Live data from Hacker News

Reporter likely to be charged for using “view source” feature on web browser

boingboing.net

151–160 of 210 posts

Re: Reporter likely to be charged for using “view source” feature on web browser

#151

Am I to understand that a state governer has the power to instruct some lacky-lawyer to charge someone with a crime, and to prosecute them for that crime? In the land of the free, this is not an independent process?

No, the state governor does not have the power to order a county prosecutor to prosecute. He can't even order the attorney general to prosecute. Might be able to put political pressure on them to do so, though.

On the other hand, the President of the United States does have some constitutional power over the Department of Justice, and appoints the US Attorney General (With confirmation by the Senate), and can fire the AG, so at the Federal level, there is a direct line of such power.

Re: Reporter likely to be charged for using “view source” feature on web browser

#152
post #139

Earlier quoted context omitted.

IANAL, but the local Missouri computer crime statute is very broad [1]. Technically, the reporter seems to have factually "Accessed a computer, a computer system, or a computer network, and intentionally examined information about another person" without "authorization." Considering the conservative PAC for the state has already pushed attack ads against the reporter [2], and the fact that the prosecutor is elected (…

The reporter did not access anything they did not have permission to access! It was on a publicly accessible website, posted publicly, for the purpose of public dissemination. The statue is even more restrictive than that- the part you didn't quote: "A person commits the offense of tampering with computer data if he or she knowingly and without authorization or without reasonable grounds to believe that he has such a…

I totally agree with you in principle. Everything the reporter accessed was publicly accessible.

That said, it seems like a prosecutor could articulate an argument that the reporter accessed information he had no reasonable grounds to believe he was authorized to access because he deliberately decoded some Base64-encoded strings that the reporter expected to contain sensitive information. Further, that because the reporter knew the site was using encoding to "protect" this information, by decoding the information he had believed might contain unauthorized information, he had "examined information about another person" that he had no "reasonable grounds" to believe he was authorized to access.

For every objection that is coming to your mind reading this, think to yourself whether you are confident you could convince a tech-illiterate prosecutor (who is looking to "hold fake news accountable") to see things your way. Further, is a jury or a judge going to be able to find salient AND relevant differences between "decoding" and "decrypting" or "client-side" vs "server-side" software? And are those differences great enough to affect their interpretation of the reporters actions in the context of the statute? Judges, prosecutors, and juries cannot be relied upon to unwrite bad tech laws.

Re: Reporter likely to be charged for using “view source” feature on web browser

#153
post #148

Earlier quoted context omitted.

>I don't really like the framing that the reporter is framed for using "view source". This reinforces the idea that the people responsible for this are just uneducated. I'm sure, at this point, someone already explained them. I don't like the framing either, but for different reasons. From my reading, the journalist is being targeted for reporting the vulnerability or perhaps for exploiting the vulnerability- I'm not…

Seeing it and doing nothing is worse in my eyes. That is how you create societies that ignore terrible problems for fear of law enforcement retaliation. The only way he should be charged is if he committed identity theft or sold the numbers. This entire debacle is a direct attack on journalists.

>This entire debacle is a direct attack on journalists.

As if this attack on a free press wasn't brazen enough, local PACs have already put out attack ads against the journalist, to frame this as the governor "holding fake news accountable." [1]

[1] https://www.youtube.com/watch?v=9IBPeRa7U8E

Re: Reporter likely to be charged for using “view source” feature on web browser

#154
From a tort perspective, it seems like the client assumes all the risk of an HTTP request: I made a request for this URI - without (obviously) knowing its contents - and you send me some contents. Even if I as the client attempt to send a malicious payload, etc. the server can transmit back whatever it would like any time - that's the rules of the game.

So the server holds all the power, and as long as I got a "200 OK" response with whatever contents you sent me, you have absolved the client of wrongdoing without a much bigger burden of proof of fraud, identity theft, etc...

Otherwise, the Internet literally becomes unusable - if even submitting this comment might result in me receiving illegal content, how does one proceed?

Sidenote: this is tangentially similar to the CitiGroup Revlon case, where Citi accidentally paid out the full principal on a loan to Revlon to a bunch of small lenders, and the lenders refused to return the money.

https://www.npr.org/transcripts/1019909860

The court ruling is interesting, in that as long as the lenders assumed the money was sent on purpose - that that was the intention of CitiGroup - then there was no reason to send the money back. But if they assumed the money was sent on accident, then it was illegal to keep it.

