Live data from Hacker News

Governor vows criminal prosecution of reporter who found flaw in state website

missouriindependent.com

431–440 of 705 posts

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#431
post #3

From the article, it sounds like nothing even remotely questionable was done by the reporter who found the flaw: > "According to the Post-Dispatch, one of its reporters discovered the flaw in a web application allowing the public to search teacher certifications and credentials. No private information was publicly visible, but teacher Social Security numbers were contained in HTML source code of the pages."

Translation: search for a certification on the public website, receive an SSN in response. Only 'hacking' by reporter was to then press 'Ctrl+U' in the browser and read the characters.

He used the basic reading skills that are taught in ever public and private education system in the country to hack us!

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#432
post #316

Earlier quoted context omitted.

The closest real-life equivalent to asking a computer server for a document and getting it is asking a human server (e.g. office clerk, archivist) for a document and getting it. If I go to the IRS to do some paperwork and notice it says "File #7881991" in the top right corner and I go to the clerk and ask them "Hey, can I have files 7881992 and 7881993, too?" and they give them to me , who is liable for that? It's qu…

This is 100% the correct analogy.

But this is assuming that the server has more agency than it does. Servers don't have minds and they don't make authorization decisions. This is more like someone giving you key to a filing cabinet in order to retrieve some documents and while you're there you snoop on the ones next to yours.

Is this system more trusting of people than it should be? Probably. Does that mean you're allowed to snoop on other people's documents -- nope.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#433

Earlier quoted context omitted.

>if the person letting you in wasn't expecting you and didn't want you there. Then they shouldn't have let you in. How are you completely absolving them of responsibility when all they had to do was say "Who the hell are you? No, you can't come in."

Well, to go with the analogy more: I leave my door unlocked because I'm expecting someone. There's a knock at my door and I yell "Come in" without looking at who is at the door. Not an unreasonable thing, happens all the time. When I finally look, I find you in my house, going through all of my things, for no reason other than you wanted to gain insight on my financial situation. Do I bear responsibility for letting…

You let me in knowing exactly who I was. You showed me some stuff I wanted to see, but sitting right next to it, out in the open, was stuff you didn't want me to see. All I had to do was look somewhere other than where you were pointing, and I did that. And then you got mad at me for looking at the stuff and called the police.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#434
post #340

Earlier quoted context omitted.

All this reminds me of the case of Lilith Wittmann [1], who got sued by the CDU (Germany's majority-holding party) in May 2021 because she discovered a security flaw in their election campaign app "CDU connect". Data from around 100.000 visitors and 18.500 election campaign helpers was not sufficiently secured. She used responsible disclosure to let the CDU know of this flaw, got sued in response. After an outcry fro…

The CDU party no longer holds the majority :-)

Still can't tell if this is good or bad.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#435

Earlier quoted context omitted.

Well, to go with the analogy more: I leave my door unlocked because I'm expecting someone. There's a knock at my door and I yell "Come in" without looking at who is at the door. Not an unreasonable thing, happens all the time. When I finally look, I find you in my house, going through all of my things, for no reason other than you wanted to gain insight on my financial situation. Do I bear responsibility for letting…

It doesn't mean I am there illegally though. Maybe I am there for some other reason and I thought you wanted to to let me in.

No one said anything about legality. I'm still going to yell at you to gtfo and never come back again, and I don't see why it would be surprising that I would.

Let's drop the metaphor. The original story was that someone accessed a number of documents they weren't supposed to but technically could, and the question was whether or not that it was reasonable that the owners of the documents were upset with that.

I argue there was good reason to be upset given the facts on the ground. In this particular situation, the original poster was there to access their own document. Having accessed someone else's document, that would be the point at which the behavior crosses from legitimate to illegitimate if it continues. Leaving at that point would be one appropriate response. But systematically going through a number of different documents goes beyond a mistake and into the realm of intentionally exploiting this security issue for unauthorized purposes. That's when it crosses from "honest mistake" to "dishonest exploitation".

I have no idea about the illegality of the issue. But the fact is plain that this person was not the intended recipient of the documents, they knew they weren't the intended recipient, and then after realizing the nature of the exploit, they continued to use it.

This is not the same as knocking on a door for a legitimate reason, being let in, and then the person inside being mad you're there. It's knocking on a door for no reason or a malicious reason, knowingly doing something inside the resident doesn't want you to do, and then wondering why they are mad at you.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#436

Earlier quoted context omitted.

