Earlier quoted context omitted.
It is very easy for IT managers to put the blame on "hackers" intruding into the network, instead of assuming they created an insecure system. In many companies this can work.
Years ago, I worked at this place, they tried to install these new core routers. The first core router worked fine, but connect the second and the whole campus network would go into meltdown. The network team could not work it out. The vendor could not work it out. But one of the IT managers had an explanation: me. Firstly, it was due to an OpenVPN I installed on a server (with permission-as a stopgap measure so we c…
Governor vows criminal prosecution of reporter who found flaw in state website
391–400 of 705 posts
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#392After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#393Earlier quoted context omitted.
I think that's a valid response if the person letting you in wasn't expecting you and didn't want you there. Like, what are you doing knocking on random doors and going into random places just to look around? That's not honest behavior. Honest behavior is that if you know you're not supposed to have access to a thing, you shouldn't obtain access to the thing even if you technically can. I think it's pretty clear that…
>if the person letting you in wasn't expecting you and didn't want you there. Then they shouldn't have let you in. How are you completely absolving them of responsibility when all they had to do was say "Who the hell are you? No, you can't come in."
Do I bear responsibility for letting you in? Yes. Should you be there? No. Should you have knocked on the door? No. Should you have tried the same at my neighbor's house and every house on my block? No. In this metaphor and in the original context, everyone is acting with honest intent except the actor knowingly trying to access obviously confidential documents.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#394[1] Parson commits $50M to investigate alleged hack of Missouri educator database. Includes video press conference by Parson himself. [1] https://fox2now.com/news/missouri/missouri-education-departm...
Talk about corruption - spending taxpayer money to cover-up mistakes made by government employeers - AND libellous statements made by government officials...
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#395Earlier quoted context omitted.
The US Government has a STIG (Security Technical Implementation Guide [1], a government-proprietary term for "IT policy") that requires that you disable Dev Tools in IE [2], Edge [3] and Chrome[4]. Their justification (from [1]): > Information needed by an attacker to begin looking for possible vulnerabilities in a web browser includes any information about the web browser and plug-ins or modules being used. When deb…
I can think of at least one legitimate reason to block the dev console. There are these posts I've seen over the years that say to "press the hotkey to open the Javascript console, and paste this Javascript blob" (obviously in much more persuading terms) to get a discount on RayBands or something. Disabling it prevents a possible information leak vector.
I can only imagine how much taxpayer money has been set on fire by developers having to debug single-page applications running on these systems without the aid of Dev Tools... these types of material wastages are created in an imperfect attempt to prevent the mere possibility of something that could be more effectively mitigated through training and web content filtering.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#396Earlier quoted context omitted.
But... they didn't change their name on the form. They literally just said "I'm still me, but I want this other file now, please." All company data was, in OPs scenario, made public to any and all authenticated users. There is no way to rationally spin this as a malicious act, in my view.
Well they changed an id number. I guess the real life version would be changing the SSN number on the form.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#397After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…
So his issue was not that you discovered the bug. His issue was that after discovering it, you went on to view a bunch of other people's data. What you did was walk down the block, pull on the doors of random houses, and if you found one unlocked, went in and took a look around. If you found my door unlocked and left me a note, I would be grateful. If you went in and took a look around, then did it to all of my neigh…
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#398After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…
So his issue was not that you discovered the bug. His issue was that after discovering it, you went on to view a bunch of other people's data. What you did was walk down the block, pull on the doors of random houses, and if you found one unlocked, went in and took a look around. If you found my door unlocked and left me a note, I would be grateful. If you went in and took a look around, then did it to all of my neigh…
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#399Earlier quoted context omitted.
Maybe he was hoping OP didnt know about VPNs, it's not an uncommon scare tactic to imply being tracked is unavoidable.
I'm sure any further unauthorized access from random VPN IPs would have also been blamed on OP, unfortunately. "He found this out then an hour later random IPs exploited it. He must have initiated those VPNs".
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#400Earlier quoted context omitted.
I don't know, that sounds like a pretty valid response given that you "shopped a few other companies to see how our plans compared".
If I ask you to show me a document, and you willingly show me the document, who exactly is responsible for the disclosure?
I might forget to lock my front door one day, but that doesn't make it ok for you to wander into my house and look at all my stuff.