Live data from Hacker News

FBI raids dental software researcher who discovered patient data on FTP server

dailydot.com

71–80 of 171 posts

Re: FBI raids dental software researcher who discovered patient data on FTP server

#71
post #51

Earlier quoted context omitted.

Yes. HIPPA.

But apparently they didn't go after the company, so maybe those data are not the kind of information protected by HIPPA?

It most certainly is information protected by HIPAA. It's just that there are no enforced consequences for companies breaking HIPAA (or pretty much any other law) while there are dire consequences for people accessing public data under the CFAA. I'll put it this way: if I wanted to murder someone in the US and get away with it, there are dozens of opportunities under the law as long as said murder is committed under the umbrella of a corporation. But god fucking forbid you access public data that was not secured properly by idiotic corporations and your life is ruined like this researcher's is about to be. Our judicial system is a joke; a society without justice is no different than the random savagery it purports to be above.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#72
post #41
post #23

Here's an investigative tool the CFAA & the FBI needs... if a company like Patterson Dental spins up an investigative raid with a baseless complaint, the Bureau should be able to charge them with a crime. One almost hopes the FBI investigation yields enough evidence to charge Patterson with a criminal violation of HIPAA.

Why would the FBI and prosecutors punish Patterson? The gave the FBI an opportunity for raids and prosecutions, and those look great on an annual review.

> Why would the FBI and prosecutors punish Patterson? The gave the FBI an opportunity for raids and prosecutions, and those look great on an annual review.

Why go after Patterson? Because that would give them opportunities for more raids and prosecutions, which look great on an annual review. And raids and prosecutions for acts which are probably more politically useful to politically-minded US Attorneys than whatever kind of case they could make against Shafer.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#73
post #37

This reminds me of something that happened to me in high school back in 1999. I found an Excel doc in a public network drive that contained every single student's SSN, DOB, whether they had free/reduced lunch, address, phone, etc. I was admittedly snooping around, but this was all public stuff every student and teacher had full access to. When I found it, I told one of the teachers that I trusted and she insisted tha…

I got bored and think I found out who the principal was. Was it B--- Hou----?

Edit: not trying to freak you out or anything. In the spirit of this article on publicly accessible information, I wanted to see if I could find out who it was through public means.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#74

About a month or so a go i found a open public mongo database with about 12GB of records regarding peoples retirement founds of what i assume was hundreds of thousands of people, account numbers, how much money was in the accounts when they had moved them to various founds and so on. Thought long and hard about what to do but decided to not do anything, dont feel like risking my entire life just to help someone. This…

In Finland, you can send an anonymous tip to the Communications Regulation Authority, who will then inform the service provider.

Perhaps the FCC has something similar?

Re: FBI raids dental software researcher who discovered patient data on FTP server

#75
post #64

Earlier quoted context omitted.

Western Europe and especially Scandanavia are better. That is my opinion based on the observations I have gathered. I am not sure where you are from, but I agree that it can also get worse.

Not necessarily. I've spent the last few years fighting various hacking charges in Finland and will most likely continue to do so for several years to come. The law enforcement here will consistently take anything the FBI tells them as a fact, even when the information provided by them has been consistently shown to be false or even maliciously fabricated. I spent 3 months in jail in 2014 because the FBI emailed the…

That's sounds like quite an interesting story if what you are saying is taken as true and at face value. Have you tried contacting press, or lawyers in the US who would want to take on your case?

Re: FBI raids dental software researcher who discovered patient data on FTP server

#76
post #42

Earlier quoted context omitted.

Oh, I've already learned the lesson loud and clear. If I ever discover a vulnerability to disclose, I'm releasing it anonymously on pastebin sites while logged into Tor through a VPN from a free WiFi spot. And, of course, sign it with a new PGP key you've just created, so that if you ever need to release a follow-up with proof that it's you, or come forward as the author of the disclosure, you can.

Of course, said key is a liability if it is found in your possession.

Encrypt, hexdump, render in green font on black background, set as wallpaper. Nobody will ask :)

Re: FBI raids dental software researcher who discovered patient data on FTP server

#77

Earlier quoted context omitted.

If patterson dental (and I say if since we don't really know) is behind him getting arrested, I hope all their patients find out about the details of this and they go out of business. If nothing else they should be charged with HIPAA violations.

Patterson is not a dental clinic. Like Henry Schein which was also mentioned in TFA, it is a large dental supply company. One reason that dentistry is so expensive, is that assholes like these run an oligopoly of "specialty" dental supplies. It's not as bad as military procurement, but it's kind of like that. Dentists as a profession are risk-averse, and that includes the "risk" of purchasing dental equipment and sup…

> So, the chance of them going "out of business" is pretty slim. It's entirely possible that dentists unfortunate enough to have chosen Eaglesoft will get to pay some HIPAA fines, however.

Will they? Since Eaglesoft claimed to provide encryption, and the practices relied on that claim, it seems unlikely that the practices are at fault; if they are subject to civil liability at all for inadvertent violations -- or even if they just have costs to cure the violations without money liability, which seems more likely given the history of HIPAA enforcement -- they would seem to have a claim for at least the total resulting costs in damages against Patterson.

As far as criminal violations of HIPAA goes, it doesn't seem particularly likely that any occurred, and if any did its pretty clear that the practices are (barring any evidence of knowledge that hasn't come to light) unlikely to have had the requisite knowledge or intent to be culpable, though the violations may have been willfully caused by Patterson's actions, which -- even though Patterson might not usually be directly covered by HIPAA as regards what appears to be on-premise software they sell -- might make Patterson a (and possibly the only) chargeable principal in any crime. 18 USC Sec. 2(b): "Whoever willfully causes an act to be done which if directly performed by him or another would be an offense against the United States, is punishable as a principal."

Re: FBI raids dental software researcher who discovered patient data on FTP server

#78
post #69
post #41

Earlier quoted context omitted.

Why would the FBI and prosecutors punish Patterson? The gave the FBI an opportunity for raids and prosecutions, and those look great on an annual review.

Field offices don't have unlimited budgets. If it turns out this raid was unjustified - and it certainly appears to be - its not going to reflect positively on the people who caused it.

That would make me even more nervous, because if they would find some childprn it would have been justified.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#79
Fun fact:

Many financial institutions use the last 4 of your SSN as identity verification.

If you're a business, it's the last 4 of your FEI/EIN.

I know at least in FL, this is publicily available at sunbiz.org

So with the account number printed at the bottom of your paycheck/stub and the FEI/EIN, you can often authenticate to a financial institution and obtain privileged information.

I know this not because I was on the "hacker" side, but because I was involved on the financial institution side of it and caught this as part of my engagement. The institution was issuing new logins for its internet banking site and the password would have been based on the users name, zip code, and SSN/FEI/EIN, all 3 of which are available (in FL) on that sunbiz.org site.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#80

Reading this, I had an idea for a new law that could counteract this stupid reaction to security research: Particularly for protected patient information (but maybe for other classes of sensitive data as well), it would be interesting to somehow classify having this information breached as a crime by the holder of the information (I realize this might be hard to do given the reality of security these days, so there w…

I like a bit of this idea, but too many people already have it in mind that the holder of the information is a "victim of hacking", so punishing them is "victim blaming", which we all know is always bad.
Post reply on HN