Slashdot Mirror


Google Search Convicts Hacker

An anonymous reader writes "Google search terms have helped convict a wireless hacker. The queries the hacker performed were introduced into evidence at court, where Matthew Schuster was charged with disrupting his former employer's wireless network and imitating other users' MAC addresses to obtain access. From the article: 'Court documents are ambiguous and don't reveal how the FBI discovered his search terms. That could have happened in one of three ways: an analysis of his browser's history and cache; an Alpha employee monitoring the company's wireless connection; or a subpoena to Google from the police for search terms tied to his Internet address or cookie. Google has confirmed that it can provide search terms if given an Internet address or Web cookie, but has steadfastly refused to say how often such requests arrive.'

116 comments

  1. AOL by celardore · · Score: 5, Funny
    Google has confirmed that it can provide search terms if given an Internet address or Web cookie, but has steadfastly refused to say how often such requests arrive. (Microsoft, on the other hand, told us that it has never received such queries for MSN Search, and AOL says it could not provide the information if asked.)

    No, they'll just give it all away anyway.
    1. Re:AOL by DDLKermit007 · · Score: 1

      The thing is that I highly doubt that they got the search results from Google. My money is on that he had auto-complete turned on. No non-tech head has the sense to turn this off. I've found credit card numbers in some of my friend's auto-complete histories. Hit the down arrow key at the Google page when your on the search box, and you can get a fairly long list of previously searched items. This kind of stuff doesn't require any kind of court order with Google.

    2. Re:AOL by celardore · · Score: 1

      I was kinda hoping for a +5 Insightful or +5 Informative. I'll just take the funny and leave it.

    3. Re:AOL by tubapro12 · · Score: 1

      Even if AOL didn't have the information anymore, just ask their business partners...

  2. Re:YRO? by Anonymous Coward · · Score: 0

    Perhaps it has something to do with the possibility that Google could cough up *your* search terms should you become the target of interest from law enforcement or the Gest^W Homeland Security department?

  3. Re:YRO? by electrosoccertux · · Score: 4, Insightful

    How does this have anything to do with my rights online? Because now you have a lot fewer of those rights.
  4. Well... by Quixote · · Score: 4, Insightful
    when Yahoo does something like this, they are teh Evil!!!!11!!one!

    But when Google does it, it can only be for the common good, right? A malicious Hax0r gets put away??

    1. Re:Well... by spun · · Score: 4, Funny

      Yes! You get it. Now you are one of us. (chanting) One of us! One of us!

      --
      - None can love freedom heartily, but good men; the rest love not freedom, but license. -- John Milton
    2. Re:Well... by A682 · · Score: 2, Informative

      The difference is that yes, in this case, a malicious "hax0r" does get put away... but in Yahoo!'s case, they did the same to a journalist who desires freedom in an oppressive communist state. They're two different things.

      Even so, I don't think Google was the source of the search terms- they have adamantly stood their ground against such practices in the past. I just don't see them taking a 180 and just giving the FBI search terms like that.

    3. Re:Well... by mgt · · Score: 1

      mmmm.. "don't be evil"

    4. Re:Well... by TheSeer2 · · Score: 2, Insightful

      It's called a subpoena.

    5. Re:Well... by jlarocco · · Score: 1
      The difference is that yes, in this case, a malicious "hax0r" does get put away... but in Yahoo!'s case, they did the same to a journalist who desires freedom in an oppressive communist state. They're two different things.

      What's the difference? In both cases somebody was breaking a law in their country. And in both cases the search engines gave relevant information to the governments of those countries. They seem almost exactly the same to me.

    6. Re:Well... by Jahz · · Score: 1
      when Yahoo does something like this, they are teh Evil!!!!11!!one!
      But when Google does it, it can only be for the common good, right? A malicious Hax0r gets put away??
      No. You make it sound like all /.ers blindly believe anything Google does is correct. Google knows how to play this crowd, and there is nothing wrong with that. You're the real problem here because of how you trivialize the issues to make it seem like a popularity contest. Some people here might think that way, but most probably do not...

      The difference between these two events is pretty basic. In Google's case:
      a subpoena to Google from the police
      This is a legal requirement that Google has no choice other than to comply with. (or to not log queries and degrade service severly). Now in Yahoo!'s case, from the article you linked:

      Yahoo Holdings Ltd. in Hong Kong worked with mainland Chinese police to find Shi, according to court documents. So far, Yahoo has refused to offer details beyond this statement released Thursday: "Yahoo must ensure that its local country sites must operate within the [local] laws, regulations, and customs."
      Can you see the differences? Do you see why Yahoo HK was evil, but Google was not? Hong Kong is a seperate government than mainland China. Yahoo in Hong Kong had no legal requirement to cooperate with mainland Chinese police (first evil deed). Then, Yahoo stated that they will comply with local "customs".
       
      So, the bottom line is that subpoenas and customs are very different things. Google will release customer data in compliance with court orders. Yahoo will release customer data in compliance with local customs. Please don't pretend these are the same thing.
      --
      There are 10 types of people in the world. Those who understand binary and those who do not.
    7. Re:Well... by Dirtside · · Score: 1
      They seem almost exactly the same to me.

      Murder and self-defense are exactly the same if you describe them both only as "using a firearm to cause a person to die". The context is important; and to some of us, suppressing free speech is not equivalent to punishing someone for breaking into a former employer's network in order to damage it.
      --
      "Destroy science and religion. Science would re-emerge exactly the same; but not religion." - Penn Jillette, paraphrased
    8. Re:Well... by bky1701 · · Score: 1

      "The context is important; and to some of us, suppressing free speech is not equivalent to punishing someone for breaking into a former employer's network in order to damage it."

      The Chinese would say the same thing; they were just punishing someone for spreading lies and propaganda in an attempt to destabilize the government. Not that they are right, just remember, everyone has excuses.

    9. Re:Well... by jlarocco · · Score: 1
      Murder and self-defense are exactly the same if you describe them both only as "using a firearm to cause a person to die". The context is important; and to some of us, suppressing free speech is not equivalent to punishing someone for breaking into a former employer's network in order to damage it.

      If you're going to do business in a country, you're obligated to follow their laws, whether you like them or not. If Google or Yahoo wants to make a statement about a country's policies, breaking the law isn't the most effective way to do it.

    10. Re:Well... by bky1701 · · Score: 1

      "Can you see the differences? Do you see why Yahoo HK was evil, but Google was not? Hong Kong is a seperate government than mainland China."

      Umm, no.

      http://en.wikipedia.org/wiki/Hong_Kong
      "The Hong Kong Special Administrative Region of the People's Republic of China (Traditional Chinese: [pronunciation]) is one of the two special administrative regions (SARs) of the People's Republic of China (PRC), the other being Macau, and one of the richest cities in the world."

    11. Re:Well... by number11 · · Score: 1

      Do you see why Yahoo HK was evil, but Google was not? Hong Kong is a seperate government than mainland China. Yahoo in Hong Kong had no legal requirement to cooperate with mainland Chinese police (first evil deed). Then, Yahoo stated that they will comply with local "customs".

