Live data from Hacker News

Governor vows criminal prosecution of reporter who found flaw in state website

missouriindependent.com

671–680 of 705 posts

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#671
post #669
post #662

Earlier quoted context omitted.

No party ever held a majority in the Federal Republic of Germany. But the CDU was the largest party in the previous parliament, and part of the governing majority.

There is by definition almost always a party holding a relative majority (more seats than any other party), which the CDU did for the longest time. You are correct that they did not hold an absolute majority (more seats than everybody else combined), ensuring that they always had to form a coalition to achieve that.

I've never heard of the word "majority" meaning "relative majority" without that qualifier, but I also wouldn't use the phrase "relative majority" to refer to what to me is clearly a minority, so what do I know :)

Nevertheless, it might be better to use unambiguous terms like "plurality", or define ones terms, when writing for an international audience.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#672

Earlier quoted context omitted.

Asking for the next file isn't false pretenses. I don't know if this analogy works quite right. Even rifling through a file cabinet wouldn't be false pretenses, it would be something else. And you have to cause injury for it to be fraud. Is "Help I was too honest to a customer." a valid injury claim?

The closest real-life equivalent to asking a computer server for a document and getting it is asking a human server (e.g. office clerk, archivist) for a document and getting it. If I go to the IRS to do some paperwork and notice it says "File #7881991" in the top right corner and I go to the clerk and ask them "Hey, can I have files 7881992 and 7881993, too?" and they give them to me , who is liable for that? It's qu…

I think misdirected mail might be a better analogy. My understanding is that, even if it is delivered to your mailbox, it is still a felony (in the US) to open mail that is not addressed to you.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#673
post #506
post #400

Earlier quoted context omitted.

Accessing data that you are not authorized to view is still wrong. The fact that someone has misconfigured the access controls doesn't change that. I might forget to lock my front door one day, but that doesn't make it ok for you to wander into my house and look at all my stuff.

Well in this case I'm knocking on your door and you're opening the door saying "Come right on in!" Requesting access (ie knocking on a door/typing a url) is not illegal. If you grant that request (ie invite me in/serving a webpage), I am under no obligation to psychically infer that you didn't mean to and refuse your invitation.

Unfortunately, it's never that simple. So much of it is about intent.

If I could simply use the excuse "well, the computer gave me the information", then there would be no such thing as hacking. It's always a case of the computer sending the information to you.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#674
post #661

Earlier quoted context omitted.

I don't think I can blame a politician for being technically illiterate, especially one that old. I don't think age should excuse this guy at all, nor do I buy into the meme that age has much of anything to do with technical literacy. Consider that Brian Kernighan is ~78, Tim Berners-Lee is 66 (the same age as Governor Parsons here), James Gosling is also 66, Rob Pike is 65, Steve Wozniak is 71, Geoffrey Hinton is 73…

Nobody tries to deny that old people can be top notch computer scientists. It's just a fact that computer technology has only arrived in the daily life of the greater population a few decades ago and therefore older people are statistically less likely to be familiar and comfortable with it the way younger people are. I'm surprised I have to write this.

It's just a fact that computer technology has only arrived in the daily life of the greater population a few decades ago

I would question that assertion, depending on how exactly we choose to define "few". Computers have been a fairly ubiquitous part of our society (in developed nations anyway) for a good 40 years or more now. And they've been absolutely ubiquitous for probably a good 30 years... ubiquitous enough that it's hard to see how any person who considers themselves an educated, competent adult wouldn't have had the opportunity to develop some baseline of technical literacy.

Personally I believe that anybody who is a functioning adult in our society today, who doesn't have that technical literacy, lacks it due to their choices not due to their age.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#675
post #624

Earlier quoted context omitted.

You’re still ascribing agency and authority to a fancy vending machine. The server has absolutely zero authority to grant you authorization to the documents. It can only grant you access. The servers are not representatives of the government or the site-owners, they are just machines. And just because the vending machine is broken and works without you paying doesn’t make it not stealing.

The fact that the server cannot make decisions that were not predetermined is exactly why the responsibility for its behaviour lies with the people running it. They make the rules, they are the ones whose job it is to read the manual. And when someone makes a technically valid request (instead of, say, SQL injection attacks) it's not the user's fault for an incorrect response. They might not even be aware that they'r…

I feel like I'm taking crazy pills here. We're specifically talking about someone who knew that they weren't supposed to access other business' data and did purposefully for their own gain. How is that not abusing the error for profit?

Like you can say "URLs aren't sensitive by default" up until the guy admits that he knows it's an error and he's accessing the private data he's not supposed to see. That changes the situation completely.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#676
post #290

Earlier quoted context omitted.

> a) Disclose this through e.g. the press b) Approach the mayor and try to get him to fix his stuff. Somehow, when it comes to IT security, people wanna see hackers do b) because a) would clearly be irresponsible. Wtf? Huh? This analogy doesn't really make sense. The difference for software is extremely basic: if you publicize a vulnerability immediately, you give more opportunity for it to be exploited while it's be…

> The difference for software is extremely basic: if you publicize a vulnerability immediately, you give more opportunity for it to be exploited while it's being fixed. if it’s live it’s already being exploited. simple principle, but very effective.

Certainly. I said "more" opportunity.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#677

After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…

It is very easy for IT managers to put the blame on "hackers" intruding into the network, instead of assuming they created an insecure system. In many companies this can work.

Hey, the only people we have to convince that it's not hacking are the insurance companies. When they start charging their clients for their absurd levels of risk and liability, we'll start to see actual change.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#678
post #513

Earlier quoted context omitted.

Didn't he also give the data he found to Gawker before notifying AT&T of the issue? That seems like a pretty key difference here, but I don't know what weev was charged and convicted for.

"Conspiracy to access a computer without authorization", which was and is completely preposterous. The Gawker part is completely immaterial, it was still a total travesty of justice. The judgement was later overturned on procedural grounds rather than on the merits (which it should have been). He did nothing that merited imprisonment, and even less so his mistreatment there.

It's more accurate to say it was a travesty of law, but probably not of justice.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#679
post #544

Earlier quoted context omitted.

Bad laws and a corrupt justice system are infinitely more dangerous than a single man, however unpleasant he may be. People pointed out at the time, that the CFAA is totally broken, but nobody listened because the victim was unsympathetic. Well, now we see in TFA how nothing has changed. "Yes, I'd give the Devil benefit of law, for my own safety's sake!" And it should be noted, that weev's turn towards overt neonazis…

Weev was very much a neo-nazi even before he was imprisoned, but I suspect he limited it to private channels. I once infiltrated some of the IRC channels he used in 2010 or so and have logs of him saying extremely antisemitic things in earnest. (The groups I infiltrated also doxxed people and used that information in smear campaigns, which is why I'm using a throwaway for this comment. I checked HN's rules and guidel…

The GNAA was probably the first tech group to play the "am I Nazi or am I just joking?" dogwhistle with the earnestness we often see today.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#680

Earlier quoted context omitted.

websites attempting to poorly comply with cookie banners and other GDPR regs that block a site from working without accepting something. I just display:none the offending elements and then remove the overflow:hidden. Disabling JS usually works, but sometimes the images in the page are lazy loaded via JS and will not load without.

Here you go: https://chrome.google.com/webstore/detail/super-agent-automa...

Can websites fingerprint visitors by the particular set of browser extensions/plugins/whatever they have installed? If so, wouldn't extensions such as this one be self-defeating, once you have a handful of them?
Post reply on HN