Showing posts with label Russia Today. Show all posts
Showing posts with label Russia Today. Show all posts

Thursday, April 4, 2013

'Whistleblower Defense League' created to fight back Obama administration's prosecutorial overreach


RT News

Published on Apr 4, 2013
As we've reported before, the Obama administration has reached new heights when it comes to prosecuting whistleblowers. Under Obama's presidency, seven people have been convicted in accordance with the Espionage Act of 1917 for leaking governmental information to the public. All previous administrations combined haven't prosecuted that many whistleblowers. Now, a group of attorneys have come together to form the Whistleblower Defense League to protect such individuals from legal action. One of those attorneys, Jay Leiderman, discusses why they felt it was necessary to create this group.

Click this link to see the video: 


For more information on the Whistleblower Defense League see this post announcing the formation of the #WBDL and this post talking about the first #WBDL case, a challenge to an unconstitutionally issued subpoena in the Barrett Brown case.  

Tuesday, February 5, 2013

Julian Assange runs for Australian Senate


Jay Leiderman on RT News 4 February 2013



Published on Feb 4, 2013Julian Assange is no stranger to controversy and this time the whistleblower is making headlines for a different reason. Australia has confirmed that the WikiLeaks co-founder is running for office. Assange has made a name for himself for exposing government secrets, but now he seeks a senate seat as a member of the WikiLeaks Party. So does candidate Assange have a fighting chance to infiltrate the political world? Jay Leiderman a lawyer for Leiderman Devine LLP gives us his take on the matter.

Find RT America in your area: http://rt.com/usa/where-to-watch/Or watch us online: http://rt.com/on-air/rt-america-air/
Like us on Facebook http://www.facebook.com/RTAmericaFollow us on Twitter http://twitter.com/RT_America

Category
News & Politics

Tuesday, January 15, 2013

Jay Leiderman on Russia Today Discussing DDoS as Protest Speech

Demanding the right to digitally protest: Hacktivists petition the White House to legalize DDoS




Another wonderful article by Andy Panda Blake accompanied this RT story.  The title is above, here is the unabridged text.  Thanks to Andy for, as usual, being fair and getting it right:


