Live data from Hacker News

Governor vows criminal prosecution of reporter who found flaw in state website

missouriindependent.com

281–290 of 705 posts

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#281

Earlier quoted context omitted.

We've always known that using DevTools was a criminal activity. In fact, the sheer number of people using them places this at criminal conspiracy levels. Better start filing those RICO cases against the browser devs. /s

How dare you did "View Source", you hacker.

Better hope they only used View Source. Could you imagine the federal crime of using curl or wget to retrieve this data?

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#282
post #186

This news should not surprise anybody who has used government websites in Missouri. Here is an example: https://mydssapp.mo.gov/CitizenPortal/application.do The website takes a LONG time to load because of how many javascripts it loads!!

Holy cow, that's incredible

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#284

Earlier quoted context omitted.

Asking for the next file isn't false pretenses. I don't know if this analogy works quite right. Even rifling through a file cabinet wouldn't be false pretenses, it would be something else. And you have to cause injury for it to be fraud. Is "Help I was too honest to a customer." a valid injury claim?

The closest real-life equivalent to asking a computer server for a document and getting it is asking a human server (e.g. office clerk, archivist) for a document and getting it. If I go to the IRS to do some paperwork and notice it says "File #7881991" in the top right corner and I go to the clerk and ask them "Hey, can I have files 7881992 and 7881993, too?" and they give them to me , who is liable for that? It's qu…

Users don't normally construct urls by hand. Wouldn't the equivalent more be like:

You filled out some form to request a document from the irs. You give the form to the person they give you the document.

You notice they dont check ids, so you change the name on the form, and get someone else's document.

This definitely seems to fit the definition of fraud:

380 (1) Every one who, by deceit, falsehood or other fraudulent means, whether or not it is a false pretence within the meaning of this Act, defrauds the public or any person, whether ascertained or not, of any property, money or valuable security or any service [that's the canada definition]

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#285

Earlier quoted context omitted.

> After I shopped a few other companies to see how our plans compared Yeah once you start using a vulnerability maliciously to obtain confidential data for your own personal gain, even if its a stupid vulnerability, you're not really good-guy security researcher anymore. If all you did was the bare minimum to demonstrate the vuln exists, that's cool. If after you do that you continue to use it to obtain confidential…

Browsing the different plans is not malicious. Jesus. And the details of different plans is not the kind of confidential info that innately deserves protection. Investigating or recording personal information would be bad, but they didn't do that.

Exactly... for them to "benefit", they would have to:

Apply for jobs at the other companies with better plans, proceed with interviews, offers and then finally accept one and quit their job at their current employer... To reap the rewards of their malicious hacking...

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#286
post #166

Earlier quoted context omitted.

If I ask you to show me a document, and you willingly show me the document, who exactly is responsible for the disclosure?

In real life, if you do it under false pretenses, you are. In this analogy the real-world version would be considered fraud.

> In real life, if you do it under false pretenses, you are.

Sure, but how is that relevant? What material false representation was made which was relied on in deciding to provide the data?

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#287

After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…

I dunno, this seems pretty normal. Just today news broke that in Germany some guy who found a flaw in a web-shop backend leaking the data of hundreds of thousands of people got raided, because the operator reported him to the police - and somehow both police and state attorney found it wise to prosecute him instead of referring the case to the GDPR officer to fine the operator. It's pretty obvious that when you find…

this is a poor analogy because the IT department isn't doing something illegal, they are just doing something poorly, the proper analogy would be if you found out the mayor routinely left the special stamp that you can use to get anyone released from jail laying on the park bench he eats lunch at - do you then go around telling people hey the mayor does this or do you say hey mayor please stop taking that stamp with you to lunch because you always forget it at the park bench and someday somebody is going to use it to do bad stuff!

OR let us reverse the analogy

You find out Facebook is running an international slave trade by using their data to find vulnerable teenage girls sending them invites and then kidnapping them. Do you A) approach Facebook and try to get them to stop their practice B) alert everyone immediately.

The answer is you alert everyone immediately because Facebook in this example is doing corrupt and illegal things. There is a difference in how you should react concerning security problems that others can take advantage of and willfully committing illegal and corrupt acts.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#288
post #217

Earlier quoted context omitted.

> ... someone from their IT department rang me on the phone and started grilling me about how many other plans I browsed, and insisted that I clear my cache and browsing history, and notified me that they would be watching to make sure nobody at our IP address didn't access any other plans while the issue was being fixed. An IT employee who doesn't know about VPNs. Sigh.

Maybe he was hoping OP didnt know about VPNs, it's not an uncommon scare tactic to imply being tracked is unavoidable.

I'm sure any further unauthorized access from random VPN IPs would have also been blamed on OP, unfortunately. "He found this out then an hour later random IPs exploited it. He must have initiated those VPNs".

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#289

[1] Parson commits $50M to investigate alleged hack of Missouri educator database. Includes video press conference by Parson himself. [1] https://fox2now.com/news/missouri/missouri-education-departm...

I notice a "Suggest Corrections" button at the bottom, of that article. Perhaps a suggestion that the Governor's entire story is a load of crap?

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#290

Earlier quoted context omitted.

I dunno, this seems pretty normal. Just today news broke that in Germany some guy who found a flaw in a web-shop backend leaking the data of hundreds of thousands of people got raided, because the operator reported him to the police - and somehow both police and state attorney found it wise to prosecute him instead of referring the case to the GDPR officer to fine the operator. It's pretty obvious that when you find…

> a) Disclose this through e.g. the press b) Approach the mayor and try to get him to fix his stuff. Somehow, when it comes to IT security, people wanna see hackers do b) because a) would clearly be irresponsible. Wtf? Huh? This analogy doesn't really make sense. The difference for software is extremely basic: if you publicize a vulnerability immediately, you give more opportunity for it to be exploited while it's be…

> The difference for software is extremely basic: if you publicize a vulnerability immediately, you give more opportunity for it to be exploited while it's being fixed.

if it’s live it’s already being exploited. simple principle, but very effective.

Post reply on HN