Live data from Hacker News

Governor vows criminal prosecution of reporter who found flaw in state website

missouriindependent.com

461–470 of 705 posts

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#461
post #362

After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…

People have gone to jail for incrementing integers in URLs like that (most famously, weev).

Looks like there is just a little bit more to that story...

https://en.wikipedia.org/wiki/Weev

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#463
post #392

After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…

How is it a bad response? They want to know what data has been exposed and ensure you delete that data. That's data leak 101. Why would you be defensive about it?

When someone is kind, helpful, and goes out of their way to help you, for free!!, you have no business demanding, insisting, or threatening a single thing.

Proper response would have been "Wow! Thanks!" and at worst "Please don't share what you saw, and thanks again."

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#464

Earlier quoted context omitted.

So his issue was not that you discovered the bug. His issue was that after discovering it, you went on to view a bunch of other people's data. What you did was walk down the block, pull on the doors of random houses, and if you found one unlocked, went in and took a look around. If you found my door unlocked and left me a note, I would be grateful. If you went in and took a look around, then did it to all of my neigh…

Asking the web server to give you information without lying or falsifying any of your request data should in no way equate to walking into random houses that are unlocked.

The proper analogy is-- you visit a public clerk and make a formal request via a form, receive the requested document from the clerk.

Then, while you're at the clerk's counter you notice a menu up high above, like at a fast food restaurant, listing random commands with no explanation. Curiously, you call one out to the clerk and see what happens. The clerk returns with a crushed can. You call out another. The clerk dumps a roll of pennies on the counter.

That's not fraud, it's negligent supervision and stupid design.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#465

Earlier quoted context omitted.

I think the analogy would be going up to the desk and saying: my id number is X (when its really Y), can i have my file. If you convince them that you really are X and they give you the file, i think that would be considerd fraudulent. Whether or not an injury takes place to raise it to the level of fraud i guess depends on what was in the file, but in countries with strong privacy laws, someone would probably be in…

Except that's not at all what they did - they simply accessed files that had been made public by the service provider . To be able to login as BoBibbidyFooBar, and subsequently access ANY company's info in the system without changing their identity from BoBibbidyFooBar does not, in any way, constitute any sort of fraud. It literally cannot, by any sensible definition.

Intent matters. The service provider clearly did not intend that the files should be public. They screwed up, and they should take responsibility for that. But that doesn't make it ok to know about the security issue and download as many documents as you can in order to use them for your own purposes. Perhaps that wouldn't be "fraud" based on whatever definition you're using, but it's clearly unethical and immoral, and IMO hopefully illegal as well.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#466

After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…

It is very easy for IT managers to put the blame on "hackers" intruding into the network, instead of assuming they created an insecure system. In many companies this can work.

In my experience the managers don't have the information to make a sound decision. The fault is putting trust in the cat who impressed you 20 years ago when alls you needed was 1 sysadmin for your exchange server. He hasn't learned anything in 20 years and is above reproach because when I point out his failings him and the manager go off in a quiet room and he DESTROYS me with trash talk.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#467
Governor Parson, While in the Army, attended night classes at the University of Maryland and the University of Hawaii, without completion of a degree.

Its not hard to see how someone with only a rural sixties highschool education might conflate this particular revelation with treasonous intent.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#468
post #408

Earlier quoted context omitted.

It's a public website. If we have to use the doors analogy, these are doors at City Hall, not people's houses.

Yeah you still can't just walk into the Mayor's office just because it's unlocked. Access isn't authorization.

And yet if I do just open the door to the Mayor's office and it's unlocked and I wander in, that's still not the same sort of trespass as entering someone's home.

And, if I'm in City Hall, the mechanism that keeps me from entering the Mayor's office should be the security guards and key-cards, not my disinclination to open a door.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#469

After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…

So his issue was not that you discovered the bug. His issue was that after discovering it, you went on to view a bunch of other people's data. What you did was walk down the block, pull on the doors of random houses, and if you found one unlocked, went in and took a look around. If you found my door unlocked and left me a note, I would be grateful. If you went in and took a look around, then did it to all of my neigh…

This analogy isn't apt. What the OP did was the equivalent of asking, "Can you share these files with me?" and the other party going, "Sure, here they are!"

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#470
post #429

Earlier quoted context omitted.

So his issue was not that you discovered the bug. His issue was that after discovering it, you went on to view a bunch of other people's data. What you did was walk down the block, pull on the doors of random houses, and if you found one unlocked, went in and took a look around. If you found my door unlocked and left me a note, I would be grateful. If you went in and took a look around, then did it to all of my neigh…

This was not an "unlocked door". This was going to the doctor's office, and while sitting in the room with your files, seeing a bunch of other patient files just left on the desk in eyesight. Not in an unlocked filing cabinet, not in an envelope, but in the open. Changing a URL is not "malicious use" nor is it considered doing something you're not supposed to. As a web client, I should be able to change or manipulate…

It's even worse than that. I think a better analogy would be that you've requested the doctor mail you your records and instead the doctor ships you his entire filing cabinet with your folder taped to the top and a note saying "read this one." (but no mention about why the filing cabinet is there too)

They weren't just in the open. A copy of these records were pushed, unsolicited, to the user's device and the user simply looked at what was sent to them.

Post reply on HN