Slashdot Mirror


Adrian Lamo Charged With Hacking

retro128 writes "Drifting around the US from state-to-state, Adrian Lamo has been making news for some time with his 'White Hat' hacking exploits. His highest-profile hacking has included Excite@Home and Yahoo. After he would break into a network, he would call up those in charge of it and help them fix the holes. So far, it has earned him praise from the administrators of those systems, but now SecurityFocus is carrying the story that the FBI has filed charges against him, and currently has his parents' house staked out. The records are sealed, so nobody knows who is responsible, but Lamo suspects the New York Times initiated the investigation when they found out how deep into their system he got."

90 of 527 comments (clear)

  1. Fit? Stops. R by Anonymous Coward · · Score: 2, Funny

    Adrian : Rule #1 : If you seek credible, first hack your own personal details to requisition a new surname.

    1. Re:Fit? Stops. R by Anonymous Coward · · Score: 3, Funny

      Yep, how do you think the New York Times felt when they'd heard that their site had been hacked by some Lamo? Of course they're going to take it personally! Now if they'd heard that Max Power had hacked into their site... that could have been another matter.

    2. Re:Fit? Stops. R by krymsin01 · · Score: 4, Interesting

      I'm sorry, but I think your analogy is unsound. A true white hat hacker doesn't drink the beer, try on the underpants, eat the pizza. More like someone you would drive by with your trunk door open, and they tell you that it's open so that all your stuff, which might be your private underclothes, doesn't end up in the middle of the road for everyone to see.

      People often make the assumption that morality dictates law. This is simply not true. In other words, if someone breaks into your system and tells you about it and helps you fix the holes instead of using your system for their own personal gain, then he's done you a favor by doing your job for you and saving your employers money if someone ever did exploit you maliciously.

      --
      stuff
    3. Re:Fit? Stops. R by zootread · · Score: 3, Interesting

      I agree that the analogy does not work. I think a better analogy is:

      You happen to figure out the combination for the lock of my safe. You open it up, look at all the nudie photos of my girlfriends (and maybe watch one of the videos). So then you tell me you figured out the combination to my safe and opened it. I know what you've seen.

      So say a someone breaks in but doesn't appear to do anything malicious. How do you know he didn't look at anything? How do you know he didn't read everyones personal mail, or log any credit card numbers or passwords? You don't. Sure, a true white hat should not be doing these things, but do you really trust someone to be a true white hat?

      When I was a teenager, I used to gain unauthorized access to systems for fun, but never did anything malicious. I was a bit of a white hat, and got rid of other people who had cracked the systems. However, I was keenly aware of the fact that I could be arrested and charged heavilly for what I was doing. If you do something illegal, you can be charged for it. Sometimes the law isn't right, but I'm finding it hard to side on Adrian Lamo's case here.

      I would love to go around cracking systems for fun and telling the admins how to fix the problems without having to worry about getting arrested. But this is simply not the case.

      --
      Zoot!
    4. Re:Fit? Stops. R by zootread · · Score: 3, Interesting

      I'd also like to add, I don't think the term "white hat" can apply to people who illegally break into systems. A white hat would be someone who sets up his own systems and tests security on them, or has permission to work on a system. He would announce vulnerabilities when he finds them, usually contacting the author of the vulnerable software first. He's the true "good guy" who has done nothing wrong.

      There's another term for someone who breaks into systems illegally, but does not do anything malicious, who may or may not do anything to help fix the problems. I believe they are called "grey hats." Hence the grey area here.

      Of course the black hats are the true criminals, who are doing other illegal activities besides the break-in (stealing credit card numbers, desctruction/defacing of the systems, etc).

      --
      Zoot!
    5. Re:Fit? Stops. R by zootread · · Score: 2, Insightful

      This is hardly practical or applicable to the real world.

      I disagree. A lot of vulnerabilities are found the way I described. They are only exploited after they've been found and the script kiddies know about it. Doing something illegal is hardly practical, in my opinion.

      As for getting permission in advance, how many sysadmins do you know would give a hacker permission to try to get in through security?

      I'm talking about hiring a professional to try and penetrate your network in order to determine where the vulnerabilities are. This is what is practical and applicable in the real world. I'm not talking about giving some random kid permission to screw with your network.

      Before all of you get high & mighty and denounce what Adrian did, realize that his way of doing things is probably the only one that works.

      You mean the one where you get caught?

      --
      Zoot!
  2. The Real Problem by Goo.cc · · Score: 5, Funny

    Maybe the real problem that the New York Times has with Lamo is that he was able to read stories without having to register for a free account. (Hell, that stupid registration requirement make me want to hack them too.)

    1. Re:The Real Problem by Surak · · Score: 4, Funny

      Yep. That whole &partner=GOOGLE thing will get the FBI after ya. Watch out!

    2. Re:The Real Problem by FsG · · Score: 5, Informative

      No need to look for new exploits when the existing ones suffice..
      1. Click on URL, you're redirected to registration/login page
      2. Go to URL bar, replace "www" with "archive" in the URL, leaving the rest alone, and hit ENTER
      3. The system will bounce you around a few erroneous URLs, before returning you to the homepage
      4. All NYT links will now work without registration, thanks to a special cookie set by the bouncing process

      --
      I made a PHP/MySQL library that prevents SQL injection & makes coding easier!
    3. Re:The Real Problem by Anonymous Coward · · Score: 2, Funny

      Nah, the NY Times is ashamed that someone actually found true facts on their web site.

    4. Re:The Real Problem by Anonymous Coward · · Score: 2, Funny

      But in this case, Adrian Lamo used &partner=in_crime

    5. Re:The Real Problem by shfted! · · Score: 3, Funny

      I always use &partner=EVILHACKER. They seem to like that too!

      --
      He who laughs last is stuck in a time dilation bubble.
  3. And good riddance. by JeffTL · · Score: 3, Insightful

    Who needs more greyhats running around testing security without so much as permission?

    1. Re:And good riddance. by SerpentDrago · · Score: 5, Insightful

      If you ask and tell theam your going to try to hack. Then they will tighten security. Thats exactly why you can't tell theam. You have to just do it. at a random time without theam knowing , then see if they catch it. Thats the only true way to "test" Do it Blind or it is not real. A BlackHat will never ask or tell you when.

    2. Re:And good riddance. by Shoten · · Score: 5, Insightful

      I think you're confusing what Lamo did with something that the NYT actually gave permission for. I agree with you, that a penetration test should be performed in such a way as to be unexpected, so paranoid admins can't do stupid things to improve the results (like turn off all inbound access for a day). But this wasn't a penetration test, it was nothing more than an uninvited and deeply illegal intrusion plus some spin control for the media.

      I know a lot of people look at it and say, "Oh, but he had good intentions, that makes it ok!" It's not really like that...we don't KNOW his real intentions at all, just what he SAYS his intentions are. But, if someone owned your network, would you just trust them when they say they didn't do anything more insidious than they told you about? I wouldn't, and the resulting cleanup to make sure that nothing more was done is an expensive and disruptive process. This is part of why the damages for relatively minor hacks end up being so enormous in many cases.

      We're always pushing ourselves to question what we're being told by the media, by our leaders, by our educators, by big business...we should really question anyone who might have an ulterior motive.

      --

      For your security, this post has been encrypted with ROT-13, twice.
    3. Re:And good riddance. by HidingMyName · · Score: 2, Insightful
      If you ask and tell theam your going to try to hack. Then they will tighten security. Thats exactly why you can't tell theam. You have to just do it. at a random time without theam knowing , then see if they catch it. Thats the only true way to "test" Do it Blind or it is not real. A BlackHat will never ask or tell you when.

      Let's try a little analogy and see how you like tha argument.

      If I ask you and tell you that I'm going to access your bank account, then you will just tighten security. This is exactly why I need to access your bank account at a random time without you knowing, then see if you catch it. That's the only true way to "test".

      It would seem that this argument is weak, because if some whitehat got your social security number, bank info, etc. you'd be upset. How would you know it is really a white hat and NOT a blackhat?

