Live data from Hacker News

Teenager facing prison for downloading unsecured files from government website

cbc.ca

431–440 of 502 posts

Re: Teenager facing prison for downloading unsecured files from government website

#431
post #422

Earlier quoted context omitted.

> It's also obvious in any case that stories, comments, jobs, ask HNs and polls are intended to be public. > it was far less obvious that the relevant documents were intended to be publicly available My browser and the respective HTTP servers consider them equally obvious publicly available.

But it's not your browser or the HTTP servers that are being prosecuted. Browsers and HTTP servers don't 'consider' anything.

> HTTP servers don't 'consider' anything.

Of course they do. They consider whether or not to give me access. If they respond with 200, they are effectively telling me that the information is public and the request is approved. There's no law moral or legal that stops me from asking for information.

I could ask a law agent for classified information, but he's not going to prosecute me for asking questions. He could be suspicious and ask "how do you know a document with that number exists?". And I can reply "oh, I'm just asking for random numbers".

Re: Teenager facing prison for downloading unsecured files from government website

#432
post #173
post #19

And this is why I'm going to route all my kids traffic through an offshore VPN by default and whitelist low latency stuff.

I've been thinking I wanted a router with two wi-fi networks. One that goes through the ISP and one that goes out over a proxy. I haven't found a solution just yet. I guess a raspberry pi with iptables and routing based on device ID could do the trick too.

I use the following configuration:

I run two tinyproxy instances on my home server and I point all browser traffic to the first instance. The first instance run with the default routing table on port 8888 and has entries like upstream localhost:8889 ".somesite.com" the second instance, which run on port 8889 is run with the vpn as default route (I use setfib under FreeBSD).

With this setup, traffic goes by default directly on the net, but the tinyproxy config file can be used to redirect some traffic through the VPN.

Of course, you can do it the other way around to have traffic by default on the VPN and direct some traffic.

Re: Teenager facing prison for downloading unsecured files from government website

#433
post #323

Earlier quoted context omitted.

I'm just surprised they didn't "redact" the documents by drawing black boxes over top of text in the Adobe Acrobat PDF editing tool... If their web presence is that clueless it seems like exactly the sort of thing that would happen. https://www.schneier.com/blog/archives/2005/05/pdf_radacting...

Something similar happened in Australia last year. Federal Government ministers all have their phone bill summaries released as part of public record with private information removed. https://www.sbs.com.au/news/how-hundreds-of-parliamentary-mo... The contractor redacted the phone numbers in this instance by changing the font colour to white (same as the background) in the PDFs uploaded to the government disclosure w…

. The large percentage of people are still clueless these days.

Re: Teenager facing prison for downloading unsecured files from government website

#434
post #381

Earlier quoted context omitted.

>Federal Government ministers all have their phone bill summaries released as part of public record with private information removed Why?

Because they want a phone line that they can talk to their spouse and children without having to field thousands of calls from well-meaning people who want to wish them a good day?

Lmao. "Wishing to mean them a good day"? Really?

Re: Teenager facing prison for downloading unsecured files from government website

#435
post #422

Earlier quoted context omitted.

But it's not your browser or the HTTP servers that are being prosecuted. Browsers and HTTP servers don't 'consider' anything.

> HTTP servers don't 'consider' anything. Of course they do. They consider whether or not to give me access. If they respond with 200, they are effectively telling me that the information is public and the request is approved. There's no law moral or legal that stops me from asking for information. I could ask a law agent for classified information, but he's not going to prosecute me for asking questions. He could be…

You can describe what a webserver does in anthropomorphic terms if you like, but it's not the webserver's "intentions" that are relevant. It's the intentions of the people who control the website and the intentions of the person who accesses it.

>There's no law moral or legal that stops me from asking for information.

I wouldn't be so confident of that if you haven't read up on the relevant laws. Many countries have prohibitions against unauthorized access that apply in circumstances where the access is not "unauthorized" in a technical sense relating to the details of the HTTP protocol. The law doesn't necessarily say what you would want it to say or what you would expect it to say. See e.g. the following example from the US. (I'm aware that the incident we're discussing occurred in Canada.)

https://motherboard.vice.com/en_us/article/wnxg94/password-s...