The court ruled that under good faith argumentation ("discharge of value") that if someone owes you money and they pay it back, even "on accident" or otherwise, you have no obligation to return it.

And again, it hinged not on the individual case per se but the effect of ruling otherwise - that you could never truly spend money that was sent to you because someone might come later and claw it back, which would just grind the financial industry to a halt.

I think the same conclusion would have to be made here: if you send something and stick a 200 on it, the recipients are entitled to what you sent them.

Re: Reporter likely to be charged for using “view source” feature on web browser

#155

From a tort perspective, it seems like the client assumes all the risk of an HTTP request: I made a request for this URI - without (obviously) knowing its contents - and you send me some contents. Even if I as the client attempt to send a malicious payload, etc. the server can transmit back whatever it would like any time - that's the rules of the game. So the server holds all the power, and as long as I got a "200 O…

>I think the same conclusion would have to be made here: if you send something and stick a 200 on it, the recipients are entitled to what you sent them.

Disclaimer: I don't work with web tech, but wouldn't that also permit a lot of activities we would absolutely consider unethical, like SQL injection? It seems like you could certainly craft a request to circumvent security controls to receive a 200 response back that we'd absolutely consider to be unethical.

Re: Reporter likely to be charged for using “view source” feature on web browser

#156
post #82

I think a lot of analogies miss the point that data was copied and transmitted to the client and accessed client side. I think it'd be more accurate to compare to a barcode Imagine requesting a voter registration form and you receive a letter in the mail with all previous residents social security numbers encoded in QR codes that were added as a "convenience feature" for the voting office In that case, it'd be ridicu…

[deleted]

Re: Reporter likely to be charged for using “view source” feature on web browser

#157

> If somebody picks your lock on your house It's not like picking a lock. It's more like turning over a sheet of paper to read what's on the other side. If this guy gets convicted, I'll eat my hat (I wear a fedora). "Thy just thow their fedora wherever the floor is And start doing horas and taps".

To me this is more like writing your SSN on a whiteboard in your living room, with the curtains open so everyone can see it.

Re: Reporter likely to be charged for using “view source” feature on web browser

#158
post #61

> If somebody picks your lock on your house It's not like picking a lock. It's more like turning over a sheet of paper to read what's on the other side. If this guy gets convicted, I'll eat my hat (I wear a fedora). "Thy just thow their fedora wherever the floor is And start doing horas and taps".

It is like if there was a smaller written text in the ink, and using a microscope you can see what the ink really contains. It was never hidden.

I regret having contributed to this analogy-storm. I thought I was just making a helpful remark, but now it's got out of control.

Re: Reporter likely to be charged for using “view source” feature on web browser

#159

Earlier quoted context omitted.

That's not a better analogy. The implication is that somehow the raw HTML is more valuable than the rendered webpage. You don't get to publish a "rendered webpage"; what you publish is raw HTML. If you didn't want people to read it, you didn't ought to have published it. [Edit] Also, taking a copy of the HTML isn't like taking keys and a purse. If you take keys and a purse, the owner has been deprived of them. That's…

SSNs were available in the source but not in the visible web page. I say the example is good.

What's visible depends on what you use to view the webpage.

GET / HTTP/1.1

If you don't happen to have a GUI ([Edit] or something like Lynx), that's how you read a website. It's not reverse engineering, or de-compiling; that's just displaying exactly what the server served.

Re: Reporter likely to be charged for using “view source” feature on web browser

#160
post #18

I don't really like the framing that the reporter is framed for using "view source". This reinforces the idea that the people responsible for this are just uneducated. I'm sure, at this point, someone already explained them. That reporter is a victim of harassment, and that if it wasn't for "view source", it could be for some unrelated stuff. It's the same as protesters being arrested for all kinds of bogus reasons,…

>I don't really like the framing that the reporter is framed for using "view source". This reinforces the idea that the people responsible for this are just uneducated. I'm sure, at this point, someone already explained them. I don't like the framing either, but for different reasons. From my reading, the journalist is being targeted for reporting the vulnerability or perhaps for exploiting the vulnerability- I'm not…

> From my reading, the journalist is being targeted for reporting the vulnerability or perhaps for exploiting the vulnerability- I'm not sure.

He reported on the vulnerability, even telling the state it existed. He never exploited it.

Post reply on HN