Earlier quoted context omitted.
Wow I wish that "rule" applied somehow to cyclists and pedestrians killed by motorists. That would be handy! As described above, against a firm with a modicum of security procedure, this "attack" would have been a no-op. As in, all the same actions could have been taken, and they would have had no effect whatsoever. "Attacks" like this take place every day, and many even succeed, with no action from prosecutors whats…
That rule very much does apply to cyclists killed by motorists! But remember, the rule is that you impute harm caused by a tort or a criminal offense . You have to start by establishing the driver was at fault.
Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking
21–30 of 67 posts
Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking
#22Earlier quoted context omitted.
As someone who works in this field and has been a party to breach investigations, it is really hard for me to imagine a breach in which the website of the Los Angeles Times is defaced costing less than $5000. I'm actually surprised --- as, apparently, were the prosecutors --- that the established losses were capped at ~$15,000. If you're operating a company with real customers and real cash flow at any kind of real s…
It is surprising to mere mortals that reverting a web page to a previous version, as GP described, costs that much. I can see an argument to include costs of investigation, and a much more tenuous argument to include costs to fix a vulnerability, but frankly the arguments not to include those costs seem more compelling. After all the defendant in this case didn't design and implement the relatively weak security. Tha…
If you find out that someone's been coming into your house when you're not there for a few weeks, but you're not entirely sure how, you don't just change your key, you also check all your windows, possibly fix the latch or replace the window on any that are broken, etc.
Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking
#23Earlier quoted context omitted.
That rule very much does apply to cyclists killed by motorists! But remember, the rule is that you impute harm caused by a tort or a criminal offense . You have to start by establishing the driver was at fault.
It's a commonplace that motorists are very rarely charged in these situations, because they "didn't see the cyclist" and also "why was the victim riding a bicycle on the street?" I guess we've established that the eggshell rule is yet another legal instrument to increase the "discretion" of LEOs, prosecutors, and judges, as if they really needed more of that.
Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking
#24Such a BAD use of tax payer money. So now we have to pay for 2 years of jail time (Probably 1 year for good behavior) for giving a key (That was actually not proven but was believed by the juror. The crime was the defacing of ONE page. This key also should have been revoked after he left the company. The recommendation of 7 years is just crazy and even the lowered 5 years is just nuts. If you just look at the cost to…
Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking
#25Earlier quoted context omitted.
I am saying that they INFLATED the loss to go over the $5,000 thresh hold.
As someone who works in this field and has been a party to breach investigations, it is really hard for me to imagine a breach in which the website of the Los Angeles Times is defaced costing less than $5000. I'm actually surprised --- as, apparently, were the prosecutors --- that the established losses were capped at ~$15,000. If you're operating a company with real customers and real cash flow at any kind of real s…
The cost should generally be limited to the actual damage done by the hacker, rather than include things that the company should have been doing anyway.
After someone uses an open window to obtain entry, does that mean that they can be charged with the cost of locating and auditing every copy of every physical key to the premises, on the basis that they could have found one and stolen it while they were in the building?
Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking
#26Earlier quoted context omitted.
As someone who works in this field and has been a party to breach investigations, it is really hard for me to imagine a breach in which the website of the Los Angeles Times is defaced costing less than $5000. I'm actually surprised --- as, apparently, were the prosecutors --- that the established losses were capped at ~$15,000. If you're operating a company with real customers and real cash flow at any kind of real s…
This is perhaps not directly related to this story, but it seems common that hackers are taken to be liable for the cost to fix whatever weaknesses they used to make the breach. This is like not fitting any locks on your doors, and then charging the burglar to put new locks on after a burglary. The cost should generally be limited to the actual damage done by the hacker, rather than include things that the company sh…
Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking
#27Earlier quoted context omitted.
This is perhaps not directly related to this story, but it seems common that hackers are taken to be liable for the cost to fix whatever weaknesses they used to make the breach. This is like not fitting any locks on your doors, and then charging the burglar to put new locks on after a burglary. The cost should generally be limited to the actual damage done by the hacker, rather than include things that the company sh…
No, that's not common. The damages imputed to attackers arise directly from what they did. The problem is that people ignore a whole class of damages in these cases: the DFIR work that is required to ensure that whoever attacked you didn't also persist themselves somehow.
Your infrastructure should aim to be robust against people persisting themselves (in this case, something that allows an employee to persist themselves beyond the validity of their credentials is a serious problem whether the hacker does it or not). Where it is not, that's your failing. Charging the hacker for finding out where your infrastructure is failing is perverse since if anything their attack made it easier to spot a failing. If they did persist themeselves, then obviously the cost to fix that belongs on the hacker, but the cost to identify such things is something you should be doing anyway.
Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking
#28Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking
#29Earlier quoted context omitted.
No, that's not common. The damages imputed to attackers arise directly from what they did. The problem is that people ignore a whole class of damages in these cases: the DFIR work that is required to ensure that whoever attacked you didn't also persist themselves somehow.
The problem is that that work seems essentially unlimited (you can invent crazier and crazier possibilities that you need to check for), and doesn't seem to be something that we do so much for physical intrusions which nevertheless have the same features (you can find keys, take copies of keys, even change locks or cut make false walls / doors). Your infrastructure should aim to be robust against people persisting th…
I don't understand how you could impute the cost of auditing infrastructure for backdoors that could have been planted in a breach to the victim of the breach, rather than to the person convicted of causing the breach. We're not talking about having each of Trib Corp's applications assessed (the cost of that would be in the many hundreds of thousands of dollars, minimum).
Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking
#30Earlier quoted context omitted.
It's a commonplace that motorists are very rarely charged in these situations, because they "didn't see the cyclist" and also "why was the victim riding a bicycle on the street?" I guess we've established that the eggshell rule is yet another legal instrument to increase the "discretion" of LEOs, prosecutors, and judges, as if they really needed more of that.
That's a coherent argument, but then I feel like I get to point out that you're litigating the whole concept of the justice system, not Keys sentence in particular. Keys is both extremely lucky and extremely privileged compared to the average person serving a multi-year sentence.