Live data from Hacker News

FBI raids researcher who discovered private patient data on public server (2016)

dailydot.com

51–60 of 98 posts

Re: FBI raids researcher who discovered private patient data on public server (2016)

#51
Similar outcomes have happened enough times when cybersec people tried to report a security hole that the security community should have noticed the pattern long ago and taken steps which imo would be just to shrug their shoulders in future when they find security holes and think about reporting them for free out of some misplaced kindness towards big business.

Re: FBI raids researcher who discovered private patient data on public server (2016)

#52

Earlier quoted context omitted.

I've physically seen many police walking around crowded areas with assault rifles in France and Italy. Germany not as much but they do carry pistols iirc.

Ditto. In nearly 30 years of living in the US I can only ever recall seeing police officers patrolling with long guns twice: once when I visited the US capitol, and once at a big festival/parade thing in Bellevue, WA. Seeing the officer in Bellevue patrolling with a long gun was actually quite unsettling. Even though all police in the US are armed and most have a long gun in their vehicle, they very rarely carry them…

It’s the bias of spending your life in unexciting places in the US, but visiting high-visibility terrorism targets (aka major tourist attractions, capitals, monuments and transport hubs) when abroad.

Rest assured that the small town cops in Europe don’t patrol with MP5s, but that the marines at local US embassy (which is a high value target) occasionally do…

Re: FBI raids researcher who discovered private patient data on public server (2016)

#53

Earlier quoted context omitted.

I've physically seen many police walking around crowded areas with assault rifles in France and Italy. Germany not as much but they do carry pistols iirc.

In Italy, rifle-armed personnel of the Army are used to guard areas at risk of terrorist attacks, e.g. train stations and other crowded areas. AFAIK they never had to intervene; I think their purpose is mostly deterrence. In Italy there is a civil police force and a military one (named Carabinieri) and both of them carry guns. However, only when they have to raid the homes of high-risk people, e.g. mafia criminals or…

the (grim) joke in Italy being that any force that even remotely has some sort of police duties (and there are many), carries a gun, even glorified traffic wardens.

But yes, machine guns and rifles are only carried by units on special duties, normally anti-terrorism (and unfortunately Italy has a long history of internal terrorism).

Re: FBI raids researcher who discovered private patient data on public server (2016)

#55

Earlier quoted context omitted.

Unbelievable. Poor guy went to jail! And was raided 2 more times. I actually want to cry

He sent intimidating messages to an FBI agents wife . That's stepping over some line Edit was wrong about the content of the message to the spouse

No.

> The factual bases of the government’s bare bones indictment are a handful of public tweets; a Facebook friend request and message sent to a public Facebook account; the following of a public Twitter account;1 and two emails to an FBI Agent – one with a “?” emoji and another inquiring about the status of a report of a patient privacy violation.

> The Defendant made no attempt to mask his identity, and the FBI never contacted the Defendant to express any concern or to ask him to stop his communications. Instead they arrested him.

> And any claim that he engaged in a sustained course of conduct with a continuity of purpose to cyberstalk or threaten are ludicrous when compared to facts embodied in the case law regarding these statutes.

Re: FBI raids researcher who discovered private patient data on public server (2016)

#56
“Many IT guys in the dental industry know that the Patterson FTP site has been unsecured for many years. I actually remember them having a passworded FTP site back in 2006. To get the password you would call tech support at EaglesoftPatterson Dental and they would just give you the password to the FTP site if you wanted to download anything. It never changed. At some point they made the FTP site anonymous. I think around 2010.”

So literally this is about anonymous access on a publicly accessible FTP server? I thought before reading the article that maybe he had hacked into it using a weak or guessable unchanged password (which would’ve been required back in 2006). The FBI response seems very excessive to say the least.

Re: FBI raids researcher who discovered private patient data on public server (2016)

#57

Earlier quoted context omitted.

He sent intimidating messages to an FBI agents wife . That's stepping over some line Edit was wrong about the content of the message to the spouse

No. > The factual bases of the government’s bare bones indictment are a handful of public tweets; a Facebook friend request and message sent to a public Facebook account; the following of a public Twitter account;1 and two emails to an FBI Agent – one with a “?” emoji and another inquiring about the status of a report of a patient privacy violation. > The Defendant made no attempt to mask his identity, and the FBI ne…

Wow so 8 mo in jail, his life gets ruined, and then they drop the larger charges? Sounds like they just wanted to ruin his life.

Re: FBI raids researcher who discovered private patient data on public server (2016)

#58

2016, says "updated May 2021" but apparently not substantially: > The Daily Dot was unable to obtain a copy of the probable cause affidavit by the time of publication, and it may be under seal.

I too was wondering why this was front page.

Re: FBI raids researcher who discovered private patient data on public server (2016)

#59

Earlier quoted context omitted.

He sent intimidating messages to an FBI agents wife . That's stepping over some line Edit was wrong about the content of the message to the spouse

No. > The factual bases of the government’s bare bones indictment are a handful of public tweets; a Facebook friend request and message sent to a public Facebook account; the following of a public Twitter account;1 and two emails to an FBI Agent – one with a “?” emoji and another inquiring about the status of a report of a patient privacy violation. > The Defendant made no attempt to mask his identity, and the FBI ne…

[deleted]

Re: FBI raids researcher who discovered private patient data on public server (2016)

#60
post #57

Earlier quoted context omitted.

No. > The factual bases of the government’s bare bones indictment are a handful of public tweets; a Facebook friend request and message sent to a public Facebook account; the following of a public Twitter account;1 and two emails to an FBI Agent – one with a “?” emoji and another inquiring about the status of a report of a patient privacy violation. > The Defendant made no attempt to mask his identity, and the FBI ne…

Wow so 8 mo in jail, his life gets ruined, and then they drop the larger charges? Sounds like they just wanted to ruin his life.

[deleted]
Post reply on HN