What if Tribune had a sister company in some other country (Australia) that did something completely unrelated. Sell children's toys or something.
An admin for the sister company gives up his credentials in order for Anonymous to deface the children's site. They instead use it to deface the Chicago Tribune.
The admin has no earthly clue that the systems are inter-related. In fact, they've been told that the systems are independent by design; anonymous found a very clever flaw.
Is he as guilty as your hypothetical Tribune admin who gave up his password to deface the Tribune?
As I understand it, he's guilty, but potentially not as guilty.
He's an accomplice if he understood the goals of Anonymous, gave them credentials to further their acts, but didn't map out with them exactly what they were going to do --- accomplice liability is for all intents in purposes liability.
On the other hand, if he casually gave them credentials because what the fuck who cares, and had no understanding that Anonymous might deface a website, he have lesser liability, or might not be liable for the defacement of the website while remaining liable for a reduced or lesser number of CFAA charges.
What if Tribune had a sister company in some other country (Australia) that did something completely unrelated. Sell children's toys or something.
An admin for the sister company gives up his credentials in order for Anonymous to deface the children's site. They instead use it to deface the Chicago Tribune.
The admin has no earthly clue that the systems are inter-related. In fact, they've been told that the systems are independent by design; anonymous found a very clever flaw.
Is he as guilty as your hypothetical Tribune admin who gave up his password to deface the Tribune?