Live data from Hacker News

SparkFun Gets A Subpoena

sparkfun.com

41–50 of 55 posts

Re: SparkFun Gets A Subpoena

#41
post #39

As much as I foam at the mouth around here against many law enforcement actions, both parties did the right thing here. It's not like they showed up in the middle of the night and yanked their entire servers out of the office without a warrant and covered it up under "homeland security" or other nonsense. They did it the proper way through the courts with a judge and public documentation of their actions, and asked f…

It went this well because no copyright was violated.

Re: SparkFun Gets A Subpoena

#42
For a european perspective; a company I used to work for was in this situation many times over. We worked with law enforcement and the data protection commission to ensure zero "pollution" of unrelated information into legal requirements (like subpoenas).

If you end up being contacted by law enforcement for data, I'd recommend doing everything you can to help educate them about the information you carry. It might be tempting to volunteer as little as possible, but you also might be the first willing and knowledgeable technical person they've spoken to in some time, and starting a relationship like that on a good foot can be incredibly useful to your company; maybe even you personally.

It can mean future requirements get handled without hassle, and may never even come to you at all if they know it's information you don't or can't carry. You can also help shape policy around how such things are handled for others in future.

YMMV depending on jurisdiction, but it's worth considering contacts from law enforcement as an opportunity to build a healthy (two way) relationship.

Re: SparkFun Gets A Subpoena

#43
post #22

> 7. Complete credit card numbers used on Order(s) Can you fail PCI compliance if you're able and do this? What if you use a third party system such as Stripe where you have no access to the full credit card number?

>Can you fail PCI compliance if you're able and do this?

There are many ways to achieve PCI compliance. Not having the data is simply the easiest.

Re: SparkFun Gets A Subpoena

#44
post #31

I think the only concern here is that the plain-text csv file containing these 20 rows was sent via email to his attorney, which was probably forwarded on to the requesting detective. That file is in no way encrypted and is essentially sitting in two email servers, two desktop machines, and possible mobile devices.. all of which are vulnerable to attack from multiple vectors. The file should have, at the least, been…

What basis do you have to conclude that? The subpoena doesn't even include an email address. It is far more likely that the data were sent on a CD-R by registered mail, or printed out and transmitted by fax. Many court systems allow information to be submitted electronically now, but only by the attorney for the presenting side.

Re: SparkFun Gets A Subpoena

#45
The interesting thing in this case is that the cops may have in effect caused more credit card numbers to be skimmed (innocent people's data taken against their will, and possibly sent or stored in plaintext somewhere along the way, putting them in further jeopardy) than the original thieves did with their skimmer. But rememeber, when a government agent does it (whether cops here or soldiers or drones abroad) it's good and just. Only when a "bad guy" does something is it evil and wrong. If the government spies on you, it's legal. When you spy on them, it's illegal. If you were to plot to overthrow the US government, for example, it's treason: illegal and "evil". Whereas if the US government plots to overthrow a foreign government, it's perfectly legal and ok. Fun stuff to think about.

Re: SparkFun Gets A Subpoena

#46
post #6

As a result, about 20 customers that had purchased a specific device at sparkfun that had delivery in Georgia had their information given to the police to use in this investigation. I really want the people running the skim operation caught, but I agree with Nate (the sparkfun guy) that it is a very fine line harassing the others that are (most likely) blameless. Am I reading this correctly that then these 20 people…

In a different case, it was their BlueSmirf module http://www.sparkfun.com/tutorial/news/SparkFun-PINScam.pdf

Re: SparkFun Gets A Subpoena

#47
post #31

I think the only concern here is that the plain-text csv file containing these 20 rows was sent via email to his attorney, which was probably forwarded on to the requesting detective. That file is in no way encrypted and is essentially sitting in two email servers, two desktop machines, and possible mobile devices.. all of which are vulnerable to attack from multiple vectors. The file should have, at the least, been…

What basis do you have to conclude that? The subpoena doesn't even include an email address. It is far more likely that the data were sent on a CD-R by registered mail, or printed out and transmitted by fax. Many court systems allow information to be submitted electronically now, but only by the attorney for the presenting side.

"It was very surreal. Just a small csv file emailed to the investigator."

from Nate down in the comments section

Re: SparkFun Gets A Subpoena

#48
post #46
post #6

As a result, about 20 customers that had purchased a specific device at sparkfun that had delivery in Georgia had their information given to the police to use in this investigation. I really want the people running the skim operation caught, but I agree with Nate (the sparkfun guy) that it is a very fine line harassing the others that are (most likely) blameless. Am I reading this correctly that then these 20 people…

In a different case, it was their BlueSmirf module http://www.sparkfun.com/tutorial/news/SparkFun-PINScam.pdf

thanks for the link. that is exactly what i was looking for.

Re: SparkFun Gets A Subpoena

#49
post #39

As much as I foam at the mouth around here against many law enforcement actions, both parties did the right thing here. It's not like they showed up in the middle of the night and yanked their entire servers out of the office without a warrant and covered it up under "homeland security" or other nonsense. They did it the proper way through the courts with a judge and public documentation of their actions, and asked f…

Not quite the right thing: the subpoena is too broad.

This is very typical for law enforcement everywhere these days. Luckily SparkFun was diligent enough to negotiate it down to relevant information, but it the "gimme all your data" attitude is a fundamental problem. This also extend to seizures ("gimme all your servers", not just the ones involved). The courts should never allow this, so although this is the proper process, it is failing. There's no point in insisting law enforcement goes through the proper channels if those proper channels don't do their job properly.

Re: SparkFun Gets A Subpoena

#50
post #47

Earlier quoted context omitted.

What basis do you have to conclude that? The subpoena doesn't even include an email address. It is far more likely that the data were sent on a CD-R by registered mail, or printed out and transmitted by fax. Many court systems allow information to be submitted electronically now, but only by the attorney for the presenting side.

"It was very surreal. Just a small csv file emailed to the investigator." from Nate down in the comments section

Oh, I didn't bother to read the comments. That surprises me, to be frank.
Post reply on HN