Live data from Hacker News

Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking

motherboard.vice.com

61–67 of 67 posts

Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking

#61
post #59
post #56

Earlier quoted context omitted.

Morale hazard does play into what they can clam as damages. If reverting the defacement using there CMS system costs 500$ and results in 2,000 in lost profit NP. If it takes someone a few hours to verify that was the only change, NP. But, they can't claim time related to revoking his permissions because they should have done that in the first place. Ditto for performing a security audit ect. This is a normal user usi…

I'm only going on here because I'm worried I've been unclear about the nature of the damage here. If you're objecting to the idea that, having caused a breach, the convicted attacker is now on the hook for securing the application they broke, so that the attack they used is no longer viable, I agree. That is in no way fair. But that's not what's happening. Instead, having been breached, and only because they've been…

Someone logged into the CMS system using an active account and changed something in the CMS system. Are they required to do an audit of anything outside the CMS system, no.

I accept that you feel an external audit is required. But, is it a reasonable expense directly incurred, no.

PS: As a parting piece of evidence. Was $10,206 to $13,147 likely to include DFIR audit and all other costs? No.

Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking

#62
post #58

Earlier quoted context omitted.

On reflection, perhaps this pointless diversion yields the following maxim: You can walk into a house through an open door, but you can't walk into a computer.

You can totally walk into a computer. I've done it. Hurts.

The only machine around here that I could totally walk into is an S/390, but oddly enough I don't have the key to its bedroom.

Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking

#63
post #45

Earlier quoted context omitted.

No, investigations for very small tech companies also cost far more than $20,000. Source: I've been a party to those, too. Even if you adopt the position that we should have laws that treats victims differently depending on how big their companies are, that wouldn't have much bearing on this case.

I'll further stipulate that the costs of investigating vulnerabilities at tiny two-engineer firms far exceed the costs of investigating vulnerabilities at giant conglomerates like Tribune Media. When those vulnerabilities amount to "don't turn off credentials for fired employees", I still say they should pay for their own damn security work, and no criminal statute should say otherwise.

That's not what they're paying for. They're paying for the cost, in employee hours and outsourced contractor hours, of ensuring that all that happened was that a page got modified. Rest assured, their CMS is surely as crappy as it was before Keys laid his stubby little fingers on it.

Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking

#64
post #63

Earlier quoted context omitted.

I'll further stipulate that the costs of investigating vulnerabilities at tiny two-engineer firms far exceed the costs of investigating vulnerabilities at giant conglomerates like Tribune Media. When those vulnerabilities amount to "don't turn off credentials for fired employees", I still say they should pay for their own damn security work, and no criminal statute should say otherwise.

That's not what they're paying for. They're paying for the cost, in employee hours and outsourced contractor hours, of ensuring that all that happened was that a page got modified. Rest assured, their CMS is surely as crappy as it was before Keys laid his stubby little fingers on it.

"Stubby little fingers"? Ouch. He's probably going to get hassled enough for his appearance in FPMITAP. It makes sense that one would need to demonize him, though. That's the same maneuver we've seen with drug users, undocumented immigrants, etc.

Why denigrate a CMS when it's well established that Tribune Media weren't removing the passwords of fired employees? If you're sure they're still not doing that, it will be grimly hilarious the next time this happens.

Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking

#65
post #63

Earlier quoted context omitted.

That's not what they're paying for. They're paying for the cost, in employee hours and outsourced contractor hours, of ensuring that all that happened was that a page got modified. Rest assured, their CMS is surely as crappy as it was before Keys laid his stubby little fingers on it.

"Stubby little fingers"? Ouch. He's probably going to get hassled enough for his appearance in FPMITAP. It makes sense that one would need to demonize him, though. That's the same maneuver we've seen with drug users, undocumented immigrants, etc. Why denigrate a CMS when it's well established that Tribune Media weren't removing the passwords of fired employees? If you're sure they're still not doing that, it will be…

It's super weird of you to try to position me alongside drug prohibitionists and deporters of immigrants. I take offense. Thankfully, this thread was long enough already.

Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking

#66
post #61
post #59

Earlier quoted context omitted.

I'm only going on here because I'm worried I've been unclear about the nature of the damage here. If you're objecting to the idea that, having caused a breach, the convicted attacker is now on the hook for securing the application they broke, so that the attack they used is no longer viable, I agree. That is in no way fair. But that's not what's happening. Instead, having been breached, and only because they've been…

Someone logged into the CMS system using an active account and changed something in the CMS system. Are they required to do an audit of anything outside the CMS system, no. I accept that you feel an external audit is required. But, is it a reasonable expense directly incurred, no. PS: As a parting piece of evidence. Was $10,206 to $13,147 likely to include DFIR audit and all other costs? No.

What do you think they spent $13,000 on?

Re: Former Reuters Journalist Matthew Keys Sentenced to Two Years for Hacking

#67
post #17

If someone broke into the tribune's printing office (which perhaps didn't collect the key or change the lock when they fired someone) and that person changed the headline and a byline for an article in the paper that went out to thousands of people, I still have a hard time believing a court would put that person in prison for 2 years because of it. At some point we have to acknowledge these tough cyber laws do nothi…

I don't know about that. What's the value of an entire print run of the Los Angeles Times? It's probably quite a bit more than the damages the court imputed to Keys.

I guess the fundamental difference driving my thinking is I believe it's futile to hand out prison sentences for crimes such as these. I'm dubious that it acts as any real deterrent to "hacking", and it waste tax-payer money.

It's also becoming clear that the plaintiffs in these cases are completely washing their hands of their own responsibility for the crime. I understand that this is common in case law such as this, but if we want to actually secure this country against real cyber criminals then we need companies to step up and take responsibility for what's happening within their networks.

Post reply on HN