Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Did he simply log in with another users password he guessed/found/user failed to log out or did he hack the server?

In my opinion, a) is not a serious crime, b) is.



Every time I hear someone talk about hacking, I have to pause and remind myself that most people who use the term really don't know what they mean by it.

It's like of like asking if he "nebulously computer crimed" the server, which the police seem to think he did, and most unfortunately is about as specific as the laws on it get.


Why is hacking a server worse than stealing a password?


Then it becomes premeditated and with intent.


Why abusing the other user space can't be premeditated?


We could try to draw parallels to physical law.

Hacking = breaking and entering

Sitting down at someone's logged-in computer = unlawful entry (not forceful entry)


The difference to the victim between unlawful entry and B&E is the amount of work needed to make the property secure afterwards.

In theory a sysadmin could claim hours of work after someone sat down at a logged-in computer or someone "hacked" entry. That admin might want to check for privalidge escalation an back doors.

(I think this indictment is bullshit and I hope he is found not guilty or has a token punishment. A federal convictions seems weirdly harsh. Cruel and unusual -especially with the subsequent consequences- for the crime.)


I thought B&E was a bigger crime because of the intentional use of force? Demonstrating a greater criminal intent, or something like that. Popping a window lock with a credit card causes no damage, but it's still B&E.

Also think the indictment is bullshit.


Actually, you're both wrong. The real significant legal distinction is usually between criminal trespass and burglary (also known as "breaking and entering"), where the latter involves entry with intent to commit some other crime beyond illegal presence. At common law, the "breaking" of the "breaking and entering" element of burglary does not require actual use of force or damage to a physical object.


If I recall right, the "breaking" part can be interpreted as broadly as pushing open a closed (but unlocked) door.

That's the letter of the law, but I sincerely doubt that was the spirit..


In UK law, simply opening an unlocked door and going inside is not a crime. You can come home to me sat on your sofa and all you can do is ask me to leave by the nearest exit (though if I refuse, you can use reasonable force to remove me).


Sitting at someone else's terminal makes it sound like a crime of opportunity, but why is stealing a password through spearphishing different from bypassing a poorly coded authentication token?


Is that what he did?

There is obviously a very large spectrum of how you could obtain a password, of varying degrees of "ethical". I have to ask you to be specific which you want to talk about.


User brador made a blanket statement that one was worse than the other. I agree with you: it's impossible to discuss without specifics.


Did the individual enter the house with a spare set of keys he found under the doormat/owner left unlocked, or did he break the door down?

In my opinion, a) is not a serious crime, b) is.

I'm not saying it's a perfect analogy, but you have to be very careful when making arbitrary lines like you did.


Your analogy only makes sense if the perpetrator just went into the house and wrote "Your house just got its ass kicked" on a post-it note.

If they stole something or vandalized the house then it makes no sense as an analogy.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: