Earlier quoted context omitted.
We've always known that using DevTools was a criminal activity. In fact, the sheer number of people using them places this at criminal conspiracy levels. Better start filing those RICO cases against the browser devs. /s
How dare you did "View Source", you hacker.
Governor vows criminal prosecution of reporter who found flaw in state website
281–290 of 705 posts
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#282This news should not surprise anybody who has used government websites in Missouri. Here is an example: https://mydssapp.mo.gov/CitizenPortal/application.do The website takes a LONG time to load because of how many javascripts it loads!!
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#283Re: Governor vows criminal prosecution of reporter who found flaw in state website
#284Earlier quoted context omitted.
Asking for the next file isn't false pretenses. I don't know if this analogy works quite right. Even rifling through a file cabinet wouldn't be false pretenses, it would be something else. And you have to cause injury for it to be fraud. Is "Help I was too honest to a customer." a valid injury claim?
The closest real-life equivalent to asking a computer server for a document and getting it is asking a human server (e.g. office clerk, archivist) for a document and getting it. If I go to the IRS to do some paperwork and notice it says "File #7881991" in the top right corner and I go to the clerk and ask them "Hey, can I have files 7881992 and 7881993, too?" and they give them to me , who is liable for that? It's qu…
You filled out some form to request a document from the irs. You give the form to the person they give you the document.
You notice they dont check ids, so you change the name on the form, and get someone else's document.
This definitely seems to fit the definition of fraud:
380 (1) Every one who, by deceit, falsehood or other fraudulent means, whether or not it is a false pretence within the meaning of this Act, defrauds the public or any person, whether ascertained or not, of any property, money or valuable security or any service [that's the canada definition]
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#285Earlier quoted context omitted.
> After I shopped a few other companies to see how our plans compared Yeah once you start using a vulnerability maliciously to obtain confidential data for your own personal gain, even if its a stupid vulnerability, you're not really good-guy security researcher anymore. If all you did was the bare minimum to demonstrate the vuln exists, that's cool. If after you do that you continue to use it to obtain confidential…
Browsing the different plans is not malicious. Jesus. And the details of different plans is not the kind of confidential info that innately deserves protection. Investigating or recording personal information would be bad, but they didn't do that.
Apply for jobs at the other companies with better plans, proceed with interviews, offers and then finally accept one and quit their job at their current employer... To reap the rewards of their malicious hacking...
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#286Earlier quoted context omitted.
If I ask you to show me a document, and you willingly show me the document, who exactly is responsible for the disclosure?
In real life, if you do it under false pretenses, you are. In this analogy the real-world version would be considered fraud.
Sure, but how is that relevant? What material false representation was made which was relied on in deciding to provide the data?
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#287After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…
I dunno, this seems pretty normal. Just today news broke that in Germany some guy who found a flaw in a web-shop backend leaking the data of hundreds of thousands of people got raided, because the operator reported him to the police - and somehow both police and state attorney found it wise to prosecute him instead of referring the case to the GDPR officer to fine the operator. It's pretty obvious that when you find…
OR let us reverse the analogy
You find out Facebook is running an international slave trade by using their data to find vulnerable teenage girls sending them invites and then kidnapping them. Do you A) approach Facebook and try to get them to stop their practice B) alert everyone immediately.
The answer is you alert everyone immediately because Facebook in this example is doing corrupt and illegal things. There is a difference in how you should react concerning security problems that others can take advantage of and willfully committing illegal and corrupt acts.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#288Earlier quoted context omitted.
> ... someone from their IT department rang me on the phone and started grilling me about how many other plans I browsed, and insisted that I clear my cache and browsing history, and notified me that they would be watching to make sure nobody at our IP address didn't access any other plans while the issue was being fixed. An IT employee who doesn't know about VPNs. Sigh.
Maybe he was hoping OP didnt know about VPNs, it's not an uncommon scare tactic to imply being tracked is unavoidable.
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#289[1] Parson commits $50M to investigate alleged hack of Missouri educator database. Includes video press conference by Parson himself. [1] https://fox2now.com/news/missouri/missouri-education-departm...
Re: Governor vows criminal prosecution of reporter who found flaw in state website
#290Earlier quoted context omitted.
I dunno, this seems pretty normal. Just today news broke that in Germany some guy who found a flaw in a web-shop backend leaking the data of hundreds of thousands of people got raided, because the operator reported him to the police - and somehow both police and state attorney found it wise to prosecute him instead of referring the case to the GDPR officer to fine the operator. It's pretty obvious that when you find…
> a) Disclose this through e.g. the press b) Approach the mayor and try to get him to fix his stuff. Somehow, when it comes to IT security, people wanna see hackers do b) because a) would clearly be irresponsible. Wtf? Huh? This analogy doesn't really make sense. The difference for software is extremely basic: if you publicize a vulnerability immediately, you give more opportunity for it to be exploited while it's be…
if it’s live it’s already being exploited. simple principle, but very effective.