Category: Law

  • Seeing those EULAs in a different context.

    Many years ago I realized that the End User License Agreements (EULA) that we are forced to endure for web sites and software was out of hand. There have been a lot of good points made in the past about them and how they are rarely read. I had written notes about an article but…

  • Seriously RIM? Call it the HackBerry from now on…

    [This was originally posted on the OSVDB blog.] Our sponsor Risk Based Security (RBS) posted an interesting blog this morning about Research In Motion (RIM), creator of the BlackBerry device. The behavior outlined in the blog, and from the original blog by Frank Rieger is shocking to say the least. In addition to the vulnerability…

  • The Lesser of Two Weevs

    Yesterday, Andrew Auernheimer (aka Weev), was sentenced for his 2012-08-16 indictment on one count of “fraud and related activity in connection with computers” (18 U.S.C. § 1030) and one count of “conspiracy to commit offense or to defraud” (18 U.S.C. § 371). This was the result of Auernheimer’s activities in 2010, where he manipulated a…

  • Cyberwar: Not what we were expecting

    For BruCON 4 (2012), and for THOTCON 0x04 (2013), Josh Corman and I presented on Cyberwar. While the topic has been beaten to death, our talk focused on two aspects. First, a solid debunking of the rhetoric and hype that has dominated the topic for years. Second, building up a new set of ideas that…

  • .de Vulnerability Information Vanishing

    [This was originally published on the OSVDB blog.] Due to a recent German law being passed, Phenoelit and now Stefen Esser’s Month of PHP Bugs has been removed. More information via an article by Robert Lemos.

  • Stupid E-mail Disclaimers and the Stupid Users that Use Them

    [This was written with Martums and originally published on attrition.org.] We thought it would be a fad. Ok, we hoped it would be a fad, destined to go away as quickly as it came. Unfortunately, those worthless e-mail legal disclaimers still pollute the internet. Written by overzealous lawyers that don’t seem to realize the stupidity futility of their effort,…

  • A Curious Response to Crime

    [This was originally published on attrition.org.] Crime pays. Those who question this only need to look at recent events surrounding a software company and one of their products. A company called Curious Labs currently develops and sells a graphic software package called Poser. It is widely used and respected by hobby graphic artists and professionals alike. Recently, Curious…

  • Convict them all! A new breed of ambulance chasers

    [This is a rebuttal/rant in which I ‘reply’ to various parts of a news article, originally published on attrition.org. This version has been updated for style.] Computer crime: Changing the public’s perception12 Oct 2000https://seclists.org/isn/2000/Oct/51 You remember Jonathan James? He made national news a couple of weeks ago. You know, he’s that nice 16-year-old young man…

  • Overlooking the Obvious Database

    This was originally published on Synthesis.net, but is 404 now. While archive.org was able to get a snapshot, the text colors are off so you only see hyperlinks unless you select all text on the page. Brad Chester recently moved two doors down from you. Taking residence in a nice three bedroom house, his landscaping…

  • The Crime of Punishment

    [This was originally published on The Synthesis and mirrored on attrition.org.] As you read this, an unusual legal case history is being established around the prosecution of computer crime. Because computer crime is still a relatively new aspect in the arena of law and prosecution, each and every case sets important precedent that will be…