This reminds me of something that happened to me in high school back in 1999. I found an Excel doc in a public network drive that contained every single student's SSN, DOB, whether they had free/reduced lunch, address, phone, etc. I was admittedly snooping around, but this was all public stuff every student and teacher had full access to. When I found it, I told one of the teachers that I trusted and she insisted tha…
I had a similar thing happen to me. In high school our user names were first letter of first name and last four of last name. The passwords were the last four digits of our phone numbers. I figured out that the teachers had the same schema for their accounts. They also published a directory with all the names and phone numbers of the students and teachers. So basically I tried accounts until I got a teacher who didn'…
FBI raids dental software researcher who discovered patient data on FTP server
81–90 of 171 posts
Re: FBI raids dental software researcher who discovered patient data on FTP server
#82This reminds me of something that happened to me in high school back in 1999. I found an Excel doc in a public network drive that contained every single student's SSN, DOB, whether they had free/reduced lunch, address, phone, etc. I was admittedly snooping around, but this was all public stuff every student and teacher had full access to. When I found it, I told one of the teachers that I trusted and she insisted tha…
I had a similar thing happen to me. In high school our user names were first letter of first name and last four of last name. The passwords were the last four digits of our phone numbers. I figured out that the teachers had the same schema for their accounts. They also published a directory with all the names and phone numbers of the students and teachers. So basically I tried accounts until I got a teacher who didn'…
Re: FBI raids dental software researcher who discovered patient data on FTP server
#83Re: FBI raids dental software researcher who discovered patient data on FTP server
#84Earlier quoted context omitted.
Not necessarily. I've spent the last few years fighting various hacking charges in Finland and will most likely continue to do so for several years to come. The law enforcement here will consistently take anything the FBI tells them as a fact, even when the information provided by them has been consistently shown to be false or even maliciously fabricated. I spent 3 months in jail in 2014 because the FBI emailed the…
That's sounds like quite an interesting story if what you are saying is taken as true and at face value. Have you tried contacting press, or lawyers in the US who would want to take on your case?
It's possible that I could win. But that wouldn't really achieve anything, it wouldn't make the .fi authorities stop.
The best option I have available is to keep fighting my charges in Finland, as no matter whether I win or lose it'll be significantly harder for any other country to prosecute me for those same crimes. The courts here are fairly reasonable, while they require ridiculously low standards of proof, you essentially have to kill someone to actually go to prison here. Perhaps that makes it easier to say "guilty" just to play safe, keep the LE and prosecutors happy.
Re: FBI raids dental software researcher who discovered patient data on FTP server
#85Reading this, I had an idea for a new law that could counteract this stupid reaction to security research: Particularly for protected patient information (but maybe for other classes of sensitive data as well), it would be interesting to somehow classify having this information breached as a crime by the holder of the information (I realize this might be hard to do given the reality of security these days, so there w…
The source of the problem in this case is that the CFAA is too loose/broad and the penalties are absurd. The solution is to fix that. Make it so that the only penalties available are proportional and innocuous actions like reporting vulnerabilities are bright-line not illegal whatsoever.
You're essentially suggesting cold war style MAD as a solution to the government foolishly supplying toxic waste to children who are then found using it to poison people they don't like, under the theory that if everyone can poison everyone then everyone will have to behave. Better to clean up the toxic waste than ensure equal access to it.
Re: FBI raids dental software researcher who discovered patient data on FTP server
#86Earlier quoted context omitted.
Why would the FBI and prosecutors punish Patterson? The gave the FBI an opportunity for raids and prosecutions, and those look great on an annual review.
> Why would the FBI and prosecutors punish Patterson? The gave the FBI an opportunity for raids and prosecutions, and those look great on an annual review. Why go after Patterson? Because that would give them opportunities for more raids and prosecutions, which look great on an annual review. And raids and prosecutions for acts which are probably more politically useful to politically-minded US Attorneys than whateve…
Re: FBI raids dental software researcher who discovered patient data on FTP server
#87Earlier quoted context omitted.
Field offices don't have unlimited budgets. If it turns out this raid was unjustified - and it certainly appears to be - its not going to reflect positively on the people who caused it.
That would make me even more nervous, because if they would find some childprn it would have been justified.
Re: FBI raids dental software researcher who discovered patient data on FTP server
#88Earlier quoted context omitted.
Step 1: Anonymously report them to law inforcement. There is no step 2.
Nonsense. It could be as a easy as printing fliers at home and dropping them in an appropriate space, or mailing letters with the return address the same as the mailing address, or using Tails 2.x to email hippa and the police using a throwaway address. But contacting them in person? NFW
Re: FBI raids dental software researcher who discovered patient data on FTP server
#89Earlier quoted context omitted.
> Why would the FBI and prosecutors punish Patterson? The gave the FBI an opportunity for raids and prosecutions, and those look great on an annual review. Why go after Patterson? Because that would give them opportunities for more raids and prosecutions, which look great on an annual review. And raids and prosecutions for acts which are probably more politically useful to politically-minded US Attorneys than whateve…
True. But given the choice between the two (and they clearly had this choice), I wonder if they consider that an individual will not be able to mount as strong a defense as a business.
That's less clear than it might seem; the information Patterson gave them may have been sufficient basis for probable cause against Shafer, but it was probably shaded (at least by omission) in a way that it did not do so against Patterson.
Now, obviously, one would hope that the FBI would do some meaningful additional investigation before conducting a raid, but there were very few people beside the person they'd been handed as a subject who would have been able to provide information which would have flipped this to something where Patterson would be the offending party (and even there, its for something which the FBI is neither the usual first investigating agency nor an agency that is particularly expert.)
Re: FBI raids dental software researcher who discovered patient data on FTP server
#90Why does US Law Enforcement so dramatically escalate every contact with a citizen? Everytime they do this, they risk accidental injury to the people, kids, pets.
What in this particular situation necessitated a SWAT-level treatment?
Maybe the law should be fixed such that warrants have to specifically include firearm authorizations.