      Why do you say that Hong Kong is a separate government than mainland China? For historical and political reasons, HK is (for a while) treated a little differently, but since 1999(?) it's a part of the People's Republic of China. Yahoo HK was just abiding by the law. And how is "local customs" different from US companies who turned data over to the US govt after 9/11 even though there was no valid legal compulsion?

      Not that I know what the answer is. If you're going to be "law-abiding", you're probably going to screw people over at the behest of whatever local regime.

    12. Re:Well... by TheSeer2 · · Score: 1

      Government != Country

    13. Re:Well... by Jahz · · Score: 1
      Why do you say that Hong Kong is a separate government than mainland China?
      Poor wording on my part. It's part of China proper, but has its own government and political structure officially known as Hong Kong Special Administrative Region of the People's Republic of China. (see: Honk Kong) It reminds me of D.C., which while not at all the same, is not a city on to itself, but rather a entirely seperate federal entity coupled with the city of Washington, Maryland.

      Yahoo HK was just abiding by the law.
      According to the article posted, it was not legally required to cooperate with mainland police. From wikipedia: "In contrast to mainland China's civil law system, Hong Kong continues to follow the common law tradition established by British colonial rule." That includes a seperate British-esq court system...

      And how is "local customs" different from US companies who turned data over to the US govt after 9/11 even though there was no valid legal compulsion?

      It isnt. Not all companies complied with requests like that, and the ones that did probably got a few law suits. I imagine it was not hard to get a court order for anything in the weeks following 9/11 anyway.

      If you're going to be "law-abiding", you're probably going to screw people over at the behest of whatever local regime.
      Agreed. There are certain things you just have to do to stay in bussiness, and compliance with law is one of them. You should recognize the massive difference between abiding by the law and following customs. Laws are written, voted on, and known to all citizens of a government. Customs are unwritten and subject to extreme variations in interpetation. Basically an excuse that can be applied to anything.
      --
      There are 10 types of people in the world. Those who understand binary and those who do not.
  5. From their privacy policy: by GPLDAN · · Score: 4, Informative

    Let's look at Google's privacy policy, shall we?

    Information sharing

    Google only shares personal information with other companies or individuals outside of Google in the following limited circumstances:
    * We have your consent. We require opt-in consent for the sharing of any sensitive personal information.
    * We provide such information to our subsidiaries, affiliated companies or other trusted businesses or persons for the purpose of processing personal information on our behalf. We require that these parties agree to process such information based on our instructions and in compliance with this Policy and any other appropriate confidentiality and security measures.
    * We have a good faith belief that access, use, preservation or disclosure of such information is reasonably necessary to (a) satisfy any applicable law, regulation, legal process or enforceable governmental request, (b) enforce applicable Terms of Service, including investigation of potential violations thereof, (c) detect, prevent, or otherwise address fraud, security or technical issues, or (d) protect against imminent harm to the rights, property or safety of Google, its users or the public as required or permitted by law.


    That's a pretty broad policy. *ANY* applicable law, regulation, legal process or enforeable governmental request. That leaves the door pretty wide open for the Chinese government to start asking for the query strings of their citizens to me.

    I think the answer is clear, if you need to see webpages and want NO trace of you - you have to compromise a machine, surf via a proxy you set up in it, and then timebomb the drive to wipe itself after you are done. And even then you may get caught, if there are firewall logs.

    Let's look at a leading company that does web proxy policy:

    DISCLOSURE
    All use of our site is confidential. We disclose user information only as provided for herein and when we believe that the law requires it, or when disclosure is necessary to identify, contact or bring legal action against someone who may be causing injury to others or interfering with Proxify's rights or property.

    In the event of an assignment, sale, joint venture, or other transfer or disposition of some or all of the assets of Proxify, you agree that we can accordingly assign, sell, license or transfer any information that our users have provided to us. Please note, however, that the purchasing party cannot use the personal information you have submitted to us under this Privacy Policy in a manner that is materially inconsistent with this Privacy Policy without your prior consent.


    That pretty much says: hey, we have your web surfing logs and we'll give em up if we have to. We don't want to, and we'll destroy logs after 30 days (it says that elsewhere in the policy) but dammit, if they bend us over and lube us up - we're gonna damn well hand it over rather than taking one for the team, so to speak.

    1. Re:From their privacy policy: by troll+-1 · · Score: 1

      We disclose user information only as provided for herein and when we believe that the law requires it, or when disclosure is necessary to identify, contact or bring legal action against someone who may be causing injury to others or interfering with Proxify's rights or property.

      But we don't want google disclosing our information based on what they believe. That's up to law enforcement. If law enforcement believes a crime has been committed let them get a warrant and subpoena google for the information.

    2. Re:From their privacy policy: by gamer4Life · · Score: 1
      That leaves the door pretty wide open for the Chinese government to start asking for the query strings of their citizens to me.


      Why are you even bringing the Chinese government into this? Replace "Chinese" with "American" and it still means the same thing.
  6. Is there a way... by bogaboga · · Score: 1

    I wonder: Is there a way to conceal IP addresses and MAC addresses? What about slashdot? Are we being monitored? You see, I have posted what has been regarded as "flambait" a number of times.

    1. Re:Is there a way... by The+Living+Fractal · · Score: 1

      ... And what's one more? ;p

      But seriously. No way to hide IP addresses from the server. Unless you want to terminate your connection. Then you can hide all day. And get nowhere fast.

      This guy who got caught.. well, in short, he sucked. Good hackers don't get caught.

      Besides, I would say calling him a hacker does a disservice to the name. He was much closer to a script kiddie IMHO.

      TLF

      --
      I do not respond to cowards. Especially anonymous ones.
    2. Re:Is there a way... by Anonymous Coward · · Score: 0
      You can't be serious...

      Mod Parent up "FUNNY"

    3. Re:Is there a way... by drpimp · · Score: 2, Informative

      Yeah it's called spoofing. MACs are easy, as this was one of the things the guy in the article was doing. I myself did the same thing back in college for WiFi in certain buildings. I simple packet sniffing can yield some great things. IP spoofing is likely to be done, but good luck on getting a response from your target, at least with out some other tricky means.

      --
      -- Brought to you by Carl's JR
    4. Re:Is there a way... by Mysticalfruit · · Score: 1

      I suppose that you could install a leapfrog program on another machine and route your traffic through their machine, thus disguising your IP.

      Though when they see the leapfrog pointing back to your machine, the gig's pretty much up...

      --
      Yes Francis, the world has gone crazy.
    5. Re:Is there a way... by The+Living+Fractal · · Score: 4, Insightful

      There are numerous ways to make yourself anonymous, however, they are for another discussion. Which is why I just suffice to say this guy is a piss-poor hacker.

      He didn't even try. He was just a disgruntled IT worker. Instead of using a machine gun to mow people down he wanted to use a transmitter to mow packets down. In this day and age people take that very seriously. So he's going to jail for 15 months. End of story.

      TLF

      --
      I do not respond to cowards. Especially anonymous ones.
    6. Re:Is there a way... by troll+-1 · · Score: 2, Informative

      But seriously. No way to hide IP addresses from the server.

