Live data from Hacker News

Weleakinfo.com Domain Name Seized: Site Had Sold Access to Hacked PII and Logins

justice.gov

11–14 of 14 posts

Re: Weleakinfo.com Domain Name Seized: Site Had Sold Access to Hacked PII and Logins

#11
post #6

At what point do security dumps become 'public' and legal to disseminate? Is there a framework for determining what is legal to provide to Brian Krebs or Haveibeenpwned.com? Would it have been illegal of Brian Krebs to pay money to weleakinfo.com for a database that also existed elsewhere? Basically is it illegal to buy, sell, give away for free to masses, give away for free to vetted individuals/researchers, or ille…

I asked a lawyer friend this question once before starting on a personal project. The answer I got in return took about 30 minutes and was filled with a lot of "ifs" and "buts" and references to at-that-time undecided cases.

That lawyer must be a very good friend indeed. It sounds like a lot of research to yield that kind of answer.

Re: Weleakinfo.com Domain Name Seized: Site Had Sold Access to Hacked PII and Logins

#12
post #6

At what point do security dumps become 'public' and legal to disseminate? Is there a framework for determining what is legal to provide to Brian Krebs or Haveibeenpwned.com? Would it have been illegal of Brian Krebs to pay money to weleakinfo.com for a database that also existed elsewhere? Basically is it illegal to buy, sell, give away for free to masses, give away for free to vetted individuals/researchers, or ille…

>US/EU, and other laws all seem relevant.

What does this mean? In the US there is no law for this.

In the EU we have the GDPR which says you never get to own or control someone else's personal information without their permission.

Just because the info is leaked, that doesn't make it public domain. The data still belongs to the user, and the people that hold it should only ever be doing so with permission.

Re: Weleakinfo.com Domain Name Seized: Site Had Sold Access to Hacked PII and Logins

#13
post #6

At what point do security dumps become 'public' and legal to disseminate? Is there a framework for determining what is legal to provide to Brian Krebs or Haveibeenpwned.com? Would it have been illegal of Brian Krebs to pay money to weleakinfo.com for a database that also existed elsewhere? Basically is it illegal to buy, sell, give away for free to masses, give away for free to vetted individuals/researchers, or ille…

>US/EU, and other laws all seem relevant. What does this mean? In the US there is no law for this. In the EU we have the GDPR which says you never get to own or control someone else's personal information without their permission. Just because the info is leaked, that doesn't make it public domain. The data still belongs to the user, and the people that hold it should only ever be doing so with permission.

>>US/EU, and other laws all seem relevant. >What does this mean?

For context, the US has arrested people who have never set foot in the US and held no assets in the US ... for breaking US law. So when it comes to "the internet" nowadays I assume I have to comply with all major countries' law, not just my own (USA). Or at least it could be helpful to know other countries laws (EU) as they compare to my own (USA).

> In the US there is no law for this.

If the FBI seized the website, I would be led to assume there's probably at least one law covering it.

> The data still belongs to the user

If I'm one of the affected users, can I see what of my data was leaked? Wouldn't I have to download the leaked data to do that? Would that be legal to download? Would it be legal for someone else to provide my own leaked data to me?

> the people that hold it should only ever be doing so with permission.

This would make http://haveibeenpwned.com/ and Google Chrome's password checker illegal -- and probably 90% of security researchers would be outlaws. That seems like an untenable policy position.

Re: Weleakinfo.com Domain Name Seized: Site Had Sold Access to Hacked PII and Logins

#14

Earlier quoted context omitted.

>US/EU, and other laws all seem relevant. What does this mean? In the US there is no law for this. In the EU we have the GDPR which says you never get to own or control someone else's personal information without their permission. Just because the info is leaked, that doesn't make it public domain. The data still belongs to the user, and the people that hold it should only ever be doing so with permission.

>>US/EU, and other laws all seem relevant. >What does this mean? For context, the US has arrested people who have never set foot in the US and held no assets in the US ... for breaking US law. So when it comes to "the internet" nowadays I assume I have to comply with all major countries' law, not just my own (USA). Or at least it could be helpful to know other countries laws (EU) as they compare to my own (USA). > In…

>For context, the US has arrested people who have never set foot in the US and held no assets in the US ... for breaking US law.

What are you talking about?

Post reply on HN