    4. Re:And good riddance. by xplenumx · · Score: 4, Insightful

      The University of Washington had a "student run" program where returning students could volunteer to help freshmen move into their dorm room. In return for their help, the UW would supply the volunteers with free food (Usually through SubWay, Dominos, etc, with a student leader ordering the food using UW budget codes). After everyone moved in, the group would disband and everyone would forget about it until the following fall. Approximately six years ago, the student leader who was in charge of ordering food decided in Winter quarter that he would use the budget codes and try to order up some food for him and his friends (http://tinyurl.com/mhck) . What was Eric's excuse when he was eventually caught? "I was just trying to show how insecure the system was" and "I was really doing Res. Life a favor". Sound familiar? Eric Feigenbaum then wrote a series of articles to the student newspaper, The Daily, regarding his experience and how the university didn't appreciate his 'generous act'. Personally I become extremely nervous when someone decides to conduct some unannounced public service, especially through illegal means. Usually the "I'm just misunderstood. I was really trying to help out" excuse comes out after the individual gets caught, but some individuals will come forward first, hoping that it'll cover their tracks. For example, I had one employee to came up to me and said that they learned how to use the copier without first putting in their copy code. Turns out the employee decided to "test" his method by making over 5000 copies over a period of three days (all after hours). Another employee within the firm reported that some equipment was missing (it would have been discovered later that week). It was eventually discovered that the very same employee had stolen the equipment the night before. I don't know the first thing about Adrian Lamo besides what's written in the referenced article. He may be the most honest, altruistic, and generally nice guy in the world. Good for him. The problem is that the next Adrian Lamo may not be.

    5. Re:And good riddance. by frater_corvus · · Score: 2, Insightful

      I know a lot of people look at it and say, "Oh, but he had good intentions, that makes it ok!" It's not really like that...we don't KNOW his real intentions at all, just what he SAYS his intentions are.

      While I agree with the content of your post, I would wager that this would be treated like any other criminal charges. By reviewing his public track record at Security Focus most people investigating Mr. Lamo's public past would deduce that he probably wasn't doing anything vindictive or with ill intent. For example, as quoted from the previous link:

      WorldCom is the latest target of a clean-cut 20-year-old hacker who's already drawn national attention discovering, exploiting, and then warning about serious security lapses at AOL, Excite@Home, Yahoo! and Microsoft. Like those other companies, security staff at the $20 billion communications giant might be surprised to learn they were compromised by a lone vagabond hacker who lives out of a weathered L.L. Bean backpack and does most of his work from Kinko's 'laptop stations,' using little more than a Web browser and his wits.

      While it doesn't make his activities any less illegal, it lends evidence that he had no motive other than exposing a security flaw with the NYT. Provided that's what Mr. Lamo is actually being charged with.

      Personally, I think people like Mr. Lamo make the world a better place. Sometimes, you don't know about an insecurity ( or don't care ) until someone actually does something to your information. Much like how I was raised to always lock doors and windows, but a lot of my friends don't seem to see the point. When their belongings go missing, I won't even bother saying, "I told you..."

  4. Great Excuse by Pave+Low · · Score: 3, Interesting
    So if someone had broken into my house without permission, then told me about it afterwards, am I supposed to feel better about it?

    Maybe I didn't install a deadbolt and an alarm system, but who made this guy the "helper" of my problems?

    There are no white-hat, gray-hats or black-hats. Only criminals and law-abiding citizens.

    --
    SIG:Slashdot: indymedia for nerds.
    1. Re:Great Excuse by hattig · · Score: 5, Interesting

      Agreed. If he wanted to perform white hat hacking, he should have approached the companies involved and asked for a job to test their security. Hell, he'd have earned money that way as well.

      But he did commit a crime - he broke into and entered their systems without permission. Sure, he did it for a good reason in his own head, and wasn't going to be malicious ... but it isn't as if he was doing the internet equivalent of rescuing the baby in a house fire.

    2. Re:Great Excuse by nearlygod · · Score: 5, Insightful

      How different is this from the investigative reporters on your local news broadcast. In many cases a white hat my find that customer's CC numbers or SS numbers are accessable via an exploit or weak security. In a way, he/she would be helping the public by giving the company and opportunity to correct the situation or at least take it public. An investigating reporter may find that a company or governemnt office is throwing out sensitive info without shredding it or taking the proper preventative measures. If I am giving a company like Amazon my CC#, I want to oknow that they are going to protect that info. Who is going to watch/audit the company if they get lazy?

      --
      The Tools Of Ignorance wanna be a tool?
    3. Re:Great Excuse by moonbender · · Score: 4, Interesting
      So if someone had broken into my house without permission, then told me about it afterwards, am I supposed to feel better about it?
      That analogy doesn't have a lot of merit. You're a private person, he didn't break into private computers. If a bank has a door to their vault which they don't know of and which is never locked, then yeah, they should be grateful for being told about it. Obviously, there's no bank so stupid, but that just goes to show that banks have a lot more experience dealing with real-world break-ins - another reason why this guy should be acknowledged for his deeds, he's making people aware of problems which they are not experienced in dealing with.
      --
      Switch back to Slashdot's D1 system.
    4. Re:Great Excuse by alienw · · Score: 2, Insightful

      I think that the reason he didn't ask for permission is because no company would have permitted hacking their systems, regardless of purpose. Yahoo does not need super-secure systems, so they have no need for a security consultant. In my opinion, the guy only wanted publicity.

      It seems like people don't quite understand that hacking someone's system and then "helping" them fix the holes is not a positive thing. If you steal my car, return it a month later, and then "helpfully" point out that I should get a security system, you deserve to be in jail.

    5. Re:Great Excuse by qtp · · Score: 4, Insightful

      So if someone had broken into my house without permission, then told me about it afterwards, am I supposed to feel better about it?

      But if someone noticed that you can see into your bathroom and bedroom from the street, do you get them busted for being a peeping tom?

      The guy's not threatening anyone, nor is he stealing or endangering anyone's life. The "Housebreaking" metaphor doesn't realy apply.

      OTOH, your mention of the deadbolt and alarm does apply, but only in the sense that if I did buy/install a deadbolt and alarm, I'd be royally pissed if they didn't work.

      --
      Read, L
    6. Re:Great Excuse by maggard · · Score: 3, Insightful
      But if someone noticed that you can see into your bathroom and bedroom from the street, do you get them busted for being a peeping tom?
      But he didn't just "look in", he went and altered files. And the curtians were down, the door closed, he didn't just happen to glance in but broke in.
      The guy's not threatening anyone, nor is he stealing or endangering anyone's life. The "Housebreaking" metaphor doesn't realy apply.
      Breaking & Entering doesn't mean anyone has to be home or their life directly threatened.
      --
      I don't read ACs: If a post isn't worth so much as a nom de plume to its author then I wont bother either.
    7. Re:Great Excuse by dirk · · Score: 3, Insightful

      Except we was in the systems and could have done anything while in there. Maybe he is a true "white hat" and didn't do anything bad and told them everything. But it is just as likely that he left a trojan or backdoor in the system. They can't tell what he did or didn't do, so they now have to not only secure their systems against whatever hacks he used to get in, but they have to scour everything on the system to make sure he didn't change any data or leave anything behind (and there is no way to tell whether he copied anything from the system).

      --

      "Information wants to be expensive" - Stewart Brand, the same guy who said "Information wants to be free"
    8. Re:Great Excuse by Have+Blue · · Score: 4, Funny
      But if someone noticed that you can see into your bathroom and bedroom from the street, do you get them busted for being a peeping tom?
      No, but if he calls me up and says "I was watching you through your bedroom window last night" I would.
    9. Re:Great Excuse by pantropik · · Score: 4, Insightful

      That's a really awful analogy.

      If someone steals your car they are doing you a serious disservice and actively depriving you of something you cannot easily do without.

