From the article, it sounds like nothing even remotely questionable was done by the reporter who found the flaw: > "According to the Post-Dispatch, one of its reporters discovered the flaw in a web application allowing the public to search teacher certifications and credentials. No private information was publicly visible, but teacher Social Security numbers were contained in HTML source code of the pages."
Translation: search for a certification on the public website, receive an SSN in response. Only 'hacking' by reporter was to then press 'Ctrl+U' in the browser and read the characters.
Governor vows criminal prosecution of reporter who found flaw in state website
431–440 of 705 posts
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#432Earlier quoted context omitted.
The closest real-life equivalent to asking a computer server for a document and getting it is asking a human server (e.g. office clerk, archivist) for a document and getting it. If I go to the IRS to do some paperwork and notice it says "File #7881991" in the top right corner and I go to the clerk and ask them "Hey, can I have files 7881992 and 7881993, too?" and they give them to me , who is liable for that? It's qu…
This is 100% the correct analogy.
Is this system more trusting of people than it should be? Probably. Does that mean you're allowed to snoop on other people's documents -- nope.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#433Earlier quoted context omitted.
>if the person letting you in wasn't expecting you and didn't want you there. Then they shouldn't have let you in. How are you completely absolving them of responsibility when all they had to do was say "Who the hell are you? No, you can't come in."
Well, to go with the analogy more: I leave my door unlocked because I'm expecting someone. There's a knock at my door and I yell "Come in" without looking at who is at the door. Not an unreasonable thing, happens all the time. When I finally look, I find you in my house, going through all of my things, for no reason other than you wanted to gain insight on my financial situation. Do I bear responsibility for letting…
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#434Earlier quoted context omitted.
All this reminds me of the case of Lilith Wittmann [1], who got sued by the CDU (Germany's majority-holding party) in May 2021 because she discovered a security flaw in their election campaign app "CDU connect". Data from around 100.000 visitors and 18.500 election campaign helpers was not sufficiently secured. She used responsible disclosure to let the CDU know of this flaw, got sued in response. After an outcry fro…
The CDU party no longer holds the majority :-)
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#435Earlier quoted context omitted.
Well, to go with the analogy more: I leave my door unlocked because I'm expecting someone. There's a knock at my door and I yell "Come in" without looking at who is at the door. Not an unreasonable thing, happens all the time. When I finally look, I find you in my house, going through all of my things, for no reason other than you wanted to gain insight on my financial situation. Do I bear responsibility for letting…
It doesn't mean I am there illegally though. Maybe I am there for some other reason and I thought you wanted to to let me in.
Let's drop the metaphor. The original story was that someone accessed a number of documents they weren't supposed to but technically could, and the question was whether or not that it was reasonable that the owners of the documents were upset with that.
I argue there was good reason to be upset given the facts on the ground. In this particular situation, the original poster was there to access their own document. Having accessed someone else's document, that would be the point at which the behavior crosses from legitimate to illegitimate if it continues. Leaving at that point would be one appropriate response. But systematically going through a number of different documents goes beyond a mistake and into the realm of intentionally exploiting this security issue for unauthorized purposes. That's when it crosses from "honest mistake" to "dishonest exploitation".
I have no idea about the illegality of the issue. But the fact is plain that this person was not the intended recipient of the documents, they knew they weren't the intended recipient, and then after realizing the nature of the exploit, they continued to use it.
This is not the same as knocking on a door for a legitimate reason, being let in, and then the person inside being mad you're there. It's knocking on a door for no reason or a malicious reason, knowingly doing something inside the resident doesn't want you to do, and then wondering why they are mad at you.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#436Earlier quoted context omitted.
I think the analogy would be going up to the desk and saying: my id number is X (when its really Y), can i have my file. If you convince them that you really are X and they give you the file, i think that would be considerd fraudulent. Whether or not an injury takes place to raise it to the level of fraud i guess depends on what was in the file, but in countries with strong privacy laws, someone would probably be in…
Nope, no way. Your analogy is wrong. A better analogy would you asking for your files, and then the secretary taking you to a filing cabinet containing everyone's files right there with yours. You don't have to lie about who you are, you can just look at other files because they're right there in the place that you were just given access to.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#437After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…
So his issue was not that you discovered the bug. His issue was that after discovering it, you went on to view a bunch of other people's data. What you did was walk down the block, pull on the doors of random houses, and if you found one unlocked, went in and took a look around. If you found my door unlocked and left me a note, I would be grateful. If you went in and took a look around, then did it to all of my neigh…
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#438Earlier quoted context omitted.
> After I shopped a few other companies to see how our plans compared Yeah once you start using a vulnerability maliciously to obtain confidential data for your own personal gain, even if its a stupid vulnerability, you're not really good-guy security researcher anymore. If all you did was the bare minimum to demonstrate the vuln exists, that's cool. If after you do that you continue to use it to obtain confidential…
You lost me at "maliciously". What harm was done by someone comparing prices? What organization lost money? Who got worse health service? "Unethical" and malicious is the current, profit-driven health insurance system. I know you're coming at it from an absolutist perspective, but I disagree entirely with passing judgement. Furthermore, the fact that you seem more upset with the person who glanced at a few plan price…
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#439Re: Governor vows criminal prosecution of reporter who found flaw in state website
#440Earlier quoted context omitted.
Asking for the next file isn't false pretenses. I don't know if this analogy works quite right. Even rifling through a file cabinet wouldn't be false pretenses, it would be something else. And you have to cause injury for it to be fraud. Is "Help I was too honest to a customer." a valid injury claim?
The closest real-life equivalent to asking a computer server for a document and getting it is asking a human server (e.g. office clerk, archivist) for a document and getting it. If I go to the IRS to do some paperwork and notice it says "File #7881991" in the top right corner and I go to the clerk and ask them "Hey, can I have files 7881992 and 7881993, too?" and they give them to me , who is liable for that? It's qu…
You can certainly assign various levels of blame and responsibility to the human "server" in those scenarios. But the human on the other side of the interaction, the one requesting information, doesn't magically become free of reproach. If they are requesting information they know they should not have access to, and then making use of that information for their own gain, they're guilty too.
There's a very narrow carve-out for the white-hat: requesting information with the intent of uncovering vulnerabilities, with the intent to help them get fixed. We expect a white-hat actor here to destroy and not make use of any information they obtain that they shouldn't have.
> If I go to the IRS to do some paperwork and notice it says "File #7881991" in the top right corner and I go to the clerk and ask them "Hey, can I have files 7881992 and 7881993, too?" and they give them to me, who is liable for that? It's quite obvious.
Yes, it is obvious: the clerk is liable for giving you something they shouldn't have, and you are liable for fraudulently representing yourself as someone who should have access to those files.
I don't get where this idea of "the other person let me do the crime, so the crime is ok" comes from. That's just not how the law works in the real world. If you then walked out of the IRS office with those files, I would absolutely expect you to get arrested. (Even if you immediately gave the files back, you'd probably be on shaky legal ground.)