Earlier quoted context omitted.
In this case, the problem wasn't so much that Trib Corp had poor security (they probably do though), but rather that an insider exfiltrated credentials to one of their servers to an IRC channel. There are a few companies in our industry where that attack wouldn't be devastating, because of very carefully designed security programs. But there are not many of those companies. Most companies you've heard of are just as…
But charging them with hacking? And putting them in prison for 2 years?
Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking
11–20 of 67 posts
Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking
#12Earlier quoted context omitted.
It is surprising to mere mortals that reverting a web page to a previous version, as GP described, costs that much. I can see an argument to include costs of investigation, and a much more tenuous argument to include costs to fix a vulnerability, but frankly the arguments not to include those costs seem more compelling. After all the defendant in this case didn't design and implement the relatively weak security. Tha…
Can you be more precise about "relatively weak security"? The accused in this case exfiltrated credentials to the system that was compromised. Most companies would fall to that attack. Meanwhile: they clearly can't just revert the web page. Keys gave a hacker group a login for a web application. How, exactly, does Trib Corp know how much damage the hacker group did to the server? There needs to be an investigation, a…
It isn't at all clear to me that the eggshell rule is relevant to this situation. This was not an act of violence. Packets were exchanged among computers, which resulted in other packets being exchanged among computers. The "legal reasoning by tortured analogy" one sees so often on HN has really crippled our collective intelligence.
Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking
#13Earlier quoted context omitted.
Can you be more precise about "relatively weak security"? The accused in this case exfiltrated credentials to the system that was compromised. Most companies would fall to that attack. Meanwhile: they clearly can't just revert the web page. Keys gave a hacker group a login for a web application. How, exactly, does Trib Corp know how much damage the hacker group did to the server? There needs to be an investigation, a…
It's my understanding that credentials were used to access a system from "outside" some time after the employment of the user associated with those credentials ceased. That is weak, relative to other firms that take the steps necessary to retire the credentials of former employees. I've worked at such firms; I know they exist. You probably have a better sense of the "average" state, however. It isn't at all clear to…
The person who smacks the eggshell-skulled victim upside the head with a magazine couldn't imagine that doing so would have fractured their skull. People don't normally have skulls as thin as eggshells. "Tough shit", says the law. "If you don't want to expose yourself to the risk of fracturing someone's skull, don't hit people upside their heads with magazines."
By the same token, whatever frailties existed in Trib Corp's internal security, necessitating expensive post-breach cleanup, are justifiably imputed to Keys, not to Trib Corp.
Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking
#14At some point we have to acknowledge these tough cyber laws do nothing but pass down intentionally harsh sentences to the unlucky few Americans that get the book thrown at them.
I predict we'll look back at them with the same embarrassment and shame we do mandatory minimum drug sentencing laws now.
Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking
#15Earlier quoted context omitted.
It's my understanding that credentials were used to access a system from "outside" some time after the employment of the user associated with those credentials ceased. That is weak, relative to other firms that take the steps necessary to retire the credentials of former employees. I've worked at such firms; I know they exist. You probably have a better sense of the "average" state, however. It isn't at all clear to…
The rule isn't about violence. It's about the fact that someone who commits a wrong can't rely on the victim's prior diminished circumstances to mitigate the impact of their own wrong. The person who smacks the eggshell-skulled victim upside the head with a magazine couldn't imagine that doing so would have fractured their skull. People don't normally have skulls as thin as eggshells. "Tough shit", says the law. "If…
As described above, against a firm with a modicum of security procedure, this "attack" would have been a no-op. As in, all the same actions could have been taken, and they would have had no effect whatsoever. "Attacks" like this take place every day, and many even succeed, with no action from prosecutors whatsoever.
You and I have different conceptions of justice. It may well be that yours conforms more exactly to that enforced by the courts; we don't live in a perfect world.
Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking
#16Earlier quoted context omitted.
The rule isn't about violence. It's about the fact that someone who commits a wrong can't rely on the victim's prior diminished circumstances to mitigate the impact of their own wrong. The person who smacks the eggshell-skulled victim upside the head with a magazine couldn't imagine that doing so would have fractured their skull. People don't normally have skulls as thin as eggshells. "Tough shit", says the law. "If…
Wow I wish that "rule" applied somehow to cyclists and pedestrians killed by motorists. That would be handy! As described above, against a firm with a modicum of security procedure, this "attack" would have been a no-op. As in, all the same actions could have been taken, and they would have had no effect whatsoever. "Attacks" like this take place every day, and many even succeed, with no action from prosecutors whats…
Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking
#17If someone broke into the tribune's printing office (which perhaps didn't collect the key or change the lock when they fired someone) and that person changed the headline and a byline for an article in the paper that went out to thousands of people, I still have a hard time believing a court would put that person in prison for 2 years because of it. At some point we have to acknowledge these tough cyber laws do nothi…
Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking
#18Earlier quoted context omitted.
But charging them with hacking? And putting them in prison for 2 years?
There's no such charge as "hacking".
Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking
#19Earlier quoted context omitted.
There's no such charge as "hacking".
Of course. We're able to make the distinction of being hacked versus someone crawling through an open window. If only jurors could be expected to do the same.
Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking
#20Such a BAD use of tax payer money. So now we have to pay for 2 years of jail time (Probably 1 year for good behavior) for giving a key (That was actually not proven but was believed by the juror. The crime was the defacing of ONE page. This key also should have been revoked after he left the company. The recommendation of 7 years is just crazy and even the lowered 5 years is just nuts. If you just look at the cost to…
In this case, the problem wasn't so much that Trib Corp had poor security (they probably do though), but rather that an insider exfiltrated credentials to one of their servers to an IRC channel. There are a few companies in our industry where that attack wouldn't be devastating, because of very carefully designed security programs. But there are not many of those companies. Most companies you've heard of are just as…