HN user

mylorse

19 karma
Posts0
Comments24
View on HN
No posts found.

If you visit and internet cafe and someone's forgotten to log out of their bank account and you fiddle with it, that's probably a crime.

That can be construed as impersonation without unauthorized access, which is in some jurisdictions is illegal.

But that is not what AT&T did, which is more like a open brothel with conference rooms and private bedrooms. They just let in anyone that looked in one type of attire, and had some numbered badge come into one of the reserved conference rooms. IoW, the security person did not ask for ID, or a password to enter. The fault lies on the brothel, not the visitor. For all we know, anyone could have come in looking with that attire, and a matching badge out of coincidence (maybe there was a costume party, who knows, still the brothel did not do a good job of securing the reserved conference rooms).

No password, no HTTPS, no access controls at all. Who is responsible for the security breach? You or the bank?

The bank, they are not complying with the legal statues, and more than likely violating their own privacy policy, if any exist.

I would argue that if there are no technological access controls in place, there is no such thing as "unauthorized access" You can't be unauthorized if there is no authorization. The default on the internet is "can access"

That is correct. In that analogy, it would be an open business, like store or malls. It follows jurisdictions of private properties, with some business statues, but overall, since it is an open-doors business, there are no authorization requirements.

They're prosecuting him for the digital equivalent of walking down a street and taking pictures of houses which don't display numbers on their mailbox.

No. Like in the example above, they are charging him of wearing an attire with a numbered badge, and coming into the reserved conference room, and learning the attendants names or addresses (which should not be there in the first place, esp. with no security protocols). The worst they can charge him is for impersonation. However, what can incriminate him is if the pages he visited clearly displayed or linked the Term of Services or EULA, which does detail this scenario, and he violated it in some way.

Thanks for the references.

I also noticed OP's article is nearly 3 years old, which says something. Time for open hardware schematics!

Mmmm, while it sounds interesting, I am surprised at several things they have not implemented:

1 CDN or mirror service to lessen the load. There are free ones:

https://en.wikipedia.org/wiki/Content_delivery_network#Notab...

2. P2P software for distributing content across a mesh network between the multiple servers (e.g. Gnunet & Freenet). Distributed Filesystems also work:

https://en.wikipedia.org/wiki/Comparison_of_distributed_file...

3. Other communication than Jabber. Proper recommended secure channels are SILC, OTR, and now Beta secushare:

https://en.wikipedia.org/wiki/SILC_%28protocol%29

https://en.wikipedia.org/wiki/Off-the-record_messaging

http://secushare.org/

The VPN is nice although. I wish STOMP was used more instead of PYSC. I still love IRC. It would also be awesome if they had a mini USENET, that would sell me over to volunteer.

No one should doubt that these devices are FCC complaint, if not, these companies could not sell in the USA:

http://www.arrl.org/part-15-radio-frequency-devices

Note: Computer terminals and peripherals that are intended to be connected to a computer are digital devices.

However to ignore the fact the these proprietary CPUs do not have additional opcodes or techniques to read its users work is ludicrous. Here are some prime examples from Intel:

http://software.intel.com/sites/manageability/AMT_Implementa...

http://blogs.intel.com/technology/2011/01/intel_insider_-_wh...

http://www.intel.com/content/www/us/en/architecture-and-tech...

AMD I have no evidence to support otherwise, but I would not doubt it.

There's more in the TOS and in the privacy policy section that people would consider offensive consenting with. Well, those that are informed, know that google works straight for the DoD, since its inception.

Can anyone convince me why I should contribute to this project when I can already use the following?: [[bitmessage.org][Bitmessage]] [[freenetproject.org][Freenet with a chat client]] [[gnunet.org][GNUnet with chat]] [[i2p2.de][I2P-Messenger]] [[retroshare.sf.net][RetroShare]]

PS You could also apply a simple Icecast and/or MPD video stream under those proctols, even [[stomp.github.io][STOMP]].