Re: Teenager facing prison for downloading unsecured files from government website

#436

Seems like a move by the provincial government to shift blame from its poor security to an imaginary bad actor; this article also from the CBC goes into more detail and asserts that fraudulent intent is necessary for a conviction, so hopefully this goes nowhere. http://www.cbc.ca/news/canada/nova-scotia/concerns-teen-bein...

Yes, it's really not clear that any crime was committed. The relevant section of the Canadian Criminal Code[1] requires either fraudulent intent or some actual manipulation/destruction of the server - not simply downloading data. It seems like overreach by the police to distract from the fact that the government failed to secure private data. [1] http://laws-lois.justice.gc.ca/eng/acts/C-46/section-342.1.h...

> The relevant section of the Canadian Criminal Code[1] requires either fraudulent intent or some actual manipulation/destruction of the server.

Not quite. The test is:

> Everyone is guilty... who, fraudulently and without colour of right, obtains, directly or indirectly, any computer service (including... the storage or retrieval of computer data)

The Crown can argue that the documents were retrieved/obtained using manipulation of the server (since the public URLs were manipulated to find non-public URLs.)

Re: Teenager facing prison for downloading unsecured files from government website

#437

Earlier quoted context omitted.

You're not. Ordinary people don't even know that you can do that.

You are saying that ordinary people don't know what a URL actually is. This is ridiculous. It takes a certain level of computer illiteracy to never notice that you can access stuff by typing into the address bar directly, or by modifying what's already there. It also doesn't take a computer whiz to use DownThemAll to enumerate URLs and download them all. They even have a dedicated function for this! Yes, one does hav…

Well maybe you shouldn't be using antisocial hacker tools like DownThemAll! An ordinary user would never use such tools. /s

Incrementing URLs by hand is one of the ways I learned about how the internet works, as a young kid. Kids are curious. This is normal behavior!

Re: Teenager facing prison for downloading unsecured files from government website

#438

Earlier quoted context omitted.

And the cries by old geezers in charge, yet clueless of what it is they’re “in-charge of”, that he stole it are eye rolling It’s ageism but at this point I’m pretty convinced old people should be term limited from office The problems we seem to be facing are almost entirely due to their inability to move on Youth shouldn’t spend their lives kowtowing to geezers that quit thinking and are simply peddling what’s become…

I'm not sure about age-limiting old people, but I'm starting to think a basic technological literacy test might not be out of place.

If there's two things people in tech seem to vastly underestimate it's how many old people are technologically literate and how many young people are technologically illiterate. I wouldn't be surprised if there are correlations but you're right, age itself isn't the issue.

Re: Teenager facing prison for downloading unsecured files from government website

#439
post #424

Earlier quoted context omitted.

But...you would have left the diamond ring by accident. Files don't "accidentally" become publicly accessible via HTTP. i.e. you don't return to your computer one day to find everything is public. Someone specifically took the steps to make this data public. The fact they didn't realize what they were doing isn't the fault of people that then view the data.

>Files don't "accidentally" become publicly accessible via HTTP Hmm? It's certainly possible to configure a web server incorrectly by accident.

That's true.

But as the person knows they are configuring a web server, I would say this is more carelessness / incompetence rather than an "accident" in the same way as losing a Diamond Ring would be.

Re: Teenager facing prison for downloading unsecured files from government website

#440
post #435

Earlier quoted context omitted.

> HTTP servers don't 'consider' anything. Of course they do. They consider whether or not to give me access. If they respond with 200, they are effectively telling me that the information is public and the request is approved. There's no law moral or legal that stops me from asking for information. I could ask a law agent for classified information, but he's not going to prosecute me for asking questions. He could be…

You can describe what a webserver does in anthropomorphic terms if you like, but it's not the webserver's "intentions" that are relevant. It's the intentions of the people who control the website and the intentions of the person who accesses it. >There's no law moral or legal that stops me from asking for information. I wouldn't be so confident of that if you haven't read up on the relevant laws. Many countries have…

> You can describe what a webserver does in anthropomorphic terms if you like, but it's not the webserver's "intentions" that are relevant. It's the intentions of the people who control the website and the intentions of the person who accesses it.

And how do you prove intent? This is a technical problem with technical protocols involved. Intent should be provided via the protocol. If the protocol says resources are public, unless otherwise stated, you can't rely on a human to answer, post factum, what resource is private.

Post reply on HN