Hacker Newsnew | past | comments | ask | show | jobs | submit | lm411's commentslogin

The Warez scene was an absolute blast. I made some of the best friends of my early teenage years there, both online and online/offline.

Unfortunately it came to a sudden end after I got a little too cocky and persistently took and re-took control of a smallish US telecom companies network, and the RCMP came knocking on my door for the FBI. That was largely unrelated to Warez but the advice given to me was that I should probably stop that as well. Thankfully I was too young to be charged with any of it at that time.

I do regret the massive headaches I must have caused the system administrators at the telecom company. Sorry guys. I have repaid my bad karma many times.


Oh...

If those RCMP folks came knocking on your door around January 22nd 1999. Hi there. Long time. It was fun chasing you, but I didn't enjoy the rm -rf.


This would have been a few years earlier... And I don't recall doing anything destructive.

It was definitely a game but I wasn't trying to cause any damage. No doubt I caused more than a few headaches though, which I do truly regret, having been on the other side of the same many times over the past 30 years.


Ah. A few years after you, then, there was a 16 year old Canadian out of #montreal (on IRC) who broke into my main server - on December '24 1998. He ended up rm -rf'ing it, and bragging about it on IRC.

I spent the next month tracking him down. He was fond of DoSing a Canadian ISP. He also, for some reason, fond of DoSing a computer lab at NASA. I tracked him through servers he had broken in at 13 different american universities, a couple of machines at NASA, one machine at fbi.gov, and a variety of others.

Coordinated with a guy at NASA, everyone but FBI was eagerly sending me logs from their servers, and the FBI+NASA looped in RCMP who got thousands of pages of logs from me. Both from servers he had broken into, and from the various IRC channels I monitored his activity from. The Canadian ISP he was fond of DoSing was also quite eager.

Around January 22nd 1999 (might have been a day before or after) the RCMP came knocking on his door. A few hours later (after being released after being interrogated) he got online and told me he would knock my servers offline permanently. At this point I had a phone number directly to the RCMP - and they paid him another visit.


yes -- at the height in the late 90s, i made a friend named chucky while playing quake online. he was just a terrific guy, older than me but treated me with respect, we would hang out IRL and he would hook me up with games after he had finished them. later he went offline and i found out he had been the leader of RISCISO and had disappeared during a criminal prosecution. hope things are well with you sean

The question is whether you find it ok that the FBI comes sniffing after you. Personally I don't find it ok at all. I don't see any of that as a crime either. The legislation is clearly written by corporations and lobbyists acting as lawyers. That's another reason why I think open source is preferrable - that way they are replaced indirectly by not depending on them in the first place, meaning, as a trade-off towards how the society is currently structured. Hopefully it will become more sane again in the future. Back then, though, say in the 1990s or early 2000s, the "vibe" of warez also was "look how great ILLEGAL can be".

You don’t think it should be illegal to hack a telecom network and take control of it?

Nope. It means the people running it did not do a good job configuring and securing it.

So if you steal something it means the owner didn’t do a good job securing it and if you murder someone they didn’t do a good job protecting themselves?

What an absurd world view.


The diff is that owner is responsible for their own shit where a telco has everyone's things in there and is exposed to the whole world instead of just one street.

It is like a bank that has sloppy security and exposes you to the whole world, including adversaries from Russia china NK etc.

Things like Telco cloud banks should absolutely be thrashed for having bad security. Responsible disclosure should also be a thing but we all know these companies sue people for that too.


I have this view when it comes to computers and software, not physical property or people.

Does that extend to medical systems? If someone hacks my pacemaker and destabilizes my heart, or my pharmacy/hospital and prevents me from receiving medical care, is that something that should be legally permitted on the basis that "medical device makers/pharmacies/hospitals should try harder, and should somehow compensate their patients if a hack occurs"?

How do you compensate someone who's dead?

This isn't hypothetical: https://www.politico.com/news/2022/12/28/cyberattacks-u-s-ho...


> Does that extend to medical systems?

Anything network connected that can be reached by an adversary. And, I did not say it shoukd be legal or illegal, just that the fault lies with who administers/secures those systems, not with whoever breaches them.

> How do you compensate someone who's dead?

In some countries where I lived, there were pricelists based on nationality that insurance would pay out in case of accidental death. If you live in a more homogenous country, you can use other factors to determine what the payout should be.


If your bank has shoddy software and a thief steals your money is that ok?

I don’t care in that scenario, it is the bank’s fault, not mine. It is on them to make it right.

It is this disconnected from reality attitude that gives technical people a bad reputation. Please reconsider your bad takes.

Since you mentioned it below several responses to this comment: Why do you think this is okay for software, but not okay in the "physical world"?

Is it about a perceived lack of consequences of the one vs the other? What if the hack caused real damage and suffering? For example, people's medical histories get stolen and exposed? Ransomware encrypts hospital systems, disrupting medical care?

Or, the inverse: while you're away, somebody breaks into your home non-destructively, takes some photos, sleeps on your couch, and leaves. Should that be forbidden? Your fault for allowing it? It is easier to pull something like this in the digital world, is that why it seems different to you?


I don't agree with GP at all, but making hacking illegal indeed gives companies a false sense of security.

Making burglaries illegal is a real way of preventing many burglaries from happening, because it puts people committing them in prison and deters some from doing it in the first place. This only works because the burglar is in the same place as the burglary, and so they can be arrested.

People with little to no computer experience apply the same standard to cybersecurity and treat foreign hackers the same way as burglars. Then they get surprised when the Russians hack them and the FBI does nothing.


You're presenting a false dilemma, there are more options than "all hacking is completely illegal" and "all hacking is a free-for-all".

We're in a thread that starts from the notion that it should not be illegal to "hack a telecom network and take control of it", because "the people running it did not do a good job configuring and securing it." That's essentially the free-for-all position, and defending it by claiming that the opposite extreme is the only other option is a false choice. Nuance and compromise exist, and our world is made of them.

Also, your argument about burglars can be applied to "hackers", too. Police can find and arrest people domestically and beyond. Consequences deter people from all sorts of illegal activity. On the other hand, nation states are not necessarily deterred by laws from kidnapping and killing people inside the territory of other countries. You've probably seen the news.

What's different is the ease of access to digitical, internet-connected systems, and the scale of abuse that affords. That's a reason to think differently about _how_ to shape the rules and laws around "hacking", but not a reason to have no rules or laws at all.


Because it is a battle of the brains, like when you play chess. And I believe the smarter one should win. This is why I have this strongly held belief that if you get hacked, it is on you. The attacker was smarter than you, simple as that. So you have to get smarter and become better. Or you get hacked again and again.

I really don’t understand the urge or need to compare software security with physical security.


> I really don’t understand the urge or need to compare software security with physical security.

Both are about preventing harm in many different forms. Software famously has effects in the physical world, that's the reason why a lot of it exists, and why people get paid that deal with software because it makes their brains feel good.

I also notice that you haven't really answered my questions around that.

> if you get hacked, it is on you. The attacker was smarter than you, simple as that.

From your perspective, what makes "smarter" different from "stronger", or "more resourceful" here? Or do you think that if your door gets bashed in, it's your fault, because your door was too weak? Or your head? What if someone outsmarts your physical security arrangements to wander around in your house? Where's your boundary here?

I think physical and "cyber" security are not so dissimilar in the need to back them up with rules and laws at some point. Still, there are differences, so I don't think the rules and laws need to be the same. You seem to be advocating to have none at all for the software case, and I'm trying to find out about that.


> Both are about preventing harm in many different forms. Software famously has effects in the physical world, that's the reason why a lot of it exists, and why people get paid that deal with software because it makes their brains feel good.

Yes, it would suck if the hospital got hacked while I underwent a surgery for example, and the ventilator stopped working. But if that happens, whoever is doing it is not stronger, just smarter than the people administering the hospital network.

> From your perspective, what makes "smarter" different from "stronger", or "more resourceful" here? Or do you think that if your door gets bashed in, it's your fault, because your door was too weak? Or your head? What if someone outsmarts your physical security arrangements to wander around in your house? Where's your boundary here?

I gave an analogy with chess. You don't have to be strong in the physical sense to win a chess match, just smarter than your opponent. This is how I see the difference.

> You seem to be advocating to have none at all for the software case, and I'm trying to find out about that.

For software, the playing field is level: you use a computer, your opponent uses a computer. But the difference is the other person's capabilities. You can be smarter and you don't get hacked, or your opponent is smarter and hacks you.


Here's how I understand your position so far:

You think it's okay when actual harm and suffering results from a "battle of the brains" via computers, because one party "outsmarted" the other. Sure, it would "suck", but you think the playing field is pure and level, making it a fair contest and any consequence fair game, and therefore it should not be illegal.

You are unable or unwilling to engage with the question if and why using a computer and "smarts" to cause harm is different from using strength, or any other advantage, to cause such adverse outcomes in other ways; it is not clear to me if you would also regard that as okay and think we should not have the laws that sanction such things; or if and why you think this anarchy should only exist in some sort of "digital computer space", crossing which would serve to make actual, real world consequences not matter that much anymore. It's almost like, by putting a computer between actions and consequences, one passes through a waterfall that washes away responsibility and "sin", in the ethical sense. But that depends on whether you think those were there to begin with, and is only an interesting metaphor for me; please don't get distracted by it.