Is temporarily slowing down a website a legal form of protest? Current US law says it isn’t, but hacktivists want the White House to make changes that would force the government to reconsider their witch-hunt against alleged computer criminals.
In the latest WhiteHouse.gov petition to go viral, the Obama administration is asked to make a method of momentarily crippling a website comparable to real word demonstrations, essentially allowing for a whole new legal form of online protest.
“With the advance in internet technology comes new grounds for protesting,” writes ‘Dylan K’ of Eagle, Wisconsin.
Dylan’s petition, uploaded this week to the White House’s We the People page, is the most recent of these electronic pleas on the website to generate national headlines. A series of petitions in late 2012 demanding the peaceful secession of certain states from the US garnered nearly one million signatures from across the country, and just this week the Obama administration was prompted to respond to one popular request to depot CNN host Piers Morganover his outspoken anti-gun views. That call for action, advocated by Second Amendment proponents and firearm owners concerned over a possible rifle ban, eventually accumulated around 110,000 electronic signatures.
When the White House responded to the petition to deport Morgan this week, press secretary Jay Carney said Americans shouldn’t let “arguments over the Constitution’s Second Amendment violate the spirit of its First.”
Those rallying for new computer laws say that current legislation limits those very constitutional rights, though, and that one electronic form of action should be covered under the First Amendment — the provision that provides for the freedom of speech, protest and assembly.
In the latest instance, the White House is asked to evaluate a federal rule that currently makes it unlawful to engage in distributed denial-or-service, or DDoS, attacks — a harmless but effective way of flooding a website’s server with so much traffic that it can’t properly render pages for legitimate users.
Performed by both seasoned hackers and novice computer users alike, DDoS-ing a website essentially makes certain pages completely unavailable for minutes, hours or days. Unlike real world protests, though, demonstrators don’t even have to leave the house to protest. Instead, humongous streams of information can be sent to servers with a single mouse click, only for that data to become so cumbersome that the websites targeted can’t properly function.
Under the Computer Fraud and Abuse Act, a DDoS assault is highly illegal. For those familiar with the method, though, they say it’s simply a matter of voicing an opinion in an online format and should be allowed.
“Distributed denial-of-service is not any form of hacking in any way,” states the petition. “It is the equivalent of repeatedly hitting the refresh button on a webpage.”
Overloading a targeted website with too much traffic, says Dylan K, is “no different than any ‘occupy’ protest.”According to him and the roughly 1,100 cosigners, there is much common ground between the two. “Instead of a group of people standing outside a building to occupy the area, they are having their computer occupy a website to slow (or deny) service of that particular website for a short time,” he says.
For companies that are hit with DDoS assaults, though, they sing a different song. In 2006, controversial radio host Hal Turner had his website taken offline after members of the then-infant hacktivist movement Anonymous used denial-of-service attacks to shut down his site to visitors. Turner said the bandwidth overflow cost him thousands of dollars in fees from his hosting company.
When Turner tried to sue those he blamed for the DDoS attack, a federal judge for the United States District Court in New Jersey eventually dismissed his claim. Other “hackers,” however, haven’t been so lucky.
When PayPal, Visa and MasterCard announced in 2010 that it would no longer accept funds for the website WikiLeaks, Anonymous and others responded with a DDoS attack on the payment service providers. The following summer, the US Department of Justice filed an indictment against 14 Americans they accused of participating in shutting down PayPal.
That same year, a homeless hacker using the alias “Commander X” was charged with waging a DDoS attack on the official government website of Santa Cruz, California because he opposed the city’s policy that outlawed sleeping in public space. X could have been sentenced to serious time for committing a felony, but he escaped the United States, allegedly seeking refuge in Canada where he is reported to be in hiding today.
