back

by rdl·16y ago·view on hn ↗
I think it's shameful that no one has stepped up to provide him with free, top notch legal assistance. I'm relatively familiar with the case (I know weev personally, too), and he is actually not exaggerating. This is exactly the kind of case the EFF exists to defend. Yes, weev is a troll and a media whore, but that doesn't automatically make him wrong.

Goatse behaved in the industry accepted standard way in popularizing a security vulnerability -- full disclosure. I personally would have done the same (although I would not have kept illegal drugs at my residence after doing so, but I also would probably ventilate anyone breaking into my home without clearly announcing a warrant...)

Free weev!

4 comments
> Goatse behaved in the industry accepted standard way in popularizing a security vulnerability

Well, as someone working in the security industry I take slight issue with this. They appear to have cashed in on the media coverage as much as possible rather than focus on proper disclosure practices. I (and a lot of people in my job, I think) would consider it just on the wrong side of unethical.

The defense of freedoms often involves defending those who exercise them in a way that we don't approve of.
Agreed; and if he is being unfairly refused representation that is a serious matter.

Additionally if he has broken no actual laws then that needs to be cleared up and he needs to be apologized too.

However I feel there is an important distinction between defend and approve; I would, for example, represent him. But I don't condone his approach to disclosure :)

Non-disclosure, vs. Responsible disclosure, vs. Full disclosure (with various levels of warning to the vendor), vs. Aggressive full disclosure is certainly an open point of debate within the security industry. It's pretty unambiguously clear that he didn't use the fruits of the vulnerability in a black hat way to hurt the end users, however.

My personal position varies based on the kind of vulnerability, actual risk to end users, etc. For something which causes minimal harm to the end users (publishing email addresses? really?), which was the result of utter incompetence on the part of a single vendor, and where the vendor can trivially fix it, I think aggressive full disclosure is the right course of action.

If it were something like a flaw in cisco bgp, I would support responsible disclosure, on a very long timescale; give the vendor enough time to fix it, and get the patch deployed to as many users as possible.

If it were a flaw in a no-longer-maintained system which were critical to life safety, I could be convinced to not disclose at all, provided there were something put in place to transition users off of the system.

It's pretty unambiguously clear that he didn't use the fruits of the vulnerability in a black hat way to hurt the end users, however.

No and I don't think that accusation has ever been made.

However; he has used the data very unethically and I don't think that it is reasonable for him to claim journalistic privileges or the cover of full disclosure to assuage that.

I have not been following the case, nor am I an expert on security disclosure. Could you expand on how he has used the data and what was very unethical about the uses made?

EDIT TO ADD: Reading your other postings I think you mean giving a copy of the leaked data to Gawker media was unethical. Is that so bad, considering they redacted it and appeared to generally handle it responsibly?

Yes. Your latter point does (and I cant believe I am saying this...) credit to Gawkers handling of the data. But Goatse handed it out (so far as we know, I admit) with no idea of what would be done with it.

Also from a security perspective (at least from mine) it is just unethical to hand over data you got - no matter how trivial :)

Why is it "shameful"? It wasn't clear whether or not weev even asked the EFF/others to defend. It seems like he only asked the judge for a public defender and was denied, and then he ranted about that for awhile.

Did he ask others to defend or at least give him some free consult/referrals? Did he get denied by them?

The problem is that weev doesn't understand how a grand jury subpoena works. He has not been indicted, nor charged with any crime related to the "hack" yet. He has only been asked to testify in front of a federal grand jury. The government has no responsibility to provide a public defender, because he hasn't been indicted and charged with a crime yet. Technically, he's not yet a defendant.

I should mention the other charge for possession is most likely completely separate, and being handled at the state/local level, since he didn't commit a federal crime in that regard (it would have to be interstate trafficking).

In short, weev doesn't understand how the federal justice system works and is asking for help.

That makes sense. His jump to conclusions made the essay longer and more convoluted and confusing than of he just said "I need legal assistance and I don't have any funds. Help!"
I believe weev has some kind of negative history with EFF.
Why aren't we reading about that, and instead reading about zionists and why a judge denied him a public defender for a misdemeanor drug charge unrelated to the computer security issue?
Not to mention that those opposing the EFF's agenda of open network access must see weev's behavior here and earlier as exemplary of why such access is dangerous.
Not to mention that Weev is on record as opposing said agenda. http://weev.livejournal.com/384838.html
I don't think the EFF should be spending donated money defending black hats from potential criminal prosecution. There are far more white hats out there that have been unfairly targeted for true responsible disclosure. There are also a lot more important free speech issues to defend than your right to shout private AT&T account information in a public theater...
I would have been 100% behind him if he had said, "hey, I noticed this hole, visit http://att.com/account_info.php?omg=noes and have a look!" By actually publishing the information, he proved that he accessed information he was not authorized to have, which the law does technically say you are not supposed to do. (The "hey, I noticed this hole", IMO, is not enough to build a solid case against him for accessing data he was not supposed to have. IANAL, though.)

Either way, though, prison is not an acceptable outcome for this behavior. "Don't do this again," maybe, but not being locked in a cage for years. How would that help anyone?

Lets hope Apple will step-in and to stand by his civil liberties. I heard they took some moves for the same for Chinese workers :P