Live data from Hacker News

FBI raids dental software researcher who discovered patient data on FTP server

dailydot.com

151–160 of 171 posts

Re: FBI raids dental software researcher who discovered patient data on FTP server

#151
post #37

This reminds me of something that happened to me in high school back in 1999. I found an Excel doc in a public network drive that contained every single student's SSN, DOB, whether they had free/reduced lunch, address, phone, etc. I was admittedly snooping around, but this was all public stuff every student and teacher had full access to. When I found it, I told one of the teachers that I trusted and she insisted tha…

I got in a lot of trouble in high school for playing with the DOS prompt in Windows. My teacher told the principal that the scary black window full of monospace text was -and I'm quoting here- a "highly sensitive zone" on the computer that no innocent student would access. Obviously I protested, and predictably the principal didn't believe a word of what I had to say.

I believe I had to stay up late writing a 4-page apology paper to forestall disciplinary proceedings since my family was planning to go on vacation the next day.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#152
post #128
post #58

Earlier quoted context omitted.

Nonsense. It could be as a easy as printing fliers at home and dropping them in an appropriate space, or mailing letters with the return address the same as the mailing address, or using Tails 2.x to email hippa and the police using a throwaway address. But contacting them in person? NFW

Never print anything for anonymous purpose. All printers have a watermark.

This is not strictly true. So many color printers have a yellow-dot identifier pattern now that you should just assume that anything you print with one can be forensically linked with the printer's serial number, unless you definitively know otherwise. Monochrome printers are much less likely to add a nearly-invisible identifier pattern to every page. Check your printed pages under a microscope with different colors of light.

Nevertheless, if you want to print something and wish to remain anonymous, it isn't a bad idea to assume that every document that a particular printer ever prints can be linked using the printer's serial number, even if you think that specific printer is safe. Never print anything on it that can be linked to your public identity. Don't connect it to the internet.

You may never know whether there's some sort of steganographic encoding mechanism that targets certain print geometries in ways that you can't detect. There probably isn't. But if you're a dissident or troublemaker, can you take even a tiny risk?

Re: FBI raids dental software researcher who discovered patient data on FTP server

#153

Earlier quoted context omitted.

If your story is true, then you were, as it appears, wrongfully and unlawfully imprisoned. I think you should at least try contacting press and some lawyers -- if what you are saying is a true story. It sounds pretty interesting to me -- I imagine someone in the press would pick it up.

>If your story is true, then you were, as it appears, wrongfully and unlawfully imprisoned. I think you should at least try contacting press and some lawyers -- if what you are saying is a true story. I was indeed wrongfully imprisoned, but by the Finnish government. I can and will receive compensation from them but at best that's going to be a few thousand euros per month, a nominal sum considering the time lost. It…

Does Finland not have protections against defamation? If someone that wasn't an American FBI employee falsely accused you of a crime, would you have a legal remedy?

Article 24, paragraphs 8-10?

It looks like you would have to file a criminal complaint in order to proceed with a civil claim, and the state cannot act on criminal charges until you actually make the complaint, unless the defamation appeared in the mass media. If the Finnish prosecutor declines to act against the FBI, your only remaining remedy is to file a claim in the court of public opinion by getting a local journalist to tell your story on a slow news day.

You owe it to yourself and all noncriminal Finnish hackers to at least make a defamation complaint to Finnish police against the FBI. Your statute of limitations is 5 years.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#154
post #7

Earlier quoted context omitted.

Yea.. but a site on the internet is more akin to a store than someone's home. It's completely normal to walk into someone's store.

An ftp server is clearly more akin to a spooky abandoned building.

Or a private lending library that is technically open to the public, but no one ever goes there, because all the books are about dental drills.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#155
post #54

Earlier quoted context omitted.

> "Did you ever stop to think if maybe this information was public for a reason?" If it was meant to be public, then you shouldn't have gotten in trouble for pointing out its existence. I don't understand the twisted logic there.

This is public for the teachers, snooping this file is the same as rummaging through teacher's stuff!

Yes, teacher's stuff containing a ton of other people's SSNs and other personal info and sitting around for anyone to access without any barrier! Totally cool, just hope no one does an rummaging!

Re: FBI raids dental software researcher who discovered patient data on FTP server

#156

Fun fact: Many financial institutions use the last 4 of your SSN as identity verification. If you're a business, it's the last 4 of your FEI/EIN. I know at least in FL, this is publicily available at sunbiz.org So with the account number printed at the bottom of your paycheck/stub and the FEI/EIN, you can often authenticate to a financial institution and obtain privileged information. I know this not because I was on…

Years ago, one of my credit unions used SSN as the account number... so every one of our checks had our SSN printed right on it.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#157

Earlier quoted context omitted.

>If your story is true, then you were, as it appears, wrongfully and unlawfully imprisoned. I think you should at least try contacting press and some lawyers -- if what you are saying is a true story. I was indeed wrongfully imprisoned, but by the Finnish government. I can and will receive compensation from them but at best that's going to be a few thousand euros per month, a nominal sum considering the time lost. It…

Does Finland not have protections against defamation? If someone that wasn't an American FBI employee falsely accused you of a crime, would you have a legal remedy? Article 24, paragraphs 8-10? It looks like you would have to file a criminal complaint in order to proceed with a civil claim, and the state cannot act on criminal charges until you actually make the complaint, unless the defamation appeared in the mass m…

I've actually been thinking of filing several of such complaints for a while, but it's sort of been on the backburner. However on monday I'll see if I can get copies of the original communications and get the complaints filed.

Rather unlikely that any prosecutor would pick them up, but who knows?

Re: FBI raids dental software researcher who discovered patient data on FTP server

#158

Fun fact: Many financial institutions use the last 4 of your SSN as identity verification. If you're a business, it's the last 4 of your FEI/EIN. I know at least in FL, this is publicily available at sunbiz.org So with the account number printed at the bottom of your paycheck/stub and the FEI/EIN, you can often authenticate to a financial institution and obtain privileged information. I know this not because I was on…

Years ago, one of my credit unions used SSN as the account number... so every one of our checks had our SSN printed right on it.

awesome!

In my experience, credit unions are usually worse than Banks on the security side. There are exceptions, but they are not the norm.

One credit union I dealt with always opened and closed with a single employee. Very dangerous for the employee. This same union kept the A and B part codes to their vault in a locked desk drawer(one of those cheap desk drawer locks that anyone can pick with a paper clip) in the lobby, and full internet access was available on all computers. Tellers all shared a single cash drawer and the teller PCs were routinely used by the tellers for general web surfing, Facebook, Pandora, etc...

Re: FBI raids dental software researcher who discovered patient data on FTP server

#159

Earlier quoted context omitted.

I am pleased they might move forward with this prosecution. Keep in mind the legal costs incurred to do this, in addition to the already employed 12-15 FBI agents who were probably paid overtime to heroically rescue that poor family from this monster was already well worth the cost. Spending more money and resources here is obviously the right thing to do. Really, the resources expended to handcuff this man in his bo…

Other places aren't much better either. In my country, you don't get to reach the courts. If some official doesn't like you, and you aren't a descendant of a well-known lineage and don't have connections, you will accidentally fall down a couple of flights of stairs, repeatedly. And should you by some miraculous series of events manage to get your case heard in a court (have $$$ to burn), they'll just appeal the verd…

> Other places aren't much better either.

You haven't been in many countries, have you?

Majority of Europe you will see SWAT team on TV once a year when they do a huge bust of over 100 drug dealers or terrorist. It would be a public shame, heads with rolls and never ending phone-calls from constitutes asking and demanding answers why their money was spent on performing a raid on a hacker who broke into publicly open computer.

I will also bet (as long as we are somewhere legal to do so like LV) a $100 that you won't find an example in Europe when SWAT team killed a dog or threw a flash grenade into a crib with a baby in it... something that happens in US and that noone can be reasonably held accountable.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#160
post #97

Earlier quoted context omitted.

Remember clock Ahmed the clock kid? I had a situation almost exactly like his, except I made a working FM radio, could change stations and listen to local news and weather, I thought it was the coolest thing ever. The school did not, and the district superintendent agreed with them. Who knew that an FM Radio made out of a La Gloria Cubana cigar box-with labelling removed so as not to run afoul of any "tobacco paraphe…

> Remember clock Ahmed the clock kid? It turned out that his invention was a fully pre-built alarm clock removed from its plastic housing. Also other details emerged that pretty much sealed the case against him - what he did was create an intentional hoax.

That's your take-away from the situation, not the fact a child was handcuffed and treated like a terrorist for purely anti-Muslim reasons? Wow.
Post reply on HN