5 ms·
A security concept so vulnerable to this should be the real crime. Kids like to troll, this has always been the case and will always be the case. I am quite ann
by Slikey 7y ago
A security concept so vulnerable to this should be the real crime. Kids like to troll, this has always been the case and will always be the case.
I am quite annoyed the internet culture is more and more invaded by these lawyers. The internet has always and should always be built on the concept that whatever can be exploited will be and the people who open themself to exploits carry the majority of blame. Maybe that's just my wishful thinking for a more wild west anarchistic internet...
- alharith 7y agoSo you wish that the digital world, a place where the majority of the youth are spending an ever-increasing amount of their time, to be subject to a culture we wouldn't tolerate in the physical world? Perhaps first define an internally consistent worldview. The reality is the internet isn't this blank space for hackers experimentation and exploitation anymore (used to be one of those kids by the way). It's becoming more and more integral to people's lives. It can cause real harm to people. It can even cause the loss of life. These things need to be taken seriously much more so than our childish notions of some anarchistic society of hackers and trolls doing as they please. Save that for the playgrounds and the skateparks. The real world works differently.
- zeepzeep 7y agoIf you leave a door open in the "physical world", someone will enter. If you have easy to exploit vulns, you'll be exploited. I tolerate that logic in the real life. Ofc the people who enter are bad, but there will always be bad people, so you're to blame for not protecting against them.
- Veen 7y agoThat is true, but it is also true that people are rightly punished for doing so.
- prophesi 7y agoWhen it comes to technology, I trust NP-hard problems much more than any government's court system. Rooms are password-protected by default. If it must be public, enable the waiting room feature (though there are currently undisclosed zero-day's for it).
- belltaco 7y agoApply that to the real world, if someone broke into your house with a battering ram you wouldn't report the theft and intrusion, and would just try to build a 6 inch thick steel door?
- prophesi 7y agoSure, if it was as cheap and easy as setting a password I'd gladly build a 6-inch steel door.
- runawaybottle 7y agoThey are not bad, they are just rascals. Must we live in a binary world? The kids are going to do this, implement some good moderator tools for the host of these meetings so they can ban ips, disable features. Those moderating feature literally exist because this is the reality of trolling since the beginning of time. We’re a community of mostly professional tech workers, and even we need shit to downvote and flag stuff.
- crankylinuxuser 7y agoThere's a term for this. "Victim Blaming". Its also the same kind of excuses heard when a woman was dressing well and gets raped. Then the refrain is "she was asking for it", or "she deserved it with the way she dressed". Notice that if a front door is unlocked and someone goes inside, its still trespassing. Just because its easier to commit a crime doesnt make the thing not a crime. (Please note, that I'm making this argument in good faith. I'm sure many here have digitally trespassed on others' computer systems without permission. It's not "trolling"; its a straight-up violation of the CFAA.)
- allknowingfrog 7y agoIt's still trespassing, but it isn't breaking and entering. Visiting a public URL isn't hacking.
- crankylinuxuser 7y agoThat's definitely still to be argued. I would have a reasonable amount of privacy if I used a random GUID to provide a hidden link. In that implementation, the link is a username-less password. That's how Craigslist, Pastebin, and email resets for all sorts of services work. And that too goes to the heart of passwords are inherently obfuscation. But that's a discussion for another time.
- new2628 7y agoYou make an interesting parallel, but the fact that you call out trespassing through an unlocked door as a crime on a website called hacker news is remarkable.
- awinder 7y agoIf someone’s house is robbed because their front door was left unlocked you might admonish them for poor security practices, but no one really debates that the robber was in the wrong and committed a crime.
- DyslexicAtheist 7y agoleaving the front door, or your parked car window open, or your wallet on the table when visiting the toilet in the pub is illegal, and you can get fined for it in most countries. edit: couple of sources: AU: https://www.examiner.com.au/story/442855/police-warning-over-car-window/ https://www.examiner.com.au/story/442855/police-warning-over... DE: https://www.augsburger-allgemeine.de/panorama/Ein-offenes-Autofenster-kann-teuer-werden-id38919827.html https://www.augsburger-allgemeine.de/panorama/Ein-offenes-Au...
- RIMR 7y agoI am pretty certain that this isn't true. At least the "most countries" part. How would they even catch you? Do you live somewhere where the police go door-to-door checking locks? Because that's terrifying...
- deleted 7y ago[deleted]
- tych0 7y agoCitation very much needed. I've done all of these things in the rural midwest for many years. A lot of times I didn't even take the keys out of the ignition.
- belltaco 7y agoIs robbing a house with the front door open, or unlocked car or stealing wallet left on table legal in those countries?
- openasocket 7y agoTo be clear, that isn't something in all of AU, it's a local law in Tasmania: "The regulation was introduced to the Tasmanian Traffic Regulations in November 2009". And I'm not positive about the German article, but it seems to imply that's a local Munich ordnance. Oh, and none of this contradicts the main point, which is that nothing in those articles suggests that robbing an unlocked car is legal. EDIT: though interestingly, at least in some municipalities breaking into an unlocked car may be a lesser crime than forcibly breaking into a locked car. Still a crime, but basically you're charged simply with stealing rather than some sort of breaking and entering.
- ntucker 7y agoI wouldn't go so far as to say "the real crime," but I wholeheartedly agree that zoom should share some responsibility here. If we're going to routinely put children in a virtual space, that virtual space should be able to be secured for them. If an after-school children's program put children in a position where, say, sexual predators easily had access to them, we'd not only blame the sexual predators, but also the system that put the kids within reach to them. I've always been very surprised zoom has an easily-guessable meeting ID namespace. It's a user experience tradeoff, but in my opinion, either the meeting IDs should be sparse and hard to guess, or there should be passwords (or possibly both).
- runawaybottle 7y agoThe guessing the meeting ID thing is probably not the real vector. I’m positive college kids and k-12 kids are sharing the private links online and amongst themselves. In that case Zoom needs what any forum software inevitably has to implement: moderating tools. Meeting hosts should be able to ban ips, if they are getting hit via a proxy, the host should be able to mute everyone/disable sharing video of everyone, etc. It’s not that hard to mitigate this stuff, the key word being mitigate not ‘stop’.
- tomnipotent 7y ago> people who open themself to exploits carry the majority of blame So a homeowner or car owner that leaves their door opens should be responsible for burglaries? Someone that wears a nice watch that leads to a mugging? How about people that commit crimes take responsibility for them?
- Slikey 7y agoSince some people are entirely mistaking my point, here some more in-depth thoughts. We should hold the companies and individuals operating on the internet to the highest standard to prevent such security violations. I am talking about a balance of the barrier here. Guessing meeting IDs is such an obvious and trivial attack vector that it should be expected to be abused. We look at companies like Facebook and expect them to keep our data safe and if they don't, we hold them accountable even though they are a victim of a crime. Some comment equated that to victim blaming in case of rape and that is just an insane analogy. Obviously if there is a real world consequence and people having damage they should have the right to get compensated and that is why we expect providers and companies to keep logs, but honestly how do we expect services to develop the highest standard if they can pass the blame to an attacker. At least an equal part if not the majority should be the organization that engineered a vulnerability because in most cases these happen due to improper design. (See programming vs. civil engineering quality discussion) We are talking about a minor inconvinience through trolling easily fixed by a proper token system on Zoom's end. This is not what the criminal justice system should be prosecuting some teenagers for.
- mannykannot 7y agoZoom's inaction here seems to better fit the concept of an attractive nuisance than a crime.
- JoeAltmaier 7y agoEverybody 'operates on the internet'. We're going to hold everybody to the highest standards of security? This is silly. There's already plenty of law around contract damages etc. Is there any need to rail about this example, and propose new rules? If you can show monetary losses due to using Zoom, go ahead and sue. Using a free account? Then there's no contract between you and Zoom - has to be 'value received' to have a contract, and you didn't pay them anything. Since there are and have been alternative to Zoom for a decade, it's hard to make this some national priority.
- crankylinuxuser 7y agoI think its more of "Think of the children" argument cropping up. IIRC there was a few high profile naked people (primarily men) doing obscene things. And there was at least 1 porno track being played. Of course, it was all during k-12 zoom. Once you introduce sex crimes against children in a public (online) school room setting, all bets are off.