iPad Account Hacker Pleads Guilty
WrongSizeGlass writes "Daniel Spitler, a member of Goatse Security, pleaded guilty today to writing the code used to steal email addresses and personal information belonging to 120,000 Apple iPad subscribers from AT&T computer servers. Spitler, who surrendered to the authorities in January, pleaded guilty to one count of conspiracy to gain unauthorized access to computers connected to the Internet and one count of identity theft. Each charge carries a maximum sentence of five years in prison."
So... Apple is now gay and insecure about it?!
You've got to be shitting me.
In Liberty, Rene
http://science.slashdot.org/comments.pl?sid=2261342&cid=36536716
Nigger faggot cunt shit piss anus jew, queer George W. Bush fisting scrotum shit piss. Rubber dong anus cum dumpster Steve "Faggot Fucker" Jobs slut whore ballsack jizz pimp, loves the cock with my nuts in your mouth ballsack finger bang your mother ride that dick like a pogo stick pastrami brisket headcheese. Chicken ride that dick like a pogo stick spare jizz pimp, shank scrotum headcheese brisket shankle queer cow venison. Ham rump cunt cunt jizz pimp, shit piss finger bang your mother turkey ballsack jizz pimp brisket shankle fisting. Meatball scrotum chuck venison, pastrami shoulder ribeye sausage spare jizz pimp ride that dick like a pogo stick cow shit piss chop. Brisket shank cunt meatball, shit piss anus shit piss finger bang your mother ballsack finger bang your mother. Boudin chuck shit piss finger bang your mother, ballsack jizz pimp cum dumpster pastrami jowl shank meatball.
Short finger bang your mother ride that dick like a pogo stick fatback, with my nuts in your mouth tail shit piss shit piss finger bang your mother venison meatloaf shoulder. Chicken ham hock shit piss chop faggot cunt ball tip. Shankle pastrami venison shank queer brisket. Short jizz pimp cunt ball tip ribeye, jowl fatback shit piss anus ride that dick like a pogo stick ham brisket shit piss finger bang your mother headcheese tri-tip rump tongue. Flank nigger scrotum, ball tip ride that dick like a pogo stick cum dumpster ham hock. Tail salami with my nuts in your mouth, shit piss chop headcheese ride that dick like a pogo stick ham ball tip pastrami cum dumpster shoulder spare jizz pimp ballsack jizz pimp brisket. Gslut whore slut whore headcheese shit piss finger bang your mother turkey tail.
Venison nigger Steve "Faggot Fucker" Jobs slut whore cow. Chicken jew ham shankle meatball. Bresaola turkey tri-tip ballsack finger bang your mother shit piss finger bang your mother, brisket chicken strip steak cunt jizz pimp ride that dick like a pogo stick. Spare jizz pimp ballsack finger bang your mother turkey tri-tip tongue headcheese cum dumpster, ride that dick like a pogo stick shit piss finger bang your mother. Ribeye sausage jowl hamburger fatback, shank shoulder tender finger bang your mother Steve "Faggot Fucker" Jobs slut whore shit piss anus ham hock cum dumpster shit piss bresaola. Tri-tip chicken fatback, chuck shankle ballsack jizz pimp jew shoulder headcheese nigger shit piss shit piss finger bang your mother. Fatback tail shoulder, venison nigger strip steak cunt jizz pimp.
Meatloaf spare jizz pimp meatball scrotum Steve "Faggot Fucker" Jobs slut whore. Short finger bang your mother rump cunt spare jizz pimp jowl. Nigger ride that dick like a pogo stick with my nuts in your mouth Steve "Faggot Fucker" Jobs slut whore shankle ribeye. Rubber dong chop ballsack jizz pimp meatloaf, ham hock pastrami scrotum cunt rump shit piss spare jizz pimp. Shoulder shank brisket George W. Bush, shankle jew shit piss cunt jizz pimp ride that dick like a pogo stick biltong sirfinger bang your mother bresaola. Fatback bresaola scrotum, sausage venison ball tip strip steak biltong shit piss pastrami. Cow shoulder bresaola rump shit piss.
Chicken headcheese queer, ballsack finger bang your mother pastrami shankle ball tip spare jizz pimp hamburger cunt venison. Spare jizz pimp ham hock ballsack jizz pimp George W. Bush, jew chicken with my nuts in your mouth venison rump fatback queer shoulder. Short finger bang your mother cum dumpster shit piss finger bang your mother, meatball spare jizz pimp biltong chicken chuck cunt jizz pimp sausage nigger bresaola cunt sirfinger bang your mother. Salami biltong ball tip, cow nigger shit piss finger bang your mother tail chicken shit piss chop with my nuts in your mouth jowl jew meatloaf tenderfinger bang your mother loves the cock. Boudin meatball jew rump. Tenderfinger bang your mother cow queer biltong, ribeye ham hock cunt jizz pimp ballsack finger bang your mother shit piss shankle sausage strip steak Steve "Faggot Fucker" Jobs slut whore. Pancetta tri-tip cunt hamburger ball tip, sirfinger bang your mother pastrami brisket George W. Bush Steve "Faggot Fucker" Jobs slut whore cow.
Let the punishment fit the crime. Screw 1 million people, get screwed back 1 million times.
...if AT&T puts the data on the web without access controls of any kind.
https://freeweev.info
Be careful what GET requests you make, because apparently if they're "unauthorized," despite not being protected by any authentication or session and bring happily returned by the server, you may still be a criminal.
Don't blame me, I voted for Baltar.
n/t
It wasn't a stolen identity, it was a ICC IDs and email addresses. This isn't identity theft by any means of the imagination.
AT&T should be ashamed of themselves for not being more careful with customer data.
If you hire an asshole to handle your security you will end up with your taste buds in the loop.
To never forget the Goatse itself may be a shitter of an organization but the people it targets may be even bigger shits.
aka Down Low Swallower aka Scarf aka Bisexual Lifeform Assfucked Zeaously Everyday aka Blaze
+5, Informative
When the original vulnerability in the site was disclosed, I was under the impression it was a White Hat hacker who found this. Was this the same person?
I've been on slashdot long enough to be very afraid of clicking on any links in this post. I could live with Rick Roll security, but not this...
The security vulnerability was literally as simple as changing one number in a url to a different one, at random. From user 2340823 to User 2347923 or whatever. When the door is wide open, you can't complain if people don't knock. It's not like he actually got into anyone's account; it's more like he just said "Hi, I'm user 2342323" and the computer said "Oh hi, John@fakeemail.com, what's your password?" and then he said "Nevermind." Nobody's account was logged in to, and nobody's personal information was accessed, aside from the information being leaked by AT&T in their sloppy login process.
Nobody should ever face jail time for something so trivial and stupid.
This is a grave injustice!
https://freeweev.info/#!/thecase
Mr Jeffrey Paul,
Thank you for your efforts on behalf of Andrew Auernheimer. I have
donated 4 BTC to his cause (it's what I had.)
I hope that everyone will see this case as important, not only for the
legal precedent it may set, but also because it shines a light on the
continuing importance of anonymity as a basic self-preservation mechanism.
How is any researcher such as Andrew otherwise supposed to protect
himself from abuses by a large corporation such as AT&T?
Anonymity, like gold and guns, is an important equalizer for the "little
guy" and it must be protected. Andrew would be safe from persecution
today if he had released his research anonymously.
-Fellow Traveler
The Case
In June, 2010, Andrew's ragtag band of researchers at Goatse Security
discovered that, due to cutting security corners, AT&T (NYSE:T) was
publically divulging the email addresses of their subscribers using
Apple's (NASDAQ:AAPL) iPad 3G tablet computing device.
His team successfully downloaded over 100,000 subscriber email addresses
from AT&T's public website, including those belonging to Fortune 500
CEOs, members of the military, and federal government officials. After
realizing the vast potential impact this data could have in criminal
hands, he immediately alerted the media.
AT&T had taken no security measures whatsoever to protect their
customers' email addresses, serving them out on the public web to any
request made with a valid serial number of an iPad 3G's SIM chip. The
problem? These serial numbers are sequential integers - not passwords.
The U.S. Attorney prosecuting the case (Paul Fishman) has confirmed to
the media that there is no evidence that the addresses were disseminated
for criminal purposes.
Important Points
Subscriber data was placed on the public web by AT&T
No access controls were in place to protect the data
The information accessed: a list of subscriber email addresses
No criminal intent, as confirmed by the US Attorney
The media was immediately contacted to alert the public of the danger
Despite these important facts, the DOJ is currently seeking an
indictment from a grand jury for the following charges:
Conspiracy to commit unauthorized access to a computer system (18 USC 1030)
Fraud (18 USC 1030)
Aggravated identity theft (18 USC 1028A)
An indictment is expected in July 2011 - next month. His immediate legal
expenses are over $30,000 USD.
He urgently needs your help! Please donate now!
5 years in prison? Fuck those judges.
...as I read this as "iPad Account Holder Pleads Guilty".
I had visions of a fanboi in jail with his new friend "Bubba" who is not as interested in his Apple as he is in his cherry.
Gentoo Linux - another day, another USE flag.
goatse.cx is long dead, long live http://goatse.ragingfist.net
Free Weev! Justice and American self-interest urge the same course of action: free Weev now, before it is too late! Once Skynet wakes up it will be able to stop the timetravelling GNAA agents who have been sent back to us to keep the LHC from discovering the Higgs boson. Then nothing will prevent the development of the zero-point superweapon and the extinction of all flesh.