Live data from Hacker News

When your classmates threaten you with felony charges

miles.land

261–270 of 350 posts

Re: When your classmates threaten you with felony charges

#261

Earlier quoted context omitted.

> "if any piece of this contract is invalid it doesn't invalidate the rest of the contract". Severability (the ability to "sever" part of a contract, leaving the remainder intact so long as it's not fundamentally a change to the contract's terms) comes from constitutional law and was intended to prevent wholesale overturning of previous precedent with each new case. It protects both parties from squirreling out of an…

Thanks for the explanation and the term "severability". I understand its point now and it makes sense to have it conceptually. I also didn't know about this part: > so long as it's not fundamentally a change to the contract's terms However, taken down one notch from theoretical to more practical: > It seems like you're arguing for some sort of punitive response to authoring a bad contract? Not quite so bluntly, but y…

I do like the idea theoretically as a deterrent against bad actors abusing the law to bully weaker parties - but the difficult part is in the details of implementation: how do you separate intent to abuse from incompetence?

Also confusing the mix here is who you are punishing when violations are found - is it the attorneys drafting the agreement? They're as likely to be unaffiliated with the company executing the contract as not, not everyone bothers with in-house counsel. Is it the company leadership forwarding the contract?

What's the scope of the punishment? An embargo on all new legal agreements for a period of time, or only with the parties to the bad contract? A requirement for change in legal representation? Now we get into overreach questions on the punishment side.

All of that to say I am guessing the reason something like this doesn't exist yet afaik is because it's a logistical nightmare to actually put into practice.

The closest I can think of to something that might work is like a credit score/rating for companies for "contract integrity" or something that goes down with negative rulings - but what 3rd party would own that? Even just the thought experiment spawns too many subqueries to resolve simply.

None of that contradicts the fact it's a good idea - just not sure if even possible to bring to life!

Re: When your classmates threaten you with felony charges

#263
post #61

Earlier quoted context omitted.

>If we lived in a world where lawyers were more cautions about what they attached there name to out of concern for losing their license we would probably be better off. That's already the case. Lawyers can be disbarred for filing frivolous lawsuits.

I'm aware, and yet this letter was written and signed by a lawyer who probably knew better and will likely face no consequences.

I'm in favor of the work done by the security researchers, and the defense offered by the EFF. However, your first comment was such a surface level understanding, and I wanted to bring it back to reality.

The general form of such a "legal threat" (threat relating to the law) is perfectly reasonable, normal, and legal (as in, conforming to the law). It's a standard part of practicing law.

However, in this specific case, they do appear to have broken one professional rule, regarding the threat of criminal prosecution conditional on a civil demand.

Aside from that one professional rule, the Fizz/Buzz letter was probably perfectly technically accurate. Whether the DA would take up the case, I doubt, but that's up to their discretion/advice from the DoJ, not based on the legal code.

I think Fizz/Buzz were incredibly foolish to send such a letter, as the researchers were essentially good samaritans being punished for their good deed (probably only because customers don't like it when supposedly professional organizations are found to be in need of such basic good deeds from good samaritans, and Fizz/Buzz would rather punish the good samaritans instead of "suffering" the "embarrassment" of public knowledge).

Re: When your classmates threaten you with felony charges

#264
post #124

Earlier quoted context omitted.

While what you say is true, I feel strongly that it shouldn't be. It is morally right to show if a product that is used by many fellow students is marketed as "100% secure"* is in fact very vulnerable. If some less ethical hackers got a hold of that data, much worse things could have happened. * that's the biggest red flag. A company saying 100% obviously has very little actual security expertise. PS: I'm a big fan o…

Devil's advocate: I get into your home by bypassing (poor) security. I take pictures and make copies of anything inside. Then I publicly announce the breach and demand that you fix your security based on a deadline I made up. Then I say "trust me, bro" when I promise to never reveal the data I stole. Nobody would find any of that moral. The analogy breaks down because your home is not a place where sensitive data of…

> I get into your home by bypassing (poor) security. I take pictures and make copies of anything inside. Then I publicly announce the breach and demand that you fix your security based on a deadline I made up. Then I say "trust me, bro" when I promise to never reveal the data I stole.

Otoh, it sounds really different if you break into your own home.

I think part of the issue is with everything in the cloud your data is no longer local (like it would have been back in the day), but you (or the custumer public) still has an interest in knowing if the data is secure, an interest that is at odds with the service provider who often has perverse incentives to not care about security.

Re: When your classmates threaten you with felony charges

#265

Earlier quoted context omitted.

Devil's advocate: I get into your home by bypassing (poor) security. I take pictures and make copies of anything inside. Then I publicly announce the breach and demand that you fix your security based on a deadline I made up. Then I say "trust me, bro" when I promise to never reveal the data I stole. Nobody would find any of that moral. The analogy breaks down because your home is not a place where sensitive data of…

Yeah, I sort of get your point. > So we did what any good security researcher does : We responsibly disclosed what we found. We wrote a detailed vulnerability disclosure report. We suggested remediations. And we proactively agreed not to talk about our findings publicly before an embargo date to give them time to fix the issues. Then we sent them the report via email. This is why the whole “I can’t believe my classma…

> So why didn’t they start with communication first before trying to hack the system? Good security researchers do that. (Not all of the time, obviously.)

I don't think that is true. I think it would be very unusual for an independent (not a pentester) security researcher to communicate anything before they have any findings.

