iPad Exploiter is Freed by Federal Appeals Court
April 11, 2014 7:40 PM
Andrew Auernheimer gets off, but the CFAA remains as ambiguous as ever
He might be an admitted troll, but Andrew "weev" Auernheimer (aka "Escher" Auernheimer) scored some sympathy when he was sentenced to 41 months (nearly four years) in prison. Now thanks to the
Third U.S. Circuit Court of Appeals
Mr. Auernheimer is a free man early in
[PDF] that some feel dodges, rather than answers fundamental questions regarding internet freedoms.
I. Closing AT&T's Open Hole
Mr. Auernheimer spent his days trolling
, and other popular online hubs. And like many, he dabbled in computer security research. While laymen might refer to what he was engaging in as "hacking" true hackers would scoff at that as he generally only poked and prodded around in systems with no access protections.
Such exploration might have gone unnoticed had he not targeted two of America's biggest and most powerful corporations Apple, Inc. (
) and AT&T, Inc. (
Back in 2010 Apple had just launched
its first generation tablet, dubbed the "iPad"
. AT&T -- Apple's long time iPhone partner -- had exclusive rights to the cellular version of the device. Every iPad has a unique identifier number -- the ICC-ID -- which is one of several pieces of information Apple uses to control remote access to customers emails.
Mr. Auernheimer, along with his friend Daniel Spitler and other online miscreants, had just founded "troll"/hacker collective Goatse Security. It is unclear which of them first figured it out, but one of the group members -- possible Mr. Auernheimer himself -- noticed Apple's iPads were sending users' ICC-ID (unencrypted) to an AT&T server, which returned the email of the customer associated with that packet.
To AT&T and Apple, this was a "feature" allowing developers quick access to user emails. But Mr. Auernheimer and the rest of Goatse Sec. correctly realized that it was a
gaping hole in the device's security
, given how easy it was to simply brute force your way into that back door, gaining everyone's emails by guessing ICC-IDs until you got valid ones.
Mr. Auernheimer faced legal reprecussions merely for accessing an open interface on the internet.
[Image Source: Boot Click]
He wrote a script that did this and it worked flawlessly, penetrating the databanks of AT&T's bare, unprotected server. Most troubling was the fact that AT&T's server was not only open to anyone who wished to ping it, but it also apparently had no restrictions on how many requests could come from specific IPs, even. Soon Goatse Sec. had the emails of most iPad 3G customers. They went to Gawker Media, who published a piece.
To validate that Goatse Sec.'s claims were accurate they weeded through the list pulling out the emails of certain high profile people including actors, members of the military, and politicians. The White House chief of staff was even on the list.
The approach worked -- Apple and AT&T owned up to the problem and finally agreed to close their security holes.
Mr. Auernheimer's home was raided in 2010, in apparent retribution for the disclosure.
[Image Source: The Washington County's Sheriff Office]
The U.S. Federal Bureau of Investigation
(FBI) began to harass Mr. Auernheimer shortly thereafter, raiding his house and arresting him when they found drugs (including a small quantity of
cocaine, LSD, and the party drug ecstasy
). Authorities also found schedule 2 and 3 pharmaceuticals.
But the raid wasn't as clean cut as it sounded at first. First, the cops were unable to explain what compelled them to conduct the search, so basically their only probable cause was that Mr. Auernheimer had caused trouble and that they didn't like him. Second, Mr. Auernheimer had roommates and it became increasingly apparent that while some -- or all -- of the drugs may have belonged to those folks, the FBI was looking to pin everything on the one resident of the household who had caused trouble by leaking the email of federal politicians.
The FBI had also reportedly denied him a public defender, subjecting him to a gag order about that violation, which Mr. Auernheimer defiantly broke.
II. Imprisoned for "Doing Arithmetic"
In Jan. 2011 the weak case was on the verge of collapse, so the FBI decided to drop charges against Mr. Auernheimer. But the
U.S. Department of Justice
(DOJ) was determined to not let his disclosure go unpunished, so they
with one count of conspiracy to access servers without permission and one count of identity theft. The DOJ justified these charges via passages in the ambiguously worded Computer Fraud and Abuse Act (CFAA) of 1986 (
18 USC § 1030
the same law
used to terrorize and harass Reddit cofounder Aaron Swartz
would later tragically take his own life
Mr. Auernheimer was brought back to jail after being booked on these charges in January, along with his colleague Mr. Spitler. Mr. Spitler, who had an IT job, quickly bailed himself out, but Mr. Auernheimer was imprisoned for an extra month as he was unemployed.
