Live data from Hacker News

Governor vows criminal prosecution of reporter who found flaw in state website

missouriindependent.com

681–690 of 705 posts

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#681
post #661

Earlier quoted context omitted.

Nobody tries to deny that old people can be top notch computer scientists. It's just a fact that computer technology has only arrived in the daily life of the greater population a few decades ago and therefore older people are statistically less likely to be familiar and comfortable with it the way younger people are. I'm surprised I have to write this.

It's just a fact that computer technology has only arrived in the daily life of the greater population a few decades ago I would question that assertion, depending on how exactly we choose to define "few". Computers have been a fairly ubiquitous part of our society (in developed nations anyway) for a good 40 years or more now. And they've been absolutely ubiquitous for probably a good 30 years... ubiquitous enough th…

Sure. In 1984, 37 years ago, a whopping 8.2% of US households sported a computer. So yeah, ubiquitous indeed.

Younger people tend to be more open to new things and less set in their ways, which certainly makes a difference in this case. Note that I'm again not talking in absolutes, but about matters of tendency. Naturally, in the individual case all things come down to opportunity and choice, but it seems curious to deny the statistics of the matter.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#682

Earlier quoted context omitted.

> and as soon as you get this data and you read all that information sent to you by mistake instead of seeing it's not yours and stopping, you have committed a crime. There's no such crime. If you disagree, by all means cite a statute. > you should look up how http works. I'm intimately familiar with http. Upon issuing a request for your records (the request, GET or otherwise), you receive a response, pushed to you,…

"push" means the data is pushed. as in without a request from you. it's mind boggling how you are not getting this. exchange is an example of this - you get email pushed to a listener on your mail client, without requesting that data. if you use pop3 however, you request the data and receive a response. you are arguing a request - a GET - the literal opposite of a push, is a push. this is something anyone who has use…

We don't have to continue the discussion but I'll wrap this up regardless for the peanut gallery.

As I've mentioned, my metaphor is request, response. This additional data is included, unsolicited, piggybacking on the response. I think this is clear.

Regarding the crime, no, this is completely incorrect. It sounds like you're referencing 18 USC § 1030. This law cannot apply whatsoever to this situation because there is no unauthorized access. The data was pushed, unsolicited, as part of an authorized access. It's being sent to all users when they use the system in a normal authorized fashion.

Viewing the data takes place on the user's own device, because the state itself put the information there. We are all authorized to access our own devices as much as we please.

The suggestion that the CFAA might apply here is nothing short of absurd.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#683
post #681

Earlier quoted context omitted.

It's just a fact that computer technology has only arrived in the daily life of the greater population a few decades ago I would question that assertion, depending on how exactly we choose to define "few". Computers have been a fairly ubiquitous part of our society (in developed nations anyway) for a good 40 years or more now. And they've been absolutely ubiquitous for probably a good 30 years... ubiquitous enough th…

Sure. In 1984, 37 years ago, a whopping 8.2% of US households sported a computer. So yeah, ubiquitous indeed. Younger people tend to be more open to new things and less set in their ways, which certainly makes a difference in this case. Note that I'm again not talking in absolutes, but about matters of tendency. Naturally, in the individual case all things come down to opportunity and choice, but it seems curious to…

The presence of a computer in the home is not the only measure of the prevalence of computers in society at large. I'm not ignoring anything. I was there, I lived it. And I know that being 66 is no excuse for lacking technical knowledge. It's willful ignorance, not a byproduct of happenstance.

Younger people tend to be more open to new things and less set in their ways

Even if that were true - and that's a pretty dubious claim, IMO - it does not necessarily follow that

... certainly makes a difference in this case.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#684

After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…

Unfortunately, this is the top comment and it has led to a lengthy discussion about the ethics of altering a url to retrieve a resource you should not have access to. Which is a fascinating discussion, but has nothing to do with the case at hand which is where the underlying html on a publicly accessible search result page contained SSNs of the teachers returned in the search. All the analogies about ‘it’s like askin…

[deleted]

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#685

After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…

I worked for a government contractor and I understand that behavior completely. The person you spoke with was tasked specifically with damage control. I am positive _somebody_ was grateful for your input, but those people aren't tasked with chatting on the phone. I know because I was dispatched for fixing and quantifying the scope of a similar issue, where a URL was allowing users to download treatment plans of other users. Being healthcare this is taken rather serious. While I was happy to fix the problem and grateful someone reported it, I was tasked with regularly reporting the progress of my work and scope of the breach throughout the incident. My only irk with the person who reported it was that they literally called the governor of the state after casually browsing hundreds of treatment plans, when they could've just called IT support. But yeah, I didn't talk to to them, a low-level IT lackey was given that task while I fixed the problem.

Oy vey, that was a mess though. Breaches happen, everyone knows it, even companies dealing with PHI that are beholden to crazy HIPAA fines. My report ended up conflicting with a bunch of dates a former supervisor, who at that point wasn't even involved in the department, had knowingly misrepresented to the state. After the fix was merged and I documented the whole scope of the breach, I go and look at the emails and reports on the matter. She's gone told the state all about the scope of the breach, misquoted release dates of the fixes, just minimized a bunch of things with which my report directly conflicted. This person who wasn't in our department anymore shouldn't have even been involved in the first place, yet here I am looking at publishing a report that'll land her in trouble. It put me in a difficult spot. I didn't want to get her in trouble and I thought about misrepresenting my own report. In the end I figured she made her bed, my report was the definitive statement on the matter and her emails were largely reactive so maybe they'd just forget what she said. It was, and they did.

The most important thing you need to do during a breach is be honest. On the other end be vocal and trust in the fact what you're doing is ultimately helpful. The government doesn't want to fine businesses. The only thing that'll end up screwing a company is if they're found to be negligent or dishonest. Negligence is easy to avoid because all you need to do is reasonably try to fix the problem once you've been made aware of it. Dishonesty on the other hand is a foot... that like a diaper-bound chubby baby, some people can't help shoving into their mouths. Don't throw IT under the bus though man, even if that guy on the phone was rude there were some good people on the matter. Some people just don't know how to act when they're caught up in a problem.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#686
post #681

Earlier quoted context omitted.

Sure. In 1984, 37 years ago, a whopping 8.2% of US households sported a computer. So yeah, ubiquitous indeed. Younger people tend to be more open to new things and less set in their ways, which certainly makes a difference in this case. Note that I'm again not talking in absolutes, but about matters of tendency. Naturally, in the individual case all things come down to opportunity and choice, but it seems curious to…

The presence of a computer in the home is not the only measure of the prevalence of computers in society at large. I'm not ignoring anything. I was there, I lived it. And I know that being 66 is no excuse for lacking technical knowledge. It's willful ignorance, not a byproduct of happenstance. Younger people tend to be more open to new things and less set in their ways Even if that were true - and that's a pretty dub…

[deleted]

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#687
post #681

Earlier quoted context omitted.

Sure. In 1984, 37 years ago, a whopping 8.2% of US households sported a computer. So yeah, ubiquitous indeed. Younger people tend to be more open to new things and less set in their ways, which certainly makes a difference in this case. Note that I'm again not talking in absolutes, but about matters of tendency. Naturally, in the individual case all things come down to opportunity and choice, but it seems curious to…

The presence of a computer in the home is not the only measure of the prevalence of computers in society at large. I'm not ignoring anything. I was there, I lived it. And I know that being 66 is no excuse for lacking technical knowledge. It's willful ignorance, not a byproduct of happenstance. Younger people tend to be more open to new things and less set in their ways Even if that were true - and that's a pretty dub…

> I was there, I lived it.

Yes, so did I. I find it curious that we seem to remember that period so differently.

I can easily find sources saying things like "between the ages of 25 and 60 people's ability to use websites declines by 0.8% per year", that's 28 percentage points difference in the ability to use a website.

But I'll stop arguing, it doesn't seem very promising at this point.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#688
post #670

Earlier quoted context omitted.

Which as I said would be perfectly fine. You then tell the owner of the binder that confidential information for other people is in the binder, and you get gratitude. If once you find the information on page 346, you then keep flipping and looking at people's private information on the next hundred pages like the OP did, you have now committed a crime. The fact that you can easily access something, does not give you…

> If once you find the information on page 346, you then keep flipping and looking at people's private information on the next hundred pages like the OP did, you have now committed a crime. I agree that morally, the guy should certainly not have continued to look through what he knew was private information he wasn't meant to have access to. I'm not sure the law sees a difference between looking at pages 347-350 and…

I am sure the law sees the difference. Intent is what makes the difference between a murder charge and the death penalty, and supervision with a suspended sentence for manslaughter, when you hit a person driving drunk.

Page 346 was an accident - your intent was to read Your data. In viewing Further pages, as the OP stated for the explicit purpose of viewing other people's confidential medical data, the intent is a crime. It's the same thing as walking up to someone's desk in an office you're allowed to be in, and looking through their files.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#689

Earlier quoted context omitted.

So his issue was not that you discovered the bug. His issue was that after discovering it, you went on to view a bunch of other people's data. What you did was walk down the block, pull on the doors of random houses, and if you found one unlocked, went in and took a look around. If you found my door unlocked and left me a note, I would be grateful. If you went in and took a look around, then did it to all of my neigh…

This analogy isn't apt. What the OP did was the equivalent of asking, "Can you share these files with me?" and the other party going, "Sure, here they are!"

It's interesting you completely omit the part where he figures out the string in the URL that's a company's ID, and uses that to request a file. In your example it would be "I'm this other person, can you share my own files with me?" Except he's lying, and he's not the other person.

Tell me, what happens if you, heavyset_go, send an invoice to Apple, and the invoice says you're "Cisco" and they pay it. Do you get to keep the money, or does the prison get to keep you?

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#690

Earlier quoted context omitted.

This analogy isn't apt. What the OP did was the equivalent of asking, "Can you share these files with me?" and the other party going, "Sure, here they are!"

It's interesting you completely omit the part where he figures out the string in the URL that's a company's ID, and uses that to request a file. In your example it would be "I'm this other person, can you share my own files with me?" Except he's lying, and he's not the other person. Tell me, what happens if you, heavyset_go, send an invoice to Apple, and the invoice says you're "Cisco" and they pay it. Do you get to…

> It's interesting you completely omit the part where he figures out the string in the URL that's a company's ID, and uses that to request a file. In your example it would be "I'm this other person, can you share my own files with me?

The OP was already authorized and authenticated on their own company account. They never falsified their authorization or their identity, they just requested documents at a specific URL and the other party had no problem replying with said documents.

Post reply on HN