Live data from Hacker News

When your classmates threaten you with felony charges

miles.land

231–240 of 350 posts

Re: When your classmates threaten you with felony charges

#231

Interestingly, Ashton Cofer and Teddy Solomon of Fizz tried some PR damage control when their wrongdoing came to light https://stanforddaily.com/2022/11/01/opinion-fizz-previously... . Their response was weak and it seems like they've refused to comment on the debacle since then.

Per the Stanford Daily article linked in the OP [0], they have also removed the statement addressing this incident and supposed improvements from their website. >Although Fizz released a statement entitled “Security Improvements Regarding Fizz” on Dec. 7, 2021, the page is no longer navigable from Fizz’s website or Google searches as of the time of this article’s publication. And, it seems likely the app still stores…

"Security Improvments Regarding Fizz":

https://web.archive.org/web/20220204044213/https://fizzsocia...

What I was looking for was if they really had a page that claimed "100% secure", but I don't think that was captured by archive.org

Re: When your classmates threaten you with felony charges

#232

Earlier quoted context omitted.

> "if any piece of this contract is invalid it doesn't invalidate the rest of the contract". Severability (the ability to "sever" part of a contract, leaving the remainder intact so long as it's not fundamentally a change to the contract's terms) comes from constitutional law and was intended to prevent wholesale overturning of previous precedent with each new case. It protects both parties from squirreling out of an…

Thanks for the explanation and the term "severability". I understand its point now and it makes sense to have it conceptually. I also didn't know about this part: > so long as it's not fundamentally a change to the contract's terms However, taken down one notch from theoretical to more practical: > It seems like you're arguing for some sort of punitive response to authoring a bad contract? Not quite so bluntly, but y…

I'm reminded of the concept of a "tact filter", which is basically "do you alter what you say to avoid causing offense, or do you alter what you hear to avoid taking offense?"

https://www.mit.edu/~jcb/tact.html

The part the original essay leaves out is that optimal behavior depends on the scale and persistence of the relationship. In personal, 1:1, long-term relationships, you should apply outgoing tact filters because if you cause offense you've torched the relationship permanently and will suffer long-term consequences from it. But in public discourse, many-to-many, transactional relationships, it's better to apply incoming tact filters because there are so many people you interact with that invariably there will be someone who forgot to set their outgoing tact filter. (And in public discourse where you have longstanding relationships with your customers with serious negative consequences for pissing them off, you want to be very, very careful what you say. The entire field of PR is devoted to this.)

So anyone who spends a significant amount of time with the general public basically needs to develop a translation layer. "i hope you hang yourself" on an Internet forum becomes "somebody had a bad day and is letting off steam by trolling." "Your business is probably in violation of federal labor laws because you haven't displayed these $400 posters we're trying to sell you" becomes "Better download some PDFs off the Department of Labor for free" [1]. "We're calling from XYZ Collection Agency about your debt" or "This is the Deputy Sheriffs office. You have a warrant out for your arrest for failing to appear for jury duty" or "This is the IRS calling requesting you pay back taxes in the amount of $X over the phone" = ignore them and hang up because it's a scam. "Continued involvement in Russia's internal affairs will lead to nuclear consequences" = Putin is feeling insecure with his base and needs to rattle some sabers to maintain support. "You are in violation of several state and federal laws facing up to 20 years in prison" = they want something from me, lawyer up and make sure we're not in violation and then let's negotiate.

[1] https://www.dol.gov/general/topics/posters

Re: When your classmates threaten you with felony charges

#233
post #91
post #63

Earlier quoted context omitted.

(a) There's no such thing as "ethical hacking" (that's an Orwellian term designed to imply that testing conducted in ways unfavorable to vendors is "unethical"). (b) You don't require permission to test software running on hardware you control (absent some contract that says otherwise). (c) But you're right, in this case, the researchers presumably did need permission to conduct this kind of testing lawfully.

> (a) There's no such thing as "ethical hacking" Weird stance. Sure, you may disagree on the limitations of scope of various ethical hacking programs (bug bounties and such) but they consistently highlight some very serious flaws in all kinds of hardware and software. Going out of scope (hacking a company with no program in place) is always a gamble and you’re betting on the leniency of the target. Probably not worth…

His point is that the way the term is used, to protect vendors, has nothing to do with ethics.

If a researcher found a serious vuln, the ethical thing may very well be to document it publicly without coordination with the vendor, especially if such coordination hurts users.

Re: When your classmates threaten you with felony charges

#234
post #124

Earlier quoted context omitted.

While what you say is true, I feel strongly that it shouldn't be. It is morally right to show if a product that is used by many fellow students is marketed as "100% secure"* is in fact very vulnerable. If some less ethical hackers got a hold of that data, much worse things could have happened. * that's the biggest red flag. A company saying 100% obviously has very little actual security expertise. PS: I'm a big fan o…

Devil's advocate: I get into your home by bypassing (poor) security. I take pictures and make copies of anything inside. Then I publicly announce the breach and demand that you fix your security based on a deadline I made up. Then I say "trust me, bro" when I promise to never reveal the data I stole. Nobody would find any of that moral. The analogy breaks down because your home is not a place where sensitive data of…

Yeah, I sort of get your point.

> So we did what any good security researcher does: We responsibly disclosed what we found. We wrote a detailed vulnerability disclosure report. We suggested remediations. And we proactively agreed not to talk about our findings publicly before an embargo date to give them time to fix the issues. Then we sent them the report via email.

This is why the whole “I can’t believe my classmates threatened legal action” line of thinking doesn’t make sense. They weren’t acting like classmates themselves. They were acting like professionals. I imagine the embargo date wasn’t well-received.

It’s also interesting that they listed all of the steps they followed that a “good security researcher” would do. So why didn’t they start with communication first before trying to hack the system? Good security researchers do that. (Not all of the time, obviously.)

> Well, a me and few security-minded friends were drawn like moths to a flame when we heard that. Our classmates were posting quite sensitive stories on Fizz, and we wanted to make sure their information was secure.

> So one Friday night…

And this is where the “good-faith security research” line of reasoning broke down for me. Think about the wording. To my ears/eyes, those sentences above seem like a carefully crafted but still flimsy excuse. It’s like a lie that you tell yourself over and over so much that you end up believing it. It seems like the researchers just wanted to have some fun on a Friday night (like he said). (And there’s nothing wrong with that. But to characterize it as only doing “good faith security research” seems like a stretch.) I guess I’m saying that I’m just not convinced. I don’t buy it.

But I get it. Articles need to be written. Talks needs to be given.

(And yes, I do believe that Fizz didn’t need to threaten legal action.)

Re: When your classmates threaten you with felony charges

#235

The story has greatly reduced value without knowing who the individuals behind Fizz really are. So that we can avoid doing business with them. It would be different if Fizz was a product of a megacorporation. “Keep calm” and “be responsible” and “speak to a lawyer” are things I class as common sense. The gold nugget I was looking for was the red flashing shipwreck bouy/marker over the names.

Ashton Cofer and Teddy Solomon, according to this article:

https://stanforddaily.com/2022/11/01/opinion-fizz-previously...

Re: When your classmates threaten you with felony charges

#236

Earlier quoted context omitted.

This is unfortunately a very common issue with Firebase apps. Since the client is writing directly to the database, usually authorization is forgotten and the client is trusted to only write to their own objects. A long time ago I was able to get admin access to an electric scooter company by updating my Firebase user to have isAdmin set to true, and then I accidentally deleted the scooter I was renting from Firebase…

One interesting thing about the statute of limitations is “the discovery rule.” For example, say the statute of limitations for 18 USC 1030 is two years. If a person hypothetically stole a scooter by hacking, two years later, they would be in the clear, right? No. The discovery rule says that if a damaged party, for good reason, does not immediately discover their loss, the statutes of limitations is paused until the…

The scooter company was well aware of it as I told them about that + several other issues immediately. :)

Re: When your classmates threaten you with felony charges

#237

Earlier quoted context omitted.

I presume that the "limb" the EFF attorney went on is basically what would've been disputed in a court of law. It's easily argued that if an app is so badly configured that just _following the Firebase protocol_ can give you write access to the database, you haven't actually circumvented any security measures, because _there weren't any to circumvent_. It reminds me of the case where AT&T had their iPad data subscrib…

IANAL, but the law does not require you to "circumvent" anything[1]. Simply, anyone who "accesses a computer without authorization ... and thereby obtains ... information from any protected computer" is in violation of the CFAA. If the researchers in question did not download any customer data, nor cause any "damages", I am not sure they are guilty of anything. BUT, if they had, "the victim had insufficient security…

> accesses a computer without authorization

They were authorized, as per the permissions that fizz gave users of the app on firebase. A group of users noticed that it was overly permissive and reported it to them.

> Leaving your door unlocked does not give burglars permission to burgle you.

This is more like giving your stuff away and then reporting it as theft.

Re: When your classmates threaten you with felony charges

#238
post #57

I'm not a lawyer, but I am professionally interested in this weird branch of the law, and it seems like EFF's staff attorney went a bit out on a limb here: * Fizz appears to be a client/server application (presumably a web app?) * The testing the researchers did was of software running on Fizz's servers * After identifying a vulnerability, the researchers created administrator accounts using the database activity the…

Good analysis. I’m really confused why in the 2020s anybody thinks that unsolicited pentesting is a sane or welcome thing to do. The OP doesn’t seem to have a “mea culpa” so I hope they learned this lesson even if the piece is more meme-worthy with a “can you believe what these guys tried to do?” tone. While their intent seems good, they were pretty clearly breaking the law.

What about due diligence? If you're about to send and store sensitive information with a service, a service that claims to be 100% secure.... shouldn't you have the right to verify that the security is up to snuff? These researchers weren't attempting to harm anybody. What's wrong with kicking the tires?

Re: When your classmates threaten you with felony charges

#239

Earlier quoted context omitted.

Good analysis. I’m really confused why in the 2020s anybody thinks that unsolicited pentesting is a sane or welcome thing to do. The OP doesn’t seem to have a “mea culpa” so I hope they learned this lesson even if the piece is more meme-worthy with a “can you believe what these guys tried to do?” tone. While their intent seems good, they were pretty clearly breaking the law.

> I’m really confused why in the 2020s anybody thinks that unsolicited pentesting is a sane or welcome thing to do. Because bug bounties?

Bug bounties are not “unsolicited”.

Re: When your classmates threaten you with felony charges

#240

Earlier quoted context omitted.

(a) what if a company hires an external red team to hack their shit, would that not be 'ethical hacking'?

No, because there's no such thing as "ethical hacking"; that's a marketing term invented by vendors to constrain researchers. You'd call what you're talking about "pentesting" or "red teaming". How you'd know you had a clownish pentest vendor would be if they themselves called it "ethical hacking".

There is no precedent for consequence-free probing of others' defenses. Unauthorized "testing conducted in ways unfavorable to vendors" is generally considered a crime of trespass, because everybody has the right to exist unmolested. Whether or not they have their shit together, you aren't authorized to test your kids' school's evacuation procedure by randomly showing up with a toy gun and a vest rigged with hotdogs and wires.

The way this goes in the digital space, people expect to break into my "house," see if they can get into my safe, snoop around in my wife's/daughter's nightstands, steal some of their underwear as a CTF exercise, help themselves to my liquor on the way out, then send me an invoice for their time while also demanding the right (or threatening) to publish everything they found on their blog. Unsolicited "security research" is a shakedown desperate to legitimize itself. Unlawful search/"fruit of the poisoned tree" exists to keep the cops from doing this to you, but it's totally acceptable for self-appointed "researchers" to do to anybody else I guess.

"Ethical hacking" is notifying the owner/authorities there's a potential problem at an address, seeing if they want your help in investigating, and working with them in that capacity-- proceeding to investigate only with explicit direction. Even if their incompetence or negligence in response affects you personally, that's not a cue to break a window and run your own investigation while collecting leverage you can use to shame them into compliance. That shit is just espionage masquerading as concern trolling.

Post reply on HN