US 'hacktivist' jailed over AT&T network attack

4.5
A US 'hacktivist' who broke into telecommunication giant AT&T's network and stole contact details for 120,000 iPad owners has been sentenced to 41 months in jail.

Andrew Auernheimer, aka Weev, stole the email addresses by exploiting a bug in the way AT&T set up its network.

Auernheimer passed the addresses to a journalist claiming the hack was done to highlight security failings.

But officials said Auernheimer knew he was breaking the law with the attack.

In a statement, US attorney Paul Fishman said Auernheimer "concocted" the story that the attack was done to make the internet more secure only after he got into trouble for the 2010 hack.

"The jury didn't buy it, and neither did the court in imposing sentence upon him today," said Mr Fishman.

In the hack attack Auernheimer worked with co-defendant Daniel Spitler to explore a bug in AT&T's network settings. They discovered that AT&T servers responded with email addresses for iPad owners when passed identifying numbers from Sim cards in the tablets.

Spitler, who pleaded guilty in June 2011, wrote software to crank through lots of different ID numbers which netted the pair more than 120,000 email addresses. AT&T has closed this loophole.

The list of addresses was passed to several journalists to publicise what the pair had found.

Lawyers for the Electronic Frontier Foundation (EFF), which campaigns on digital rights, said the sentence was unjust.

"Weev is facing more than three years in prison because he pointed out that a company failed to protect its users' data, even though his actions didn't harm anyone," said Marcia Hofmann, an attorney at the EFF.

"The punishments for computer crimes are seriously off-kilter, and congress needs to fix them," she added. The EFF would help Mr Auernheimer prepare an appeal against the sentence, she said.

Spitler is currently awaiting sentencing.

Posted:

Source: http://www.bbc.co.uk/news/technology-21845246

Comments

"US 'hacktivist' jailed over AT&T network attack" :: Login/Create an Account :: 178 comments

If you would like to post a comment please signin to your account or register for an account.

NotedPosted:

Crazy stuff, I have always wondered how people do stuff like this.

ToesPosted:

Yikes
Mimz
Hall
Vice
Soulful
Hall
Teh
Vice Whats up with all the hackers lately?


yea true some hackers do it for fun /:


Because they can and think they won't get caught..


Most of them don't get caught.


true, but the ones that do deserve it.


They all deserve it, just not all of them do get caught..


There has always been a lot, it has only recently been publicized as much.

Not all hackers deserve it, plenty of people find exploits like this and release it to the company to help them fix it or to gain some money for giving their services. Plenty of hackers actually get hired because they can do this stuff on their own.


Still.. I think they should serve some jail time.

If they could all be found they would.

ToesPosted:

Mimz
Hall
Vice
Soulful
Hall
Teh
Vice Whats up with all the hackers lately?


yea true some hackers do it for fun /:


Because they can and think they won't get caught..


Most of them don't get caught.


true, but the ones that do deserve it.


They all deserve it, just not all of them do get caught..


There has always been a lot, it has only recently been publicized as much.

Not all hackers deserve it, plenty of people find exploits like this and release it to the company to help them fix it or to gain some money for giving their services. Plenty of hackers actually get hired because they can do this stuff on their own.


Really? That would be a cool job as a professional hacker.

BashfulPosted:

Hall
Vice
Soulful
Hall
Teh
Vice Whats up with all the hackers lately?


yea true some hackers do it for fun /:


Because they can and think they won't get caught..


Most of them don't get caught.


true, but the ones that do deserve it.


They all deserve it, just not all of them do get caught..


There has always been a lot, it has only recently been publicized as much.

Not all hackers deserve it, plenty of people find exploits like this and release it to the company to help them fix it or to gain some money for giving their services. Plenty of hackers actually get hired because they can do this stuff on their own.

HallPosted:

Vice
Soulful
Hall
Teh
Vice Whats up with all the hackers lately?


yea true some hackers do it for fun /:


Because they can and think they won't get caught..


Most of them don't get caught.


true, but the ones that do deserve it.


They all deserve it, just not all of them do get caught..

HallPosted:

Axe I honestly don't see how people find hacking into companies fun, or enjoyable. This is just stupid, and he deserves the jail time.


Exactly, he really does. I don't see their reasoning, they could use their skills in a job..

KiiLERPosted:

Cygnet
Vice
Axe I honestly don't see how people find hacking into companies fun, or enjoyable. This is just stupid, and he deserves the jail time.


I agree, it may be fun at the moment, but its not worth it in the long run.


I feel like they think if they hack into a company, and then get caught they might end up in a career for them to help there security..but that usually never happens..


We don't honestly know what his intent was, but isnt the punishment a little harsh? There are worse things you can do than show AT&T and security exploit in their system.

CygnetPosted:

Vice
Axe I honestly don't see how people find hacking into companies fun, or enjoyable. This is just stupid, and he deserves the jail time.


I agree, it may be fun at the moment, but its not worth it in the long run.


I feel like they think if they hack into a company, and then get caught they might end up in a career for them to help there security..but that usually never happens..

CheeseStuffedPizzaPosted:

Jail time for this guy. What a group does this?

ToesPosted:

Axe I honestly don't see how people find hacking into companies fun, or enjoyable. This is just stupid, and he deserves the jail time.


I agree, it may be fun at the moment, but its not worth it in the long run.