{"id":23,"date":"2007-02-05T12:10:00","date_gmt":"2007-02-05T12:10:00","guid":{"rendered":"http:\/\/codeinmybug.wordpress.com\/2007\/02\/05\/samy-a-hero-or-a-villian\/"},"modified":"2008-05-07T15:16:22","modified_gmt":"2008-05-07T09:46:22","slug":"samy-a-hero-or-a-villian","status":"publish","type":"post","link":"https:\/\/projectbee.org\/blog\/archive\/samy-a-hero-or-a-villian\/","title":{"rendered":"Samy: A hero or a villian!"},"content":{"rendered":"<p>First thing first. I hate these sites meant for so called &#8220;socializing&#8221;.<br \/>\nSites like: Orkut, MySpace, etc. Ditto with games like SecondLife.<br \/>\nHeck Man.<br \/>\nJust get out of these places and get a life&#8230;. [Be more like Swen, the GBCD ;)]\n<p>Anyways. There is this guy who created a, so called, WORM for MySpace.<br \/>\nIt was a beautifully written piece of code&#8230; all in javascript. What this worm did was, it added Samy as a hero in the profile of every person who visited Samy&#8217;s profile.<br \/>\nAnd that&#8217;s not all, it also added Samy as a hero to the visitors who visited ANY affected profile.<br \/>\nHe gives a beautiful (and &#8220;for-dummies&#8221;) writeup:<br \/>\n<a href=\"http:\/\/namb.la\/popular\">Story in his own words<\/a><br \/>\n<a href=\"http:\/\/namb.la\/popular\/tech.html\">Technical details<\/a><\/p>\n<p>It created a havoc. Lakhs of profiles  were infected in a few hours. MySpace had to take down the site to &#8220;repair&#8221; it.<br \/>\nThe code is so beautifully crafted that it made me smile.<\/p>\n<p>Now, was this wrong?<br \/>\nTo a certain extent, YES.<\/p>\n<p>Was it a punishable crime?<br \/>\nmmm&#8230; Depends on the extent and type of punishment. [If my views matter&#8230; well it&#8217;s my blog, so it matters \ud83d\ude09 ]\n<p>The recent news is that Samy has been sentenced for <span style=\"font-weight:bold;\">three years of  probation <\/span>and <span style=\"font-weight:bold;\">90 hours of community service. <\/span>He <span style=\"font-weight:bold;\">cannot have access to internet<\/span> during this period. [Though I am not able to understand what it means. He&#8217;ll anyways be using ATM etc.]\nHowever, this kind of &#8220;punishment&#8221; doesn&#8217;t make a sense to me.<\/p>\n<p>If we really have to punish the &#8220;culprits&#8221;, why not punish MySpace too?<br \/>\nWhy shouldn&#8217;t MySpace take the responsibility of the privacy of it&#8217;s users?<br \/>\nWhy was MySpace stupid to allow <span style=\"font-weight:bold;\">DIV<\/span> tags?<br \/>\n<span style=\"font-weight:bold;\"><span style=\"font-weight:normal;\">Why shouldn&#8217;t iexplorer and safari be sentenced for allowing javascript inside CSS?<\/span><\/span><\/p>\n<p><span style=\"font-weight:normal;\">These are questions that cannot be answered because the world belongs to the BIG-BAD-BOYS.<\/span><br \/>\n<span style=\"font-weight:normal;\">What this boy did not <\/span><span style=\"font-weight:normal;\">really <\/span><span style=\"font-weight:normal;\">harm anyone. He could have modified the code to steal private information, (the way your gmail book can be stolen).<\/span><br \/>\n<span style=\"font-weight:normal;\">Moreover, he  published the code after MySpace had fixed the problem.<\/span><br \/>\n<span style=\"font-weight:normal;\">&#8230;&#8230;. and yet he has been SENTENCED.<\/span><\/p>\n<p><span style=\"font-weight:normal;\">I am reminded of an incident that Lalit told me about.<\/span><br \/>\n<span style=\"font-weight:normal;\">There was this guy who informed the site administrator about some loophole in his site and was jailed.<\/span><\/p>\n<p><span style=\"font-style:italic;font-weight:normal;\">&#8220;&#8230; but why?&#8221;<\/span><br \/>\n<span style=\"font-style:italic;font-weight:normal;\">&#8220;Because you are not supposed to peek inside my house, even if the door is open.&#8221;<\/span><br \/>\n<span style=\"font-style:italic;font-weight:normal;\">&#8220;&#8230; and what if I am one of those who have signed up to stay in your house? Isn&#8217;t my privacy your responsibility? Shouldn&#8217;t I be allowed to check the locks and doors?&#8221;<\/span><br \/>\n<span style=\"font-style:italic;font-weight:normal;\">&#8220;No. I am a freaking BIG-BAD-BOY. You&#8217;ve no right to mess with me. If you even dare, be prepared to be jailed.&#8221;<\/span><\/p>\n<p><span style=\"font-weight:normal;\">Well&#8230;. That makes sense now.<\/span><span style=\"font-style:italic;font-weight:normal;\"><br \/>\n<\/span><span style=\"font-weight:normal;\">So next time you find a loophole either sit silently or sell it.<\/span><br \/>\n<span style=\"font-weight:normal;\">That&#8217;s all I can conclude.<\/span><\/p>\n<p><a href=\"http:\/\/digg.com\/submit?phase=2&amp;url=code-in-my-bug.blogspot.com\/2007\/02\/samy-hero-or-villian.html\"><img decoding=\"async\" src=\"http:\/\/www.digg.com\/img\/little-digg.gif\" border=\"0\" alt=\"\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>First thing first. I hate these sites meant for so called &#8220;socializing&#8221;. Sites like: Orkut, MySpace, etc. Ditto with games like SecondLife. Heck Man. Just get out of these places and get a life&#8230;. [Be more like Swen, the GBCD ;)] Anyways. There is this guy who created a, so called, WORM for MySpace. It &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/projectbee.org\/blog\/archive\/samy-a-hero-or-a-villian\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Samy: A hero or a villian!&#8221;<\/span><\/a><\/p>\n","protected":false},"author":6,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[24,168,167],"tags":[36],"class_list":["post-23","post","type-post","status-publish","format-standard","hentry","category-hack","category-security","category-webappsec","tag-myspace"],"aioseo_notices":[],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/pf2XR-n","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/projectbee.org\/blog\/wp-json\/wp\/v2\/posts\/23","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/projectbee.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/projectbee.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/projectbee.org\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/projectbee.org\/blog\/wp-json\/wp\/v2\/comments?post=23"}],"version-history":[{"count":0,"href":"https:\/\/projectbee.org\/blog\/wp-json\/wp\/v2\/posts\/23\/revisions"}],"wp:attachment":[{"href":"https:\/\/projectbee.org\/blog\/wp-json\/wp\/v2\/media?parent=23"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/projectbee.org\/blog\/wp-json\/wp\/v2\/categories?post=23"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/projectbee.org\/blog\/wp-json\/wp\/v2\/tags?post=23"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}