Live data from Hacker News

Reporter likely to be charged for using “view source” feature on web browser

boingboing.net

121–130 of 210 posts

Re: Reporter likely to be charged for using “view source” feature on web browser

#121
post #42

Earlier quoted context omitted.

Specially when the public side is underfunded and defending yourself is insanely expensive. Not that law is cheap anywhere, but from recent cases like Kyle Rittenhouse and officer Potter it seems just stupid and broken.

What was wrong with the Potter case?

That that sort of case would take weeks in court room and even longer outside and cost tens or hundreds of thousands to pay for defence.

Re: Reporter likely to be charged for using “view source” feature on web browser

#122
post #78

Earlier quoted context omitted.

"A better analogy would be you're walking in the street past a neighbor's house and notice their front door wide open with no one around. You can see a purse and car keys near the door. You phone that neighbor, and tell them their door is open and their purse and keys are easily visible from the street. Would Parson consider this breaking and entering?" This was only a few lines below that.

You're going down dicey waters there. Say your neighbor has an atrium and gets medication delivered. Said medication is clearly labeled as light/heat sensitive, and the package is left by the delivery person in direct sunlight. Their front door is unlocked. You open the door and tuck the package safely inside. Breaking and entering? Anyone telling me that qualifies has some serious thinking on Mens Rea to do.

You had me in the first half. I think the better completion of this analogy would be:

You ordered some medication, and the delivery guy drops it in your atrium. You open the package and find that it includes your neighbor's medication, too. You tell the delivery guy that he sent your neighbor's medication. The delivery guy calls the police and requests you be arrested.

Re: Reporter likely to be charged for using “view source” feature on web browser

#123
post #18

I don't really like the framing that the reporter is framed for using "view source". This reinforces the idea that the people responsible for this are just uneducated. I'm sure, at this point, someone already explained them. That reporter is a victim of harassment, and that if it wasn't for "view source", it could be for some unrelated stuff. It's the same as protesters being arrested for all kinds of bogus reasons,…

“Show me the man and I’ll show you the crime”

-Lavrentiy Beria

https://www.oxfordeagle.com/2018/05/09/show-me-the-man-and-i...

Re: Reporter likely to be charged for using “view source” feature on web browser

#124

Earlier quoted context omitted.

They might prosecute, but I bet a jury would throw it out

It probably won’t even get to jury. It might get dismissed with prejudice before it goes to trial.

It will still end up costing this person tons of legal fees and probably years of stress to get there though.

Re: Reporter likely to be charged for using “view source” feature on web browser

#125
post #18

I don't really like the framing that the reporter is framed for using "view source". This reinforces the idea that the people responsible for this are just uneducated. I'm sure, at this point, someone already explained them. That reporter is a victim of harassment, and that if it wasn't for "view source", it could be for some unrelated stuff. It's the same as protesters being arrested for all kinds of bogus reasons,…

>I don't really like the framing that the reporter is framed for using "view source". This reinforces the idea that the people responsible for this are just uneducated. I'm sure, at this point, someone already explained them.

I don't like the framing either, but for different reasons. From my reading, the journalist is being targeted for reporting the vulnerability or perhaps for exploiting the vulnerability- I'm not sure.

To be clear, most websites have some disclaimer that says "don't use this website for unauthorized purposes". This is deliberately vague and includes "don't use SSNs that we leave laying around".

Should the website leave SSNs laying around? Definitely not.

Should the web site owner have the strong arm of the law come smashing down on them? Absolutely.

Should others use those SSNs? Definitely not.

If the journalist saw the SSNs and then did nothing, leave him alone. If he did something with them, charge him. If he reported them, and he is being harassed for reporting them, then write an article about that.

Re: Reporter likely to be charged for using “view source” feature on web browser

#126
post #41

Earlier quoted context omitted.

The title doesn't say they were charged it says "likely".

The article does nothing to substantiate that claim. We already know that the feds essentially told the state to fuck off. At this point it really is unlikely that the reporter will be charged.