      Just use an anonymous proxy like tor.

    7. Re:Is there a way... by markwalling · · Score: 2, Interesting

      after reading rfc 2549, i belive that anyone could spoof their ip or mac address very easily. trusted networks do not shit on your car

      --
      ...For the beast had been reborn with its strength renewed, and the followers of Mammon cowered in horror.
    8. Re:Is there a way... by foamrotreturns · · Score: 1

      Definitely a bad hacker. The only way that Google could keep his search terms and link them directly to him as a person would be if he were logged into his Gmail account when he was searching for the help he sought (or if he did them while sitting at his desk at work or home). Had he been smart, he would have done all the research from a public terminal in a library or university where no logon is needed. But we've already established that he wasn't smart. His imprisonment is not an effective disincentive to other hackers because he was just so stupid about it, and no self respecting real hacker would be so careless and they're probably all laughing at his sorry ass now.

  7. I'm suprised it took this long... by Mysticalfruit · · Score: 1

    Yet another reason to create a web user, copy in your bookmarks, do your online reading and can that user!

    --
    Yes Francis, the world has gone crazy.
  8. Another story of not being smart(tm) by junglee_iitk · · Score: 3, Informative

    I am no hacker and I do use google for many searches that I would not like to be a public information. Let us come clean, how many of us have not searched for a mp3 we liked a lot, or p0rn, or how to bypass company firewall?

    The first thing he should have done is to delete Cache, browse anonymously, and FOR GOD'S SAKE, not be logged into google (which is integrated everywhere), or delete search history, or delete all cookies!

    I know because I have suffered from this kind of stupidity, and in the end, I was unable to blame anyone.

  9. A Fourth Way by Tackhead · · Score: 1
    > That could have happened in one of three ways: an analysis of his browser's history and cache; an Alpha employee monitoring the company's wireless connection; or a subpoena to Google from the police for search terms tied to his Internet address or cookie.

    ...or by simply getting a judge to approve the running of a query against a database consisting of all traffic to/from the routers that constitute the edges of Google's network, without confirming or denying the existence of such a database.

    1. Re:A Fourth Way by rjpear · · Score: 1

      Wow..That's probably Overkill for this case... More than likely.. the Business suspect the guy is the perp and Either Takes his work machines and has analysis done on the Web Cache/History to see what this guy is looking at while using that PC OR Law Enfocement gets the bad guys computer, which said bad guys thinks will never be looked at, and with a Search Warrant the Computer is analyzed and Google search terms pop up and are introduced as evidence in trial.. Not really a big deal... and happens every day with Child Porn investigations...

  10. Google Account by garcia · · Score: 1

    Google has confirmed that it can provide search terms if given an Internet address or Web cookie, but has steadfastly refused to say how often such requests arrive.'

    Or your Google Account search history if you remained logged in after you use GMail (or any of their other services).

    1. Re:Google Account by MrP-(at+work) · · Score: 1

      don't forget google ads

      --
      [an error occurred while processing this directive]
  11. On my best behavior by Joebert · · Score: 1

    I hope nobody ever finds a reason to check my search records, I already know I can never become a politician.

    --
    Wanna fight ? Bend over, stick your head up your ass, and fight for air.
    1. Re:On my best behavior by Anonymous Coward · · Score: 0

      No, but you can be marked as possible terrorist any day without good reason these days.

    2. Re:On my best behavior by Joebert · · Score: 2, Insightful

      I'm not worried about that, everybody is a possible terrorist theese days.

      --
      Wanna fight ? Bend over, stick your head up your ass, and fight for air.
  12. Re: Wake up and smell the coffee!!! (Re:YRO?) by Anonymous Coward · · Score: 3, Insightful

    Because Google can say ANYTHING it wants about you and people/police/FBI/government/corporations/your_emp loyer/etc will believe them without an OPEN REVIEW of how they obtain, generate, and store that information.

    Is the information faulty? Did someone munge with the data? Were Google's databases corrupt? Was the data recreated or generated from other data? Has Google's spy software been through open source review? How well was Google's software tested?

    It continually astounds me how intellectually lazy Americans have become! It continually astounds me how the American people are willing to look the other way when it comes to their liberty and civil rights being encroached on!

    THINK FOR ONCE PEOPLE!

  13. This is why... by Anonymous Coward · · Score: 0

    I stopped using google. Here are some alternatives:

    Scroogle (uses Google)
    Clusty

    1. Re:This is why... by The-Ixian · · Score: 1

      boggle

      --
      My eyes reflect the stars and a smile lights up my face.
  14. Re: Wake up and smell the coffee!!! (Re:YRO?) by heinousjay · · Score: 3, Interesting

    So it's not clear that Google had anything to do with this, and aside from the search terms, other evidence also pointed to his crimes. I'm pretty sure you've overreacted.

    I'm not too surprised, though. A story like this (and realistically, the entire YRO section) is pretty much intended to rile the tin-foil hat crowd. Good thing for me that I'm entertained by it.

    --
    Slashdot - where whining about luck is the new way to make the world you want.
  15. MAC Address Filtering... by e4g4 · · Score: 5, Insightful

    ...is not a bloody security feature. This is why people who actually want to secure a wireless network use some combination of Radius and VPNs...

    --
    The secret to creativity is knowing how to hide your sources. - Albert Einstein
    1. Re:MAC Address Filtering... by b0s0z0ku · · Score: 1
      This is why people who actually want to secure a wireless network use some combination of Radius and VPNs...

      That's also one way to maintain an open network for casual surfers without compromising your home/business network. Put the wireless net on the Internet side of a firewall. Only VPN users get to cross the firewall and play on the company Intranet.

      -b.

  16. How to not get caught by troll+-1 · · Score: 5, Informative

    The Linksys router Schuster used at his home and its MAC address proved that he was accessing the CWWIS wireless network.

    Sounds like the MAC address was tied to his name somewhere and this was the evidence the FBI used to obtain the warrant. After that, everything was revealed by the contents of his computer.

    If you purchase a network card online with a credit card it's possible that the FBI can trace the MAC address of that card back to you, providing the seller keeps records. If you're a linux user you can change your MAC address with,

    ifconfig ethX hw ether xx:xx:xx:xx:xx:xx

    As long as you don't pass traceable information (like logging onto a traceable email account) and you use an anonymous proxy like tor as extra protection, it's pretty difficult to trace you. It's possible, of course, to locate you physically by triangulating your radio signals but this requires a bit more effort.

    The above is provided for educational purposes only. I do not advocate breaking the law.

    1. Re:How to not get caught by necro2607 · · Score: 1

      Indeed, you can change the NIC's MAC address on your OS X machine as well (from here):

      Under Mac OS X, the MAC address can be altered in a fashion similar to the Linux and FreeBSD methods:
      ifconfig en0 lladdr 02:01:02:03:04:05
      or
      ifconfig en0 ether 02:01:02:03:04:05


      If you're really concerned you can also just permanently modify the MAC address by editing data on the NIC's EEPROM. :)

    2. Re:How to not get caught by wikes82 · · Score: 2, Interesting

      Interesting, Now I can use skype to make 100% anonymous phone call All I gotta do just change my MAC addr then find a good wi-fi spot, then register a new skype account. Only 9 days left for the FREE skype phone call to US.

