Live data from Hacker News

FBI raids dental software researcher who discovered patient data on FTP server

dailydot.com

81–90 of 171 posts

Re: FBI raids dental software researcher who discovered patient data on FTP server

#81
post #37

This reminds me of something that happened to me in high school back in 1999. I found an Excel doc in a public network drive that contained every single student's SSN, DOB, whether they had free/reduced lunch, address, phone, etc. I was admittedly snooping around, but this was all public stuff every student and teacher had full access to. When I found it, I told one of the teachers that I trusted and she insisted tha…

I had a similar thing happen to me. In high school our user names were first letter of first name and last four of last name. The passwords were the last four digits of our phone numbers. I figured out that the teachers had the same schema for their accounts. They also published a directory with all the names and phone numbers of the students and teachers. So basically I tried accounts until I got a teacher who didn'…

this isn't really the same, it sounds you logged ("hacked") into someone elses account by correctly guessing their password and then used their account for nefarious purposes

Re: FBI raids dental software researcher who discovered patient data on FTP server

#82
post #37

This reminds me of something that happened to me in high school back in 1999. I found an Excel doc in a public network drive that contained every single student's SSN, DOB, whether they had free/reduced lunch, address, phone, etc. I was admittedly snooping around, but this was all public stuff every student and teacher had full access to. When I found it, I told one of the teachers that I trusted and she insisted tha…

I had a similar thing happen to me. In high school our user names were first letter of first name and last four of last name. The passwords were the last four digits of our phone numbers. I figured out that the teachers had the same schema for their accounts. They also published a directory with all the names and phone numbers of the students and teachers. So basically I tried accounts until I got a teacher who didn'…

I don't think that's really similar at all. You circumvented password protection and used it to play games. I don't agree with the punishment, but you clearly broke the rules. I also don't see that as having anything whatsoever to do with standardized learning, just you wanting to play games at school.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#84
post #64

Earlier quoted context omitted.

Not necessarily. I've spent the last few years fighting various hacking charges in Finland and will most likely continue to do so for several years to come. The law enforcement here will consistently take anything the FBI tells them as a fact, even when the information provided by them has been consistently shown to be false or even maliciously fabricated. I spent 3 months in jail in 2014 because the FBI emailed the…

That's sounds like quite an interesting story if what you are saying is taken as true and at face value. Have you tried contacting press, or lawyers in the US who would want to take on your case?

Honestly, going after the FBI for lying to the Finnish police would probably be a pretty hard case to win. Especially considering how blatantly unreasonable the behaviour of the .fi authorities has been.

It's possible that I could win. But that wouldn't really achieve anything, it wouldn't make the .fi authorities stop.

The best option I have available is to keep fighting my charges in Finland, as no matter whether I win or lose it'll be significantly harder for any other country to prosecute me for those same crimes. The courts here are fairly reasonable, while they require ridiculously low standards of proof, you essentially have to kill someone to actually go to prison here. Perhaps that makes it easier to say "guilty" just to play safe, keep the LE and prosecutors happy.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#85

Reading this, I had an idea for a new law that could counteract this stupid reaction to security research: Particularly for protected patient information (but maybe for other classes of sensitive data as well), it would be interesting to somehow classify having this information breached as a crime by the holder of the information (I realize this might be hard to do given the reality of security these days, so there w…

> classify having this information breached as a crime by the holder of the information

The source of the problem in this case is that the CFAA is too loose/broad and the penalties are absurd. The solution is to fix that. Make it so that the only penalties available are proportional and innocuous actions like reporting vulnerabilities are bright-line not illegal whatsoever.

You're essentially suggesting cold war style MAD as a solution to the government foolishly supplying toxic waste to children who are then found using it to poison people they don't like, under the theory that if everyone can poison everyone then everyone will have to behave. Better to clean up the toxic waste than ensure equal access to it.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#86
post #41

Earlier quoted context omitted.

Why would the FBI and prosecutors punish Patterson? The gave the FBI an opportunity for raids and prosecutions, and those look great on an annual review.

> Why would the FBI and prosecutors punish Patterson? The gave the FBI an opportunity for raids and prosecutions, and those look great on an annual review. Why go after Patterson? Because that would give them opportunities for more raids and prosecutions, which look great on an annual review. And raids and prosecutions for acts which are probably more politically useful to politically-minded US Attorneys than whateve…

True. But given the choice between the two (and they clearly had this choice), I wonder if they consider that an individual will not be able to mount as strong a defense as a business.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#87
post #69

Earlier quoted context omitted.

Field offices don't have unlimited budgets. If it turns out this raid was unjustified - and it certainly appears to be - its not going to reflect positively on the people who caused it.

That would make me even more nervous, because if they would find some childprn it would have been justified.

You are being paranoid. There are over 13,000 FBI agents but probably 5x that number are needed to deal with organized crime, white collar crime, national security threats, public corruption, background investigations and other cases within their jurisdiction. You can bet there were/are a few agents shaking their heads in irritation over what appears to be a waste of resources.

Re: FBI raids dental software researcher who discovered patient data on FTP server

#88
post #58
post #49

Earlier quoted context omitted.

Step 1: Anonymously report them to law inforcement. There is no step 2.

Nonsense. It could be as a easy as printing fliers at home and dropping them in an appropriate space, or mailing letters with the return address the same as the mailing address, or using Tails 2.x to email hippa and the police using a throwaway address. But contacting them in person? NFW

Yes, print flyers on your home printer that you purchased with a credit card in your own name and had shipped to your home address. Handle all the pieces of paper with your bare hands, too. What could possibly go wrong?*

*https://www.eff.org/issues/printers

Re: FBI raids dental software researcher who discovered patient data on FTP server

#89
post #86

Earlier quoted context omitted.

> Why would the FBI and prosecutors punish Patterson? The gave the FBI an opportunity for raids and prosecutions, and those look great on an annual review. Why go after Patterson? Because that would give them opportunities for more raids and prosecutions, which look great on an annual review. And raids and prosecutions for acts which are probably more politically useful to politically-minded US Attorneys than whateve…

True. But given the choice between the two (and they clearly had this choice), I wonder if they consider that an individual will not be able to mount as strong a defense as a business.

> But given the choice between the two (and they clearly had this choice)

That's less clear than it might seem; the information Patterson gave them may have been sufficient basis for probable cause against Shafer, but it was probably shaded (at least by omission) in a way that it did not do so against Patterson.

Now, obviously, one would hope that the FBI would do some meaningful additional investigation before conducting a raid, but there were very few people beside the person they'd been handed as a subject who would have been able to provide information which would have flipped this to something where Patterson would be the offending party (and even there, its for something which the FBI is neither the usual first investigating agency nor an agency that is particularly expert.)

Re: FBI raids dental software researcher who discovered patient data on FTP server

#90
As a separate issue: why the "shock and awe" response to what is (even allegedly) a non-violent crime? Why the assault rifles? Why could he not have been arrested by just a couple agents walking upto the door, knocking, serving the search warrant, and then maybe having the techs step in to conduct the search and seizure?

Why does US Law Enforcement so dramatically escalate every contact with a citizen? Everytime they do this, they risk accidental injury to the people, kids, pets.

What in this particular situation necessitated a SWAT-level treatment?

Maybe the law should be fixed such that warrants have to specifically include firearm authorizations.

Post reply on HN