7 ms·
Disagree. “Hack” typically implies malicious intent so it kind of does matter. “Leak” probably would have been more appropriate since this appears to have been
by shevis 4y ago
Disagree. “Hack” typically implies malicious intent so it kind of does matter. “Leak” probably would have been more appropriate since this appears to have been the result of negligence rather than malice.
- deleted 4y ago[deleted]
- kodah 4y agoI have never in my life heard that hack comes with malicious intent. To me hacking is a generalized term for successful unauthorized computer system access.
- shevis 4y agoAfter giving this some more thought I think you’re right. I would even broaden your definition to include using authorized access in ways that weren’t originally intended by the computer system’s designers. I was trying to distinguish between breaches that result from intentional exploitation (malicious or otherwise) and breaches that result from negligence. Having thought about it a bit more, these things are not actually mutually exclusive. Many intentional exploitations take advantage of dumb mistakes (e.g. posting credentials in a public repo). As such, I take back my earlier disagreement: this is a valid use of the word “hack”.
- ZeroSolstice 4y agoMyself, I would agree with your earlier definition of this being a leak[1] simply using the definition. There wasn't a program created or exploit discovered that exposed previously private information, an authorized user posted to the incorrect privilege level location. [1] https://www.dictionary.com/browse/leak https://www.dictionary.com/browse/leak
- cowl 4y agoA leak by definition is something from inside. This was not. This was an exploit from outside actors that made this data available to the public. Note the difference: > accidentally posting credentials for Atlassian's Envoy setup in a public repository this was a leak. Using those credentials to then obtain other data and post them publicly-> this is the hack. A hack does not need to be complicated, just to accomplish something that was not intended.
- ZeroSolstice 4y agoI disagree that finding mistakingly posted credentials, logging in and performing an export task is a hack, hacking, or exploitation. All the functionality was already available as it would be for any authorized user. This is the equivalent of reading the user guide.
- shevis 4y agoUsing leaked credentials to access a system that would not otherwise be accessible is absolutely an exploit. Similarly, convincing a security guard to let you in to an area of a building that you aren’t allowed into is also an exploit.
- ZeroSolstice 4y ago> Using leaked credentials to access a system that would not otherwise be accessible is >absolutely an exploit. Can you go into this a bit more as I'm not seeing anything being exploited? Were the credentials not valid? Was exporting data not available to that authentication user? Did they elevate their permissions beyond what the original credentials provided? If I find $20 on the street and buy a lotto ticket and win, what was exploited? I used the money to buy an item that can be purchased with money. In this example would you be saying that finding the money was the exploit or using the discovered money to buy something? > Similarly, convincing a security guard to let you in to an area of a building that you >aren’t allowed into is also an exploit. I agree this is an exploit, aptly named social engineering. However in this example you started with nothing and "convinced" the guard to do something. This is different than already having the credentials. The equivalent for this example, to me, would be finding a persons office/building card and walking past the guard but I wouldn't see that as an exploit. Both the access control and guard are reacting accordingly to the expected inputs. I would view an exploit as going beyond the intent of the built-in/existing controls.
- ZeroSolstice 4y agoCan you expand on this a bit? A search on the internet provides plenty of examples of this, even a search in the dictionary[1]. Along with movies[2], books[3], and typical news reporting hack/hacking/hackers has been used to indicate malicious intent. You can debate crackers vs. hackers and that its the intent that differentiates them but its a moot point based on that very thin veil of separation. Similar to the title security researcher or pentester you only can believe whats presented publicly by that person, group or organization and you can never validate that they haven't sold access or exploits to anyone else. I would say your generalized term would be better understood as a security audit, pentest or bug bounty which would appear to represent a non-malicious intent to gain "successful unauthorized computer system access" as defined by the contract. [1] https://www.merriam-webster.com/dictionary/hack https://www.merriam-webster.com/dictionary/hack [2] https://cybersecurityventures.com/movies-about-cybersecurity-and-hacking/ https://cybersecurityventures.com/movies-about-cybersecurity... [3] https://www.amazon.com/Cuckoos-Egg-Tracking-Computer-Espionage/dp/1416507787 https://www.amazon.com/Cuckoos-Egg-Tracking-Computer-Espiona...
- cowl 4y agohttps://www.google.com/search?q=define%3A+hacking https://www.google.com/search?q=define%3A+hacking https://en.wikipedia.org/wiki/Hacker https://en.wikipedia.org/wiki/Hacker "Reflecting the two types of hackers, there are two definitions of the word "hacker": 1. Originally, hacker simply meant advanced computer technology enthusiast (both hardware and software) and adherent of programming subculture; see hacker culture.[3] 2. Someone who is able to subvert computer security. If doing so for malicious purposes, the person can also be called a cracker.[4] Today, mainstream usage of "hacker" mostly refers to computer criminals, due to the mass media usage of the word since the 1990s." Fortunetly there is a trend to revert back to the non malicous meaning of the word. See you are commenting on a "Hacker" news site. See https://hackaday.com/ https://hackaday.com/ See even "DailyHacks" or "LifeHacks" in a social non technical setting, etc. Hacking is simply fiddling with a system and making it do something that it was not designed to do.
- ZeroSolstice 4y agoYeah I understand the difference between the two which is why I mentioned them. Moving back to the non-malicious meaning seems like a moot point. The layperson doesn't care about the difference only the outcome. Which in most cases is they don't know you or have a business relationship with you and you are now accessing their system. If I was working within the pentester / security researcher space I would not be doing any work outside the bounds of an explicit contract/bug bounty program, etc as any access gained would be illegal access regardless of your "supposed" intentions. In my original comment I was looking for the OP to expand upon: "I have never in my life heard that hack comes with malicious intent" as that seemed odd given the books, movies and legal cases.
- wongarsu 4y agoThe employee leaked the credentials, but I'd argue that finding the leaked credentials, logging in, dumping the data into a file and publishing it with a note how you pwned the company is still a hack. Not a highly skilled hack, but still a hack.