In any case, that's a very interesting position. I'm curious what you gain from arguing it. Where does that come from? It's possible you're just trolling, but maybe smarts and brains connected via networks are truly special to you. Why?

(Edit: Please disregard "what you gain", it comes across completely wrong and takes it in an unintended direction. "Where does it come from" is what I mean.)


> You think it's okay when actual harm and suffering results from a "battle of the brains" via computers, because one party "outsmarted" the other. Sure, it would "suck", but you think the playing field is pure and level, making it a fair contest and any consequence fair game, and therefore it should not be illegal.

I said the fault lies with the administrators of those systems, not with attackers. I really think I never said it should be legal or illegal. I don’t really care if it is illegal or not, hackers are not dettered by the legality of it. Do you think someone in The Gambia cares that hacking is illegal in Canada?

> You are unable or unwilling to engage with the question if and why using a computer and "smarts" to cause harm is different from using strength

For me being smart and being strong are two wildly different things. It is like asking me why I don’t compare apples to oranges. I can’t.

> In any case, that's a very interesting position. I'm curious what you gain from arguing it. Where does that come from? It's possible you're just trolling, but maybe smarts and brains connected via networks are truly special to you. Why?

I am not trolling. I see this, hacking and securing something against hacking, as an “intellectual fight”.

Let’s say you are a 50 year old security admin that gets owned by a 14 year old with a computer. You were beat because the 14 year old one was smarter than you, not that he had more experience or was physically stronger than you. Just smarter.

Now imagine you’re part of a security team and you still get owned. What does that say about you?

I am at a loss on how to explain that when it comes to computer security the fault, in my book, does not lie with the hacker.

Just like when a flaw is found and exploited I do not blame the one who found it, but whoever made it possible in the first place. And in the case that the flaw was patched and a software update was made available, but it was not installed promptly, then the fault lies with whoever did not update the system.

Regarding arguing: I made a statement expressing my position and got mobbed for it. Now I am defending my position.

We can agree to disagree and keep enjoying what is left of our weekends.


Oh, I don't mind the disagreement, I'm curious to understand why your position is so different from mine, after getting closer to understanding what your position actually is. (I had to do that because there are some implicit premises in my thinking vs what you're saying which seem fundamentally different, and I had to work those out for myself.)

I think I do get it now, and it seems to be pretty much to what I described before. While I think that there is responsibility for the outcomes of one's actions no matter through which ways and means they are accomplished, for you, it seems to depend: making it about smarts or intellect or whatever, and putting a computer in between, causes it to transcend legality and morality. Adverse consequences are not on the actor anymore, and purely on the "defender".

That's not how a lot of people (including myself) see this issue. They would not agree that responsibility and outcomes should get disconnected or redistributed by changing the ways and means in between. (Edit, just to make this extra clear: The idea is that it should not matter if one uses their brain and a computer to effect damage, or some other means. Computers are a different tool, not a different game.) Even more, people find it hard to follow both the ethics and the logic of your argument, because you've not been able to express WHY an exception should be made for "smarts" and "computers" and not in other cases. Whenever I've asked you to explain, you've either misunderstood or evaded the question and responded with re-iterating that "smart" is different from "strong", as if that explains anything. (It boils down to being asked: "Why should the difference between red and blue matter here?" and answering with "Because they are different.")

So, you're taking an position that people find ethically problematic and logically inconsistent, and that's the reason why you receive this pushback: people feel motivated to counter what they see as an uncontested "ethical divergence", and you gave them an obvious logical chink to pry a lever into.

What I'm taking away is that you truly believe this, which is so foreign to me that I'm completely mystified. It makes me curious, and also uncomfortable, and for both reasons I wonder: How? Why? However, you're simply re-iterating your position, and I've come no closer to finding out, nor do I think I actually will, because I can't find a way to phrase my questions in a way that would bridge a barrier of understanding between us and make you respond to what I'm asking.

I'm still curious. But in any case, please do enjoy the rest of your weekend.


You don’t have to be smarter than your opponent to beat them in chess. You need to be better at chess, that’s it. Sure you need some degree of intelligence to be good at chess but being better at chess is not an indicator that you are smarter than your opponent. Same goes for computer security or any other intellectual field.

For instance, I’m pretty sure I’m better at computer security than Terence Tao but no way would I say I’m smarter than him.


