Live data from Hacker News

FBI raids dental software researcher who discovered patient data on FTP server

dailydot.com

51–60 of 171 posts

Re: FBI raids dental software researcher who discovered patient data on FTP server

#51
post #34

Do you have laws in the USA that mandate protection of health data?

Yes. HIPPA.

But apparently they didn't go after the company, so maybe those data are not the kind of information protected by HIPPA?

Re: FBI raids dental software researcher who discovered patient data on FTP server

#53

About a month or so a go i found a open public mongo database with about 12GB of records regarding peoples retirement founds of what i assume was hundreds of thousands of people, account numbers, how much money was in the accounts when they had moved them to various founds and so on. Thought long and hard about what to do but decided to not do anything, dont feel like risking my entire life just to help someone. This…

Seems like, at the very least, you could offer it to Wikileaks. Might be too small a story for them to care about though.

I'm looking at 'Have I been pwned' [0], but they seem to care about only breaches that have been publicly acknowledged. Sounds like they don't want to be in the business of breaking this kind of news themselves.

Maybe there needs to be a new Web site for this kind of thing -- located outside the US, of course. (Probably there already is one and I don't know about it.)

[0] https://haveibeenpwned.com/

Re: FBI raids dental software researcher who discovered patient data on FTP server

#54
post #37

This reminds me of something that happened to me in high school back in 1999. I found an Excel doc in a public network drive that contained every single student's SSN, DOB, whether they had free/reduced lunch, address, phone, etc. I was admittedly snooping around, but this was all public stuff every student and teacher had full access to. When I found it, I told one of the teachers that I trusted and she insisted tha…

> "Did you ever stop to think if maybe this information was public for a reason?"

If it was meant to be public, then you shouldn't have gotten in trouble for pointing out its existence. I don't understand the twisted logic there.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#55
post #37

This reminds me of something that happened to me in high school back in 1999. I found an Excel doc in a public network drive that contained every single student's SSN, DOB, whether they had free/reduced lunch, address, phone, etc. I was admittedly snooping around, but this was all public stuff every student and teacher had full access to. When I found it, I told one of the teachers that I trusted and she insisted tha…

> I was nearly expelled for "hacking". They placed me on "academic probation"

This reaction makes me very, very angry.

I would love to push it back on them: it's unclear under what laws/regulations this would fall, but if you (as the student who found it) can get in trouble for finding this info, they can most certainly get in trouble for posting it in a location it can be found in.

Further, because you were actually punished for it, it means one of two things: they were in fact in the wrong for publishing it (and thus should be punished -- whether it's a criminal offence or merely a professional reprimand); or if they can't be punished, neither can you -- which means the principal should be in trouble for a giving out a groundless punishment.

In my mind, it ceases being an "honest mistake" when they attempt to punish the person who points it out.

I realize that the real world is much more complex than this: you were a kid, your parents don't necesarily want to put you through the doubtless retaliation the administration would put you through anyway (even if not official), and the people with the authority may not see it the same way (in the same way police officers rarely charge other officers with crimes).

Re: FBI raids dental software researcher who discovered patient data on FTP server

#56
post #37

This reminds me of something that happened to me in high school back in 1999. I found an Excel doc in a public network drive that contained every single student's SSN, DOB, whether they had free/reduced lunch, address, phone, etc. I was admittedly snooping around, but this was all public stuff every student and teacher had full access to. When I found it, I told one of the teachers that I trusted and she insisted tha…

I had a similar thing happen to me. In high school our user names were first letter of first name and last four of last name. The passwords were the last four digits of our phone numbers.

I figured out that the teachers had the same schema for their accounts. They also published a directory with all the names and phone numbers of the students and teachers. So basically I tried accounts until I got a teacher who didn't change their password. Then I used their ability to place files in shared folders on the network to distribute Quake2 across the different servers. I told a friend and they told people and inevitably the school blamed me for it and kicked me out of all my electives that had computers in them. I was the first student to ever fail touch typing because I couldn't complete the class.

Standardized learning and I have never been friends. I'm glad they tought me the system doesn't work and to work/learn outside of it.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#57
In the meantime, companies like Apple and Google are deleting users' files without their consent and infecting computers with malware through ads yet I don't see Tim Cook or Larry Page being woken up in the middle of the night by a SWAT team. What a fucking joke our legal system is.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#58
post #49
post #11

Another lesson not to trust people/organizations ignorant enough to keep confidential data in plain text on anonymous FTP. It seems that the 21st century responsible disclosure procedure goes like that: 0. use tor for the research itself 1. report problems anonymously 2. if they don't care - report them to law enforcement for breach of confidentiality 3. if these don't care either or don't accept anonymous tips - mak…

Step 1: Anonymously report them to law inforcement. There is no step 2.

Nonsense. It could be as a easy as printing fliers at home and dropping them in an appropriate space, or mailing letters with the return address the same as the mailing address, or using Tails 2.x to email hippa and the police using a throwaway address. But contacting them in person? NFW

Re: FBI raids dental software researcher who discovered patient data on FTP server

#59

About a month or so a go i found a open public mongo database with about 12GB of records regarding peoples retirement founds of what i assume was hundreds of thousands of people, account numbers, how much money was in the accounts when they had moved them to various founds and so on. Thought long and hard about what to do but decided to not do anything, dont feel like risking my entire life just to help someone. This…

Bran Krebs (Krebs On Security) breaks these types of stories, though he's a journalist so would publicly disclose it. Very possible he'd contact them privately prior to a story though in the hopes they fix it before publication.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#60

It needs to be understood that if you react this way to responsible disclosure practices, your company & you personally will be subject to irresponsible disclosure practices.

Oh, I've already learned the lesson loud and clear. If I ever discover a vulnerability to disclose, I'm releasing it anonymously on pastebin sites while logged into Tor through a VPN from a free WiFi spot. And, of course, sign it with a new PGP key you've just created, so that if you ever need to release a follow-up with proof that it's you, or come forward as the author of the disclosure, you can.

Would you do this to a company that has a clearly stated responsible disclosure policy and respects your efforts? Especially if it involved commonly used desktop software that would harm many people by ignoring an existing policy?
Post reply on HN