Live data from Hacker News

Governor vows criminal prosecution of reporter who found flaw in state website

missouriindependent.com

521–530 of 705 posts

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#521
post #480
post #392

Earlier quoted context omitted.

How is it a bad response? They want to know what data has been exposed and ensure you delete that data. That's data leak 101. Why would you be defensive about it?

The point being that the IT guy made sure this guy will never try to report on anything again. As they will ".. would be watching .. at our IP address .. while the issue was being fixed." Instead of a normal company having a bug bounty and sometimes even with cash prizes. Do you think google "will watch your IP" after you reported a bug? or will they give yo money? What helps in the short run? and what helps in the l…

> Do you think google "will watch your IP" after you reported a bug? or will they give yo money?

I honestly think they'll do both - but they won't tell you they're watching your IP because it's needlessly antagonistic.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#522
post #414

Earlier quoted context omitted.

It is very easy for IT managers to put the blame on "hackers" intruding into the network, instead of assuming they created an insecure system. In many companies this can work.

I very much want the blame to be on the person who broke into my house regardless of whether my door was locked or my window was open.

Which works great when there's some kind of access restriction in place.

If you wind up putting your tax returns in the 'little free library' you set up on your front yard, you can't blame others for reading them, then handing them back to you and not telling anyone else.

That's the proper analogy for what happened in the original article.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#524

After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…

“No, I didn’t look at any other plans, but I’ve notified our lawyer who is now compiling the list of exposed company plans before she contacts each of these companies for class action suit proceedings”.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#526
post #254
post #246

Earlier quoted context omitted.

wow, what fraction of websites leak data I want to look at? should I be poking at every non-tech-giant site I go to?

Careful, son, you're quickly entering elite hacker turf.

Dont worry, I only do all this behind 7 proxies. Plus I called google and they know all about it.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#527
post #378

Earlier quoted context omitted.

The US Government has a STIG (Security Technical Implementation Guide [1], a government-proprietary term for "IT policy") that requires that you disable Dev Tools in IE [2], Edge [3] and Chrome[4]. Their justification (from [1]): > Information needed by an attacker to begin looking for possible vulnerabilities in a web browser includes any information about the web browser and plug-ins or modules being used. When deb…

I can think of at least one legitimate reason to block the dev console. There are these posts I've seen over the years that say to "press the hotkey to open the Javascript console, and paste this Javascript blob" (obviously in much more persuading terms) to get a discount on RayBands or something. Disabling it prevents a possible information leak vector.

I've never seen one in the wild, thought it would be interesting to see what they want you to paste into the console, probably something to transmit them your session token. I know Facebook has a huge warning about it when you open devtools on their site.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#528
post #392

After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…

How is it a bad response? They want to know what data has been exposed and ensure you delete that data. That's data leak 101. Why would you be defensive about it?

> They want to know what data has been exposed

They should check their own logs instead of relaying on a 3rd party that may not tell the truth. This shows incompetence.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#529
This article reminded me that I had to report a data leak I found on an ecommerce website from my country some months ago, so I just did that. I reported it to a government agency responsible for cybersecurity in my country, which apparently accepts reports about private companies.

Any precautions that you recommend when reporting this kind of vulnerability/data leak? (Apart from "do not access other people's data if you can avoid it")

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#530
post #66

Earlier quoted context omitted.

This could actually become illegal in the UK. The official secrets act might be amended to make it illegal to embarrass the state...

To quote Yes Minister: "The Official Secrets Act is not there to protect secrets, it is there to protect officials."

A good faith reading of that statement interprets it to mean: the act isn't intended to keep pertinent information away from the public, but to protect the identities of officials who were tangentially involved.

Surely no official interprets it to mean: protecting the public image of officials by way of hiding pertinent information from the public, right?

Post reply on HN