Live data from Hacker News

When your classmates threaten you with felony charges

miles.land

291–300 of 350 posts

Re: When your classmates threaten you with felony charges

#291

Earlier quoted context omitted.

My point is that it doesn't matter how slippery the underlying words are, because you're not meant to piece together the meaning of the statement from those words --- or rather, you are, but deceptively, by attributing them to the policy preferences of the people who coined the term. Logomachy aside: "ethical hacking" was a term invented by huge companies in the 1990s to co-opt security research, which was at the tim…

I guess what I'm trying to say is that there is, and can be, such a thing as "ethical hacking," but perhaps it's not coterminous what vendors and others might claim it to be. The meanings of words evolve over time, sometimes for the worse ( cough "literally"), and sometimes for the better. Groups have also reclaimed derogatory words through concerted action.

It's a complicated human activity, so of course there are ethics to it. But I'd strongly recommend not using the words "ethical hacker" next to each other, because that term has more meaning than you probably intend.

Re: When your classmates threaten you with felony charges

#292
post #57

I'm not a lawyer, but I am professionally interested in this weird branch of the law, and it seems like EFF's staff attorney went a bit out on a limb here: * Fizz appears to be a client/server application (presumably a web app?) * The testing the researchers did was of software running on Fizz's servers * After identifying a vulnerability, the researchers created administrator accounts using the database activity the…

I'm not a lawyer, so I'm pretty sure what I'm about to say wouldn't hold up in a court of law, but if you claim your system is 100% secure, then someone hacks it, I think by definition your are allowed to be there and not subject to the CFAA. In a 100% secure system you can't get into anything you're not allowed to, so if you're accessing something, you by definition, are allowed to. We all here no, there is no such…

No, definitely not, this doesn't work at all.

Re: When your classmates threaten you with felony charges

#293

Earlier quoted context omitted.

Not really, many professional researchers notify law enforcement when engaging in something that could be viewed as illegal or generate calls to the police. What should happen is the addition of a "reasonable" standard and using existing case law policy positions to not prosecute people who have a reasonable basis supporting their claim of security research. Instead we'll be left with the lazy lawmakers doing nothing…

I hate the use of "reasonable" in law. Who's to define what's reasonable?

I generally hate it too. But it is better than "it's illegal, but we won't prosecute researchers". Note that "researchers" is also undefined. Reasonable would be one step up for the even worse status quo.

Re: When your classmates threaten you with felony charges

#294

> Stay calm. I can’t tell you how much I wanted to curse out the Fizz team over email. But no. We had to keep it professional — even as they resorted to legal scare tactics. Your goal when you get a legal threat is to stay out of trouble. To resolve the situation. That’s it. The temporary satisfaction of saying “fuck you” isn’t worth giving up the possibility of an amicable resolution. Maybe it's because I'm getting…

> Maybe it's because I'm getting old Yup, that's it :) These kids are either in college or just graduated. They were smart enough to get themselves legal help before saying anything stupid, which is impressive. Cut them some slack!

My ego has probably by now rewritten my memories to match who I am today. This situation seems like it would have had me and my friends laughing, not scared. Brains are weird.

Re: When your classmates threaten you with felony charges

#295

Earlier quoted context omitted.

I hate the use of "reasonable" in law. Who's to define what's reasonable?

Any time you see that word you can be pretty sure that the matter under consideration is a fact question for the jury. The reason you hate that word is because you prefer hard and fast, bright line rules. That’s fine, I do too. Reasonable just means there’s no good way to have a bright line rule and we have to consider these questions one at a time, in context.

As someone also frustrated by this vernacular I really appreciate this perspective. Thanks!

Re: When your classmates threaten you with felony charges

#297

Earlier quoted context omitted.

> I get into your home by bypassing (poor) security. I take pictures and make copies of anything inside. Then I publicly announce the breach and demand that you fix your security based on a deadline I made up. Then I say "trust me, bro" when I promise to never reveal the data I stole. Otoh, it sounds really different if you break into your own home. I think part of the issue is with everything in the cloud your data…

I agree that there's friction between the greater public good and private interests. But I don't agree with the reductive take that compromised security means companies don't care or are greedy. Companies that do care and have an army of security staff still fuck up. The reality check is that security is incredibly complicated, expensive, very easy to do incorrectly. If anything, us software developers should do some…

> The reality check is that security is incredibly complicated, expensive, very easy to do incorrectly.

Indeed. Which is what i meant by perverse incentives. You can generally make more money by ignoring security or doing the bare minimum. Doing security right is expensive, and the consequences of doing it wrong are usually not that much at the end of the day (for the company anyways, the users might be screwed). All this adds up to rational actors under investing in security. And honestly it is hard to blame them.

Re: When your classmates threaten you with felony charges

#298
post #284

Earlier quoted context omitted.

I disagree with this take. There are certainly lines of what is and is not ethical behaviour (where they are is highly debatable), but the vendor doesn't have a monopoly on deciding that.

The ostensible researchers didn’t follow the ethos to which they claimed and linked. Do you disagree with that?

Yes i disagree. You are quoting the document out of context and it doesn't say what you are implying it says.

Maybe out of context is the wrong word. You quote enough of the paragraph it just doesn't support your point.

All the paragraph says is that one hypothetical situation may have legal consequences in some juridsictions. It does not make any claim as to whether or not that is ethical or right.

Re: When your classmates threaten you with felony charges

#299

A private individual or company cannot file criminal/felony charges. Those are filed by a County Prosecutor, District Attorney, State Attorney, etc after being convinced of probable cause. They could threaten to report you to the police or such authorities, but they would have to turn over their evidence to them and to you and open all their relevant records to you via discovery. > Get a lawyer Yes, if they're seriou…

> A private individual or company cannot file criminal/felony charges. Those are filed by a County Prosecutor, District Attorney, State Attorney, etc after being convinced of probable cause.

That's not true, depending on where you live in the US. Several states allow private citizens to file criminal charges with a magistrate. IIRC, NJ law allows actual private prosecution of criminal charges, subject to approval by a judge and prosecutor. I think that's a holdover from English common law.

Re: When your classmates threaten you with felony charges

#300

I think I might be a bit of an outlier on this, but I struggle to see the value of imposing an embargo date in a security disclosure unless it's sent to a large institution that is used to a formal process like that. In most cases, if you're trying to communicate to someone that you've found a vulnerability under the pretense that you're doing it for the greater good, why begin by the relationship with a deadline bef…

Security researchers have a duty to users and industry first, then to the specific companies they are disclosing to. Most companies, without time pressure, do absolutely nil to fix the issues they are made aware of.

It's completely fine to discuss or request a different disclosure date when communicating with researchers. The delay is their protection against inaction.

Post reply on HN