      To use your analogy in a way that actually makes sense:

      He isn't stealing your car. He is walking up and seeing if the door is unlocked and the keys are in the ignition. At the very MOST he is starting the car to prove he COULD steal it if he wanted to. But he never actually steals the car or harms you in any way (except maybe making you feel really stupid for having such an easily stolen car). He doesn't deprive you of it "for a month".

      Basically he's checking to see if he COULD steal your car, NOT stealing it. Then he tells you what to do to keep others from stealing it.

      Doesn't sound like evil incarnate to me. If I was being a total idiot as regards security I think I'd appreciate it if someone pointed that out to me before someone else came along and took advantage of it and ended up doing real harm.

      The shame would be worth it in the end, I think. Unless you happen to be the NY Times, which is probably pretty sick of being shamed at this point.

    10. Re:Great Excuse by xenoandroid · · Score: 4, Insightful

      The difference is that he didn't hijack the servers and use them for his own deeds for a month and returned them. He got in, observed how severe the exploit was, got out, and told the admins that they need to fix it. If someone broke into my car without doing any damage to it and then left a note giving me suggestions I'd welcome it, it's not like they drove off with the car and they might have saved my car from future theft.

    11. Re:Great Excuse by practicalista · · Score: 2, Insightful

      As I have pointed out elsewhere, the open door analogy is basically lame because the problem here is not the crime but, society's response to the crime. A trespasser remains a trespasser. In computer crime, a trespasser can suddenly become an armed robber if the person whose property was invaded has enough political muscle.

      Also there is a third party issue here too. One of the files he gained access to contained personal information of another person. Where is the New York Times' legal responsibility to protect the information that it holds from others in this whole discussion?

      Or, to extend you analogy, if you borrow you friends laptop and then leave it in an unlocked car, do you not share some responsibility?

    12. Re:Great Excuse by moonbender · · Score: 2, Funny

      Healthy, sick, somewhat healthy, happy, unhappy, everything between those extremes, nervous, imprisoned and so on ad infinitum. "State of existance" is not a very clearly defined term.

      --
      Switch back to Slashdot's D1 system.
    13. Re:Great Excuse by qtp · · Score: 2, Funny

      If you crawled in through the doggy door and took a look at the porn collection in my bathroom I would be pissed.

      How bout if I just looked at your porn using that Windows fileshare you've got open to your cablemodem?

      Was that "breaking and entering"

      --
      Read, L
    14. Re:Great Excuse by MrHanky · · Score: 5, Interesting

      An interesting analogy.

      After drinking heavily in a bar, a friend of mine and I bought some slices of pizza at a shop, and went outside to eat. Since we were too drunk to stand up, we sat down on the steps outside another shop, which was closed for the night. That is, it should have been. My friend was leaning his back on the door, which was open. He fell right in.

      Now, the right thing to do, according to you, would be to go away, minding his own business. And what the hell was he doing, trespassing on the steps outside the shop and all. If this was in Texas, he would be rightfully shot. However, my friend, being both an imbecile and a crook with neither morals, nor respect for private property, went inside to look for a telephone and hopefully the phone number to the owner (we were both too tired to do any serious looting). And so the owner was noticed and the door was closed, and my friend got a serious hangover.

      The moral of this story is: if you drink, you get a hangover, so alchohol is bad, 'mkay?

    15. Re:Great Excuse by Shanep · · Score: 4, Funny

      YOU CANNOT BREAK THE LAW, EVEN FOR GOOD REASONS! IF YOU DO, EXPECT TO GO TO JAIL!

      I would bust his skull open with my tire iron, then call the cops.

      Okay, so busting this guys skull open is breaking the law for:

      a) A good reason.
      b) A bad reason.
      c) No reason at all.
      d) None of the above.

      BTW, the thief will sue you from here to eternity. Maybe if you make it out of jail alive some day, you might be able to find a job to pay off that lifetime of debt to him.

      ; )

      You can't just go around breaking open skulls because someone pisses you off. YOU CANNOT BREAK THE LAW, EVEN FOR GOOD REASONS! IF YOU DO, EXPECT TO GO TO JAIL!

      --
      War crimes, torture, lies, illegal spying... Would someone give Bush a blowjob, already, so he can be impeached?
    16. Re:Great Excuse by morissm · · Score: 5, Insightful

      The home invasion analogy is a very bad one. A home is by its very nature badly protected (you don't spend millions securing it, do you?) but it is also a sanctuary, a place where a break-in results in a certain emotional stigma.

      A better analogy would be this one: Suppose that somebody is waiting in an airport's lobby. He has not gone through the security checks yet. While waiting, he notices airport personnel going through what seems to be an unlocked employee-only door. A thought flashes in his mind: "This doesn't seem very secure. I thought airports were supposed to be secure." So he goes to the door and lo and behold, it is unlocked! He goes through it and find a bunch or corridors and doors.

      Naturally curious and a little adventurous, our guy wonders how far he can go. He goes forward and manages to get to the departure area WITHOUT going through security. He feels a little proud of having easily broken a system on which governements and airlines has spent millions.

      Being a good citizen, our guy then goes to the security counter and shows his finding to the cop. But suddenly, the cop puts cuffs on him and charges him with trespassing and attempting to bypass security in an airport. Of course, the proper action would have been for the guy to go to security as soon as the unlocked door was found. Adrian Lamo should have stopped his investigation at the misconfigured proxy.

      However, is it reasonable to charge somebody with a federal crime for having gone a little further in testing the security of a system? Whether is was an airport or NYT's intranet.

      I don't think so. The FBI can claim that they don't know whether the guy smuggled dope during his attempt and the NYT can claim that they'll have to check every system for backdoors but I believe it's mostly bad faith from people lashing out because they felt humiliated. Get a grip... fix your stuff and move on. Destroying the life of somebody who tried to help you is just stupid and cruel.

    17. Re:Great Excuse by arth1 · · Score: 4, Insightful

      What companies do about those who warn them is what irks me. Not only do they press charges as if they had been maliciously broken into, but they tend to want to bill the white hat hacker for EVERYTHING related to the incident, including but not limited to ignorant PHBs spending months in meetings about it, as well as the price for fixing the mess.

      It's like you getting to work one day and finding a note stating "the bathroom window opens from the outside, and the spare key for the filing cabinet where you keep customer data shouldn't be taped to the bottom of the counter." Then what do you do? Call in all the staff, and close up the store for a week while you hold meetings, followed by changing all the locks and buying a gun, and finally suing the person who left the note, charging him with the total costs of what you did?

      Or you tell a farmer that you were hiking in his woods when you discovered that his game warden was poaching. The farmer's reaction is charging you with trespassing. While he may have a legal right to do so, he'd be a real jerk AND idiot to do so.

      The above is, unforunately, the analog to what's happening in the electronic world.

      I'm not saying that Lamos and other self-appointed white hat hackers are RIGHT in what they do (I believe they aren't), but even if the messenger isn't welcome, you don't shoot him or blame hime for all the problems he reports.
      The main reason why you shouldn't do that isn't just because it's a petty thing to do, but because you HURT yourself and others in the long run.

      See, if I were a hacker operating like Lamos, and saw companies doing that, instead of alerting the companies and risking facing their and the paranoid law makers full wrath, I would stop alerting the companies about their flaws -- instead, I would anonymously alert the PUBLIC.

      Seen from the viewpoint of a company, what's better about that? Yet, that's what they're pushing hackers into.
      The companies might argue that they would want people to stop rattling doors in the first place, and that's a valid argument. However, it's not going to happen until you have exterminated every potential criminal and curious kid on the planet.
      In a Utopia, you don't even need a door lock, because no-one would ever walk through the door without a right to do so. However, companies can't argue that as a defense -- not installing a lock would be seen as gross negligence, because it's expected that criminals and curious people will trespass unless minimal safety measures are taken. That's how our society is.

      Charging Lamos is a signal, all right. Unfortunately the signal isn't "don't test our security uninvited", but "once you've tested our security uninvited, don't tell us -- stay anonymous and tell it to everyone else".