Mr. Auernheimer lived in Arkansas and conducted the server scrape there, so his attorneys (hired by an internet fundraising campaign) argued that the case should be tried there. Attorneys instead chose to try it in New Jersey, a state known for higher conviction rates. They made the tenuous argument that many of the affected iPad users lived in that state -- an argument that could be made for virtually any jurisdiction.
The feds won, the trial was taken to New Jersey. And they won again when the verdict was read. In Nov. 2012 he was found guilty of both charges, prompting him to write an article in
sarcastically titled "
Forget Disclosure - Hackers Should Keep Security Holes to Themselves
Andrew Auernheimer faced nearly four years in prison after sentencing. [Image Source: The Verge]
The surprisingly mature account made a compelling case for disclosure of security flaws. He pointed out that Apple had a long history of ignoring warnings from security researchers and typically only fixed flaws after they were disclosed.
Nonetheless, a federal judge in the New Jersey District Court was unmoved by his arguments and sentenced to 41 months in prison.
Mr. Auernheimer appealed. His lawyers -- financed by the Electronic Frontier Foundation (EFF) -- appealed that decision to the third circuit.
III. EFF, Auernheimer Win, But Fail to Beat Back CFAA
The EFF team argued that Mr. Auernheimer wasn't gaining unauthorized access or "hacking" as any member of the public could access the server as he did, and AT&T's partners would regularly do so. They also argued that Mr. Auernheimer should have been tried in Arkansas and the DOJ had no business hauling him to New Jersey. The DOJ argued that the choice of venue "[did] not affect substantial rights." The EFF suggested otherwise.
The verdict of a three-judge panel came in this week, resoundingly in Mr. Auernheimer's favor. The judges wrote in their ruling "no evidence was advanced at trial [that] any password gate or other code-based barrier [was breached]", a statement that seemed to suggest that Mr. Auernheimer's lawyers fundamental argument might be right.
However, the panel made the rather odd decision of not issuing a full ruling on that argument. Instead, they sidestepped the issue somewhat; deciding the DOJ's choice of venue was inappropriate enough to vacate the verdict.
The court writes:
Although this appeal raises a number of complex and novel issues that are of great public importance in our increasingly interconnected age, we find it necessary to reach only one that has been fundamental since our country’s founding: venue... The proper place of colonial trials was so important to the founding generation that it was listed as a grievance in the Declaration of Independence.
Venue issues are animated in part by the danger of allowing the Government to choose its forum free from any external constraints. The ever-increasing ubiquity of the Internet only amplifies this concern. As we progress technologically, we must remain mindful that cybercrimes do not happen in some metaphysical location that justifies disregarding constitutional limits on venue. People and computers still exist in identifiable places in the physical world. When people commit crimes, we have the ability and obligation to ensure that they do not stand to account for those crimes in forums in which they performed no essential conduct element of the crimes charged.
“Though our nation has changed in ways which it is difficult to imagine that the Framers of the Constitution could have foreseen, the rights of criminal defendants which they sought to protect in the venue provisions of the Constitution are neither outdated nor outmoded.” Passodelis, 615 F.2d at 977. Just as this was true when we decided Passodelis in 1980 — after the advent of railroad, express mail, the telegraph, the telephone, the automobile, air travel, and satellite communications — it remains true in today’s Internet age. For the forgoing reasons, we will reverse the District Court’s venue determination and vacate Auernheimer’s conviction.
Auernheimer was hauled over a thousand miles from Fayetteville, Arkansas to New Jersey. Certainly if he had directed his criminal activity toward New Jersey to the extent that either he or his co-conspirator committed an act in furtherance of their conspiracy there, or performed one of the essential conduct elements of the charged offenses there, he would have no grounds to complain about his uprooting. But that was not what was alleged or what happened. While we are not prepared today to hold that an error of venue never could be harmless, we do not need to because the improper venue here—far from where he performed any of his allegedly criminal acts—denied Auernheimer's substantial right to be tried in the place where his alleged crime was committed.
Some may be disappointed at this outcome, but the end result is at least one internet activists will be pleased with -- Mr. Auernheimer's freedom.
