Forget Disclosure — Hackers Should Keep Security Holes to Themselves
Hackers Should Keep Security Holes to Themselves — Editor's Note: The author of this opinion piece, aka “weev,” was found guilty last week of computer intrusion for obtaining the unprotected e-mail addresses of more than 100,000 iPad owners from AT&T's website, and passing them to a journalist.
Context & Ripple Effects
Ten days after a jury found him guilty of computer intrusion — coverage of the verdict noted he had pulled more than 100,000 iPad owners' e-mail addresses off AT&T's website and handed them to a journalist — weev takes to Wired's opinion pages to argue that hackers should keep security holes to themselves entirely.
The piece converts his criminal case into a referendum on disclosure itself: the same act that produced the prospect of prison time is recast as proof that disclosing flaws to the public earns researchers prosecution rather than thanks.
First-order effects
- weev heads into sentencing with the conviction standing, and his op-ed now frames the case as a test of whether touching an unprotected web endpoint counts as intrusion at all.
- AT&T gets its answer on the iPad exposure — the addresses were harvested and published — but the precedent that accessing a publicly reachable page can support a felony charge lands on every security researcher probing carrier and consumer-web infrastructure.
Second-order effects
- Researchers weighing whether to report vendor flaws now price in prosecution risk alongside the fix, pushing disclosure toward quiet, negotiated channels rather than public write-ups like the one that triggered this case.
- Vendors such as AT&T lose the reputational pressure that forced rapid patches when flaws went public, shifting more of the cost of unpatched holes onto their own customers.
Third-order effects
- If convictions like this one hold, vulnerability handling migrates structurally out of public disclosure and into private markets and insider knowledge, weakening the informal research-to-vendor pipeline that has kept consumer web services patched.
- Courts and Congress face mounting pressure to define 'unauthorized access' precisely, because a standard that criminalizes reading an unprotected page makes ordinary security testing legally indistinguishable from intrusion.
The trend: Prosecutorial charging decisions, not researcher ethics, are becoming the force that redraws vulnerability disclosure norms — pushing flaw reports away from public channels and toward private, legally safer arrangements.