16 ms·
This hacker might seem shady, but throwing him in jail is bad for everyone
- austenallred 13y agoReading this article http://www.theverge.com/2013/9/12/4693710/the-end-of-kindness-weev-and-the-cult-of-the-angry-young-man http://www.theverge.com/2013/9/12/4693710/the-end-of-kindnes... makes me feel not too terrible that he's being thrown in jail.
- computer 13y agoThrowing him in jail is an awful outcome for justice and for the precendent it sets. I'm very much hoping he walks out of court a free man. Once outside the court, he could get hit by a bus as far as I'm concerned. When we want weev free, we're fighting for law and society, for just principles, not for the individual.
- nym 13y agoI was with you up until wishing another human dead.
- gliese1337 13y agoTo be fair, there is an important difference between wishing someone got hit by a bus and simply not caring if they did get hit by a bus. I, for one, would not want him dead, as death is rather an overly severe punishment for his actual crimes. I would probably even think it somewhat unfortunate if he actually did get hit by a bus, simply because humans dying in general is unfortunate. But, were it to happen, an honest evaluation of my feelings leads me to predict that I would not weep.
- marshray 13y agoWe could also wish that Weev or people like him did not exist, without actually wishing that anyone now alive become dead, or predicting what our feelings might be were such a thing to happen.
- computer 13y agoI may have not formulated that as subtle as I meant, since English is not my primary language. So my apologies for that. I do not wish him dead. I mean that I'll fight for him in this case since it's important for society, but since he's such an awful person I would lose all interest in him after he's out of court. Read it as a figure of speech, since we technology people always speak about people who might get hit by a bus when thinking about the future of products.
- forgottenpass 13y agoNo, your meaning was clear. That guy was either trolling by deliberately misinterpreting you, or needs English lessons himself.
- subsection1h 13y agoWhat is the greatest harm that someone has caused you? Just curious.
- wavefunction 13y agoHe belongs in prison for a long time, but not for what he's currently being prosecuted for. It sets a terrible precedent, and I'm sure that, given his personality, he'll be prosecutable for something again soon enough.
- anaphor 13y agoIf memory serves, he was actually busted for drug possession not long after the gawker article went up, but he's not actually being prosecuted for that is he?
- deleted 13y ago[deleted]
- adamnemecek 13y agoSir Thomas More: What would you do? Cut a great road through the law to get after the Devil? William Roper: Yes, I'd cut down every law in England to do that! Sir Thomas More: Oh? And when the last law was down, and the Devil turned 'round on you, where would you hide, Roper, the laws all being flat?
- deleted 13y ago[deleted]
- freyrs3 13y agoOf course he deserves to be in jail, but he should be in jail under harassment and identity theft laws instead of the hacking charges.
- deleted 13y ago[deleted]
- mylorse 13y agoExactly! In the United States, there are protections for that: Libel & Slander Which is why he was convicted of. Harassment laws could also be implemented, depending on the jurisdiction.
- asabjorn 13y agoHe did something equivalent to scanning a public bulletin board for information that AT&T put there through what seems like sheer incompetence. There does not seem to be any hacking involved unless you also classify google as an automated hacking engine. I feel bad that someone might get jail time and a felony conviction for crawling a public forum.
- tlrobinson 13y agoAnd I wish the Westboro Baptist Church and a variety of other people who do objectionable things could be thrown in jail, but not by abusing laws and setting terrible precedents for further abuse.
- sneak 13y agoWeev's a right shithead, you're absolutely right. I still bailed him out of jail for the time leading up to and during his trial. Why? Because UNPOPULAR SPEECH SHOULD NEVER BE CRIMINAL, no matter how revolting. Indeed, it is the unpopular and revolting stuff that needs the most defending: "The trouble with fighting for human freedom is that one spends most of one's time defending scoundrels. For it is against scoundrels that oppressive laws are first aimed, and oppression must be stopped at the beginning if it is to be stopped at all." —H.L. Mencken
- mayanksinghal 13y agoI have no information of the case at hand, but that could the reason why the prosecutor went for hacking charges instead of harassment.
- LargeWu 13y agoThere's a huge gap between unpopular speech and harassment, which is illegal, and in many cases criminal. I agree he should not be in jail for the crime he was convicted of, but he almost certainly deserves to be there otherwise.
