3 ms·
Sounds to me like the database credentials were embedded in the application so presumably the application would log in to the vendors server as an intended acti
by a_dabbler 3y ago
Sounds to me like the database credentials were embedded in the application so presumably the application would log in to the vendors server as an intended action. Does this mean all the vendors users must be charged with hacking also?
- HL33tibCe7 3y agoThe clue’s in the name: “misuse”.
- dzhiurgis 3y agoIs there evidence he misused the data or the server? Did he download all the data and sold to third parties, spammed the hell out of existing users or anything like that? How is verifying the credentials misuse?
- HL33tibCe7 3y agoHe didn’t just “verify the credentials”. He was in the database making queries, viewing private data.
- feanaro 3y ago"Viewing" private data for purposes of verification of the issue. How about you just don't ship passwords in the application like some negligent troglodyte?
- dzhiurgis 3y agoHow do you find out it was private data without viewing it first? How is that misuse of data if you just view it?
- hnbad 3y agoExtracting credentials from a piece of software to manually connect to a server without authorization in order to go spelunking is clear-cut misuse regardless of what data you find on the server.
- the_why_of_y 3y agoThe customer who hired this consultant was authorized to read that data because it was their data, not the vendor's; it was just stored on the vendor's server.
- hnbad 3y agoHe was authorized to read that data. He was not authorized to freely access the server the data was stored on, or to extract the credentials from the software. This is an obvious difference that matters. I can't break into an AWS data center to access my data, even if I they didn't have any security and I knew exactly where my data is stored. Not because I could be seeing other people's data but because I'd be trespassing.