Live data from Hacker News

When your classmates threaten you with felony charges

miles.land

91–100 of 350 posts

Re: When your classmates threaten you with felony charges

#91
post #63

I realize it is quick to be against Fizz, but I thought ethical hacking required prior permission. Am I to understand you can attempt to hack any computer to gain unauthorized access without prior approval? That doesn't seem legal at all. Whether or not there was a vulnerability, was the action taken actually legal under current law? I don't see anything indicating for or against in the article. Just posturing that "…

(a) There's no such thing as "ethical hacking" (that's an Orwellian term designed to imply that testing conducted in ways unfavorable to vendors is "unethical"). (b) You don't require permission to test software running on hardware you control (absent some contract that says otherwise). (c) But you're right, in this case, the researchers presumably did need permission to conduct this kind of testing lawfully.

> (a) There's no such thing as "ethical hacking"

Weird stance. Sure, you may disagree on the limitations of scope of various ethical hacking programs (bug bounties and such) but they consistently highlight some very serious flaws in all kinds of hardware and software.

Going out of scope (hacking a company with no program in place) is always a gamble and you’re betting on the leniency of the target. Probably not worth it unless you like to live dangerously.

Re: When your classmates threaten you with felony charges

#92

Maybe its just my Oppositional Defiant Disorder talking, but I would have nuked their db after that bs threat.

> Maybe its just my Oppositional Defiant Disorder talking

Is that the clinical term for Internet Tough Guy?

I imagine deleting the DB would almost certainly lead to actual CFAA consequences. Which kinda suck, as I recall.

Re: When your classmates threaten you with felony charges

#93

I don't understand why in both contracts and legal communication (particularly threatening one), there is little to no consequence for the writing party to get things right. I've seen examples of an employee contract, with things like "if any piece of this contract is invalid it doesn't invalidate the rest of the contract". The employer is basically trying to enforce their rules (reasonable), but they have no negativ…

> "if any piece of this contract is invalid it doesn't invalidate the rest of the contract".

Severability (the ability to "sever" part of a contract, leaving the remainder intact so long as it's not fundamentally a change to the contract's terms) comes from constitutional law and was intended to prevent wholesale overturning of previous precedent with each new case. It protects both parties from squirreling out of an entire legal obligation on a technicality, or writing poison pills into a contract you know won't stand up to legal scrutiny.

If part of the contract is invalidated, they can't leverage it. If that part being invalidated changes the contract fundamentally, the entire contract is voided. What more do you want?

It seems like you're arguing for some sort of punitive response to authoring a bad contract? That seems like a pretty awful idea re: chilling effect on all legal/business relationship formation, and wouldn't that likely impact the weaker parties worse as they have less access to high-powered legal authors? That means that even negotiating wording changes to a contract becomes a liability nightmare for the negotiators, doesn't that make the potential liability burden even more lopsided against small actors sitting across the table from entire legal teams?

I guess I'm having trouble seeing how the world you're imagining wouldn't end up introducing bigger risk for weaker parties than the world we're already in.

Re: When your classmates threaten you with felony charges

#94
post #57

I'm not a lawyer, but I am professionally interested in this weird branch of the law, and it seems like EFF's staff attorney went a bit out on a limb here: * Fizz appears to be a client/server application (presumably a web app?) * The testing the researchers did was of software running on Fizz's servers * After identifying a vulnerability, the researchers created administrator accounts using the database activity the…

I presume that the "limb" the EFF attorney went on is basically what would've been disputed in a court of law. It's easily argued that if an app is so badly configured that just _following the Firebase protocol_ can give you write access to the database, you haven't actually circumvented any security measures, because _there weren't any to circumvent_.

It reminds me of the case where AT&T had their iPad data subscriber data just sitting there on an unlisted webpage. Don't remember which way it went, but I think the guy went out of his way there to get all the data he could get, which isn't the case here.

Re: When your classmates threaten you with felony charges

#95
post #57

I'm not a lawyer, but I am professionally interested in this weird branch of the law, and it seems like EFF's staff attorney went a bit out on a limb here: * Fizz appears to be a client/server application (presumably a web app?) * The testing the researchers did was of software running on Fizz's servers * After identifying a vulnerability, the researchers created administrator accounts using the database activity the…

> After identifying a vulnerability, the researchers created administrator accounts using the database activity they obtained

Ignoring the legalities of it all, this step crosses a line morally imo.

Re: When your classmates threaten you with felony charges

#96

Interestingly, Ashton Cofer and Teddy Solomon of Fizz tried some PR damage control when their wrongdoing came to light https://stanforddaily.com/2022/11/01/opinion-fizz-previously... . Their response was weak and it seems like they've refused to comment on the debacle since then.

Per the Stanford Daily article linked in the OP [0], they have also removed the statement addressing this incident and supposed improvements from their website.

