Live data from Hacker News

DOJ Subpoenas Twitter About Five Users Over a Smiley Emoji Tweet

techdirt.com

41–50 of 90 posts

Re: DOJ Subpoenas Twitter About Five Users Over a Smiley Emoji Tweet

#41
post #5

Earlier quoted context omitted.

The problem isn't the government, it's the "citizens." We're a society of cowards, who are afraid of everything and want the government to do something about it. E.g. crime rates are at historic lows, but more than half of Americans say that they worry a "great deal" about crime: http://news.gallup.com/poll/190475/americans-concern-crime-c... . It's not getting any better, it's probably getting worse. We're not that…

Not true that crime rates are at historic lows, particularly violent crime which is over double the 1960 rate: http://www.factcheck.org/2016/07/dueling-claims-on-crime-tre... But if you are in the Chicago area, you should know that like wealth, crime is incredibly unevenly distributed. There are communities that have effectively zero risk of violent crime, and communities within 30min drive that have violent crime ra…

>Not[e] true that crime rates are at historic lows, particularly violent crime which is over double the 1960 rate:

Which ignores the context of the data that while still double the 1960 rate, it is also half the peak 1991 rate, and has generally been decreasing since then. The murder rate is similar to the early 1960's, after it's peak in the 70s/80s.

I have nothing to disagree with your comment on Chicago, which sounds plausibly accurate.

Re: DOJ Subpoenas Twitter About Five Users Over a Smiley Emoji Tweet

#42
post #37

Earlier quoted context omitted.

"unauthorized access" is bs. It was a public ftp server and he notified the owners. It's like telling your neighbor his door is open.

> It's like telling your neighbor his door is open. I think it's more like your neighbors door being open and you going in side and seeing that the refrigerator is open. Therefore proving that you trespassed on private property. Not legal. Of course in most cases you wouldn't be prosecuted for that I would imagine unless you tramped around the house. Article says: "he'd come across an FTP server operated by another d…

Occam's Razor would say he logged in, saw a patient_data directory or something similar, and logged out. We don't know anything really about how his perusal or lack thereof had him come to that conclusion. If it was running batch job processing that places like Epic and others do, it could have a recognizable directory structure that would give it a clear fingerprint.

Re: DOJ Subpoenas Twitter About Five Users Over a Smiley Emoji Tweet

#43
post #20

Earlier quoted context omitted.

That's like saying you looked at my open front door so you committed B&E

Sure, that's one way to look at it. But also, since you have to actually interact with the server in order to discover such vulnerabilities in it, it could also be viewed as similar to walking in through an unlocked door and looking around. That, at least, is trespassing, I believe.

Alright if we want to get specific it's like being blind and touching a home's open front door. Incredulous​ that the door is open you feel around inside for a second and feel a set of keys on the hook. You leave at this point and a week later are arrested for B&E because your fingerprints are on the keys (or you were stupid enough to tell the owner their door was open)

Re: DOJ Subpoenas Twitter About Five Users Over a Smiley Emoji Tweet

#44
post #37

Earlier quoted context omitted.

"unauthorized access" is bs. It was a public ftp server and he notified the owners. It's like telling your neighbor his door is open.

> It's like telling your neighbor his door is open. I think it's more like your neighbors door being open and you going in side and seeing that the refrigerator is open. Therefore proving that you trespassed on private property. Not legal. Of course in most cases you wouldn't be prosecuted for that I would imagine unless you tramped around the house. Article says: "he'd come across an FTP server operated by another d…

First, I don't believe it is against the law to simply connect to a public FTP server. And I'm certain that I wouldn't bother to notify somebody that their public FTP server was... public. However, if I saw something that clearly wasn't supposed to be public.

It's more like looking across the street and seeing a private act through an open window, and going to the front door and knocking and telling them that the window is open.

There are laws against leaving patient data in the public. There are laws against public indecency.

There are also laws against unauthorized access and laws against being a peeping Tom.

Which one is going on is not necessarily easy to determine.

Re: DOJ Subpoenas Twitter About Five Users Over a Smiley Emoji Tweet

#45
post #5

I can't even anymore. If this story is anywhere near true -- and I have no reason to believe it is not -- then what the hell do we as citizens DO about it? How can we put an end to ridiculous infringements on rights and wasteful use of resources? It certainly starts with voting for representatives that won't allow thus, but damn. There aren't a lot of good choices out there. And even if there are, how do we fix the i…

The problem isn't the government, it's the "citizens." We're a society of cowards, who are afraid of everything and want the government to do something about it. E.g. crime rates are at historic lows, but more than half of Americans say that they worry a "great deal" about crime: http://news.gallup.com/poll/190475/americans-concern-crime-c... . It's not getting any better, it's probably getting worse. We're not that…

>The problem isn't the government, it's the "citizens."

The problem is that statement has always been true, even in good times.

Re: DOJ Subpoenas Twitter About Five Users Over a Smiley Emoji Tweet

#46

I used to tell my son that there will always be work for computer security specialists and that he should go for that. This makes me wonder about my advice.

I assume that if you're freelance you're at more risk of finding yourself on the receiving end of a CFAA violation. What I wonder is that if security researchers who work for domestic companies face the same degree of scrutiny that these freelance researchers do. I guess that if you work for a company you're probably not looking at anyone's website that's not explicitly paying you/your company and under some contract…

While what you posted makes sense with the right definitions, I think you might understand better if you're careful with your definitions of "security specialist" (what SubiculumCode said), "security researcher" (what you said), and the other classifications.

Not all specialists or researchers are doing penetration testing. Of those, not all of them are penetration testing third party stuff, and of those, not all of them are doing it without permission. That's the only one that will get you into trouble.

I'm not, technically, a "security specialist" of any stripe, but I take a very careful interest in the defensive side of security, and am currently in the middle of implementing a fairly security-sensitive system. I don't worry that the FBI is going to bust down my door at 2am because I've tweaked the API of my code to make it harder to write cross-site scripting attacks, or because I fixed the architecture so that authentication is done very early in the request cycle instead of ad-hoc and inconsistently very late in the request cycle in a way that requires every developer of every individual web page to have to enforce all authentication. Most security work is going to involve internal matters and the fixing thereto, and, yeah, the job isn't going anywhere any time soon.

(Though it does have the eternal challenge of convincing people they need to pay for it, and the problem that even in companies where programming is the major product like Facebook and Google, you're still going to be a cost center.)

Re: DOJ Subpoenas Twitter About Five Users Over a Smiley Emoji Tweet

#47
post #21

Earlier quoted context omitted.

So he downloaded a list of files. That's like going in the door, opening the refrigerator (or filing cabinet) and making an inventory. The list itself could have private and protected information.

An ftp client downloads a list of files as soon as you connect. It's the same as fat fingering a website in your browser. Are you saying I should go to jail if I type the wrong website, it loads, and it turns out that site was supposed to be "private"? My browser downloaded the home page and all the files on it. What if I click the wrong wifi network and use it all day without noticing? Should I get charged for "unau…

> Are you saying I should go to jail if I type the wrong website

No, I'm not saying anyone should go to jail. The person in question did not do this by mistake though.

In general I'm in agreement with you. I'm just making sure we don't mix analogies. Looking through an open door is not the same as connecting to an FTP server and getting list of files.

Re: DOJ Subpoenas Twitter About Five Users Over a Smiley Emoji Tweet

#48
post #21

Earlier quoted context omitted.

So he downloaded a list of files. That's like going in the door, opening the refrigerator (or filing cabinet) and making an inventory. The list itself could have private and protected information.

An ftp client downloads a list of files as soon as you connect. It's the same as fat fingering a website in your browser. Are you saying I should go to jail if I type the wrong website, it loads, and it turns out that site was supposed to be "private"? My browser downloaded the home page and all the files on it. What if I click the wrong wifi network and use it all day without noticing? Should I get charged for "unau…

Some graphical FTP clients might download a list of files, but certainly not all. It's not a standard part of the protocol to immediately execute 'LIST'.

You may have fat fingered a URL, but your browser still asked for it and any content located there.

I don't agree with prosecution on things like this, but the reality is the best analogies are still doors and locks: My front door is connected to a walkway, which is connected to the public sidewalk. You may see my door is open and unlocked, but you're still trespassing if you walk in. If you did, I may decide not to press charges, but that's my choice. And I'd be mad as hell at anyone who created a law that said I couldn't just because my door is open.

I think the best solution is for people to treat others with a little more goodwill, and find other ways to make society less litigious overall. Unfortunately, corporations drive a lot of that because a corporation's only goal is to make money. People, however, can make different choices.

Re: DOJ Subpoenas Twitter About Five Users Over a Smiley Emoji Tweet

#49

Earlier quoted context omitted.

An ftp client downloads a list of files as soon as you connect. It's the same as fat fingering a website in your browser. Are you saying I should go to jail if I type the wrong website, it loads, and it turns out that site was supposed to be "private"? My browser downloaded the home page and all the files on it. What if I click the wrong wifi network and use it all day without noticing? Should I get charged for "unau…

Some graphical FTP clients might download a list of files, but certainly not all. It's not a standard part of the protocol to immediately execute 'LIST'. You may have fat fingered a URL, but your browser still asked for it and any content located there. I don't agree with prosecution on things like this, but the reality is the best analogies are still doors and locks: My front door is connected to a walkway, which is…

(replying to myself)

After walking away from this I thought of an analogy to fit the other side: Attractive Nuisance

Maybe a security researcher/group/company could sue on behalf of customers affected by an open FTP server because it's an "Attractive Nuisance" on the Internet. Affecting a company's bottom-line is about the only way to get some to take notice.

Post reply on HN