11 ms·
Article/title is a bit confusing and perhaps borderline clickbait, so... If I understand correctly it seems like his crime was *using* the exposed database cre
by wackget 3y ago
Article/title is a bit confusing and perhaps borderline clickbait, so...
If I understand correctly it seems like his crime was *using* the exposed database credentials to log in to the third-party database server.
So he wasn't charged for simply "exposing" the credentials as the title says, but actually using them to poke around.
- bluefirebrand 3y agoIt is basically impossible to know what a system is without accessing it and looking around. It is like being given a key card for security clearance in a building. You assume any door it opens is a room you're allowed to be in. If security finds you in a room you aren't supposed to be in, is that your fault? Or whoever gave you the card with the wrong clearance level? Also how about the situation where you open a door, look inside, immediately realize you're not supposed to be there and then report it to security? Should you be punished?
- secondcoming 3y agoI don't see why an investigation into excessive logging requires running queries on a database.
- lcnPylGDnU4H9OF 3y agoIf they connect with a desktop application, said application might run some queries against `INFORMATION_SCHEMA` in order to display schemas, tables, and columns. If the investigation is open-ended enough ("we have no idea so just figure it out"), then it might seem reasonable to connect to the database to see what it's about. It's already hard to see the malice in their actions but it's harder still when I consider that they immediately alerted the company who made the error. Even more when I consider that the company fixed the error. This developer did the company a favor and they had charges filed against them over it.
- formerly_proven 3y agoThis is a high profile case because they went public with it, but I assure you, stuff like this happens a lot more frequently than you might think (the public can attend court proceedings in that country, but they are neither published nor publicized for the vast, vast majority of cases). It's why anyone remotely familiar with the legal situation (not just in germany, many countries have similarly broad laws, like CFAA or the Computer Misuse Act) will tell you to never ever, ever do vulnerability disclosure yourself to the responsible party.
- ptx 3y agoWhat should you do instead? How would someone familiar with the legal situation disclose a vulnerability?
- hnbad 3y agoIt doesn't have to be malicious, it can just be negligent. What he did was essentially digital trespass. He assumed the database only contained data for his client but he knew the database was hosted and operated by the vendor and did not ask for permission to access it. Instead he analyzed the software (in the most basic way, i.e. opening it in a text editor and looking for plaintext strings) to retrieve credentials and used those for accessing the third-party system without permission. It's of course ridiculous that the police and prosecution called this "decompilation" but I agree with them to a point: the password didn't spontaneously fall in his lap, he deliberately went out to look for it in the software itself, even if he found it in the most trivial way possible. And then he decided to use those credentials to access an external system he must have known did not belong to his client without asking for permission. This rapidly enters grey hat territory and crosses a legal line. I think it's right to be appalled by the mere act of opening the file in an editor being considered suspect by the prosecution but I also think it's important to understand that it wasn't just the software analysis that got him into trouble, it was the digital trespass that this enabled.
- HL33tibCe7 3y agoFinding a key on the floor and then using that key to break into a building is illegal, and for good reason.
- judge2020 3y agoIt's more like you're given a keycard to a building that says "Floor 20" but then find out it has access to all the floors and telling the building security about it. All they did was 'open' the 'elevator door' here revealing the access they mistakenly had. It doesn't sound like they snooped through other customers' data or downloaded anything.
- User3456335 3y agoYou're not really given it though. You found it and even though nobody ever asked you to use the key card you used it on the floor that nobody ever asked you to go to.
- hooverd 3y agoThey weren't not allowed either, though.
- feanaro 3y agoYour machine regularly uses that key to access what's behind the door on your behalf; there is no reason you shouldn't be able to access it yourself. If you don't find the key and realise it's actually a lost one, leading to a potentially dangerous place, someone else will and they won't be benevolent.
- Almondsetat 3y agoIf you don't know what the key does who are you reporting it to?
- contravariant 3y agoIf that's unclear the answer is simple, destroy the key. Otherwise you can try to be a good neighbour and let them know. You do not get to just open random doors and see what's going on. The real issue here is whether this instance is comparable, not whether opening doors with lost and found keys is a bad thing. The real difference is whether they 'found' the key or if they were handed it. In this case I'd argue they were handed the key, as there was no plausible protection mechanism preventing them from accessing the key. It wasn't lying around somewhere forgotten or secret, it was in plain sight. And frankly we need some good Samaritan laws for cases where someone responsibly disclose a vulnerability without doing further harm, even if what they did was illegal on its own it certainly should not be in light of the fact that they responsibly disclosed the vulnerability.
- acangiano 3y agoTroy Hunt called that behavior "way too far into the grey for my comfort" in a recent post about the massive Naz.API leak.
- Gelob 3y agoSays the guy who gets emailed hacked database from cybercriminals
- itishappy 3y agoRight, the guy who's job is receiving hacked databases of user credentials from cybercriminals argues actually using said credentials would be going too far.
- contravariant 3y agoIn that case the keys he has were definitely not his to use. Here we're looking at someone handed an API key by a company and then using it to access the API. A lot of this depends on whether you view a phone as a device running third party' programs on behalf of the user, or a device that third parties allow users to run software on on behalf of the third party. A lot of society is moving towards the later view, which is of course fundamentally wrong.
- posterboy 3y agoIt's rather different. Some time I saw my neighbour left the key sticking outside. Doesn't feel like an invitation to me. Also, garden doors aren't necessarily locked and I think this is difficult to legislate. German law applies to TFA so compare Hausfriedensbruch (criminal code): the adverbs of choice are "widerrechtlich" like undefined behaviour; "ohne Befugnis", essentially without permission, e.g. in case of not a lawful entry of police. Official translation actually distinguishes "unlawful" and later "without permission". I always feel it says, like, illegal entry is illegal. Vandalism uses the same words, section 303a applied to computer sabotage as "Data manipulation". https://www.gesetze-im-internet.de/englisch_stgb/englisch_stgb.html#p1274 https://www.gesetze-im-internet.de/englisch_stgb/englisch_st... https://www.gesetze-im-internet.de/englisch_stgb/englisch_stgb.html#p2817 https://www.gesetze-im-internet.de/englisch_stgb/englisch_st... PS: the relevant section is 202a "Data espionage", following another comment. https://news.ycombinator.com/item?id=39047283 https://news.ycombinator.com/item?id=39047283 https://www.gesetze-im-internet.de/englisch_stgb/englisch_stgb.html#p1957 https://www.gesetze-im-internet.de/englisch_stgb/englisch_st...
- posterboy 3y agoThis deserves further commentary. In my humble opinion, what really grinds my gears is the abuse of the letter of the law, “circumventing the access protection”. If your fence has gaping holes, it's not a functional fence. Since this is hackernews, graffiti "vandalism" is still a good example. The only protection of public facing walls is law enforcement, which is spotty. Private property such as trains may employ fences and security, which can be circumvented. Train stations and trains in service have to open anyhow. Terms of Service may explicitly forbid pollution, defacement, however you want to call it (this holds by analogy if you leave logs on the server, my point being, as it were, that security is a process). The law makes a practical difference for each of these cases, but the spirit of the law is the same in each case and the baseline is that the law is whatever is deemed appropriate by the powers that be, the finder of facts, population as represented by select individuals, the common joe. This, in turn, is supposed to be enshrined in constitutions of sorts. In sum, “unlawful" (“widerrechtlich” or “unbefugt”) derives in different ways from constitutional rights. In the given case, subsection 202a is based on confidentiality (Art. 10 GG "privacy of correspondance"), but in my example (guilty as charged) the laws against vandalism are based on property (Art. 14 GG). In result, your comparison is a type error for me (as is circumvent if access control is a process). https://www.gesetze-im-internet.de/englisch_gg/index.html https://www.gesetze-im-internet.de/englisch_gg/index.html Comparative Law is a real thing, by the way, that is most foreign to me, but I make due.