“For a 30-minute online protest I’m facing 15 years in a penitentiary,” he told the National Post last year while on the run. According to an interview he gave last month with Ars Technica, he also participated in OpPayBack — the Anonymous-led assault PayPal and others over their WikiLeaks blockage.
California attorney Jay Leiderman has represented X, and has gone on the record to compare DDoS attacks with real life sit-ins.
“A DDoS is a protest, it’s a digital sit it. It is no different than physically occupying a space. It’s not a crime, it’s speech,”he told Talking Points Memo in 2011. “They are the equivalent of occupying the Woolworth's lunch counter during the civil rights movement," The Atlantic quoted him saying last year.
Speaking specifically of the operation against the companies that cut funding to WikiLeaks, the lawyer said online action is equivalent to peaceful protest.
“Take PayPal for example, just like Woolworth's, people went to PayPal and said, I want to give a donation to WikiLeaks. In Woolworth's they said, all I want to do is buy lunch, pay for my lunch, and then I'll leave. People said I want to give a donation to WikiLeaks, I'll take up my bandwidth to do that, then I'll leave, you'll make money, I'll feel fulfilled, everyone's fulfilled,” he said. “PayPal will take donations for the Ku Klux Klan, other racists and questionable organizations, but they won't process donations for WikiLeaks. All the PayPal protesters did was take up some bandwidth. In that sense, DDoS is absolutely speech, it should absolutely be recognized as such, protected as such, and the law should be changed.”
Leiderman added that he considers the use of DDoS not to be an “attack” in some circumstances, but actually legitimate protest. 
“[T]he law should be narrowly drawn and what needs to be excised from that are the legitimate protests,” he said. “It's really easy to tell legitimate protests, I think, and we should be broadly defining legitimate protests,” he said.
New York attorney Stanley Cohen, who is representing one of the accused “PayPal 14” hackers responsible for the Anonymous-led operation, agrees.
“When Obama orders supporters to inundate the switchboards of Congress, that’s good politics, when a bunch of kids decide to send a political message with roots going back to the civil rights movement and the revolution, it’s something else,” Cohen told TPM in 2011. “Barack Obama urged people to shutdown the switchboard, he’s not indicted.”
“It’s not identity theft, not money or property, pure and simple case of an electronic sit in, at best,” he said.
So far over 1,100 people agree on WhiteHouse.gov, and hope the Obama administration will get their point. Until then, though, Commander X and others face upwards of a decade in prison apiece for violating a clause in the Computer Fraud and Abuse Act that makes it unlawful to “knowingly cause the transmission of a program, information code or command, and as a result of such conduct, intentionally causes damages without authorization to a protected computer.”
With attorneys like Leiderman and Cohen arguing that the damages in questions aren’t quite criminal, the White House may have to respond to the latest WhiteHouse.gov petition. The Obama administration is mandated to respond if it can garner 25,000 signatures in the next month. Until then, though, proponents of DDoS as free speech can cite what Jay Carney said when petitioners rallied for the deportation of Piers Morgan for his call to ban assault weapons.
“The Constitution not only guarantees an individual right to bear arms, but also enshrines the freedom of speech and the freedom of the press – fundamental principles that are essential to our democracy,” said Carney. 
Meanwhile, exercising constitutional rights by way of overloading web servers isn’t being accepted as such by the government. That doesn’t mean that Anonymous or other so-called ‘hacktivists’ will change their ways: just last month, members of the hive-mind computer collective waged a DDoS attack on the website of the Westboro Baptist Church after the religious group announced plans to picket the funerals of mass shooting victims in Newtown, Connecticut. Anonymous waged a similar wave of attacks on the Church of Scientology in 2008, the result of which landed a number of Anons in prison for violating federal law.

