4 ms·
I'll argue the other side: It's more similar to finding a key hidden under the mat at someone's house. You can then contact the owner and inform them of the se
by User3456335 3y ago
I'll argue the other side:
It's more similar to finding a key hidden under the mat at someone's house. You can then contact the owner and inform them of the security issue but what you should not do is use the key to open the door and go in and see if there is really harm in you being able to enter. Because you might accidentally achieve the exact thing that a criminal wants such as finding a note with a password on it. You can then claim you didn't want to find it but the fact is that 1) you broke the law by entering and 2) you caused a malicious event (namely obtaining a password).
You can then pinky swear that you didn't already use it for any further malicious actions but that will be difficult to verify.
If I ever lose my key, I don't want people to enter my house to prove that they can. Inform me of how you obtained the key and I'll change the locks and make sure I don't lose my key again. If you do enter my house, expect me to press charges.
- hypeatei 3y agoIt's not similar at all. The key (connection string) was already given to him via the app and he was entering the house (database) on a regular basis. This would be like mistaking a door for the bathroom but find a closet full of gold instead.
- User3456335 3y agoHe had access to the key by looking at the source code. The key wasn't intended to be used by him manually.
- ryandrake 3y agoI wonder if there was some kind of software license that stated that the developer was giving the user the key but the user wasn't permitted to use it. At least in that case, he would have known the company's intentions. I don't think we can otherwise know for sure the company's intentions. If I leave the front door to my house open (or if I tape the key to the outside of the door, to further strain the physical key analogy), is it my intention that people just come on in? We have no idea.
- User3456335 3y agoAre you given a key if it is contained in the source code of a compiled binary that you are given?
- evilDagmar 3y ago...except it was not the source code. Apparently right there in the application in cleartext. If what the investigator intended didn't matter, then what the vendor intended doesn't matter, either. He literally opened the application binary in a text editor to look for clues (despite the fact that there are common tools like `strings` for this) and saw the credentials, and since he'd been specifically hired to fix a problem with the database, he used those credentials to connect to the database. `SHOW DATABASES` would be a perfectly normal thing to type at this point, and apparently once he saw that these credentials granted access to everything he immediately stopped and logged out. If his lawyers had been better this would have never made it to court. Liability should have fallen on the contract customer, but for certain the design of Modern Solution's software and application were nothing short of wildy irresponsible. If they really face no risk for this, it's time for all German companies to start contracting firms in other countries where idiots aren't allowed to leave thousands of customers data exposed to the first schlub who happens to notice them.
- deleted 3y ago[deleted]
- williamcotton 3y agoWell, the key was already “given to him” by the nature of leaving it under the mat. Oh, but this is a food truck that he’s been visiting on a regular basis so obviously he’s allowed to go in the back door, with full access to all the ingredients and poking around inside the cash register? Also, if you take someone else’s gold behind a door you unlocked with a key that isn't yours, it is called stealing.
- hypeatei 3y ago> leaving it under the mat. Nothing was "under the mat" since he was already using his PC to connect to the database with those same credentials. > if you take someone else’s gold behind a door you unlocked with a key that isn't yours, it is called stealing. Nothing was stolen, he informed the vendor of the issue immediately.
- PurpleRamen 3y agoBut he had no right to examine the app, or enter the database outside the app. Even if that is a simple task for an expert, it's still an obvious difference between legitimate usage of the app, and illegitimate usage of the database. Wouldn't that account as reverse-engineering, which is often also illegal?
- williamcotton 3y agoWe’re getting downvoted by the “I have no clue about how the criminal justice system works” brigade.
- Ensorceled 3y agoYou are getting down voted by people who understand that, while the situation is nuanced, it is NOT equivalent to flipping over the house mat at random house and entering it. It may not be totally akin to a security card opening more doors than it should, but it is entirely reasonable to assume that "the key in your copy of the app" is "your personal access key".
- williamcotton 3y agoWell, apparently the courts think it is equivalent, at least in Germany and the United States. That you favor one argument over another as your lens with which to side when it comes to really stupid analogies, including mine, is entirely in bad faith.
- hypeatei 3y agoSo your argument is that since the courts think a certain way, that we should accept that and move on?
- williamcotton 3y agoI agree with the courts. Most people so outside of a vocal minority on this forum. What is you plan if you disaggre?
- Prickle 3y agoIt wasn't hidden though. Lets pretend the guy was a pest exterminator, hired to kill some bug infestation. He is given a keycard to access most of the building. As he is hunting down the nest, he finds a hole in the wall. Bugs tend to come through holes in walls, so he goes in to figure out whether what he is looking for originates there. He enters the room on the other side, and looks around for other holes that might have bugs. He then notices a file with big red letters saying "TOP SECRET". Turns out he accidentally entered the maximum security file room. So now he leaves the room, goes to security and tells them what he found. Then gets arrested for 1 count of trespassing and 1 count of breaking and entering. How is that fair?
- Levitating 3y agoExactly. As the original article states, he just didn't assume he'd stumble onto a sensitive database. > According to the defendant, the defendant has first assumed that the software on his customer's server will connect to a Modem Solution database that was only intended for his customer and contained only his data. From the read-out database name, this sounded quite plausible. However, the defendant quickly discovered that the corresponding database contained much more information.
- FrustratedMonky 3y agoExactly. Maybe he could just be exploring an API. It isn't hidden, maybe this is how I'm supposed to get data.
- lamontcg 3y ago> It wasn't hidden though. If a key is taped to the outside of the door that it opens, you still can't use it without committing a trespass. Not unless you got authorization to use it from the right person(s) first. Shitty security isn't a legal invitation.
- zilti 3y agoThe key was taped to the outside of the door explicitly to be used by the customer though.
- seabass-labrax 3y agoUnfortunately, like many physical security analogies, there's no one correct way of translating the details from the software world to the real world. I think how close you think those two situations are depends on whether you consider the application to be an agent of the customer (like a personal shopper), or of the shop (like a salesman). Did: A - the programmer coerce the application (an agent of the shop) into accessing secret information (breaking into the shop warehouse), or B - the programmer ask the application (his own agent, a personal shopper) to go and look for interesting things in the database (shop's warehouse) for him, a privilege that the application (personal shopper) was afforded in advance by the shop? I personally think that A is a dangerous precedent to set for society. Treating any network-bound application as the agent of its creator would mean it was wrong to observe your computer (which you generally use for more than just accessing one online shop), and would therefore effectively kill FOSS.
- User3456335 3y agoHe didn't ask the application though. He changed the application or used information in the source code in a way that the shop didn't intend. So B is clearly not the case. But even just assuming that the fact that the app was using a key means that he can try to access other things with it is a dangerous precedent. Can I access your OnlyFans if you give me the password to your Netflix account and you use the same password for both? Can I access the company database directly if the app connects to it? There could be all sorts of confidential info on that server, perhaps the gossip of the customer service people about you or info about other customers.
- DANmode 3y agoIf the mat was in their driveway, maybe.
- pasabagi 3y agoThe word 'house' is doing a lot of illicit work in your metaphor. A better analogy would be if a bunch of families had decided to install CCTV cameras, then got their neighbor Garry to watch them. Unbeknownst to them, Garry was storing the tapes a lot longer than anybody imagined, was pointing the cameras so they looked into people's bedrooms, and he was selling some metadata to third parties, and he also kept the key to his house in a plant pot by the door. Some teenagers messing around, find the key, and have a look around. Suddenly, it's the teenager, not Garry, who's the problem here. That's how data breaches work at the moment. And because it's Garry's 'house', we all think of the company as the victim.