Live data from Hacker News

FBI raids dental software researcher who discovered patient data on FTP server

dailydot.com

11–20 of 171 posts

Re: FBI raids dental software researcher who discovered patient data on FTP server

#11
Another lesson not to trust people/organizations ignorant enough to keep confidential data in plain text on anonymous FTP.

It seems that the 21st century responsible disclosure procedure goes like that:

0. use tor for the research itself

1. report problems anonymously

2. if they don't care - report them to law enforcement for breach of confidentiality

3. if these don't care either or don't accept anonymous tips - make noise in the media

Of course, this is for dealing with idiots who keep their data on public FTP. If the attack takes some clever hacking, go check if they don't offer bug bounties. Funny times we are living in.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#12

The FBI is going to have a hell of a time arguing that accessing a public FTP server with no password protection is a crime.

The outcome of a trial is secondary. Have you ever been sued by the government? How much money, time, effort and nerves do you think you will lose, no matter the outcome? The act of being sued is plenty of punishment. If they really want to destroy you they can keep going through the courts even after losing - they could not care less if they win or lose.

> The act of being sued is plenty of punishment.

This is so true and so many people don't realize it.

It's easy to be idealistic about these things until it actually happens to you.

Being "in the right" doesn't mean you'll win ("right" according to your morals/ethics and "right" legally are often two completely different things) and it doesn't mean that the costs of fighting - financial, personal, etc. won't ruin you, especially when the plaintiff is stubborn, vindictive and has deeper pockets than you do.

More often than not, you'll end up settling civil cases, and the tangible and intangible costs that you accrued while fighting your case are usually victory enough for the plaintiff.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#15

The FBI is going to have a hell of a time arguing that accessing a public FTP server with no password protection is a crime.

I am pleased they might move forward with this prosecution. Keep in mind the legal costs incurred to do this, in addition to the already employed 12-15 FBI agents who were probably paid overtime to heroically rescue that poor family from this monster was already well worth the cost. Spending more money and resources here is obviously the right thing to do. Really, the resources expended to handcuff this man in his boxers in front of his 9-year-old daughter were a very well allocated by one of our most important government agencies, the FBI.

I'm also very much glad to see the incredible foresight and knowledge that the FBI is displaying here. What better way to show us why we should not responsibly disclose data vulnerabilities than to arrest and raid someone's home for doing so?

Stories like this really influence me to put my faith in the capabilities of law enforcement. What that means for our individual rights and freedoms, and for the future of the US economy is sure to be nothing but excellent! I would never think about moving away from such a country!

Re: FBI raids dental software researcher who discovered patient data on FTP server

#16
post #5

Earlier quoted context omitted.

I believe that it is still considered unauthorized access even if they don't have a password set up. I think it goes back to law that existed before computers where if you entered someones home without permission you can't simply argue that there wasn't a lock on the door. Edit: ProAm above reminded me of the Andrew Auernheimer case that was nearly identical to this and was resolved as I describe.

Please stop with home / lock / etc. metaphors. This is a very simple situation and there is no need to analogize. When you analogize to a separate situation like keyed locks or zeppelin airspace access rules you're attempting to say something about similarities between the reasoning in resolving the rule on both sides, which requires you to actually make a contention about what aspects of the situation are compatible…

I was merely theorizing that in 1986 when the Computer Fraud and Abuse Act was written that was the reasoning behind why it was written in that way. I assumed that the readers here understand the underlying tech involved.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#18

It needs to be understood that if you react this way to responsible disclosure practices, your company & you personally will be subject to irresponsible disclosure practices.

Oh, I've already learned the lesson loud and clear. If I ever discover a vulnerability to disclose, I'm releasing it anonymously on pastebin sites while logged into Tor through a VPN from a free WiFi spot.

And, of course, sign it with a new PGP key you've just created, so that if you ever need to release a follow-up with proof that it's you, or come forward as the author of the disclosure, you can.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#20
It sounds like Patterson Dental deserves as much blame as the FBI, if not more, because it sounds like they were the ones pressing charges and motivating prosecution in the first place. Also, why aren't they being charged with what is almost certainly a HIPAA violation?
Post reply on HN