      Regards,
      --
      *Art

    18. Re:Great Excuse by rikkards · · Score: 2, Informative

      actually there are companies whose sole income is breaking into networks to ensure they are at a certain level of security. This includes hacking (cracking, whatever) as well as social engineering.

    19. Re:Great Excuse by MrHanky · · Score: 2, Insightful
      The analogy breaks right there. Your friend didn't go around trying lots of doors to see which ones were open. Your friend, upon finding one that was open, didn't go in and wander around.

      Exactly (although he did go in and wander a bit). My point being, there are certain grey areas, but most people will agree where the lines between grey and black are. He was definately trespassing, but that was the best way to find a phone (and phone number). And he found the door open purely by accident - he most certainly didn't break in. Using nmap on a large netblock is hardly an accident, neither is willfully sending GET /default.ida?NNNNNNNNNNN[...] requests to an unpatched IIS (no that's probably not what Lamo did, but it's one of the few exploits I know).
    20. Re:Great Excuse by Penguin's+Advocate · · Score: 2, Insightful

      Don't alert the public! You'll get sued for defamation or slander or something. You get in trouble either way.

      Anyway, since he already did... The customers (or employees) of NYT should sue the NYT for their lax security which puts their personal information at risk.

      The problem with this whole thing is that the "right" thing to do is not the same as the "legal" thing to do. It is right to help people. Whether it's helping my car not get stolen or helping me not get sued by all my customers when their info is used for shady purposes. The world is so F'd up and people are so F'd up and nobody trusts anybody and they really have no reason to and It's F'ing pissing me off and I can't thing of anything to do about it. The world is FUBAR and it's everyone's fault and nobody wants to F'ing admit it and so everyone's just sitting there afraid to do anything (and they have every F'ing reason to be afraid) and there's a few powerful people out there who aren't afraid to do anything, in fact they've got some set of F'ing balls. And the number of those people who are evil is exponentially greater than the number of those who are good. It's all just so F'd up. You can't do a damned thing for anyone anymore without having to worry about getting sued. You try to do something nice for someone, something goes wrong and now your up shit's creek without a F'ing paddle. The only good people out there are the people who don't sue people, and they're all F'd because they're all gonna get F'ing sued by some worthless punk who's pretending to be hurt so he doesn't have to work for the rest of his life and who doesn't give a flying F about you or any of your problems and is only thinking about himself. The whole F'ing world seems like it's the same way, "One-Way". ME ME ME I I I and F everybody else and the horse the F'ing rode in on. Nobody accepts a F'ing apology, everyone's out for a quick $ and nobody gives a shit about anyone else. I care about people, I'm nice to people, I help people, and one of these day's I'm gonna get F'ing sued for it or arrested for it, and you know what, I don't give a shit, I'm not going to stop being human because a bunch of greedy F's don't give a F about me or my family, F them, and F anyone who agrees with them.

      --
      Frag 'em all...
    21. Re:Great Excuse by Planx_Constant · · Score: 2, Insightful

      YOU CANNOT BREAK THE LAW, EVEN FOR GOOD REASONS! IF YOU DO, EXPECT TO GO TO JAIL!
      Rosa Parks broke the law. Gandhi broke the law. Our founding fathers broke the law. They all seem like pretty good reasons to me.
      Adrian Lamo does expect to go to jail. He is willing to turn himself in, once he knows what the charges are.

      --
      Heisenberg might have been here.
  5. Damn straight he should be arrested by Servo · · Score: 2, Interesting

    He was violating the law. He did not have prior authorization when he hacked into these systems. While some companies may have been happy to be warned of the vulnerabilities they had, and were glad to have them fixed, what he did was still illegal. He should deserve to be arrested, but given his motives will hopefully be given some leniency when it comes to sentencing.

    --
    A slip of the foot you may soon recover, but a slip of the tongue you may never get over. -Benjamin Franklin
  6. Call to "The Screen Savers" by Larkfellow · · Score: 5, Informative

    Here's a link to The Screen Savers (on Tech TV) that has some information about what Adrian had to say when he called in live to speak with Leo.

    --

    -- Never monkey with another Monkey's monkey

  7. hacking... by softspokenrevolution · · Score: 4, Insightful

    Well, zero tolerance. The thing here is that to an awful lot of people, and especially those who make the laws, hacking is hacking is hacking, who cares what someone says they were doing it for.

    I can realy understand how someone could consider that they're doing a service for admins and all of that, but the point is that you are still breaking into a system and then turning around and saying, "hey, this is a security hole, you should fix it" is kind of like G. Guido coming down to your house, breaking in through a window with a golf-club and then saying, "Hey, I can break into your house, better listen to me or I'll do it again."

    I'm sure that Adrian has some noble goals, but fundamentally when a company decides that they don't like people creeping into their system and then presses charages against those who do, it's their right to feel that their security was violated. Good luck to him really, but there are other ways you can help people protect their network security than by breaking into them.

    1. Re:hacking... by El+Cubano · · Score: 4, Insightful

      I can realy understand how someone could consider that they're doing a service for admins and all of that, but the point is that you are still breaking into a system and then turning around and saying, "hey, this is a security hole, you should fix it" is kind of like G. Guido coming down to your house, breaking in through a window with a golf-club and then saying, "Hey, I can break into your house, better listen to me or I'll do it again."

      I'm sure that Adrian has some noble goals, but fundamentally when a company decides that they don't like people creeping into their system and then presses charages against those who do, it's their right to feel that their security was violated. Good luck to him really, but there are other ways you can help people protect their network security than by breaking into them.

      I can see your point, but what he was doing was exposing flaws in the security of "public" places on the net. How is this any different than when the local news where I live broke into the nearby international airport's restricted area and did a report from there (this was about a year after 9/11) to show how lax security had become again.

      When the journalists do it, it is a public service. When a private citizen does it, it is a crime. WTF? Personally, if I am going to be utilizing the services of these sites, I want to know that they have good security (and not just because they say so).

      There is no way anyone can convince me that what he was doing was wrong. He was providing a public service, and if the public is too ungrateful to realize that, then it is really sad.

      It's not like he extorted money from the comapnies, or demanded some compensation, heck he even helped them fix the holes. It is just sickening that you can't even be a good Samaritan without someone wanting to take your head off.

  8. Go Mom! by The+Tyro · · Score: 4, Insightful

    Heheh... when the agents wanted to come into her home, she told them to get stuffed and come back with a warrant...

    That's love, folks.

    It would be ironic if this was set up by the NYtimes. I thought investigative/secret camera/sting operation reporting was supposed to be agressive journalism... couldn't his "hack" be considered the same sort of thing? "Unsporting" doesn't begin to describe it, particularly if he was up-front and honest about helping them out. If the NYtimes can investigate, blow the whistle on others, and embarass them into action, I'd say the same card can be played against the Times. "Sour Grapes" anyone?

    Yes, he was likely technically in the wrong, no doubt about it, particularly if you adhere to the letter of the rule, rather than the spirit of the rule... even so, this seems a bit heavy-handed.

    --
    Even if a man chops off your hand with a sword, you still have two nice, sharp bones to stick in his eyes.
    1. Re:Go Mom! by LostCluster · · Score: 2, Interesting

      Yeah, there are many reporters through the years who have broken laws in the course of reporting, and I'm sure some archive searchers can come up with NY Times examples, where the investigative reporter escapes punishment because they broke the law in the name of journalism.

      Lamo didn't down the company, or commit credit card fraud with Rush Limbaugh's SSN. There are much worse hackers out there, but the FBI's just looking for somebody to make an example of because they can't quite figure out where the first SoBig came from...

    2. Re:Go Mom! by SunPin · · Score: 2, Interesting

      Yes, you are correct but he should have covered his ass by setting up a security magazine online so he could enjoy the Freedom of the Press.

      Freedom of the Press belongs only to those that own a press. Everyone else will be raped when the system feels like doing so.