- PhasmaFelis 13y agoBy "unpopular speech", do you mean the AT&T bit, or the harassment bit? If the latter, I disagree. A free and fair society can certainly draw a line between "unpopular speech" and "criminal harassment." If I were to threaten to murder you, you wouldn't expect the police to say "Eh, nothing we can do, he's got a right to free speech. Call us back after he shoots you, you'll have a case then."
- jrockway 13y agoIf I were to threaten to murder you, you wouldn't expect the police to say "Eh, nothing we can do, he's got a right to free speech. Call us back after he shoots you, you'll have a case then." This is the problem with thought experiments regarding crime: they always make the facts 100% certain, when in real life, the facts are never 100% certain. If we were to rephrase your thought experiment, it would be: "Some guy said some other guy was going to kill him. Let's throw that some other guy in prison for a while, just in case." Not quite as clear-cut as you think, is it?
- CamperBob2 13y agoPopular people -- and popular rights -- can be defined as "the ones that don't need defending."
- rpgmaker 13y agoWoah, I am still against his prosecution but I don't really feel sorry for him now. Some people are just sick, why would he do that to a person for no reason? FTA: "His rise as a folk hero is a sign of how desensitized to the abuse of women online people have become," Sierra said. "I get so angry at the tech press, the way they try to spin him as a trickster, a prankster. It’s like they feel they have to at least say he’s a jerk. Openly admitting you enjoy ‘ruining lives for lulz’ is way past being a ‘jerk’. And it wasn’t just my life. He included my kids in his work. I think he does belong in prison for crimes he has committed, but what he’s in for now is not one of those crimes. I hate supporting the Free Weev movement, but I do." She is so much better person than I am.
- chris_mahan 13y agoFrom the internet, Kathy is a very nice and decent person. What happened to her is awful, and I'm glad she's still around, albeit in her reduced online presence. Shame on us all.
- meritt 13y agoYou're missing the point. The point is the government is charging him under the CFAA and that will set an extremely dangerous precedent. If they want to charge him under any other numerous crimes (data theft, attempted extortion, being an asshat) then I wouldn't have a problem with it either because those are things he's guilty/might-be-guilty of. Hacking and violating the CFAA is not one of his crimes.
- bcoates 13y agoThat link is baffling, the first few paragraphs sound like bad things happening but they don't form any sort of coherent narrative and the link to the New York Times article is a story about someone else entirely. It has the form of an outrage article without any actual content, as if someone fed Tumblr and Vice magazine into a Markov text generator.
- hackula1 13y agoThe acts described in the article probably should have put him in jail. The latest is unrelated though.
- legutierr 13y agoThe reason to defend weev in this case is to ensure that the specific act for which he is being prosecuted is not treated as a crime in other cases. If weev harassed this woman in the manner described in the article you reference, he probably should be prosecuted for that. But it's not ok for prosecutors to put him in jail for something that should be perfectly legal, just because they can't (or didn't) put him in jail for something else.
- msandford 13y agoIf you visit and internet cafe and someone's forgotten to log out of their bank account and you fiddle with it, that's probably a crime. Since in nearly all cases they probably didn't intend to do such a thing. We can surmise this by observing the banking website had a password to protect the account holder. This is evident by virtue of the "log out" link that's clearly visible and that the website is served over HTTPS and the normal convention that banking information is private. Now imagine that you come upon a computer and that you click on one of the favorites. It's a banking website. No password, no HTTPS, no access controls at all. Who is responsible for the security breach? You or the bank? I would argue that if there are no technological access controls in place, there is no such thing as "unauthorized access" You can't be unauthorized if there is no authorization. The default on the internet is "can access" They're prosecuting him for the digital equivalent of walking down a street and taking pictures of houses which don't display numbers on their mailbox.
- derleth 13y ago> I would argue that if there are no technological access controls in place, there is no such thing as "unauthorized access" You can't be unauthorized if there is no authorization. The default on the internet is "can access" Or is it like walking into someone's private home because they left the door open? Or merely unlocked? The law likes to operate on analogies, because analogous situations are ones for which we have precedent, and precedent makes the law predictable. The sad thing is, precedent goes back to the pre-computer era, too, and isn't necessarily overturned just because new technology with new social expectations is involved. Maybe in a couple generations.