    3. Re:How to not get caught by Swimport · · Score: 1

      The above is provided for educational purposes only. I do not advocate breaking the law.

      I do.

    4. Re:How to not get caught by Anonymous Coward · · Score: 0

      You don't need to worry about the MAC address of your NIC. That does not go out over the wire to web servers. The MAC they are talking about the MAC of the router. That is what the outside world see's not the MACs of your internal NICs.

    5. Re:How to not get caught by Anonymous Coward · · Score: 0

      A secondary link from the article indicates the device had cached the last 4 mac addresses that had been used. They all matched devices used by other clients.

    6. Re:How to not get caught by max+born · · Score: 1

      This is for when you hack your neighbor's linksys router and you don't wanna get caught.

    7. Re:How to not get caught by Anonymous Coward · · Score: 0

      Yes, because it's basically BSD. Us *nix users know about this stuff. Windows users of course, have no idea what a MAC address is, and probably don't care.

    8. Re:How to not get caught by totally+bogus+dude · · Score: 1

      You don't need to worry about the MAC address of your NIC. That does not go out over the wire to web servers. The MAC they are talking about the MAC of the router. That is what the outside world see's not the MACs of your internal NICs.

      None of your MAC addresses go over the wire to web servers, unless the web servers are on the same physical network as you.

    9. Re:How to not get caught by sacrilicious · · Score: 1
      None of your MAC addresses go over the wire to web servers, unless the web servers are on the same physical network as you.

      Two scenarios to keep in mind:

      • (1) You're surfing on a wireless hotspot that isn't yours, e.g. you're at starbux, or using a neighbor's router. You download something that The Man gets interested in. The Man then requests access to the (starbux's or neighbor's) router, and gleans your mac address from it.
      • (2) You're surfing on the wireless router in your own home. You think you're safe, since you could always reset (or destroy) the router if trouble started coming. But... your ISP has a backdoor in their cable/dsl modem that allows them direct access to your wireless router... and, your router happens to have a known exploitable bug in it that allows remote access. Or you just haven't secured it to begin with.
      --
      - First they ignore you, then they laugh at you, then ???, then profit.
    10. Re:How to not get caught by CodeBuster · · Score: 1

      The MAC address can be changed in Windows as well, which is probably not such a bad idea all things considered. If you want any privacy these days you have to secure it for yourself because nobody else cares anymore and some are actively trying to subvert it.

  17. Profiling Internet Users? by drewzhrodague · · Score: 2, Interesting

    I know that Google analyzes the searches of its users -- for good purposes. I am sure they analyze how their search works, how users use it, and other things about those users. This helps them make a better tool. What I'm worried about is when this information is used to profile users, and identify potential 'terrorists'.

    --
    Zhrodague.net - I do projects and stuff too.
  18. Hackers by necro2607 · · Score: 0, Flamebait

    "In October 2003, police armed with a search warrant showed up and seized his computer (PDF)."

    Ouch, this brings back memories of Hackers. As cheesy as it was, that movie hit close to home because I had gotten in trouble so many times in the past all through my earlier years in school, being banned from a total of four or so different school computer labs (three different schools) by the age of 13... One of the better stories: I was snooping around on the computer's hard drive using Netscape by browsing "file:///", which was apparently "hacking". Curiosity killed the cat, I guess.

    Anyway, with all that past experience in mind, based on how amateur this guy seems to be (searching on how to execute his attack *on the target's network*) I can easily imagine how freaked out he was when police showed up at his place and took all his computer hardware.

    Of course, I don't really feel bad considering how bad a job he did of covering his tracks and maintaining anonymity and so on.

    1. Re:Hackers by Anonymous Coward · · Score: 0

      hahah I got in trouble on some ol windows 3.11 machines when I used Notepad.exe to open up autoexec.bat and remove the last line win.exe so I could use the command line.

      The number of things they did to try and prevent access to a computer in school and it still boggles the mind how so many people are still illiterate.

      I also find it funny my secret word is teaches.

    2. Re:Hackers by mandelbr0t · · Score: 1

      One of the better stories: I was snooping around on the computer's hard drive using Netscape by browsing "file:///", which was apparently "hacking". Curiosity killed the cat, I guess.

      Wow, your sysadmin was a real jerk. I actually got caught pirating using the school network (lesson learned: pirating to just anyone is asking for trouble), which got me banned until they found out they needed geeks to operate PageMaker for the yearbook. hahaha :) The librarians just sighed every time I used the computer -- the latest attempts to keep the hackers out inevitably failed.

      mandelbr0t

      --
      "Please describe the scientific nature of the 'whammy'" - Agent Scully
    3. Re:Hackers by necro2607 · · Score: 1

      Yeah, it was actually on a library computer I was on, too, so I was banned from the library's computers... until a couple years later when I was suddenly recruited to help keep the library network running in the school... heh!

    4. Re:Hackers by necro2607 · · Score: 0, Offtopic

      One of the best tricks I ever came up with was building my own HyperCard stack to launch whatever program I wanted, after discovering a pretty big bug in the school's "security" software. Our Mac labs had At Ease, and it would only have just a few "educational" programs etc. available to students. However, I found a really big vulnerability - you could take any program and simply change the creator code with ResEdit to match that of any one of the "allowed" programs, and it would then be allowed to run.

      So I'd take some various "tools" from the web (At Ease password cracking type stuff, mostly, and of course a copy of Bolo to play with friends over the LAN while we snuck in during lunch), change the creator codes to match SimpleText or Math Blaster or whatever, and build a HyperCard stack that would launch the programs for me.

      It got to the point where I was making "Bolo disks" (for all my friends) which included a copy of the game, some extra maps and a HyperCard launcher stack. I got a reputation as a bigtime hacker among everyone in the school (and I was 11 years old!), which was both good and bad - tons of awesome extracurricular stuff related to computers, but always seen with an eye of caution...

    5. Re:Hackers by Anonymous Coward · · Score: 0

      That reminds me of the week I was suspended from school for enabling the school's email system. This was the early nineties before email was popular or well known.

      A friend of mine 4 years earlier had watched an admin type in their sysop password, "help," into the system. We had a field day those 4 years with the system. We created our own classrooms in the school's database and various other harmless things.

      One day in Pascal class we shelled to DOS (using the menu option from Word) and ran the exe for the mail program. I typed a message, "Someone is using the system who is unauthorized." Then I typed a command "send msg1 to all" and I watched in terror as every student, teacher, and administrators name scrolled up the screen.

      Stupid me reacted on gut-instinct and pulled the plug on the computer when the command was really running on the server. Even stupider me had not logged in under the sysop account and had instead used my own account to shell to does.

      My stomach was in knots the whole night knowing I was in for it. The guidance counselor confronted me about it the next day with a log of messages in her hand with my name on it. Surprisingly though their system time was off by several hours so I told them I wasn't even near a computer at that time and denied it for a few days.

