Live data from Hacker News

FBI raids dental software researcher who discovered patient data on FTP server

dailydot.com

141–150 of 171 posts

Re: FBI raids dental software researcher who discovered patient data on FTP server

#141
post #37

This reminds me of something that happened to me in high school back in 1999. I found an Excel doc in a public network drive that contained every single student's SSN, DOB, whether they had free/reduced lunch, address, phone, etc. I was admittedly snooping around, but this was all public stuff every student and teacher had full access to. When I found it, I told one of the teachers that I trusted and she insisted tha…

A similar thing happened to me at my university. This new website came out called TheFacebook.com and it seemed hip to add artificial friends like famous actors, super heroes, etc. I had the bright idea to add the school president as a friend by creating a fake account like the thousands of other fake accounts on TheFacebook. I needed a university email address, but luckily, my school allowed you to create a personal…

Some time later I received a letter with a list of 20 or so charges including things like Identity Theft and the possibility that I may be expelled.

Wow. Whatever happened to the cops coming and saying "That was dumb. Let this be a lesson. Don't do it again."?

Re: FBI raids dental software researcher who discovered patient data on FTP server

#142
post #101

Earlier quoted context omitted.

Requiring the warrant to specify the level of force could be interesting. Are there good reasons why this could not be done?

I honestly don't think that being rude and/or hurting feelings (or scarring a baby) really enters into law enforcement of this type (also see my other comment).

You're moving the goal-posts. I don't think that being rude or hurting feelings should cross their mind.

Bringing a gun escalates things immediately. If I was in that home and I was carrying a gun, and if a handful of people abruptly came in with assault rifles, I'm liable to react very differently because it's such an affront to what feels reasonable. I think it's more reasonable to think that this is a terrorist attack and to react accordingly, rather than the reality of people acting as an agent of the government bringing deadly force in droves because someone grabbed a file from a public FTP server.

If I had seen 5 men in suits and shades peacefully walk in without any kind of weapon, I'm not going to think anything of it. They're putting themselves at risk. It makes no sense.

And the honest answer as to, "why?" is that the people who kick in doors are complete meatheads who think that morality and legality strictly align. They think if someone has broken the law, they deserve anything that is coming. They don't care about anyone's safety, they care about taking baddies.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#144
post #90

As a separate issue: why the "shock and awe" response to what is (even allegedly) a non-violent crime? Why the assault rifles? Why could he not have been arrested by just a couple agents walking upto the door, knocking, serving the search warrant, and then maybe having the techs step in to conduct the search and seizure? Why does US Law Enforcement so dramatically escalate every contact with a citizen? Everytime they…

>Why does US Law Enforcement so dramatically escalate every contact with a citizen?

US LEOs are indoctrinated with the belief that they are 'at war'. Convincing the public of this is imperative to retaining authority, securing more funding, and receiving immunity from any consequences of their actions. One way they accomplish the above is by never passing up an opportunity to dress up like an army man and publicly display force

Re: FBI raids dental software researcher who discovered patient data on FTP server

#145
post #97
post #55

Earlier quoted context omitted.

> I was nearly expelled for "hacking". They placed me on "academic probation" This reaction makes me very, very angry. I would love to push it back on them: it's unclear under what laws/regulations this would fall, but if you (as the student who found it) can get in trouble for finding this info, they can most certainly get in trouble for posting it in a location it can be found in. Further, because you were actually…

Remember clock Ahmed the clock kid? I had a situation almost exactly like his, except I made a working FM radio, could change stations and listen to local news and weather, I thought it was the coolest thing ever. The school did not, and the district superintendent agreed with them. Who knew that an FM Radio made out of a La Gloria Cubana cigar box-with labelling removed so as not to run afoul of any "tobacco paraphe…

> Remember clock Ahmed the clock kid?

It turned out that his invention was a fully pre-built alarm clock removed from its plastic housing.

Also other details emerged that pretty much sealed the case against him - what he did was create an intentional hoax.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#146
post #115

Earlier quoted context omitted.

Requiring the warrant to specify the level of force could be interesting. Are there good reasons why this could not be done?

At a federal level, this is mostly done. Before executing a search warrant, feds usually pull criminal background and check gun registries. Then look at the reason for a search warrant (drugs, guns, terrorism, etc.). In theory, they combine those things to decide whether to just knock on the door and walk in or bring SWAT along. This happens different between agencies and what parts of the country. But, codifying the…

They check gun registries? Why?

I suppose that registered guns suggest that someone is not criminal, because the alternative assumption should be unregistered guns.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#147
post #101

Earlier quoted context omitted.

Requiring the warrant to specify the level of force could be interesting. Are there good reasons why this could not be done?

I honestly don't think that being rude and/or hurting feelings (or scarring a baby) really enters into law enforcement of this type (also see my other comment).

It wasn't long ago that an officer serving a warrant for a non violent offense threw a grenade into a baby's crib (yes, the baby was inside).

Now I'm not sure where their training draws the line on infant collateral damage: Don't shoot in rooms with babies? Shoot around the babies?

But imagine if the rule was: Don't upset the children. (silly I realize, but thats how what-ifs are played). It seems like decisions would be made resulting in fewer grenades landing in bassinets.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#148
post #146
post #115

Earlier quoted context omitted.

At a federal level, this is mostly done. Before executing a search warrant, feds usually pull criminal background and check gun registries. Then look at the reason for a search warrant (drugs, guns, terrorism, etc.). In theory, they combine those things to decide whether to just knock on the door and walk in or bring SWAT along. This happens different between agencies and what parts of the country. But, codifying the…

They check gun registries? Why? I suppose that registered guns suggest that someone is not criminal, because the alternative assumption should be unregistered guns.

Well, if they're going to arrest someone, they'd have a belief that they're a criminal. If there's evidence that they have a gun (e.g. entry in the gun registry under their name), then they'd have to consider it an attempt to apprehend a presumed-armed, suspected criminal.

I don't see why a registered gun would be a point in their favor. They probably registered their car, paid their taxes, and stopped at red lights too.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#149
I'm not addressing the FBI response, but hear me out. As a security researcher you have to stop at the first vulnerability. Don't use the vulnerability to get more information. It's the companies responsibility to ascertain the impact of the problem. This person should not have attempted to download anything from the FTP server. It should have spotted the FTP server, notified the company and made it clear they never attempted to download anything from it.

There was a similar issue with S3 credentials and Facebook a few months ago. The security researcher went too far. There was a large outcry by everyone about Facebooks response. I'm not addressing the response. I'm saying as a security researcher you need to protect yourself by trying very hard to limit the impact of what you're doing to remove risk of legal liability. Only go as far as the first problem and no further.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#150
post #37

This reminds me of something that happened to me in high school back in 1999. I found an Excel doc in a public network drive that contained every single student's SSN, DOB, whether they had free/reduced lunch, address, phone, etc. I was admittedly snooping around, but this was all public stuff every student and teacher had full access to. When I found it, I told one of the teachers that I trusted and she insisted tha…

A similar thing happened to me at my university. This new website came out called TheFacebook.com and it seemed hip to add artificial friends like famous actors, super heroes, etc. I had the bright idea to add the school president as a friend by creating a fake account like the thousands of other fake accounts on TheFacebook. I needed a university email address, but luckily, my school allowed you to create a personal…

To be honest, that sounds like a really stupid idea.
Post reply on HN