Goatse Security iPad Hacker Gets 41 Months for "Doing Arithmetic"
March 18, 2013 11:06 PM
comment(s) - last by
Exploiting iPad flaw proves costly for researcher, despite relatively responsible disclosure process
Nearly four years behind bars; that's the fate a New York security "researcher" faces after being
by a jury of his peers and sentenced by a federal judge on cybercrime charges involving his 2010 exploitation of a flaw in the security of iPad service provider AT&T. He allegedly used the flaw to
expose the email address of over 100,000 individuals
I. A Leaky Hole
The story began in June 2010. Apple, Inc. (
) had just released
the first generation iPad
, a tablet computer that transformed the form factor from overlooked to
. And the service provider du jour for iPads with 3G data connectivity was AT&T, Inc. (
But AT&T's iPad support services had a relatively minor, but notable security flaw. AT&T's iPad-related servers ran a script that accepted an ICC-ID (
integrated circuit card identifiers
), an identifier unique to each device.
If sent a valid ICC-ID, the script served up the personal email of the subscriber associated with that device. AT&T had planned to use the feature to generate a slick AJAX-style response on its web applications for the iPad.
AT&T left a gaping hole in their iPad web scripts. [Image Source: DailyTech/Jason Mick]
But Andrew Auernheimer, Daniel Spitler, and other hackers with the profanely named "troll" hacker collective Goatse Security identified the vulnerability when they were probing AT&T's servers. They quickly wrote a so-called "data slurper" -- a script that performed a brute force attack, working through tables of ICC-IDs and recording the ones that received a response.
apologized for the breach
and took down the script, closing its hole.
II. Investigation, Trial Conclude in Guilty Verdict
But the damage was already done. Goatse Sec. had published its results to the blog site
, revealing parts of a data set that contained roughly
114,000 email addresses
. Among the high-profile figures exposed were ABC News anchor Diane Sawyer, New York City Mayor Michael Bloomberg, and current Chicago Mayor Rahm Emanuel.
Soon after the data loss,
U.S. Federal Bureau of Investigation
agents investigating the incident conducted a raid on the home Mr. Auernheimer who had moved from New York to a residence in Arkansas. Mr. Auernheimer, aka "weev" or "Escher Auernheimer" was arrested by federal agents on suspicion of computer crimes. Authorities also allegedly found
cocaine, LSD, and ecstasy
in his residence. Lawyers for Mr. Auernheimer contend that the raid was unnecessary and illegal. The security "researcher" has yet to face charges on the drugs found.
with one count of conspiracy to access servers without permission and one count of identity theft. These offenses -- spelled out in the Computer Fraud and Abuse Act of 1986 (
18 USC § 1030
) -- carry a maximum sentence of five years in prison and a fine of up to $250,000 USD.
Goatse Security "researcher" Andrew Auernheimer was found guilty of two counts of computer crimes and may be sentenced to up to five years in prison, pending appeal. [Image Source: AP]
Mr. Auernheimer was charged in
U.S. District Court for the District of New Jersey
, the location where his co-defendant (Daniel Spitler) was charged. Initially, federal authorities had planned to charge the two members separately, which would have resulted in a trial of Mr. Auernheimer in an Arkansas District Court. However, the case was eventually shuffled to the New Jersey District Court.
In June 2011, Mr. Spitler, aka "JacksonBrown"
to the two cybercrimes counts, in hopes of receiving a lighter sentence. He is currently awaiting sentencing.
Mr. Auernheimer fought the charges, and but the triakl with the jury finding Mr. Auernheimer guilty of both counts, despite the fact that Mr. Auernheimer only accessed a gaping open system.
III. Auernheimer to Cyber-Dissidents: Rise Up
Four months after that guilty verdict Mr. Auernheimer seems more at peace with his coming time behind bars. He participated in a mostly lighthearted
("Ask Me Anything") on Sunday before the sentencing.
Ironically, prosecutors tried to turn Mr. Auernheier's upbeat and sarcastic Reddit comments against him at the sentencing hearing the next day. They pushed for 4 years -- nearly the maximum sentence. The judge instead sentenced him to a slightly shorter 41 months sentence, to be followed by 3 years of supervised release, during which time his electronic behavior will be monitored.
The accused read John Keats'
The Fall of Hyperion
and told reporters at a press conference, "I'm going to jail for doing arithmetic."
Andrew Auernheimer will soon be headed to a nearly four year stay in prison.
[Image Source: The Verge]
The statement comes just months after his proclamation that he hoped he would get the maximum 5 year sentence to encourage
and other cyber-rebels to "rise up and storm the decks."
He and his co-defendant Mr. Spitler will have to pay $73,000 USD in restitution if the verdict sticks. Mr. Auernehimer is currently appealing the sentence. His attorney, Tor Ekeland told
in an interview that courts are divided on what exactly constitutes "unauthorized access" in the CFAA, pointing to a possible route for the appeal.
This article is over a month old, voting and posting comments is disabled
You'll all find out, every single one of you.
