GOATSE SECURITY▊
A handful of trolls with a shock-site name and a slogan — "Gaping Holes Exposed" — found that AT&T's own iPad sign-up page would cough up any owner's email address if you fed it a valid device serial number. So they wrote a script and fed it 114,000 of them, scooped up the inboxes of CEOs, generals, and White House staff, and handed the list to a Gawker reporter before telling AT&T. One member did federal time under a computer-crime law written for a different era — until a federal appeals court threw the whole conviction out on a technicality that wasn't a technicality at all. The case became the fault line in a fight that still isn't settled: is poking a public URL a crime, or is it journalism?
All data was gathered from a public webserver with no password, accessible by anyone on the Internet. … We disclosed only to a single journalist and destroyed the data afterward. We did the right thing.
Goatse Security, "A response to AT&T's letter," security.goatse.fr, June 14, 2010 — their own defense of the disclosure, days after the breach hit the press
- WHO
- Goatse Security — a self-described "grey hat" research crew, described as a nine-person outfit and a division of the trolling organization GNAA; named for the Goatse.cx shock site, slogan "Gaping Holes Exposed" FACT
- PRINCIPALS
- Andrew "weev" Auernheimer and Daniel Spitler — both named in the public court record for the AT&T case
- THE DRAMA
- Found that a public AT&T endpoint returned an iPad owner's email for any valid ICC-ID; enumerated ~114,000 of them; handed the list to Gawker; got prosecuted for it
- RECORD
- Auernheimer convicted Nov 2012 (CFAA conspiracy + identity fraud), sentenced to 41 months; Spitler pleaded guilty, sentenced to three years' probation. Conviction VACATED on venue grounds, 2014 FACT
- STATUS
- VACATED — a landmark in the "is finding a flaw in a public URL a crime?" fight; the emails were real, and so was the reversal
This file is a case record, not a character study. The intrusion was real and the prosecution was real; so was the fact that the "server" in question was a public web page with no password on it, and so was the appeals court's decision to erase the conviction. The through-line is the gap between two true stories: a trolling crew that grabbed a hundred thousand strangers' email addresses and gave them to a gossip site to make a splash — and a government that stretched a venue rule and an aging computer-crime statute far enough that a federal appeals court reeled it back in. Both are in the paperwork.
the drama timeline
ACT I — THE HOLE IN THE PAGE (JUNE 2010)
AT&T built a convenience into its iPad sign-up page. Goatse Security noticed it was a door.
-
EARLY JUN 2010
The prepopulated email
To make logging in easier, AT&T's iPad-registration website prepopulated the user-ID field with a customer's email address whenever it received that iPad's ICC-ID — the serial number on the device's SIM. Feed the public page a valid ICC-ID over the open Internet, and it handed back the matching email. No password was involved. As the appeals court later put it, the tool "simply accessed the publicly facing portion of the login screen and scraped information that AT&T unintentionally published."
-
JUN 5–8, 2010
The account slurper
Daniel Spitler wrote a script — the "account slurper" — that guessed ICC-IDs across their predictable numeric range and saved every email address the page leaked. Auernheimer, per the court, "helped him to refine" it. Guessing serial numbers at scale is what the industry calls a brute-force attack. Between June 5 and June 8, the program collected 114,000 email addresses — among them government, military, media, and corporate accounts.
ACT II — THE DISCLOSURE (JUNE 9, 2010)
They didn't file a bug report. They called a reporter.
-
JUN 9, 2010
"Apple's Worst Security Breach"
Auernheimer emailed members of the media to publicize the find; one who bit was Ryan Tate of Gawker. To prove the story, Auernheimer shared the list. Tate published on June 9 under the headline "Apple's Worst Security Breach: 114,000 iPad Owners Exposed," with the addresses redacted. Some journalists Auernheimer contacted tipped off AT&T, which fixed the endpoint immediately. The order of operations — press first, vendor second — is the single fact both sides of the later fight kept returning to.
-
JUN 14, 2010
The crew answers AT&T
After AT&T emailed its customers characterizing the episode as a malicious act, Goatse Security fired back in a public post: the data "was gathered from a public webserver with no password," they had disclosed "only to a single journalist" and "destroyed the data afterward," and "people in critical positions have a right to completely understand the scope of vulnerability immediately." Their frame: responsible-ish disclosure of AT&T's own flaw. The FBI opened an investigation the same week.
ACT III — THE PROSECUTION (2011–2013)
The government did not see disclosure. It saw unauthorized access — and charged it in New Jersey.
-
2011–12
Two counts in Newark
A federal grand jury in Newark returned a two-count indictment charging Auernheimer with conspiracy to violate the Computer Fraud and Abuse Act (18 U.S.C. § 1030) and identity fraud (18 U.S.C. § 1028(a)(7)). Neither man had been in New Jersey; the AT&T servers were in Texas and Georgia; the Gawker reporter, wherever he was, was not in New Jersey either. Spitler, charged separately, pleaded guilty.
-
NOV 20, 2012
Convicted
A jury found Auernheimer guilty on both counts — one count of identity fraud and one of conspiracy to access a computer without authorization. The security-research community read it as a warning shot: a man convicted of a felony for scraping a page that returned data to anyone who asked.
-
MAR 18, 2013
41 months
Auernheimer was sentenced to 41 months in federal prison, three years' supervised release, and roughly $73,000 in restitution to AT&T. He delivered a defiant pre-sentencing speech — "the Internet will topple governments" — and began serving. Spitler, who had cooperated, drew three years' probation.
ACT IV — THE VACATUR (APRIL 11, 2014)
The Third Circuit never reached the question everyone wanted answered. It didn't have to.
