7 ms·
I agree, but that is not the issue. The issue was how the case was decided. He incremented a number in a URL, and that was his ultimate crime. Do you honestl
by halviti 11y ago
I agree, but that is not the issue.
The issue was how the case was decided.
He incremented a number in a URL, and that was his ultimate crime.
Do you honestly think it's right to send someone to jail for several years because they were messing around with a URL?
Of course he likely deserved to be charged with something, but not what he was charged with, and it hurts the rest of us when things like this set a bad precedent.
- gph 11y ago>He incremented a number in a URL, and that was his ultimate crime. IANAL, but the way I understand it, it's not about the method that you used to access the system. Even if someone was highly incompetent and left their system open to being accessed, the fact that you accessed it knowing you shouldn't have is the actual crime. After all, even if someone leaves the doors and windows wide open to their house, it's still illegal to go inside if you don't have permission. In this case they left the URLs open to be accessed, but it was clear that that part of the website wasn't meant to be accessed by the general public and the prosecutors were able to convince a jury/judge that weev would have reasonable known that.
- msandford 11y agoI walk up to a grocery store with automatic doors. The lights are all on. The doors open. I walk in. It's 8am. This grocery store has two sets of doors, about 200 feet apart. At the other set of doors there is a sign that says that the store doesn't open until 9am. Am I trespassing?
- gph 11y agoAgain IANAL and trespassing is a different law than the CFAA, but if the prosecutors could reasonable prove that it wasn't an honest mistake and you were knowingly going into the store when you're aware it's not allowed, then yes I think you could be charged with trespassing. Like say you're an ex-employee who for some reason wants to go look at the schedule (maybe your stalking one of your old co-workers). If you walked in knowing the store was closed and you shouldn't be there, then I have to imagine you'd be arrested and charged with trespassing amongst other things.
- msandford 11y agoBoth deal with unauthorized access and intent don't they? The point I'm trying to make is that it's VERY difficult to divine intent in the absence of any kind of access control. In other words, given my above example and that's all the information you have, you can't prove that I intended to trespass. Now if the doors didn't open automatically and there was a broken lock, it's much easier to determine intent. But in Weev's case, there was no broken lock because there was no lock at all! Going strictly from the evidence we can surmise that AT&T didn't INTEND to prevent unauthorized access because they did nothing to prevent it.
- res0nat0r 11y agoWe always delve into ridiculous analogies on this site for some reason when it comes to this case, trying to somehow justify that someone, knowingly, was accessing a system they, again knowingly, knew they should not have been accessing. Status codes, locks, no locks, these silly analogies aren't really useful. Proving intent is.
- msandford 11y agoSo prove the intent. Prove what was going on inside his head. Prove that he didn't merely SUSPECT that he shouldn't have had the information, but that he KNEW he shouldn't. The reason that things get so silly is that it's very difficult to prove intent in the absence of any kind of access control. If he had bruteforced an admin password, the intent trail is there to be found. If he had done SQL injection, again, it's easy to argue intent. If he had physically broken into the building and stolen paper documents, again the intent is easy to discern. I would argue that it's akin to finding an unmarked binding lying in the street with absolutely no way of telling whose it is, and what it contains. You open it and don't see anything that says "AT&T confidential information" and start paging through it. How could you possibly be convicted of a crime for that? I know there's criminal "finding" whereby you don't try hard enough to return something to someone that's obviously lost it. But that doesn't apply in this case because the binder in question isn't marked in any kind of meaningful way. Even if it had a header or footer or cover or something that said ANYTHING then I'd be persuaded differently. But leaving a web service with confidential information on the internet with no access control, I might argue is criminal negligence.
- rhino369 11y agoThat is a poor analogy. I'd say it's more like walking into the back room of the store even though the door was wide open, and then snooping around in there. That is trespassing.
- msandford 11y agoI actually think it's the perfect analogy. It's a robot that does exactly what you tell it to do. If you apply power it'll open for ANYONE and if you don't apply power, it doesn't. I can't see a better analogy for the webserver that revealed confidential information as someone who accidentally left the automatic door on. It opened when the owner didn't want it to, but you can't blame the user of an automatic door for taking its working as some kind of implied permission. If the owner of said automatic door didn't want it to open he or she had only to switch the door off to make their desires translate 100% into real action. Where things get dicey is that there are certain customs and tradition and clues regarding whether a store is open or not. If the lights are off and it's the middle of the night and there are no cars in the parking lot and etc, it's probably not open and the door opening is probably a mistake, not on purpose. The internet does not provide any kind of context clues like this, except perhaps for robots.txt and that doesn't apply to humans!
- jMyles 11y agoYou've been too charitable. The site gave a 200 status code. It's more like the store having a huge sign that says "OPEN, COME ON IN!"
