Live data from Hacker News

Governor vows criminal prosecution of reporter who found flaw in state website

missouriindependent.com

321–330 of 705 posts

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#321

Earlier quoted context omitted.

The closest real-life equivalent to asking a computer server for a document and getting it is asking a human server (e.g. office clerk, archivist) for a document and getting it. If I go to the IRS to do some paperwork and notice it says "File #7881991" in the top right corner and I go to the clerk and ask them "Hey, can I have files 7881992 and 7881993, too?" and they give them to me , who is liable for that? It's qu…

Users don't normally construct urls by hand. Wouldn't the equivalent more be like: You filled out some form to request a document from the irs. You give the form to the person they give you the document. You notice they dont check ids, so you change the name on the form, and get someone else's document. This definitely seems to fit the definition of fraud: 380 (1) Every one who, by deceit, falsehood or other fraudule…

I don't think changing the name is a fair comparison.

This definition of fraud doesn't define the word "defraud"? I don't know how I'm supposed to see if it fits or not.

It can't mean any action, or going into a store, lying about my name, and asking what aisle has baked beans would fit. Because that has "deceit" and "any service".

If I interpret things as the service being minimal and provided for free, so that I'm not deceptively getting the service, then we have to look at what actually gets sent to me, and whether it's "property, money or valuable security". And since it's just a copy of the data sent at no cost, it's much harder to argue fraud exists.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#322

I commented days ago about a state website that was returning all kinds of nicely formatted NPI in JSON from an API response, but the NPI was not displayed. I donned my black hat and other hacker attire and pressed F12 to open the browser's developers tools (a tool created by a shifty company named Google most people have never heard of), and there it was, plain as day, SSNs, addresses, etc. I closed the page and nev…

At least make a throwaway email account somewhere and email the state's IT department to let them know. I doubt it'd ever get fixed (given state budgets), but still.

In states that have state-level IT departments (usually, in addition to opposed to agency-internal ones), the state-level one mostly does IT project and contracting policy and oversight (often limited to large projects for active overisght), and maybe executes enterprise contracts for infrastructure that is used across agencies.

For an in-production system, there is a good chance that they have no responsibility for ongoing maintenance, and no special information beyond what is on the website as to who is responsible for maintenance.

You are better off contacting (anonymously or otherwise) the responsible agency. But, sadly, probably the most effective way to get it changed (after the flurry of butt covering) is to anonymously notify the media.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#323
>Republican state Rep. Tony Lovasco, who according to his legislative biography has worked in software deployment and maintenance, tweeted Thursday that “it’s clear the Governor’s Office has a fundamental misunderstanding of both web technology and industry standard procedures for reporting security vulnerabilities.

>“Journalists responsibly sounding an alarm on data privacy is not criminal hacking,” he said.

I worry that we're heading in a direction where somebody like Lovasco won't be willing to break with somebody of the same political party even for something like this.

It's already incredibly easy to code this story as a PR "win" for Democrats by embarrassing a prominent Republican.

So then isn't giving a common-sense perspective in this circumstance kind of just a betrayal of everything your side stands for?

I mean it's pretty unlikely that anything of legal import actually happens to the reporter, so for the "greater good" of accomplishing your wider agenda, or perhaps even more importantly preventing the other side's agenda, it might be better to just stay quiet and let this blow over as partisan bickering.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#325

Earlier quoted context omitted.

Asking for the next file isn't false pretenses. I don't know if this analogy works quite right. Even rifling through a file cabinet wouldn't be false pretenses, it would be something else. And you have to cause injury for it to be fraud. Is "Help I was too honest to a customer." a valid injury claim?

I think the analogy would be going up to the desk and saying: my id number is X (when its really Y), can i have my file. If you convince them that you really are X and they give you the file, i think that would be considerd fraudulent. Whether or not an injury takes place to raise it to the level of fraud i guess depends on what was in the file, but in countries with strong privacy laws, someone would probably be in…

Nope, no way. Your analogy is wrong.

A better analogy would you asking for your files, and then the secretary taking you to a filing cabinet containing everyone's files right there with yours. You don't have to lie about who you are, you can just look at other files because they're right there in the place that you were just given access to.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#327

Earlier quoted context omitted.

It’s not a nice response, but IT needs to be able to answer questions about the extent of a given breach (what info was accessed by whom and when). This is a legal requirement in the case of health information. Ideally people could be courteous while fulfilling their legal obligations, but IT folks aren’t generally chosen for their public relations or customer service skills.

Yes, and they need to do that based on the forensic data available to them, even if the answer is “we don’t know, it could be everything.”. Asking the person who caused the breach to explain the extent of your data loss is not an acceptable, or reliable, practice.

I don’t expect that it is sufficient, but it probably gives the IT person something to tell their boss in the short term: “We’ll verify, but he says he only accessed X”.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#328

Earlier quoted context omitted.

It’s not a nice response, but IT needs to be able to answer questions about the extent of a given breach (what info was accessed by whom and when). This is a legal requirement in the case of health information. Ideally people could be courteous while fulfilling their legal obligations, but IT folks aren’t generally chosen for their public relations or customer service skills.

If he can monitor ip addresses to make sure this guy isn't browsing anymore, then he should be able to check those same logs to answer his own question. If you want people that have zero obligation to help you then you should probably be nice to them. The nefarious criminal isn't going to report things like this to you.

I already agreed that this doesn’t warrant unkindness.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#329

Earlier quoted context omitted.

That's not even close to the same analogy though. This would be like knocking on the door, asking if you can come in, and the person living there letting you in. Then getting mad about it later even though they let you in.

I think that's a valid response if the person letting you in wasn't expecting you and didn't want you there. Like, what are you doing knocking on random doors and going into random places just to look around? That's not honest behavior. Honest behavior is that if you know you're not supposed to have access to a thing, you shouldn't obtain access to the thing even if you technically can. I think it's pretty clear that…

>if the person letting you in wasn't expecting you and didn't want you there.

Then they shouldn't have let you in. How are you completely absolving them of responsibility when all they had to do was say "Who the hell are you? No, you can't come in."

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#330

Earlier quoted context omitted.

You lost me at "maliciously". What harm was done by someone comparing prices? What organization lost money? Who got worse health service? "Unethical" and malicious is the current, profit-driven health insurance system. I know you're coming at it from an absolutist perspective, but I disagree entirely with passing judgement. Furthermore, the fact that you seem more upset with the person who glanced at a few plan price…

If you accessed my medical records, nobody would be “harmed” as they are fairly normal. It would still be wrong.

Because it would be a privacy issue. But that assumes they're looking at your information on purpose, and not just some price tags.
Post reply on HN