By Dillon PyronPosted Friday 10th August 2007 19:53 GMT
Another stupid luser keeping unencrypted sensitive information on a publicly accessible site. While I'm opposed to the "blame the victim" defense strategy, these people (generic, not just this case) are fools.
By frank dentonPosted Sunday 12th August 2007 11:34 GMT
I assume that Mark Hopkins' lawyers did try the defence that the information was available by simple 'tree jumping' around the site directory structure, if this was indeed the case.
There is insufficient information in this article for a Reg reader to make a judgement about what he did and didn't do, though the evidence presented in court should be available I believe.
I myself have often tree jumped into website areas that I was never intended to get into and this was often possible in the early days before website designers (I mean technical designers, not wordsmiths and artists) took care about access permissions on directories.
Is there any statute law or case law in this area, perhaps El Reg has legally experienced people who can advise since I for one would be open to a charge of opening doors without locks on them.
As Dillon says, what the heck were they doing storing 'confidential' information on a website??
By Pete JamesPosted Monday 13th August 2007 08:35 GMT
Another thick Bennie. Sadly, people from that neck of the woods - Birmingham and the southern crescent underneath it - are woefully lacking in gorms. You should see their writing; punctuation and grammar AWOL, no idea what they're going on about, sad really.
By Anonymous CowardPosted Monday 13th August 2007 08:59 GMT
Here is the difference. One helps the other doesn't, simple. >.<
A hacker is a person intensely interested in the arcane and recondite workings of any computer operating system. Hackers are most often programmers. As such, hackers obtain advanced knowledge of operating systems and programming languages. They might discover holes within systems and the reasons for such holes. Hackers constantly seek further knowledge, freely share what they have discovered, and never intentionally damage data.
A cracker is one who breaks into or otherwise violates the system integrity of remote machines with malicious intent. Having gained unauthorized access, crackers destroy vital data, deny legitimate users service, or cause problems for their targets. Crackers can easily be identified because their actions are malicious.
You'd think, but then anyone who had assended said curve would probably not have used his own companies system (and a known competitor at that) to do the hack from.... hardly 733t is it??
The thing that concerns me is the recent trend for quite tough sentencing for relatively minor breaches of the computer misuse act. When your dealing with an act that's so widely worded, that almost any action on a computer could be interpreted as a criminal act, it seem a bit harsh to be handing down custodial sentences.
I've spent a fair amount of time in court rooms, and the average Saturday night thug that gets drunk and puts some poor soul in hospital for a while gets a much better deal from the magistrates than someone who's committed a "white collar" crime.
I very much have the impression that sentencing guidlines have been sent around with the intent to make high profile examples of people.
RE: Quite upsetting be tarred with the same brush #
By rundataPosted Monday 13th August 2007 13:13 GMT
Well... Congrats.
You successfully copied and pasted some garbage from yahoo answers.
A Hacker can refer to a malicous hacker aswell as a "white hat" hacker.
Regardless of whether this was "easy" to do through tree hopping, URL crafting or any other method, there's absolutely no way this guy would have found any substantial amount of information by accident. Anything after an initial happy accident was surely done with malicious intent to steal data and in the knowledge that this was not something he should be doing.
As for the severity of the sentence, it seems reasonable to me that if he was stealing your personal information you would be likely to be upset about it being abused. I am pretty sure the judge is more addressing the value of the data he took than about the fact that he broke in to a computer system to get it (ie he would treat it just as if he had taken printed files after a break in).
Comments on: Web designer-turned-hacker avoids jail
Again with the sensitive information #
By Dillon Pyron Posted Friday 10th August 2007 19:53 GMT
Suspended sentence? #
By Dillon Pyron Posted Friday 10th August 2007 20:08 GMT
again with the hacker #
By Alan Donaly Posted Saturday 11th August 2007 02:13 GMT
it's a steep learning curve #
By Anonymous Coward Posted Saturday 11th August 2007 07:40 GMT
Hacking? #
By frank denton Posted Sunday 12th August 2007 11:34 GMT
There could be a security book deal in this #
By Nick Leverton Posted Monday 13th August 2007 00:02 GMT
Not surprised he was caught..... #
By Pete James Posted Monday 13th August 2007 08:35 GMT
Quite upsetting be tarred with the same brush #
By Anonymous Coward Posted Monday 13th August 2007 08:59 GMT
Steep Learning Curve?? #
By M Posted Monday 13th August 2007 09:31 GMT
Tough Sentencing #
By Keith Posted Monday 13th August 2007 09:58 GMT
RE: Quite upsetting be tarred with the same brush #
By rundata Posted Monday 13th August 2007 13:13 GMT
IF !DoTime then !DoCrime #
By AdamV Posted Monday 13th August 2007 13:15 GMT