lives, but he was cunning enough to never quite cross the criminal-harassment line with anyone brave enough to press charges, so they got him on this instead. It's a rotten precedent, and I can't really blame anyone for opposing it on principle, but let's do remember that Weev himself is not any kind of hero.
- eridius 13y agoAlso don't forget that Weev was considering selling the info he got, before he decided to be lazy and just tell the world. So not only is he a massive troll, but his motives for the "hack" were also less than saintly.
- andrewcooke 13y agoglad i haven't been jailed for things i've considered. i'd be down for murdering a lot of commentators on hn...
- bigiain 13y ago<devil's advocate>If you "consider" stealing thousands of credit card numbers, break into a business and collect all the required data, then get lazy before you get around to incurring fraudulent charges and just boast about it instead, perhaps you _do_ deserve jail time</devil's advocate> weev fucked up - and he _knew_ he was "fucking up" when he went from "finding a vulnerability" to "automatically exploiting that vulnerability to collect as much data as he could". Felten, Blaze, Schneier, Kaminsky - they would all have tried incrementing the get parameter - when it worked they would all have tried a bunch more times to confirm their assumptions, none of them would expect to get away with subsequent wholesale download of AT&T's customer data. Neither should weev.
- pyre 13y agoIIRC, all he would have been selling is email addresses that are known to belong to iPad owners with AT&T as a provider. I don't recall that he had any credit card info.
- tossmeup 13y agoSorry, but this isn't the martyr you're looking for. Have fun in jail beardybutt.
- throwawaykf02 13y ago> We do what Andrew Auernheimer did. You mean, exploit a weak access control scheme, fail to disclose the exploit properly, instead use it to download private data in bulk, make unwise brags to reporters about potentially misusing that data, and then be dicks to the judge?
- puppetmaster3 13y agoPeople commenting are in http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
- jingo 13y agoThe brief leaves me with the impression that curl http://example.com/page[1-100].html (sequential download) where no URL is password protected (open access) is still a violation of the CFAA if someone can convince a court that such access was "unauthorized". That's crazy. And the prosecutor would probably proceed to call the above command "software". As in "the defendant wrote software..." Makes for a compelling narrative doesn't it? But the truth is, Daniel Stenberg wrote the software and included this feature for a reason. Was that reason to assist users with criminal intent? C'mon. I can't help but think of all the many sources of exposed email addresses on the internet, whether they are exposed through ambivalence toward users' privacy or simply incompetence (as with AT&T). Such sources are constantly mined by email marketers. WHOIS data comes to mind. Correct me if I'm wrong, but the information this defendant accessed was nothing more than email addresses. Is that right? How many businesses on the web fail to adequately protect their customers' email addresses? Many more than just AT&T. And how many businesses sell their customers' email addresses to email marketers? Doesn't AT&T require customers to opt out lest their email address and other personal info be shared with AT&T "marketing partners". I don't know but I wouldn't be surprised. I have no opinion on the guilt or innocence of this defendant. Maybe he deserves to be prosecuted. But anyone with half a brain should be disturbed that a CFAA prosecution can proceed on a set of facts such as these. AT&T had to literally create "damage", by racking up a $7000 postage bill. Did the defendant "cause" money to be spent on postage? No, that expense was caused by AT&T's carelessnes in exposing email addresses and their subsequent decision to notify customers of their mistake by postal mail. Whatever happened to mitigation of damages? I guess there's probably much I don't understand about this case. But reading the brief, the interpretation of the statute sounds incredibly one-sided. With this sort of loose interpretation, how can anyone defend himself against a CFAA prosecution? If a party wants to claim some access to their computer was "unauthorized", then maybe they need to set up a proper mechanism for authorization. Usually, that's a password. The URL's this defendant accessed, where he found email addresses, were not password protected. Putting confidential information at URL's that you don't think anyone will guess does not seem to me to be a proper system for authorization. Claiming that anyone who stumbles on these URL's is making "unauthorized" access seems a like a weak argument. Apparently it'll do just fine.
- zimbatm 13y ago> Most importantly, like Auernheimer, researchers cannot always conduct testing with the approval of a computer system’s owner. Such independent research is of great value to academics, government regulators and the public even when – often especially when — conducted without permission and contrary to the website owner’s subjective wishes. It would be fun to do that in the real world ; Yes mister, I was walking in the mall at night. I though an independent review of their security system was important. Here are some of their employee files that I found in a drawer as a proof that personal information could be leaked. :D
- GeneralMayhem 13y agoMore like "here are some of their employee files that were taped to the front door, and which I leafed through out of curiosity." Anything that is URL-accessible without password protection cannot seriously be compared to being behind locked doors or even on private property. It's in public view.