Live data from Hacker News

When your classmates threaten you with felony charges

miles.land

271–280 of 350 posts

Re: When your classmates threaten you with felony charges

#271

Earlier quoted context omitted.

Yes, but I don't see a better solution. If we make "security research" legal, then any hacker can just say "oh I was just going to disclose my findings to them".

Here’s a better solution: change the laws! Knowing the audience of this forum, you’re probably American and under 35. You have lived your whole life with an inoperable legislator. The US Congress, through a mixture of time-honored traditions with unfathomable externalities (there can never be more than this amount of representatives) and disinterested sports-like politics, is unable to print new laws in a reactive fa…

You get that the legal situation for this stuff is even gnarlier in Europe, right?

Re: When your classmates threaten you with felony charges

#272
post #63

Earlier quoted context omitted.

(a) There's no such thing as "ethical hacking" (that's an Orwellian term designed to imply that testing conducted in ways unfavorable to vendors is "unethical"). (b) You don't require permission to test software running on hardware you control (absent some contract that says otherwise). (c) But you're right, in this case, the researchers presumably did need permission to conduct this kind of testing lawfully.

(a) what if a company hires an external red team to hack their shit, would that not be 'ethical hacking'?

As a point of comparison, we don't talk about "ethical plumbing" as a term. If a company hires a plumber to fix their bathroom, they're just a plumber. If somebody breaks the law to enter a place and mess with the pipes, they're just a trespasser.

But the companies that brand themselves as selling "ethical" penetration testing, and sell certifications for "ethical hacking" would very much like you to lump other companies and other security researchers who are operated legally into the same mental bucket as criminals by implicitly painting them as "unethical".

Re: When your classmates threaten you with felony charges

#273
Given the aggressive response from this company, it is less likely that it will become the target of any security researchers in the future (who wants the hassle ?). That by itself makes their app less secure in the long term. Also, who'd want to support founders with this "I will destroy you!, even though you helped me improve my system" mentality ? I wouldn't be surprised if this startup dies off from this info.

Kudos to Cooper, Miles and Aditya for seeing this through.

Re: When your classmates threaten you with felony charges

#274

Earlier quoted context omitted.

> I've seen examples of an employee contract, with things like "if any piece of this contract is invalid it doesn't invalidate the rest of the contract". This concept of severability exists in basically all contracts, and is generally limited to sections that are not fundamental to the nature of the agreement. (The extent of what qualifies as fundamental is, as you said, up to a court to interpret.) In your specific…

> especially the ones that protect you as the individual - will remain in force even if a sub section is invalidated In a right-to-work state, what protections can an individual realistically expect to receive from a contract?

Employment contracts can govern firing. You can have a contract that says can only be fired for cause and get one month of notice for other dismissals.

Actual employment contracts are rare in the US. I think because don't want legal hassle for most employees, but executives and other important employees have contracts.

Other countries have contracts for every employee. I assume they use a standard contract for most employees, and that the laws limit the scope.

Re: When your classmates threaten you with felony charges

#275
post #57

I'm not a lawyer, but I am professionally interested in this weird branch of the law, and it seems like EFF's staff attorney went a bit out on a limb here: * Fizz appears to be a client/server application (presumably a web app?) * The testing the researchers did was of software running on Fizz's servers * After identifying a vulnerability, the researchers created administrator accounts using the database activity the…

I'm not a lawyer, so I'm pretty sure what I'm about to say wouldn't hold up in a court of law, but if you claim your system is 100% secure, then someone hacks it, I think by definition your are allowed to be there and not subject to the CFAA. In a 100% secure system you can't get into anything you're not allowed to, so if you're accessing something, you by definition, are allowed to.

We all here no, there is no such thing as something 100% secure, but if you're gonna go making wild claim, you should have to stand by them.

Re: When your classmates threaten you with felony charges

#276
I think I might be a bit of an outlier on this, but I struggle to see the value of imposing an embargo date in a security disclosure unless it's sent to a large institution that is used to a formal process like that. In most cases, if you're trying to communicate to someone that you've found a vulnerability under the pretense that you're doing it for the greater good, why begin by the relationship with a deadline before you "go public?" Wouldn't that be something you do later on if it appears that they're just blowing you off and won't do anything about it?

I don't think this applies to the reporter in this case, but it does seem like there's a bit of a trend in security research lately to capitalize on the publicity of finding a vulnerability for one's own personal branding. That feels a bit disingenuous. Not that the appropriate response would be to threaten someone with legal action.

Re: When your classmates threaten you with felony charges

#277
post #253
post #217

Earlier quoted context omitted.

> golden parachutes Nobody has these except top execs who are already in a huge position of power. > vacation days, sick days, payout of the same Nope, not anymore: nothing is guaranteed with "flexible time off". I literally cannot meet my performance goal if I take more than 1 day of sick/vacation day PER YEAR. Yes, my raises are tied to this performance goal. Yes, it's probably illegal, but who cares? Nobody is eve…

I don’t know what to say in response to your complaints except negotiate better working conditions next time you get hired. The company wrote it. You accepted it. You can always ask for different terms and walk away if they don’t agree, start your own company, or change industries to one where companies are willing to negotiate. If you want protections for employees, sure you can (erroneously, in my opinion) look to…

> You can always ask for different terms and walk away if they don’t agree, start your own company, or change industries to one where companies are willing to negotiate.

I suspect you have lived a very privileged life if you really believe these options are actually open to most employees in the U.S. Switch industries? Start your own company? Those are both extreme life-altering multi-year responses to losing PTO payout, and only work for people who have major safety nets and support in their lives. Companies pull this bullshit because they know they can get away with it. Guess what: they're right. I'm glad you are in such a state of privilege that you can spend 4 years going back to college and switching industries without going into massive debt and without suffering from the loss of income during that time, but you are extremely lucky to be in that position. Do not assume others are lazy and/or stupid and/or bad negotiators because they can't. Negotiating is not about shaking hands harder, it's about having leverage, and 98% of U.S. workers have none.

> negotiate better working conditions next time you get hired

These were not the working conditions at the time I was hired. None of this was in any contract I signed. Companies change this stuff after-the-fact all the time. What are you going to do, hire an employment lawyer? You'd poison your own drinking well, potentially forever, with the possible upside of being the only employee in your company that actually get PTO paid out? Come on. Nobody is doing this. Companies pull this bullshit because they can.

Re: When your classmates threaten you with felony charges

#278

I think I might be a bit of an outlier on this, but I struggle to see the value of imposing an embargo date in a security disclosure unless it's sent to a large institution that is used to a formal process like that. In most cases, if you're trying to communicate to someone that you've found a vulnerability under the pretense that you're doing it for the greater good, why begin by the relationship with a deadline bef…

Do you disagree that Users might be entitled to know when a corporation is misusing their private, sensitive information? What is ethical does not begin and end with the corporations best interest, the users whose private information is being mishandled are the victims here, let us not lose perspective.

Re: When your classmates threaten you with felony charges

#279
post #57

I'm not a lawyer, but I am professionally interested in this weird branch of the law, and it seems like EFF's staff attorney went a bit out on a limb here: * Fizz appears to be a client/server application (presumably a web app?) * The testing the researchers did was of software running on Fizz's servers * After identifying a vulnerability, the researchers created administrator accounts using the database activity the…

Federal supremacy preempts, rather than moots.

Fizz may have violated more than a state bar rule; this could very well be extortion (depending).

I would tend to agree with the balance of your comments.

Re: When your classmates threaten you with felony charges

#280

Earlier quoted context omitted.

Not really, many professional researchers notify law enforcement when engaging in something that could be viewed as illegal or generate calls to the police. What should happen is the addition of a "reasonable" standard and using existing case law policy positions to not prosecute people who have a reasonable basis supporting their claim of security research. Instead we'll be left with the lazy lawmakers doing nothing…

I hate the use of "reasonable" in law. Who's to define what's reasonable?

Any time you see that word you can be pretty sure that the matter under consideration is a fact question for the jury. The reason you hate that word is because you prefer hard and fast, bright line rules. That’s fine, I do too.

Reasonable just means there’s no good way to have a bright line rule and we have to consider these questions one at a time, in context.

Post reply on HN