12 ms·
Charges dropped against pentesters paid to break into Iowa courthouse
- LeonB 7y agoThis has been quite a wild ride. Part of me says Wynn and De Mercurio could try to sue someone -- either their initial customer for not giving them sufficient safety, or people responsible for them being charged -- but then I consider that suing "The law" is such a famously bad idea that it's celebrated in song ("I fought the law and the law won.") Ultimately, I think they'll get some good conference talks out of it.
- thaumasiotes 7y ago> then I consider that suing "The law" is such a famously bad idea that it's celebrated in song ("I fought the law and the law won.") But that song is about armed robbery being punished by the law, not suing anyone. The lyrics aren't subtle: > Robbin' people with a six-gun > I fought the law and the, the law won Fighting the law outside the system by disobeying it is a totally different concept from fighting the law within the system by suing over it.
- ineedasername 7y agoWell, fighting the law outside the system is actually a bit more complicated. See civil disobedience, the civil Rights movement, etc as examples where laws were.deliberately broken to successfully fight against and change those laws.
- thaumasiotes 7y agoYeah, I agree that that's fighting the law outside the system. I don't think it's different from robbery in the same way that fighting the law from within the system is, I think they're similar in that regard. They're different in that robbery commands nearly zero popular support, making it a bad candidate for change through civil disobedience.
- ineedasername 7y agotrue, short of Robin Hood there's not much of a positive example of roberry as civil disobedience.
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- whatsmyusername 7y agoThey look great from my perspective. Coalfire will be able to hire on this event in a field with a -15% unemployment rate. If they’re smart they’ll both work this into lucrative speaking arrangements. Iowa can go tuck themselves in.
- gowld 7y agoThere are multiple laws. This issue was a dispute between two branches of government. That's a scenario where you can win. NYC /NYPD has a large budget for police brutality settlements.
- irjustin 7y agoAt first, I assumed I was going to be only angry at the justice system, but after understanding the contract document was split in 3 with very wishy/washy language, part of the problem is on the contracted company. This is why you have explicit language in your documents. It's not there for when things go well - it's when things go bad like this situation. In fact, I argue this is an expected outcome. How can you run a security contract that does explicitly illegal things w/o having clear language about what is supposed to happen. FWIW: - The pen testers should be ready to spend time in jail and be compensated as such. A piece of paper should not get you off free immediately. That thing needs to be verified, so expect it to take time. - Language in your doc needs to be clear exactly what will happen. The whole fiasco afterwards should not needed to have taken place. If the customers want 'more pen testing' charge them for it. Overall this is a great outcome. Just need to clean up the edges a bit.
- olliej 7y agoyeah, but the problem is this shouldn't have taken months to be dropped - the full info about the contract was available by the end of that week, and should have results in the charges being dropped then and there.
- bawolff 7y agoAlso make sure the people who hire you actually own the system being tested. Like if my neighbour hires some random to pentest my house for kicks, it doesnt make it ok for pentester to break into my house because they signed a contract with my neighbour
- p1necone 7y agoDepends, if the pentesters didn't ask for any proof that your neighbour owned and occupied the house then sure, the neighbour and the pentesters should be prosecuted. But if your neighbour lied and falsified documents to the point reasonable due diligence would have been fooled, perhaps the pentesters can be considered not at fault?
- 7y ago
- qaq 7y agoMight be safer to work for larger outfit with good legal department?
- noodlesUK 7y agoCoalfire is one of the larger more reputable orgs in this space.
- exabrial 7y agoLesson here is don't embarrass the prosecutor's office. These people aren't held accountable to anyone and they don't want that to change.
- sonotathrowaway 7y agoWouldn’t the lesson here be don’t perform any penetrates for courthouses in Iowa? They’ve shown themselves to be vindictive and petty, why exactly is their security worth risking my freedom?
- clort 7y agoOn the other side of this, surely your freedom is already at risk if the courthouse has poor security?
- ashtonian 7y agoI keep telling people the only solution is to get rid of the but nobody listens..
- SketchySeaBeast 7y ago> is to get rid of the but nobody listens Sorry, get rid of what?
- jakeasmith 7y agoDon’t worry about it. He got rid of it.
- blackearl 7y agoThat's why companies that don't pay and even sometimes prosecute white hats basically paint a giant target on their backs. All they've accomplished is ensuring that future security practices will be worse and they'll be less secure.
- guug 7y agoAbout 10 years ago, I stumbled across a local government website that leaked personal information about all registered citizens (including full names, civil id numbers, dates of birth, academic grades, etc). I didn't report it because I knew they would try to go after me. Fast forward to last year, the government decided to double down on their stance by making punishments harsher than most crimes of violence without carving exemptions for white hat researches. Unsurprisingly, my country's infrastructure was shown to be completely compromised by Snowden's (or Manning's) leaks.
- Aperocky 7y agoPunishment will not stop anyone - they won't find anyone to punish. It will simply lead to everything getting leaked and sold underground.
- Brave-Steak 7y agoI don’t know if this is a real option, but did you consider anonymously leaking it to the press?
- cesarb 7y agoIf you "stumbled across a local government website", you cannot "anonymously leak" it anymore, since your IP address is already on the web server's logs. After an "anonymous leak", it's the first place they'll look. The only good alternative is to keep quiet, and pray that nobody else finds it and anonymously report it to the press before the logs containing your IP address are rotated and deleted.
- moneywoes 7y agoWhat state if you don't mind me asking
- guug 7y agoNot in the US.
- parliament32 7y ago
- Pyxl101 7y agoWhy did it take so long to dismiss the charges? Wasn’t it obvious from the beginning that they had no criminal intent? (Or is criminal intent not necessary for this crime?) I would love to read some reporting about what was going on behind the scenes. Anyone have a link?
- dannyw 7y agoIt was a pissing contest amongst two sheriffs. The original first responders were going to let them go, and a new sheriff arrived on the scene and said the original state administrative office had no authority to authorize it for _his_ courthouse.
- lasky 7y agoAnd once again, any US organization allowed to use a .gov domain loses yet ANOTHER notch of credibility, and confidence in their competence.
- fyfy18 7y agoNobody here has mentioned the fact that they went through a locked door (well supposedly it was unlocked, they closed it, and they broke in to test it) even though their 'get-out-of-jail-free' letter explicitly said that was not permitted. I agree it took embarrassingly long to get the case dropped, but it seems like if they hadn't done this there wouldn't have been a problem in the first place.
- auiya 7y agoLast I heard the attrition rate at Coalfire was quite high. Issues like these I'm sure aren't helping.
- lightedman 7y agoCharges dropped? Time to file for malicious prosecution against the DA's office.
- cartothemax 7y agoThat county had a breach in late November of last year too. https://www.kcci.com/article/dhs-data-breach-in-dallas-county-affects-more-than-4000-peoples-information/30657725 https://www.kcci.com/article/dhs-data-breach-in-dallas-count...
- korethr 7y agoSo, are these guys going to be at DefCon, with a presentation about their experience, and lessons to share with the wider security community? Because I would be interested in watching said presentation.