Live data from Hacker News

Governor vows criminal prosecution of reporter who found flaw in state website

missouriindependent.com

371–380 of 705 posts

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#371

After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…

So his issue was not that you discovered the bug. His issue was that after discovering it, you went on to view a bunch of other people's data.

What you did was walk down the block, pull on the doors of random houses, and if you found one unlocked, went in and took a look around. If you found my door unlocked and left me a note, I would be grateful. If you went in and took a look around, then did it to all of my neighbors, we would have you arrested.

The bug here is an unlocked door. It being unlocked is a security risk, and people are thankful if you let them know. If after identifying the security risk you proceed to commit a crime, you're surprised people aren't "grateful?"

>difficult to hold yourself accountable

isn't it though...

>are malicious actors

so you.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#372

Earlier quoted context omitted.

I don't know, that sounds like a pretty valid response given that you "shopped a few other companies to see how our plans compared".

Being wary of the guy, sure. But it's a terrible response in general. The correct response is to take the site down ! Monitoring IP addresses? Really? First, it's trivial to just use a different IP address. Second, even if you could track people perfectly, which you can't, who the hell thinks it's okay for data to get leaked as long as you know who it gets leaked to?

Vehemently agree. The response demonstrates, if nothing else, the lack of an appropriate Incident Response Plan. A competent legal team would not vet and approve such a response, instead redirecting it through the appropriate channels if they felt the need to respond directly.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#373
post #246

Earlier quoted context omitted.

> echo json_encode($search_results); This is how I found out how much I, and all other contractors were being paid. And also how much the contracting company was actually charging the clients. All the data was being returned in a json but the very little was being displayed. Looking at the story, this is more of a posture thing. I'm sure the Governor is surrounded with people who can tell him that no hacking took pla…

wow, what fraction of websites leak data I want to look at? should I be poking at every non-tech-giant site I go to?

The analogy is going up to a house and checking all the doors and windows to see if they are locked. That's rather like port scanning, a form of 'poking'. If you go to a state government web site and do that, even if you don't exfiltrate data or load it up with ransomware, it's definitely very shady behavior, although it seems there are no laws against it in the USA (some ISPs will ban users caught doing this however).

Obviously if you broke into someone's house and then asked them to pay you for your 'vuln discovery', err...

However, I think looking at HTML code on a public facing web page is not that. If you hang naked pictures of yourself on your front door, you don't get to complain when people take pictures of them.

1. https://www.calyptix.com/top-threats/port-scanning-legal-ans...

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#374
post #89
post #21

> Parson said...the reporter was “attempting to embarrass the state and sell headlines for their news outlet.” Literally a reporter's job.

The funny thing is, the reporter successfully embarrassed the state, then the state embarrassed itself further in response.

Streisand effect, too. None of us would have heard about this otherwise.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#376

Earlier quoted context omitted.

I did that once a long, long time ago with the organization that monitors maritime piracy around the world. They have a mailing list which I accidentally stumbled on that included I assume since I only saw the one page of email addresses that ended in top level domains like un.org and navy.mil thousands of email addresses. I contacted through email the people running the organization that I accidentally stumbled on t…

Huge missed opportunity for mass email of URL shortener link to the youtube Rick Astley video.

There were cia.gov email addresses in there too. When these guys don't get a joke and fixate on you, they really fixate on you. They are more clingy than that song.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#377
“The state is committed to bring to justice anyone who hacked our system and anyone who aided and abetted them to do so,” Parson said

I assume they'll start with the head of the Office of Administration Information Technology Services Division whose team allowed such a glaring vulnerability in the first place.

If IT management held some responsibility for breaches, then maybe it wouldn't be so hard to get funding for security measures.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#378

Earlier quoted context omitted.

We've always known that using DevTools was a criminal activity. In fact, the sheer number of people using them places this at criminal conspiracy levels. Better start filing those RICO cases against the browser devs. /s

The US Government has a STIG (Security Technical Implementation Guide [1], a government-proprietary term for "IT policy") that requires that you disable Dev Tools in IE [2], Edge [3] and Chrome[4]. Their justification (from [1]): > Information needed by an attacker to begin looking for possible vulnerabilities in a web browser includes any information about the web browser and plug-ins or modules being used. When deb…

I can think of at least one legitimate reason to block the dev console. There are these posts I've seen over the years that say to "press the hotkey to open the Javascript console, and paste this Javascript blob" (obviously in much more persuading terms) to get a discount on RayBands or something. Disabling it prevents a possible information leak vector.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#380

>Republican state Rep. Tony Lovasco, who according to his legislative biography has worked in software deployment and maintenance, tweeted Thursday that “it’s clear the Governor’s Office has a fundamental misunderstanding of both web technology and industry standard procedures for reporting security vulnerabilities. >“Journalists responsibly sounding an alarm on data privacy is not criminal hacking,” he said. I worry…

The fact that it happened here should calm your worries at least a little bit.
Post reply on HN