22 ms·
Teenager facing prison for downloading unsecured files from government website
- swampthinker 8y agoAm I crazy? Aren't FOIA requests, by definition, public information?
- dumbfounder 8y agoThis happened in Canada. They might have a FOIA equivalent, but I wouldn't assume it has the same rules as in the US.
- codefined 8y agoIn the UK and most of Europe, you cannot request the personal information of anyone else via a freedom of information request, since it is likely to contain sensitive information to that person. For the UK, you can find out more information about the specifics of this from the data protection act, which includes clauses about FOI requests.
- Kelbit 8y agoIn this case, most of the documents were public, but there were a small number which had confidential information and were inappropriately stored on the public portal.
- deleted 8y ago[deleted]
- cryptoz 8y agoWow. The trauma inflicted upon the children in the family when the Canadian government bursts into their house can never be undone or taken back. Nor can the financial and mental, emotional stress of losing their computers and ability to do productive work and go to school. (Edit: will there be any reparations for this abhorrent behaviour? Have they apologized? Will they, at least? Not that it matters, the damage to this entire family is done.) Some questions. Is the website still online? What happens if every Canadian downloads the files? What a dystopia. Do we only have one part of the story, can the situation really be as bad as depicted on the article? This is atrocious. Edit: And where is the case against the people in the office who put the sensitive information of others into public view, (assuming and against the law), the actual perpetrators of an actual crime?
- astrodust 8y agoIt's worth noting this sort of thing is highly unusual which is why it's getting so much media attention.
- remir 8y agoThe Gov of Nova-Scotia shut down the site, but you can still find some documents on Google (they're cached). The subcontractor of the site fucked up and they're blaming this kid.
- JasonFruit 8y agoIs it trauma, or an education in tyranny? Admittedly, it's not the kind of education I'd prefer for my children, but in the long run, nakedly tyrannical behavior is better than concealed.
- sbarre 8y agoThis reads like the beginning of The Hacker Crackdown.. As a Canadian, reading this article made me angry. If the information is not supposed to be public, it should not be reachable without authorization or authentication. Never mind a curious 19-year-old, there are tons of crawlers and indexers out there that attempt to enumerate URLs where they think there might be other content. Shame on them for building a poorly secured site, but even more for trying to railroad a curious kid who made them look stupid.
- freshmint 8y agoI already play with urls that have possible id's in them out of habit. The only difference here is the poor kid was on a gov website and they did not want the information he found to be public. ( Or like in the USA he might have to pay for each document accessed. But I feel that should not result in a raid to his house.) It is a shame the kid was their target and not a google bot like you said.
- gowld 8y agoGooglebot has the resources to fight back against government attacks.
- rayiner 8y ago> I already play with urls that have possible id's in them out of habit Do you jiggle door handles out of habit to see if they're unlocked? It's antisocial behavior. If you were supposed to have access to that document, it would be accessible from a link or search box on the main site.
- samatman 8y agoIt... it is accessible from a link That's what a url with an id in it is a link
- rayiner 8y agoA "link" is a DOM element in a web page which references a URL, but a URL is not itself a link. To point a finer point on it: the fact that a URL is referenced in a link means that a user is supposed to see and access it.
- wardn 8y agoDamn kids. They're all alike.
- GuiA 8y agohttp://archive.org/stream/The_Conscience_of_a_Hacker/hackersmanifesto.txt http://archive.org/stream/The_Conscience_of_a_Hacker/hackers... https://en.wikipedia.org/wiki/Hacker_Manifesto https://en.wikipedia.org/wiki/Hacker_Manifesto
- cooldevguy 8y agoYou sir, won the internet today with that quote
- j32fun 8y agoSince this is publicly accessible, what would be the chance that search engines indexed the files? In this case, would Google bot be charged? Or if this were, say, Equifax or Facebook. I mean, in those situations, the companies were blamed for "the leak". It seems rather convenient to cherry pick the law to apply on this poor teenager.
- mikekij 8y agoI think I read that Google had, in fact, indexed all of these pages.
- Declanomous 8y agoGoogle did indeed index these files according to the following article: https://evandentremont.com/some-information-on-the-freedom-of-information-hack/ https://evandentremont.com/some-information-on-the-freedom-o...
- Scoundreller 8y agoAll? Or just the ones that others posted links to?
- colemannugent 8y agoYeah, what about that Cloudflare memory leak they had a while back? Are all the caches that retained the info complicit?
- remir 8y agoA quick Google search return some (cached) results: https://webcache.googleusercontent.com/search?q=cache:4N3wSVBovwcJ:https://foipop.novascotia.ca/foia/views/_AttachmentDownload.jsp%3FattachmentRSN%3D2761+&cd=30&hl=fr&ct=clnk&gl=ca https://webcache.googleusercontent.com/search?q=cache:4N3wSV...