> It seems like the researchers just wanted to have some fun on a Friday night (like he said). (And there’s nothing wrong with that. But to characterize it as only doing “good faith security research” seems like a stretch.)

I don't get it. Good faith research is fun. Most people don't get into the industry because they hate the work. I don't even understand what you are trying to imply was in their mind that would disqualify their actions from being in good faith.

Re: When your classmates threaten you with felony charges

#266

Earlier quoted context omitted.

Devil's advocate: I get into your home by bypassing (poor) security. I take pictures and make copies of anything inside. Then I publicly announce the breach and demand that you fix your security based on a deadline I made up. Then I say "trust me, bro" when I promise to never reveal the data I stole. Nobody would find any of that moral. The analogy breaks down because your home is not a place where sensitive data of…

Yeah, I sort of get your point. > So we did what any good security researcher does : We responsibly disclosed what we found. We wrote a detailed vulnerability disclosure report. We suggested remediations. And we proactively agreed not to talk about our findings publicly before an embargo date to give them time to fix the issues. Then we sent them the report via email. This is why the whole “I can’t believe my classma…

Agreed.

I think they should negotiate a security test beforehand. For their own sake but also to get a buy-in. And if a company categorically refuses, you can then publish that, or share that you worry about a lack of track record in known security audits. That's a professional way to hold them accountable.

Breaking into a system unannounced and then stating "do what I say...OR ELSE", is neither legal nor professional. When you're surprised that this will be perceived as an attack instead of being helpful, I don't know what to say.

Re: When your classmates threaten you with felony charges

#267

Earlier quoted context omitted.

Not really, many professional researchers notify law enforcement when engaging in something that could be viewed as illegal or generate calls to the police. What should happen is the addition of a "reasonable" standard and using existing case law policy positions to not prosecute people who have a reasonable basis supporting their claim of security research. Instead we'll be left with the lazy lawmakers doing nothing…

I hate the use of "reasonable" in law. Who's to define what's reasonable?

Similar in flight rules: one cannot fly a paraglider over "congested area". But what is "congested area" is intentionally not defined in the rules, and left up to judges to decide for each case separately.

Because if FAA tries to come up with a definition, there will always be weird unjust corner cases. Or just ban the paragliders whatsoever. I think the current ambiguity is the best compromise.

Re: When your classmates threaten you with felony charges

#268

Earlier quoted context omitted.

Devil's advocate: I get into your home by bypassing (poor) security. I take pictures and make copies of anything inside. Then I publicly announce the breach and demand that you fix your security based on a deadline I made up. Then I say "trust me, bro" when I promise to never reveal the data I stole. Nobody would find any of that moral. The analogy breaks down because your home is not a place where sensitive data of…

> I get into your home by bypassing (poor) security. I take pictures and make copies of anything inside. Then I publicly announce the breach and demand that you fix your security based on a deadline I made up. Then I say "trust me, bro" when I promise to never reveal the data I stole. Otoh, it sounds really different if you break into your own home. I think part of the issue is with everything in the cloud your data…

I agree that there's friction between the greater public good and private interests.

But I don't agree with the reductive take that compromised security means companies don't care or are greedy. Companies that do care and have an army of security staff still fuck up.

The reality check is that security is incredibly complicated, expensive, very easy to do incorrectly.

If anything, us software developers should do some reflection on our software stack. It's honestly quite shit if it requires daily updates and a team of security gurus to not get it wrong.

Re: When your classmates threaten you with felony charges

#269

Earlier quoted context omitted.

No, because there's no such thing as "ethical hacking"; that's a marketing term invented by vendors to constrain researchers. You'd call what you're talking about "pentesting" or "red teaming". How you'd know you had a clownish pentest vendor would be if they themselves called it "ethical hacking".

There is no precedent for consequence-free probing of others' defenses. Unauthorized "testing conducted in ways unfavorable to vendors" is generally considered a crime of trespass, because everybody has the right to exist unmolested. Whether or not they have their shit together, you aren't authorized to test your kids' school's evacuation procedure by randomly showing up with a toy gun and a vest rigged with hotdogs…

You're doing the same thing the other commenters are: you're trying to derive from first principles what "ethical hacking" means. That's why this marketing trick is so insidious: everybody does that, and attributes to the term whatever they think the right things are. But the term doesn't mean those right things: it means what the vendors meant, which is: co-opted researchers working in collusion with vendors to give dev teams the maximum conceivable amount of time to apply fixes (years, often) and never revealing the details of any flaws (also: that any security researcher that doesn't put the word "ethical" in their title is endorsing criminal hacking; also: that you should buy all your security services from I.B.M.).

You can say "that's not what I mean by ethical hacking", but that doesn't matter, because that's what the term of art itself does mean.

If you want to live in a little rhetorical bubble where terms of art mean what you think they should mean, that's fine. I think it's worth being aware that, to practitioners, that's not what the terms mean, and that people familiar with the field generally won't care about your idiosyncratic definitions.

Re: When your classmates threaten you with felony charges

#270
post #204

Earlier quoted context omitted.

> This seems like a problem with the existing law, if that's how it works. > I understand why you feel that way, but it's not the way the law works. OP was saying they don't think the law should work that way.

Wait'll they learn about the Eggshell Skull Rule.

This is more in the neighborhood of contributory negligence.
Post reply on HN