Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> "Breaking in" suggests that there is access control (locks, doors, walls, etc) in place.

No, it doesn't. See, this is what happens when you start talking about crimes on the internet when you really shouldn't be. If I leave all my doors and windows opened, or if I put a box of valuables in the middle of an empty lot that I own, it doesn't suddenly make it legal for people to steal from me.

AT&T leaving their doors and windows open does not suddenly authorize any ol' grody troll to walk in and take personal information.

Whether you like it or not, his crime will be made into a physical analogy.



I _mostly_ agree with you.

How about _this_ analogy?

AT&T left a box of valuables in the middle of a lot they own, and weev walked by and grabbed them. Problem is, they weren't AT&T's valuables, they were mine and yours and 100,000 other peoples who'd entrusted AT&T with them.

Now who's "the bad guy"? Who's the more culpable "criminal"? WHo would we be holding to account if it were a bank who'd piled up the cash from 100,000 people's savings accounts into a building with all its doors and windows open?

Sure, what weev did was wrong. I don't think it was the _only_ wrong done here, or possibly even the "worst" wrong.


I think that's fair. AT&T should be reprimanded for a serious lack of security — how much they should be reprimanded would be another topic for debate.

But it doesn't take away from weev's crime (both this one and his previous harassments.)


Sorry for your distorted reality. You're saying that everyone who accesses unsecured information on a badly secured server gets reprimanded. You're placing the onus of security on the user which makes your point pure BS.


Granted. But how do you propose that AT&T would ever be reprimanded without someone like weev?

I strongly believe that weev should have notified AT&T before Gawker. But if they were unresponsive, as often happens, what then?


On the other hand, when AT&T leaves its doors and windows open 'in the web' they get a free pass from the general public because the technical aspect is lost on them.

If a bank used someone's first and last name as the 'access control' to their money, sure someone breaking in and stealing things is wrong, but should the bank be punished for negligence? Probably. When companies have security breaches 'on a computer' why is this different? Why the free pass? Why is the person that 'broke in,' or that that pointed out the flaw without breaking in the bad guy? Why aren't the companies themselves held to task for creating shoddy controls, and not following best practices when it comes to computer security?

A better example to demonstrate what's going on to the public would be to have a web form that says "Enter your SSN#" and a submit button. People understand that. Changing the terms in the URL bar is voodoo to many people, and this unfortunately leads to the belief that someone exercised nefarious skills to pull off an attack.


Is more like if you wrote out your customers personal data in a book left nailed to a front door that opens onto a public street and then tried to criminalise anyone who looked at pages that weren't relevant to them.


This is somewhat reasonable, since people need to actually come onto your property to access the book. It's probably unreasonable to say that someone was trespassing because they walked up to your door.


No they don't, the door opens onto a public street and the book is nailed to the front of it. This hypothetical book can be read while standing on the sidewalk. Sorry for not being more clear.


sneak said: "Breaking in" suggests that there is access control (locks, doors, walls, etc) in place.

ceol said: No, it doesn't.

I say: Yes it does. Your house has walls and probably a picket fence too. Either one is a boundary. The keyword here is "boundary" and not "locks". Having people's info waiting behind a serial number is not a "boundary" but rather a key-value pair accessible from the public domain. Your house is not accessible from the public domain because you have boundaries. Your servers are accessible from the public domain because you specifically have to put them online and make them accessible. Once you make servers accessible from the public domain then it is your responsibility to safeguard the privacy of what you put there. Weev did not DDoS the servers or inject SQL into their code. He accessed public info. Similarly if you put public info about you on facebook then it is not a security breach if I go there and check it out.


Physical analogies do not work regarding the internet. What happened is like he was given an address, he drove to it in a van, and a screen showed him his email. Then, he extrapolated that the buildings in the block he went to would do something similar, so he drove around to them in a car labeled 'VAN' and they showed emails.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: