Live data from Hacker News

Teen Reported to Police After Finding Security Hole in Website

wired.com

71–80 of 123 posts

Re: Teen Reported to Police After Finding Security Hole in Website

#71
post #68

I was put into isolation for three weeks during high school when I was found to be hacking my way through the network. In reality I had found access to the remote server through the winword.exe open dialog that didn't require passwords and was displaying in the list of network drives, but didn't in explorer. Because I found this, I was able to find the RM (Research Machines) Management Console and use a teachers (act…

> I had found access to the remote server [...]. I was able to find the [...] Management Console and use a teachers [...] password [...] create a hidden admin user [...]. Through this I could [...] control every PC in the school. And this is why we can't have nice things. Admins at The Age (in this case) see someone trying to "report" a vulnerability and instantly jump to the conclusion that the user is someone like…

I don't see the point in bringing the legal hammer down on a student. With security holes this large and gaping, it's the system administrator that needs to change the way they do things. For instance, monitor the creation of new admin accounts, monitor logged data for events that indicate a breach, enforce some level minimal password difficulty, etc. This sort of malfeasance seems like _exactly_ what the sysadmin at a school should be expecting. Someone who waltzes up to the login prompt and types the first thing that comes to mind.

Personally, I don't think this or anything close should be made illegal. Who was hurt? What was the damage and the cost? Private data was likely at risk, and maybe there's a case to be made there, but I'm not entirely convinced that shouldn't be laid at the feet of the organization for shoddy security practices.

Re: Teen Reported to Police After Finding Security Hole in Website

#72
post #44

And thus, once again, it's proven that full and anonymous public disclosure is the only way to notify website owners of their vulnerabilities.

And every time that happens a bunch of apologists appear shouting "Why didn't they inform the site operators first? That is really irresponsible" And then some poor teen believes it and thinks "maybe it's wise to inform the site first" and subsequently goes to jail for doing the 'responsible' thing. And so the cycle continues.

Wouldn't combining the two tactics be the actually responsible thing to do? Inform the operators anonymously, and tell them that in four weeks a copy of this e-mail will be publicized.

Re: Teen Reported to Police After Finding Security Hole in Website

#73
post #67

Earlier quoted context omitted.

Where do you see that the paper gave them the kid's info? All I see is he contacted them directly, and no indication that the followup from the paper is where they got his info.

>When The Age called the Transportation Department for comment, it reported Rogers to the police. Last sentence in the third paragraph.

I assumed that "it" refers to the Transportation Department.

Re: Teen Reported to Police After Finding Security Hole in Website

#74
post #8
post #6

Clearly, the government department is wholly responsible for putting up a rubbish website, but from another article on the story, "He first contacted PTV by email on Boxing Day.." . I wonder if the "white-hat hacker" didn't time his notification quite intentionally knowing there was a much lower probability of action being taken promptly. If they'd just patched the security hole he wouldn't get any exposure. It makes…

By that logic why would he even bother reporting it and have security experts poking around the logs and potentially find traces of his download. Personally i would have sold it to the highest bidder. Being "white hat" gets you in trouble more often than not. Il stick to "gray hat" thank you very much. If i ever choose to disclose any vulnerability to the owners i will not reveal my identity and after arbitrary amoun…

> if it's still present sell it to the highest bidder let them deal with the consequences.

Them, and the innocent victims of this breach - the people who just wanted to buy a bus pass.

Why not disclose anonymously and publicly, instead of selling the data off?

Re: Teen Reported to Police After Finding Security Hole in Website

#75
post #25

(DEVIL'S ADVOCATE) Am I allowed to go to businesses and try to pick the locks, look inside, and then report to the business owner that their lock was pickable? Well... yes, but I'd probably be reported to police. Websites, like locks, aren't bullet proof. How many web applications out there don't have a security flaw somewhere? Doing penetration tests on unwilling victims is risky. Trying to break wifi, company intra…

Every time I hear about another case like this, I struggle with how I feel about it. I think it really depends on how he discovered the issue, and how far he took those findings. Let's say he just happened put a quote in a field and noticed that it broke the response from the site. That is a good indicator that a SQL injection might be possible. If he stops at that point and reports his findings, I don't see an issue with that. In my mind, it is like being at a friend's house, where you have permission to be, but noticing that their safe is wide open with their valuables visible to all. Or maybe being in a store and noticing that they've left the cash drawer wide open. However, if he continued to probe and see if he could get data using a SQL injection vulnerability, I feel that is more like walking up to the safe and jiggling the handle, or checking to see if that cash drawer is locked. I don't think your friend or the store owner would be very happy, and the site admins probably wouldn't be too happy about it either.

Re: Teen Reported to Police After Finding Security Hole in Website

#76
This seems to be the state of society we are in: If somebody uncovers a problem that exists, he is reported to the police. But if one organization spies on everybody and uses the data in irresponsible ways, they are promoted.

I have no doubt, that the coming generations will have big difficulties to distinguish between right and wrong.

We don't have the problem now with single fallen states, but with a fallen human kind.

Re: Teen Reported to Police After Finding Security Hole in Website

#77

Earlier quoted context omitted.

Your statement: Being "white hat" gets you in trouble more often than not. Is beyond absurd.

I would argue that your reply is the one that's absurd. Why is the quote you mentioned unreasonable?

Because "Being white hat gets you in trouble more often than not." is so obviously untrue to anybody with even the vaguest relation to the industry. It implies that more than 50% of the time, when you disclose a vulnerability responsibly you get in trouble. When it's more likely much much less than 0.1% of the time.

People getting in trouble for reporting vulnerabilities is highly rare. Show me 100 cases of it, and I'll still tell you it's rare.

Re: Teen Reported to Police After Finding Security Hole in Website

#78

This seems to be the state of society we are in: If somebody uncovers a problem that exists, he is reported to the police. But if one organization spies on everybody and uses the data in irresponsible ways, they are promoted. I have no doubt, that the coming generations will have big difficulties to distinguish between right and wrong. We don't have the problem now with single fallen states, but with a fallen human k…

[deleted]

Re: Teen Reported to Police After Finding Security Hole in Website

#80
post #62

In high school I was blacklisted from an admin position for demonstrating that you could write in Digital Command Language a program that simulated the login environment, stored login attempts, and then after three tries exited to the real login environment to let the user in. In college I was nearly expelled for just mentioning to the IT guys that they didn't have a password on some database, and I could get in with…

> These attitudes haven't changed much since 1990 at least. Why would they? A blatant oversight is a sign of incompetence and by making such incompetence public, you're threatening their job security. Why would anyone react positively? You're better off making the disclosure anonymously.

> You're better off making the disclosure anonymously.

When the info comes from an anonymous source they can't take their frustration out on the messenger. (Instead of thanking the messenger as they should.) I don't get why these hackers often give up their anonymity.

Post reply on HN