Thursday, December 13, 2012

TWO RECENT HACKTIVIST TRIALS HAVE DANGEROUS IMPLICATIONS FOR A FREE INTERNET



26




by 

TWO RECENT HACKTIVIST TRIALS HAVE DANGEROUS IMPLICATIONS FOR A FREE INTERNET

Twice last week, the justice system heard cases related to hacking, and in both instances, information sharing and cyberlaw were dealt a seriously heavy-handed blow. The government was the bully here, and the dorky little hacker had his glasses knocked square off his face.
It reminds us that the Internet is serious business, but also that a man’s gaping butthole can cause a lot of damage — but more on that later.
On November 20, alleged Wikileaks source Jeremy Hammond was denied bail in a New York City courtroom, and told he’s more dangerous than a sex offender because he compromised the computers of a private intelligence firm. In New Jersey, just hours later, a jury of his peers quickly convicted Andrew Auernheimer on charges of accessing a protected computer, and disclosing an AT&T security flaw while working with a group called Goatse Security. Hammond could get life in jail for his crime, and Auernheimer is likely to do a few years on a trumped-up charge for involving himself with a collective named after an Internet-famous image of a man’s wide-open rectum. Really. Look it up.
But it’s more than just a matter of sharing information, vile viral photographs, and making the world a wee-bit smarter. These rulings offer an eye-opening example of how far the government is willing to go to deter future hacktivism, even if it sets a deleterious legal precedent that could affect us all.
***

Hammond, seen here, plotting teh evil cyber-terrorisms
There was no conviction in Hammond’s case, but in Manhattan a federal judge did deny bail for the twenty-something Chicago man accused of involvement with last year’s high-profile hack of Strategic Forecasting, aka Stratfor, a private intelligence company that advises customers on global issues and has been routinely commissioned by law enforcement to, among other activities, investigate political protesters in the United States. Federal prosecutors are charging Hammond with being one of a handful of persons responsible for compromising Stratfor’s data by collaborating with a group called LulzSec, an offshoot of the hacktivist collective Anonymous. Now he is stuck behind bars facing three charges relating to hacking and fraud stemming from months of undercover investigation.
UNTIL THE COURTS CAN CATCH UP WITH THE TECHNOLOGY, AND CONGRESS CAN FIND A WAY TO BALANCE PRIVACY AND SECURITY IN THE CYBER-SECTOR, IT’S AN INCREDIBLY HOSTILE TIME FOR ALL COMPUTER USERS, NOT JUST HACKERS.
Hammond likely won’t stand trial for quite a while. As of this writing, he’s been locked up more than 260 days with slim chance of release. On Tuesday, a judge said she will keep it that way indefinitely until the government’s attorneys are ready have at him.
“Jeremy, only 27 years old, has spent most of his young life contributing to charitable efforts and acting on his principles to right what he perceives as wrong,” reads a statement posted this week on an online support network for the hacker’s defense. “Now, due to his contributions to the Anonymous collective, Jeremy could, if found guilty, spend 30-plus years in prison.”
Sure enough, Judge Loretta A. Preska did acknowledge in court that Hammond faces a sentence of 35 years to life should a jury convict him on charges that have so far proven relatively victimless, with the exception of the few intelligence agents whose reputations were tarnished, along with the customers of the company whose log-ins were compromised. Coincidentally, details emerged last week that reveal that Judge Preska’s husband happens to be one of the thousands of Stratfor subscribers whose credentials were hacked by LulzSec. The court has not acknowledged the connection, and now the wife of someone with a vested interest in seeing a conviction controls Hammond’s fate. So far, she’s showing signs that it won’t be an easy case for the defense.
“Judge Preska and the prosecuting attorneys did state that Jeremy was more of a danger to the community than an online sexual predator because Jeremy has ways to hide his identity online and, pardon my sarcasm here, because Jeremy knows how to use Tor,” writes Sue Crabtree of the Hammond Solidarity Network. Tor, or The Onion Router, is an identity-masking software bundle funded by the US State Department and used to create anonymity for web users who wish to keep their digital footprint relatively untraceable, often over fear of prosecution and persecution. So far it seems like Hammond was right in thinking he needed it.
“The truth is, Jeremy has done no wrong and those determined to prosecute him are guilty,” reads a statement from his supporters. “The State is guilty of protecting their own interest, especially in their pursuit to prosecute those they consider dangerous to their agenda.”
According to Crabtree, the courtroom was informed this week that Hammond’s name is now on a federal terrorist watch-list and his pleas for bail were rejected because the judge considers him a flight-risk, despite the fact that he doesn’t have a passport.
***

