8 ms·
The free Web program that got Bradley Manning convicted of computer fraud
- venomsnake 13y agoQuantity has quality of its own. So does efficiency. When you make a process much more efficient you after a tipping point convert it to something else entirely - like the surveillance that. Technology is amplifier. Of course getting 10 more years just because he used wget instead of bash scripts that loop with nc is absurd. But the fact that he used simple automation to do the job should be taken into consideration. So should be the fact that solitary confinement is torture. But the whole trial seemed like Kangaroo court to me anyway ... Edit: Also technically he was authorized to use wget - he had permissions to download it from wherever or to install the package and had permissions to set the executive bit to true.
- alan_cx 13y agoNot trying to justify Bradley's treatment in any way, but to put the other side... Is it not possible that wget was not authorized specifically because if would make copying lots of file easier and quicker? I mean, if I were in charge of sensitive data like that, it would be the sort of thing I want to consider. If legit use is no say a file by file basis, then only a select few would need some sort of batching tool. So, why make it easier? That fact that you can do it other ways, I see no reason to then just allow anything. We all still have locks on our doors, despite knowing a determined thief will defeat or circumvent them.
- GhotiFish 13y agoI see where you're going with this, but you're fixing that problem on the wrong end. If they want to rate limit with exceptions, they should rate limit with exceptions. Not insist all the clients limit themselves, with exceptions. Following your analogy, we all have locks on our doors, despite telling thieves not to steal our cars.
- silentOpen 13y agoIf batch downloading is de facto fraud then the military should have been monitoring their HTTP logs for this suspiciously fraudulent signature and immediately stepped in to prevent the leak. That they had a mandate to secure sensitive data and failed in that task does not make Manning's actions fraudulent. Is security important to US military or not? Both having lax security at the time of breach and then severely punishing a leaker for using trivial tools does not inspire confidence in the competence of our military security.
- Amadou 13y agoAlso technically he was authorized to use wget - he had permissions to download it from wherever or to install the package and had permissions to set the executive bit to true. Do we know this to be true? Was Manning himself even responsible for the installation of wget on the systems he used?
- aqme28 13y agoNot authorizing wget and classifying that as computer fraud may have its justification, but giving someone 10 years for what amounts to a form of trespassing is absurd.
- jared314 13y agoThey are making an example of him for publicly distributing classified documents. The prosecution found every legal justification to convict him of that crime.
- ojbyrne 13y agoI'll admit to not really following the trial or general crime news, but it seems like "making an example" has become significantly more common over the past few years.
- frozenport 13y agoI would venture to say that making an example is a time tested tradition.
- nilved 13y agoIt's also unfair and immoral by definition. However long it's existed doesn't matter.
- dredmorbius 13y agoPity they don't take that concept to Wall Street.
- aa0 13y agoThey do but backwards. http://dealbook.nytimes.com/2011/03/18/ex-goldman-programmer-sentenced-to-8-years-for-theft-of-trading-code/ http://dealbook.nytimes.com/2011/03/18/ex-goldman-programmer...
- 13y ago
- pothibo 13y agoThis is crazy. If he had used IE "Save as a file", he wouldn't have been convicted of fraud?
- fnordfnordfnord 13y agoThat's what some people might believe, after focusing on the minutiae of the charges. I wouldn't bet on it though. Manning shamed and embarrassed his chain of command, the gov't at large, the military at large, the diplomatic corps, etc, etc. He was always going to get the book thrown at him; and the only thing that might have stopped it is widespread public outrage.
- anigbrowl 13y agoNo. This article strikes me as unreliable clickbait that shows a poor understanding of how the law operates.
- gambiting 13y agoSo is the US government listing every single program authorized to be used on their computer? And I mean every single one? That would include: -ls -cat -bash and in Windows land: explorer.exe If he used windows explorer to copy those files, could they have argued that explorer.exe was not on the list of authorized programs to use?
