Print 28 comment(s) - last by Piiman.. on May 4 at 11:32 AM

Exploiting iPad flaw proves costly for researcher, despite relatively responsible disclosure process

Nearly four years behind bars; that's the fate a New York security "researcher" faces after being found guilty by a jury of his peers and sentenced by a federal judge on cybercrime charges involving his 2010 exploitation of a flaw in the security of iPad service provider AT&T. He allegedly used the flaw to expose the email address of over 100,000 individuals.

I. A Leaky Hole

The story began in June 2010.  Apple, Inc. (AAPL) had just released the first generation iPad, a tablet computer that transformed the form factor from overlooked to in vogue.  And the service provider du jour for iPads with 3G data connectivity was AT&T, Inc. (T).  

But AT&T's iPad support services had a relatively minor, but notable security flaw.  AT&T's iPad-related servers ran a script that accepted an ICC-ID (integrated circuit card identifiers), an identifier unique to each device.  

If sent a valid ICC-ID, the script served up the personal email of the subscriber associated with that device.  AT&T had planned to use the feature to generate a slick AJAX-style response on its web applications for the iPad.

iPad hole
AT&T left a gaping hole in their iPad web scripts. [Image Source: DailyTech/Jason Mick]

But Andrew Auernheimer, Daniel Spitler, and other hackers with the profanely named "troll" hacker collective Goatse Security identified the vulnerability when they were probing AT&T's servers.  They quickly wrote a so-called "data slurper" -- a script that performed a brute force attack, working through tables of ICC-IDs and recording the ones that received a response.

AT&T apologized for the breach and took down the script, closing its hole.

II. Investigation, Trial Conclude in Guilty Verdict

But the damage was already done.  Goatse Sec. had published its results to the blog site Gawker, revealing parts of a data set that contained roughly 114,000 email addresses.  Among the high-profile figures exposed were ABC News anchor Diane Sawyer, New York City Mayor Michael Bloomberg, and current Chicago Mayor Rahm Emanuel.

Soon after the data loss, U.S. Federal Bureau of Investigation agents investigating the incident conducted a raid on the home Mr. Auernheimer who had moved from New York to a residence in Arkansas.  Mr. Auernheimer, aka "weev" or "Escher Auernheimer" was arrested by federal agents on suspicion of computer crimes.  Authorities also allegedly found cocaine, LSD, and ecstasy in his residence.  Lawyers for Mr. Auernheimer contend that the raid was unnecessary and illegal.  The security "researcher" has yet to face charges on the drugs found.

However, he was charged with one count of conspiracy to access servers without permission and one count of identity theft.  These offenses -- spelled out in the Computer Fraud and Abuse Act of 1986 (18 USC § 1030) -- carry a maximum sentence of five years in prison and a fine of up to $250,000 USD.

Andrew Auernheimer
Goatse Security "researcher" Andrew Auernheimer was found guilty of two counts of computer crimes and may be sentenced to up to five years in prison, pending appeal. [Image Source: AP]

Mr. Auernheimer was charged in U.S. District Court for the District of New Jersey, the location where his co-defendant (Daniel Spitler) was charged.  Initially, federal authorities had planned to charge the two members separately, which would have resulted in a trial of Mr. Auernheimer in an Arkansas District Court.  However, the case was eventually shuffled to the New Jersey District Court.

In June 2011, Mr. Spitler, aka "JacksonBrown" pled guilty to the two cybercrimes counts, in hopes of receiving a lighter sentence.  He is currently awaiting sentencing.

Mr. Auernheimer fought the charges, and but the triakl with the jury finding Mr. Auernheimer guilty of both counts, despite the fact that Mr. Auernheimer only accessed a gaping open system.

III. Auernheimer to Cyber-Dissidents: Rise Up

Four months after that guilty verdict Mr. Auernheimer seems more at peace with his coming time behind bars.  He participated in a mostly lighthearted 
Reddit AmA ("Ask Me Anything") on Sunday before the sentencing.  

Ironically, prosecutors tried to turn Mr. Auernheier's upbeat and sarcastic Reddit comments against him at the sentencing hearing the next day.  They pushed for 4 years -- nearly the maximum sentence.  The judge instead sentenced him to a slightly shorter 41 months sentence, to be followed by 3 years of supervised release, during which time his electronic behavior will be monitored.

The accused read John Keats' The Fall of Hyperion and told reporters at a press conference, "I'm going to jail for doing arithmetic."

Andrew Auernheimer
Andrew Auernheimer will soon be headed to a nearly four year stay in prison.
[Image Source: The Verge]

The statement comes just months after his proclamation that he hoped he would get the maximum 5 year sentence to encourage Anonymous and other cyber-rebels to "rise up and storm the decks."

