Live data from Hacker News

FBI raids dental software researcher who discovered patient data on FTP server

dailydot.com

121–130 of 171 posts

Re: FBI raids dental software researcher who discovered patient data on FTP server

#121
post #100

Earlier quoted context omitted.

Two reasons perhaps. Publicity and safety of the officers. How do they know how this person is going to react (or anyone else in the house)? And the publicity is much greater with a greater show of force (hence a deterrent) as well with a shock and awe response.

Research on the subject says this is more dangerous for the cops then the calmer approaches. The irony is cops do this to protect themselves, and statistically speaking it has the exact opposite effect.

Can you provide a link to said research?

Re: FBI raids dental software researcher who discovered patient data on FTP server

#122
post #37

This reminds me of something that happened to me in high school back in 1999. I found an Excel doc in a public network drive that contained every single student's SSN, DOB, whether they had free/reduced lunch, address, phone, etc. I was admittedly snooping around, but this was all public stuff every student and teacher had full access to. When I found it, I told one of the teachers that I trusted and she insisted tha…

and people wonder why schools get shot up.

you did this to yourselves.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#123

Earlier quoted context omitted.

Research on the subject says this is more dangerous for the cops then the calmer approaches. The irony is cops do this to protect themselves, and statistically speaking it has the exact opposite effect.

If the research says that then either: (1) The law enforcement decision makers are unaware of the research (which is unlikely), or (2) The stated motivation is not the actual motivation.

Or (3) they don't believe the research and trust their "instincts", right or wrong.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#124
post #84

Earlier quoted context omitted.

Honestly, going after the FBI for lying to the Finnish police would probably be a pretty hard case to win. Especially considering how blatantly unreasonable the behaviour of the .fi authorities has been. It's possible that I could win. But that wouldn't really achieve anything, it wouldn't make the .fi authorities stop. The best option I have available is to keep fighting my charges in Finland, as no matter whether I…

If your story is true, then you were, as it appears, wrongfully and unlawfully imprisoned. I think you should at least try contacting press and some lawyers -- if what you are saying is a true story. It sounds pretty interesting to me -- I imagine someone in the press would pick it up.

>If your story is true, then you were, as it appears, wrongfully and unlawfully imprisoned. I think you should at least try contacting press and some lawyers -- if what you are saying is a true story.

I was indeed wrongfully imprisoned, but by the Finnish government. I can and will receive compensation from them but at best that's going to be a few thousand euros per month, a nominal sum considering the time lost. It's hardly an irregular thing here, mostly because every single case where a person is taken into investigative custody and not given a prison sentence is treated as such. This has created a situation where these cases are so common that the justice system treats them as acceptable routine.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#125
post #37

This reminds me of something that happened to me in high school back in 1999. I found an Excel doc in a public network drive that contained every single student's SSN, DOB, whether they had free/reduced lunch, address, phone, etc. I was admittedly snooping around, but this was all public stuff every student and teacher had full access to. When I found it, I told one of the teachers that I trusted and she insisted tha…

> I was nearly expelled for "hacking". They placed me on "academic probation" and threatened that if I did so much as forget my school ID at home one day, I would be immediately expelled without question. I was removed from my elective classes that involved computers and was disallowed from touching any computers at school.

Makes me glad that my school was reasonable when I got dragged into some "hacking" accusations. We were just made to work with the IT staff for a week (instead of going to classes), and that was the end of it.

The IT staff were surprising fine with it all (I think they realised A) that we weren't malicious, just bored and curious, and B) that it was their mistakes that gave people access (VNC server installed on all PCs with the password "vnc"; domain admin. account having the password of "school" etc.)

Re: FBI raids dental software researcher who discovered patient data on FTP server

#126
post #97

Earlier quoted context omitted.

Remember clock Ahmed the clock kid? I had a situation almost exactly like his, except I made a working FM radio, could change stations and listen to local news and weather, I thought it was the coolest thing ever. The school did not, and the district superintendent agreed with them. Who knew that an FM Radio made out of a La Gloria Cubana cigar box-with labelling removed so as not to run afoul of any "tobacco paraphe…

It sounds like you weren't sufficiently brown to get media attention? "Public school bureaucracy run by bureaucrats" doesn't have the right mass appeal.

> It sounds like you weren't sufficiently brown to get media attention?

Or just didn't have a family with the right media instincts.

> "Public school bureaucracy run by bureaucrats" doesn't have the right mass appeal.

It has incredible mass appeal, which is frequently exploited politically -- by both sides of the political spectrum.

But for it to get media attention, someone's got to get it to the media's attention. Outside of people and institutions that are already high-probability news sources, the media isn't really actively monitoring what goes on to find potential stories, things become stories because someone involved brings it to the attention of the media.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#128
post #58
post #49

Earlier quoted context omitted.

Step 1: Anonymously report them to law inforcement. There is no step 2.

Nonsense. It could be as a easy as printing fliers at home and dropping them in an appropriate space, or mailing letters with the return address the same as the mailing address, or using Tails 2.x to email hippa and the police using a throwaway address. But contacting them in person? NFW

Never print anything for anonymous purpose. All printers have a watermark.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#129
post #13

I could not get this site to fully load even after (or maybe because) my adblocker blocked 68 requests. However, loads great in lynx!

I wasn't joking, the site actually loads much better, faster and more readably in lynx than it did in my regular browser (safari with ABP)

Re: FBI raids dental software researcher who discovered patient data on FTP server

#130

This is so wrong, but it's not surprising. We've been reading stories for years of security researchers being charged with a crime or harassed for simply pointing out blatant security holes. What kind of thinking is this? He was doing them a favor. Every time, it seems to me that they are embarrassed by the incident and lash out. WHY!?? We should be treating these researchers like heroes, not kicking in their doors a…

I thought they did not have the "reason" for the arrest -- only the warrant.

The arrest may have nothing to do with accessing the Public FTP, and entirely to do with the research he was doing on the FTP service itself. If he was attempting to exploit the FTP service hosted by someone else (something or other aboubt database credentials was mentioned), he would absolutely be in violation of CFAA. You do that sort of research on your OWN system.

First rule of security testing: make sure you have permission.

Post reply on HN