- tptacek 11y agoThis is logic that says that SQL Injection is fine, so long as the HTTP request bearing it elicits a 200 response. Obviously, outside the airless void of a message board argument, this isn't how things work.
- jMyles 11y ago> This is logic that says that SQL Injection is fine, so long as the HTTP request bearing it elicits a 200 response. For my tastes, this is actually a reasonable configuration of things. Nobody is forcing you to use HTTP. If you decide to, and you provide access to your database via HTTP, and you allow me to submit a payload which makes changes you don't like, you are welcome to stop me and issue a 403. It's your database, after all. This whole controversy seems like a way of shifting blame for security failures from the parties who actually failed to people who were uninvolved in the implementation and just happened to be the first (or the first noticed) to use applications in a way unintended by the designers.
- gph 11y ago>This whole controversy seems like a way of shifting blame for security failures from the parties who actually failed to people who were uninvolved in the implementation. That's basically victim blaming though. If someone commits a crime against you, we don't let the criminal go free just because you were inept or negligent in preventing the crime. In a sense they committed a crime against all of society by breaking our laws. It would be ridiculous to start applying laws based on whether the victim did enough to prevent it. No one should be allowed to break the law no matter how easy and vulnerable a person leaves themselves open to it.
- jMyles 11y ago
- jMyles 11y ago> After all, even if someone leaves the doors and windows wide open to their house, it's still illegal to go inside if you don't have permission. Holy hell this metaphor is so bereft of life. When will we stop using it? Weev didn't go to anyone's home. He stayed at his own computer. Typed in URLs. Received a 200 status code. There are really no good, compelling similarities between this action and entering someone's home.
- gph 11y agoFine let's drop the analogies > He stayed at his own computer. Typed in URLs. I don't understand why everyone in this message thread is being so obtuse about how he accessed the site. It DOESN'T matter what method you use to access the system under the CFAA. The thing that matters is intent. If you disagree with that then fine. And whether anyone can actually prove beyond a reasonable doubt what someone's intentions are is infinitely debatable. But the fact of the matter is that the prosecution proved in a court that weev knowingly accessed a portion of a computer system that he knew wasn't meant to be open to the public and that he knew he did not have authorization to access. It doesn't matter that all he had to do was type in a URL. He knew those URLs weren't meant to be accessed by him, or at least that's what was proven in court. I'm not really trying to get into a debate about whether the CFAA is a good law, I don't really think it is. But there's certainly evidence that weev broke the law as it's currently written. Yea he got a 200 status code back and we can endlessly debate whether that should mean someone is given permission to access the site. But I think, and the jury/judge agreed, that weev wasn't just poking around their website thinking that those URLs were open to the public. I mean come on, this wasn't just some random user who happened to type in a URL not knowing what it was going to access. Weev knew what the fuck he was doing. Whether there's actually enough evidence to prove that is of course up for debate, but as the law is currently written I think he was guilty.
- jMyles 11y agoI agree 100%. The law is stupid, weev knew he was being a jackass and he said so. I was just saying that the "if I leave my house unlocked..." analogy is totally toxic to an adult conversation on the matter.
- tptacek 11y agoThis is exactly like saying that someone convicted of trespassing had an ultimate crime of "turning a doorknob", ergo we should all fear for our ability to turn doorknobs. No, that's not how it works. The state must prove not just action, but intent.
- dragonwriter 11y agoWell, its not that similar, in that weev's conviction was overturned on appeal based on improper venue, with the appeals court also quite skeptical (though, as the improper venue was sufficient to dismiss the conviction, not stating an authoritative conclusion on this point) as to the sufficiency of the evidence to support the charges. Both the people arguing for and those arguing against the result in weev's case seem to be forgetting what the final result actually was.
- tptacek 11y agoI'm sorry but I don't see what this has to do with the point I raised. I am very familiar with Auernheimer's case, so if you could spell out in more detail what you're objecting to, I'm pretty sure I can follow along. The point I was making upthread had less to do with Auernheimer's case than it did with the silly notion that the case turned on "incrementing a URL".
- dragonwriter 11y ago> The point I was making upthread had less to do with Auernheimer's case than it did with the silly notion that the case turned on "incrementing a URL". Your rebuttal seemed to be based on the premise that the conviction turned on more than action, but substantive evidence of intent. My response addressed the fact that, while the conviction was dismissed for procedural reasons, the appeals court also appeared skeptical of the substantive result the same reasons that the critics here are -- that the evidence did not appear sufficient to show the intent.
- tptacek 11y ago
- dragonwriter 11y ago> He incremented a number in a URL, and that was his ultimate crime. What ultimate crime? Are we forgetting that weev's conviction was overturned on appeal, indicating that it was a result of legal error. There was no crime. Not in a "well, some people on the internet think he shouldn't have been convicted" sense, but in a "the legal system has authoritatively declared that his conviction was in error" sense.