10 ms·
State Bar of California addresses breach of confidential data
- danso 5y agoAccording to this LA Times [0] story, the records were apparently found on judyrecords.com, a project recently discussed in a Show HN [1] > State Bar officials learned about the posted records on Feb. 24. As of Saturday night, all the confidential information that had been published on the website judyrecords.com — which included case numbers, file dates, information about the types of cases and their statuses, respondent and complaining witnesses names — had been removed, officials said. > ...Full case records were not published. Officials said they don’t know whether the published information was the result of a hacking incident. Judyrecords.com is a website that aggregates nationwide court case records. edit: The "Info" link [2] on judyrecords.com has updates related to this event. It asserts that the confidential data was available on the CA Bar's own website: > These records were all (confidential & non-confidential) previously publicly available at https://discipline.calbar.ca.gov https://discipline.calbar.ca.gov (now offline). [0] https://www.latimes.com/california/story/2022-02-27/california-bar-investigates-possible-data-breach-after-discipline-records-published-online https://www.latimes.com/california/story/2022-02-27/californ... [1] https://news.ycombinator.com/item?id=30399881 https://news.ycombinator.com/item?id=30399881 [2] https://www.judyrecords.com/info https://www.judyrecords.com/info
- coding123 5y agoI thought something was off about that site. I doesn't seem fair or legal to just publish that data like that. I think in the era of go in and get things things should be "public". Now in the search engine age and data available at your fingertips we need to entirely change our public records laws... Immediately. edit: In fact a HN User said this with NO REPLY from the author of that Show HN: I have some records that are sealed, but show up in this database. So there are records that were once ‘public’ but are no more, but this database makes them public again. I think that website should be taken offline immediately.
- mistrial9 5y agoplease recall a basic motivation for the formation of the United States of America, versus the Kingdom of Britain under George III. In the legal system of Britain, all Crown records are SECRET unless cleared. Under the Federal Laws of the USA, all Federal records are PUBLIC unless classified. get the idea?
- 5ESS 5y agoBlame the state governments for publishing those records in the first place. Everyone knows that once information is published on the internet there is really no “undo” button. If judyrecords goes down another, perhaps less scrupulous, operator will release another similar site.
- wolverine876 5y agoWithout transparency, including public records, how do we hold the powerful accountable? Court records are public to prevent secret government courts from abusing people (among other reasons). How do we operate a democracy, which depends on citizens controlling their country? And most importantly, who does get access to the records? That exculsive access will give them a lot of power.
- SllX 5y agoSomething that stuck out to me about that website is that we really do publish a lot. If you ever had a speeding ticket, that’s a matter of public record now. If you ever had a parking violation, that’s a matter of public record. I mean to be honest, if you just have a car, I can probably find you on that website if I know your name. Also goes for divorces. By and large I agree with your take, but playing around with the search got me thinking that maybe we just make too much a matter of public record and that some things might just be too noisy, even if it isn’t the biggest privacy violation per se. Still mulling it over though, so I can’t say I’m committed to that position yet, feel free to talk me back.
- oh_sigh 5y agoI have owned a car in NY, FL, and CA, have been married, and have received parking violations in all 3 of those states, and my very unique name is not present at all on that website.
- sva_ 5y agoLet me guess... judyrecords.com collected these by iterating over some chronological id that didn't properly check if someone has read rights. edit: would love to check, but[0] > The State Bar Court Portal will be unavailable from February 25th to February 28th due to maintenance activities. During this time the Case Search and Court Calendar functionality will not be available. [0] https://apps.statebarcourt.ca.gov/dockets.aspx https://apps.statebarcourt.ca.gov/dockets.aspx via https://www.statebarcourt.ca.gov/Public-Records-Information https://www.statebarcourt.ca.gov/Public-Records-Information
- adolph 5y agoApparently the State Bar has been breaking the law. The State Bar announced today that it is taking urgent action to address a breach of confidential attorney discipline case data that it discovered on February 24. A public website that aggregates nationwide court case records was able to access and display limited case profile data on about 260,000 nonpublic State Bar attorney discipline case records, along with about 60,000 public State Bar Court case records. The site also appears to display confidential court records from other jurisdictions. Under California Business and Professions Code 6086.1(b), all disciplinary investigations are confidential until the time that formal charges are filed, and all investigations are confidential until a formal proceeding is instituted. The nonpublic case profile data from the State Bar appears to have been displayed on this public website in violation of this statute. It includes case number, file date, case type, case status, and respondent and complaining witness names. It does not include full case records. We do not yet know how many attorney or witness names were disclosed.
- akira2501 5y agoIs displaying those records in public the violation of the statute? Or was it merely allowing the documents out of their control? Such that.. now they're out, does the website actually have any obligation to follow the "Business and Professions Code?"
- user3939382 5y agoThis is probably a stupid question to those who work with these concepts often: can all the user data in the DB be hashed with the user’s password so that nothing is gained from a breach? Is this mostly a CPU resource problem or would would jwt architecture preclude that from working? (I haven’t built auth systems for several years)
- mwint 5y agoHashing would make the content irretrievable; something like XORing with the password would make the password recoverable if you know the content.
- krisoft 5y agoXORing with the password sounds just splendid :D Caesar is asking for his cipher back. That method wouldn't stop a determined 12 year old, let alone a competent attacker. Please use a properly engineered and implemented encryption instead of coming up with harebrained schemes.
- entelechy0 5y agoRight, which is why you would never XOR in this manner, and would hash instead. You don't want the password or content retrievable that easily.
- jaywalk 5y agoThe reason we can store and use password hashes is because the user provides their password every time they login. So we hash the password they provided at login and compare that to the hash that was stored. We can't determine what their password is based on the hash alone, which is why we couldn't hash all the user data in the DB with their password and store that.
- rahimnathwani 5y agoMost systems store data to which more than one user needs access. Most systems will restore access for a user who forgot their password.
- 5y ago
- ejb999 5y agoDoesn't sound like a breach to me - sounds like the state bar association inadvertently gave out the information, and now they are looking for someone to blame - someone else that is.
- 5ESS 5y agoIt wasn’t a breach. Those records were publicly available. It’s a shame the site’s operator complied with the takedown request. Unfortunately that’s what happens when you use a US hosting provider and domain. In the interest of transparency, site operator should consider migrating the site to a provider outside of US jurisdiction and/or making torrents of the record data that can’t be simply taken down.
- LordDragonfang 5y ago>Those records were publicly available. The very first paragraph of the article seems to contradict that. Do you have a source that says otherwise?
- deleted 5y ago[deleted]
- dahfizz 5y ago> Was this a hack? And how did this happen? > We do not know yet. The State Bar’s Odyssey case management system software vendor, Tyler Technologies, has been tasked with investigating what happened, taking the steps needed to rectify the breach, and ensuring something similar does not happen again. The State Bar also retained a team of IT forensics experts to assist in our investigation. > The site owner claims that the State Bar’s confidential and public case records were all previously available at a public URL. Is this true? > The State Bar Court website allows the public to search for publicly available case information. The extent to which the external aggregating website was able to obtain nonpublic information that was stored in the Odyssey case management system is still being investigated. It sounds extremely likely that the state bar had a website misconfigured, and the automated systems of the aggregation site sucked down all the data it was technically (but not legally) given access to. https://www.calbar.ca.gov/About-Us/News/Data-Breach-Updates https://www.calbar.ca.gov/About-Us/News/Data-Breach-Updates
- cyral 5y ago> We apologize to anyone who is affected by the website’s unlawful display of nonpublic data Sounds like Missouri teachers SSN leak again... The website that judyrecords scraped, discipline.calbar.ca.gov, contained all of these "nonpublic" records for anyone to see.
- stefan_ 5y agoIt can be legal for you to scrape something yet very illegal to reproduce it. This applies even more when the site you scraped didn't have permission to show the data in the first place. Their mistake does not rise to be your permission; if it was my data, I would have as much a claim against you as them. "The software did it" is not an excuse.
- robertlagrant 5y agoThe software didn't do it, indeed. The custodians of the data who allowed private data to be made public did it.
- cyral 5y agoI'm assuming the owner of this site has permission to reproduce court documents from each source, generally these types of documents are public record and can be reposted. It sounds like whoever configured this portal where the public can view documents misconfigured it and allowed for private documents to be shown, without any indication that they were supposed to be private.
- gnicholas 5y agoOn a related note, the California Bar website employs dark patterns that mislead members into paying inflated annual dues. When you renew your membership, there are a variety of addon payments you can opt into by checking boxes for these items. Then, on a later page, there are various addon payments that you have to opt out of. Making things even trickier, these aren't pre-checked boxes, which might lead the user to realize he needs to uncheck them. Instead, there is a list of "adjustments" with a dropdown menu for each. The dropdown defaults to "none", which would lead users to think that they are not paying for an extra item. But when you click on the dropdown, you see the option to "deduct $x" if you don't want to pay the additional fee. I've never seen a dark pattern like this anywhere else. Perhaps the folks who run the calbar website could spend less time finding ways to trick members into overpaying and more time securing private information.
- calrizien 5y agoI noticed this too while trying to renew my bar dues. Its so devious. It degrades the whole profession when the gatekeeper is obviously trying to scam you.
- gnicholas 5y agoAnd it's been this way for at least two years. This isn't an innocent fleeting mistake.
- robertlagrant 5y agoIt's a sad day when you realise most things are like this.
- kingcharles 5y agoI've seen similar, but it's rare because it is such a dark pattern, and on a more high-profile site that nail would get hammered down pretty quickly. I was going to joke that you're a lawyer, you should sue them, but they're not doing anything illegal, just very shady.
- 5y ago
- bastardoperator 5y agoSurprised this site isn't managed by CDT (https://cdt.ca.gov/ https://cdt.ca.gov/)
- deleted 5y ago[deleted]
- reset-password 5y agoWhy is it so impossible for these people/organizations to accept that they made a mistake and own up to it? The entire response by the State Bar of California is nothing but a deflection of blame that rests solely on themselves and their chosen vendor(s). What are they going to do next, call Missouri's governor and ask for the playbook to follow? The humans behind the scenes at the bar are looking incredibly pathetic here.
- vore 5y agoThey did, see the update: https://www.calbar.ca.gov/About-Us/News/Data-Breach-Updates https://www.calbar.ca.gov/About-Us/News/Data-Breach-Updates They have nothing but praise for the judyrecords owner, actually!
- xbar 5y agoAgreed. Closing with "Law enforcement has been notified" doubles-down on "we published everything but maybe if we can get somebody charged for a bogus crime then we won't look so stupid."
- KarlKemp 5y agoThey are lawyers. „Pathetic“ is the after-shave they use. “Liability” is the nickname for the kid they secretly loath. “Blame” is a verb.
- sva_ 5y ago> Why is it so impossible for these people/organizations to accept that they made a mistake and own up to it? Maybe they accept it, but just don't admit to their mistake. Seems to be a growing trend, unfortunately. Perhaps the result of a society who more and more punishes people for admitting to their mistakes, rather than rewarding them for admitting to it and learning from it. It's very sad to me, that this seems to be getting so much more common.
- deleted 5y ago[deleted]
- duped 5y ago
- tossitafter 5y agoI used judyrecords to check myself after it was posted here. I had a charge from over a decade ago listed as a felony that had been reduced to a misdemeanor. The state system shows as a misdemeanor. I paid good money to an attorney for a misdemeanor. I'm not sure why judyrecords shows it as a felony, and it has me wondering about the effectiveness of my legal defense. edit: If you're wondering if I'm a hardened criminal with a wake of victims left behind, the answer is no. I was 22 and got caught in the midwest with an ounce and a half of cannabis. This website, as far as I'm concerned, is displaying inaccurate information about me that that could have serious negative consequences for myself.
- duped 5y agoJust spitballing, it's just a dump of records. They might have records for your arrest, arraignment, charge, plead, whatever (not sure what's in your state). When I was looking through it, it didn't seem like a comprehensive or organized set of documents by case. You might want to check with a more thorough source, like a criminal background check agency.
- deleted 5y ago[deleted]
- jahewson 5y ago> We take our obligations to protect confidential data with the utmost seriousness Really?
- rahimnathwani 5y ago"Under California Business and Professions Code 6086.1(b), all disciplinary investigations are confidential until the time that formal charges are filed, and all investigations are confidential until a formal proceeding is instituted." Does this part of the code apply to everyone, or only the folks in charge of the investigations, or in charge of safeguarding the information? If someone is in a bar and overhears a Bar employee talking loudly about an investigation, do they have a legal duty to keep what they heard confidential?
- chrismcb 5y agoNo. Once confidential information is leaked, it is no longer confidential. The person who leaked the data can be in trouble. But the person who received it isn't... Assuming they didn't break any laws receiving it. In your particular example, the Bar employee shouldn't have been talking about confidential stuff in public, where it can be overheard. There is no expectation of privacy in a bar, so the eavesdropper is most likely on the clear.