- legutierr 13y ago> Or is it like walking into someone's private home because they left the door open? Or merely unlocked? It's more like if you were to walk into a retail establishment where the employees left the door unlocked after heading home for the day. You can't buy anything because the cash register is locked, and taking something would clearly be stealing, but if sign posted says "we're open", can you be faulted for looking around?
- killnine 13y agoThis was a legitimate white hat project until he collected more than enough evidence to prove his point. But he didn't stop there. Not at ten. Not at a hundred. What purpose does collecting thousands serve that just a hundred don't, in terms of white hat campaign?
- deleted 13y ago[deleted]
- mangoman 13y agoI love the use of analogy to describe the situation to those who may not understand exactly what Weev did. But can we decide law simply on analogy? Which analogy is a more accurate tale of what Weev did? What I like about this article is it explains what Weev did and how incredibly common his techniques were, without too much analogy. Analogies may be much more effective, but a direct explanation feels a lot more genuine.
- mylorse 13y agoHow about mines?: https://news.ycombinator.com/item?id=6435769 https://news.ycombinator.com/item?id=6435769 You are welcome to critique, not harass⸮:
- nonce42 13y agoIt's worth reading the criminal complaint and indictment (https://www.eff.org/cases/us-v-auernheimer https://www.eff.org/cases/us-v-auernheimer) to get some background. In particular: the discussions of using the email addresses for a phishing scheme, using them for spam, shorting AT&T stock and profiting off the data release, setting up WiFi routers so they can blame it on a third party, discussing how this was a federal crime, and how to spin themselves as a legitimate security organization. These things make it really hard to view weev as a genuine security researcher who was prosecuted for no good reason.
- joncfoo 13y agoThe entire IRC conversation comes off as jest - nothing actionable from what I read (besides running the scripts). Even so, since when did it become a crime to talk about doing something [illegal]? Also, Weev himself says that he is unwilling to short AT&T's stock - I think he understood the ramifications that would have.
- lawnchair_larry 13y agoIt's not worth reading that, because it's taken completely out of context. As badly as it's taken out of context, you're actually taking it even more out of context in your comment here. Weev actually said that shorting stock would be illegal, and said something to the effect of "if you do it, I don't want to know about it" and discouraged many other "suggestions" from people who didn't appear to have any real part in it, but were cheerleading. In any case, that is very typical IRC conversation for a large portion of that subculture. They joked about doing these things, but they didn't actually take steps to do them. He considers himself a satirist, so it's not much different than some comedians talking nonsense over beers and having it show up in an indictment. One of the chatters observing said they should post the list to full-disclosure. Weev replied saying "no, don't do that, its potentially criminal." He then talked about how he gets to spin it in the media and he's won. That says pretty clearly that he was only out to make a scene, which is what he has always done.
- victorf 13y agoSo because there was some thoughtcrime regarding actual criminal activity we should accept the prosecution for scraping the website? No. Prosecute him for identity theft if and after he commits it.
- biot 13y agoEveryone throws out analogies about walking into unlocked houses and such. Those are fairly poor analogies, so let me offer one which I think is far better at conveying what really happens. Imagine you walked into a public library and struck up a conversation with the librarian: You: Can you tell me general information about this library? Librarian: Certainly, this library was built in 1990, has a million books on its shelves, and... You: What are the hours? Librarian: Monday to Saturday, 10AM to 8PM. Sunday, 10AM to 5PM. You: Frothy bacon generates utilitarian synapses! Librarian: I'm sorry, that's not really a proper question I can help you with. You: Can I borrow book identified by ISBN 4961357406830? Librarian: Sure, here you go. You: Can I borrow book identified by ISBN 6498794651315? Librarian: Sure, here you go. You: Can I borrow book identified by ISBN 9840546790354? Librarian: Sure, here you go. You: Can I borrow book identified by ISBN 3168706780943? Librarian: Sure, here you go. You: Can I borrow book identified by ISBN 7893781056145? Librarian: Sure, here you go. You: Can I borrow book identified by ISBN 2764894617987? Librarian: Sure, here you go. You: Can I borrow book identified by ISBN 9764660911970? Librarian: Sure, here you go. You: Can I borrow book identified by ISBN 6666666666666? Librarian: Sorry, that book doesn't exist. You: Can I borrow book identified by ISBN 8669177714641? Librarian: Sorry, you've been requesting too many books lately. You: Can you let me into the Staff lounge? Librarian: Sorry, you'll need to show me your staff credentials when asking. You: Can you provide me with a list of all employees and their salaries? Librarian: Sorry, you are not allowed to have that information. You: Can I use the general conference room on the third floor? Librarian: Actually, that was moved. It's now on the second floor. As you can no doubt see, these translate directly into HTTP requests: GET / 200 OK - This library was built in 1990, has a million books... GET /hours 200 OK - Monday to Saturday, 10AM to 8PM. Sunday, 10AM to 5PM. POST /frothy-bacon-generates-utilitarian-synapses 400 BAD REQUEST GET /books/4961357406830 200 OK - [contents] GET /books/6498794651315 200 OK - [contents] GET /books/9840546790354 200 OK - [contents] GET /books/3168706780943 200 OK - [contents] GET /books/7893781056145 200 OK - [contents] GET /books/2764894617987 200 OK - [contents] GET /books/9764660911970 200 OK - [contents] GET /books/6666666666666 404 NOT FOUND GET /books/8669177714641 429 TOO MANY REQUESTS GET /admin 401 UNAUTHORIZED GET /employees/salaries 403 FORBIDDEN GET /floor/3/conference 301 MOVED; Location: /floor/2/conference In both cases, we have a gatekeeper (librarian / web server) which is capable of responding to requests, can authorize various requests, can require credentials for sensitive requests, can limit the rate at which requests come in, can deny requests altogether, and can identify when requests for certain things have moved to new locations. The librarian is smart enough to not hand out things like access to the staff lounge, a list of employees and their salaries, or even things like an arbitrary library member's borrowing history. The web server has been configured to not hand out things like admin access or other things which are deemed sensitive, but the owners of the web server have taken the position "Well, nobody's going to be guessing ISBN numbers, so we'll let anybody on the internet request the contents of those books." When is the onus on the web server owner to configure their security properly? When is a "200 OK" response actually not okay? This is the "mind reader" aspect the article mentions.
- 3327 13y agohe is a hacker? He must be doing computer sorcery - off with his head.
- PhasmaFelis 13y agoSo does anyone know why exactly they weren't able to get Weev on criminal harassment? I wouldn't expect the gummint to fail to bring the charge unless they thought there was no hope of victory, but it seems like such a gimme.
- bcoates 13y agoI'm not sure there is any relevant law. At the federal level it appears to require "obscenity" which is very hard to prove for anything short of child pornography.
- PhasmaFelis 13y agoIIRC, he photoshopped pictures of Kathy Sierra's kids into porn and posted them online, and emailed her graphic threats to rape her with a chainsaw, . It doesn't seem like you'd have a hard time convincing a jury of "obscenity".
- usaphp 13y agoHere is my analogy: 1. You just finished your workout and went to a locker room at your gym (he went to a public website) 2. You opened up your own locker and took your stuff from it (checked his account) 3. You found out that very few people are using locks in the gym locker room (figured the account id in url ) 4. You know that it is not your belongings in other people lockers, but they are not locked just because people are just lazy or don't want to spend money on the lock (he knew that those accounts do not belong to him, and were accidentally not locked by by at&t) 5. You decided if those lockers are not locked - that means that clothes inside of those lockers are public property and you can easily borrow them (tried to browser to other urls and get private account info) 6. You go ahead and try opening every single locker in a room and put all the belongings you find in opened lockers on ebay to make profit and sell it, BEFORE letting know the owners or the gym that those belongings are not locked. (sold private data to somebody) I think thats not legal behavior, as long as you understand that the property you are taking is not yours - you are making a crime by taking it (stealing)
- Liru 13y agoYour analogy starts to break down somewhere around point 3 or 4. It's not that few people use a lock on their locker. A closer analogy would be that the gym installed an electronic lock on each locker, but didn't actually make sure they worked. It also wildly disconnects around point 6. You make it sound like he stole everything that the users had in the accounts. In reality, he just copied their info. He didn't give himself anything from their accounts, like transferring credits to give himself free cable or something like that. Instead of stealing everything and selling it on eBay, it was more like him going through people's lockers, taking a picture of what they have inside, and then selling the pictures.
- Dylan16807 13y agoI reject that analogy pretty hard. Account ID is basically locker number. It's not a password/lock.