Auernheimer, seen here, sporting a super-terrorist beard
Across the river in Newark, New Jersey, 27-year-old Andrew Auernheimer was found guilty of essentially punching his keyboard.
In 2010, Auernheimer found what was pretty much a massive AT&T fuck-up while working with a group called Goatse Security, or GoatSec. The Apple iPad that worked with the telecom’s 3G network was just a few weeks old at the time and still the coolest and most must-have item for upper-middle-class America, a fact that posed a pretty big problem when Auernheimer noticed that all of those privileged persons’ information was sitting on the Internet, unencrypted, open for anyone smart enough to see if they knew where to look.
“IF RECENT EVENTS HAVE TAUGHT US ANYTHING IT’S THAT CONGRESS IS ABSOLUTELY USELESS AND IS NOT LIKELY TO DO ANYTHING ON ANY ISSUE AT ANY TIME,” SAYS LEIDERMAN. “THEY ARE THE MOST IMPOTENT BAND OF INDIVIDUALS ON THE PLANET, SO WE NEED TO LEAVE IT TO THE COURT TO LET THIS SHAPE OUT.”
Auernheimer never stole any passwords, and he never hacked Apple or AT&T. Last week in court he was abundantly clear about his intentions. “No, I did not attempt to monetize off of this,” he said during testimony, a fact reinforced by the prosecution’s own evidence. When GoatSec was asked to sell their findings, Auernheimer told a colleague well before he was under indictment, “I am saying that it has been destroyed and we’re not going to violate principles for money. And none of our people have a copy of the data at all.” GoatSec never quite made the damage prosecutors led the jury to believe. AT&T patched the flaw almost instantly–a flaw they only learned of because of Auernheimer.
“I don’t think that people should keep software vulnerabilities secret,” Auernheimer explained to the court. “I think the consumer has a right to be informed when they’re put at risk by a company. And we have not only a right as Americans to analyze things that corporations publish and make publicly accessible, but perhaps even a moral obligation to tell people.”
While no nefarious hacks ever occurred, Auernheimer did, however, hype up his discovery. Just like how he used his noggin to discover a massive security breach and went public with his findings, he also sold himself goddamn brilliantly, using hyperbole and elusiveness in disclosing his findings with a cryptic allure that only a hacker could have. It worked in getting the story out, and it worked on convincing a jury to convict him.
A driving force during the prosecution’s questioning of Auernheimer was the specific language he used when he first approached the press with his findings. “I would be absolutely happy to describe the method of theft in more detail,” Auernheimer wrote on behalf of GoatSec in June 2010 to a few media contacts whose emails were compromised by the exploit. It was PR gold and likely the impetus behind the story’s success. Then the courts used it against him, bringing it up repeatedly during Auernheimer’s brief time on the stand.
“I felt I was free to use rhetoric and hyperbole like ‘theft’ because the underlying act of accessing public information–it boggles my mind that it could be considered a crime,” Auernheimer said on the stand this week.
“It’s a universal understanding,” he said, “when you put something on the Internet — http, to my understanding, is a publishing system. And when you put something on the open Internet and you didn’t protect it with a password or a firewall, you’ve made it a part of the public record.”
“And when you publish something, you can’t sit there and say–you know, when somebody uses it to embarrass you, you can’t kill the messenger and say, ‘Well, I didn’t want you to have that.’ Well, you shouldn’t have made it available if that’s true.”
For accessing a “protected computer,” Auernheimer could get fives years for each of the two charges. Security experts say a retrial is likely and Auernheimer himself is adamant about appealing. After all, his charges are dog shit.
“The ‘protected computer’ is any network computer. You access a protected computer every day,” Auernheimer told reporters outside of a courtroom on Tuesday. “Have you ever received permission from Google to go to Google?”
Auernheimer said moments after being convicted that he expected a guilty verdict and will appeal—news he tweeted from his phone since he isn’t allowed to touch an actual computer for a while. For the time being, he’s out on $50,000 bail awaiting sentencing or perhaps an appellate ruling that could eventually bring his case to the Supreme Court.
***
After details from both the Auernheimer and Hammond cases came in Tuesday evening, I called Jay Leiderman, a defense attorney from Southern California who has represented a fair share of alleged computer criminals, including some aligned with the Anonymous movement that spawned LulzSec. When Leiderman picked up the phone, he was just finishing a day of lawyering near Los Angeles and had barely heard any news from the East Coast yet.
Jay Leiderman

