Live data from Hacker News

Governor vows criminal prosecution of reporter who found flaw in state website

missouriindependent.com

391–400 of 705 posts

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#391

Earlier quoted context omitted.

It is very easy for IT managers to put the blame on "hackers" intruding into the network, instead of assuming they created an insecure system. In many companies this can work.

Years ago, I worked at this place, they tried to install these new core routers. The first core router worked fine, but connect the second and the whole campus network would go into meltdown. The network team could not work it out. The vendor could not work it out. But one of the IT managers had an explanation: me. Firstly, it was due to an OpenVPN I installed on a server (with permission-as a stopgap measure so we c…

Did that IT manager ever apologize for accusing you of being the problem?

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#392

After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…

How is it a bad response? They want to know what data has been exposed and ensure you delete that data. That's data leak 101. Why would you be defensive about it?

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#393

Earlier quoted context omitted.

I think that's a valid response if the person letting you in wasn't expecting you and didn't want you there. Like, what are you doing knocking on random doors and going into random places just to look around? That's not honest behavior. Honest behavior is that if you know you're not supposed to have access to a thing, you shouldn't obtain access to the thing even if you technically can. I think it's pretty clear that…

>if the person letting you in wasn't expecting you and didn't want you there. Then they shouldn't have let you in. How are you completely absolving them of responsibility when all they had to do was say "Who the hell are you? No, you can't come in."

Well, to go with the analogy more: I leave my door unlocked because I'm expecting someone. There's a knock at my door and I yell "Come in" without looking at who is at the door. Not an unreasonable thing, happens all the time. When I finally look, I find you in my house, going through all of my things, for no reason other than you wanted to gain insight on my financial situation.

Do I bear responsibility for letting you in? Yes. Should you be there? No. Should you have knocked on the door? No. Should you have tried the same at my neighbor's house and every house on my block? No. In this metaphor and in the original context, everyone is acting with honest intent except the actor knowingly trying to access obviously confidential documents.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#394

[1] Parson commits $50M to investigate alleged hack of Missouri educator database. Includes video press conference by Parson himself. [1] https://fox2now.com/news/missouri/missouri-education-departm...

$50m? Wouldn't that be better spent on the actual education system and educators itself?

Talk about corruption - spending taxpayer money to cover-up mistakes made by government employeers - AND libellous statements made by government officials...

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#395
post #378

Earlier quoted context omitted.

The US Government has a STIG (Security Technical Implementation Guide [1], a government-proprietary term for "IT policy") that requires that you disable Dev Tools in IE [2], Edge [3] and Chrome[4]. Their justification (from [1]): > Information needed by an attacker to begin looking for possible vulnerabilities in a web browser includes any information about the web browser and plug-ins or modules being used. When deb…

I can think of at least one legitimate reason to block the dev console. There are these posts I've seen over the years that say to "press the hotkey to open the Javascript console, and paste this Javascript blob" (obviously in much more persuading terms) to get a discount on RayBands or something. Disabling it prevents a possible information leak vector.

There's a legitimate reason for doing _almost anything_ - it's a question of likelihood, impact, and knock-on effects.

I can only imagine how much taxpayer money has been set on fire by developers having to debug single-page applications running on these systems without the aid of Dev Tools... these types of material wastages are created in an imperfect attempt to prevent the mere possibility of something that could be more effectively mitigated through training and web content filtering.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#396

Earlier quoted context omitted.

But... they didn't change their name on the form. They literally just said "I'm still me, but I want this other file now, please." All company data was, in OPs scenario, made public to any and all authenticated users. There is no way to rationally spin this as a malicious act, in my view.

Well they changed an id number. I guess the real life version would be changing the SSN number on the form.

An ssn is considered private info, the plan number wouldn't be.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#397

After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…

So his issue was not that you discovered the bug. His issue was that after discovering it, you went on to view a bunch of other people's data. What you did was walk down the block, pull on the doors of random houses, and if you found one unlocked, went in and took a look around. If you found my door unlocked and left me a note, I would be grateful. If you went in and took a look around, then did it to all of my neigh…

It's a public website. If we have to use the doors analogy, these are doors at City Hall, not people's houses.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#398

After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs. After I…

So his issue was not that you discovered the bug. His issue was that after discovering it, you went on to view a bunch of other people's data. What you did was walk down the block, pull on the doors of random houses, and if you found one unlocked, went in and took a look around. If you found my door unlocked and left me a note, I would be grateful. If you went in and took a look around, then did it to all of my neigh…

Wow. The parent comment did not state they then sifted around for personal data. They checked if there was a bug and found it. For all we know the personal data is front and center, so this rudimentary check also revealed personal information. It’s not like they said they downloaded the SSNs. Good job a miming the ignorance and bad faith of the nameless bureaucrat the parent comment mentioned though, maybe this is just satire and I’m missing it..

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#399
post #217

Earlier quoted context omitted.

Maybe he was hoping OP didnt know about VPNs, it's not an uncommon scare tactic to imply being tracked is unavoidable.

I'm sure any further unauthorized access from random VPN IPs would have also been blamed on OP, unfortunately. "He found this out then an hour later random IPs exploited it. He must have initiated those VPNs".

VPN doesn’t matter here. OP made it clear he was logged into the system first. Presumably all data is blocked until you are logged in. And if you are logged in, IT admin does not care about your IP address when they have your username.

Re: Governor vows criminal prosecution of reporter who found flaw in state website

#400
post #166

Earlier quoted context omitted.

I don't know, that sounds like a pretty valid response given that you "shopped a few other companies to see how our plans compared".

If I ask you to show me a document, and you willingly show me the document, who exactly is responsible for the disclosure?

Accessing data that you are not authorized to view is still wrong. The fact that someone has misconfigured the access controls doesn't change that.

I might forget to lock my front door one day, but that doesn't make it ok for you to wander into my house and look at all my stuff.

Post reply on HN