US 'hacktivist' jailed over AT&T network attack

4.5
A US 'hacktivist' who broke into telecommunication giant AT&T's network and stole contact details for 120,000 iPad owners has been sentenced to 41 months in jail.

Andrew Auernheimer, aka Weev, stole the email addresses by exploiting a bug in the way AT&T set up its network.

Auernheimer passed the addresses to a journalist claiming the hack was done to highlight security failings.

But officials said Auernheimer knew he was breaking the law with the attack.

In a statement, US attorney Paul Fishman said Auernheimer "concocted" the story that the attack was done to make the internet more secure only after he got into trouble for the 2010 hack.

"The jury didn't buy it, and neither did the court in imposing sentence upon him today," said Mr Fishman.

In the hack attack Auernheimer worked with co-defendant Daniel Spitler to explore a bug in AT&T's network settings. They discovered that AT&T servers responded with email addresses for iPad owners when passed identifying numbers from Sim cards in the tablets.

Spitler, who pleaded guilty in June 2011, wrote software to crank through lots of different ID numbers which netted the pair more than 120,000 email addresses. AT&T has closed this loophole.

The list of addresses was passed to several journalists to publicise what the pair had found.

Lawyers for the Electronic Frontier Foundation (EFF), which campaigns on digital rights, said the sentence was unjust.

"Weev is facing more than three years in prison because he pointed out that a company failed to protect its users' data, even though his actions didn't harm anyone," said Marcia Hofmann, an attorney at the EFF.

"The punishments for computer crimes are seriously off-kilter, and congress needs to fix them," she added. The EFF would help Mr Auernheimer prepare an appeal against the sentence, she said.

Spitler is currently awaiting sentencing.

Posted:

Source: http://www.bbc.co.uk/news/technology-21845246

Comments

"US 'hacktivist' jailed over AT&T network attack" :: Login/Create an Account :: 178 comments

If you would like to post a comment please signin to your account or register for an account.

CheeseStuffedPizzaPosted:

They has been a lot of hackers lately. They need to stop.

CearnsyPosted:

DLT
TakeTheDamnPiLL
xIIJazza surely, You'd rather pay the guy to tell you how he managed to do it?


I don't think he would since he could get into people's account and manipulate them.


Had he found the exploit then told them about it instead of using it for his own gain then they may have rewarded him.


Surprisingly they might have but they could also do something as he was looking for a flaw i guess

MTVPosted:

TTGiMonster poor guy it was only going to make some money :( and 41 months is way to long


Well what he did was illegal so he kinda deserved it

TTGiMonsterPosted:

poor guy it was only going to make some money :( and 41 months is way to long

DLTPosted:

TakeTheDamnPiLL
xIIJazza surely, You'd rather pay the guy to tell you how he managed to do it?


I don't think he would since he could get into people's account and manipulate them.


Had he found the exploit then told them about it instead of using it for his own gain then they may have rewarded him.

JakesLobbies-Posted:

M60
640 he must be very very smart.


Well to hack something you would have to be


True there,

TakeTheDamnPiLL
640 he must be very very smart.


Indeed he was until he got caught.


Maybe to have the talent to do that yea, but he got arrested, say a lot about how well he "Hacked" AT&T xD

CearnsyPosted:

Compliance
M60
640 he must be very very smart.


Well to hack something you would have to be


Usually stupid people don't hack major businesses.


Well that makes sense they wouldn't know how to

OdinPosted:

Yikes
ever AT&T sucks anyways. I wish he would have taken them down.


Ikr, AT&T is garbage, I hate it so much.


What are you guys talking about! Hah AT&T is just as good as the other service providers if not better!

EverPosted:

AT&T sucks anyways. I wish he would have taken them down.

TTG-xSHADOWSxPosted:

Good thing I always stick with Verizon.