Here's an investigative tool the CFAA & the FBI needs... if a company like Patterson Dental spins up an investigative raid with a baseless complaint, the Bureau should be able to charge them with a crime. One almost hopes the FBI investigation yields enough evidence to charge Patterson with a criminal violation of HIPAA.
FBI raids dental software researcher who discovered patient data on FTP server
41–50 of 171 posts
Re: FBI raids dental software researcher who discovered patient data on FTP server
#42It needs to be understood that if you react this way to responsible disclosure practices, your company & you personally will be subject to irresponsible disclosure practices.
Oh, I've already learned the lesson loud and clear. If I ever discover a vulnerability to disclose, I'm releasing it anonymously on pastebin sites while logged into Tor through a VPN from a free WiFi spot. And, of course, sign it with a new PGP key you've just created, so that if you ever need to release a follow-up with proof that it's you, or come forward as the author of the disclosure, you can.
Re: FBI raids dental software researcher who discovered patient data on FTP server
#43Re: FBI raids dental software researcher who discovered patient data on FTP server
#44Thought long and hard about what to do but decided to not do anything, dont feel like risking my entire life just to help someone. This is me assuming they did not intend to have it publicly open.
With that story out there, it would be nice to have a legit legal way to inform the police or a similar trustworthy government agency that could handle issues like this.
Re: FBI raids dental software researcher who discovered patient data on FTP server
#45Earlier quoted context omitted.
Isn't this exactly what Andrew Auernheimer was charged and convicted with?
Yes - and that's also pointed out in the arcticle: “It’s weev all over again.”
"He is an upstanding family man, with 4 children. He accessed a publicly available server on the Internet, the kind of server you could access at any time by clicking a hyperlink on Facebook, and now he is a felon and rotting in jail." Or something like that.
Re: FBI raids dental software researcher who discovered patient data on FTP server
#46Earlier quoted context omitted.
Yea.. but a site on the internet is more akin to a store than someone's home. It's completely normal to walk into someone's store.
An ftp server is clearly more akin to a spooky abandoned building.
It's like Shafer wrote a letter to their office asking for their list of patients, and lo and behold, they've sent him back an envelope containing that list.
Re: FBI raids dental software researcher who discovered patient data on FTP server
#47The FBI is going to have a hell of a time arguing that accessing a public FTP server with no password protection is a crime.
Why? Andrew "Weev" Auernheimer was prosecuted AND CONVICTED for accessing a public HTTP server with no password protection. They apparently didn't have any trouble pursuing that with a straight face. The conviction was overturned because they had prosecuted him in the wrong state.
Re: FBI raids dental software researcher who discovered patient data on FTP server
#48The FBI is going to have a hell of a time arguing that accessing a public FTP server with no password protection is a crime.
I believe that it is still considered unauthorized access even if they don't have a password set up. I think it goes back to law that existed before computers where if you entered someones home without permission you can't simply argue that there wasn't a lock on the door. Edit: ProAm above reminded me of the Andrew Auernheimer case that was nearly identical to this and was resolved as I describe.
From the article:
I actually remember them having a passworded FTP site
back in 2006. To get the password you would call tech support
at Eaglesoft\Patterson Dental and they would just give you the
password to the FTP site if you wanted to download anything.
It never changed. At some point they made the FTP site anonymous.
While there so no mention of the username involved in the anonymous access, it sounds like they switched from handing out a common password (stupid, but probably qualifying as "unauthorized access" for CFAA purposes. However, if the change where they "made the FTP site anonymous" involved the standard username "anonymous", then the server is offering access.Re: FBI raids dental software researcher who discovered patient data on FTP server
#49Another lesson not to trust people/organizations ignorant enough to keep confidential data in plain text on anonymous FTP. It seems that the 21st century responsible disclosure procedure goes like that: 0. use tor for the research itself 1. report problems anonymously 2. if they don't care - report them to law enforcement for breach of confidentiality 3. if these don't care either or don't accept anonymous tips - mak…
There is no step 2.
Re: FBI raids dental software researcher who discovered patient data on FTP server
#50Earlier quoted context omitted.
I believe that it is still considered unauthorized access even if they don't have a password set up. I think it goes back to law that existed before computers where if you entered someones home without permission you can't simply argue that there wasn't a lock on the door. Edit: ProAm above reminded me of the Andrew Auernheimer case that was nearly identical to this and was resolved as I describe.
Yea.. but a site on the internet is more akin to a store than someone's home. It's completely normal to walk into someone's store.