Photobucket Hackers Nabbed, Face Serious Charges From US Authorities
The U.S. Department of Justice said in a statement released Friday that two men, Brandon Bourret, and Athanasios Andrianakis, of Colorado Springs, Colorado
and Sunnyvale, California, respectively, were arrested for their sale of software designed to breach the security of photo-sharing site Photobucket.com; their "Photofucket" app, says the linked Register report, was used "to plunder Photobucket's users' private and password-protected information, images and videos, it has been alleged ... The charge sheet against Bourret and Andrianakis details one count of conspiracy and one count of computer fraud, aid and abet – both of which carry a maximum prison sentence of five years and a fine of up to $250,000.
In addition, the men stand accused of two counts of access device fraud, which carries a higher prison sentence of up to 10 years and a fine of up to a quarter of a million dollars, per count." The indictment, filed in Federal District Court in Colorado, is far easier to read than many.
I believe their "hack" was just guessing (common) filenames on urls, trying them and moving to the next guess.
"...their "Photofucket" app, says the linked Register report, was used "to plunder Photobucket's users' private and password-protected information, images and videos, it has been alleged .."
Sounds exactly like any one of the many NSA programs that have been pointed out over the past year after Snowden relased info.
The assets in question were not "protected" by passwords, they were stored on publicly accessible and easily guessable URLs. I mean, if by protected by password they mean anyone without the password could take common camera file names and type in an easily guessable URL without the password then well ya.
Pointing out a flaw in someone else's software should not, by itself, be a criminal act. Once the information is public, automating the exploit could be done by anyone proficient in the art.
But selling a tool that uses the vulnerability? They crossed a line, but throwing the book at them seems a little harsh.
09F91102 no, 455FE104 nope, F190A1E8 uh-uh, 7A5F8A09 that's not it, C87294CE no. Ah! 452F6E403CDF10714E41DFAA257D313F.
So Chinese college students are reading Obama's unclassified emails and these guys are busted for hacking ebay photos. :-D
Those penalties seem overly harsh.
"If any question why we died, Tell them because our fathers lied."
What the hell is wrong here? These guys are going to do time for an attack based on a jurrassic flaw? Isn't this crap in books on the subject with titles like "don't ever set up a website like this"!
How much jail time did Photobucket executives get for allowing such lax security in their app in the first place? Must be at least twice the 5 years that these two are getting. Maybe more. Right?
I'm royal.
So what is YOUR connection to the Spencer family? or is it just a 'royal PITA' you are accepting credit for? If so, the Hollywood fire hydrant, and duct tape is for you dude, your fantasy's fulfilled. Now go away and let the people sort this shit out.
you get more time for hacking a corporation then you do for manslaughter.
by TheSpoom (715771) Uncaring Linux user here. I have nothing to add to this but please continue. *munches popcorn*
These assholes did things they had no moral right to do. They deserve to be punished because they actually committed intrusions, which is
behavior that is fundamentally different from merely exposing a security flaw.
To those of you who are spouting off the bullshit "moral relativism" arguments about how the NSA or Obama or some other government entity does things which are wrong "therefore anyone else who does similar stuff should not be punished" : Your thought processes are deeply in need of repair and your personal moral code is as well. A decent human being doesn't look for excuses which will justify or excuse bad behavior ; a decent human being does what is right because it is the right thing to do and avoids doing what is wrong simply because it is wrong, even if no one is watching.
So it only goes that they receive a fate worse than death. Place them under house arrest and block all network access except to 4chan -- which they shall be forced to moderate. To ensure they actively moderate, they will wear a shock collar around their neck which will administer increasingly painful jolts to prod them into action
one count of computer fraud, aid and abet – both of which carry a maximum prison sentence of five years and a fine of up to $250,000
that sounds familiar.
Anons need not reply. Questions end with a question mark.
Although the maximum penalties are, in my opinion, way too high I'm just happy they're not adding on the dozens of fraud, cracking, and illegal access charges I'm so used to seeing. One charge of violating each actually applicable law is a refreshing change. I wonder if this is a signal the abuse of plea bargaining and DA threats has stopped?
If video games influenced behavior the Pac Man generation would be eating pills and running away from their problems.
No, pretty soon they're going to drop the pretense and just start calling it what it is: "War on the People"
I mean when someone breaks in to your house, you should go to jail right? After all, your home security sucks. I don't care if you think it is good, it sucks. Virtually nobody bothers with good home security.
So you should go to jail if someone breaks in... ...or maybe you should reexamine this "blame the victim" attitude so many geeks have with regards to hacking.
Here manslaughter is a Class 2 Felony. That means 4 years minimum sentence (or 3 years minimum if there are mitigating circumstances), 10 year maximum (12.5 if there are aggravating circumstances). This is presuming first time offence, and only one count. A repeat offence can bring it up to as much as 35 years.
So no, doesn't look higher to me. Remember there's a difference between maximum and minimum. When a sentence is "up to" that means "the absolute maximum a court may sentence for a given offence." Usually, there's a fair bit of range in a sentence since the idea is a judge will consider the factors of the individual case.
Don't worry, the next ones will do just that. As you said, it's "cheaper" if you get caught. And probably easier to pull off, too.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
Or...It's bad enough when Obama/Bush/Hillary but here we have two yahoos who would let anyone do it.
When Fascism comes to America, it will call itself Anti-Fascism, and tell you to give up your guns.
Of course they won't. Even Stalin and Mao never sold their mass murders as anything other than "War on {criminal flavor of the day}".
Therefore, by the (faulty) logic you're using, you're just a cow with a keyboard - osu-neko (2604)
So it only goes that they receive a fate worse than death. Place them under house arrest and block all network access except to 4chan -- which they shall be forced to moderate.
Prisoners usually receive some token payment for their work, though. 4chan janitors do it for free.
Why does anybody, anyone at all, still believe in this "cloud" thing? Any person or company that stores anything personal/private/confidential/valuable in "cloud space" is Just Asking For It.
I speak as a person with 50 years experience in IT. The lesson of those years is - You cannot, must not, trust Other People with your precious jewels. The human race does not just have malicious individuals; it is 80% composed of lazy incompetents who don't pay attention and can't keep promises.
"Cock Up Your Beaver" does not mean what you think. This sig is intended to clog filters and annoy do-gooders
Alrighty then, what would be your reasoning for the implementation of fascism and the resulting wide spread corruption?
Yeah, I'm a 'wingnut' alright... the OXCART type, but I support the non military application of it..
Put your shit on a publicly accessible site? Fuck you if you have a problem with people accessing it.
The web doesn't belong to you. The server your shit is on doesn't belong to you. If you don't want personal stuff being publicly accessible don't have it somewhere that enables that.
Fuck off with your "mine" schoolyard bullshit. You're like the tossers who think Twitter is a private chatroom with invites for participation who have the nerve to get annoyed that their conversations can be interrupted by anybody with an account.
"Wait. Something's happening. It's opening up! My God, it's full of apricots!"
From what I read there: http://photofucket.software.in...
It appears that Photofucket is a backup tool for downloading pictures from your Photobucket account, if you have the login/password.
Otherwise, it will simply bruteforce all urls (probably by using counters with base filenames) in order to grab the pictures.
Unless they collected the passwords entered by their users, I don't see any crime here, except the offensive name for Photobucket.
WTF ?
What do you mean, 'Even Stalin'? His acts were as mainstream as it gets at the time, and the people running the Western Media were enthusiastic about covering it up.
Mao had a very closed up environment to work in. Western Journalists weren't touring through China in useful idiot mode during the worst of his atrocities, like the dupes in Russia.