This reminds me of something that happened to me in high school back in 1999. I found an Excel doc in a public network drive that contained every single student's SSN, DOB, whether they had free/reduced lunch, address, phone, etc. I was admittedly snooping around, but this was all public stuff every student and teacher had full access to. When I found it, I told one of the teachers that I trusted and she insisted tha…
FBI raids dental software researcher who discovered patient data on FTP server
161–170 of 171 posts
Re: FBI raids dental software researcher who discovered patient data on FTP server
#162Reading this, I had an idea for a new law that could counteract this stupid reaction to security research: Particularly for protected patient information (but maybe for other classes of sensitive data as well), it would be interesting to somehow classify having this information breached as a crime by the holder of the information (I realize this might be hard to do given the reality of security these days, so there w…
In my industry, the EPA produces technology forcing regulation, we will have to invest a few hundred million to meet the upcoming standards and continue selling our product in the US after 2020. To sell our product in 2027, we need technology that hasn't been commercialized yet.
Maybe computer security could use a technology forcing regulation to get real investment in secure software to happen.
Re: FBI raids dental software researcher who discovered patient data on FTP server
#163Earlier quoted context omitted.
Remember clock Ahmed the clock kid? I had a situation almost exactly like his, except I made a working FM radio, could change stations and listen to local news and weather, I thought it was the coolest thing ever. The school did not, and the district superintendent agreed with them. Who knew that an FM Radio made out of a La Gloria Cubana cigar box-with labelling removed so as not to run afoul of any "tobacco paraphe…
It sounds like you weren't sufficiently brown to get media attention? "Public school bureaucracy run by bureaucrats" doesn't have the right mass appeal.
We're brown, I think colloquially "black".
Re: FBI raids dental software researcher who discovered patient data on FTP server
#164Earlier quoted context omitted.
It sounds like you weren't sufficiently brown to get media attention? "Public school bureaucracy run by bureaucrats" doesn't have the right mass appeal.
Ahmed: police called. handcuffed, questioned for 90 minutes, transported to juvenile jail, all without being able to see parents. plus racist comments. iamdave: picked up from school by his dad, no police involved. Not exactly the same situations. Both crappy situations, but Ahmed's treatment was an order of magnitude more inappropriate.
Re: FBI raids dental software researcher who discovered patient data on FTP server
#165Earlier quoted context omitted.
Oh, I've already learned the lesson loud and clear. If I ever discover a vulnerability to disclose, I'm releasing it anonymously on pastebin sites while logged into Tor through a VPN from a free WiFi spot. And, of course, sign it with a new PGP key you've just created, so that if you ever need to release a follow-up with proof that it's you, or come forward as the author of the disclosure, you can.
Would you do this to a company that has a clearly stated responsible disclosure policy and respects your efforts? Especially if it involved commonly used desktop software that would harm many people by ignoring an existing policy?
Re: FBI raids dental software researcher who discovered patient data on FTP server
#166The FBI is going to have a hell of a time arguing that accessing a public FTP server with no password protection is a crime.
Sometimes that's just the time, expense, job and reputation loss, etc. of the arrest, but sometimes (e.g. Freddie Gray) the ride is a'rough ride' and you can't beat that either.
Re: FBI raids dental software researcher who discovered patient data on FTP server
#167Re: FBI raids dental software researcher who discovered patient data on FTP server
#168I know this is only tangentially related to the HN content here, but does anyone have a sense of why the FBI would choose to respond to this sort of case with a dozen agents and weapons drawn? Rather than, say, two guys politely ringing the bell and asking him to come with them? Unless there's a lot left out of this article, I wouldn't think most "unauthorized computer access" suspects tend to be heavily armed. (Part…
Re: FBI raids dental software researcher who discovered patient data on FTP server
#169Earlier quoted context omitted.
Nonsense. It could be as a easy as printing fliers at home and dropping them in an appropriate space, or mailing letters with the return address the same as the mailing address, or using Tails 2.x to email hippa and the police using a throwaway address. But contacting them in person? NFW
Yes, print flyers on your home printer that you purchased with a credit card in your own name and had shipped to your home address. Handle all the pieces of paper with your bare hands, too. What could possibly go wrong?* * https://www.eff.org/issues/printers
Re: FBI raids dental software researcher who discovered patient data on FTP server
#170Earlier quoted context omitted.
Never print anything for anonymous purpose. All printers have a watermark.
This is not strictly true. So many color printers have a yellow-dot identifier pattern now that you should just assume that anything you print with one can be forensically linked with the printer's serial number, unless you definitively know otherwise. Monochrome printers are much less likely to add a nearly-invisible identifier pattern to every page. Check your printed pages under a microscope with different colors…