3 ms·
Right, you should be furious at the people who created the site because they are absolutely at fault. But X is at fault for ludicrously bad security practices a
by thinkharderdev 5y ago
Right, you should be furious at the people who created the site because they are absolutely at fault. But X is at fault for ludicrously bad security practices and Y exploited said bad security illegally are not mutually exclusive.
But to use your example, if you accidentally ship you credit card to me amongst a bunch of other papers, it would still be illegal for me to sell the information on the dark web. Likewise, if the reporter in question took the SSNs and sold them on the dark web that would presumably be prosecutable as well. Now if I just took the credit card and returned it to you, I don't think any reasonable person would consider that illegal (and I certainly hope that no prosecutor would try and bring a case for it). My only point is that we ultimately are making judgements about malicious intent.
To be clear I don't mean to imply this is just some misunderstanding either. Obviously the MO governor is just being a blowhard to try and deflect blame for a really bone-headed screw up. But I see a lot of discussions in security/hacker circles where people seemingly think that if security is bad enough, then whatever you do to exploit it cannot possibly be illegal. But I don't think that is true and people should keep it in mind.
- CRConrad 5y ago> But X is at fault for ludicrously bad security practices and Y exploited said bad security illegally are not mutually exclusive. No, but even that wasn't the case here. When X has NO -- not even "ludicrously bad" -- security, Y can't have "exploited" anything, because there was nothing for them to exploit.