Live data from Hacker News

FBI raids dental software researcher who discovered patient data on FTP server

dailydot.com

21–30 of 171 posts

Re: FBI raids dental software researcher who discovered patient data on FTP server

#21
post #14

The FBI is going to have a hell of a time arguing that accessing a public FTP server with no password protection is a crime.

Isn't this exactly what Andrew Auernheimer was charged and convicted with?

Yes - and that's also pointed out in the arcticle:

“It’s weev all over again.”

Re: FBI raids dental software researcher who discovered patient data on FTP server

#22

It sounds like Patterson Dental deserves as much blame as the FBI, if not more, because it sounds like they were the ones pressing charges and motivating prosecution in the first place. Also, why aren't they being charged with what is almost certainly a HIPAA violation?

If patterson dental (and I say if since we don't really know) is behind him getting arrested, I hope all their patients find out about the details of this and they go out of business. If nothing else they should be charged with HIPAA violations.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#23
Here's an investigative tool the CFAA & the FBI needs... if a company like Patterson Dental spins up an investigative raid with a baseless complaint, the Bureau should be able to charge them with a crime. One almost hopes the FBI investigation yields enough evidence to charge Patterson with a criminal violation of HIPAA.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#25
post #5

The FBI is going to have a hell of a time arguing that accessing a public FTP server with no password protection is a crime.

I believe that it is still considered unauthorized access even if they don't have a password set up. I think it goes back to law that existed before computers where if you entered someones home without permission you can't simply argue that there wasn't a lock on the door. Edit: ProAm above reminded me of the Andrew Auernheimer case that was nearly identical to this and was resolved as I describe.

This doesn't hold up because homes are made to be accessed by one person or a specific group of people.

It is more like having a store with lights on and an open sign then arresting someone for breaking an entering when they go inside.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#26

> Defense attorney Tor Ekeland, who represented Auernheimer in the federal court case in New Jersey, has offered to help Shafer ... Based on his website it appears that "Tor" is actually his given name. What an odd coincidence.

Yeah common Scandinavian name, same as Thor, essentially.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#27
I know this is only tangentially related to the HN content here, but does anyone have a sense of why the FBI would choose to respond to this sort of case with a dozen agents and weapons drawn? Rather than, say, two guys politely ringing the bell and asking him to come with them?

Unless there's a lot left out of this article, I wouldn't think most "unauthorized computer access" suspects tend to be heavily armed. (Particularly if the company actually reported the context of the "crime", including the fact that he had voluntarily notified them of the problem.)

Re: FBI raids dental software researcher who discovered patient data on FTP server

#28
post #7
post #5

Earlier quoted context omitted.

I believe that it is still considered unauthorized access even if they don't have a password set up. I think it goes back to law that existed before computers where if you entered someones home without permission you can't simply argue that there wasn't a lock on the door. Edit: ProAm above reminded me of the Andrew Auernheimer case that was nearly identical to this and was resolved as I describe.

Yea.. but a site on the internet is more akin to a store than someone's home. It's completely normal to walk into someone's store.

An ftp server is clearly more akin to a spooky abandoned building.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#29

It sounds like Patterson Dental deserves as much blame as the FBI, if not more, because it sounds like they were the ones pressing charges and motivating prosecution in the first place. Also, why aren't they being charged with what is almost certainly a HIPAA violation?

If patterson dental (and I say if since we don't really know) is behind him getting arrested, I hope all their patients find out about the details of this and they go out of business. If nothing else they should be charged with HIPAA violations.

Patterson is not a dental clinic. Like Henry Schein which was also mentioned in TFA, it is a large dental supply company. One reason that dentistry is so expensive, is that assholes like these run an oligopoly of "specialty" dental supplies. It's not as bad as military procurement, but it's kind of like that. Dentists as a profession are risk-averse, and that includes the "risk" of purchasing dental equipment and supplies without a 300% price markup.

So, the chance of them going "out of business" is pretty slim. It's entirely possible that dentists unfortunate enough to have chosen Eaglesoft will get to pay some HIPAA fines, however.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#30
post #27

I know this is only tangentially related to the HN content here, but does anyone have a sense of why the FBI would choose to respond to this sort of case with a dozen agents and weapons drawn? Rather than, say, two guys politely ringing the bell and asking him to come with them? Unless there's a lot left out of this article, I wouldn't think most "unauthorized computer access" suspects tend to be heavily armed. (Part…

I imagine it's a part of a trend of "militarization" of law enforcement. In the last few years police forces have greatly expanded their SWAT forces, partly because of the practice of the US military giving away surplus military tech to law enforcement. And if you have a hammer, all the world seems like a nail.

The rationalization is that serving warrants can sometimes be risky, so why take the chance? It's in law enforcement's best interest to err on the side of caution: better to scare the crap out of people than get shot without warning. Which is why the government and the courts are supposed to balance LE's concerns with the rights of the people.

Post reply on HN