      Finally, the principal who was a former FBI agent confronted me and said, "We've got witnesses, blah blah.. vandalism.. or something" and I fessed up. I told him it was an option on my screen to shell to DOS, to which he responded, "You have the option to jump off the roof, does that mean you're going to take it."

      To make a long story short I was suspended for 5 days and my parents had to beg them not to involve the police. I was an idiot, but I never meant any harm. I think their biggest concern was that the sum total of the messages had taken up 1.5mb of drive space and had taken someone hours to manually delete all the files.

      Suffice it to say I wasn't allowed near a computer the rest of the year and could only use Apple IIE's to compile my code.

      Either way, it's funny to think back to now. I wasn't a hacker then nor am I now. A hacker doesn't get caught and knows enough to cover their tracks. At the worst I was an idiot who knew enough to piss off others who knew nothing at all.

    6. Re:Hackers by Anonymous Coward · · Score: 0

      Sorry about the typo up there. I meant DOS instead of does. I got a bit excited while typing as I thought the boss was going to sneak up on me and read my life's history.

      One thing I forgot to mention is that I became some sort of small legend afterwards. When the students logged on the next day they each had a new email address and some disovered what email was for the first time. The feature had previously been disabled for all the students.

      The next year they had 4 new rules in the handbook on computer usage, and people who had ignored me suddenly thought I was somehow more interesting...

      But I was no hacker and the fame didn't get me laid... so what good was it?

    7. Re:Hackers by necro2607 · · Score: 1

      Offtopic? Lawl, sorry for discussing things on this discussion forum.

    8. Re:Hackers by Anonymous Coward · · Score: 0

      Actually this is a comments section for a news article about Google searches being used to convict a disgruntled employee for breaking into his employers' wireless network. Your comments were off-topic.

    9. Re:Hackers by Anonymous Coward · · Score: 0

      Seems pretty on-topic since I'm discussing past computer/network hacking when the article is about someone who got arrested for computer/network hacking... I thought sharing personal experience related and very similar to topics discussed in TFA would be pretty on-topic, but apparently that's not the case? ...

    10. Re:Hackers by Phroggy · · Score: 1

      Heh, you did that too? ;-)

      Here's a HyperCard stack I created to disable FoolProof, which prevented users from dragging icons in the Finder (and probably did a couple of other things, but that was the main feature I remember).

      --
      $x='S24;r)>63/* h@<5+oZ)32"5cz';$me='phroggy'x$];
      $x=~y+ -xz+\0-Tx+;print$_^chop$me for split'',$x;
  19. Criminals should never use credit cards! by Anonymous Coward · · Score: 0

    Canada's version of 9-11 was the Air India bombing which brought down a plane with 329 people aboard in 1985. The guy who built the bomb bought a radio to build the bomb with and the police caught him because he used his credit card for the transaction. So, the cops have been catching people by tracing credit cards for a long time.

    http://www.hinduonnet.com/fline/fl2005/stories/200 30314003510000.htm

    Actually, the best way to not be caught is to not be a criminal and even that is not a 100% guarantee. Some Bulgarian nurses have been convicted of murder in Lybia because their patients got AIDS. It happens here too. Lots of people have been convicted of murder and later exonerated. OK, where's my tin hat ...

  20. Transparent Proxy by RockoW · · Score: 2, Insightful

    This kind of proxy is very common on businesses and among other useful stuff they log the HTTP request made by any client in the network. This is the easiest way, noone else is requiered to get the queries just check your own server logs.

    1. Re:Transparent Proxy by The-Ixian · · Score: 1

      Yeah, I suppose in this case that is probably true. But proxies generally only log the URL visited. So queries sent to a web site would only show up if HTTP GET was used AND your particular proxy gathered additional path information from the URL to put into the log (I know that my Squid proxy does not gather such information, it only logs the base URL path). HTTP POSTs probably would not show up at all unless some other mechanism was enabled/added to the proxy.

      --
      My eyes reflect the stars and a smile lights up my face.
  21. Google convicts?! by jrm228 · · Score: 1

    Wow - after reading that headline it's clear that corporations are getting more powerful. This conviction brought to you by Google Court Beta.

  22. Actually... by Anonymous Coward · · Score: 3, Insightful

    Actually, the first thing he should have done was to stop using his former employer's wireless network by appropriating its other customers MAC addresses to gain illegal access. The second thing he should have done was to not launch DOS attacks against said customers' websites. That automatically raised damages to above $5000 which led to the FBI getting involved. Once that happened, he was screwed.

  23. Re: Wake up and smell the coffee!!! (Re:YRO?) by necro2607 · · Score: 2, Insightful

    Yeah, it's a bit sensationalistic to claim he was "convicted" simply due to his google search terms - those were merely one part of the evidence given in court.

  24. Two ways by Anonymous Coward · · Score: 0

    JAP - I use this at work. It's usually pretty fast and works well. The app is a single .jar so no installation is required.

    Tor - I use this often, too, but it's much slower

  25. Re:YRO? by Anomalous+Cowbird · · Score: 3, Insightful

    Because now you have a lot fewer of those rights.

    In what way? To claim that a "right" has been violated here seems tantamount to making an assertion such as "Of course I may leave footprints, but no one has a right to follow them."

    Why should an electronic trail have legal protections that a physical trail does not?

  26. Perhaps... by torrentami · · Score: 2, Funny

    instead of searching for: "how to broadcast interference over wifi 2.4 GHZ," "interference over wifi 2.4 Ghz," "wireless networks 2.4 interference," and "make device interfere wireless network." he should have first searched for: "how to surf anonymously," "how to delete my browser data," and "how to shower without dropping your soap."

    1. Re:Perhaps... by Anonymous Coward · · Score: 0

      Aww.. a prison rape joke. TEH FUNNYH!!1

  27. Certain exceptions, if memory serves by Stonehand · · Score: 2, Interesting

    I seem to recall that there is a legal obligation to report certain classes of suspicious activity if they become aware of it -- notably, child pornography. They may not be obligated to actively search for it, but if they spot indications that a user is involved in that while analyzing their logs...

    --
    Only the dead have seen the end of war.
  28. Re:YRO? by JasonKChapman · · Score: 4, Insightful
    How does this have anything to do with my rights online?
    Because now you have a lot fewer of those rights.

    Yeah, what with being forced to use Google and all.

    I mean, seriously, which right was violated here? The right to use a search engine without records? The right to use someone's wireless network without records?

    --
    Sorry, I'm a writer. That makes you raw material.
  29. Faulty Article Title by JasonKChapman · · Score: 5, Insightful

    Kudos on the post's headline being more accurate than TFA's headline.

    The article's headline says: "Google searches nab wireless hacker," but the article actually says:

    Wireless hacker pleads guilty when his Google searches are used as evidence against him.

    That may seem like simple semantics, but it's actually a pretty big difference.

