Live data from Hacker News

Governor vows criminal prosecution of reporter who found flaw in state website

missouriindependent.com

261–270 of 705 posts

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#261

Earlier quoted context omitted.

Say you are invited to your friends apartment in an apartment building, but none of the apartments have locks. So you decide to open up some other random apartments and look through their things, who is responsible?

I think in this example both are equally responsible: 1. People who kept their doors unlocked 2. Person who randomly entered doors & found things. We need to take care of security of our properties, though stealing is wrong.

Nope, opening an unlocked door is still considered break&enter. AFAIK, the "unlocked door" can even be a beaded curtain. Turns out that the legal definition of "break" in this context is extremely old and doesn't correspond to lay usage anymore.

But I think that a better analogy would be asking the apartment manager to see your payment history and getting handed the entire apartment building's ledger.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#262

Quote from the St Louis Post Dispatch article is even more groan-worthy: "In the letter to teachers, Education Commissioner Margie Vandeven said “an individual took the records of at least three educators, unencrypted the source code from the webpage, and viewed the social security number (SSN) of those specific educators.” I guess webpages are kinda like encryption for idiots.

You left out the best bit: "through a multi-step process"

Nice catch... Unbelievable. What isn't a multi-step process, really? The first thing I do in the morning is to make coffee and though I've distilled that process down to its bare minimum so I can do it while still half asleep, it is still very much a multi-step process...

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#263
post #77

Earlier quoted context omitted.

“I’m going to weaponize the law because you embarrassed us.”

I can't imagine that a large, national organization like the ACLU or CPJ would want to dump tons of money into making this a massive national story should that happen... Someone about to experience the Streisand effect in FULL force.

In a state like Missouri getting sued by the ACLU is probably something that can be used to win an election and is seen as a badge of honor. They probably welcome it and all it costs them is tax payer dollars. They really just need to publicize any controversial party the ACLU represented and claim to be standing up to the sorts of people that would defend that behavior.

If they lose in court it turns into a two for one as they get to rail against 'activist judges' and whip their base to go out and vote.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#264
post #34

I don't think I can blame a politician for being technically illiterate, especially one that old. But what the heck is up with the state bureaucrats who report to that guy? I mean someone it the freaking state bureaucratic hierarchy should at least be lucid enough to consult someone who has an actual clue about things as these.

> I don't think I can blame a politician for being technically illiterate, especially one that old.

I certainly can. They have plenty of money to hire staff, and that should include people to make sure they understand the technology that is integral to the every day lives of their constituents, or at least to push back when they do/say something completely counter to how the world works.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#265

Earlier quoted context omitted.

> After I shopped a few other companies to see how our plans compared Yeah once you start using a vulnerability maliciously to obtain confidential data for your own personal gain, even if its a stupid vulnerability, you're not really good-guy security researcher anymore. If all you did was the bare minimum to demonstrate the vuln exists, that's cool. If after you do that you continue to use it to obtain confidential…

Language cheapens itself when spoken cheaply. Abusing over the top terminology on minute areas of controversy will ultimately lesson the impact of your outrage when something actually bad comes along. Someone browsing healthcare plans available to other employees of different companies is not something that should win you the label “malicious actor” and come associated with other implications. This data leaking harms…

I used the word "malicious". Its not like i used the word "murderer" or "evil overlord". I'm not saying OP should go to jail or anything.

All i'm saying is if you find an exploit, and after you verify it works, you contunue to use it for your own personal ends, you're no longer benign and you shouldn't expect a warm welcome from the security team.

The line is when you start to use exploits on computers not owned by yourself for your own ends instead of for the purpose of verifying and reporting the vuln. Sure you could cross that line a little bit or a lot, but you're not innocent if you're over it.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#267
post #196

Earlier quoted context omitted.

Domestic abuse is pretty "normal" too. That doesn't make it tolerable.

These 2 things are not even remotely comparable.

So? Something being "normal" doesn't make it just. Or even legal.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#268
post #166

Earlier quoted context omitted.

If I ask you to show me a document, and you willingly show me the document, who exactly is responsible for the disclosure?

In real life, if you do it under false pretenses, you are. In this analogy the real-world version would be considered fraud.

In our version though the system can require you to show whatever ID or authentication the designer decides so how can any process as simple as changing an ID in the URL be fraudulent. In this example the person who browsed other plans either wasn’t asked for any ID or the person fetching the documents didn’t check authorization. Either one is negligence on the department/sites side.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#269

Quote from the St Louis Post Dispatch article is even more groan-worthy: "In the letter to teachers, Education Commissioner Margie Vandeven said “an individual took the records of at least three educators, unencrypted the source code from the webpage, and viewed the social security number (SSN) of those specific educators.” I guess webpages are kinda like encryption for idiots.

"Unencrypted" in this context means "did something we don't understand".

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#270

Earlier quoted context omitted.

Asking for the next file isn't false pretenses. I don't know if this analogy works quite right. Even rifling through a file cabinet wouldn't be false pretenses, it would be something else. And you have to cause injury for it to be fraud. Is "Help I was too honest to a customer." a valid injury claim?

I think the analogy would be going up to the desk and saying: my id number is X (when its really Y), can i have my file. If you convince them that you really are X and they give you the file, i think that would be considerd fraudulent. Whether or not an injury takes place to raise it to the level of fraud i guess depends on what was in the file, but in countries with strong privacy laws, someone would probably be in…

But they didn't do that. They just asked for a different file, not misrepresenting their identity.
Post reply on HN