Live data from Hacker News

US cybercrime laws being used to target security researchers

theguardian.com

61–70 of 94 posts

Re: US cybercrime laws being used to target security researchers

#61

Earlier quoted context omitted.

" ...this kind of "pro bono" work isn't telling us anything we don't know... " That's scary right there. If you're deploying something you know has vulnerabilities you have bigger problems than losing sleep at 3am. Same for operating something you know is vulnerable. You (collective, not you, personally) totally deserve to get up at 3am. It's grossly irresponsible, because what you probably don't already know is how…

> If you're deploying something you know has vulnerabilities ... Everything has vulnerabilities.

Would "something with known vulnerabilities" be better?

Does everything have known vulnerabilities that are not actively being worked on?

Re: US cybercrime laws being used to target security researchers

#62
post #38

Earlier quoted context omitted.

How would you feel if I broke into your place of business, made a list of all of the things you were doing that were out of compliance with federal and state laws and regulations, then left you my card and offered to let you hire me to do legal compliance work for you?

"Broke in" rather presupposes the point. If we're analogizing, an exterminator seeing rat droppings in your restaurant and offering to solve your problem rather than letting the department of health deal with it, is a slightly more realistic example.

Taking that a step further: it is like an exterminator going around different of restaurants, then crawling under customer's tables while they are eating, saying, "Don't mind me, just looking from rat droppings."

A more legit exterminator would agree to come past while the customers were not there.

Re: US cybercrime laws being used to target security researchers

#63
post #6

Earlier quoted context omitted.

So should someone find a remote exploit in OpenWhatever that gives them remote root access and they publicly disclose that (without having tested it on the Internet... just in their lab) then they are not subject to the CFAA?

Correct. The CFAA requires access without authorization or exceeding authorized access. Presumably you are an authorized user of your own systems. It is possible that some vendors may try to use User Acceptance Licenses to further restrict what actions can be taken with their software (even in case where you've purchased it and installed it on your system). I believe (and would love to be corrected by a lawyer), that…

I have no problem with punishing unauthorized access although the punishment is stupid severe.

I mean once you've been sentenced under the CFAA you might as well have a shootout with the police or kill some people it make no difference hell the extra charges won't make much a difference you're still facing life.

Does that make sense to anybody?

What they do require though is an exception for researchers and you can define researchers anybody who discloses the vulnerability to the owner of the vulnerable system before publishing it publicly. A security researcher is required to disclose publicly the results of his research in order to be considered a researcher.

A regular hacker cannot claim to be a security researcher since hackers never disclose the vulnerabilities they find to the owner of the system even if they do share them publicly with other hackers sometimes. It is not in their interest to let the owner of the vulnerable system know they have a problem.

Re: US cybercrime laws being used to target security researchers

#64
post #18

Earlier quoted context omitted.

Google, Facebook, and now over 70 companies do grant tacit permission for anyone to test their systems, and will pay the researchers for a disclosure, as long as they follow the program rules , which are usually quite reasonable. I'm serious when I say that few people are more thankful than myself for the existence of security bug bounties. However, one thing has always crossed my mind: since the legal definition of…

> only the owner of the hacked computer can file a complaint against the attacker, and legal proceedings can commence only after such a complaint has been filed. Does it work the same way in the U.S.? After a US law enforcement agency has been notified of a complaint by a victim of a crime they forward it to a prosecutor. At this point the victim can no longer drop the charges. The only person who can drop the case t…

There is something really disturbing about a system that allows personal ambition to play such an important role in how the institution of justice operates in effect, at least in specialised matters like this.

Expensive attorneys and ambitious prosecutors, each trying to twist half-truths to, more or less, ignorant judges and jurys. Makes me wonder if some of these servants of justice are forgetting that, their specific role aside, as the above description suggests, their common goal is to reach an honest conclusion about whether someone actually did something wrong, which implies everyone's effort to understand in what ways are the related actions harmful and how does that harm balance against fundamental freedoms.

