Earlier quoted context omitted.
"...testing deployed systems without authorization is always risky..." While what you describe may be the sad reality, it makes zero sense. If a legit researcher, 'specially one that's being transparent about it, researches any domestic system, then that's got to be better than the Iranians, Russians or Chinese doing it (which they do anyway). But hey, what do we know anyway. There's probably some benefit that makes…
How would you feel if I broke into your place of business, made a list of all of the things you were doing that were out of compliance with federal and state laws and regulations, then left you my card and offered to let you hire me to do legal compliance work for you?
US cybercrime laws being used to target security researchers
41–50 of 94 posts
Re: US cybercrime laws being used to target security researchers
#42this is dumb on many layers - threatening white hat who could be held accountable but could be hired to do further audit; failing to come to grips that if you are insecure enough to threaten someone, you know - internet will find out that you rather than fixing holes in your system rather use expensive lawyers to intimidate people who on the whole trying to a good thing for you. The whole thing about unauthorized acc…
Re: US cybercrime laws being used to target security researchers
#43Earlier quoted context omitted.
"...testing deployed systems without authorization is always risky..." While what you describe may be the sad reality, it makes zero sense. If a legit researcher, 'specially one that's being transparent about it, researches any domestic system, then that's got to be better than the Iranians, Russians or Chinese doing it (which they do anyway). But hey, what do we know anyway. There's probably some benefit that makes…
How would you feel if I broke into your place of business, made a list of all of the things you were doing that were out of compliance with federal and state laws and regulations, then left you my card and offered to let you hire me to do legal compliance work for you?
Re: US cybercrime laws being used to target security researchers
#44Earlier quoted context omitted.
Agreed. You don't get a pass for breaking into someone's house just because you say you weren't there to cause any harm. Yes, it's good to be pragmatic and understand that there's always something the owner of the house could have done to help prevent the break in -- close the door, lock them, get locks that are harder to pick, install security cameras, etc. etc. -- but the person breaking into your house is still wr…
I think what makes it tricky is that the systems are automated and intent and authorization aren't so clear. We never call up the owner of a web server and ask them for permission to browse their site. We just connect to port 80 or 443 and go to town. This is universally accepted as authorized use. Now, say you're running a vulnerable sshd such that if you send just the right bytes, it'll log you in as root without t…
The real problem is that a lock on a door is more obvious than a URL scheme. The government is saying that entering a 7-11 that is unlocked, but walking in backwards, is criminal trespass because that's not what the 7-11 intended for the customer to do. That's nonsense. Implicit authorization in physical property is just so much more straightforward, and the government is trying to maliciously take advantage of the lack of common sense on what is unauthorized, helped along by a Congress that willfully authorizes such action.
And I like your server dealer analogy. The question is whether or not a computer is an agent of its owner and whether its decisions, right or wrong, can be relied upon in business dealings as the actions of its owner.
So what is the digital equivalent of a lock on a door? Must the law explicitly say a lock on a door signifies lack of authorization to enter? Is walking into a 7-11 store backwards implicitly unauthorized?
Re: US cybercrime laws being used to target security researchers
#45Earlier quoted context omitted.
"...testing deployed systems without authorization is always risky..." While what you describe may be the sad reality, it makes zero sense. If a legit researcher, 'specially one that's being transparent about it, researches any domestic system, then that's got to be better than the Iranians, Russians or Chinese doing it (which they do anyway). But hey, what do we know anyway. There's probably some benefit that makes…
I disagree that it makes zero sense. There are reasonable concerns at play here: * Security testing is extremely disruptive to production systems, most especially if those systems haven't been hardened in any way. Security testers are not as a rule good at predicting how their tests can screw up a production system. * No matter how much effort you put into a security program (Google and Facebook put a lot of effort i…
"...especially if those systems haven't been hardened..."
Well that's just it, isn't it? If the system hasn't been hardened then it wouldn't hold anything of interest and therefore wouldn't be targeted by either friendly researchers or malicious adversaries.
If a system holds value it should be appropriately secured. That must include dealing with attacks as part of business as usual.
As for meaningful, selective pressure - well then why bother with bug bounties? Even Microsoft, the only organisation at that level with a published SDL [edit: security development lifecycle], offers them now.