They aren't dependent on the feds to bring charges.

The feds' involvement would be for prosecuting the reporter for CFAA violations. Missouri has its own computer intrusion legislation that would be the basis for charges from the state.

Re: Reporter likely to be charged for using “view source” feature on web browser

#127

This smells like clickbait. No charges have been filed, just a statement from a governor who has a history of bloviating about the press. “Likely to be charged” is a huge stretch.

I don't think it is that big a stretch. There's more details in the Verge article[1]:

> They turned the case over to Cole County Prosecuting Attorney Locke Thompson on Monday, December 27. Governor Parson then held a press conference on Wednesday, December 29, where he cited a state statute related to computer tampering and repeatedly suggested Thompson should use it to prosecute Renaud and the paper.

As of the time of writing this comment, that was four days ago, and during the holidays. It certainly seems like charges will be brought unless Thompson chooses to side against the Governor and decline to pursue charges (I'm not sure what the political implications of that would be in either direction.) State statute is here [2]. IANAL, but this statute seems very broad. Especially sections 3, 4, and 5:

>A person commits the offense of tampering with computer data if he or she knowingly and without authorization or without reasonable grounds to believe that he has such authorization: [...] (3) Discloses or takes data, programs, or supporting documentation, residing or existing internal or external to a computer, computer system, or computer network; or (4) Discloses or takes a password, identifying code, personal identification number, or other confidential information about a computer system or network that is intended to or does control access to the computer system or network; (5) Accesses a computer, a computer system, or a computer network, and intentionally examines information about another person;

Like, yeah, factually the reporter did examine information about another person without authorization. This law sucks, but it is not a stretch to think they will prosecute the reporter.

[1] https://www.theverge.com/2021/12/31/22861188/missouri-govern...

[2] https://revisor.mo.gov/main/OneSection.aspx?section=569.095

Re: Reporter likely to be charged for using “view source” feature on web browser

#128

This is a fascinating question. I can see strong arguments on both sides. Just because something is publicly accessible, it doesn't make it free to take or use. Of course there will never be a strict line, so one needs to take into account the intent, intensity, and the usual parameters.

Another perspective is that the private data was extracted and conveyed by the state website to the end user completely without their request or consent!

I find it reasonable that the government should be held legally liable for introducing users to the hazard of accidental exposure to confidential data.

Re: Reporter likely to be charged for using “view source” feature on web browser

#129

Earlier quoted context omitted.

The keys and purse don’t represent the raw html, they represent the social security numbers that were visible in the raw html. The front door was wide open in that this information should have been kept in the backend, not the frontend. It's a good analogy.

It's not a good analogy because your browser is your house. The "open front door" analogy works in some instances of "hacking," like enumerating an ID field in a URL. But in those cases you are making an active request to "enter the door" for each ID. That's not the case here – you downloaded a page you have access to, and the server included more data in the page than it should have, without you asking for it. It's…

Does it really matter whether you're in your own house or standing on the public street? The good Samaritan in the analogy didn't go through the open door. They just phoned their neighbor to warn them: "Hey, your door is open, leaving your purse in plain view. You should probably fix that!"

A bad actor would have actually stolen the purse. Just like a bad actor would have used the social security numbers to commit identify fraud. Since neither of those things happened, prosecuting anyone is ridiculous, in both the analogy and real life.

Re: Reporter likely to be charged for using “view source” feature on web browser

#130
post #18

I don't really like the framing that the reporter is framed for using "view source". This reinforces the idea that the people responsible for this are just uneducated. I'm sure, at this point, someone already explained them. That reporter is a victim of harassment, and that if it wasn't for "view source", it could be for some unrelated stuff. It's the same as protesters being arrested for all kinds of bogus reasons,…

They might prosecute, but I bet a jury would throw it out

Never underestimate the ignorance of a jury or the lies of a DA.
Post reply on HN