Live data from Hacker News

When your classmates threaten you with felony charges

miles.land

61–70 of 350 posts

Re: When your classmates threaten you with felony charges

#61

Earlier quoted context omitted.

Writing a demand letter that leans in favor of your client's interests is not only okay, it is the standard course of action for a civil dispute. https://www.law.cornell.edu/wex/demand_letter

Perhaps they shouldn't. If we lived in a world where lawyers were more cautions about what they attached there name to out of concern for losing their license we would probably be better off. Less bullying by corporations with lots of money etc. No problems with demand letters for legitimate issues that are well supported by evidence though.

>If we lived in a world where lawyers were more cautions about what they attached there name to out of concern for losing their license we would probably be better off.

That's already the case. Lawyers can be disbarred for filing frivolous lawsuits.

Re: When your classmates threaten you with felony charges

#63

I realize it is quick to be against Fizz, but I thought ethical hacking required prior permission. Am I to understand you can attempt to hack any computer to gain unauthorized access without prior approval? That doesn't seem legal at all. Whether or not there was a vulnerability, was the action taken actually legal under current law? I don't see anything indicating for or against in the article. Just posturing that "…

(a) There's no such thing as "ethical hacking" (that's an Orwellian term designed to imply that testing conducted in ways unfavorable to vendors is "unethical").

(b) You don't require permission to test software running on hardware you control (absent some contract that says otherwise).

(c) But you're right, in this case, the researchers presumably did need permission to conduct this kind of testing lawfully.

Re: When your classmates threaten you with felony charges

#65

Earlier quoted context omitted.

I'm not even suggesting it has to happen at a legal level, but perhaps at a professional level, I would think any lawyer writing baseless threatening letters to people should be subject to losing there license.

Writing a demand letter that leans in favor of your client's interests is not only okay, it is the standard course of action for a civil dispute. https://www.law.cornell.edu/wex/demand_letter

[flagged]

Re: When your classmates threaten you with felony charges

#66

I don't understand why in both contracts and legal communication (particularly threatening one), there is little to no consequence for the writing party to get things right. I've seen examples of an employee contract, with things like "if any piece of this contract is invalid it doesn't invalidate the rest of the contract". The employer is basically trying to enforce their rules (reasonable), but they have no negativ…

Even if you get it right, the court can change what is right at any time by ruling differently than last time.

Re: When your classmates threaten you with felony charges

#68
Commentary on the journalism:

Fantastic for calling Fizz out. "Fizz did not protect their users’ data. What happened next?" This isn't a "someone hacked them". It's that Fizz failed to do what they promised.

I'm still curious to hear if the vulnerability has been tested to see if it's been resolved.

Re: When your classmates threaten you with felony charges

#69
post #57

I'm not a lawyer, but I am professionally interested in this weird branch of the law, and it seems like EFF's staff attorney went a bit out on a limb here: * Fizz appears to be a client/server application (presumably a web app?) * The testing the researchers did was of software running on Fizz's servers * After identifying a vulnerability, the researchers created administrator accounts using the database activity the…

[flagged]

Re: When your classmates threaten you with felony charges

#70
post #4

> And at the end of their threat they had a demand: don’t ever talk about your findings publicly. Essentially, if you agree to silence, we won’t pursue legal action. Legally, can this cover talking to e.g. state prosecutors and the police as well? Because claiming to be "100% secure", knowing you are not secure, and your users have no protection against spying from you or any minimally competent hacker, is fraud at m…

They could be legitimately ignorant of their security vulnerabilities. That might go to negligence more than fraud.

They could not have been ignorant of storing non-anonymous, plain-text messages. Even if we don't count that as insecure, they can only appeal to ignorance/negligence up until the point the security researchers informed them of their vulnerabilities.

After that, that they continued their "100% secure" marketing on one side, while threatening researchers into silence on the other, is plainly malicious.

Post reply on HN