- bowmessage 8y agoReally worried about what the authorities might find in his 30TB of 4chan backups. Hoping for the best outcome for them.
- daodedickinson 8y agoExactly. Why did this kid admit that? How astronomcally low are the odds there's nothing illegal to possess in there?
- cwkoss 8y agoHe's a 19 year old kid, not a criminal mastermind
- selectodude 8y agoThere's quite a bit of child pornography that has graced the pages of 4chan over the years.
- chaboud 8y ago"How astronomcally low are the odds there's nothing illegal to possess in there?" That is a haunting reflection of the state of affairs with regards to information and laws regarding information. Criminalizing the mere possession of information should be a tool only of the despotic and/or idiotic. Of course, these clowns left "private" information accessible by public urls without identification, so we know that they're at least idiots.
- astrodust 8y agoAs the amount of 4chan material you've archived increases the probability of not archiving something illegal quickly diminishes to zero.
- Anon1096 8y agoDepending on the boards archived there's a pretty good chance he doesn't have CP. Only /b/ (and I hear /sp/ as well but I never go there) really ever have child porn, and then very very rarely and quickly deleted to the point that an archiver might not pick it up. Due to the sheer size and uselessness of a possible /b/ archive I kind of doubt there's anything bad.
- CosmicShadow 8y agoNot the kind of response I would expect as a Canadian. Can't they send someone undercover ahead of time to find out it's just some kid at his family house and then take the appropriate response? There are better ways to handle this, and there are certainly better ways to secure government files! If it's publicly accessible, it's public information. Obfuscation doesn't count!
- marzell 8y agoThere really should be accountability of whoever chose to store the data in an insecure manner.
- isostatic 8y agoI wonder how they noticed. Perhaps the lowest-bid contract company that made the site decided to use something like amazon glacier for storage of boring documents nobody will ever need. Then along comes someone that causes them all to be extracted at great cost, some middle manager receives a bill for $millions and wants to blame the kid rather than his own failings.
- sigstoat 8y ago(added: the link to evandentremont.com elsewhere in the comments discusses how this was supposedly discovered, and other details of interest.) that would make its own interesting information request. you probably couldn't directly ask "how'd you find him out?" at this point, but you could ask for maybe IT costs per month over the last X months broken out by organization the money was paid out to. also possible (probable, even, in my mind) he just crawled too hard, the machine was slow, and the folks in the office working on it complained. (god only knows how much processing the service does behind the scenes when a PDF is requested. for all we know it is being reassembled from tiffs of individual pages every time.)
- raverbashing 8y agoI don't think you can get from glacier in "real time", you need to prefetch it first
- amatecha 8y agoThe truth is even sadder than you might expect (the rest of this post is a quote from this article[0]): Conrad said the breach was detected by a provincial employee, but it was a fluke. “The employee was involved in doing some research on the site and inadvertently made an entry to a line on the site — made a typing error and identified that they were seeing documents they should not have seen,” Conrad told a technical briefing. [0]: http://toronto.citynews.ca/2018/04/11/halifax-police-probing-n-s-freedom-of-information-site-breach-government-says/ http://toronto.citynews.ca/2018/04/11/halifax-police-probing...
- jessaustin 8y agoThere's a bit of a leap from that to knowing this dude had done the same thing? That describes the employee finding a vulnerability. It probably took some study of the logs to find "the breach". How many similar breaches by actors overseas and less-vulnerable Canadians did they ignore?
- deleted 8y ago[deleted]
- phnofive 8y agoSeems like a move by the provincial government to shift blame from its poor security to an imaginary bad actor; this article also from the CBC goes into more detail and asserts that fraudulent intent is necessary for a conviction, so hopefully this goes nowhere. http://www.cbc.ca/news/canada/nova-scotia/concerns-teen-being-railroaded-in-privacy-breach-to-cover-government-slip-1.4616972 http://www.cbc.ca/news/canada/nova-scotia/concerns-teen-bein...
- eigenvector 8y agoYes, it's really not clear that any crime was committed. The relevant section of the Canadian Criminal Code[1] requires either fraudulent intent or some actual manipulation/destruction of the server - not simply downloading data. It seems like overreach by the police to distract from the fact that the government failed to secure private data. [1] http://laws-lois.justice.gc.ca/eng/acts/C-46/section-342.1.html http://laws-lois.justice.gc.ca/eng/acts/C-46/section-342.1.h...
- inetknght 8y agoHonestly, I'd like to see the kid's lawyers push back and claim damages against the province and its contractors. How else shall we force problems like this to be fixed?