>Although Fizz released a statement entitled “Security Improvements Regarding Fizz” on Dec. 7, 2021, the page is no longer navigable from Fizz’s website or Google searches as of the time of this article’s publication.

And, it seems likely the app still stores personally identifiable information about its "anonymous" users' activity.

> Moreover, we still don’t know whether our data is internally anonymized. The founders told The Daily last year that users are identifiable to developers. Fizz’s privacy policy implies that this is still the case

I suppose the 'developers' may include the same founders who have refused to comment on this, removed their company's communications about it, and originally leveraged legal threats over being caught marketing a completely leaky bucket as a "100% secure social media app." Can't say I'm in a hurry to put my information on Fizz.

Re: When your classmates threaten you with felony charges

#97

I feel like this article reflects an overall positive change in the way disclosure is handled today. Back in the 90s this was the sort of thing every company did. Companies would threaten lawsuits, or disclosure in the first place seemed legally dubious. Discussions in forums / BBS's would be around if it was safe to disclose at all. Suggestions of anonymous email accounts and that sort of thing. Sure you still get s…

The problem is that it is still entirely illegal to do this kind of hacking without any permission.

The fact that a lot of companies have embraced bug bounties and encourage this kind of stuff against them unfortunately teaches "kids" that this kind of thing is perfectly legal/moral/ethical/etc.

As this story shows though you're really rolling the dice, even though it worked out in this case.

> Discussions in forums / BBS's would be around if it was safe to disclose at all. Suggestions of anonymous email accounts and that sort of thing.

This is probably still a better idea if you don't have the cooperation of the target of the hack via some stated bug bounty program. But that doesn't help the security researcher "make a name" for themselves.

And you're basically admitting to the fact that you trespassed, even if all you did was the equivalent of walking through an unlocked door and verifying that you could look inside their refrigerator.

The fact that it may play out in the court of public opinion that you were helping to expose the lies of a corporation doesn't change the fact than in the actual courts you are guilty of a crime.

Re: When your classmates threaten you with felony charges

#98

Earlier quoted context omitted.

One interesting thing about the statute of limitations is “the discovery rule.” For example, say the statute of limitations for 18 USC 1030 is two years. If a person hypothetically stole a scooter by hacking, two years later, they would be in the clear, right? No. The discovery rule says that if a damaged party, for good reason, does not immediately discover their loss, the statutes of limitations is paused until the…

Does this apply to criminal or just civil?

Generally it applies to both. But some crimes (eg murder) might not have a statute of limitations.

https://www.law.cornell.edu/wex/statute_of_limitations

Also there are subtle questions around what discovery means here. Usually it is some sort of "could be discovered with reasonable effort". If I had proof of your wrongdoing in a letter sent to me, I am unlikely to get away with saying, "Oh, I didn't read the letter when I got it." If that proof was buried in a computer file with a million pages, I probably can reasonably say, "That was a needle in a haystack, and I didn't even know what to look for." For situations between those extremes, there will be case law that likely varies by state.

This is where a lawyer gets to earn their pay.

Re: When your classmates threaten you with felony charges

#99
post #57

I'm not a lawyer, but I am professionally interested in this weird branch of the law, and it seems like EFF's staff attorney went a bit out on a limb here: * Fizz appears to be a client/server application (presumably a web app?) * The testing the researchers did was of software running on Fizz's servers * After identifying a vulnerability, the researchers created administrator accounts using the database activity the…

I don't think you have the pattern of facts correct (unless you have access to more information than what is in linked the Stanford Daily article).

> At the time, Fizz used Google’s Firestore database product to store data including user information and posts. Firestore can be configured to use a set of security rules in order to prevent users from accessing data they should not have access to. However, Fizz did not have the necessary security rules set up, making it possible for anyone to query the database directly and access a significant amount of sensitive user data.

> We found that phone numbers and/or email addresses for all users were fully accessible, and that posts and upvotes were directly linkable to this identifiable information. It was possible to identify the author of any post on the platform.

So AFAICT there is no indication they created any admin accounts to access the data. This is yet another example of an essentially publicly accessible database that holds what was supposed to be private information. This seems like a far less clear application of the CFAA than the pattern of facts you describe.

Re: When your classmates threaten you with felony charges

#100

Earlier quoted context omitted.

No, because it would be legitimate? Just like it is legitimate to use force to stop someone from hurting you...

"It would be legitimate" is just an assertion. The entire debate is about what is legitimate and what is not. You're supposed to be saying why things are or are not legitimate, either legally or morally.

Sure, but if I shoot someone in self defense, there will be an investigation and I have to show why I thought it was legitimate. If a lawyer writes a baseless threatening letter, at the very least I should be able to have the bar association investigate.
Post reply on HN