Earlier quoted context omitted.
If I ask you to show me a document, and you willingly show me the document, who exactly is responsible for the disclosure?
Accessing data that you are not authorized to view is still wrong. The fact that someone has misconfigured the access controls doesn't change that. I might forget to lock my front door one day, but that doesn't make it ok for you to wander into my house and look at all my stuff.
Governor vows criminal prosecution of reporter who found flaw in state website
421–430 of 705 posts
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#422After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…
> ... someone from their IT department rang me on the phone and started grilling me about how many other plans I browsed, and insisted that I clear my cache and browsing history, and notified me that they would be watching to make sure nobody at our IP address didn't access any other plans while the issue was being fixed. An IT employee who doesn't know about VPNs. Sigh.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#423Earlier quoted context omitted.
Say you are invited to your friends apartment in an apartment building, but none of the apartments have locks. So you decide to open up some other random apartments and look through their things, who is responsible?
That's not even close to the same analogy though. This would be like knocking on the door, asking if you can come in, and the person living there letting you in. Then getting mad about it later even though they let you in.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#424Earlier quoted context omitted.
Oh that is so bad. It's events and negligence like this that give credence to credentialing requirements for software engineering.
Imagine if we had credentialing requirements for elected office…
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#425Earlier quoted context omitted.
We've always known that using DevTools was a criminal activity. In fact, the sheer number of people using them places this at criminal conspiracy levels. Better start filing those RICO cases against the browser devs. /s
How dare you did "View Source", you hacker.
"The Governor is in possession of software on his personal computer that allows him to decrypt the personal details of thousands of constituents who may have voted for or against him."
The "software" being a web browser, of course.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#426Earlier quoted context omitted.
I think we're all gronw-ups here and don't need analogies here.
People of all ages suffer from confirmation bias. Analogies can be useful because they allow someone to appreciate the logic of an argument while temporarily dissociating from strongly-held opinions. After the framing moves back to the question under debate, the logic might stick. At least all parties might understand everyone’s perspective better after a few analogies are exchanged.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#427Earlier quoted context omitted.
So his issue was not that you discovered the bug. His issue was that after discovering it, you went on to view a bunch of other people's data. What you did was walk down the block, pull on the doors of random houses, and if you found one unlocked, went in and took a look around. If you found my door unlocked and left me a note, I would be grateful. If you went in and took a look around, then did it to all of my neigh…
Wow. The parent comment did not state they then sifted around for personal data. They checked if there was a bug and found it. For all we know the personal data is front and center, so this rudimentary check also revealed personal information. It’s not like they said they downloaded the SSNs. Good job a miming the ignorance and bad faith of the nameless bureaucrat the parent comment mentioned though, maybe this is ju…
You might have missed this part. I did, too, on first reading. They did sift around.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#428Earlier quoted context omitted.
If I ask you to show me a document, and you willingly show me the document, who exactly is responsible for the disclosure?
Accessing data that you are not authorized to view is still wrong. The fact that someone has misconfigured the access controls doesn't change that. I might forget to lock my front door one day, but that doesn't make it ok for you to wander into my house and look at all my stuff.
So if a piece of paper flies in my face and has company secrets and I manage to look at, I'm at fault here ?
> I might forget to lock my front door one day, but that doesn't make it ok
Sorry but if you're not going to secure your belongings, then expect to be robbed.
Being 'ok' has nothing to do with it.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#429After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…
So his issue was not that you discovered the bug. His issue was that after discovering it, you went on to view a bunch of other people's data. What you did was walk down the block, pull on the doors of random houses, and if you found one unlocked, went in and took a look around. If you found my door unlocked and left me a note, I would be grateful. If you went in and took a look around, then did it to all of my neigh…
This was going to the doctor's office, and while sitting in the room with your files, seeing a bunch of other patient files just left on the desk in eyesight.
Not in an unlocked filing cabinet, not in an envelope, but in the open.
Changing a URL is not "malicious use" nor is it considered doing something you're not supposed to.
As a web client, I should be able to change or manipulate the URL to my heart's content, it is 100% the server's job to restrict my access and make sure that I cannot access resources I shouldn't.
This is entirely the fault of the operators, not the user, and they were mad at them because they _allowed_ the user to access things they should not.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#430Earlier quoted context omitted.
How dare you did "View Source", you hacker.
> you hacker What a "hacker" is is a matter of definition. But, the fact is the state was using "encryption" with such a level of security that pressing one button on any computer with a browser is all that is required to defeat it.