Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Defence lawyers said although the hack attacks were carried out using a computer owned by Mr Warg, he was not the person that used it to steal the files. Instead, they said, an unnamed hacker took over this machine and used it to carry out the attacks.

Given the circumstances, this claim seems obviously true. People who break into computers usually use broken-into computers as proxies.



Are you familiar with the evidence the court considered? Is it instead the case that you'd have a hard time convicting anyone of hacking-related crimes under any circumstances because of the possibility that someone else might have been pulling the strings?

Often when cases like this are reported, the evidentiary details don't make it into the story. It's easy to understand why someone would have a problem with a conviction when all the information they have is the BBC's 10,000ft summary.

What's worse is, that 10,000ft summary can bias you by framing the whole story in your mind. You're skeptical right off the bat. That's probably always healthy! But it's good to know how your mind is being primed to digest new information, too.

Obviously, sometimes you get the details and the case doesn't get less murky. The Aurenheimer case is an example; I don't have a clue what to think about it, and would like to think that whatever my prejudices are, I'd have been a not-guilty vote in a jury based on that doubt.


I've taken a look at the evidence, but the primary sources are in a foreign language so there's certainly a possibility I've missed something major.

There are kinds of evidence that I would find convincing. Testimony from police that he had certain things open on the screen at the moment of arrest (as in the Silk Road case). Or hidden-camera video of him at a terminal, doing something bad. Or an audio recording of a voice call in which he tries to do social engineering.

I haven't found anything like that. If someone posts a link, I'll certainly change my mind. But for know, all the evidence I know of is of a sort that one person could've forged.


> Is it instead the case that you'd have a hard time convicting anyone of hacking-related crimes under any circumstances because of the possibility that someone else might have been pulling the strings?

That is kind of a serious problem. It's like the "open WiFi" defense. It's completely plausible that someone else actually used your WiFi or compromised your computer, but at the same time some people have this visceral reaction to allowing it as a defense because it's so hard to disprove and can be used by anyone.


This comment should somehow be auto-posted into every HN thread about popular news accounts of criminal computer use. Maybe added to the HN guidelines. Or both.


Is it enough to be skeptical about the trial to know that prosecutors installed software on the piece of evidence without informing anyone?


You don't need an excuse to be skeptical. Skepticism is healthy.


> People who break into computers usually use broken-into computers as proxies.

That's possibly [1] true, but aren't those broken-into computers almost always the computers of ordinary users? How often do the people breaking into computers use broken-into computers belonging to a computer security expert who knows how to protect their systems from such break-ins?

[1] Not sure about the "usually" part.


How often do the people breaking into computers use broken-into computers belonging to a computer security expert who knows how to protect their systems from such break-ins?

I know it's counterintuitive, but all the time. Until only a few years ago, it was almost as if every security expert was being publicly owned constantly. Hackers hack each other.

The dirty secret that explains why they would hack those who can protect their systems: nobody knows how to protect their systems. The best firewall is not pissing off hackers.


In the 20+ year history of computer crime prosecution, outside of this disputed case, what is the next most likely case where a hacker effectively framed another hacker who was then successfully prosecuted for the offense?


Shimomura and Mitnick.... ... ......


Shimomura was successfully prosecuted?


He's being facetious.


I would hope so.


Other way around. I have heard people seriously claim that Shimomura framed Mitnick, though I won't speak to how likely that is.


A pretty hard claim for him to make himself at this point:

https://www.mitnicksecurity.com/about/kevin-mitnick-worlds-m...


You only asked for next most likely, not likely. :)


Anakata was too smart to go after users' computers. He was more of a Kerberos server fellow. Good guy.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: