Live data from Hacker News

FBI raids dental software researcher who discovered patient data on FTP server

dailydot.com

61–70 of 171 posts

Re: FBI raids dental software researcher who discovered patient data on FTP server

#61

About a month or so a go i found a open public mongo database with about 12GB of records regarding peoples retirement founds of what i assume was hundreds of thousands of people, account numbers, how much money was in the accounts when they had moved them to various founds and so on. Thought long and hard about what to do but decided to not do anything, dont feel like risking my entire life just to help someone. This…

Annonomous email through a few proxies from a one time email address should be sufficient.

"I accidentally discovered this when I miss typed an IP."

Re: FBI raids dental software researcher who discovered patient data on FTP server

#62
post #37

This reminds me of something that happened to me in high school back in 1999. I found an Excel doc in a public network drive that contained every single student's SSN, DOB, whether they had free/reduced lunch, address, phone, etc. I was admittedly snooping around, but this was all public stuff every student and teacher had full access to. When I found it, I told one of the teachers that I trusted and she insisted tha…

> I was told by the county IT administrator "Did you ever stop to think if maybe this information was public for a reason?"

Absolutely jaw-dropping.

People's reactions to this kind of thing just blow my mind. If you are about to walk away from your car, having parked it in a high-crime area, and a passerby points out to you that you haven't locked it, do you call the police and have them arrested for looking into your car? If they were going to steal your car, would they have told you about it???

My wife ran into this back in 2001 or so. She had visited some Web site and noticed that the URLs followed a familiar pattern -- I think related to the Microsoft Access database. She wondered if some internal files were accessible via paths analogous to those she'd seen on the intranet where she worked. Sure enough, they were. She told the company about it, and of course they yelled at her.

Unfathomable.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#63

It sounds like Patterson Dental deserves as much blame as the FBI, if not more, because it sounds like they were the ones pressing charges and motivating prosecution in the first place. Also, why aren't they being charged with what is almost certainly a HIPAA violation?

> Also, why aren't they being charged with what is almost certainly a HIPAA violation?

Foremost among the many reasons, because investigation of HIPAA Privacy and Security violations is almost entirely (if not entirely) complaint-based rather than proactive, and probably no one filed a complaint to the HHS Office of Civil Rights.

Which I think should be the immediate and first act on discovering something like this with PHI, if for no other reason that doing so makes clearly applicable the whistleblower protections of 45 CFR 160.316.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#64

Earlier quoted context omitted.

Other places aren't much better either. In my country, you don't get to reach the courts. If some official doesn't like you, and you aren't a descendant of a well-known lineage and don't have connections, you will accidentally fall down a couple of flights of stairs, repeatedly. And should you by some miraculous series of events manage to get your case heard in a court (have $$$ to burn), they'll just appeal the verd…

Western Europe and especially Scandanavia are better. That is my opinion based on the observations I have gathered. I am not sure where you are from, but I agree that it can also get worse.

Not necessarily. I've spent the last few years fighting various hacking charges in Finland and will most likely continue to do so for several years to come.

The law enforcement here will consistently take anything the FBI tells them as a fact, even when the information provided by them has been consistently shown to be false or even maliciously fabricated.

I spent 3 months in jail in 2014 because the FBI emailed the Finnish NBI and alleged that I had perpetrated various attacks against large US tech companies, they provided some information vaguely connecting me to the crimes and claimed to have further evidence they'd deliver shortly. They requested that the Finnish police arrest me and seize my equipment, they did so without question.

Based on that single contact from the FBI the Finnish NBI held me in jail for 3 months and banned me from using the phone or in any manner communicating with anyone outside the jail. After the 3 months had passed the FBI had still failed to deliver any evidence, and the Finnish police had failed to discover any. In fact, they had unquestionably discovered heaps of evidence against the aforementioned allegations since the very day they arrested me. Just a few days before Christmas they were forced to very reluctantly release me.

Now it's 2016 and I just recently got a letter stating that most of those charges have been dropped as the FBI has failed to deliver the promised evidence. I've also received letters informing me of various covert surveillance techniques utilized against me after my release. These are supposed to require an even higher standard of proof than keeping someone in investigative custody, but obviously they're hard to contest when you aren't told about them.

Incompetent fucks desperately hoping to score big wins for their careers or with personal vendettas are hardly an US only problem, but at least in the US I could've fought the FBI in court. That's hardly an option here. The only thing that's better here are the sentencing policies.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#65
Reading this, I had an idea for a new law that could counteract this stupid reaction to security research:

Particularly for protected patient information (but maybe for other classes of sensitive data as well), it would be interesting to somehow classify having this information breached as a crime by the holder of the information (I realize this might be hard to do given the reality of security these days, so there would need to be some nuance of course). The crux of my idea would be to automatically count any access that results in prosecution as a breach of said data, thus meaning that prosecuting a security researcher would automatically put the information holder under separate prosecution. I wonder if something like this could be feasible.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#66
Unless there is more to the story, he won't be prosecuted for accessing an anonymous FTP server. However, they will scour the computers/drives they took (for months or possibly even years), looking for evidence of this or any other technically illegal misdeed. In the unlikely event they find nothing that they can take issue with (this being a security researcher's computer equipment, they'll find all kinds of hacking tools and possibly evidence of other research that could be construed as hacking attempts), in a year or so, he might get his stuff back. If they find anything, he'll face charges for that.

That's how law enforcement in the US works. A crack in the door, in the form of a ridiculous accusation, is all it takes for one's life to be destroyed.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#67
post #14

The FBI is going to have a hell of a time arguing that accessing a public FTP server with no password protection is a crime.

Isn't this exactly what Andrew Auernheimer was charged and convicted with?

Not at all, the key in weevs case was intent.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#68

About a month or so a go i found a open public mongo database with about 12GB of records regarding peoples retirement founds of what i assume was hundreds of thousands of people, account numbers, how much money was in the accounts when they had moved them to various founds and so on. Thought long and hard about what to do but decided to not do anything, dont feel like risking my entire life just to help someone. This…

You could search PGP keyservers for email addresses/domains of the local media where that retirement fund is located and take it from there, using your own judgment about the reporter and outlet, and how much you'd want to mask that communication.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#69
post #41
post #23

Here's an investigative tool the CFAA & the FBI needs... if a company like Patterson Dental spins up an investigative raid with a baseless complaint, the Bureau should be able to charge them with a crime. One almost hopes the FBI investigation yields enough evidence to charge Patterson with a criminal violation of HIPAA.

Why would the FBI and prosecutors punish Patterson? The gave the FBI an opportunity for raids and prosecutions, and those look great on an annual review.

Field offices don't have unlimited budgets. If it turns out this raid was unjustified - and it certainly appears to be - its not going to reflect positively on the people who caused it.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#70

The FBI is going to have a hell of a time arguing that accessing a public FTP server with no password protection is a crime.

Unless they put a banner at the top after you login that says "This server is private blah blah blah"
Post reply on HN