- kazinator 8y agoAnyone familiar with the Streisand effect would have predicted that this would in fact result in this failure getting as much attention as the circumstances can imaginably furnish.
- jt2190 8y ago> The relevant section of the Canadian Criminal Code[1] requires either fraudulent intent or some actual manipulation/destruction of the server. Not quite. The test is: > Everyone is guilty... who, fraudulently and without colour of right, obtains, directly or indirectly, any computer service (including... the storage or retrieval of computer data) The Crown can argue that the documents were retrieved/obtained using manipulation of the server (since the public URLs were manipulated to find non-public URLs.)
- lurker456 8y agoperhaps we need an RFC that defines this type of approach (pages "secured" behind easily guessable urls) as public information.
- fouc 8y agoThat actually seems like a good idea to me. I wonder if there isn't already one? It'd be a good symbolic source of authority on issues like this. There could also be other RFCs covering our usage of the internet, and our expectations of what our rights are as internet users. Or perhaps stick that all in one "definitive" RFC.
- astrodust 8y agoInstead of actual security why not have a spec for /humans.txt which can say things like "Please don't read anything in the /secret directory."
- gruez 8y agoand what would that achieve? all it's going to do is force companies to add legal boilerplate (eg. those "this message is intended for the recipient only..." that you see in email signatures) to every imaginable place to cover their ass, meanwhile doing nothing to improve security.
- FundThrowaway 8y agoTalk about no sense of humour.
- outworlder 8y agoAs if the brilliant minds behind this website would even know what a RFC is.
- fouc 8y agoThe RFC would be more for future "legal" defense around this type of issue to use as evidence for support of enumerable urls = public api.
- udia 8y agoThe teenager was downloading publicly available records on a Freedom-Of-Information portal. Why law enforcement is involved, or why this is even remotely a criminal act, completely baffles me.
- drb91 8y agoIt’s easier to prosecute than to fix. More than that, the kid pointed out the service is broken. Pretty humiliating. It’s not at all unusual to prosecute to save face, especially rather than admit that your org gave the info to a teenager when that’s illegal.
- Scoundreller 8y agoI think it also included records of the submitter (private data). Sometimes you get Freedom of Information Act information because you got an individual's consent to release information that would otherwise not be released (e.g. something about your spouse/family member that consented to the information not being redacted). Perhaps the same portal handled Privacy Act requests where people requested their own information that the government holds.
- frostirosti 8y agoSounds an awful lot like the computer fraud and abuse act
- politician 8y agoAdd "help avoid sending teenagers to prison" to the list of reasons why you should prefer UUIDs over integers in your Internet-facing REST API. This API was supposed to be private and yet supported trivial enumeration?
- Someone1234 8y agoMany UUIDs aren't secure either and can be trivially enumerated. A better approach might be a long number generated using a secure random number generator and converted to a BASE-64 string.
- Wald76 8y agoGenerally you generate a random UUID which is quite difficult to enumerate.
- kbar13 8y agouuidv4 is random assuming your rng source is random
- Someone1234 8y agoAnd assuming you're legitimately getting a UUIDv4 instead of a UUIDv1 or UUIDv2 now and forever...
- larkeith 8y agoA better approach would be to not put private data in the public domain.
- thisacctforreal 8y agoI think a cryptographic hash is fine. If you know the hash, you likely already know the file.
- Someone1234 8y agoA cryptographic hash of what? Cryptographic hashes aren't random by nature.
- XorNot 8y agoAnd this is why I'm going to route all my kids traffic through an offshore VPN by default and whitelist low latency stuff.
- Gabrielfair 8y agoI'm starting a proxy project that can be used in countries where VPN is illegal. I'm looking for collaborators. https://github.com/UncleGrape/UncleGrape https://github.com/UncleGrape/UncleGrape
- JorgeGT 8y agoTypos in README: "versitle", "explictly"
- indiandennis 8y agoI'm interested in contributing, although I don't have much experience with networking code. Any idea what language you're going to be using?
- jopsen 8y agoI've been thinking I wanted a router with two wi-fi networks. One that goes through the ISP and one that goes out over a proxy. I haven't found a solution just yet. I guess a raspberry pi with iptables and routing based on device ID could do the trick too.
- c22 8y agoWhy not just set up two wifi routers? This is surely also the best solution for ensuring data compartmentalization.