3/20/2013 9:21:43 PM
In 2009, while working as a contract pharmacist in a rural healthcare facility, I got a call from the PA on shift. The PA explained that one of the EMT's was at the clinic with his dog ($3000 bird dog, 2 years old). The dog had ingested a large quantity of rat poison, the antidote for which is Vitamin K. The nearest vet was 60 miles away, the EMT was on call (wasn't even supposed to be at the clinic, but we were only a block or so from the EMT quarters). The dog wasn't going to survive the trip anyway. The PA asked if we had any injectable Vit K on hand, and if so, if I'd see fit to dispense the medication to the EMT that he might save his friend. I said yes, and thereby became a federal felon.
For dispensing $143 worth of medication (which amount I tried to reimburse the clinic the following day, and was rebuked), we lost everything. Our house, vehicles, my ability to ever earn a living in my chosen profession (although I still retain my professional license in good standing, I am banned from working for any entity that bills a federally funded program; e.g. Medicare/Medicaid, i.e. all entities). The OIG rousted me out of Wanblee, SD a week after I buried my father. Armed Federal agents arrested me at gun point after threatening me and my wife, the week after we buried my father-in-law. They could have made a phone call; instead they sent armed marshals to point loaded weapons at us whilst screaming obscenities.
I copped a plea and received 3 years probation. Had I gone to trial, I would've lost and served 2 years in a Federal penitentiary.
For $443 (the final determination of restitution), the Federal government was willing to spend upward of $100,000 over a three year period, all to keep a "dangerous felon" off the streets. This does not include $150,000 in Federally insured student loans I will never be able to repay, or the hundreds of thousands of dollars of lost tax revenue over the span of my career.
I currently work day labor for minimum wage. With a Federal larceny conviction, I can't get a job mowing lawns.
Tommy Chong served 18 months in prison for allowing his likeness to be displayed on a brand of marijuana paraphernalia. When he got out, he said "People come up to me and ask "Whoa, man, prison; what was that like?" I tell them "You'll find out. Every single one of you is going to find out." God help us, he is right.
The Federal prosecutorial system is completely off the rails. Their decision to indict and prosecute a case is based entirely on what that prosecution will do for the AUSA in charge. Whether you are low hanging fruit, like me, or a high ticket item, like Schwartz, all "civilians" are viewed as an expediency to a higher pay grade, and another notch on the prosecutor's gun. The cost to the individual, and to society as a whole, doesn't even enter the equation.
It is time for the American people to wake up. The longer we wait, the more difficult that awakening becomes.
Bye the bye, the dog survived. Every time the EMT came into the clinic, he made a point of thanking me, and shaking my hand. It was never about the dog, kids. It was about not letting a young man watch his friend die a horrible death, when I could do something to prevent that. For what this has cost me, cost my family, not acting would've cost me so much more. My soul, my humanity and my free will.
RE: You'll all find out, every single one of you.
5/4/2013 11:32:15 AM
You should have taken this to every media outlet you could find.
Since the only reason they go after people without deep pockets in the first place is to pretend they are doing their jobs the only way to get this jerks to back down is to make them look bad.
"A politician stumbles over himself... Then they pick it out. They edit it. He runs the clip, and then he makes a funny face, and the whole audience has a Pavlovian response." -- Joe Scarborough on John Stewart over Jim Cramer
Second Hacker in AT&T/iPad Case Seeks Plea Deal
July 29, 2011, 12:16 AM
Apple, AT&T Convince FBI to Charge Goatse Security
January 18, 2011, 10:31 AM
Goatse Security Researcher Arrested After FBI Raid Reveals Blow, X
June 16, 2010, 8:34 AM
AT&T Apologizes to iPad Customers, We Reveal Hackers' Locales
June 14, 2010, 9:37 AM
AT&T's Gaping Hole Exposes 114,000 iPad 3G Buyers' Email Addresses
June 9, 2010, 5:55 PM
Retiree Sues Apple For $7,500 for Wiping Honeymoon Photos From His iPhone
November 30, 2015, 10:23 AM
iPhone 7 May Pack 3-4 GB Memory, More Storage; 4-Inch Comeback is Rumored
November 20, 2015, 10:12 PM
OnePlus One, OnePlus 2 Will Receive Android Marshmallow in Q1 2016
November 16, 2015, 9:58 AM
Lenovo Whoa: Motorola Droid MAXX 2 and Turbo 2 Break Cover in Leaks
October 26, 2015, 3:12 PM
Leak: Apple Preps for First Real Android App Foray With New Apple Music App
October 24, 2015, 1:59 PM
Pepsi Smartphone? Empty Calories Coming Soon to the Midrange
October 12, 2015, 11:41 PM
Latest Blog Posts
Sceptre Airs 27", 120 Hz. 1080p Monitor/HDTV w/ 5 ms Response Time for $220
Dec 3, 2014, 10:32 PM
Costco Gives Employees Thanksgiving Off; Wal-Mart Leads "Black Thursday" Charge
Oct 29, 2014, 9:57 PM
"Bear Selfies" Fad Could Turn Deadly, Warn Nevada Wildlife Officials
Oct 28, 2014, 12:00 PM
The Surface Mini That Was Never Released Gets "Hands On" Treatment
Sep 26, 2014, 8:22 AM
ISIS Imposes Ban on Teaching Evolution in Iraq
Sep 17, 2014, 5:22 PM
More Blog Posts
Copyright 2016 DailyTech LLC. -
Terms, Conditions & Privacy Information