“Hammond was told he can’t do house arrest and could be put away for 39 years to life,” I told him. He paused. For a while.
Leiderman suggests there’s no way in hell that Hammond will be put away for life for sharing the Stratfor data, but says that the way his and Auernheimer’s cases were handled say a lot about the justice system.
“The way the government is reading these laws really makes about all behavior criminal,” Leiderman tells me.
In the case of Auerenheimer, Leiderman says, “He didn’t access a protected computer yet he was convicted of it.”
“It is clearly a situation of them striking while the iron is still ambiguous,” he says. For right now, there is a real lack of well-defined cyberlaw.
“At some point the federal courts are going to have a chance to consider these issues and realize the prosecutions that they are currently undertaking are in fact what the laws were designed to prevent,” he says. “But before that happens, the federal government is intensifying their pound of flesh. They are trying to scare everyone and make them think that every time they punch upon that keyboard that they are risking 15 years in federal prison. And for as long as that, it’s nothing but a scare tactic and one that ultimately can’t survive in an era of internet freedom.”
***
Hammond, who has been confined to jail since March, isn’t likely to be spared from those scare tactics as his case progresses. In a case that is highly under documented, even within the court reporting circuit, the federal charges against Hammond likely have as much to do with computer hacking as it does with making a domestic scapegoat out of one of the few US citizens the government might be able to directly link to Wikileaks. Unlike with Auerenheimer, though, there is at least a precedent and an actual burden of proof that Hammond acted on ill intentions.
To say either Auernheimer or Hammond went public with some Earth shattering knowledge wouldn’t exactly be correct. It is, however, pretty safe to acknowledge that Tuesday’s ruling—especially in the Newark case —accentuates the fact that the Justice Department is now willing to put anyone behind bars for crimes that aren’t yet properly defined.
Hammond’s story is one that has a bit more structure to it—in terms of current law, anyway—but both tales need to be talked about before another harmless hacker is locked away for exposing anything from botched, billion-dollar corporate security to handing “super-secret” intelligence to the enemy—in this case, Julian Assange of Wikileaks.
According to his indictment, Hammond and LulzSec stole credit card numbers from Stratfor’s servers as well as a trove of personal emails from employees, hundreds of thousands of messages that are still being combed through by researchers nearly a year later. If he is guilty of what he is accused, Hammond is likely to receive a sentence that will set an unfortunate precedent. It’ll also be perhaps the first real punch Uncle Sam’s landed on WikiLeaks.
As of this writing, no person has yet to be tried in civilian court for any crimes connected to WikiLeaks. Private First Class Bradley Manning, the accused source of sensitive military documents from the Iraq and Afghanistan wars, will be court-martialed early next year. Meanwhile, he’s been held in conditions considered torturous by the UN for over 900 days. Jacob Appelbaum, a computer researcher from the West Coast who represented Assange at a hacker conference in 2010, was recently informed that he is still under federal investigation nearly two years after the FBI first subpoenaed his personal Gmail account. At this rate, Hammond might be the first head from the WikiLeaks snake that the Justice Department can cut away, although information sharing and hacktivism isn’t likely to die as quickly. They will, however, have hard proof that their actions won’t be tolerated.
Hammond’s a self-described communist and anarchist, but his political leanings aren’t quite as sexy and dangerous as the US attorneys’ hyperbolic Hollywood portrayal  His indictment highlights his freeganism—digging through garbage for food. His rap sheet is called into question, which includes an arrest for “violently protesting” a speech delivered by a Holocaust denier. The court has been made aware that Hammond’s probation officer once found “questionable literature” in his residence—pamphlets for a protest against a white supremacist group.
“I do think that Hammond’s prosecution is 100 percent political, not withstanding whatever actions he may have taken,” Leiderman says.
“I think we’ve come to a place in America where we no longer value the political dissident. Where speech that is contrary to government is no longer seen as a valuable thing in society,” he says.
“The way that speech works and the way that free speech works is that if an idea is too radical and if an idea is too far flung and too far fetched—like dumpster diving for your food—it’s going to be rejected by the people in the marketplace of ideas, and that’s the way the marketplace of ideas works. But when it’s the government telling us, ‘Nah, this idea is no good. We need to reject it,’ then it’s no longer free choice in the marketplace of ideas. We’re being told what to think and that’s where it gets scary.”
“It is scary when you put it that way,” I told Leiderman.
LulzSec and Anonymous have both waged online campaigns to draw attention to efforts from Washington to pass cybersecurity legislation that, in every instance so far, sought to severely limit personal Internet freedoms. President Obama is soon expected to act on an executive order to do what Congress can’t, and prosecutions against harmless computer “criminals” could easily crescendo. After all, almost every attempt from Washington so far to put together cybersecurity legislation has allowed for the government to play grab-ass with any and all information stored on the servers of private companies. At the same time, existing legislation already lets the feds conduct surveillance over email accounts and other activity with little more than a court order. Just ask the last head of the CIA.
While lawmakers on the Hill and the country’s courts are both trying to make sense of how to approach computer crime, no one is safe in the meantime. Currently, over 5,000 people have installed a free browser plug-in that lets anyone comb through websites using a URL incrementing script in Firefox that more or less mimics what Auernheimer was charged with, and there’s another publicly available plugin for Google Chrome. Even Facebook was started with a script that combed through Harvard’s databases for public-facing images of the student population. Auernheimer’s discovery wasn’t groundbreaking, but his conviction would be. Until the courts can catch up with the technology, and Congress can find a way to balance privacy and security in the cyber-sector, it’s an incredibly hostile time for all computer users, not just hackers.
“If recent events have taught us anything it’s that Congress is absolutely useless and is not likely to do anything on any issue at any time,” says Leiderman. “They are the most impotent band of individuals on the planet, so we need to leave it to the court to let this shape out. And you know, the courts don’t suffer fools lightly. The courts have historically done a reasonably good job in protecting our freedoms and narrowly circumscribing crimes such that bold behavior isn’t criminal. And the way the government is reading these laws really makes about all behavior criminal.”
For now, says Leiderman, interpretation in regards to computer crimes is weak. While it’s arguable that the justice system will never keep up with the pace of technology, at this rate it could be too late before laws are finally structured in such a way that Hammond and Auernheimer aren’t looking at guaranteed, asinine sentences.
Meanwhile, says Leiderman, the state of affairs is ludicrous. “They’ve made a rule so broad, so amorphous and so ambiguous,” he says, “that reasonable people can’t ascertain what conduct is in fact covered.”
“We’re at a point in the history of these prosecutions where the government can literally charge anyone for anything and they seem to be doing that in a very targeted manner. They are going after people they don’t like for speech that they don’t like and they are going to get these convictions up until the point where courts start telling them, ‘Stop it. This isn’t what these laws were meant for.’”
That’s assuming the people have a voice long enough to make that opinion heard.
Blake is a web producer for Russia Today. Follow him on Twitter.
http://buffalobeast.com/404-error-justice-not-found/