- null0pointer 8y agoI have just set this up a week ago at my apartment. I use hostapd and dnsmasq on a raspberry pi to make it a wireless AP. It is connected to the primary router via ethernet and uses iptables to route wifi traffic via ethernet. Then I just installed OpenVPN to route traffic via a VPN. I haven't tested for DNS leaks yet as this is an ongoing project. There are a couple of other things on my todo list still. Such as easier switching of VPN node (current method is to ssh in and restart OpenVPN with a new config...) and ad blocking. Hope this can help you although it's still a bit immature and quite hacky IMO
- amatecha 8y agoIf you can see the data by iterating a single number in a URL, and there's zero authentication or verification of credentials, there's no possible way to call it malicious. The fact this family's home was raided was already a colossal mistake. The fact charges are even _suggested_ is such a joke I don't even have words to describe it.
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- danso 8y agoThis reminds me of a purported "hack" back in the Governor Schwarzenegger days. An employee from a rival campaign found a public-accessible FTP directory full of audio files, which they then leaked to the press. IIRC, the California Highway Patrol opened up an investigation but ended up not pursuing charges. https://www.dailynews.com/2006/09/13/arnolds-audio-open-to-public-foe-claims/ https://www.dailynews.com/2006/09/13/arnolds-audio-open-to-p... edit: the other parallel, IIRC, was that part of the web site was kept private. But the user found the audio by navigating to a parent directory which was apparently open to the public: https://www.dailynews.com/2007/02/02/chp-clears-angelides-camp-in-flap-over-web-audio-files/ https://www.dailynews.com/2007/02/02/chp-clears-angelides-ca... > Essentially, aides opened the Web address, or URL, from one of Schwarzenegger’s speeches and lopped a few characters from the end of the address. That yielded a directory of audio recordings.
- erpellan 8y agoThis is appalling. The operators of the site should be charged for criminal negligence. You don't get to call it stealing if all it took was 3 keystrokes in the address bar of a browser. Backspace. Number. Return. Hacked!!
- deleted 8y ago[deleted]
- czbond 8y agoCases like this make me want to attend law school. I am well versed in technology, have acted as CISO and other capacities. I bet I could decimate many prosecuting attorneys trying to make their weak cases.
- anfilt 8y agoDo it! Then when you get enough experience become a Judge. So when a prosecutor brings your stupid case you can just throw out!
- drtillberg 8y agoInterdisciplinary skills are really undervalued in law practice. Usually (US) lawyers try to fill a room with 1 subject experts, which is uneconomical, and a government typically is not going to do it. So, in a run-of-the-mill matter like this there is no interdisciplinary skills available to stop the slow motion train wreck.
- ryandrake 8y agoGood thing he’s in Canada and only got raided. If he were in the USA, they would have tossed flashbangs and tear gas into his house, vaulted in through the windows, shot the family dog, and held the whole family at gun point, boots on their necks. It’s a shame that police departments think these “shock and awe” tactics are even remotely appropriate for dealing with non-violent suspects.
- jstarfish 8y agoI don't like or agree with it either, but it is unfortunately necessary for the preservation of digital evidence. Many nonviolent actors involved in cybercrimes have prepared killswitches or some other manner of instantly burning everything to the ground if you give them enough time to react when you show up with a warrant.
- jessaustin 8y agoIf we can't enforce the law without making society terrible, let's get rid of the law.
- billofwrongs 8y agoRemember Aaron.
- manfredo 8y agoAaron Swartz' situation is substantially different. Swartz knowingly violated the terms of service of JSTOR, and deliberately circumvented it's rate limiting. And he knew what he was doing was against the law, he even published a manifesto outlining his intentions to do this as a form of civil disobedience. The kid in this story just incremented sequential IDs on what was supposed to be public information.
- ebullientocelot 8y agoIt isn't a breach if the administrators of the repository failed to secure the information. Regardless of the likelihood of conviction it is reprehensible to terrify some kid with the threat of losing his freedom as a means of saving face, which is what this appears to be. I certainly hope he gets out of this.
- whack 8y agoThis might be a controversial opinion here, but intent does matter. If I see a bunch of stuff sitting the sidewalk and I take some because I think it's free, that's a reasonable thing to do. But going into someone's house and taking their tv is not. "It's their own fault for not locking the door" isn't a valid legal defense, and I would prefer not to live in a country where victim-blaming becomes a get-out-of-jail-free card. Based on what little I've read thus far, the teenager does indeed seem to have good intent. If that's the case, I'm cautiously optimistic that the court system will set him free without any consequences. But if the prosection can prove that he was aware of the data's confidentiality and was acting with malicious intent, then he deserves a conviction. Let's let the legal system run its course, before gathering our pitchforks.
- gcommer 8y agoThat analogy assumes a lot about how hard/hidden obvious id numbers in URLs are. I'd counter that this situation is more like "putting your stuff on the curb and being mad when people take it". Rather than scapegoat the kid, the government should be investigating themselves for criminal negligence.
- whack 8y ago> "That analogy assumes a lot about how hard/hidden obvious id numbers in URLs are" Well, I did give 2 different analogies, and without knowing more specifics, I'm not taking a stand on which analogy better fits this case. Depending on the specific design the government used, and the steps the teenager took to access the content, either analogy could be applicable. > "Rather than scapegoat the kid, the government should be investigating themselves for criminal negligence." That's a false dichotomy. Investigating government officials for negligence shouldn't preclude prosecuting a (hypothetical) malicious hacker.
- jellicle 8y agoThat's because we know what a "house" is - a bunch of private property with a wall around it (even if the wall is not locked). Usually comes in sets with other bunches of private property with walls around it. And we know the default - you aren't welcome in those walled forts unless you are welcomed in by the owner. Not at all clear that files on a public webserver look very much like a private house.
- brandon272 8y agoI am absolutely incensed reading this. The government made no reasonable effort to conceal the information and put it on a _publicly accessible_ web server. They made the information available to the public whether or not that was their intention. How can any reasonable person conclude that typing in an HTTP url qualifies as an illegal breach?
- brailsafe 8y agoIncensed. Learned a new word today. Danke.
- gtlondon 8y agoThey've made the information publicly accessible via HTTP, yet react like this when someone then views in. Scary stuff. I just can't comprehend this at all. To even describe it as a "breach" is inaccurate -- the real headline is "government publishes data they hadn't intended to".
- itronitron 8y agowhat part of _freedom of information portal_ do they not understand?
- adanto6840 8y agoI agree with many of the comments here, along the lines of "intent?" and "bad law", etc... How can I provide material assistance to either this kid and/or to the problem at large? I'm looking for something other than "donate to the EFF [or equiv.]" ideally though; I'd prefer to donate directly to his legal fund, or even do some legwork myself that will help, etc. And ideally in a way that not only helps him, but that helps prevent these situations from occurring in the future -- i.e. working towards law change, influencing prosecutorial discretion (meh), etc...
- inetknght 8y agoPropose changes (additions, subtractions, et al) to current law. Talk to your (I don't know Canadian politics) political figureheads about your proposals. Shop them around. Talk to your law enforcement agencies about computer crimes. Write and talk publicly about the issues.
- EamonnMR 8y agoI'm not an expert in Canadian law, but are there any elected officials in the chain of the decision to conduct a raid? If so this ought to be severely career limiting. If it was an elected judge who approved the warrant, for example.
- jgmjgm 8y agoFYI - Judges aren't elected in Canada. Good point though. The real question is who continues this process now that it has clearly been exposed.
- hydrox24 8y agoThe provincial government or federal government appoints judges. [0] But if it is anything like here in Australia (we are both Westminster systems) then this does not mean the government is held accountable. Judge appointments are assumed to be fairly neutral and it hardly ever comes up at election time. [0]: https://en.wikipedia.org/wiki/Judicial_appointments_in_Canada https://en.wikipedia.org/wiki/Judicial_appointments_in_Canad...
- Magi604 8y agoHe's archived portions of 4chan? It's likely then that he's gotten some "bad" stuff without him really knowing it. The police will search through his files, find the bad stuff, and charge him with some sort of possession/accessing/downloading charge. Life = ruined.
- bpchaps 8y agoGod dammit. An almost identical thing happened to me after submitting a public records request to Seattle's IT department for email metadata for January 2017. Instead of sending me the email metadata I requested, they ended up accidentally sending me millions of actual emails. FBI investigations, cheating husbands' texts, SSNs, credit cards, zabbix alerts (so many 100% disk space alerts). When I contacted Seattle them to tell them what happened (on my own will), the conversation quickly turned to a point where we had to get lawyers involved. Basically, they told me that if I agreed to have Kroll [1] scan my hard drives to prove that I deleted the records, then they would give me "legal indemnification". They eventually agreed to accept an affidavit that I deleted everything, and had to wipe TRIM and that I wrote a script to confirm deletion to the effect of, "grep -r $FILES_HEADER_FIELDS /". One part that led to such a strong action by them was that they didn't see in their logs how I downloaded everything and thought that I found a backdoor to download all of their emails. They had some annoying rate limiting that prevented too many files from being downloaded at once, so I copied the files from the page's source, then ran a wget against everything. Since the files were being downloaded from S3, their webserver logs didn't include most of the downloads, which led to some suspicion. Funny enough, Seattle told me it would cost $32m and 320 years of employee salary, but I ended up sending them $40. It just blows my mind. https://crosscut.com/2017/10/seattle-information-technology-department-email-leak-city-scrambles https://crosscut.com/2017/10/seattle-information-technology-... [1] https://www.kroll.com/ https://www.kroll.com/
- jstarfish 8y agoThe way things played out for you is exactly how we handle corporate exfiltration. Employees are unilaterally terminated for the violation, but we'll agree to not press charges if they disclose any dissemination and attest to its deletion. Good for you for not having to deal with Kroll.