Andrew Auernheimer is now a free man. [Image Source: Stephanie Keith]
It appears that Mr. Auernheimer is a free man, as unlike in the case of a mistrial, such an order to vacate a federal judgment typically eliminates the verdict altogether. To try Mr. Auernheimer again would arguably be consider double jeopardy, a fundamentally unconstitutional legal act.
Mr. Auernheimer's top lawyer -- Orin Kerr --
wrote an article
The Washington Post
about the verdict and its importance.
We'll have to wait for more federal trials and appeals -- or Congressional action -- to get closure on the CFAA and how to make its ambiguous language less of a ticket to arbitrary, and at times punitive, imprisonment.
Third US Circuit Court of Appeals
The Washington Post
"It looks like the iPhone 4 might be their Vista, and I'm okay with that." -- Microsoft COO Kevin Turner
Bill to Reform Computer Fraud and Abuse Act Proposed in Aaron Swartz's Name
June 24, 2013, 5:08 AM
House Committee Questions Aaron Swartz Charges in Letter to DOJ
January 29, 2013, 5:08 PM
Anonymous Declares War on the U.S. Government Following Aaron Swartz' Suicide
January 26, 2013, 1:43 PM
Apple, AT&T Convince FBI to Charge Goatse Security
January 18, 2011, 10:31 AM
Goatse Security Researcher Arrested After FBI Raid Reveals Blow, X
June 16, 2010, 8:34 AM
Are You in the Market for Earphones?
March 24, 2017, 7:35 AM
Samsung Galaxy S8, Rumored Launch Date!
March 18, 2017, 6:45 AM
How about Leica Cameras
March 13, 2017, 6:30 AM
Nokia has ditched this camera technology in its new smartphones
March 7, 2017, 8:45 AM
A Baseball Cap With Camera
March 3, 2017, 7:00 AM
Nokia 3310 with longer battery life
February 28, 2017, 7:05 AM
Most Popular Articles
Samsung Galaxy S8, Rumored Launch Date!
March 18, 2017, 6:45 AM
Gigabyte GA-Z170X-Gaming G1 – Intel Thunderbolt 3 Certified Motherboard
March 9, 2017, 6:25 AM
Lenovo ThinkPad T460 - Ultra-Thin and Feather-light
March 3, 2017, 6:00 AM
Huawei P8 Lite 2017 – Android 7 Nougat Smartphone with Octa-Core Processor
March 8, 2017, 7:03 AM
Intel Optane SSd DC P4800X – Super Fast 3D Storage
March 20, 2017, 7:35 AM
Latest Blog Posts
Are you thinking of performance and speed? Intel claims:
Mar 25, 2017, 7:45 AM
Apple buys an automation app called Workflow. The deal was completed today and brings the app along with its developers.
Mar 23, 2017, 7:35 AM
Apple Announces new color for iPhones and iPads
Mar 22, 2017, 7:45 AM
Instagram: You Can Now Save Live Videos For Later
Mar 21, 2017, 7:49 AM
Samsung Galaxy S8 to Get New Color Scheme
Mar 20, 2017, 7:45 AM
What else to worry about?
Mar 17, 2017, 6:45 AM
Icon of the Day: Intel/ NVIDIA or Mobileye
Mar 16, 2017, 6:15 AM
JUST IN - Twitter Hijacked : High-Profile Account Accesses
Mar 15, 2017, 7:07 AM
Mar 14, 2017, 7:30 AM
News and Tips
Mar 13, 2017, 6:30 AM
iPhone 8 – May Not Get Curved Screen
Mar 11, 2017, 8:00 AM
California paves way to self-driving car tests without humans
Mar 11, 2017, 7:18 AM
Smart Machines V hackers
Mar 10, 2017, 7:00 AM
Uber Can Resume Autonomous Car Testing in California
Mar 9, 2017, 6:50 AM
Mar 8, 2017, 7:09 AM
Mar 7, 2017, 8:45 AM
World news 3-6
Mar 6, 2017, 5:40 AM
Mar 4, 2017, 7:40 AM
Mixed News of the Day
Mar 4, 2017, 6:32 AM
Jaguar Land Rover invests in ride-sharing
Mar 3, 2017, 7:00 AM
Mixed News of The World:
Mar 2, 2017, 7:02 AM
World New 3-1
Mar 1, 2017, 6:30 AM
More Blog Posts
Copyright 2017 DailyTech LLC. -
Terms, Conditions & Privacy Information