    --
    Sorry, I'm a writer. That makes you raw material.
  30. Server location isn't a defense by msobkow · · Score: 1

    If someone is charged in one country for what is done with servers located in another country, it stands to reason they're liable for what they did in the origin country. International treaties specify information sharing between various security and police forces, so any company has to comply with such requests. If a country signs up to an international treaty, then the people and businesses in that country have to abide as best they can.

    Think about it -- sysadmins and servers are scattered around the globe, but the corporations that manage them have to comply with the law in each country they have offices in. It doesn't matter whether that country has servers located elsewhere -- they're just tools.

    --
    I do not fail; I succeed at finding out what does not work.
  31. Forget about the Google... by camusflage · · Score: 1, Insightful

    Am I alone for thinking that 15 months in prison, three years of probation, and $20k in restitution is just a LITTLE high for MAC spoofing to score some free wifi? Even if it was taken to the level of interfering with the signal, 2.4G is unlicensed. As any aspiring hacker should know, a properly configured microwave will cause wifi (and 2.4G phones and baby monitors) many problems. Unless he was pulling some seriously bad juju, this is Mitnick-esque "damages".

    --
    The truth about Scientology, Xenu, and you: Operation Clambake
    1. Re:Forget about the Google... by Anonymous Coward · · Score: 2, Informative

      He wasn't just looking to score some free wifi, he was actively interfering with his former employer's business operations by DOS'ing customer websites, and knocking customers offline. To me, the sentence is appropriate. In fact, he's lucky to get what he got compared to some of the draconian sentences handed to other hackers in other criminal cases for doing far less than what he did.

    2. Re:Forget about the Google... by Shihar · · Score: 1, Redundant

      He was doing more then getting free wifi. He launched a DOS against his former companies customers. This guy got exactly what he deserved. The moral of the story? Don't break into your former employer's wireless and start locking DOS attacks or else you get thrown in jail. If anything, I think the guy got off light.

    3. Re:Forget about the Google... by Anonymous Coward · · Score: 0

      Wow, way to just slightly reword AC's post to score some karma points. Fuckin' karma whore.

  32. Re: Wake up and smell the coffee!!! (Re:YRO?) by bberens · · Score: 3, Interesting

    That's like looking at a key eye witness who saw you stab Nicole Brown Simpson and saying "How do I know you weren't on LSD and just imagining me there?" Seriously, independent third party witnesses are key to the judicial process. Get over yourself. Google openly makes money on the fact that they keep track of your browsing habits in order to make their advertising revenue more beneficial to their paying customers. Google could plaster those records for everyone on the planet to see them and your rights still haven't been violated. If you don't like what Google or any other company does, don't use them. With Google it's especially easy to avoid. Being a techy, you could take it a step farther and route google.com to /dev/null.

    --
    Check out my lame java blog at www.javachopshop.com
  33. How can this be considered evidence? by pclminion · · Score: 1

    In this day and age where anybody can wardrive past your place and do God knows what with your Internet connection (provided your WAP isn't secured), how can simple Google query logs prove ANYTHING? For all we know, this guy had an enemy at work who decided to set him up.

    And if he doesn't have a WAP, or it's secured, then it's just as possible that the aforementioned enemy somehow hacked into this guy's computer and sent those queries.

    How likely is this to happen? Maybe not that likely, but in this country at least guilt must be proved BEYOND reasonable doubt. I think the ease with which people can compromise your home net connection definitely provides reasonable doubt. In ALL cases.

    Even more, the fact that this guy is clearly not "liked" at work just makes it even more plausible that somebody would want to frame him. What are the chances? Low, probably, but is there reasonable doubt? Definitely.

    1. Re:How can this be considered evidence? by sentencieuse · · Score: 1

      Well... Except for the fact where 1) he pleaded guilty and 2) there were other evidence.

    2. Re:How can this be considered evidence? by ScrewMaster · · Score: 3, Insightful

      True, but the GP's point is still valid ... conviction based solely upon server log entries (or even the use of such logs to intimidate, such as the RIAA has been doing) should simply be unacceptable to a judge. Such information being a part of the fabric of evidence in a larger case is one thing, but it is simply not reliable enough to be depended upon in such important matters.

      Courts need to become more technically competent, I think. We're too accustomed to the idea that if data comes from a computer it is implicitly trustworthy, and that's a big problem.

      --
      The higher the technology, the sharper that two-edged sword.
    3. Re:How can this be considered evidence? by jc42 · · Score: 1

      Well, I have heard this sort of thing being used to explain why you should leave your wireless access point wide open. The argument goes that, if you secure it, evidence in packets coming from it can be used against you. But if you don't secure it, those packets could have come from any passerby.

      Wasn't this argued here on /. sometime recently? But I'm not sure I want to be a test case.

      --
      Those who do study history are doomed to stand helplessly by while everyone else repeats it.
    4. Re:How can this be considered evidence? by sentencieuse · · Score: 1

      Still: he wasn't convicted based solely upon server log entries, was he? I don't know about you, but I certainly don't believe that data that comes from a computer is "implicitly trustworthy", and I don't think that a lot of people do. Quite the opposite, as a matter of fact. I don't know why you bring up the RIAA, but their actions are rarely defendable.

    5. Re:How can this be considered evidence? by ScrewMaster · · Score: 1

      People have implicit trust in computers and software because, for most of them, they simply have no choice. They have to assume that what the computer tells them is accurate, because otherwise they can't do their jobs. I cannot tell you the number of times, in the past twenty-five years, that I've delivered a custom data acquisition system and asked the customer to do an end-to-end test on it to verify the accuracy of the results. "Nah, we trust you" I would often get told, to which I would say, "No! Don't just trust me ... prove that it works." A judge, of all people, is supposed to look at any source of evidence with a jaundiced eye. Lives depend upon it, and just taking a prosecutor's word that the "evidence" is valid is wrong, and assuming that a log entry is meaningful just because a server somewhere wrote it is just as wrong.

      I bring up the RIAA because it is precisely that sort of evidence that they present in court. It is exactly that sort of evidence that wins them summary judgments against their victims. And it is most certainly the sort of evidence to which a judge should say, "WTF?" when he sees it.

      --
      The higher the technology, the sharper that two-edged sword.
  34. Re: Wake up and smell the coffee!!! (Re:YRO?) by Anonymous Coward · · Score: 0

    The sanity, expertise, and/or reliability of witnesses is often questioned in court. Numerous times people have been sentenced to prison or even put to death on faulty evidence or testimony. This is one of the primary reasons some want to do away with the death penalty.

    IF Google is a key factor in the case, THEN there is prudent reason to question the reliability of their data.

    While it may be fun to joke about the tin foil crowd I think this is an honest concern.

  35. Re:YRO? by hackstraw · · Score: 2, Insightful

    Why should an electronic trail have legal protections that a physical trail does not?

    Physical trails in the public are not protected. Physical trails in private are.

    Its OK for me to watch you in public talking to person X. In theory, one needs a warrant and probable cause of a specific crime to listen to person talking with person X on the telephone.

  36. Supeona by nurb432 · · Score: 1

    None of that matters when they get the letter. They have to fork it over regardless of what agreement you made with them at that point anyway.

    I just wonder how long it will take to start general 'fishing expeditions' of search history to show 'possible intent' of comitting a crime and get warrants based on that 'suspicion'. " we see here you did a search for the word crack, come with us". " we dont care that what you have searched for might have been legal when you searched, its not now".

    Scary stuff.

    Curiosity did kill the cat, and it may kill the rest of us too...

    --
    ---- Booth was a patriot ----
  37. Re:YRO? by Macthorpe · · Score: 3, Insightful

    That's not comparable.

    In this instance it would be like talking to person X on company Y's premises. Company Y certainly has a right to know what is going on in their building and if it's illegal have every right to call the police about it.

    That's my view, anyway.

    --
    "It does not do to leave a live dragon out of your calculations, if you live near him." - Tolkien
  38. Re:YRO? by beckerist · · Score: 1

    Your metaphor is rendered invalid when the receiving end of your conversation is a corporate entity residing on a public domain. Google has every right to surrender any information it may have. Whether it's ethical to do so remains another, entirely different question. Don't be evil!!!

  39. Clarifications w.r.t. How to not get caught by mitigator · · Score: 1

    Your post leads to confusion .. not that it has anything wrong in it, but it has the potential to confuse:

    __1__
    His MAC address, when he connected to the local gateway, was logged.

    You suggest using tor for protection; tor wouldn't have helped this person. Tor obfuscates IPs.

    __2__
    Another poster writes that he's sure the FBI would use a MAC address database to track the person down.

    This would prove *extremely* difficult, and generally not plausible.
    There is a "database"[1], but it's a pretty granular database, with the equivalent of old-school "Class A" (256^3) blocks of addressing[2], going to the manufacturer-on-record of that NIC.

    It's also important to know, folks, that just because you change your MAC address, it doesn't mean you're "secure". Infact, if you do it on any of many wired networks, port-security will kick in and you'll be administratively (automagically) shutdown.

    There's very very little anonymity, if any, left on the Internet these days.

    And call it what it is -- just because there's a wireless signal, and it happens to reach into your home, doesnt mean you can use it. It's still "theft of services," and tack on some aggravated Theft By Deception, Exceeding Authorized Access, Circumventing a device connected to a Critical Infrastructure, one could even make a stretch argument to identity theft.

    I'm all for finding new and fun ways to get around systems.. but break down and buy a router already, eh? :-)

    [1] IEEE OUI
    [2] 00->ff ^ 3

  40. Grammar, people, grammar by Anonymous Coward · · Score: 0

    When I read the title I thought that google search was the one doing the convicting. I was about to say, "Whoa, google has really grown too large if its search engine has legal jurisdiction."

    Perhaps "Google Search used to Convict Hacker" would be more appropriate?

  41. Re:Default GoogleFox by Anonymous Coward · · Score: 0

    Or your mistyped urls via search from the address bar.
    Or how long your browser was open for (to the nearest half hour), via the lesser/default anti-phishing protection.

    Yeah, not exactly your bank account details, but still none of their fucking business.

  42. Re: Wake up and smell the coffee!!! (Re:YRO?) by jc42 · · Score: 2, Interesting

    That's like looking at a key eye witness who saw you stab Nicole Brown Simpson and saying "How do I know you weren't on LSD and just imagining me there?"

    Funny, yes. But I have a story that's not too far off from that sort of thing. About 10 years ago I was working on a project at a big corporation whose name isn't relevant here. I had a row of machines with different OSs for doing portability testing. Someone sent me email pointing to a bit of humor on some web site, and by chance I happened to read it on the NT box. It was cute, I sent back a message saying that I'd laughed, and went about the day's work.

    When I came in the next morning, the NT machine was sitting there displaying a whole lot of pornographic images. "Well, that's interesting ..." They had come from another machine in the same domain as the funny page. I erased them, checked occasionally, and they didn't reappear.

    But the next morning, they were there on the screen again. So I really investigated. I found the "deleted" email, fetched the funny page again, and examined its source. It had some truly bizarre javascript that I didn't quite understand, but I did find the routine that fired off a download just after midnight. I called a few coworkers over and showed them the original page, the code, and the results. Nobody could quite explain the code, other than that it did something just after midnight. We found that when we disabled JS, the porn downloads stopped.

    We tried it on a number of other machines. It only worked on MS Windows boxes, not on Solaris or linux or FreeBSD or any of the others. We had lots of Windows boxes, each with a different release installed, so after a while, we had lots of machines that were all downloading porn every night just after midnight.

    We did discuss the implications if the higher-ups got wind of this. We had this scenario of them trying to figure out how we were sneaking in every night at midnight without the security guys seeing us, downloading a lot of porn, and then sneaking out without being seen. We were sure that the porn downloads were going into our permanent records.

    Actually, we thought it was funny, as did our bosses. And these were all "crash and burn" test machines, so eventually we wiped each one clean, reinstalled the OS, and the porn went away.

    But the legal system doesn't have our sense of humor. It's easy to imagine, in the light of TFA, that we could have been charged with a repeated pattern of downloading porn on company machines. In some companies, this could have easily got us fired. Luckily for us, our bosses just considered us crazy software developers.

    I did learn enough that, some time later, I wrote up a little demo of how to make an innocent-looking web page download files that the user never sees, but which leaves incriminating downloads in the browser cache and the firewall logs, which could convict them as happened to this guy. I use the demo to convince people that I'm not being paranoid when the first thing I do with a new browser is to turn off java, JS and any other "scripting" tool. We're reaching the stage where you can be convicted for what you computer does behind your back. Stories like this are good for explaining why everyone really needs to learn enough about how their software works that you can block things like this that can plant evidence on your machine.

    Of course, you really can't know about every automated thing that might be hidden in that box. And I should probably add this news story to my demo's docs, as an extra motivator.

    --
    Those who do study history are doomed to stand helplessly by while everyone else repeats it.
  43. Hey, I've done that ... by jc42 · · Score: 2, Insightful

    Court documents say that Schuster ran a Google search over CWWIS' network using the following search terms: "how to broadcast interference over wifi 2.4 GHZ," "interference over wifi 2.4 Ghz," "wireless networks 2.4 interference," and "make device interfere wireless network." [TFA]

    Hmmm ... A few months ago, I did a number of google searches with very similar terms. I was trying to find out how to diagnose and defend against some wireless interference. Not that I learned all that much. I suspect that you need some rather special equipment to locate the source of interference, but I don't know what that equipment might be.

    Anyway, I wonder if I could be a suspect now because of those searches?

    I have noticed in the past that if you ask questions about security, you're usually treated as if you were a potential security risk, not as someone trying to improve your own security.

    --
    Those who do study history are doomed to stand helplessly by while everyone else repeats it.
  44. Create a user? Lame. by Anonymous Coward · · Score: 0

    Use tor and vmware. Tor for network anonymity, vmware for local cleanliness. "Revert to snapshot" is your friend.

  45. Title of Article is wrong. by Anonymous Coward · · Score: 0

    Wow, this slashdot article even has the title wrong. As any hacker will tell you, the scumbag who pulled off this exploit was a cracker. I have seen this error committed countless times by clueless newspapers and magazines, but I'm surprised that Slashdot got this wrong.

  46. Re: Wake up and smell the coffee!!! (Re:YRO?) by glwtta · · Score: 1

    It continually astounds me how the American people are willing to look the other way when it comes to their liberty and civil rights being encroached on!

    Dude, the American people just looked the other way when the US government allowed itself to torture prisoners, and compromised just about every tenet of a fair trial. And you want us to care about web cookies and browser logs and shit?

    --
    sic transit gloria mundi
  47. Re: Wake up and smell the coffee!!! (Re:YRO?) by sacrilicious · · Score: 1
    Is the information faulty? Did someone munge with the data? Were Google's databases corrupt? Was the data recreated or generated from other data? Has Google's spy software been through open source review? How well was Google's software tested?

    Agreed all! I'll add one: Might someone at google have an agenda? I.e., might the data be deliberately falsified?

    --
    - First they ignore you, then they laugh at you, then ???, then profit.
  48. Re: Wake up and smell the coffee!!! (Re:YRO?) by sacrilicious · · Score: 1
    That's like looking at a key eye witness who saw you stab Nicole Brown Simpson and saying "How do I know you weren't on LSD and just imagining me there?" Seriously, independent third party witnesses are key to the judicial process. Get over yourself.

    In a (sane) legal proceeding, there are resources allocated to evaluating the likelihood of scenarios proposed by either side. If one side posits that one of the witnesses may be unreliable because of being on LSD, the assertion isn't just tossed out... it's evaluated. There will be people who can come forward and testify as to the witness's habits, character, circumstances, all of which will usually lead to a reasonable assessment of the credibility of the "might he have been on LSD" question.

    If google turns over search terms, this gets one FUCK of a lot harder. If someone wants to contest the search terms, what exactly are they going to say? "Um, I want google to prove the impossibility of someone mucking with the records in question. And I'd like google to prove the integrity of the code involved in collecting and storing this data"... even though doing so is in all likelihood impossible even for someone with a triple PhD in computer science, and to even try is something that google will fight tooth and nail since it would involve revealing both code and business logic.

    --
    - First they ignore you, then they laugh at you, then ???, then profit.
  49. Re: Wake up and smell the coffee!!! (Re:YRO?) by justinchudgar · · Score: 1

    One of my "bosses", who is responsible for security control of our Active Directory domain was utterly mystified that I could log into a dozen or so PCs in 4 different offices and change the Domain that they belong to without leaving my chair. She had never heard of VNC let alone FastPush. Her expectation was that I would physically walk to each desk and do this in turn. With that level of comprehension and that level of responsibility, it would be SO easy to scatter red herrings throughout the enterprise. Without details on how the evidence was gathered and the skill of the investigators, I have little faith in its reliability.

    --
    WARNING: Smoking this sig may cause lowered IQ, insanity or short term memory loss. It is also really bad for your monit
  50. Geeks dump Google like a hot rock by Anonymous Coward · · Score: 0

    Back in the early 90's, google was cool. Powerful sneezer geeks told other geeks about it. It provided better, faster results than Dogpile, Hotbot, etc.

    Fast forward to 2006. Google is cutting deals with the CIA and FBI to share all the data they've compiled and data mined on individuals.

    Forget it. I say, forget google. F! google.

    It comes down to a war. The geeks vs. the pigs. Google is just turning around and taking it in the *** from the pigs, and not standing for anything anymore - originally it stood to empower people to find the information they needed to improve thier lives. From finding obscure drivers to medical information to self diagnose, to finding the latest copy of software to old friends. It was about individual empowerment through the spread of information that wanted to be free.

    Now, however, the pigs are all over the net, and they have brought their corrupt anal retentive mentality with them. I'm so sick of the geeks on slashdot rolling over and taking it in the ass without a fight, dickering around about "the law", etc. Its like listening to a bunch of old ladies squabble about the price of eggs down at the local grocery store.

    The law is nothing but a corrupt way to internalize control over you. There are oceans of laws to criminalize and deamonize anyone for profit via a slander game. You can ask any judge, and he can't quote verbatim even 1% of the laws out there. If a judge can't, for sure the rest of the public can't. These laws are passed out of site and 99% of people which have to live under them have nothing to do in their creation. In most towns, you don't even have access to the laws, unless you can talk your way into a privately owned law library owned by the lawyers in the town.

    Watch Braveheart.

    Which side are you on? Are you a geek? Or are you a pig?

    Or are you a freedom fighter? Or are you just a sheep in geek clothing.

    The only single law I want, is the law to be left alone. You could replace those hundreds of lawspeak mumbo jumbo books with that. The original framers of the constituion started out right. Life, liberty, and the pursuit of happiness, which in spirit comes down to just that - the right to be left alone - in their mind, from overreaching state power. After that it spiraled down into the toilet bowl because they patterened their system after the only thing they knew, English law, which is what they were fleeing, and which was corrupt to the very core. It exploded in Federalism and all their checks and balances were for naught. The state is nothing but a bunch of thugs, a gang with radio, which cares only about projecting power. The only checks and balances left now are the powerful viral ideas they made popular, which can't be killed. That one has to fight the spread of the power and corruption of government, because when any of us lose our liberties anywhere, all of us lose.

    So if you work for Google, take note. This geek will no longer patronize your sites or products. I will no longer promote you. You have fallen out of favor with the powerful sneezers, which is eventual death in cyberspace.

  51. Re: Wake up and smell the coffee!!! (Re:YRO?) by Phroggy · · Score: 1

    We're reaching the stage where you can be convicted for what you computer does behind your back. I respectfully disagree. Many people have experienced their computers doing things they never wanted and don't understand, and I think (perhaps overly optimistically) that the courts will be sympathetic if somebody discovers (e.g.) that your computer has been downloading child pornography at 12:30am every night and saving it in your browser cache, if you claim you weren't aware of it and don't know how to make it stop.

    Stories like this are good for explaining why everyone really needs to learn enough about how their software works that you can block things like this that can plant evidence on your machine.

    Considering how much of the modern Web you'd be shutting yourself out from if you disabled JavaScript, I wouldn't view that as a solution. What are some other lessons you think novice computer users need to learn, that would have prevented this particular problem from arising? Can you clearly explain the reasons to your mother? Have you done so?
    --
    $x='S24;r)>63/* h@<5+oZ)32"5cz';$me='phroggy'x$];
    $x=~y+ -xz+\0-Tx+;print$_^chop$me for split'',$x;
  52. Re:YRO? by Tzarius · · Score: 1

    So if your phone lines pass through Company Y's systems, they can listen in? Oops, now all forms of long-distance communication are open for listening!

  53. Re:YRO? by Anonymous Coward · · Score: 0

    But, oops, that's already covered by a completely seperate raft of laws and is a completely different kettle of fish.

    Telephone conversations are between two people, Google searches are between you and Google. Just as the other person in your conversation is allowed to tell the police what you said, Google and say what you were searching for.

    Sorry to rip up your tin-foil hat.