Live data from Hacker News

Teen Reported to Police After Finding Security Hole in Website

wired.com

41–50 of 123 posts

Re: Teen Reported to Police After Finding Security Hole in Website

#41
post #25

(DEVIL'S ADVOCATE) Am I allowed to go to businesses and try to pick the locks, look inside, and then report to the business owner that their lock was pickable? Well... yes, but I'd probably be reported to police. Websites, like locks, aren't bullet proof. How many web applications out there don't have a security flaw somewhere? Doing penetration tests on unwilling victims is risky. Trying to break wifi, company intra…

With a physical lock, you'd have to pick the lock each time you wanted access, and avoid being seen. The bar for repetitive attacks on the web is much lower, because you only need to write the "lock picking" script once, and then you can use it indefinitely, disseminate it, etc. A poorly protected website is more akin a house with no lock on it at all, and reporting that "this house has no lock" is not a criminal act…

(Devils Advocate)

What about this: seeing the house has no lock, opening the door, going inside, counting the money in the owners wallet, putting it back, then reporting that "Anyone could steal $300 from that guy".

Re: Teen Reported to Police After Finding Security Hole in Website

#42
post #25

(DEVIL'S ADVOCATE) Am I allowed to go to businesses and try to pick the locks, look inside, and then report to the business owner that their lock was pickable? Well... yes, but I'd probably be reported to police. Websites, like locks, aren't bullet proof. How many web applications out there don't have a security flaw somewhere? Doing penetration tests on unwilling victims is risky. Trying to break wifi, company intra…

They don't need help to see that some guy is fumbling their physical locks, a website can be attacked without been seeing.

Let me put that in another way, if a guest lean close to a lock and then look around to report that there is a defective lock or prone to fail I will be grateful. (But not if he pickit)

Re: Teen Reported to Police After Finding Security Hole in Website

#43
post #37

To me this is really weird. If a neighbor knocks on your door to tell you that you forgot the keys in the keyhole outside you thank him, you don't call the police...

This is a bit different and would be like the neighbor opening the door and waking into your bedroom to tell you.

Disagree.

Re: Teen Reported to Police After Finding Security Hole in Website

#45
post #37

To me this is really weird. If a neighbor knocks on your door to tell you that you forgot the keys in the keyhole outside you thank him, you don't call the police...

This is a bit different and would be like the neighbor opening the door and waking into your bedroom to tell you.

No, the kid didn't log into the website and make some postings to their internal communication systems (forums, email listings, etc). He attempted to contact them through official channels but was ignored.

After that, he went to the local news agency. This is totally different.

Re: Teen Reported to Police After Finding Security Hole in Website

#46
In the U.S., hacker Andrew Auernheimer, aka “weev”, is serving a three-and-a-half-year sentence for identity theft and hacking after he and a friend discovered a hole in AT&T’s website that allowed anyone to obtain the email addresses and ICC-IDs of iPad users.

I don't understand why weev is mentioned in the same article as this teen. Weev was allegedly discussing the practicalities of making money through fraud using the information he obtained. It's almost certain he wasn't wearing a completely white hat. This teen sounds like he was doing the proper white hat thing, but then got reported to the police anyhow, at least according to the information provided in the article.

Re: Teen Reported to Police After Finding Security Hole in Website

#47
post #29

When I first read The Cuckoo's Egg by Cliff Stoll, I was wondering if anyone would think to criminalize connecting something to the network that had no protection. So instead of throwing teenagers in jail, they would make an example of systems administrators. Perhaps that would have quickened the advance of internet security awareness. At one time, there was a law in Minnesota that it was a misdemeanor to leave your…

There are similar laws in many other jurisdictions.

I think there should be a digital whistleblower law to protect people who report such things in good faith. It should include a clause to make it negligence to ignore such a valid report.

Re: Teen Reported to Police After Finding Security Hole in Website

#48
post #44

And thus, once again, it's proven that full and anonymous public disclosure is the only way to notify website owners of their vulnerabilities.

And every time that happens a bunch of apologists appear shouting "Why didn't they inform the site operators first? That is really irresponsible"

And then some poor teen believes it and thinks "maybe it's wise to inform the site first" and subsequently goes to jail for doing the 'responsible' thing. And so the cycle continues.

Re: Teen Reported to Police After Finding Security Hole in Website

#49
post #25

(DEVIL'S ADVOCATE) Am I allowed to go to businesses and try to pick the locks, look inside, and then report to the business owner that their lock was pickable? Well... yes, but I'd probably be reported to police. Websites, like locks, aren't bullet proof. How many web applications out there don't have a security flaw somewhere? Doing penetration tests on unwilling victims is risky. Trying to break wifi, company intra…

Always beware of physical -> digital analogies. When the whole world has the ability to walk by your door, windows, and alarm system and pick at it without being seen, then you probably should be grateful when some of them let you know the back door is open.

Yes, but there's still a world of difference between walking by a door and stopping to pick the lock.

Re: Teen Reported to Police After Finding Security Hole in Website

#50
I was put into isolation for three weeks during high school when I was found to be hacking my way through the network. In reality I had found access to the remote server through the winword.exe open dialog that didn't require passwords and was displaying in the list of network drives, but didn't in explorer.

Because I found this, I was able to find the RM (Research Machines) Management Console and use a teachers (actually the deputy head) password "teacher" (no word of a lie) to create a hidden admin user in the list of student accounts. Through this I could get to RM Tutor 3 which allowed me to control every PC in the school.

I was gathering information to give to the IT staff, but I was grassed on instead, so I was in the wrong. I spent 3 weeks explaining everything and how to fix it, then I was allowed to continue my quest so long as I asked permission and gave info straight away rather than hoarding it.

Apparently if I had denied it they would've got the police involved, but I was honest and upfront when they asked me.

My brother started the same school three years ago (I've been gone for 8 years) and I was still able to access a few things with the remote panel — after which I alerted the school to it. I don't think they were best pleased to hear from me...

Post reply on HN