Earlier quoted context omitted.
Huge missed opportunity for mass email of URL shortener link to the youtube Rick Astley video.
There were cia.gov email addresses in there too. When these guys don't get a joke and fixate on you, they really fixate on you. They are more clingy than that song.
Governor vows criminal prosecution of reporter who found flaw in state website
481–490 of 705 posts
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#482Earlier quoted context omitted.
It is very easy for IT managers to put the blame on "hackers" intruding into the network, instead of assuming they created an insecure system. In many companies this can work.
Years ago, I worked at this place, they tried to install these new core routers. The first core router worked fine, but connect the second and the whole campus network would go into meltdown. The network team could not work it out. The vendor could not work it out. But one of the IT managers had an explanation: me. Firstly, it was due to an OpenVPN I installed on a server (with permission-as a stopgap measure so we c…
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#483Earlier quoted context omitted.
So his issue was not that you discovered the bug. His issue was that after discovering it, you went on to view a bunch of other people's data. What you did was walk down the block, pull on the doors of random houses, and if you found one unlocked, went in and took a look around. If you found my door unlocked and left me a note, I would be grateful. If you went in and took a look around, then did it to all of my neigh…
Asking the web server to give you information without lying or falsifying any of your request data should in no way equate to walking into random houses that are unlocked.
(Playing devil’s advocate here)
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#484Earlier quoted context omitted.
Being wary of the guy, sure. But it's a terrible response in general. The correct response is to take the site down ! Monitoring IP addresses? Really? First, it's trivial to just use a different IP address. Second, even if you could track people perfectly, which you can't, who the hell thinks it's okay for data to get leaked as long as you know who it gets leaked to?
It’s not a nice response, but IT needs to be able to answer questions about the extent of a given breach (what info was accessed by whom and when). This is a legal requirement in the case of health information. Ideally people could be courteous while fulfilling their legal obligations, but IT folks aren’t generally chosen for their public relations or customer service skills.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#485Earlier quoted context omitted.
I dunno, this seems pretty normal. Just today news broke that in Germany some guy who found a flaw in a web-shop backend leaking the data of hundreds of thousands of people got raided, because the operator reported him to the police - and somehow both police and state attorney found it wise to prosecute him instead of referring the case to the GDPR officer to fine the operator. It's pretty obvious that when you find…
Yeah, in my mind, the only "responsible disclosure" these days is one made anonymously to the local data protection authority.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#486Earlier quoted context omitted.
Say you are invited to your friends apartment in an apartment building, but none of the apartments have locks. So you decide to open up some other random apartments and look through their things, who is responsible?
Analogies are never helpful for things like this. We don't need to reach for analogies to observe that while the theoretical ideal is to report it after just one false access, that no significant damage was done by accessing just a few more via human manipulation of the browser URL, with no recording or sharing of the results. From a human perspective, no damage was done. Whether that legally crosses a line involves…
OP admitted to continue changing URLs in order to check out what plans other companies were getting and what they cost. That means OP downloaded lists of employee names, ages, SSNs, and other data. If I were an employee at one of these other companies, I'd be pissed at OP for that. I'd be even more pissed at the people who built the marketplace website for making the rookie security mistake that allowed it, but it's absolutely not ok to download other people's information when you shouldn't have access to it, and use that to your own advantage.
Sure, I don't think this is something that should be prosecuted as a CFAA violation with big fines and jail time. That's not a proportionate response. But I also don't think we should signal that it's ok to look at (and use!) other people's data just because someone else forgot to lock it up properly. I think, for example, something on the level of a parking ticket would be appropriate here.
If OP had changed the URL once, found the vulnerability, and then immediately closed the page and reported the problem, I would see nothing bad in what they did. But they didn't merely do that, and IMO crossed the line in their subsequent actions.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#487Earlier quoted context omitted.
There were cia.gov email addresses in there too. When these guys don't get a joke and fixate on you, they really fixate on you. They are more clingy than that song.
Are you saying that the CIA is never going to give him up?
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#488Earlier quoted context omitted.
Say you are invited to your friends apartment in an apartment building, but none of the apartments have locks. So you decide to open up some other random apartments and look through their things, who is responsible?
That's not even close to the same analogy though. This would be like knocking on the door, asking if you can come in, and the person living there letting you in. Then getting mad about it later even though they let you in.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#489Earlier quoted context omitted.
Missouri is not even remotely considered to be in "the south". At least not by those who live there or in neighboring states.
I know a lot of people who regard it as a hybrid southern/midwestern state. Plenty of confederate flags to be found in Missouri, certainly, and the MU/KU rivalry is, on our side at least, heavy on "bleeding Kansas" rhetoric and imagery, which keeps Missouri's Southern-sympathizing role in the war alive in our popular culture (such as it is). Lots and lots of our local icons, oft-mentioned historical figures, et c., r…
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#490Earlier quoted context omitted.
I think the analogy would be going up to the desk and saying: my id number is X (when its really Y), can i have my file. If you convince them that you really are X and they give you the file, i think that would be considerd fraudulent. Whether or not an injury takes place to raise it to the level of fraud i guess depends on what was in the file, but in countries with strong privacy laws, someone would probably be in…
Nope, no way. Your analogy is wrong. A better analogy would you asking for your files, and then the secretary taking you to a filing cabinet containing everyone's files right there with yours. You don't have to lie about who you are, you can just look at other files because they're right there in the place that you were just given access to.
Analogies are always going to be imperfect, but I can't see the argument that the "separate request" analogy is any worse than yours, let alone "wrong".