- User3456335 3y agoI'll argue the other side: It's more similar to finding a key hidden under the mat at someone's house. You can then contact the owner and inform them of the security issue but what you should not do is use the key to open the door and go in and see if there is really harm in you being able to enter. Because you might accidentally achieve the exact thing that a criminal wants such as finding a note with a password on it. You can then claim you didn't want to find it but the fact is that 1) you broke the law by entering and 2) you caused a malicious event (namely obtaining a password). You can then pinky swear that you didn't already use it for any further malicious actions but that will be difficult to verify. If I ever lose my key, I don't want people to enter my house to prove that they can. Inform me of how you obtained the key and I'll change the locks and make sure I don't lose my key again. If you do enter my house, expect me to press charges.
- hypeatei 3y agoIt's not similar at all. The key (connection string) was already given to him via the app and he was entering the house (database) on a regular basis. This would be like mistaking a door for the bathroom but find a closet full of gold instead.
- User3456335 3y agoHe had access to the key by looking at the source code. The key wasn't intended to be used by him manually.
- ryandrake 3y agoI wonder if there was some kind of software license that stated that the developer was giving the user the key but the user wasn't permitted to use it. At least in that case, he would have known the company's intentions. I don't think we can otherwise know for sure the company's intentions. If I leave the front door to my house open (or if I tape the key to the outside of the door, to further strain the physical key analogy), is it my intention that people just come on in? We have no idea.
- akira2501 3y ago> It is basically impossible to know what a system is without accessing it and looking around. What reason do you have to needing to know what a system is? Just because you think you have a password for it? > If security finds you in a room you aren't supposed to be in, is that your fault? It depends. Do you know you're not supposed to be in that room? > Should you be punished? I've run into this exact same situation three times. One was a hard coded SSH key to a root account, two were hard coded passwords. In all three cases, I simply contacted the vendor, let them know I had this key, coordinated disclosure with them, and then told them what the password was and where I found it. In all three cases, the disclosure was enough for them to go wide eyed, immediately understand which systems were impacted, and then quickly leave the call to go fix the problem. There is _zero_ reason for you to _use_ exposed credentials if you find them. It adds nothing to the "security research" you may be doing.
- andersa 3y agoBut in this particular case, it sounds like it wasn't known to him that it was an exposed credential. He thought it would just access his own data, so there would have been no reason to report anything to the vendor at that point. The access to protected data here was accidental.
- akira2501 3y agoHe thought the credentials, which were hard coded into the app, for an mysql server, somehow accessed only his data? That's hard to believe. Which seems like the defense understood, because they offered that the "name of the remote database" seemed like it could be related to his customer that he was contracted to. In the end, he's going to pay 3,000 euro, and made an example of. He could have received 3 years in prison. So slightly unfair to everyone but hardly worth stretching credulity to defend.
- andersa 3y agoHm, I think I misread the article. It just says it was accessing a database named after the client, not that the user/password suggested being specific to the client. So you're right, it being hard coded then suggests it can likely access all of them. He should have stopped there and reported the issue. While paying a fine of 3000€ is likely without consequence for most programmers, that's not the only thing that happens. It now shows up on his criminal record and would be considered in any future case against him.
- qwertox 3y ago> It is like being given a key card for security clearance in a building. Not really. Apparently they interpret the software which has the embedded key as an "agent". So it's more like you go into a building and get assigned a person who opens the door and retrieves the stuff you want from there for you. Turns out that the person was on drugs and promptly fell asleep ("malfunctioning") and you take the key to get into the room but it turns out you've just witnessed that this company is a huge scam. Now they want to sue you.
- drannex 3y agoI stand by the phrase "Hacking Is Not A Crime". It's what you do with the data once you have access to it. If you do nothing, it shouldn't be a crime, the crime should be the, presumably, nefarious usage if used.
- itishappy 3y agoI would not recommend trying that defense in a courtroom.
- drannex 3y agoIt has been tried, and been successful in many cases (on mobile, so not linking at this time). A proper example is in respect to right to repair laws and court cases. This is one of the primary arguments in the ability to hack your own devices, and others in the cases of grey/white hat hacking defenses.
- sterlind 3y agoYou can do a lot of damage by simply accessing data: blackmail, state or industrial espionage, insider trading, HIPPA violations, obtaining signing keys or passwords for lateral movement, etc. All those require additional intent, to be fair, but it's hard to prove intent and much easier to prove access. And there are very few legitimate reasons to access someone else's private data, and many nefarious ones.