      --
      Laws are for people with no friends.
  9. Seems fair by TheFairElf · · Score: 3, Insightful

    If he's going to hack websites, even with the best intentions he's still breaking the law. It seems it would be better for him to work at a security firm (or open his own) and at least get paid for all his troubles. Then he'll be rich and he'll be praised for basically doing the same thing.

  10. This seems unfair by practicalista · · Score: 5, Insightful

    I am not sure what he did at the New York Times can even be considered hacking.

    So far as I can tell he set his web proxy to the address of the company infranet, surfed around that, downloaded some documents and used the information contained in these to get some more.

    Whilst I don't approve of hacking per-se, I'd have to say that here, this is very little more than exposing a badly designed web site.

    Imagine that you go to you Gas company's online web site, look at the URL and see your account number in it. You think to yourself, I wonder what would happen if I changed one of the digits. You do and lo and behold up pops all the information to another customer.

    Now you can go for your 15 minutes of fame and ring up SecurityFocus or you can have a quiet word with the Webmaster of the Gas company - either way, you are not a hacker.

  11. Sheesh! by joto · · Score: 2, Insightful
    What did he expect really? That everybody should love him because he snooped around in their systems without permission?

    He must have been living under a very large big rock for a long time, if he thought this kind of behaviour has ever been accepted by the authorities and most sysadmins.

    And by the way, hacking systems without permission have never been white-hat. At best, I would call it grey-hat, although black-hat is certainly also fitting.

    If we start judging people on intentions instead of what they do, I think most people will start complaining. "No, I was only trying to help the sysadmin, so I haven't done anything illegal", is about as stupid as "You thought about stealing that car, so you should go to jail for that".

  12. How lame... by Jon+Abbott · · Score: 3, Funny
    ...the FBI has filed charges against [Lamo], and currently has his parents' house staked out.
    Well that's just... lame-o! [ducks for cover]
  13. He accessed an internal network by mindstrm · · Score: 2, Insightful

    that he knew he did not have permission to access, by his own admission.

    Any way you slice it, that breaks the letter of the law.

    If you want to test the secrurity of my network without getting charged if you break in, then I suggest you obtain myh persmission to do so in the first place.

    Analogy: You find a guy walked in your front door cause it was open, snooped around your house, your bedroom, your closet... then told you "You shouldn't leave that box of money in your closet, and you should leave your door locked".
    Is he guilty of trespass / unlawful entry? Damn straight. Would you feel violated? Damn straight.

    1. Re:He accessed an internal network by practicalista · · Score: 5, Insightful

      The law make distinctions between trespass, breaking and entry, armed robbery and so on.

      The guy who wanders around your house is a trespasser not an armed robber. It seems here that a better analogy would be :

      A guy walks in to your unlocked house, boasts about it and you insist that he prosecuted for the worst possible crime he *may* have committed, not the crime he did commit (to walk through an unlocked door).

    2. Re:He accessed an internal network by catenos · · Score: 2, Informative

      not the crime he did commit (to walk through an unlocked door).

      Excuse my ignorance, but is this really a crime in the USA? AFAIK local laws, in Germany anyone can walk into any open (as in "not closed", not "not locked") area as it pleases him/her, until and only until, you say him he is not welcome. Then you can call the police if he stays or reenters.

      That's probably why most estates have garden fences. Most of them don't stop anyone, but they declare the garden a "closed" area (presumed that the fence gate is closed, of course).

      So, yes, I can simply walk into a stranger's house, as long as he left the door open, and given that I don't do anything illegal additionally, there was no crime. (But that doesn't mean that the owner won't call the police and the police won't hold me and investigate what illigal activity I might have done in the house, if I don't have a reasonable explanation for being in that house).

      --
      Keep an eye on which arguments are silently dropped in replies. Not always, but often times it's very telling.
  14. What was he thinking? by tarranp · · Score: 4, Insightful

    If you break into someone's house, telling him after the fact how yo got in does not automatically pardon you from the crime...

    Had Adrian simply notified the New York Times in a timely manner about the open proxy servers, he would have been fine and probably accomplished his mission.

    Instead, he took his time cracking the system, widening the holes so to speak, and then went to a reporter(!), of all people.

    There is nothing inherently wrong with his desire to improve security. There is nothing wrong with him looking around the public spaces on the internet for chinks. What was wrong was that he failed to tell the people maintaining the chinks directly about them, widened them until he got at valuable data, didn't tell the affected people about the data he had received, but then went to a third party and told them about the wanging big hole he had made. I'm sure he views himself as a knight in shining armor, but in this matter he behaved like a publicity-seeking self-promoter.

    Yes, shame on the NYT for misconfiguring their systems, but even more shame on Adrian for doing something so illegal and counterproductive.

    It does not matter if a person thinks he's a good guy, he still does not have carte blanche to do whatever he wishes.

  15. finaly a good analogy by claude_juan · · Score: 2, Funny

    from the techtv site...

    "Lamo hacked into the website of The New York Times in February 2002 and took the Social Security numbers of several people. He then added his name to the list of contributors to The New York Times and notified the paper of what he'd done."

    kind of like this....

    middle-aged man #1 (Lamo) - "hey, i screwed your 16 year old daughter. i took her virginity, but i have to tell you she wasn't very good."

    Lamo expected this...
    middle-aged man #2 (NYT) - "oh hey thanks! i'll get her some literature and make sure she's up to speed!"

    But instead he got punched in the face and sent (pending) to jail.

    do you really think he had the "good" in mind? "i'll just take a few socials cuz thats harmless." what a putz.

  16. Re:hacking...a service by globalar · · Score: 3, Interesting

    From the article:
    "'I hope there will be a time when Adrian can do positive things that everyone agrees are positive,'"

    This service analogy, or the positive light of the grey hacker's actions, does have some weight, as the hacker can inform the admins about the specific flaws of their system security.

    But then again, any service should be prompted or invited. And a larger problem is this isn't just washing windows, these are problem areas, flaws, and security flaws at that. These might even give access to a company's dirty laundry. So not only is this service uninvited and not approved, it gives access to private company resources and information, and uses the security holes to get in.

    Yes, I assume if security is the only dimension that your job entails, then this is all worth it. But to most people in charge, and arguably the general populace at large, this is an intrusion by illegal means.

    I personally value my private virtual space. If you get on my computer and get into my root account, it's an intrusion. Yeah, I will listen to how you did it, but for your troubles you'll never use my computer again.

  17. Horrible analogy. by pb · · Score: 4, Insightful

    What if I just leave a signed note on the inside of your car that says "follow these three easy steps, and then no one else will be able to break into your car again"? Do you say "hey, thanks, buddy!", or "hey, someone broke into my car!"...

    --
    pb Reply or e-mail; don't vaguely moderate.
    1. Re:Horrible analogy. by Sycraft-fu · · Score: 2, Insightful

      Depends if you asked permission first. If you come to me and say "hey, I think there is a problem with your car security, let me show you". I'll say "ok" and let you go to work. If you then break in, and tell me how to fix it I'll be happy. However if I catch you trying to break in to my car without my permission I'll call the cops.

      Physical or virtual, you need my permission to use my stuff. If you want to borrow something, get a login on my server, test my security, etc ASK ME. It is not yours to mess with as you please. I don't care if your intent is just to find problems and notify me, you still need my permission first.

      Heck, with physical secutiy, I am fully aware of most of the problems I have. I know the weaknessess to my house and car. Problem is, they cost too much to fix. Well, that does NOT give you permission to exploit them, even if just to let me know they are there.

  18. Um, what?? by GrouchoMarx · · Score: 5, Interesting

    OK, white hat cracking someone is still cracking their system, no matter how benevolent the intent. But this part just makes my blood boil:

    French did not know what the specific allegations were, because the charging document is sealed.

    Especially in light of this part of another article that people need to spend more time reading:

    In all criminal prosecutions, the accused shall enjoy the right to a speedy and public trial, by an impartial jury of the State and district wherein the crime shall have been committed, which district shall have been previously ascertained by law, and to be informed of the nature and cause of the accusation; to be confronted with the witnesses against him; to have compulsory process for obtaining witnesses in his favor, and to have the assistance of counsel for his defense.

