After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…
People have gone to jail for incrementing integers in URLs like that (most famously, weev).
Governor vows criminal prosecution of reporter who found flaw in state website
461–470 of 705 posts
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#462Once again, Gov Parsons makes me embarrassed to be a Missouri resident.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#463After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…
How is it a bad response? They want to know what data has been exposed and ensure you delete that data. That's data leak 101. Why would you be defensive about it?
Proper response would have been "Wow! Thanks!" and at worst "Please don't share what you saw, and thanks again."
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#464Earlier quoted context omitted.
So his issue was not that you discovered the bug. His issue was that after discovering it, you went on to view a bunch of other people's data. What you did was walk down the block, pull on the doors of random houses, and if you found one unlocked, went in and took a look around. If you found my door unlocked and left me a note, I would be grateful. If you went in and took a look around, then did it to all of my neigh…
Asking the web server to give you information without lying or falsifying any of your request data should in no way equate to walking into random houses that are unlocked.
Then, while you're at the clerk's counter you notice a menu up high above, like at a fast food restaurant, listing random commands with no explanation. Curiously, you call one out to the clerk and see what happens. The clerk returns with a crushed can. You call out another. The clerk dumps a roll of pennies on the counter.
That's not fraud, it's negligent supervision and stupid design.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#465Earlier quoted context omitted.
I think the analogy would be going up to the desk and saying: my id number is X (when its really Y), can i have my file. If you convince them that you really are X and they give you the file, i think that would be considerd fraudulent. Whether or not an injury takes place to raise it to the level of fraud i guess depends on what was in the file, but in countries with strong privacy laws, someone would probably be in…
Except that's not at all what they did - they simply accessed files that had been made public by the service provider . To be able to login as BoBibbidyFooBar, and subsequently access ANY company's info in the system without changing their identity from BoBibbidyFooBar does not, in any way, constitute any sort of fraud. It literally cannot, by any sensible definition.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#466After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…
It is very easy for IT managers to put the blame on "hackers" intruding into the network, instead of assuming they created an insecure system. In many companies this can work.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#467Its not hard to see how someone with only a rural sixties highschool education might conflate this particular revelation with treasonous intent.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#468Earlier quoted context omitted.
It's a public website. If we have to use the doors analogy, these are doors at City Hall, not people's houses.
Yeah you still can't just walk into the Mayor's office just because it's unlocked. Access isn't authorization.
And, if I'm in City Hall, the mechanism that keeps me from entering the Mayor's office should be the security guards and key-cards, not my disinclination to open a door.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#469After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…
So his issue was not that you discovered the bug. His issue was that after discovering it, you went on to view a bunch of other people's data. What you did was walk down the block, pull on the doors of random houses, and if you found one unlocked, went in and took a look around. If you found my door unlocked and left me a note, I would be grateful. If you went in and took a look around, then did it to all of my neigh…
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#470Earlier quoted context omitted.
So his issue was not that you discovered the bug. His issue was that after discovering it, you went on to view a bunch of other people's data. What you did was walk down the block, pull on the doors of random houses, and if you found one unlocked, went in and took a look around. If you found my door unlocked and left me a note, I would be grateful. If you went in and took a look around, then did it to all of my neigh…
This was not an "unlocked door". This was going to the doctor's office, and while sitting in the room with your files, seeing a bunch of other patient files just left on the desk in eyesight. Not in an unlocked filing cabinet, not in an envelope, but in the open. Changing a URL is not "malicious use" nor is it considered doing something you're not supposed to. As a web client, I should be able to change or manipulate…
They weren't just in the open. A copy of these records were pushed, unsolicited, to the user's device and the user simply looked at what was sent to them.