Live data from Hacker News

US cybercrime laws being used to target security researchers

theguardian.com

21–30 of 94 posts

Re: US cybercrime laws being used to target security researchers

#21
post #4

Earlier quoted context omitted.

This is both a comment on vulnerability research and a credible System Of A Down song lyric.

Yeah, it felt kinda trite writing it. I just haven't found a way to articulate the idea without asking myself "Oh, so you're still a teenager getting stoned every day thinking you have thoughts about things, hows that working out for you?" Edit: Maybe I should just lean into it and write a phrack article. I'm sorry, that's a low blow, I enjoyed phrack even when the writing style wasn't my speed.

I'll just note that the biggest "moneyed interests" in the technology industry have more or less waived most of their ammunition to stop research under the CFAA by posting public bug bounties. Not only have they made it much harder to sue researchers, but they also pay strangers to do it.

Re: US cybercrime laws being used to target security researchers

#22
post #3

Note that this concerns the subset of security research that involves actively talking to computer systems owned by other people, presumably in production, on the public Internet. Most security research does not in fact work this way. Consider, for instance, virtually any memory corruption vulnerability; while it was once straightforward (in the 90s) to work out an exploit "blind", today, researchers virtually always…

"...testing deployed systems without authorization is always risky..." While what you describe may be the sad reality, it makes zero sense. If a legit researcher, 'specially one that's being transparent about it, researches any domestic system, then that's got to be better than the Iranians, Russians or Chinese doing it (which they do anyway). But hey, what do we know anyway. There's probably some benefit that makes…

I disagree that it makes zero sense. There are reasonable concerns at play here:

* Security testing is extremely disruptive to production systems, most especially if those systems haven't been hardened in any way. Security testers are not as a rule good at predicting how their tests can screw up a production system.

* No matter how much effort you put into a security program (Google and Facebook put a lot of effort into it; more than most people on HN can imagine), attackers still find stuff. So there's not a lot of intellectual coherence to the idea that open, no-holds-barred research applies a meaningful selective pressure.

* It can be very difficult to distinguish genuinely malicious attacks from "security research", and malicious attacks are already extraordinarily difficult to prosecute.

I'm not saying that the rules as they exist under the CFAA today make perfect sense.

Re: US cybercrime laws being used to target security researchers

#23
post #7

this is dumb on many layers - threatening white hat who could be held accountable but could be hired to do further audit; failing to come to grips that if you are insecure enough to threaten someone, you know - internet will find out that you rather than fixing holes in your system rather use expensive lawyers to intimidate people who on the whole trying to a good thing for you. The whole thing about unauthorized acc…

Pardon my language, but that is such utter horseshit, and I think you know it.

Just because my door is unlocked, or my digital property is unsecured, you do NOT have permission and should not assume you can take access. That is the scummiest argument I've heard in quite some time. You do not have permission to steal something just because it's super convenient to do so; regardless of whether it is physical or digital.

Re: US cybercrime laws being used to target security researchers

#24

Earlier quoted context omitted.

It in no way diminishes the effect of a crime if a person does not lock their front door. It is not the victim's fault if they did not install bulletproof glass and employ a security guard. If you think differently you have a twisted outlook on life, a sort of might-makes-right view of righteousness. Such rationale is the rationale of a lowlife. "The front door was unlocked so its their fault I stole from them." "If…

Agreed. You don't get a pass for breaking into someone's house just because you say you weren't there to cause any harm. Yes, it's good to be pragmatic and understand that there's always something the owner of the house could have done to help prevent the break in -- close the door, lock them, get locks that are harder to pick, install security cameras, etc. etc. -- but the person breaking into your house is still wr…

I think what makes it tricky is that the systems are automated and intent and authorization aren't so clear.

We never call up the owner of a web server and ask them for permission to browse their site. We just connect to port 80 or 443 and go to town. This is universally accepted as authorized use.

Now, say you're running a vulnerable sshd such that if you send just the right bytes, it'll log you in as root without the password. I imagine most will say that this is unauthorized use.

But what's the difference really? In both cases, you're asking the server to do something, and then it does it. In the real world, we have various things to look for. Private dwellings are off limits without an invitation. Elsewhere, a lock means you don't go in, even if it would be trivial to defeat. Or just a sign that says you should stay out. It's not so clear with computers.

People have been convicted of a crime for taking a public URL and chopping off the last component and getting a directory listing from the server. To one side, the fact that you had to edit the URL and the fact that the directory listing wasn't what the rest of the site was like was enough to establish that as "unauthorized". To the other side, the guy just asked the server, "Can I have what's located here?" And the server replied, "Yep, sure, here you go."

A few weeks ago, there was a story here about a blackjack player who cheated a casino out of a bunch of money. He asked for a dealer who spoke Mandarin. His confederate then asked the dealer in Mandarin to turn certain cards upside down for luck. Normally this would be fine, but the cards at this particular casino weren't quite symmetric on the back, so they could tell them apart. The request would be suspicious, but they used a language the bosses couldn't understand, so they didn't realize what was going on.

In the end, the casino sued the guy for hefty damages. And yet all he did was ask and then receive what he asked.

In many ways, servers are like that dealer. You talk to it in a weird language that the owner can't understand (or he can, but he doesn't listen in on everything) and sometimes you can ask it for something the owner would refuse, but the server/dealer says yes.

So while it's clear that walking off with somebody's laptop just because they left the front door open is wrong, it's much less clear to me where you draw the line with networked computers, and it doesn't look like others have a particularly clear idea either. Given that fundamental lack of clarity, I don't think it's completely unreasonable to characterize these guys as locating spots where access is authorized (and thus legal) but shouldn't be, rather than locating spots where unauthorized access can be gained.

Re: US cybercrime laws being used to target security researchers

#25
post #18

Earlier quoted context omitted.

Google, Facebook, and now over 70 companies do grant tacit permission for anyone to test their systems, and will pay the researchers for a disclosure, as long as they follow the program rules , which are usually quite reasonable. I'm serious when I say that few people are more thankful than myself for the existence of security bug bounties. However, one thing has always crossed my mind: since the legal definition of…

> only the owner of the hacked computer can file a complaint against the attacker, and legal proceedings can commence only after such a complaint has been filed. Does it work the same way in the U.S.? After a US law enforcement agency has been notified of a complaint by a victim of a crime they forward it to a prosecutor. At this point the victim can no longer drop the charges. The only person who can drop the case t…

and more to this...

usually these cases go to special DA Investigation units who invest huge sums of money to determine who was involved and to what extent (think full blown computer forensic investigations to gather evidence). even when the cases make absolutely no sense to pursue, they will persist on the sole outcome of recovering some of these costs... i know first hand, borderline extortion.

Re: US cybercrime laws being used to target security researchers

#26
post #16

Earlier quoted context omitted.

A better analogy would be someone entering your house if the door is left open, and then them shouting to see if someone is home or if they left for work - in view of closing the door for them.

And then someone called the police when they found someone random was in their house without authorization. And the intruder said "I was only there to shut the door for them."

Which parallels white hats getting arrested for legitimate security research.

Hence my analogy stands.

Re: US cybercrime laws being used to target security researchers

#27

Monied interests want you to play in their safe playground without rocking the boat, the legal and technical enforcement is closing in. Slowly, but the ratchet only turns one direction. I worry that the only reason it hasn't closed in entirely is that smart people exploring is more beneficial to business than not. For now. Over the last few weeks I've been wondering when the scale flips and general purpose computing…

Does it really only turn in one direction, though?

I hear that kind of talk a lot, usually about taxes and government programs. It seems incredibly depressing, for one thing. It's fundamentally saying that you can never win, just delay the inevitable loss.

Fortunately, it doesn't seem to be true, whether it's taxes or computers. Computers might be getting squeezed a bit now, but there have been far worse periods, followed by better. Go back in time to, I don't know, 1990. You want an OS for your PC? Sure, Windows or DOS? You want a wide-area network connection of some kind? We have a variety of choices for you, ranging from the local phone company to the local phone company, or even the local phone company.

Remember when you had to be careful never to tell the phone company that your second line was for dialup internet, because they'd charge you more if they found out you were going to use it with a modem? Remember when you had to worry that they'd figure it out anyway from your usage patterns, or that they'd just cut you off regardless because you were tying up a line for hours and hours every day?

I don't want to tell you not to fight. Certainly, there are plenty of problems right now, and it's well worth fighting. But we should realize that there are many ways that it can be and has been worse, and that the ratchet really does go both ways when people want it to.

Re: US cybercrime laws being used to target security researchers

#28

I think this article is misleading to British English readers. > HD Moore, creator of the ethical hacking tool Metasploit and chief research officer of security consultancy Rapid7, told the Guardian he had been warned by US law enforcement last year over a scanning project called Critical.IO, which he started in 2012. British might confuse "warning" for what's known in Britain as a "police caution", which is a extra-…

  > ...judged summarily by police...
Wikipedia claims [1] that the offender can't be summarily judged by the police because they must agree to be cautioned:

  > In order to safeguard the offender's interests, the 
  > following conditions must be met before a caution can be 
  > administered:
  >   * there must be evidence of guilt sufficient to give 
  >     a realistic prospect of conviction;
  >   * the offender must admit the offence;
  >   * the offender must understand the significance of a
  >     caution and give informed consent to being 
  >     cautioned.
Did you mean something else when you wrote "summarily judged?" Or does Wikipedia have this wrong?

[1] http://en.wikipedia.org/wiki/Police_caution#Circumstances_fo...

Re: US cybercrime laws being used to target security researchers

#29

Monied interests want you to play in their safe playground without rocking the boat, the legal and technical enforcement is closing in. Slowly, but the ratchet only turns one direction. I worry that the only reason it hasn't closed in entirely is that smart people exploring is more beneficial to business than not. For now. Over the last few weeks I've been wondering when the scale flips and general purpose computing…

Cory Doctorow's keynote at Chaos Communication Congress (2011) was about this trend. It's not technically feasible to make a turing-complete system that only does things that the creator likes. All anti-virus and DRM systems are provably limited unless general-purpose computation is removed. https://www.youtube.com/watch?v=HUEvRyemKSg

Re: US cybercrime laws being used to target security researchers

#30
post #24

Earlier quoted context omitted.

Agreed. You don't get a pass for breaking into someone's house just because you say you weren't there to cause any harm. Yes, it's good to be pragmatic and understand that there's always something the owner of the house could have done to help prevent the break in -- close the door, lock them, get locks that are harder to pick, install security cameras, etc. etc. -- but the person breaking into your house is still wr…

I think what makes it tricky is that the systems are automated and intent and authorization aren't so clear. We never call up the owner of a web server and ask them for permission to browse their site. We just connect to port 80 or 443 and go to town. This is universally accepted as authorized use. Now, say you're running a vulnerable sshd such that if you send just the right bytes, it'll log you in as root without t…

Comparing requests to a server to edge sorting in blackjack is really insightful. The analogy isn't totally similar, though, since in the edge sorting case, the player walks away with money, while URL chopping just gives information.

I should mention that the player involved, Phil Ivey, is probably the most famous poker player in the world. According to Wikipedia, "Ivey is regarded by numerous poker observers and contemporaries as the best all-round player in the world today...his other nickname is 'The Tiger Woods of Poker'." [1]

[1] http://en.wikipedia.org/wiki/Phil_Ivey

Post reply on HN