    Excuse me, what part of cracking the NY Times is a threat to national security? Why are so many court documents sealed these days? There is NO legitimate reason for securing this sort of charge. Even if the prosecutors were to go as far as claiming he were a terrorist, there's still no nuclear weapons secrets (which we all know by now anyway, despite being classified) in the NY Times payroll database.

    He should use that in his defense; because the case was sealed, it's unconstitutional and therefore he can't be found guilty.

    I don't support this sort of vigilante white hat hacking, but I oppose ignoring the constitution even more.

    --

    --GrouchoMarx
    Card-carrying member of the EFF, FSF, and ACLU. Are you?

    1. Re:Um, what?? by One+Louder · · Score: 2, Funny

      Excuse me, what part of cracking the NY Times is a threat to national security?
      Well, if the New York Times is compromised by hackers, how can we ever trust the accuracy of the stories published by this hallowed national treasure...oh wait...never mind....
  19. Mixed feelings on this issue by Orion+Blastar · · Score: 5, Insightful

    If he was hired to test security it would be a different matter. But he allegedly broke into those systems without permission. That puts him in violation of Cybercrime laws.

    I feel sorry for him, because he did allegedly report the weaknesses to the admins and he could have just read the data and not told anyone and used the information for his on purposes. So his intentions were good, to plug security holes by finding them and telling the admins about it. But he is doing it the wrong way, without permission.

    He may want to think about pleading guilty and making a deal to get reduced charges. This will make him famous and when he gets out of jail and ends probation, he can become a security consultant. Otherwise they may try to make an example out of him and charge him with a full pentalty and any other charges they can think of.

    But then the places he broke into didn't use good security practices and didn't apply the latest updates. Personally, I wouldn't put a machine on the Internet that contains sensitive data on it that only my company should have access to like contact information, credit card numbers, etc.

    --
    Remember, Slashdot does not have a -1 disagree moderation, and no, troll, flamebait, and overrated are not substitutes.
  20. Jayson Blair? Ah. by AtariAmarok · · Score: 2, Funny

    "but Lamo suspects the New York Times initiated the investigation when they found out how deep into their system he got.""

    Ah. This will lead to the perfect explanation of the Jayson Blair problem and other NYT prattfalls:

    "It wasn't us. Lamo hacked our personnel files to make sure Blair was hired and employed. He also altered our articles so they were not longer factually pristine."

    --
    Don't blame Durga. I voted for Centauri.
  21. Why do they do it? by Knunov · · Score: 4, Insightful

    I know what many of you are thinking. Why not tell these companies BEFORE you break in?

    Because IT'S NOT FUN, that's why. Or perhaps more accurately, it's not stimulating.

    Hacking these sites takes time, and the payoff is getting inside and saying, "WOO-HOO! I DID IT!" The fact that he does nothing malicious afterwards and even calls and helps the sysadmins unfuck their systems is a testament to his character.

    For those who would compare his antics to breaking into your home, but not stealing anything, it's a poor analogy. Why? Because your house is your personal meatspace. And if he went inside, he would see many things personal to you, such as family pictures, your kid's toys, or if he was REALLY unlucky, your fat, naked ass sitting in a Lazy Boy with a bowl of chips balanced on your ponderous belly, flipping through the channels.

    "Uhhh... hey dude. Your lock is vulnerable."

    See? Just not the same.

    Getting past a computer's defenses is not the same as physically entering a home or bank vault, though I would find the latter far less intrusive than home invasion, especially if he never even touched the money.

    Now, if he LOOKED at personal/confidential files once inside, that is a different story. But beating a system's defenses, with the only ambition of proving you can do it, then calling the responsible party and helping them fix the security flaw SHOULD NOT be punished.

    Misdemeanor, at most.

    It doesn't matter what he could have done while inside, it matters what he did, or more specifically did not do while inside the system.

    "That bastard! He saw my FILE NAMING SCHEME!"

    Yeah, he should fry for that...

    Knunov

    --
    Why do users with IDs under 100,000 or over 700,000 usually have the most worthwhile comments?
  22. Hacker the Gray by AppHack · · Score: 5, Funny

    So he's a gray hat hacker who has fallen into shadow. Will he come back as a white hat hacker, more powerful than before?

  23. Dialectic by Henry+V+.009 · · Score: 5, Insightful

    Everyone enjoys comparing hacking to breaking into someone's house or trespassing on private property. It is not. You cannot be 'inside' someone else's server. (It is doubly impossible given the girth of most hackers.) The physical definitions fall apart. And the metaphorical analogies do not mesh physical property and Turing machines so well.

    We can begin with what we do know for sure about hacking. A hacking incident is when someone sends packets of information (in some form and by some medium) from a computer or computers to someone else's computer or computers. Which packets are illegal and which are not? Any exact definition raises problems. You can say that any packets that change the functioning of the target system in an unintended way is hacking. So the ignorance of the owner becomes the limit of what is or is not hacking. Faking an email address on a badly designed sign up page (or using mailinator) might be hacking under that definition. Other definitions are similarly problematic. Currently our legal system tends to default (once it actually gets to jury trial) to the above definition, but (in effect) adds that the act must be highly technical and use specialized tools. (Other definitions exist, and I am of course willing to bust holes in any particular one you care to suggest--so go ahead and suggest them.)

    But there is such a thing as computer hacking. Everyone knows that. Even if we cannot have an exact legal definition, we know that some things are clearly computer hacking. What is the best way of creating law (which is now inexact) to deal with this behavior? I would suggest making the motive of the hacker one of the main considerations of law. It is always hard to for legal systems to judge guilt based on motive--and they should not if they can avoid it--but in this case, they must either judge the motive of the victim or the perpetrator. If the motive is vandalism or theft, then the act should be punished. Adrian Lamo's motive appears to have been an act that should not have been punished--though it is highly important to state that we do not yet know the facts.

  24. Adrian we're here to help by Kurt+Russell · · Score: 4, Funny

    you

  25. What a joke by Vellocet · · Score: 2, Interesting

    Come on. This guy has been breaking computer laws for years. Entering a system without prior authorization is against the law, period. Two things amuse me about Adrian Lamo: 1) He has never demonstrated significant or diverse knowledge of computer networks. The methods he uses to enter systems are trivial and repetitive. His ego is the only thing that can't be replaced by a simple script. 2) He brags about not accepting or extorting money. It's just as sickening that Adrian Lamo is all about fame. As the article points out "In February, 2002, Lamo told the Times of their vulnerability through a SecurityFocus reporter." As usual, Mr. Lamo talks to the cameras before talking to his victims. This is how this guy gets paid: national press coverage. To any security professional, this guy is a complete joke. Let him slide back into obscurity.

    1. Re:What a joke by Entrope · · Score: 3, Insightful

      Your argument falls flat on a number of points.

      Reportedly, his access to the NYT systems was by using publically accessible proxy servers. Saying he needs prior authorization to do that is naive -- do you need prior authorization to access arbitrary mail or web servers on the Internet? Leaving the systems open is prima facie authorization. There would have to be some indication that only NYT employees (or whomever) were authorized to use the system.

      You are amused that he uses the same tactics to access many poorly secured networks. Does it not worry you that so many networks are poorly secured in identical ways? I believe that is a much more significant issue.

      You are further amused that he does it not for money, but for publicity. HELLO MCFLY. There are an unknown number of other systems just waiting for someone to break into them. If Mr. Lamo publicizes the existence gaping security problems (especially after working to help close the specific examples he finds), it encourages other businesses to close their holes. Without him, many of them would rather than sit fat and lazy and hope whoever penetrates them gets caught.

      That publicity also brings business to the security professions who you think consider him a joke. Talk about biting the hand that feeds you.

  26. What country does he think he lives in? by Cyno · · Score: 2, Funny

    Here in the US we do not tolerate these activities. He knows too much which makes him a potential terrorist. Using his skills without a license, without the authorization of the government, without legal protection, will land his ass in prison.