SDL ref. http://msdn.microsoft.com/en-us/library/windows/desktop/cc30...
I've had my rant. Will shut up now.
Re: US cybercrime laws being used to target security researchers
#46Earlier quoted context omitted.
Yeah, it felt kinda trite writing it. I just haven't found a way to articulate the idea without asking myself "Oh, so you're still a teenager getting stoned every day thinking you have thoughts about things, hows that working out for you?" Edit: Maybe I should just lean into it and write a phrack article. I'm sorry, that's a low blow, I enjoyed phrack even when the writing style wasn't my speed.
I'll just note that the biggest "moneyed interests" in the technology industry have more or less waived most of their ammunition to stop research under the CFAA by posting public bug bounties. Not only have they made it much harder to sue researchers, but they also pay strangers to do it.
Who would actually oppose fixing that? Is it purely a lack of understanding the issue on the part of legislators?
Re: US cybercrime laws being used to target security researchers
#47Earlier quoted context omitted.
I'll just note that the biggest "moneyed interests" in the technology industry have more or less waived most of their ammunition to stop research under the CFAA by posting public bug bounties. Not only have they made it much harder to sue researchers, but they also pay strangers to do it.
It makes me wonder who actually likes the CFAA the way it is. Does anybody? I don't see how it's helping anybody. Most of the actually malicious computer intrusions come from outside of U.S. jurisdiction. It's like trying to reduce child labor in China by increasing the breadth of the offense and severity of the penalties in Texas. The next thing you know nothing has changed in China but a father in Texas is facing f…
I actually do not have a problem with the CFAA's statutory prohibitions on unauthorized access. They seem eminently sensible to me. Don't mess with systems that don't belong to you.
I do think the CFAA has a grave and dangerous flaw: I think its sentencing makes absolutely no sense. I generally do not believe that computer crimes should have sentences that scale with the iterator in a "for()" loop. In the cases where sentences could reasonable scale along with the magnitude of the attack, the meaningful scaling factor should (and I think typically does, in a sane reading of the law) come from some other crime charged along with CFAA.
Re: US cybercrime laws being used to target security researchers
#48Earlier quoted context omitted.
I disagree that it makes zero sense. There are reasonable concerns at play here: * Security testing is extremely disruptive to production systems, most especially if those systems haven't been hardened in any way. Security testers are not as a rule good at predicting how their tests can screw up a production system. * No matter how much effort you put into a security program (Google and Facebook put a lot of effort i…
TLDR: I strongly disagree. " ...especially if those systems haven't been hardened... " Well that's just it, isn't it? If the system hasn't been hardened then it wouldn't hold anything of interest and therefore wouldn't be targeted by either friendly researchers or malicious adversaries. If a system holds value it should be appropriately secured. That must include dealing with attacks as part of business as usual. As…
Re: US cybercrime laws being used to target security researchers
#49Earlier quoted context omitted.
How would you feel if I broke into your place of business, made a list of all of the things you were doing that were out of compliance with federal and state laws and regulations, then left you my card and offered to let you hire me to do legal compliance work for you?
If it was well known that large and highly funded subsets of foreign militaries were roaming around breaking into everyones businesses and stealing things / exploiting the lack of legal compliance then, yes, I'd be very pleased that someone took the time to both find the mistake and give me the chance to fix it / get it fixed by them before it was used against me with legitimate malicious intent.
Re: US cybercrime laws being used to target security researchers
#50Earlier quoted context omitted.
And as someone who has been on both sides of doing security research and systems administration. Generally, this kind of "pro bono" work isn't telling us anything we don't know, and since its not coordinated with the target it'll potentially get system/network/security adminstrators up at 3am in their morning to respond to your probes, and will drain company resources. You're also demanding that the company address w…
" ...this kind of "pro bono" work isn't telling us anything we don't know... " That's scary right there. If you're deploying something you know has vulnerabilities you have bigger problems than losing sleep at 3am. Same for operating something you know is vulnerable. You (collective, not you, personally) totally deserve to get up at 3am. It's grossly irresponsible, because what you probably don't already know is how…
Everything has vulnerabilities.