- andrewaylett 13y agoHow about replacing step three with "You notice that all the lockers have glass tops" and following that with a story about taking photographs?
- gwu78 13y agoKudos to the WP for ongoing coverage of this case. There are important issues being litigated here that could affect everyone, and I'd argue they are worth discussing without regard to this particular defendant and the sheer stupidity of his actions. However, I find WP's use of Poulson's activities as an example of "legitimate" automated HTML retrieval ("scraping") to be an odd one. It seems an awkward a comparison to convey what should be a simple point, in my opinion. How about something much more common? Googlebot. Imagine if we forbade Google from using automation and from scraping content and placing it in the Google cache. No more web search. Alas, because of the ad hoc nature of the Web (i.e., there is no unifiying organizational scheme for locating content across all websites as there would be in, say, locating content in a library of books), you cannot access Web content until you first discover it. In order to discover content, you generally have to search. In order to create an index and cache of content to search, someone has to scan/crawl/scrape websites. The later three are activities that are routinely automated. As such, they will violate many website Terms of Service and may get you banned simply for being "automated". In fact, to use Google as an example (not picking on them per se, it's just that they are a well-known example), crawling Google will "get you banned" from using Google, temporarily. The irony of this has always intrigued me: Google may crawl your servers, but under Google's policies, you may not crawl Google's servers. If I create an index of your website, at your expense (by aggressively running automated queries against your http server, as Google does, for example), am I obligated to share it with you? In any event, attempts to criminalize automation should raise red flags with anyone who is even slightly tech savvy.
- jebblue 13y ago>> The irony of this has always intrigued me: Google may crawl your servers, but under Google's policies, you may not crawl Google's servers. It looks like some of their site can be crawled and some not, that's how robots.txt has worked for a long time: http://www.google.com/robots.txt http://www.google.com/robots.txt
- gwu78 13y agoAnd search results (the data they have obtained via crawling others' sites) is not among the data that can be crawled. What are you suggesting?
- ajays 13y ago/u/biot's analogy is apt. But I don't understand why it isn't a defence that the HTTP protocol starts with a REQUEST . The server is the one who actually serves up the information. If I _request_ something from you ("hey, can I borrow your car?"), and you give it to me, then what's the problem here?
- mabhatter 13y agogovernment always prefers "shoot the messenger" to actual security. There should be literally be nothing illegal about what he did in that case. he didn't "hack" anything except HIS computer to pretend to be an iPad. And that would be the point of identifying it as a security concern. After all, if he had figured it out, surely the Russians and Chinese figured it out between when he did it and they prosecuted him... it doesn't make the hole go away!!! What he did is like sticking a GM car key into a Toyota. Generally that doesn't work, it shouldn't work... but what if it does anyway? shouldn't the company that makes the cars fix that?
- JanneVee 13y agoIt is annoying when people throw analogies around describe it to a highly technical audience. When is hacker news going to discuss the fact that User-Agent in the http header is not a security feature? When is the discussion that sequential id is equivalent to no security? No analogy in the world is going to change the fact that User-Agent checking and sequential id:s are not security features. And if courts are allowed to make them security features it is bad news for everyones security.
- hawleyal 13y agoThe information was public. He did nothing wrong. It is similar to accidentally posting all those email addresses on a bulletin board on the street and hoping no one reads them.
- darklajid 13y agoI know this is not a position people over here like to support, but.. But this technique, known as "scraping," is surprisingly common among technologically sophisticated users and has a number of legitimate applications. To get a list of sex offenders, Poulsen wrote an automated program to search the Department of Justice Web site for each zip code in the United States and then save the name and address of each registered sex offender in that zip code to a file. Really? Really? That's a 'legitimate application'? Nevermind that the pure existence of that registry is a slap in the face for people with my understanding of Freedom and Liberty (in caps), scraping _that list_ is why we want to protect scraping? I haven't felt that disconnected to content on this site for a long time. Yet most people would agree that Poulsen's actions were a legitimate journalistic project. So we might want to be careful about subjecting this kind of technique to criminal penalties. Most people?? In what world? I'm sorry for the detour, but the whole article is trying to defend weev while linking to atrocious actions of that guy in the past and coming up with the most despicable (Thanks Hollywood, learned a new term) reason for scraping _ever_. Disgusting.
- gtirloni 13y agoIt must be mental masturbation day here on HN.