-
APR 11, 2014
Wrong court, whole thing gone
The U.S. Court of Appeals for the Third Circuit, in an opinion by Judge Chagares, held that venue in New Jersey was improper — none of the essential conduct occurred there — and vacated the conviction entirely (United States v. Auernheimer, 748 F.3d 525). Venue, the court wrote, is "more than a technicality," touching "the fair administration of criminal justice and public confidence in it," and "especially" so "in the era of mass interconnectivity." In passing, the court noted the account slurper never "breached any password gate or other code-based barrier" — the observation the disclosure-law fight has cited ever since.
-
APR 2014
Out of prison, into the canon
Auernheimer, represented on appeal by the Electronic Frontier Foundation (with attorney Orin Kerr arguing and amici from Mozilla, security researchers, and defense-lawyer groups), walked out of federal prison. EFF's Hanni Fakhoury said the prosecution "presented real threats to security research." Auernheimer would later become a notorious and controversial public figure for reasons well outside this case — that turn is documented in his fuller profile at thefire.lol, and is not the subject of this file.
both sides, on the record
The government's case: this was unauthorized access, not research. Goatse Security wrote a program whose only purpose was to harvest data AT&T never meant to publish, ran it 114,000 times, and the emails themselves were the payload — personal identifying information taken at scale. A jury agreed and convicted on both counts.
The disclosure was self-serving: they went to Gawker before AT&T, shared the actual list to "lend credibility" to the story, and named the crew after a shock site with a slogan about exposing holes. On the government's read, the "responsible disclosure" frame was a costume worn over a publicity stunt that dumped 114,000 people's data into a reporter's inbox.
It was a public URL: there was no password, no lock, no "breach" in any technical sense — the appeals court itself found the tool only "scraped information that AT&T unintentionally published." Punishing someone for reading a page the company left open, the defense argued, criminalizes ordinary web research [1].
AT&T's flaw, disclosed: Goatse Security's account is that they found AT&T's mistake, told a journalist, destroyed the data, and forced a fix — a service, not a crime. EFF and a bench of security researchers backed the appeal precisely because the prosecution "presented real threats to security research" [3].
The conviction did not survive: a federal appeals court vacated it. Whatever the conduct was, the record now shows one man served over a year for a felony that no longer exists on his sheet, on a charge a court said was brought in the wrong place under a statute stretched past its seams [1].
YOU DECIDE
The trolls grabbed 114,000 strangers' email addresses and gave them to a gossip site to make a point, and the point was partly "look how clever we are." That is not nothing. But the thing they exploited was a public page with no password, the company's own error, and the felony conviction the government won for it was erased by a federal appeals court that found the case shouldn't have been in that courtroom at all. Strip away both the crew's self-mythology and the prosecutor's press release and you are left with the question the courts still haven't cleanly answered: when a website hands data to anyone who asks, is taking it a crime — or is it just reading?
The archive keeps the account slurper — and the opinion that vacated the sentence for running it.
evidence locker
PRIMARY / COURT RECORD
United States v. Auernheimer, 748 F.3d 525 (3d Cir. 2014) FACT — the full Third Circuit opinion (No. 13-1816, Chagares, J., filed Apr 11, 2014): how the AT&T endpoint worked, the account slurper, the 114,000 count (June 5–8, 2010), the Gawker disclosure, the two counts (CFAA § 1030 conspiracy + § 1028(a)(7) identity fraud), the 41-month sentence, the "publicly facing…no password gate" finding, and the venue holding that vacated the conviction.
www2.ca3.uscourts.gov/opinarch/131816p.pdf
Electronic Frontier Foundation — US v. Andrew Auernheimer (case page) FACT — case docket, the 41-month March 2013 sentence, the April 2014 reversal, and the amicus briefs (Mozilla, security researchers, NACDL, Digital Media Law Project).
eff.org/cases/us-v-auernheimer
FIRST-PARTY & CONTEMPORANEOUS REPORTING
Goatse Security — "A response to AT&T's letter" ATTRIBUTED — first-party; the crew's own June 14, 2010 defense ("public webserver with no password," "disclosed only to a single journalist," "destroyed the data afterward").
security.goatse.fr/a-response-to-atts-letter
Gawker — "Apple's Worst Security Breach: 114,000 iPad Owners Exposed" (Ryan Tate, Jun 9, 2010) ATTRIBUTED — the original disclosure story, via the Wayback Machine (the live gawker.com URL is dead).
web.archive.org — gawker.com/5559346 (archived)
The Register — "Weev gets 41 months in prison" (Mar 18, 2013) ATTRIBUTED — the sentencing and Auernheimer's defiant courtroom speech.
theregister.com — 2013/03/18
Wikipedia — Goatse Security ATTRIBUTED — the crew's origin as a GNAA division, the Goatse.cx-derived name and "Gaping Holes Exposed" slogan, the nine-person grey-hat description, and the Nov 20, 2012 conviction date.
en.wikipedia.org/wiki/Goatse_Security
CONTEXT & CROSS-LINKS
thefire.lol — weev (fuller profile) CROSS-LINK — the standalone biography of Andrew Auernheimer, including the later public turn deliberately kept out of this case file.
thefire.lol/profiles/weev/
The standard. The AT&T iPad case is a matter of public court record; the indictment, the conviction, the 41-month sentence, and the 2014 vacatur are stated as fact and sourced to the Third Circuit's own opinion. Andrew Auernheimer and Daniel Spitler are named because the court and the Justice Department named them. The competing characterizations — "responsible disclosure of AT&T's flaw" versus "unauthorized access, and the emails were the crime" — are given as the two attributed sides of a live legal dispute, never adopted as this file's voice. This is the crew/case record only; Auernheimer's later, unrelated public conduct is documented in his fuller thefire.lol profile and is not litigated here. If a line here couldn't survive scrutiny, it wouldn't be on the page.