This news should not surprise anybody who has used government websites in Missouri. Here is an example: https://mydssapp.mo.gov/CitizenPortal/application.do The website takes a LONG time to load because of how many javascripts it loads!!
Governor vows criminal prosecution of reporter who found flaw in state website
301–310 of 705 posts
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#302Earlier quoted context omitted.
Asking for the next file isn't false pretenses. I don't know if this analogy works quite right. Even rifling through a file cabinet wouldn't be false pretenses, it would be something else. And you have to cause injury for it to be fraud. Is "Help I was too honest to a customer." a valid injury claim?
I think the analogy would be going up to the desk and saying: my id number is X (when its really Y), can i have my file. If you convince them that you really are X and they give you the file, i think that would be considerd fraudulent. Whether or not an injury takes place to raise it to the level of fraud i guess depends on what was in the file, but in countries with strong privacy laws, someone would probably be in…
To be able to login as BoBibbidyFooBar, and subsequently access ANY company's info in the system without changing their identity from BoBibbidyFooBar does not, in any way, constitute any sort of fraud. It literally cannot, by any sensible definition.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#303After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…
I dunno, this seems pretty normal. Just today news broke that in Germany some guy who found a flaw in a web-shop backend leaking the data of hundreds of thousands of people got raided, because the operator reported him to the police - and somehow both police and state attorney found it wise to prosecute him instead of referring the case to the GDPR officer to fine the operator. It's pretty obvious that when you find…
Perhaps responsible disclosure could pass through his entity?
It's a way of anonymising the source to keep them safe, and centralising the risk to someone who is already highly regarded by companies and governments.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#304> Parson said...the reporter was “attempting to embarrass the state and sell headlines for their news outlet.” Literally a reporter's job.
Those scheming reporters! /s
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#305Earlier quoted context omitted.
> After I shopped a few other companies to see how our plans compared Yeah once you start using a vulnerability maliciously to obtain confidential data for your own personal gain, even if its a stupid vulnerability, you're not really good-guy security researcher anymore. If all you did was the bare minimum to demonstrate the vuln exists, that's cool. If after you do that you continue to use it to obtain confidential…
> malicious actor malice implies intent. If we take author at their word, there wasn't any, though you could say they took it too far by looking at other stuff they probably knew it was ethically wrong to do so. Though, sometimes it isn't clear you're in compromising territory until you're in it. If any of the confidential information obtained wrongly gets used to advantage … that's malice. If the parent set out to e…
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#306Earlier quoted context omitted.
Browsing the different plans is not malicious. Jesus. And the details of different plans is not the kind of confidential info that innately deserves protection. Investigating or recording personal information would be bad, but they didn't do that.
Exactly... for them to "benefit", they would have to: Apply for jobs at the other companies with better plans, proceed with interviews, offers and then finally accept one and quit their job at their current employer... To reap the rewards of their malicious hacking...
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#307Earlier quoted context omitted.
Nearly all politicians act like this when they're in power. The general public is easily mislead. HN notices it when it's a tech issue, but it happens in economics, medicine, basically everywhere. They have zero incentives to accept responsibility.
Nearly all politicians prosecute reporters? No, I'm pretty sure that is just the fascists.
i’m not from the US, but is it common in the US to use these kinds of accusations? seems ultra far fetched.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#308> Parson said...the reporter was “attempting to embarrass the state and sell headlines for their news outlet.” Literally a reporter's job.
The funny thing is, the reporter successfully embarrassed the state, then the state embarrassed itself further in response.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#309Earlier quoted context omitted.
The closest real-life equivalent to asking a computer server for a document and getting it is asking a human server (e.g. office clerk, archivist) for a document and getting it. If I go to the IRS to do some paperwork and notice it says "File #7881991" in the top right corner and I go to the clerk and ask them "Hey, can I have files 7881992 and 7881993, too?" and they give them to me , who is liable for that? It's qu…
Users don't normally construct urls by hand. Wouldn't the equivalent more be like: You filled out some form to request a document from the irs. You give the form to the person they give you the document. You notice they dont check ids, so you change the name on the form, and get someone else's document. This definitely seems to fit the definition of fraud: 380 (1) Every one who, by deceit, falsehood or other fraudule…
All company data was, in OPs scenario, made public to any and all authenticated users.
There is no way to rationally spin this as a malicious act, in my view.