  27. Good intentions don't mean it is legal by rblancarte · · Score: 5, Insightful

    Drago - you are a fool. If you are hacking people's systems without their permission, YOU ARE BREAKING THE LAW. PERIOD. END OF STORY. If people were allowed to say "Well, I was doing it so I could help their security", then you would have all sorts of Blackhats hacking systems, and then claiming, "I was going to help, but you arrested me first." No.

    Look, there are ways to do security checks like this, without the security teams knowing that you are doing it. Get permission, make sure that no one is tipped off, and then test the systems.

    If there is one thing I can't stand it is people doing illegal actions and then claiming they are doing it for the greater good. This type of action cannot be condoned. Sure, you might be doing help, but you also might not.

    --
    It is human nature to take shortcuts in thinking.
    1. Re:Good intentions don't mean it is legal by Izago909 · · Score: 4, Insightful

      So let's throw the (relatively) most desirable type of hacker in jail so he gets out of the way of the black hats. This is some bullshit logic. Regardless of what his 'true' intentions were, his track record speaks volumes: He's always come clean with people.
      While network admins are busy giving themselves kudos for integrating Microsoft's latest and greatest secure systems, he is busy looking for holes. Without these types of white hats, all the world would have is insecure networks remaining open to black hats until they discovered the holes the really hard way.
      Screw all the evil, sinister things you think his 'true' intentions are. He and his counterparts have potentially saved your company millions in expenses when some black hat could have made off with gigabytes of confidential data. Think these white hats are bad? Wait until you have class actions out the wazoo because many of your customers are now facing the business end of your over confidence.
      Screw modern hacking laws because they are stale and outdated. People always like to tack on new laws without even considering removing or revising obsolete sections. All it's going to do is alienate any potential allies. The bad guys won't get caught because they hide, the good guys don't hide because they think they don't have a reason to.
      White hats are thrown in jail because they get bad attention and can cause a PR mess. Many times, the work of black hats can be covered up by the company or government. How many stories have we heard of hackers holding sensitive data ransom or extorting businesses in some way? You really don't think EVERY incident gets publicized, do you? These people want to make it look like they are tough on hackers, so they go after the easiest and most public targets.
      You will be giving a powerful message to upcoming generations of hackers. If the end result is the same, what the hell do I need this white hat for?
      Someone will come knocking at your door, it's inevitable. What color hat do you want him to be wearing?

    2. Re:Good intentions don't mean it is legal by Kenja · · Score: 3, Funny

      If the post man goes into your house, rumages around and then leaves you a note that your underwear is dirty and your out of milk he should be arested.

      --

      "Have you ever thought about just turning off the TV, sitting down with your kids, and hitting them?"
  28. It brings up another issue by The+Tyro · · Score: 3, Insightful

    and that's ethical vs not, whether it's hacking, or journalism.

    Journalists are supposed to operate by an ethical code, and the vast majority do so. Journalistic ethics would say that you cannot break the law in order to get a story... though that's not say it hasn't been done. Check out this link. It would seem that ethical standards in journalism are quite flexible, and that there is no set rulebook. Instead, as in ethical dilemmas in many disciplines, one must weigh competing evils. The evil of impersonating someone, or operating under a false identity, veruse letting a politician go on with corrupt, harmful actions... which weighs more, and who decides?

    By the same token, one might make the same argument for Adrian's actions. He intended no harm (as an investigative reporter might intend no harm in impersonating someone else to get a story), so the Mens Rea AKA "guilty mind" did not exist. Reporters often argue, when investigating and digging into the lives of public figures and officials, that those officials have less of an expectation of privacy than regular citizens... and to some extent they're right. Yet, how does the watchdog presume to waive the privacy of others in the pursuit of a story, while immediately running to the FBI? The media also argue that they have the right to dig, based on the fact that they are defending the public's "right to know." (how many times have we heard that?) The media assumes that power as society's watchdog... but who's watching them? Apparently, Adrian was, and they are NOT happy about it.

    It's doubly ironic that an organization dedicated to exposing the truth (ostensibly in a transparent, above-board, and for-the-greater-good fashion), is getting their panties in a bunch over someone showing them some truth in a like manner. Apparently the old grey lady doesn't have a problem airing the dirty laundry of others, but is awfully sensitive about her own problems... and from an ethical standpoint, Adrian's actions are probably arguable either way.

    I'm sorry, but I find this whole thing incredibly funny.

    --
    Even if a man chops off your hand with a sword, you still have two nice, sharp bones to stick in his eyes.
  29. Oh, because corporations are always trustworthy by the-banker · · Score: 4, Insightful

    I understand most of the arguments against what Lamo did, but there are a few points I want to get off my chest:

    1. To all those saying, 'Its like he broke in your house': No it isn't. The machines were connected to the internet, which is a public medium. A house is a physically closed space where courts have rules one can have an expectation of privacy. Nobody can claim that the internet should provide an expectation of privacy - by its very nature of using shared resources it flies in the face of such an argument.

    2. I don't know how it needs to be done, but truthfully do you (the collective Slashdot you) trust companies to secure their networks, perform audits and be upfront and honest about their failures? If I were a NYT partner I would be furious that my information may have been publicly accessible, yet I would never have known about its vulnerability without Lamo. How many companies have been hacked, had credit card or other info stolen, and just not said anything about it? When Acxiom was hacked, personal information on individuals was stolen over 8 months before they "discovered" the hack - and the hack was found by Hamilton County, Ohio Prosecutor's office when investigating another case that had come forward. What are the chances that Acxiom KNEW they had been hacked, compromised personal information, and said nothing? I am guessing with the current climate of corporate ethics, a pretty high chance exists that a lot of information is being disseminated by people who stole it and consumers have no idea because the company in question is sweeping it under the rug.

    Hacking into someone else's system is bad. Nobody can disagree there, but the bottom line is a tradeoff of negative impacts - for what Lamo did I see a lot fewer negative consequences than today's corporate irresponsibility with personal information and computer security.

  30. Response by Overly+Critical+Guy · · Score: 3, Insightful

    I say, "Why did you have to break into my car to write me a note?"

    --
    "Sufferin' succotash."
  31. Re:My house, my property by Henry+V+.009 · · Score: 2, Interesting

    So you maintain physical lines for people to send packets of information to your server, without requiring any specific agreement from them before use. You have no contract they must first agree to, and no posted rules that they must first read before sending packets to your computer. Someone uses one of those physical lines to send information to your server. Your server sends information back to him that is not acceptable to you. After the fact, you feel that the information he sent went against some permission that you never explictly stated. Therefore you wish him punished as a tresspasser?

  32. Interview him by BortQ · · Score: 2, Insightful

    I would really like to see a slashdot interview with this guy.

    --

    A Multiplayer Strategy Game for Mac OS X, Windows, and Linux
  33. The Problem is how they're handling this by miraclemax · · Score: 2, Insightful

    I personally am of two minds about this whole thing. I understand that if he really was meaning to be honest and helpful with his exploit of their shoddy system, that he was doing a good thing in helping them correct it. Better someone who would be nice about it than someone who would not tell. but, at the same time, regardless of the intent, he did do something illegal. And regardless of your intention afterwards, it was a violation to their system and property to do so in the first place. So, in all fairness to his intentions, he should be prosecuted after due process. **What IS wrong, however, is that he has not been allowed to see the charges against him. He has said that as soon as he sees the charges against him, as is his Constitutional right, that he will turn himself in, so long as those charges are reasonable. Remember that Kevin Mitnick reportedly had inflated wild charges brought against him in a hacker hysteria and had reportedly had a lot of his rights violated in captivity. If I were him and pending jail time, I would be very nervous in light of this and other previous cracker captures.

  34. Its a sad world by madstork2000 · · Score: 2, Interesting

    Consider this:
    You see an open door at your neighbors house. You know the guy is on vacation.

    Do you call the cops? Probably not, you just go over and check out the place for him. Most of the time the door was not securely latched, or the kids watering the plants forgot to close it.