Semantics. If you have a computer, the hacker has a computer, and you get hacked, the hacker is smarter. For whatever values of better/creative/resourceful you want to attribute to “smarter”.

Do you really think that computer skills are available to everyone on an equal playing field?

So you would be fine with someone clearing out your house, while you were away?

There is no door, that cannot be opened with enough effort. Part of what stops people trying, is the fear of consequences.


I have this view when it comes to computers and software, not physical property or people.

And most people do not have guards and dogs walking around the perimeter, but we still blame the burglars for breaking in their houses.

Maybe you should think through the consequences of living in a society where anything a person can do is allowed lmao

This is trolling or edgelord teen

This is the epitome of the "blame the victim" culture.

When it comes to computers and software, yes. They need to do a better job not letting others screw them over.

It’s an interesting view. In this case you are claiming the victims are bound to the creator/vendor of the software/service, not the hacker?

In a nutshell, yes.

My issue is that software security is not taken seriously most of the time because features are more important than spending a little more time on code quality.

The hacker is not the one writing buggy software.


I was in a small courier group way back when. FXP was definitely common. We could copy a lot of software in a small amount of time.

"Attempt at a coup"? I assure you if those folks had attempted a coup they most likely would have succeeded.

Those folks were there to make a statement and have the best party since before covid.


It is yes - in situations like that, your best bet is to view the SSL cert details. Of course, only if you trust the issuer. ;)


Not really the Pi's fault - really it's AI causing the massive increase in HW prices (notably RAM in this case) that has really destroyed the market for the Pi's.

Same thing happening for servers, gaming PC's, cell phones, so on.


Many in the west certainly wouldn't agree with you now, or 100+ years ago.

https://xcancel.com/DonBraid/status/1187052993788559360

This is about more than just money though.

Politically the west is underrepresented and the cultural difference between the West and the rest of Canada is very significant - unless you ask folks from Ontario who have never been to AB. In my opinion, Canada is too geographically and culturally diverse for a central government to have so much power.


> Canada is too geographically and culturally diverse for a central government to have so much power.

The United States has also had this problem for a long time, imo.


Discussing separation is okay when QC threatens it - hence the clarity act. But when AB wants to do it, they are just a bunch of redneck traitors according to the rest of Canada.

(Cue the "AB is nothing", "AB has no culture", folks that don't have a clue what they are talking about).


> they are just a bunch of redneck traitors according to the rest of Canada.

That's also the prevailing sentiment in much of Alberta.


Of these, I really only see "indigenous rights/claims" as a particularly difficult issue.

For currency, The Maldives, with a relatively small population and tiny GDP has their own currency. What is the difficulty in currency? Ignoring the fact that AB would probably just use the greenback.

All of these of these issues are surmountable.


By glossing over all the details as “surmountable” you are illustrating how easy it is to ignore critical complexity. Debt includes concepts like “what does independent Alberta actually own or have to go into debt to purchase if major assets within its borders are literally Canadian federal property or connected to existing treaty rights?” This answer makes or breaks the entire proposal and does not have an easy or obvious solution.


Surmountable - "possible to deal with or solve successfully".

Does not mean "easy". It means they can be overcome.


I'll give you that currency isn't a huge issue. From what I recall, Quebec wanted to continue using the Canadian dollar if they separated.

If they opted to go with the USD, they'd have to trade all their CAD - which will undoubtedly take a huge hit if they separated.

I still think that separatists would say that Alberta doesn't have to deal with a share of the debt and that would be a sticking point.


Incorrect. If you've ever been through Alberta you'd already know that though.

Oil & gas fields, and wells, are distributed over much of Alberta.

https://static.aer.ca/prd/documents/catalog/Map90_Oil_Gas_Fi...


i did a bit of playing with aer data back in december, and was super surprised just how distributed the wells are.

without doubt there is a main concentration around Lloydminister though, and the developed oil sands at least are all in one place


I meant that the oil fields themselves could just as well declare that they wanted out of Alberta after Alberta splits. Splitting goes all the way down.


This is kind of ridiculous. The fields are geographical areas, not political or cultural entities, and most of the pople living within a certain field don't have the slightest idea what or if any field they live in.


And yet, somehow the people of Alberta suddenly are aware aren't they? Even though they previously were just "Canadians"? Why would the people now living close to all the money but getting bad representation in Edmonton be happier than if they got bad representation in Ottowa? Splitting goes all the way down.


When the AI scrapers were just getting started, that is basically what I thought - their plan was to scrape / suck up everything they possibly could before people realized what was happening and blocked them.

The rate at which they were spidering and scraping was so far beyond what any other supposedly legit spider was doing, it seemed like the logical explanation.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: