Live data from Hacker News

Teenager facing prison for downloading unsecured files from government website

cbc.ca

111–120 of 502 posts

Re: Teenager facing prison for downloading unsecured files from government website

#111
post #94

Earlier quoted context omitted.

This seems more like a failure to develop proper social norms with regard to Internet information. > If the information is not supposed to be public, it should not be reachable without authorization or authentication. I don't lock my car, and often not my house either. I don't think that means you should be able to snoop around and see what interests you. Websites are private property. It is obvious what parts you're…

But the difference is that a website is built to be publicly accessible on the public internet. Your car, presumably, is not offered as a public resource.

Except this data was obviously not intended to be publicly accessible, or else it would have been reachable from some public-facing portion of the site.

Re: Teenager facing prison for downloading unsecured files from government website

#112
post #6

Since this is publicly accessible, what would be the chance that search engines indexed the files? In this case, would Google bot be charged? Or if this were, say, Equifax or Facebook. I mean, in those situations, the companies were blamed for "the leak". It seems rather convenient to cherry pick the law to apply on this poor teenager.

A quick Google search return some (cached) results: https://webcache.googleusercontent.com/search?q=cache:4N3wSV...

Re: Teenager facing prison for downloading unsecured files from government website

#113

perhaps we need an RFC that defines this type of approach (pages "secured" behind easily guessable urls) as public information.

Instead of actual security why not have a spec for /humans.txt which can say things like "Please don't read anything in the /secret directory."

and what would that achieve? all it's going to do is force companies to add legal boilerplate (eg. those "this message is intended for the recipient only..." that you see in email signatures) to every imaginable place to cover their ass, meanwhile doing nothing to improve security.

Re: Teenager facing prison for downloading unsecured files from government website

#114

Good thing he’s in Canada and only got raided. If he were in the USA, they would have tossed flashbangs and tear gas into his house, vaulted in through the windows, shot the family dog, and held the whole family at gun point, boots on their necks. It’s a shame that police departments think these “shock and awe” tactics are even remotely appropriate for dealing with non-violent suspects.

I don't like or agree with it either, but it is unfortunately necessary for the preservation of digital evidence.

Many nonviolent actors involved in cybercrimes have prepared killswitches or some other manner of instantly burning everything to the ground if you give them enough time to react when you show up with a warrant.

Re: Teenager facing prison for downloading unsecured files from government website

#116
post #94

Earlier quoted context omitted.

This seems more like a failure to develop proper social norms with regard to Internet information. > If the information is not supposed to be public, it should not be reachable without authorization or authentication. I don't lock my car, and often not my house either. I don't think that means you should be able to snoop around and see what interests you. Websites are private property. It is obvious what parts you're…

>I don't lock my car, and often not my house either. I don't think that means you should be able to snoop around and see what interests you. Websites are private property Here's a better analogy; you put up a "yard sale" sign in your front yard, fill the driveway with property, and then call the police on the first person who shows up claiming they are trespassing.

When you put up a "yard sale" sign, you're conveying what is called an "implied license" to access the property. The scope of a trespasser's right to access a property is limited to what a reasonable person would consider to be granted by the license. A reasonable person would assume that a "yard sale" sign grants a license to access the yard on which the sign is posted, but not to go around to the back yard and peek into the basement windows.

A public web page is no different. A reasonable person would not assume that content you can only get to by editing a URL manually is supposed to be accessible to the public. A typical person would not even know that you can do that. Those typical people are the ones that get to set the rules, not hackers.

Re: Teenager facing prison for downloading unsecured files from government website

#117
post #52

Earlier quoted context omitted.

Many UUIDs aren't secure either and can be trivially enumerated. A better approach might be a long number generated using a secure random number generator and converted to a BASE-64 string.

If things should be secure, they should be behind authentication and authorization for that content. To argue about what is the best ID to be used is just trying to fix what is not broken, IMHO.

Security is multi layered.

Re: Teenager facing prison for downloading unsecured files from government website

#118
post #4

This reads like the beginning of The Hacker Crackdown.. As a Canadian, reading this article made me angry. If the information is not supposed to be public, it should not be reachable without authorization or authentication. Never mind a curious 19-year-old, there are tons of crawlers and indexers out there that attempt to enumerate URLs where they think there might be other content. Shame on them for building a poorl…

I already play with urls that have possible id's in them out of habit. The only difference here is the poor kid was on a gov website and they did not want the information he found to be public. ( Or like in the USA he might have to pay for each document accessed. But I feel that should not result in a raid to his house.) It is a shame the kid was their target and not a google bot like you said.

Googlebot has the resources to fight back against government attacks.

Re: Teenager facing prison for downloading unsecured files from government website

#119
post #91
post #55

This might be a controversial opinion here, but intent does matter. If I see a bunch of stuff sitting the sidewalk and I take some because I think it's free, that's a reasonable thing to do. But going into someone's house and taking their tv is not. "It's their own fault for not locking the door" isn't a valid legal defense, and I would prefer not to live in a country where victim-blaming becomes a get-out-of-jail-fr…

You can find some documents from https://foipop.novascotia.ca in Google cache, so should Google be sued too?

[deleted]

Re: Teenager facing prison for downloading unsecured files from government website

#120
post #64

Earlier quoted context omitted.

Since it helps the older generation to think about digital content in metaphors, I'd argue that the kid was entering through an open window of a public building. Although a bit strange, no one would give this hypothetical person a third look.

I think the most precise metaphor is: a kid walked through the front door of a public library, borrowed a couple freely available books, then the government realized those books mistakenly included sensitive information. In order to address that error, 15 police officers raided the kid's house.

That would be an accurate analogy if these documents were linked to from a publicly-accessible portion of the site. They were not. This is more like someone walking into an unlocked back room and grabbing books that hadn't been shelved.
Post reply on HN