    But what if you discover that the place has been trashed and stuff presumably stolen. I would call the cops, and my neighbor. Would they be suspicious of me? Yes probably at first, but in the long run they'll more likely be grateful.

    Obvisously, there are good reason for laws, tresspassing is one of the fundemental laws throughout history. But, I'm willing to give up a little privacy if and when someone goes out of their way to HELP me protect my property. I'd much rather a neighbor walk through my house in my absence if they think something is wrong.

    I also happen to own a tiny hosting company, and I would definately rather have a white hat let me in on specific exploits my system is vulnerable to rather than leave it alone and let the script kiddies do their thing, if I have screwed up.

    Unfortunately for Mr. Lamo a law is a law, and with the overzealous (at least on high profile cases) FBI on the case, they'll probably try to make him into another Mitnick.

    It is a sad world, everywhere we go policies, principles, and even laws try to dissuade people from working together and co-operating. Capitalism, democracy are great in principle, and can be in practice, but even the best ideals can be bastardized by people in power.

    Free software is said to be communism by its critics, sharing code in a CS course is bound to get you expelled, make a backup copy of a CD and face the rather of the RIAA, the world will probably end if the same DVD Can be played in europe, japan and the USA.

    This is in my opinion another example of moral decay. We have all these rules and laws that do not promote morals, but rather promote some arbitrary standard of "rightness".

    It is the principles of openess, and co-operation that have drawn me to Linux, and free speech software. I'm trying to raise my children right, to teach them to help others for the sake of helping. When something needs to be done, if you can do it, do it. I try to instill them with team values, that together they can accomplish more than they can by themselves.

    Its just ashame that the way things are going I'll likely end up looking like a bad parent...

    1. Re:Its a sad world by gvc · · Score: 2, Insightful

      It might be more apt to consider what the response might be if you walked up and down the street trying the doors on houses belonging to people who don't know you from Adam, without regard to whether they were home or not.

  35. All the news thats is fitted to print by cluge · · Score: 4, Insightful

    The NYT is one of the most hypocritical organizations today. They sue to get 9/11 tapes of people dieing - all in the name of "openess" and "public information", yet they have a network connected to the public network - which is open and transparent through their own doing - and thats bad/illegal? PLEASE - The NYT's proxy servers were so misconfigured that it was akin to them posting information in the window of the downtown offices and then getting pissed if people read what they posted.

    You can bet your rear quarters that if our hacker had been a reporter on a story for the NYT that they would be vigorously defending his actions. Like most large corporate entities the NYT has no moral basis for anything it does, in the end it's about money, not honesty, truth or enlightenment. It sure as hell isn't about the times mission statement which is "The Company's core purpose is to enhance society by creating, collecting and distributing high-quality news, information and entertainment."

    Perhaps our hacker should have "enhanced society" by distrubiting the inromation he found to the world. It would have been high quality news to see how one of the most influtential papers is really run.

    --
    "Science is about ego as much as it is about discovery and truth " - I said it, so sue me.
  36. NYT? by wolf- · · Score: 3, Funny

    They were worried he knew just how much of their news was faked.

    --
    ----- LoboSoft specializes in Digital Language Lab
  37. Police vs. judiciary by gvc · · Score: 2, Insightful

    As far as I know, John Ashcroft has not yet been able to completely eliminate the distinction between these two distict components of the administration of justice.

    Most of the arguments that I've seen here are the sort that Mr. Lamo can make in court. If the court finds that his actions were justified, it has the opportunity to acquit, or to give some other form of discharge.

    In my neighbourhood, I would like the police to arrest people they find in jewellery stores late at night, or in my home while I'm on vacation, or on my computer without permission. If the prosecutor or the judge decides that no charge should be made, or that the charge should be dropped, fine.

    While I feel some sympathy for this self-appointed security checker, I can't immediately fault the police. Especially without access to the facts of the case, which will be exposed in the judicial process.

    One might argue that Mr. Lamo is being punished by having to go to court. I think not. He must have been well aware that his actions were provocative and that this was a likely outcome. Now he will have the opportunity to justify his actions.

  38. Entering via an open door... by podperson · · Score: 3, Insightful

    If you leave your front door open and I take a look inside your house, what crime have I committed? At most, I am told, trespass. If you left the keys under the mat and I opened the door, it's breaking and entering.

    Similarly, if I take your car with the clearly stated intention to return it when I am done (e.g. if I desperately needed to drive someone to the hospital), I haven't stolen it, I've borrowed it -- with or without your permission.

    Theft, burglary, etc. are crimes defined in part by the intention of the alleged perpetrator and the damages suffered by the alleged victim.

    OTOH we live in a world where one of the first "terrorist" groups targeted by the government after 9/11 were Environmental Activists who destroy machinery but have been careful never to hurt anyone.

    But I'm no lawyer.

  39. Re: hacking and intentions.... by parliboy · · Score: 2, Insightful

    Well, the big reason he was taking his sweet time was that the federal prosecutor sealed the charges. When you see sealed charges today, you know that's the thing that goes hand-in-hand with being disappeared and threatened with charges of terrorism if you don't plead guilty.

    Sorry, but I don't think I'd do anything different in those circumstances.

    --
    "You're never ready, just less unprepared."
  40. Further evidence of our retarded society by KalvinB · · Score: 2, Insightful

    "without requiring any specific agreement from them before use"

    This is just another example of why our world is going to shit. Too many retarded people that think I have to make you sign something before you can't damage something I own.

    Didn't sign an agreement that you can't egg my house on holloween? Guess you can then huh? What are you, stupid?

    Our society has become so braindead that unless you tell someone specifically not to do some specific act, they assume they can regardless of the fact general laws exist.

    Property laws exist that say you can't damage other people's property. Why? Because common decency has gone out the windows thanks to an abundance of retards that have engulfed our society.

    "Therefore you wish him punished as a tresspasser?"

    Listen, idiot. You don't need to sign an agreement that you won't damage my property before you're not allowed to.

    Unf-in believable. Do the Slashdot community a favor. Pack up your computer and send it back to HP where you got it from.

    Ben

  41. Re: hacking and intentions.... by Quothz · · Score: 3, Informative

    It seems pretty obvious to me that hackers doing this sort of thing are simply trying to draw as much attention to themselves as possible, in order to boost their ego and enhance their career options.

    Not at all like, say, teen athletes, who play sports for the sheer fun of it.

    Besides, if he was so confident his activities were legal and ok, why is he running around from state to state, in hiding?

    Well, according to the article, he's in California working on a documentary. Not exactly the kind of thing you'd do if you were "in hiding".

    If he felt he had a strong case in his favor, you'd think he'd just turn himself in to the FBI right away, so he could show their folly in court and walk away righteous.

    This just tells me he's not an idiot. Talking to a lawyer before the cops is good sense, and perfectly legal. Nothing in the law requires him to turn himself in, so he can take his own sweet time and make sure his rights are protected.

    You got some kinda grudge against this guy, or did you just not read the article?

  42. Re: hacking and intentions.... by Tadghe · · Score: 3, Insightful

    King TJ, you should read a bit on Mr. Lamo before you go casting stones.

    1. He has repeatidly turned down anything from the companies he's helped.
    2. He has always agreed to sign whatever NDA's are required of him. 3. That hardly fits the profile of somone trying to "bolster" his profile.
    4. He has done this for *years*.
    5. He has (A far back as I can remember hearing him speak) been aware that one day someone would not take too highly of his efforts.
    6. He's hardly on the run, he's trying to get in touch with his Lawyer to setup the details of turning himself in.
    7. He has NEVER released (as far as I can remember) the exact details of ANY of his corporate hacks.

    Want proof? Go seach SecurityFocus, he hangs out on BugTraq and a few of the other lists. For heavens sakes man, quit trolling without at least reading about the guy.

    --
    Bugs Bunny was right.
  43. Hack the NYTIMES?! by Safety+Cap · · Score: 2, Informative

    Why bother when others have done all the the hard work for you?

    --
    Yeah, right.