He and his co-defendant Mr. Spitler will have to pay $73,000 USD in restitution if the verdict sticks.  Mr. Auernehimer is currently appealing the sentence.  His attorney, Tor Ekeland told The Verge in an interview that courts are divided on what exactly constitutes "unauthorized access" in the CFAA, pointing to a possible route for the appeal.

Source: The Verge

Comments     Threshold

This article is over a month old, voting and posting comments is disabled

RE: Poor Guy Gettin Screwd IMO
By xti on 3/20/2013 5:29:32 PM , Rating: 0
youre the moron that cant see that suicide is a cowards way out.

Swartz took his own life because the alternatives are intolerable

this screams 'woe is me' and emo crap of todays youth - suicide is someones own damn fault because you arent strong enough to live up to your choices.

ALL of this avoided if he didnt post stuff he wasnt supposed to. 'tard.

RE: Poor Guy Gettin Screwd IMO
By ritualm on 3/21/2013 12:28:34 AM , Rating: 4
youre the moron that cant see that suicide is a cowards way out.

That's your comeback?

How about this one: the government has bottomless pockets and practically unlimited time to muck up your life, long after everything is decided - just because it can.

Next: explain to me how this is borderline fair. A big time financial executive gets 6 months at a country club-style minimum security prison for actions that caused the foreclosure of thousands of homes and enriched himself at everyone else's expense. Swartz could've ended up with as much as 35 years total for a comparatively harmless intrusion.
this screams 'woe is me' and emo crap of todays youth - suicide is someones own damn fault because you arent strong enough to live up to your choices.

ALL of this avoided if he didnt post stuff he wasnt supposed to. 'tard.

Right... because the following never happened:
While Swartz had indeed compromised MIT's network and the JSTOR database, the Middlesex County district court decided that he wouldn't face jail time for his actions. The matter would have been closed and Swartz would have been "off the hook" so to speak, but United States Attorney Carmen M. Ortiz took up the case and things decidedly took a turn for the worse.

Ortiz decided to hit Swartz with 13 felony charges that could have sent him to jail for up to 35 years. Swartz would also be on the hook for a $1 million fine for his actions. In a 2011 press release, Ortiz declared that, "Stealing is stealing whether you use a computer command or a crowbar, and whether you take documents, data or dollars. It is equally harmful to the victim whether you sell what you have stolen or give it away.”

With the U.S. Government breathing down his neck and with no outlet and no amicable resolution in sight to "humanely" resolve his legal woes, Swartz took his own life on January 11, 2013.

After Swartz committed suicide, Ortiz acknowledged that, “There was no evidence against Mr. Swartz indicating that he committed his acts for personal gain” and that his conduct “did not warrant the severe punishments authorized by Congress.”

Who the hell thinks it's right to resurrect a done deal and say, "no, this is wrong, we're going to screw you until we win!"? Swartz wasn't a coward, that title belongs to the government.

xti, you're not just retarded, you're delusional.

RE: Poor Guy Gettin Screwd IMO
By xti on 3/23/13, Rating: 0
RE: Poor Guy Gettin Screwd IMO
By ritualm on 3/21/2013 12:40:30 AM , Rating: 2
Or how about something even simpler.

A corporation "inadvertently" puts supposedly private data online, free for anyone to steal and pilfer. All it gets is a slap in the wrist, several million dollars in fines tops, and a promise to not repeat the same mistake in the future (by the way, a promise that is never kept).

An individual exposing security vulnerabilities in a system used by thousands of customers gets multiple years behind bars, their lives completely ruined by the government and corporation together.

Care to explain how he shouldn't have done what he did?

Oh but this guy drives the point home even better than you do.

xti, you're not just retarded, you're delusional.

RE: Poor Guy Gettin Screwd IMO
By xti on 3/23/2013 11:18:06 PM , Rating: 1
suicide is cowardly. link whatever you want. then ask families of those that take their lives if it solved anything.

he knew what he was doing going online doing something he wasnt supposed to. tough shit.

RE: Poor Guy Gettin Screwd IMO
By InsGadget on 3/24/2013 12:36:06 PM , Rating: 2
Agree with your contentions, ritualm, but please find another word to use besides "retard".

"There is a single light of science, and to brighten it anywhere is to brighten it everywhere." -- Isaac Asimov

Copyright 2016 DailyTech LLC. - RSS Feed | Advertise | About Us | Ethics | FAQ | Terms, Conditions & Privacy Information | Kristopher Kubicki