Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The problem is that there is little consensus on what the boundaries in digital space should mean. Law makers, not without a certain logic, approach things from the principles of private property. Is changing a public URL considered "conspiracy to access a computer without authorization?" Well why would you do it, intentionally? Would you jiggle my door handle to see if that would unlock it? And if it was a crappy lock and jiggling it did unlock it, would it be unauthorized access to my property if you then walked in the door?

There is a line of thinking in the tech community that accessing data you're not supposed to access is only "bad" if you do something "bad" with it. But in meat space, we enforce fences in their own right, whether or not there is any other criminal activity involved. Arguably, doing so makes the larger problem of ensuring that their isn't associated criminal activity more tractable.

Actually, real world example: over the weekend someone stole my phone out of my (unlocked) car while it was parked in my apartment building's garage. Now, let's say he hadn't stolen the phone. Just rifled through the glove box and center console. No harm no foul, right? Of course not. We presume there is no good reason to be looking through someone else's car, even if you fully intend not to take anything.

Now, that doesn't mean we should treat digital boundaries the same as physical ones, but I don't think it's as obvious as some people in the tech community make it out to be that there shouldn't be penalties (of some sort--the magnitude of such penalties is a whole another debate) for intentionally violating digital boundaries, regardless of how well they are protected.



It's not likely that someone would get a long jail sentence for breaking into your car and not taking anything. If they had never committed a crime before, they'd probably get a fine or probation. There are usually monetary thresholds for a crime to be considered "grand theft" (a felony) vs. "petty theft" (a misdemeanor).


I don't think that violating digital boundaries without anything else should warrant long jail sentences (or any jail sentences at all). But I think there is value in enforcing borders in their own right, even if the punishment is nominal.


And if weev had seen the exploit, thought to himself, "heh, that's funny," and not gone back, he would not be headed to prison. But, that isn't what happened.


If he found it and then sold it to a government agency, he'd be rich and not in jail. Selling exploits to the government is a lucrative business. Google "CIPAV", for one.


Are you suggesting that the government would have purchased a bug in AT&T's website?


No. AT&T is willing to do anything the gov wants. Now, say it was a hole in Gmail? I bet there's government agencies, foreign and domestic, that would buy that for sure.


There seems to be a pervasive notion that because mass-exploitable remote code execution vulnerabilities have a market value, all vulnerabilities do. That's not true.


Agreed. I stand corrected.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: