4 ms·
The thing is though, I think this is basically correct. They probably could prosecute the reporter if they really, really wanted to. Not that I think they could
by thinkharderdev 5y ago
The thing is though, I think this is basically correct. They probably could prosecute the reporter if they really, really wanted to. Not that I think they could actually convict someone who was obviously acting in good faith to report a security vulnerability, but security research of this kind seems like such a gray area legally speaking. In general we wouldn't treat an obvious flaw in physical security as a mitigating factor for theft. That is, if I drop my wallet in a public place it is still probably theft for someone to pick it up and take the cash inside.
To be clear, this is in NO WAY a defense of the way the government acted in this case which was both insane and harmful, but just to say that a lot of what makes things illegal is subjective judgements about intent. This is why professional pen testers (the careful ones at least) generally specify in very clear terms what the scope of their engagement is (and still sometimes end up getting arrested). I can only imagine that doing independent security research is a mine field.
- wizzwizz4 5y ago> but security research of this kind seems like such a gray area legally speaking. Security research in general is a grey area. “Security research” of this kind is like spotting that the entire database is on file in a public library, with confidential data “encrypted” using Pig Latin, then reporting it to the librarian.
- thinkharderdev 5y agoYou're right, I shouldn't have said "of this kind" because in this case I don't think any sane person would think this was nefarious. But my point was just that, to use you example, the only way you would know that said database had confidential information in it would be to "decrypt" it. Then it is a question of why you did that. Was it malicious? No, but a sufficiently bad faith actor my try to argue that it was so you should be careful. Take another example. Say you fire up Wireshark in on a public network like a coffee shop and see some unencrypted network traffic with confidential information in it. The packets were delivered to your computer and there for anyone to see. But why are you capturing traffic that wasn't intended for you (in the broader sense)? What if the traffic IS encrypted but with weak encryption that is easily cracked? As soon as you step off the path of "I am viewing information which was clearly meant for me" you're in a gray area. Of course as a society we should recognize that people who do these things and then responsibly disclose them are doing a valuable public service, but not everyone understands these things. Or in this particular case, some people are heavily incentivized to make bad faith arguments in order to deflect blame from their own screw ups. So it's worth being careful.
- wizzwizz4 5y ago> But my point was just that, to use you example, the only way you would know that said database had confidential information in it would be to "decrypt" it. While it looks obscure to the uninitiated, anyone with a day-to-day familiarity with Pig Latin (e.g. a schoolchild) would be able to just read the information straight off, with little-to-no conscious “decoding” stage. > As soon as you step off the path of "I am viewing information which was clearly meant for me" you're in a gray area. People say that, but the law is usually quite explicit about such matters. Your “grey area” is just ignorance of the law. (And I'll go on record as saying that the law around this is usually really silly.)
- derangedHorse 5y agoThis is not like dropping a wallet in a public place. This is literally the equivalent of sending your wallet to my house amongst other things that I actually requested. When you visit a website you are essentially trusting the website and giving it permission to download arbitrary data (in the form of HTML, CSS, and Javascript) to your machine. Now imagine if that website gave you more data than you intended to the point where it made you liable as an owner of something you neither intended to have nor wanted. In terms of delivering something malicious to someone under no presumption of its deliverance, it's analogous to the extreme case of someone shipping a whole bunch of cocaine in a package with a book that you ordered. If we want to get closer to the actual problem, it's like you finding a paper shipped with your book and seeing a whole bunch of social securities numbers on it that may have included your own! Now if you have reasonable indication that this list was being sent out to everyone who ordered books from a specific place, of course you'd want to inform the people sending books to stop doing this so you could feel safe about your personal information. Now imagine instead of protecting the information which has been going out to random people, the company decided to get angry and attempt to prosecute you for pointing out their negligence. It's absolute idiocracy. As one of the Missouri residents who had their social security number exposed in this way I'd be furious at those who were delivering it.
- thinkharderdev 5y agoRight, you should be furious at the people who created the site because they are absolutely at fault. But X is at fault for ludicrously bad security practices and Y exploited said bad security illegally are not mutually exclusive. But to use your example, if you accidentally ship you credit card to me amongst a bunch of other papers, it would still be illegal for me to sell the information on the dark web. Likewise, if the reporter in question took the SSNs and sold them on the dark web that would presumably be prosecutable as well. Now if I just took the credit card and returned it to you, I don't think any reasonable person would consider that illegal (and I certainly hope that no prosecutor would try and bring a case for it). My only point is that we ultimately are making judgements about malicious intent. To be clear I don't mean to imply this is just some misunderstanding either. Obviously the MO governor is just being a blowhard to try and deflect blame for a really bone-headed screw up. But I see a lot of discussions in security/hacker circles where people seemingly think that if security is bad enough, then whatever you do to exploit it cannot possibly be illegal. But I don't think that is true and people should keep it in mind.