Re: US cybercrime laws being used to target security researchers

#65
post #42
post #7

this is dumb on many layers - threatening white hat who could be held accountable but could be hired to do further audit; failing to come to grips that if you are insecure enough to threaten someone, you know - internet will find out that you rather than fixing holes in your system rather use expensive lawyers to intimidate people who on the whole trying to a good thing for you. The whole thing about unauthorized acc…

I am just a simple country boy, but my understanding of "White Hat" is about hacking done with explicit permission. The article suggests activities that cross the line.

Exploring open systems is a right, hence the open internet. If you don't want people walking the streets maybe you should put up a fence, close the door. Since internet protocols provide authorization via login/authentication token functionality - that what people should use to provide restricted services - not sic lawyers when someone elses packets land in their networks. RTF-RFCs.

Re: US cybercrime laws being used to target security researchers

#66
post #42
post #7

this is dumb on many layers - threatening white hat who could be held accountable but could be hired to do further audit; failing to come to grips that if you are insecure enough to threaten someone, you know - internet will find out that you rather than fixing holes in your system rather use expensive lawyers to intimidate people who on the whole trying to a good thing for you. The whole thing about unauthorized acc…

I am just a simple country boy, but my understanding of "White Hat" is about hacking done with explicit permission. The article suggests activities that cross the line.

Exploring open systems is a right, hence the open internet. If you don't want people walking the streets maybe you should put up a fence, close the door. Since internet protocols provide authorization via login/authentication token functionality - that what people should use to provide restricted services - not sic lawyers when someone elses packets land in their networks. RTF-RFCs.

Re: US cybercrime laws being used to target security researchers

#67
post #64
post #18

Earlier quoted context omitted.

> only the owner of the hacked computer can file a complaint against the attacker, and legal proceedings can commence only after such a complaint has been filed. Does it work the same way in the U.S.? After a US law enforcement agency has been notified of a complaint by a victim of a crime they forward it to a prosecutor. At this point the victim can no longer drop the charges. The only person who can drop the case t…

There is something really disturbing about a system that allows personal ambition to play such an important role in how the institution of justice operates in effect, at least in specialised matters like this. Expensive attorneys and ambitious prosecutors, each trying to twist half-truths to, more or less, ignorant judges and jurys. Makes me wonder if some of these servants of justice are forgetting that, their speci…

Judges and juries aren't ignorant. They just don't give a shit about the things that are important to you. To your typical juror off the street, "hacking" into a computer for ostensibly "white hat" reasons is no different than breaking into a store to "test the alarm system." The reaction is not "oh yes, we have to make sure our legal system is flexible enough to accommodate this sort of 'security research'" but rather, first, "I don't believe you" or, at best, "didn't your mother ever tell you it is wrong to mess with other peoples' things without permission?"

Re: US cybercrime laws being used to target security researchers

#69
post #38

Earlier quoted context omitted.

How would you feel if I broke into your place of business, made a list of all of the things you were doing that were out of compliance with federal and state laws and regulations, then left you my card and offered to let you hire me to do legal compliance work for you?

That's not quite a fair analogy. It'd be more like if you go into a bank and see a giant hole in their vault. You tell them about it and they sue you for breaking it. Meanwhile actual criminals come and go as they please anonymously. The bank's clients are the actual victims of course, it's not like this just affects the bankers.

[deleted]

Re: US cybercrime laws being used to target security researchers

#70
post #67
post #64

Earlier quoted context omitted.

There is something really disturbing about a system that allows personal ambition to play such an important role in how the institution of justice operates in effect, at least in specialised matters like this. Expensive attorneys and ambitious prosecutors, each trying to twist half-truths to, more or less, ignorant judges and jurys. Makes me wonder if some of these servants of justice are forgetting that, their speci…

Judges and juries aren't ignorant. They just don't give a shit about the things that are important to you. To your typical juror off the street, "hacking" into a computer for ostensibly "white hat" reasons is no different than breaking into a store to "test the alarm system." The reaction is not "oh yes, we have to make sure our legal system is flexible enough to accommodate this sort of 'security research'" but rath…

To your typical juror off the street, "hacking" into a computer for ostensibly "white hat" reasons is no different than breaking into a store to "test the alarm system."

That sounds a lot like ignorance.

Post reply on HN