6 ms·
If the researcher had done that -- queried every cellphone and published it -- I fully expect they'd receive the same treatment from law enforcement that weev a
by neuralk 8y ago
If the researcher had done that -- queried every cellphone and published it -- I fully expect they'd receive the same treatment from law enforcement that weev and Aaron Swartz got, if not worse
- gruez 8y agoscrape and publish the data over TOR. problem solved.
- kridsdale1 8y agoJoe Sixpack won’t browse it then
- amatecha 8y agohaha, oh they would when countless major news orgs carry the story!
- gruez 8y agopublish as in, send an email to major news publications
- celticninja 8y agoPublished as in make available on the web.
- shpx 8y agoYou can share a Tor website with people who don't have the Tor Browser installed by adding ".to" after ".onion" https://www.tor2web.org https://www.tor2web.org
- Cthulhu_ 8y agoThat one won't be up long, I mean all it takes is a link to that site to an onion site with some child porn or whatever.
- celticninja 8y agotor2web has been around for a decade now.
- deleted 8y ago[deleted]
- kyrra 8y agoI think Weev and AT&T us a better example. https://en.m.wikipedia.org/wiki/Weev https://en.m.wikipedia.org/wiki/Weev
- xfitm3 8y agoI was not familiar with this case. He received a sentence of 41 months! From wikipedia: “noting that no circumvention of passwords had occurred and that only publicly accessible information was obtained” My personal opinion is corporations have excessive influence over the US government.
- ada1981 8y agoIf we are going to have a flawed system, I’m glad when folks like this guy take the brunt of it. What a nut job. But yeah, accessing public information probably shouldn’t get you 41 Months in jail.
- pritambaral 8y ago> What a nut job. Agreed. > If we are going to have a flawed system, I’m glad when folks like this guy take the brunt of it. This is wrong on multiple levels. 1. It normalizes and makes it seem slightly more acceptable to have a flawed system; 2. This guy did not "take the brunt" of it. Plenty of other people — dangerous nut jobs and otherwise — have unjustly suffered similarly or worse at the hands of the US judicial system. 3. His conviction was later vacated and he was released.
- PhasmaFelis 8y agoWe should perhaps stop using Weev as an example of an innocent victimized by overzealous prosecutors. His actual conviction was trumped-up, but he'd likely have been in prison already if all the people he harassed and abused had pressed charges instead of trying to get on with their lives.
- nullymcnull 8y agoNeither the fact that Weev is a gigantic asshole, or your conjecture about what he might have been convicted of since, retroactively erases the injustice of the DOJ's absurd prosecution of him for the AT&T 'hack' - which was imo more about AT&T's wounded pride, and unwillingness to admit that they had effectively given that customer data away. The AT&T hack is a perfectly good example, probably the most relevant one we have, of someone doing exactly what the GP suggested. Which undoubtedly would face much the same kind of overzealous prosecution, if not much worse given the current climate. I do agree with GP though, and wish more researchers would be a lot less polite and well-behaved with their disclosures, sow a little more chaos even. This really was a golden opportunity to have a real national impact, and to give a huge number of non-tech people an unprecedentedly effective wake-up call.
- danmg 8y agoHe doesn't have enough technical skill to pull off anything. The AT&T hack, a for loop in php, was beyond his technical ability and had to get someone else to do it. Blogging about being a bad boy and pretending to be master of anonymous/the cyber aryan nation is his gimmick. He wishes he was david koresh, but he's completely harmless.
- ZephyrP 8y agoI have never seen him code, but I personally spoke with weev a number of times while he was a regular at a (in)famous SF hackerspace. He demonstrated a thorough familiarity with ptmalloc internals, enough to correct someone else's remark about fastbins (meanwhile taking frighteningly large hits of whippets). Additionally, he was the first person I had ever heard mention Rust.... wayyy back in 2012 (I'm embarrassed to say I thought he was talking about Racket and tried to correct him - I was 19 and thought I knew everything). He seemed to know quite a bit about the language even then. He continued to discuss other topics arising from this with other hackers. One such conversation I remember more clearly was his exchange with another hacker (a quite skilled one by my estimation) where he seemed to speak rather cogently about the relative merits of a complete semantic tableaux and SMT solvers to determine "real ptr lifetime" (beyond just adhering to a set of idioms that enable a constraint solver to verify reference use). So if he can't code PHP, then that's even more impressive. As an aside - in person, he came across as very warm, funny, charming and even deliberately inclusive. It feels strange now, but long ago, if you looked at him with the right shades on, he'd seem to give a nudge-and-a-wink that the "trolling", including his iconoclastic project of the time: the posthumous baptism of Muhammad's remains via becoming a Mormon deacon (of some sort??) were all intended to be thought-provoking irreverence rather than chaotic evil. No matter what was discussed he always gave the impression there was something more there, something almost hermetic. In those intervening years my view of him has assumed a different proportion. Those weren't all harmless culturejamming tricks pulled off in the name of some Discordian spirit which lies somewhere behind the neocortex of the hacker mindset. At that time, and many years before then, there were pranks, tricks and trolls that were unimaginably cruel, purposeless and petty. Since, prison has hardened him further into a wicked racist, who, lacking a better word, is insane.
- SlowRobotAhead 8y agoThat years later the website he started would be a monetized shill and bot cesspool? ;)
- derefr 8y agoWell sure; so just tip off a foreign national who already lives in Russia or whatever, and they can do it. Unlike an NSA leak, you don’t need physical access to places only US citizens can be in to touch this data; you just need an internet connection.
- ncallaway 8y ago> so just tip off a foreign national who already lives in Russia or whatever, and they can do it. That's ends up being conspiracy to commit the crime, which hits you just about as hard as the crime itself. You better be _very_ confident that the FBI/NSA won't be able to intercept your communications or tie you to the foreign national who commits the crime.
- derefr 8y agoOr... just be a foreign national who discovers this in the first place?
- stingraycharles 8y agoYou're literally suggesting that a researcher should go to Russia so that they can exploit the vulnerability before disclosing it to the people of the United States. I have a feeling that wouldn't fly well in court.
- dizziest 8y agoWhoosh? It's pretty obvious who derefr is talking about. EDIT: I can't tell if you're being sarcastic or not
- stingraycharles 8y agoApparently this is going over my head. Who is derefr talking about?
- tajen 8y agoGiven the enforcement served to whistleblowers, I’d be ok if they took financial benefit from leaks: Auction leaked data to foreign intelligence or companies, then make the price known. We’ve been warned enough times. That’s the only way Americans will put a price on privacy, and fines for unsecured systems will climb through the roof, with wilful enforcement by both companies and customers. And the whistleblower gets paid, better than rotting in Russia for years.
- tuxxy 8y agoThat's a great way to end up on espionage charges.