Live data from Hacker News

FBI raids dental software researcher who discovered patient data on FTP server

dailydot.com

41–50 of 171 posts

Re: FBI raids dental software researcher who discovered patient data on FTP server

#41
post #23

Here's an investigative tool the CFAA & the FBI needs... if a company like Patterson Dental spins up an investigative raid with a baseless complaint, the Bureau should be able to charge them with a crime. One almost hopes the FBI investigation yields enough evidence to charge Patterson with a criminal violation of HIPAA.

Why would the FBI and prosecutors punish Patterson? The gave the FBI an opportunity for raids and prosecutions, and those look great on an annual review.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#42

It needs to be understood that if you react this way to responsible disclosure practices, your company & you personally will be subject to irresponsible disclosure practices.

Oh, I've already learned the lesson loud and clear. If I ever discover a vulnerability to disclose, I'm releasing it anonymously on pastebin sites while logged into Tor through a VPN from a free WiFi spot. And, of course, sign it with a new PGP key you've just created, so that if you ever need to release a follow-up with proof that it's you, or come forward as the author of the disclosure, you can.

Of course, said key is a liability if it is found in your possession.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#44
About a month or so a go i found a open public mongo database with about 12GB of records regarding peoples retirement founds of what i assume was hundreds of thousands of people, account numbers, how much money was in the accounts when they had moved them to various founds and so on.

Thought long and hard about what to do but decided to not do anything, dont feel like risking my entire life just to help someone. This is me assuming they did not intend to have it publicly open.

With that story out there, it would be nice to have a legit legal way to inform the police or a similar trustworthy government agency that could handle issues like this.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#45
post #14

Earlier quoted context omitted.

Isn't this exactly what Andrew Auernheimer was charged and convicted with?

Yes - and that's also pointed out in the arcticle: “It’s weev all over again.”

Except this guy didn't leak a bunch of emails like weev did? Right? If he does go down, that would be terrible for him and his family, but he would be a better poster child for government overreach than weev is.

"He is an upstanding family man, with 4 children. He accessed a publicly available server on the Internet, the kind of server you could access at any time by clicking a hyperlink on Facebook, and now he is a felon and rotting in jail." Or something like that.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#46
post #7

Earlier quoted context omitted.

Yea.. but a site on the internet is more akin to a store than someone's home. It's completely normal to walk into someone's store.

An ftp server is clearly more akin to a spooky abandoned building.

A more accurate analogy for an FTP server is a machine that sends you letters on demand.

It's like Shafer wrote a letter to their office asking for their list of patients, and lo and behold, they've sent him back an envelope containing that list.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#47

The FBI is going to have a hell of a time arguing that accessing a public FTP server with no password protection is a crime.

> The FBI is going to have a hell of a time arguing that accessing a public FTP server with no password protection is a crime.

Why? Andrew "Weev" Auernheimer was prosecuted AND CONVICTED for accessing a public HTTP server with no password protection. They apparently didn't have any trouble pursuing that with a straight face. The conviction was overturned because they had prosecuted him in the wrong state.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#48
post #5

The FBI is going to have a hell of a time arguing that accessing a public FTP server with no password protection is a crime.

I believe that it is still considered unauthorized access even if they don't have a password set up. I think it goes back to law that existed before computers where if you entered someones home without permission you can't simply argue that there wasn't a lock on the door. Edit: ProAm above reminded me of the Andrew Auernheimer case that was nearly identical to this and was resolved as I describe.

It sure sounds like there wasn't a "lock on the door". There is a significant difference between FTP and other protocols: FTP has specific support for "anonymous" sessions. There is even an entire RFC (1635, "How to Use Anonymous FTP")[1] on the topic.

From the article:

    I actually remember them having a passworded FTP site
    back in 2006. To get the password you would call tech support
    at Eaglesoft\Patterson Dental and they would just give you the
    password to the FTP site if you wanted to download anything.
    It never changed. At some point they made the FTP site anonymous. 
While there so no mention of the username involved in the anonymous access, it sounds like they switched from handing out a common password (stupid, but probably qualifying as "unauthorized access" for CFAA purposes. However, if the change where they "made the FTP site anonymous" involved the standard username "anonymous", then the server is offering access.

[1] https://tools.ietf.org/html/rfc1635

Re: FBI raids dental software researcher who discovered patient data on FTP server

#49
post #11

Another lesson not to trust people/organizations ignorant enough to keep confidential data in plain text on anonymous FTP. It seems that the 21st century responsible disclosure procedure goes like that: 0. use tor for the research itself 1. report problems anonymously 2. if they don't care - report them to law enforcement for breach of confidentiality 3. if these don't care either or don't accept anonymous tips - mak…

Step 1: Anonymously report them to law inforcement.

There is no step 2.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#50
post #7
post #5

Earlier quoted context omitted.

I believe that it is still considered unauthorized access even if they don't have a password set up. I think it goes back to law that existed before computers where if you entered someones home without permission you can't simply argue that there wasn't a lock on the door. Edit: ProAm above reminded me of the Andrew Auernheimer case that was nearly identical to this and was resolved as I describe.

Yea.. but a site on the internet is more akin to a store than someone's home. It's completely normal to walk into someone's store.

Yea. This would be a felony that a 4 year old child, your tech ignorant grandmother, and any other random Facebook user could commit by clicking on a link.
Post reply on HN