- WestCoastJustin 8y agoI've contacted the reporter to see if we can setup a legal fund for this guy. It sounds like he's being bullied. This could also get a very bad precedent in Canada as this is totally absurd.
- gburt 8y agoPlease keep us informed on the outcome. I have written a letter to my MP and MLA as well as the MP for Halifax.
- WestCoastJustin 8y agoHe got back to me and said there is no legal fund at this time. These people need to hire a lawyer ASAP. Their sons life is over because he wrote a for loop with wget. for i in `seq 1 7000`; do wget http://foi.example-gov-domain.gc.ca/foi-download.cgi?id=$i; done Boom, you are not going to federal prison for 10 years! What a complete joke!
- Sytten 8y agoAs an act of solidarity, we should all run it until they drop charges and fix the damn thing. They can't charge 5000 people.
- Kelbit 8y agoKeep us informed. I'll chip in.
- anaphor 8y agoI would love to help out if possible. I'm a Canadian citizen but not in Halifax, so I guess I can write my MP but I don't think they have much authority to look into a provincial matter like this.
- zkirill 8y agoCall Andy Fillmore's [1] office anyway. [1] https://www.ourcommons.ca/Parliamentarians/en/members/Andy-Fillmore(88325) https://www.ourcommons.ca/Parliamentarians/en/members/Andy-F...
- zupa-hu 8y agoCouldn't it be argued that clicking links on a web page are no different from changing an ID in the URL? Web pages contain loads of URLs. You can't tell if you have the right to access the content behind it. The URL itself is simply an address to something - or nothing (404). Having an ID in the URL is a compact way of signaling a huge list of URLs. Thus, the kid simply followed links published on the website.
- nkrisc 8y agoIf a URL responds to any unauthorized HTTP request with data, how is the requester supposed to know that the data they received is supposed to be private or sensitive?
- null0pointer 8y agoA better (more accurate) analogy than finding an open window/door is that of asking a government employee for data. Kid: "Hi, what is the personal info in that file?" Employee: What they should say: "You are not authorised to see the contents of that file." What they actually said: "Sure, here's all the information in that file."
- Simulacra 8y agoThis is very sad. Any information that is not secured, and thus CAN be accessed, should be considered publicly available. If that rule or precedent were in place (a law would never happen) it might force system owners to be more cautious.
- pont 8y agoThis situation can't be improved. Start using Tor.
- gburt 8y agoPlease write to CIPPIC [0] and the Members of Parliament [1] and Members of the Provincial Leglisation [2] for both your local jurisdiction if appropriate and Halifax, Nova Scotia to help protect this kid. The federal Minister of Justice [3] and Technology [4] may be good additions. Remember what happened last time we let a government go wild on a kid incrementing a number in a public URL. The fact is, it is the organization who published "personally identifiable information" on the public internet who should be punished - and, in any case, criminal law is not the tool to do it. The kid who incremented a number in a URL to download that information is not the bad guy. What if the kid was not Canadian? Are you going to try to extradite a Russian national over accessing information on a public web server? When a server announces to the world that it can answer HTTP requests, making a reasonable number of HTTP requests is, to me and most technologists I know, authorization (and thus, should be seen as with colour of right or non-fraudulent). The fact those HTTP requests released data he was apparently not entitled to is a security issue, a bug, a problem to be paid for by the actor who manages the HTTP server, not a problem of law. Unfortunately, this section of law has not been used often enough to clarify to me the interpretation of those words. Here are some follow on questions: - Why was there "personal information" in FOI releases? Surely a FOI release was intended for the public, as that is the intent of the act. Who's fault is it that there was undesired information in the releases? - How do we get this law changed? As the law is written, it hangs on the words "fraudulently and without colour of right" - the rest of the clause is incoherent babble of a 1985 technophobe. [0] https://cippic.ca/ https://cippic.ca/ [1] https://www.ourcommons.ca/Parliamentarians/en/members/Andy-Fillmore(88325) https://www.ourcommons.ca/Parliamentarians/en/members/Andy-F... [2] https://nslegislature.ca/members https://nslegislature.ca/members [3] http://www.justice.gc.ca/eng/contact/index.html http://www.justice.gc.ca/eng/contact/index.html [4] http://www.ic.gc.ca/eic/site/icgc.nsf/eng/h_00279.html http://www.ic.gc.ca/eic/site/icgc.nsf/eng/h_00279.html
- Introvertuous 8y agoWhat an age we live in, utterly depressing.
- ikeboy 8y ago>He estimates he has around 30 terabytes of online data on hard drives in his home, the equivalent of "millions" of web pages. Wow.
- c3534l 8y agoNo one will face prison for making these documents public in the first place, I'm sure.
- Cofike 8y agoThis is pretty disgusting. The provincial government should be absolutely ashamed of themselves.
- komali2 8y ago>Officers took her 13-year-old daughter to question her in a police car. Why are the cops allowed to do this? Why do you have to be "rescued" by your lawyer in order to not be questioned by the police without legal representation? Not sure how it works elsewhere but the cops badgered the fuck out of me until my lawyer finally got to the station and chased them out. So, if I was a 13 year old on the way to school and thrown into the police car, they could just do that until I crack?
- makecheck 8y agoWhat is it about headlines involving charges that love to focus on “facing prison”. At the very least this should indicate the RANGE of punishments, and there is a hell of a range. From the article, he’s been charged with “unauthorized use of a computer”. IANAL but there would seem to be at least two possible interpretations of this charge [1], and the “Summary Election” variant has a MAXIMUM punishment of $5000 fine or 6 months. The other interpretation “Indictable Election” is a maximum of 10 years. As with any case, details matter. Judges aren’t just sending every hacker to prison for 10 years. He may be judged not guilty (evil intent must be proven; then there’s his age, etc.), or given a way, way, way smaller punishment than this “prison” he “faces”. [1] http://criminalnotebook.ca/index.php/Unauthorized_Use_of_Computer_(Offence) http://criminalnotebook.ca/index.php/Unauthorized_Use_of_Com...
- dennisgorelik 8y agoAfter figuring out that they screwed up, government agents should have politely visit the teen, interview him, go through his computer together and delete compromised files. Then quietly fix the vulnerability. Instead they produced PR disaster by disrupting lives of a law-abiding family. These are signs of arrogance and incompetence of decision makers at that government department.
- bitmapbrother 8y agoI find the his story of "archiving the Internet" extremely amusing. Good luck with that defense. He was 19 at the time and knew exactly what he was doing - or should I say "archiving". He estimates he has around 30 terabytes of online data on hard drives in his home, the equivalent of "millions" of web pages. He usually copies online forums such as 4chan and Reddit, where posts are either quickly erased or can become difficult to locate. "I preserve things, I archive the internet. I have history on my computer, and all of that should be saved and preserved," he said.
- realusername 8y agoYou are not providing any argument against why he should not do that.
- jonathanwallace 8y agoIf you're frustrated by this story and live in Georgia, USA, you should immediately contact the Governor's office and express your concern and share that he veto a similar bill sitting on his desk, SB 315. https://action.eff.org/o/9042/p/dia/action4/common/public/?action_KEY=10692 https://action.eff.org/o/9042/p/dia/action4/common/public/?a...
- ersh 8y agoThis is really funny to see people comparing downloading a file to breaking into an unlocked window. You guys don't really have a clue on what Internet is.
- evincarofautumn 8y agoIt’s more like taking a photo of a public bulletin board with a hundred posts on it, where three of the posts contain private information and so shouldn’t have been posted. Anyone could have viewed the posts on the board one by one; he just copied them all at once for later viewing.
- bcheung 8y agoThe levels of security: 1) Formal methods and cryptography 2) Obfuscation 3) Litigation Looks like they chose the latter.
- deleted 8y ago[deleted]
- shkkmo 8y agoI assume it was the large number of requests over a short period from a single IP that drew their eye to it? I wonder how many other people found the same thing and slurped this data down in a more circumspect way before this kid was kind enough to expose this privacy breach for us?
- FroshKiller 8y agoThis story resonates with me. I faced a similar charge in college. I got indicted by a grand jury, and it was years before the DA dismissed the charges. Absolutely nerve-wracking, and I was innocent!
- Scoundreller 8y ago> Around the same time, his Grade 3 class adopted an animal at a shelter, receiving an electronic adoption certificate. > "The website had a number at the end, and I was able to change the last digit of the number to a different number and was able to see a certificate for someone else's animal that they adopted," he said. "I thought that was interesting." He's like, 20 years ahead of his classmates.
- FundThrowaway 8y agoFrom the article: "When he was around eight, he remembered playing around with the HTML of the Google search page, making the coloured letters spell out his name." Isn't the Google logo an image? Smells a bit fishy to me.
- hazeii 8y agoI make that about 11 years ago - the page was rather different then.
- FundThrowaway 8y agoIt was an image 11 years ago also. http://web.archive.org/web/20070106132559/http://www.google.com:80/ http://web.archive.org/web/20070106132559/http://www.google....
- govtransparency 8y agoI work in a US city government doing government transparency work. I have a title that can get people on the phone. What can I do to help?
- EamonnMR 8y agoThis is shockingly heavy handed. Would they try and extradite Sundar Pichai if Google's crawler happened to index the pages?
- stevew20 8y agoEach officer and official involved in this should face prison, as would any common burgler who holds a family at gunpoint in their own home.
- flashman 8y agoThis is crap. Late last year I found a public S3 bucket with 23,000 JSON files in it, which I used to make a visualisation: https://vimeo.com/249970399 https://vimeo.com/249970399 The reason I felt confident to do this was because there was no access control on the files and I'd reported it to PUBG Corp, with the bucket remaining public weeks later. Before people are punished for downloading unprotected information, the person who left it like that should be hauled up in front of the courts.
- some_account 8y agoAmerican culture strikes again.
- Nickg00617 8y agoJust like Aaron Swartz. Is it really necessary to send 15 officers and / or sentence people to 20+ years in prison for downloading freely available information? Aaron Swartz faced a longer prison sentence than most murderers within the US, and the sentence for murder in almost any other country in the world. Common sense has completely gone out the window in both policing, and the criminal justice system. Was anyone injured? Did anyone suffer financial loss? Fear to self? Any form of significant damage at all? The answer to all the previous questions is a definitive and resounding NO!
- amarant 8y agoTeenager facing prison for looking at poster the government (mistakenly) put up... Mandatory xkcd: https://xkcd.com/932/ https://xkcd.com/932/
- dandare 8y ago> His bedroom is upstairs. That's where police found him sleeping when 15 officers raided the family home last Wednesday morning. Calculate the cost of the 15 officers raid plus prosecution plus the damages to the teenager and repeatedly bash it over the head of the responsible officer in the next election. This is how to deal with this shit in democracy. Even if people are insensitive to someone else's freedom they are sensitive about their money.
- alex7o 8y agoI can give a very anecdotal example, where I live all the doors on the flat look the same, the just have small numbers over the door. Because the exit door is the same just without a number and it is next to the door of my flatmate. Because I was in a hurry I accidentally entered my flatmate room when I intended to get out of the flat. This is more or less the same.
- _pmf_ 8y agoI think people would be less upset about the teenager going to jail if the chain of highly paid Peter principle executives responsible for the files being accessible would also have to face any investigation at all.
- simonh 8y agoI've actually done a similar thing myself. When my wife was doing her Nursing degree she was downloading some documents she wanted to reference from an NHS web sites. The report for one year wasn't linked, so I checked the URL scheme, figured out what the URL for the report should be (only the date was different in the file names of reports for different years) and downloaded it directly. It never occurred to me I might be committing a crime.
- plopilop 8y agoIn France, we had a similar case, a computer guy with the pseudonym Bluetouff[0]. He downloaded loads of national agencies confidential documents, because they were available on Google. However, he was sentenced (3,000€ fine), because when he explored the website, he arrived on a connection page, thus realizing he should not have accessed these files, but continued anyway. I just hope for the teenager that he did not encounter any login page in his search (which seems unlikely because he used a script). [0] (in french): http://www.maitre-eolas.fr/post/2014/02/07/NON%2C-on-ne-peut-pas-%C3%AAtre-condamn%C3%A9-pour-utiliser-Gougleu http://www.maitre-eolas.fr/post/2014/02/07/NON%2C-on-ne-peut...
- Rotdhizon 8y agoThe most interesting part of this to me is that for the charge to stick, they have to prove he did what he did with malicious intent.Keeping in mind the article states that other employees of this business also viewed these classified documents and are facing no repercussions because the company states they did it on accident. While in every scenario this kid should get off completely, that very well may not be the case. The US is extremely stringent when it comes to cyber crime, more often than not they like to make an example out of people rather than show mercy. The technical writeup for this was spot on, it seems like the company is embarrassed and instead of admitting they severely screwed up, they are doubling down on trying portray this teen as some super high tech malicious hacker who was trying to steal government secrets. It doesn't matter how lax your security is, if you can convince the population that this teen was nothing but an unethical, scumbag hacker, no one will show him sympathy.
- kamranjon 8y agoIsn't this Canada though?
- hoc_opus 8y ago>At the family's request, CBC News is granting him anonymity because of his hope the charge will be dropped and his reputation preserved. The only thing about this article that didn't irritate me.
- hoc_opus 8y ago>At the family's request, CBC News is granting him anonymity because of his hope the charge will be dropped and his reputation preserved. The only part of this article that didn't irritate me.