11 ms·
FBI raids dental software researcher who discovered patient data on FTP server
- tehwebguy 10y agoThe FBI used to be cool when it was all Agent Mulder. Now it's all Cigarette Smoking Man and lame.
- vox_mollis 10y agoThe FBI has always been our enemy, from John Edgar Hoover onward.
- AdmiralAsshat 10y agoThe FBI is going to have a hell of a time arguing that accessing a public FTP server with no password protection is a crime.
- LionessLover 10y agoThe outcome of a trial is secondary. Have you ever been sued by the government? How much money, time, effort and nerves do you think you will lose, no matter the outcome? The act of being sued is plenty of punishment. If they really want to destroy you they can keep going through the courts even after losing - they could not care less if they win or lose.
- slantyyz 10y ago> The act of being sued is plenty of punishment. This is so true and so many people don't realize it. It's easy to be idealistic about these things until it actually happens to you. Being "in the right" doesn't mean you'll win ("right" according to your morals/ethics and "right" legally are often two completely different things) and it doesn't mean that the costs of fighting - financial, personal, etc. won't ruin you, especially when the plaintiff is stubborn, vindictive and has deeper pockets than you do. More often than not, you'll end up settling civil cases, and the tangible and intangible costs that you accrued while fighting your case are usually victory enough for the plaintiff.
- cmdrfred 10y agoI believe that it is still considered unauthorized access even if they don't have a password set up. I think it goes back to law that existed before computers where if you entered someones home without permission you can't simply argue that there wasn't a lock on the door. Edit: ProAm above reminded me of the Andrew Auernheimer case that was nearly identical to this and was resolved as I describe.
- nfriedly 10y agoYea.. but a site on the internet is more akin to a store than someone's home. It's completely normal to walk into someone's store.
- cmdrfred 10y agoI'm not justifying the law I consider it ridiculous but I'm pretty sure that is how it is written.
- maxerickson 10y agoAn ftp server is clearly more akin to a spooky abandoned building.
- agroot12 10y agoA more accurate analogy for an FTP server is a machine that sends you letters on demand. It's like Shafer wrote a letter to their office asking for their list of patients, and lo and behold, they've sent him back an envelope containing that list.
- ohyes 10y agoI think that's a gopher server
- logfromblammo 10y agoOr a private lending library that is technically open to the public, but no one ever goes there, because all the books are about dental drills.
- ProAm 10y agoIsn't this exactly what Andrew Auernheimer was charged and convicted with?
- chinathrow 10y agoYes - and that's also pointed out in the arcticle: “It’s weev all over again.”
- Buttons840 10y agoExcept this guy didn't leak a bunch of emails like weev did? Right? If he does go down, that would be terrible for him and his family, but he would be a better poster child for government overreach than weev is. "He is an upstanding family man, with 4 children. He accessed a publicly available server on the Internet, the kind of server you could access at any time by clicking a hyperlink on Facebook, and now he is a felon and rotting in jail." Or something like that.
- ryanl0l 10y agoNot at all, the key in weevs case was intent.
- wallace_f 10y agoI am pleased they might move forward with this prosecution. Keep in mind the legal costs incurred to do this, in addition to the already employed 12-15 FBI agents who were probably paid overtime to heroically rescue that poor family from this monster was already well worth the cost. Spending more money and resources here is obviously the right thing to do. Really, the resources expended to handcuff this man in his boxers in front of his 9-year-old daughter were a very well allocated by one of our most important government agencies, the FBI. I'm also very much glad to see the incredible foresight and knowledge that the FBI is displaying here. What better way to show us why we should not responsibly disclose data vulnerabilities than to arrest and raid someone's home for doing so? Stories like this really influence me to put my faith in the capabilities of law enforcement. What that means for our individual rights and freedoms, and for the future of the US economy is sure to be nothing but excellent! I would never think about moving away from such a country!
- goodplay 10y agoOther places aren't much better either. In my country, you don't get to reach the courts. If some official doesn't like you, and you aren't a descendant of a well-known lineage and don't have connections, you will accidentally fall down a couple of flights of stairs, repeatedly. And should you by some miraculous series of events manage to get your case heard in a court (have $$$ to burn), they'll just appeal the verdict (and win). There is no escaping this shitfest.
- wallace_f 10y agoWestern Europe and especially Scandanavia are better. That is my opinion based on the observations I have gathered. I am not sure where you are from, but I agree that it can also get worse.
- ryanl0l 10y agoNot necessarily. I've spent the last few years fighting various hacking charges in Finland and will most likely continue to do so for several years to come. The law enforcement here will consistently take anything the FBI tells them as a fact, even when the information provided by them has been consistently shown to be false or even maliciously fabricated. I spent 3 months in jail in 2014 because the FBI emailed the Finnish NBI and alleged that I had perpetrated various attacks against large US tech companies, they provided some information vaguely connecting me to the crimes and claimed to have further evidence they'd deliver shortly. They requested that the Finnish police arrest me and seize my equipment, they did so without question. Based on that single contact from the FBI the Finnish NBI held me in jail for 3 months and banned me from using the phone or in any manner communicating with anyone outside the jail. After the 3 months had passed the FBI had still failed to deliver any evidence, and the Finnish police had failed to discover any. In fact, they had unquestionably discovered heaps of evidence against the aforementioned allegations since the very day they arrested me. Just a few days before Christmas they were forced to very reluctantly release me. Now it's 2016 and I just recently got a letter stating that most of those charges have been dropped as the FBI has failed to deliver the promised evidence. I've also received letters informing me of various covert surveillance techniques utilized against me after my release. These are supposed to require an even higher standard of proof than keeping someone in investigative custody, but obviously they're hard to contest when you aren't told about them. Incompetent fucks desperately hoping to score big wins for their careers or with personal vendettas are hardly an US only problem, but at least in the US I could've fought the FBI in court. That's hardly an option here. The only thing that's better here are the sentencing policies.
- pxlpshr 10y agoThese are the types of cases SV money should fund and defend.
- mcherm 10y ago> The FBI is going to have a hell of a time arguing that accessing a public FTP server with no password protection is a crime. Why? Andrew "Weev" Auernheimer was prosecuted AND CONVICTED for accessing a public HTTP server with no password protection. They apparently didn't have any trouble pursuing that with a straight face. The conviction was overturned because they had prosecuted him in the wrong state.
- swalsh 10y agoUnless they put a banner at the top after you login that says "This server is private blah blah blah"
- Esau 10y agoIf it is, then it should be a crime to access unprotected wifi.
- fencepost 10y agoThe problem with this is summed up with the phrase "you can beat the rap, but you can't beat the ride." Sometimes that's just the time, expense, job and reputation loss, etc. of the arrest, but sometimes (e.g. Freddie Gray) the ride is a'rough ride' and you can't beat that either.
- fiatmoney 10y agoIt needs to be understood that if you react this way to responsible disclosure practices, your company & you personally will be subject to irresponsible disclosure practices.
- CydeWeys 10y agoOh, I've already learned the lesson loud and clear. If I ever discover a vulnerability to disclose, I'm releasing it anonymously on pastebin sites while logged into Tor through a VPN from a free WiFi spot. And, of course, sign it with a new PGP key you've just created, so that if you ever need to release a follow-up with proof that it's you, or come forward as the author of the disclosure, you can.
- miander 10y agoOf course, said key is a liability if it is found in your possession.
- qb45 10y agoEncrypt, hexdump, render in green font on black background, set as wallpaper. Nobody will ask :)
- kodablah 10y agoWould you do this to a company that has a clearly stated responsible disclosure policy and respects your efforts? Especially if it involved commonly used desktop software that would harm many people by ignoring an existing policy?
- CydeWeys 10y agoNo, I wouldn't do it to a company that has a history of handling disclosures properly. But for every one company that does that, there's a dozen that are clueless.
- TACIXAT 10y ago
- 2close4comfort 10y agoThe FBI putting the Cyber in Cyber. I know we all feel safer with them on the watch
- qb45 10y agoAnother lesson not to trust people/organizations ignorant enough to keep confidential data in plain text on anonymous FTP. It seems that the 21st century responsible disclosure procedure goes like that: 0. use tor for the research itself 1. report problems anonymously 2. if they don't care - report them to law enforcement for breach of confidentiality 3. if these don't care either or don't accept anonymous tips - make noise in the media Of course, this is for dealing with idiots who keep their data on public FTP. If the attack takes some clever hacking, go check if they don't offer bug bounties. Funny times we are living in.
- Retric 10y agoStep 1: Anonymously report them to law inforcement. There is no step 2.
- hackney 10y agoNonsense. It could be as a easy as printing fliers at home and dropping them in an appropriate space, or mailing letters with the return address the same as the mailing address, or using Tails 2.x to email hippa and the police using a throwaway address. But contacting them in person? NFW
- tombrossman 10y agoYes, print flyers on your home printer that you purchased with a credit card in your own name and had shipped to your home address. Handle all the pieces of paper with your bare hands, too. What could possibly go wrong?* *https://www.eff.org/issues/printers https://www.eff.org/issues/printers
- hackney 10y agoGee, let's find out. First off it applies to "some color laser printers". Don't have one. Second, printer was bought in person with cash and was a gift. Third, gee that's super hard, wear latex gloves. I sure hope the police are more intelligent than you are. No offense.
- eric_h 10y agoI could not get this site to fully load even after (or maybe because) my adblocker blocked 68 requests. However, loads great in lynx!
- deleted 10y ago[deleted]
- eric_h 10y agoI wasn't joking, the site actually loads much better, faster and more readably in lynx than it did in my regular browser (safari with ABP)
- wyldfire 10y ago> Defense attorney Tor Ekeland, who represented Auernheimer in the federal court case in New Jersey, has offered to help Shafer ... Based on his website it appears that "Tor" is actually his given name. What an odd coincidence.
- mjgoins 10y agoYeah common Scandinavian name, same as Thor, essentially.
- openasocket 10y agoIt sounds like Patterson Dental deserves as much blame as the FBI, if not more, because it sounds like they were the ones pressing charges and motivating prosecution in the first place. Also, why aren't they being charged with what is almost certainly a HIPAA violation?
- blktiger 10y agoIf patterson dental (and I say if since we don't really know) is behind him getting arrested, I hope all their patients find out about the details of this and they go out of business. If nothing else they should be charged with HIPAA violations.
- jessaustin 10y agoPatterson is not a dental clinic. Like Henry Schein which was also mentioned in TFA, it is a large dental supply company. One reason that dentistry is so expensive, is that assholes like these run an oligopoly of "specialty" dental supplies. It's not as bad as military procurement, but it's kind of like that. Dentists as a profession are risk-averse, and that includes the "risk" of purchasing dental equipment and supplies without a 300% price markup. So, the chance of them going "out of business" is pretty slim. It's entirely possible that dentists unfortunate enough to have chosen Eaglesoft will get to pay some HIPAA fines, however.
- dragonwriter 10y ago> So, the chance of them going "out of business" is pretty slim. It's entirely possible that dentists unfortunate enough to have chosen Eaglesoft will get to pay some HIPAA fines, however. Will they? Since Eaglesoft claimed to provide encryption, and the practices relied on that claim, it seems unlikely that the practices are at fault; if they are subject to civil liability at all for inadvertent violations -- or even if they just have costs to cure the violations without money liability, which seems more likely given the history of HIPAA enforcement -- they would seem to have a claim for at least the total resulting costs in damages against Patterson. As far as criminal violations of HIPAA goes, it doesn't seem particularly likely that any occurred, and if any did its pretty clear that the practices are (barring any evidence of knowledge that hasn't come to light) unlikely to have had the requisite knowledge or intent to be culpable, though the violations may have been willfully caused by Patterson's actions, which -- even though Patterson might not usually be directly covered by HIPAA as regards what appears to be on-premise software they sell -- might make Patterson a (and possibly the only) chargeable principal in any crime. 18 USC Sec. 2(b): "Whoever willfully causes an act to be done which if directly performed by him or another would be an offense against the United States, is punishable as a principal."
- rrggrr 10y agoHere's an investigative tool the CFAA & the FBI needs... if a company like Patterson Dental spins up an investigative raid with a baseless complaint, the Bureau should be able to charge them with a crime. One almost hopes the FBI investigation yields enough evidence to charge Patterson with a criminal violation of HIPAA.
- a3n 10y agoWhy would the FBI and prosecutors punish Patterson? The gave the FBI an opportunity for raids and prosecutions, and those look great on an annual review.
- rrggrr 10y agoField offices don't have unlimited budgets. If it turns out this raid was unjustified - and it certainly appears to be - its not going to reflect positively on the people who caused it.
- tobltobs 10y agoThat would make me even more nervous, because if they would find some childprn it would have been justified.
- rrggrr 10y agoYou are being paranoid. There are over 13,000 FBI agents but probably 5x that number are needed to deal with organized crime, white collar crime, national security threats, public corruption, background investigations and other cases within their jurisdiction. You can bet there were/are a few agents shaking their heads in irritation over what appears to be a waste of resources.
- tobltobs 10y agoThat is even more reason for those FBI agents in charge to find something else to legitimate this waste of resources. For a real life example how this works you might google "FBI Keith Gartenlaub"
- Steuard 10y agoI know this is only tangentially related to the HN content here, but does anyone have a sense of why the FBI would choose to respond to this sort of case with a dozen agents and weapons drawn? Rather than, say, two guys politely ringing the bell and asking him to come with them? Unless there's a lot left out of this article, I wouldn't think most "unauthorized computer access" suspects tend to be heavily armed. (Particularly if the company actually reported the context of the "crime", including the fact that he had voluntarily notified them of the problem.)
- openasocket 10y agoI imagine it's a part of a trend of "militarization" of law enforcement. In the last few years police forces have greatly expanded their SWAT forces, partly because of the practice of the US military giving away surplus military tech to law enforcement. And if you have a hammer, all the world seems like a nail. The rationalization is that serving warrants can sometimes be risky, so why take the chance? It's in law enforcement's best interest to err on the side of caution: better to scare the crap out of people than get shot without warning. Which is why the government and the courts are supposed to balance LE's concerns with the rights of the people.
- geggam 10y agoSOP ...Military tactics against citizens. Overwhelm with force so the subject cowers in fear. Works great doesnt it ?
- hellbanner 10y agoYes, remember GwB's "Shock & Awe"
- jessaustin 10y agoUntil agents start getting thrown in prison for assault, their ridiculous assaults on harmless residents who pose no threat will continue. The best policy may be, simply not to be home at 6 AM. They're psychologically incapable of raiding when normal people are awake, or of making arrests in safer ways such as via a phone call to an attorney or simply waiting by their target's car until he leaves for work in the morning.
- pmontra 10y agoDo you have laws in the USA that mandate protection of health data?
- AnimalMuppet 10y agoYes. HIPPA.
- pmontra 10y agoBut apparently they didn't go after the company, so maybe those data are not the kind of information protected by HIPPA?
- joesmo 10y agoIt most certainly is information protected by HIPAA. It's just that there are no enforced consequences for companies breaking HIPAA (or pretty much any other law) while there are dire consequences for people accessing public data under the CFAA. I'll put it this way: if I wanted to murder someone in the US and get away with it, there are dozens of opportunities under the law as long as said murder is committed under the umbrella of a corporation. But god fucking forbid you access public data that was not secured properly by idiotic corporations and your life is ruined like this researcher's is about to be. Our judicial system is a joke; a society without justice is no different than the random savagery it purports to be above.
- jneal 10y agoThis reminds me of something that happened to me in high school back in 1999. I found an Excel doc in a public network drive that contained every single student's SSN, DOB, whether they had free/reduced lunch, address, phone, etc. I was admittedly snooping around, but this was all public stuff every student and teacher had full access to. When I found it, I told one of the teachers that I trusted and she insisted that I must tell the principal. So I went down to the principal's office and told her. My primary goal was to get this removed or made private because even at that young age I knew this was very sensitive data and I wouldn't want just anyone having access to my information like that. When I got home from school, I found my mother upset because we'd been called to return to school for an emergency meeting. I was questioned, and when I told them I only wanted this sensitive information properly secured I was told by the county IT administrator "Did you ever stop to think if maybe this information was public for a reason?" I took a second, and literally wanted to say "There is no reason this information should ever be public" but I ended up keeping my mouth shut in hopes to not get into further trouble. I was nearly expelled for "hacking". They placed me on "academic probation" and threatened that if I did so much as forget my school ID at home one day, I would be immediately expelled without question. I was removed from my elective classes that involved computers and was disallowed from touching any computers at school. Fun fact: Someone on the yearbook staff accidentally deleted the only copy of the yearbook files and our yearbook was in danger of basically not being made. I was called to the principal's office and asked to help. I was able to recover the deleted files and save the day. At some point they realized I never had malicious intent, but I still hold a small grudge for the way I was treated as a criminal for uncovering such a big security hole.
- eximius 10y ago> "Did you ever stop to think if maybe this information was public for a reason?" If it was meant to be public, then you shouldn't have gotten in trouble for pointing out its existence. I don't understand the twisted logic there.
- ludamad 10y agoThis is public for the teachers, snooping this file is the same as rummaging through teacher's stuff!
- a3n 10y agoIt's as if the CFAA was intended to protect behavior like Patterson did.
- callesgg 10y agoAbout a month or so a go i found a open public mongo database with about 12GB of records regarding peoples retirement founds of what i assume was hundreds of thousands of people, account numbers, how much money was in the accounts when they had moved them to various founds and so on. Thought long and hard about what to do but decided to not do anything, dont feel like risking my entire life just to help someone. This is me assuming they did not intend to have it publicly open. With that story out there, it would be nice to have a legit legal way to inform the police or a similar trustworthy government agency that could handle issues like this.
- ScottBurson 10y agoSeems like, at the very least, you could offer it to Wikileaks. Might be too small a story for them to care about though. I'm looking at 'Have I been pwned' [0], but they seem to care about only breaches that have been publicly acknowledged. Sounds like they don't want to be in the business of breaking this kind of news themselves. Maybe there needs to be a new Web site for this kind of thing -- located outside the US, of course. (Probably there already is one and I don't know about it.) [0] https://haveibeenpwned.com/ https://haveibeenpwned.com/
- gregmac 10y agoBran Krebs (Krebs On Security) breaks these types of stories, though he's a journalist so would publicly disclose it. Very possible he'd contact them privately prior to a story though in the hopes they fix it before publication.
- dreamsofdragons 10y agoAnnonomous email through a few proxies from a one time email address should be sufficient. "I accidentally discovered this when I miss typed an IP."
- rveeblefetzer 10y agoYou could search PGP keyservers for email addresses/domains of the local media where that retirement fund is located and take it from there, using your own judgment about the reporter and outlet, and how much you'd want to mask that communication.
- deleted 10y ago[deleted]
- joesmo 10y agoIn the meantime, companies like Apple and Google are deleting users' files without their consent and infecting computers with malware through ads yet I don't see Tim Cook or Larry Page being woken up in the middle of the night by a SWAT team. What a fucking joke our legal system is.
- merrywhether 10y agoReading this, I had an idea for a new law that could counteract this stupid reaction to security research: Particularly for protected patient information (but maybe for other classes of sensitive data as well), it would be interesting to somehow classify having this information breached as a crime by the holder of the information (I realize this might be hard to do given the reality of security these days, so there would need to be some nuance of course). The crux of my idea would be to automatically count any access that results in prosecution as a breach of said data, thus meaning that prosecuting a security researcher would automatically put the information holder under separate prosecution. I wonder if something like this could be feasible.
- AgentME 10y agoI like a bit of this idea, but too many people already have it in mind that the holder of the information is a "victim of hacking", so punishing them is "victim blaming", which we all know is always bad.
- AnthonyMouse 10y ago> classify having this information breached as a crime by the holder of the information The source of the problem in this case is that the CFAA is too loose/broad and the penalties are absurd. The solution is to fix that. Make it so that the only penalties available are proportional and innocuous actions like reporting vulnerabilities are bright-line not illegal whatsoever. You're essentially suggesting cold war style MAD as a solution to the government foolishly supplying toxic waste to children who are then found using it to poison people they don't like, under the theory that if everyone can poison everyone then everyone will have to behave. Better to clean up the toxic waste than ensure equal access to it.
- zardo 10y ago>(I realize this might be hard to do given the reality of security these days, so there would need to be some nuance of course) In my industry, the EPA produces technology forcing regulation, we will have to invest a few hundred million to meet the upcoming standards and continue selling our product in the US after 2020. To sell our product in 2027, we need technology that hasn't been commercialized yet. Maybe computer security could use a technology forcing regulation to get real investment in secure software to happen.
- downandout 10y agoUnless there is more to the story, he won't be prosecuted for accessing an anonymous FTP server. However, they will scour the computers/drives they took (for months or possibly even years), looking for evidence of this or any other technically illegal misdeed. In the unlikely event they find nothing that they can take issue with (this being a security researcher's computer equipment, they'll find all kinds of hacking tools and possibly evidence of other research that could be construed as hacking attempts), in a year or so, he might get his stuff back. If they find anything, he'll face charges for that. That's how law enforcement in the US works. A crack in the door, in the form of a ridiculous accusation, is all it takes for one's life to be destroyed.
- sathackr 10y agoFun fact: Many financial institutions use the last 4 of your SSN as identity verification. If you're a business, it's the last 4 of your FEI/EIN. I know at least in FL, this is publicily available at sunbiz.org So with the account number printed at the bottom of your paycheck/stub and the FEI/EIN, you can often authenticate to a financial institution and obtain privileged information. I know this not because I was on the "hacker" side, but because I was involved on the financial institution side of it and caught this as part of my engagement. The institution was issuing new logins for its internet banking site and the password would have been based on the users name, zip code, and SSN/FEI/EIN, all 3 of which are available (in FL) on that sunbiz.org site.
- csours 10y agoMy last bank had the username for online banking set to the account number, and the password set to the last 4 of SSN by default. The password was limited to 4 characters, but they did allow special characters.
- DrScump 10y agoYears ago, one of my credit unions used SSN as the account number... so every one of our checks had our SSN printed right on it.
- sathackr 10y agoawesome! In my experience, credit unions are usually worse than Banks on the security side. There are exceptions, but they are not the norm. One credit union I dealt with always opened and closed with a single employee. Very dangerous for the employee. This same union kept the A and B part codes to their vault in a locked desk drawer(one of those cheap desk drawer locks that anyone can pick with a paper clip) in the lobby, and full internet access was available on all computers. Tellers all shared a single cash drawer and the teller PCs were routinely used by the tellers for general web surfing, Facebook, Pandora, etc...
- cloudjacker 10y agoUse Tor through Whonix gateway. FBI's NIT doesn't have a way through that.
- ghoul2 10y agoAs a separate issue: why the "shock and awe" response to what is (even allegedly) a non-violent crime? Why the assault rifles? Why could he not have been arrested by just a couple agents walking upto the door, knocking, serving the search warrant, and then maybe having the techs step in to conduct the search and seizure? Why does US Law Enforcement so dramatically escalate every contact with a citizen? Everytime they do this, they risk accidental injury to the people, kids, pets. What in this particular situation necessitated a SWAT-level treatment? Maybe the law should be fixed such that warrants have to specifically include firearm authorizations.
- wtvanhest 10y agoRequiring the warrant to specify the level of force could be interesting. Are there good reasons why this could not be done?
- gist 10y agoI honestly don't think that being rude and/or hurting feelings (or scarring a baby) really enters into law enforcement of this type (also see my other comment).
- nickysielicki 10y agoYou're moving the goal-posts. I don't think that being rude or hurting feelings should cross their mind. Bringing a gun escalates things immediately. If I was in that home and I was carrying a gun, and if a handful of people abruptly came in with assault rifles, I'm liable to react very differently because it's such an affront to what feels reasonable. I think it's more reasonable to think that this is a terrorist attack and to react accordingly, rather than the reality of people acting as an agent of the government bringing deadly force in droves because someone grabbed a file from a public FTP server. If I had seen 5 men in suits and shades peacefully walk in without any kind of weapon, I'm not going to think anything of it. They're putting themselves at risk. It makes no sense. And the honest answer as to, "why?" is that the people who kick in doors are complete meatheads who think that morality and legality strictly align. They think if someone has broken the law, they deserve anything that is coming. They don't care about anyone's safety, they care about taking baddies.
- pipermerriam 10y agoThe FBI seems to have lost it's way (Same with most of the other 3-letter governmental entities and other law enforcement). How do we change the system so that they are held accountable for these sort of things? This is getting ridiculous. I can't predict the general public's opinions on things like this but it seems so clearly "wrong". I have hope for a peaceful fix but I am skeptical that we aren't well on our way to a much more traditional violent revolution. Everything I've read on the subject suggests that the early signs of revolution are a sufficiently large disparity between the rich and the poor such that the poor can no longer provide for themselves. It seems like this is well on its way and likely speeding up. I'd love to see some statistics on situations like the 2014 Ferguson Missouri situation. I'm curious if there's a rise in situations where the government sufficiently crosses the line that the public backlash manifests violently. I expect that we're still in a stage where these situations are still largely centered around poor minorities [1] but situations like this suggest that incidents are starting to expand into demographics that might get the "middle class" [2] to finally pay attention. I hope we can find a way to unite as a single voice to change things. I hope it doesn't end up being violent. The following things encourage me. * Decreased relevance of the "mass media". This is a double edged sword. On one hand it allows for news that might be ignored by a major network to still be disseminated widely. On the other hand, the "public" has a really poor track record of consuming news that isn't also entertainment and many of these issues seem to fall entirely outside of people's interests. * The ability to aggregate these sort of events to establish a clear pattern of behavior. It's getting harder to hide things. Also these disclaimers: 1. I say poor minorities because based on my knowledge of the law enforcement overstepping it's typically in situations involving people who are poor and black. 2. The "middle class" is used here to reference a predominantly "white" demographic that most mass media caters to. I've struggled to find the appropriate language here, fearing I'll be labeled racists somehow. Hoping that my message reads as intended.
- phusion 10y agoThis is so wrong, but it's not surprising. We've been reading stories for years of security researchers being charged with a crime or harassed for simply pointing out blatant security holes. What kind of thinking is this? He was doing them a favor. Every time, it seems to me that they are embarrassed by the incident and lash out. WHY!?? We should be treating these researchers like heroes, not kicking in their doors and having the FBI charge them with criminal CFAA violations. Once the chilling effect comes down in full force, we'll have a much less secure Internet.
- spydum 10y agoI thought they did not have the "reason" for the arrest -- only the warrant. The arrest may have nothing to do with accessing the Public FTP, and entirely to do with the research he was doing on the FTP service itself. If he was attempting to exploit the FTP service hosted by someone else (something or other aboubt database credentials was mentioned), he would absolutely be in violation of CFAA. You do that sort of research on your OWN system. First rule of security testing: make sure you have permission.
- mevile 10y agoI'm not addressing the FBI response, but hear me out. As a security researcher you have to stop at the first vulnerability. Don't use the vulnerability to get more information. It's the companies responsibility to ascertain the impact of the problem. This person should not have attempted to download anything from the FTP server. It should have spotted the FTP server, notified the company and made it clear they never attempted to download anything from it. There was a similar issue with S3 credentials and Facebook a few months ago. The security researcher went too far. There was a large outcry by everyone about Facebooks response. I'm not addressing the response. I'm saying as a security researcher you need to protect yourself by trying very hard to limit the impact of what you're doing to remove risk of legal liability. Only go as far as the first problem and no further.
- King-Aaron 10y agoSo basically, when you discover critical vulnerabilities in a server, do not tell the owners about it. Sell the information anonymously to the highest bidder.