Live data from Hacker News

When your classmates threaten you with felony charges

miles.land

311–320 of 350 posts

Re: When your classmates threaten you with felony charges

#311
Do you think that someone less ethically minded could have resolved the issue more simply by redirecting their landing page to a warning that the site was insecure and shutting it down incurring near zero personal risk of retaliation and letting people make an informed choice about continuing to use the site.

This is wholly and obviously illegal but so is the described ethical hacking. You have adopted a complex nuanced strategy to minimize harm to all parties. This is great morally but as far as I can tell its only meaningful legally insofar as it makes folks less likely to go after you nothing about it makes your obviously illegal actions legal so if you are going to openly flout the law it makes sense to put less of a target on your back while you are breaking the law.

Re: When your classmates threaten you with felony charges

#312

Earlier quoted context omitted.

There is obviously such a thing as going too far, but it's kind of hard to draw a clear line. In a good faith context, laws and precedents can change quickly, sometimes based on the whim of a judge, and there are many areas of law where there is no clear precedent or where guidance is fuzzy. In those cases, it's important to have severability so that entire contracts don't have to be renegotiated because one small cl…

> At the end of the day, documents like this are written by lawyers in legalese that's not designed for ordinary people. Does it have to be this way?

"Legalese" can often be simplified, but concepts that are necessarily in law are often not widely known by lay people, and as such it's hard to avoid some terminology and reasoning that require a bit of legal training to understand.

But every subject and field has their own set of terminology. It's just like programming -- while we strive to make code easier to understand (eg. Python is better than assembler in this regard), there's still a necessary learning curve. Your question is almost like asking "why can't we just tell the computer what we want to do in plain English?"

Sometimes the legalese is actually comprehensible if you give it a bit of patience. Often though, programmers like to make (wrong) assumptions about how the words are to be interpreted though, and that's where most people trip up.

Re: When your classmates threaten you with felony charges

#313

I don't understand why in both contracts and legal communication (particularly threatening one), there is little to no consequence for the writing party to get things right. I've seen examples of an employee contract, with things like "if any piece of this contract is invalid it doesn't invalidate the rest of the contract". The employer is basically trying to enforce their rules (reasonable), but they have no negativ…

IANAL, but the letter is borderline extortion/blackmail. Threatening to report an illegal activity unless the alleged perpetrator does something to your advantage can be extortion/blackmail AFAIK.

Re: When your classmates threaten you with felony charges

#314

Earlier quoted context omitted.

To me that reads less as "this is legal" and more as "this is illegal, but we (the executive branch of the government) will be nice and not go after you for it as long as we think you're a good guy". That's (arguably) better than nothing, but not exactly an ideal way to structure our justice system in my opinion.

Yes, but I don't see a better solution. If we make "security research" legal, then any hacker can just say "oh I was just going to disclose my findings to them".

Well, the thing about making security research legal is that the law can outline what is legal and illegal security research, instead of leaving it in a grey area of a policy statement that may change at any time without notice, or from a political agenda.

A well executed law change will make it very clear where the line is to get into illegal territory and would likely include industry feedback in the drafting. The downside is it could also go the other way, policy changes are executed by politicians who likely have a fairly poor grasp of the tech and industry, and could leave the policy in a worse shape until tested by the court system.

If the law were to say outline steps the hacker must do, barriers that can't cross, it may actually make it harder for a hacker to say I was just doing research.

Re: When your classmates threaten you with felony charges

#315

Earlier quoted context omitted.

If it's a threat, then that's literally blackmail. It's only legal to use the legal action, period. Once you pull in a THREAT, it becomes blackmail/extortion.

A cease and desist letter is a "threat" and is not illegal/blackmail/extortion.

It's not a cease and desist letter. It's an extortion attempt to put pressure the alleged hackers to sign a non-disclosure agreement.

It's kind of a tricky gray area where similar demands might be legal, but I do think in this case it should be illegal.

Re: When your classmates threaten you with felony charges

#316

Earlier quoted context omitted.

Here’s a better solution: change the laws! Knowing the audience of this forum, you’re probably American and under 35. You have lived your whole life with an inoperable legislator. The US Congress, through a mixture of time-honored traditions with unfathomable externalities (there can never be more than this amount of representatives) and disinterested sports-like politics, is unable to print new laws in a reactive fa…

You get that the legal situation for this stuff is even gnarlier in Europe, right?

Belgium legalises ethical hacking:

https://www.law.kuleuven.be/citip/blog/belgium-legalises-eth...

HN thread from 4 months ago: https://news.ycombinator.com/item?id=35847860

Re: When your classmates threaten you with felony charges

#317

Earlier quoted context omitted.

> this is subtle: you can easily rack up 5-6 figure damage numbers from unauthorized security research, but Fizz was so small and new that I'm assuming nobody even contemplating retaining a forensics firm or truing things up with their insurers, who probably did not exist This seems like a problem with the existing law, if that's how it works. It puts the amount of "damages" in the hands of the "victim" who can choos…

Strange things happen every day but in my experience the jury decides on the damages, not the plaintiff.

We're talking about what rule the law should intend to be used, not who applies the rule.

Re: When your classmates threaten you with felony charges

#318

Earlier quoted context omitted.

Yeah, I sort of get your point. > So we did what any good security researcher does : We responsibly disclosed what we found. We wrote a detailed vulnerability disclosure report. We suggested remediations. And we proactively agreed not to talk about our findings publicly before an embargo date to give them time to fix the issues. Then we sent them the report via email. This is why the whole “I can’t believe my classma…

> So why didn’t they start with communication first before trying to hack the system? Good security researchers do that. (Not all of the time, obviously.) I don't think that is true. I think it would be very unusual for an independent (not a pentester) security researcher to communicate anything before they have any findings. > It seems like the researchers just wanted to have some fun on a Friday night (like he said…

You do get some of what I said it seems like especially because you didn’t acknowledge my first paragraph that explained why they weren’t acting like classmates themselves (which was a major theme/point in the article/blog post lol. It’s in the title).

I don’t feel a need to fully address all of your comments (because the first one was just your opinion similar to my own opinion). We can each look up stats for this.

But your second comment (also an opinion as mine was) did stick out to me due to emotional/psychological/human reasons, I guess:

> Good faith research is fun.

I was speaking about intention. I’m not convinced that “research” (whether it was good or bad faith even) was the goal here.

(FYI, I know the author of the post said this was written and talked about before. All I did was form an opinion based on his summary of the events for this specific HN post. I assumed it would have all of the salient information. But if there’s something missing, please point it out.)

It’s a cool story though.

Re: When your classmates threaten you with felony charges

#319

Earlier quoted context omitted.

Yeah, I sort of get your point. > So we did what any good security researcher does : We responsibly disclosed what we found. We wrote a detailed vulnerability disclosure report. We suggested remediations. And we proactively agreed not to talk about our findings publicly before an embargo date to give them time to fix the issues. Then we sent them the report via email. This is why the whole “I can’t believe my classma…

Agreed. I think they should negotiate a security test beforehand. For their own sake but also to get a buy-in. And if a company categorically refuses, you can then publish that, or share that you worry about a lack of track record in known security audits. That's a professional way to hold them accountable. Breaking into a system unannounced and then stating "do what I say...OR ELSE", is neither legal nor professiona…

> When you're surprised that this will be perceived as an attack instead of being helpful, I don't know what to say.

Correct. This is why I believe they (or at least some of them) weren’t actually surprised lol.

> If you can’t tell from his wisdom, it was not Cooper’s first time dealing with legal threats.

This is a quote from the post. The author acknowledged that his fellow researcher was experienced with interacting with lawyers for exactly this kind of scenario.

Red flag. Red hat?

Re: When your classmates threaten you with felony charges

#320
post #57

I'm not a lawyer, but I am professionally interested in this weird branch of the law, and it seems like EFF's staff attorney went a bit out on a limb here: * Fizz appears to be a client/server application (presumably a web app?) * The testing the researchers did was of software running on Fizz's servers * After identifying a vulnerability, the researchers created administrator accounts using the database activity the…

Good analysis. I’m really confused why in the 2020s anybody thinks that unsolicited pentesting is a sane or welcome thing to do. The OP doesn’t seem to have a “mea culpa” so I hope they learned this lesson even if the piece is more meme-worthy with a “can you believe what these guys tried to do?” tone. While their intent seems good, they were pretty clearly breaking the law.

It’s both sane and welcome. the alternative to unsolicited testing is your app getting owned and your customer data being sold and you being sued into oblivion. unsolicited. Your vulnerability doesn’t cease to exist because you don’t want people to look at it.
Post reply on HN