Is it wise to advertise that you've hacked any app in this social climate?
Theoretically, could the founder of Yo have pressed charges against the student? (This would, of course, be complete suicide for any startup. But companies aren't always rational actors.)
I don't think the US court system agrees, which is what I'm asking about here.
In fact, it seems straightforward to make a case against the student's activities. From the Computer Fraud and Abuse Act:
(2) intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains—
...
(C) information from any protected computer;
The phone numbers are probably information from a protected computer.
Young people are pretty often cavalier about jeopardizing their futures. I'm just checking whether there is, in fact, a chance that this young person could have.
Protected computers: In practice, any ordinary computer has come under the jurisdiction of the law, including cellphones, due to the inter-state nature of most internet communication. (See the case history, below).
I recall a case where the courts did not agree with you. I can't remember names or many details, but the gist was that some guy realized that one of the pages was taking an fdat argument that was his userid, and by simply incrementing that number he could retrieve the data of any user he wanted. He presented his findings to the company (something major, like AT&T maybe), and they immediately sued him. He fought in court saying he wasn't malicious and was "white hat" as you say, but I believe he was convicted.
Comments
Is it wise to advertise that you've hacked any app in this social climate?
Theoretically, could the founder of Yo have pressed charges against the student? (This would, of course, be complete suicide for any startup. But companies aren't always rational actors.)
Nope, they are white hat. Hacking a product/app/website and not talking about it, not warning the founder is the problem.
In fact, what those guys are doing increases the collective conscious and improves the system to be able to develop better/safer products.
I don't think the US court system agrees, which is what I'm asking about here.
In fact, it seems straightforward to make a case against the student's activities. From the Computer Fraud and Abuse Act:
(2) intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains—
...
(C) information from any protected computer;
The phone numbers are probably information from a protected computer.
Young people are pretty often cavalier about jeopardizing their futures. I'm just checking whether there is, in fact, a chance that this young person could have.
The computer was obviously not protected.
Protected computers: In practice, any ordinary computer has come under the jurisdiction of the law, including cellphones, due to the inter-state nature of most internet communication. (See the case history, below).
http://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
I recall a case where the courts did not agree with you. I can't remember names or many details, but the gist was that some guy realized that one of the pages was taking an fdat argument that was his userid, and by simply incrementing that number he could retrieve the data of any user he wanted. He presented his findings to the company (something major, like AT&T maybe), and they immediately sued him. He fought in court saying he wasn't malicious and was "white hat" as you say, but I believe he was convicted.
Does anyone remember this case?
Weev. Search HN, there are hundreds of conversations about that case.
Indeed, he was sent to prison.
I don't get to hack stuff just because I say "white hat."
If it's not yours, don't mess with it.
And leave security holes open for people with less good intent and actually harm users?
There are plenty of companies who will pay you for your services, and under contract so it's completely legal, too.