I feel there's an enormous education/awareness gap when it comes to basic security practices and it's going to hurt all of us sooner or later by having our private information leaked, sold, abused, maybe ultimately deemed irrelevant in itself -- ie what would the world look like if all (or a significant chunk) of private information was leaked and you couldn't trust the old tokens of identity?
Governor vows criminal prosecution of reporter who found flaw in state website
231–240 of 705 posts
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#232Earlier quoted context omitted.
I think "view source" was actually invented by the Russians, then leaked by "4chan" - They're an individual, not a group. You probably got it mixed up with Lunix, that was invented by "4chan".
Completely tangential, but have you seen LUnix (Little Unix)? It's actually pretty impressive for something on the C64. Full on preemptive multitasking seems pretty impressive for something as little as the Commodore. https://en.wikipedia.org/wiki/LUnix
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#233Earlier quoted context omitted.
Nearly all politicians act like this when they're in power. The general public is easily mislead. HN notices it when it's a tech issue, but it happens in economics, medicine, basically everywhere. They have zero incentives to accept responsibility.
Nearly all politicians prosecute reporters? No, I'm pretty sure that is just the fascists.
Was Obama a fascist? I have no desire to engage in whataboutism, they all show their true colors when they're in power and shown corrupt or incompetent.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#234After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…
> After I shopped a few other companies to see how our plans compared Yeah once you start using a vulnerability maliciously to obtain confidential data for your own personal gain, even if its a stupid vulnerability, you're not really good-guy security researcher anymore. If all you did was the bare minimum to demonstrate the vuln exists, that's cool. If after you do that you continue to use it to obtain confidential…
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#235Earlier quoted context omitted.
> After I shopped a few other companies to see how our plans compared Yeah once you start using a vulnerability maliciously to obtain confidential data for your own personal gain, even if its a stupid vulnerability, you're not really good-guy security researcher anymore. If all you did was the bare minimum to demonstrate the vuln exists, that's cool. If after you do that you continue to use it to obtain confidential…
You lost me at "maliciously". What harm was done by someone comparing prices? What organization lost money? Who got worse health service? "Unethical" and malicious is the current, profit-driven health insurance system. I know you're coming at it from an absolutist perspective, but I disagree entirely with passing judgement. Furthermore, the fact that you seem more upset with the person who glanced at a few plan price…
It removes the information asymmetry, which protect the profits of the seller.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#236Earlier quoted context omitted.
In real life, if you do it under false pretenses, you are. In this analogy the real-world version would be considered fraud.
Asking for the next file isn't false pretenses. I don't know if this analogy works quite right. Even rifling through a file cabinet wouldn't be false pretenses, it would be something else. And you have to cause injury for it to be fraud. Is "Help I was too honest to a customer." a valid injury claim?
If you convince them that you really are X and they give you the file, i think that would be considerd fraudulent. Whether or not an injury takes place to raise it to the level of fraud i guess depends on what was in the file, but in countries with strong privacy laws, someone would probably be in a heap of trouble.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#237After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…
I dunno, this seems pretty normal. Just today news broke that in Germany some guy who found a flaw in a web-shop backend leaking the data of hundreds of thousands of people got raided, because the operator reported him to the police - and somehow both police and state attorney found it wise to prosecute him instead of referring the case to the GDPR officer to fine the operator. It's pretty obvious that when you find…
If one contacts the corrupted major for a timed disclosure, he gets time to hide crimes or can continue being corrupted, but the press running the story only damages the major.
If I run to the press with a vulnerability, everyone is empowered in exploiting it. Sure it puts lots of pressure on the devs, but devs can only work so fast, which creates a window of opportunity which damages both them and their users. A timed disclosure doesn't prevent exploitation that's already happening, but doesn't increase the problem by itself
The desired outcomes in the two cases are different, and it's no surprise different strategies are optimal.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#238Quote from the St Louis Post Dispatch article is even more groan-worthy: "In the letter to teachers, Education Commissioner Margie Vandeven said “an individual took the records of at least three educators, unencrypted the source code from the webpage, and viewed the social security number (SSN) of those specific educators.” I guess webpages are kinda like encryption for idiots.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#239Earlier quoted context omitted.
I dunno, this seems pretty normal. Just today news broke that in Germany some guy who found a flaw in a web-shop backend leaking the data of hundreds of thousands of people got raided, because the operator reported him to the police - and somehow both police and state attorney found it wise to prosecute him instead of referring the case to the GDPR officer to fine the operator. It's pretty obvious that when you find…
Domestic abuse is pretty "normal" too. That doesn't make it tolerable.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#240Earlier quoted context omitted.
Nearly all politicians prosecute reporters? No, I'm pretty sure that is just the fascists.
Substitute whistleblower for reporter and yes, nearly all politicians will use the criminal justice system to silence their critics. Was Obama a fascist? I have no desire to engage in whataboutism, they all show their true colors when they're in power and shown corrupt or incompetent.
Then don't.
I think Snowden should be pardoned and considered a national hero, but he unquestionably committed a very serious crime. There was no crime committed in the State of Missouri on this matter.