I think the analogy would be going up to the desk and saying: my id number is X (when its really Y), can i have my file. If you convince them that you really are X and they give you the file, i think that would be considerd fraudulent. Whether or not an injury takes place to raise it to the level of fraud i guess depends on what was in the file, but in countries with strong privacy laws, someone would probably be in…

Nope, no way. Your analogy is wrong. A better analogy would you asking for your files, and then the secretary taking you to a filing cabinet containing everyone's files right there with yours. You don't have to lie about who you are, you can just look at other files because they're right there in the place that you were just given access to.

And even in that case you're still not allowed to look at other people's documents. Like it doesn't matter that they're right in front of you, you still haven't been given authorization.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#437

After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…

So his issue was not that you discovered the bug. His issue was that after discovering it, you went on to view a bunch of other people's data. What you did was walk down the block, pull on the doors of random houses, and if you found one unlocked, went in and took a look around. If you found my door unlocked and left me a note, I would be grateful. If you went in and took a look around, then did it to all of my neigh…

Asking the web server to give you information without lying or falsifying any of your request data should in no way equate to walking into random houses that are unlocked.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#438

Earlier quoted context omitted.

> After I shopped a few other companies to see how our plans compared Yeah once you start using a vulnerability maliciously to obtain confidential data for your own personal gain, even if its a stupid vulnerability, you're not really good-guy security researcher anymore. If all you did was the bare minimum to demonstrate the vuln exists, that's cool. If after you do that you continue to use it to obtain confidential…

You lost me at "maliciously". What harm was done by someone comparing prices? What organization lost money? Who got worse health service? "Unethical" and malicious is the current, profit-driven health insurance system. I know you're coming at it from an absolutist perspective, but I disagree entirely with passing judgement. Furthermore, the fact that you seem more upset with the person who glanced at a few plan price…

I definitely agree that this is not a big ethical breach in terms of magnitude, but it is still better not to look. Apparently this is not intended to be public information. If this information is private, I guess the companies want to derive some (slight) competitive advantage from not sharing it. I think you could make a strong argument that companies should make their healthcare offerings public knowledge, but they aren't currently (I guess?). In any case, access should be granted on the basis of an even playing field.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#439
So they included the SSNs in the HTML source, and then said the reporter hacked and unencrypted the HTML by reading the non-displayed SSNs in the source. That's like taping the SSNs up to the inside of a tinted window and then saying the reporter committed breaking and entering by shining a flashlight on the window.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#440

Earlier quoted context omitted.

Asking for the next file isn't false pretenses. I don't know if this analogy works quite right. Even rifling through a file cabinet wouldn't be false pretenses, it would be something else. And you have to cause injury for it to be fraud. Is "Help I was too honest to a customer." a valid injury claim?

The closest real-life equivalent to asking a computer server for a document and getting it is asking a human server (e.g. office clerk, archivist) for a document and getting it. If I go to the IRS to do some paperwork and notice it says "File #7881991" in the top right corner and I go to the clerk and ask them "Hey, can I have files 7881992 and 7881993, too?" and they give them to me , who is liable for that? It's qu…

No, it's not, because computers and humans are not the same. A computer might give away too much information because someone misconfigured it. The closet human analog to that would be if the human was improperly trained in what information they're supposed to give out. But the human also has other options: they could be tricked into giving out more information than they should, or they could be giving out more information because they're being paid off or given some other benefit.

You can certainly assign various levels of blame and responsibility to the human "server" in those scenarios. But the human on the other side of the interaction, the one requesting information, doesn't magically become free of reproach. If they are requesting information they know they should not have access to, and then making use of that information for their own gain, they're guilty too.

There's a very narrow carve-out for the white-hat: requesting information with the intent of uncovering vulnerabilities, with the intent to help them get fixed. We expect a white-hat actor here to destroy and not make use of any information they obtain that they shouldn't have.

> If I go to the IRS to do some paperwork and notice it says "File #7881991" in the top right corner and I go to the clerk and ask them "Hey, can I have files 7881992 and 7881993, too?" and they give them to me, who is liable for that? It's quite obvious.

Yes, it is obvious: the clerk is liable for giving you something they shouldn't have, and you are liable for fraudulently representing yourself as someone who should have access to those files.

I don't get where this idea of "the other person let me do the crime, so the crime is ok" comes from. That's just not how the law works in the real world. If you then walked out of the IRS office with those files, I would absolutely expect you to get arrested. (Even if you immediately gave the files back, you'd probably be on shaky legal ground.)

Post reply on HN