- gte525u 13y agoTypically restricted access computers (govt or not) require an authorization form to install software and require software to be installed by an authorized person. Any use of programs not installed via that process (with supporting paperwork) would be considered misuse. Even if the settings of the system do not prevent an authorized user from performing those actions. Furthermore, access to such systems will require the user also to sign an authorized use form.
- jlgaddis 13y ago> ... access to such systems will require the user also to sign an authorized use form. As well as agreeing to such policies every single time they log in to a computer.
- hackula1 13y agoSo I guess he could have used a nix box then and just used curl, which comes preinstalled? I am not saying the government has no case here, but using wget is way too fuzzy to weak to be one of the central charges.
- anigbrowl 13y agoYou know, I wouldn't rely on this article for accurate characterization of the government's legal position. Saying 'prosecutors argued that...' and then linking to a 2011 Guardian article threw up a red flag for me. That article didn't describe prosecutor's arguments; it described expert witness testimony. And the trespass was not the unauthorized nature of wget, although this was mentioned in passing, but the way in which it was employed to access data from the '.22' computer that was for secure/classified material. wget is mentioned by the forensic expert in the context of describing how he came to his conclusions, but that's a far cry from saying it's bad in and of itself. Suppose I'm investigating a physical trespass, and I say that I discovered characteristic bootprints in the area that perfectly matched a pair of boots owned by the suspect. That doesn't mean the boots themselves are illegal, it just shows that someone was wearing that particular pair of boots while trespassing. As far as mentioning the non-authorized nature of wget, it's equivalent to observing that the boots in my example were not regular army issue. I don't know precisely what prosecutors argued as I haven't obsessively followed the trial, so if someone can link to a primary source that contradicts the above I'm happy to be corrected. But as posted, the article seems to be drawing an incorrect inference from another news report, an as such is a questionable third-hand account of what prosecutors were really saying.
- deleted 13y ago[deleted]
- joelhaus 13y agoThis sounds accurate. My understanding is that the words "trespass" or "computer fraud" are used in relation to: http://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act http://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act (a law which I believe is generally construed far too broadly--even though it looks to be appropriate here). Nothing to do with wget, he could've used a browser to the same effect. That said, this reporting is indicative of most of the "journalism" around Snowden and Manning. While it's no longer surprising, it's still disappointing.
- ibudiallo 13y agoMake sure you read the fine prints before you view source on a page.
- tossmeup 13y agoBrawndo's got electrolytes. It's what computers crave.
- morgante 13y agowget likely came pre-installed...
- muyuu 13y agoThis was a Windows machine apparently. He used zip to compress, pointed to sharepoint links... looks like an all-windows operation. Looks like he downloaded and installed wget himself.
- DigitalSea 13y agoWow, wget is one hell of a tool isn't it? I think it should be a requirement that judges have to take a mandatory digital refresher course every 12 months to ensure they can deal with cases like this because this is ridiculous.They got him on a technicality, I guess they are clutching at straws and trying to get him on as many things as they possibly can.
- CptCodeMonkey 13y agoIssue is wget. >U.S. prosecutors pointed out that wget was not on the list of “approved” programs for use in facility where Manning worked. I know it sounds trivial but it was an unauthorized tool run on a system that was supposed to be secure as that system was talking to SIPRNET. Above all the other things PFC Manning has shown the world, he's also shown that security standards & procedures around some of the most damning secrets the DOD & State department could stupidly put on one fileshare was unprotected. Ironically this stuff might have shown up in foreign intelligence circles even without the PFC's actions.
- gpcz 13y agoAssuming the computer was running Windows, you wouldn't need wget to perform HTTP requests in batch -- you could make a VBScript to do it (src: http://stackoverflow.com/questions/204759/http-get-in-vbs http://stackoverflow.com/questions/204759/http-get-in-vbs ). I would assume that Windows (and therefore everything in it) would be considered "authorized" in that case, but would the VBScript be considered unauthorized software? If that's the case, would you need to get approval every time to write macros to make your job more efficient? Is there actually a line drawn in the military about what is considered software?
- megablast 13y agoInteresting, if the description in the article is true, would writing your own program count as running a program not on the accepted list?