I don't think I can blame a politician for being technically illiterate, especially one that old. But what the heck is up with the state bureaucrats who report to that guy? I mean someone it the freaking state bureaucratic hierarchy should at least be lucid enough to consult someone who has an actual clue about things as these.
I can't stress how differently power works in the Southern States (EDIT: Missouri is a midwestern state officially, but I've always considered it part of the South). It's a very traditional place, where you do not dare contradict, let alone correct, your boss. There is none of this "avoid surrounding yourself with sycophants because they will only tell you what you want to hear" business. There is no upside to speaki…
Governor vows criminal prosecution of reporter who found flaw in state website
241–250 of 705 posts
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#242Earlier quoted context omitted.
Completely tangential, but have you seen LUnix (Little Unix)? It's actually pretty impressive for something on the C64. Full on preemptive multitasking seems pretty impressive for something as little as the Commodore. https://en.wikipedia.org/wiki/LUnix
I hadn't, but I may be trying to rig that up in an emulator later, that seems awesome!
[1] I know LUnix didn't come out until 1993, so it would have been too late to save Commodore, and certainly past the C64's prime. It just demonstrates what the C64 was capable of.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#243After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…
I dunno, this seems pretty normal. Just today news broke that in Germany some guy who found a flaw in a web-shop backend leaking the data of hundreds of thousands of people got raided, because the operator reported him to the police - and somehow both police and state attorney found it wise to prosecute him instead of referring the case to the GDPR officer to fine the operator. It's pretty obvious that when you find…
Huh? This analogy doesn't really make sense. The difference for software is extremely basic: if you publicize a vulnerability immediately, you give more opportunity for it to be exploited while it's being fixed. Malicious actors who hadn't found the vulnerability yet now get it handed to them on a silver platter.
Private notification simply gives the operator a head start on closing the hole before it's more widely known by potential attackers.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#244Earlier quoted context omitted.
Say you are invited to your friends apartment in an apartment building, but none of the apartments have locks. So you decide to open up some other random apartments and look through their things, who is responsible?
That's not even close to the same analogy though. This would be like knocking on the door, asking if you can come in, and the person living there letting you in. Then getting mad about it later even though they let you in.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#245Earlier quoted context omitted.
In real life, if you do it under false pretenses, you are. In this analogy the real-world version would be considered fraud.
Asking for the next file isn't false pretenses. I don't know if this analogy works quite right. Even rifling through a file cabinet wouldn't be false pretenses, it would be something else. And you have to cause injury for it to be fraud. Is "Help I was too honest to a customer." a valid injury claim?
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#246Quote from the St Louis Post Dispatch article is even more groan-worthy: "In the letter to teachers, Education Commissioner Margie Vandeven said “an individual took the records of at least three educators, unencrypted the source code from the webpage, and viewed the social security number (SSN) of those specific educators.” I guess webpages are kinda like encryption for idiots.
> echo json_encode($search_results); This is how I found out how much I, and all other contractors were being paid. And also how much the contracting company was actually charging the clients. All the data was being returned in a json but the very little was being displayed. Looking at the story, this is more of a posture thing. I'm sure the Governor is surrounded with people who can tell him that no hacking took pla…
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#247Re: Governor vows criminal prosecution of reporter who found flaw in state website
#248Earlier quoted context omitted.
The funny thing is, the reporter successfully embarrassed the state, then the state embarrassed itself further in response.
Color me surprised. I really don't understand the whole "double down" approach to doing things.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#249This news should not surprise anybody who has used government websites in Missouri. Here is an example: https://mydssapp.mo.gov/CitizenPortal/application.do The website takes a LONG time to load because of how many javascripts it loads!!
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#250Earlier quoted context omitted.
If I ask you to show me a document, and you willingly show me the document, who exactly is responsible for the disclosure?
Say you are invited to your friends apartment in an apartment building, but none of the apartments have locks. So you decide to open up some other random apartments and look through their things, who is responsible?
We don't need to reach for analogies to observe that while the theoretical ideal is to report it after just one false access, that no significant damage was done by accessing just a few more via human manipulation of the browser URL, with no recording or sharing of the results. From a human perspective, no damage was done.
Whether that legally crosses a line involves a whole lot of details that few, if any people here, will be able to speak to, because of the complication of the law, and HN's conclusion as to the legality is of marginal interest even if someone competent were to give an opinion.
We can speak to the fact that even if it does technically cross a line, a prosecutor really ought to use their discretion to not prosecute since nobody was hurt. We can say that because that's just an opinion. I expect we don't have very many people here who actually want the book thrown here (though, as always, enough read this that it's probably non-zero).