- drannex 3y agoYou missed the second part, which is that the use of the data is the crime, not the access to it.
- User3456335 3y agoAre you hereby giving people permission to hack your devices as long as they only use it to do good?
- deleted 3y ago
- soraminazuki 3y agoThere's nothing confusing about it, it just doesn't frame it in the way you prefer. From the perspective of the developer, it's natural to assume that the password was in place to prevent non-users from accessing, not legitimate users. After all, the credential wasn't hidden or obscured in any way. When it became clear that users weren't supposed to have access, it was reported to the vendor. Am I missing something here? On one hand, there's a developer doing their job. On the other, there's another "embarrassed" company retaliating and intimidating would-be bug reporters. It seems crystal clear what's going on.
- Sparkyte 3y agoThat isn't hacking which the title implies. Hacking is more involved and exploitation of systems. This is just taking the keys and unlocking the door to your benefit.
- why_at 3y agoYes, he logged into the server using the credentials embedded in the app. Since the server contained information from other users, this would clearly be some kind of crime if used this access maliciously or maybe even if he just logged in knowing that he wasn't supposed to be allowed to. But I think the salient point here is whether or not he could have known that before logging into the server. Since the credentials are in the app, should he assume that the company's security is so bad that this would give him access to all their customer data? He is obviously allowed to use the app, and the app uses these credentials so it's not too much of a leap for him to think that he should be allowed to use them as well. Regardless, I think the result of this ruling will clearly be bad for computer security. In the future maybe someone who finds a vulnerability like this won't report it out of fear of legal retribution.
- 2muchcoffeeman 3y agoI guess the moral of the story is, if you find hardcoded credentials, immediately inform whoever is in charge without actually using the credentials. Or can that still get you sued?
- tiluha 3y agoI'd probably not say anything. At most anonymously. I'm not taking the risk as i stand nothing to gain
- aqme28 3y agoI don't think the "hardcoded" part is at issue here. If this wasnt a MySQL database but an API that exposed other customer information, he would have the same moral duty to disclose and the same legal liability, I think.
- tptacek 3y agoMaybe not? Again, only speaking to US law, but your intent matters a lot here, and you have more plausible deniability sending API requests than you do making a direct connection to a database.
- dang 3y agoIf someone can suggest a better (more accurate and neutral) title, we can change it above. (It's best to use a representative phrase from the article body rather than making up new language; that's usually, though not always, possible.)
- qwertox 3y ago> but actually using them to poke around. This is true, but he believed that the database was held exclusively for the client, hence only containing data belonging to the client, who gave him permission to access his data. Apparently the name of the database also seemed to indicate this. As soon as he then noticed that it contained all the data of all customers, he disconnected.
- hnbad 3y agoIt doesn't matter what he thought was in the database or what it was for. He knew it was hosted and provided by a third party for use with that third party's software which his client was using. His crime wasn't accessing the data. His crime was accessing the data in a way he had not been authorized to do. As far as he was concerned, the investigation should have stopped at "there are hardcoded plaintext credentials here". But not only did he then also try if those credentials were correct, he also used those credentials to go spelunking. That's trespass even if he had reason to believe there were no other customers' data on that server.
- qwertox 3y agoWas the client not authorized to access their data with the use of the password, which the application managed for them? The password should have been a per-client password intended to protect the client's data from any foreign access, a key given from the service provider to the client in form of an easily usable application in order for the client to make use of the service.
- hnbad 3y ago> The password should have been a per-client password intended to protect the client's data from any foreign access, a key given from the service provider to the client in form of an easily usable application in order for the client to make use of the service. What should have been is irrelevant to the discussion. Yes, the security practices by the vendor were abhorrent and this jeopardized their customers' users privacy and they should be fined by the data protection agency for that. But that has no impact on what the contractor did. > Was the client not authorized to access their data with the use of the password, which the application managed for them? The client was authorized to use the software which accessed the data using the password. The client was clearly not authorized to extract the password, use it to connect to the database manually or through their own software and go spelunking. How could you possibly think that was authorized? Implicit authorization can always only be interpreted in the most limited way. It doesn't matter what he expected to find, it only matters HOW he accessed it. That's just how laws work.