5 ms·
It wasn't hidden though. Lets pretend the guy was a pest exterminator, hired to kill some bug infestation. He is given a keycard to access most of the building
by Prickle 3y ago
It wasn't hidden though.
Lets pretend the guy was a pest exterminator, hired to kill some bug infestation. He is given a keycard to access most of the building. As he is hunting down the nest, he finds a hole in the wall. Bugs tend to come through holes in walls, so he goes in to figure out whether what he is looking for originates there.
He enters the room on the other side, and looks around for other holes that might have bugs. He then notices a file with big red letters saying "TOP SECRET". Turns out he accidentally entered the maximum security file room. So now he leaves the room, goes to security and tells them what he found. Then gets arrested for 1 count of trespassing and 1 count of breaking and entering.
How is that fair?
- Levitating 3y agoExactly. As the original article states, he just didn't assume he'd stumble onto a sensitive database. > According to the defendant, the defendant has first assumed that the software on his customer's server will connect to a Modem Solution database that was only intended for his customer and contained only his data. From the read-out database name, this sounded quite plausible. However, the defendant quickly discovered that the corresponding database contained much more information.
- FrustratedMonky 3y agoExactly. Maybe he could just be exploring an API. It isn't hidden, maybe this is how I'm supposed to get data.
- lamontcg 3y ago> It wasn't hidden though. If a key is taped to the outside of the door that it opens, you still can't use it without committing a trespass. Not unless you got authorization to use it from the right person(s) first. Shitty security isn't a legal invitation.
- zilti 3y agoThe key was taped to the outside of the door explicitly to be used by the customer though.
- lamontcg 3y agoNo it wasn't intended for customer use, the customer wasn't supposed to be directly hitting that API. There was reverse engineering that had to happen before recovering the plaintext password. He was already someplace fairly iffy for him to be. It was much more like being on the front porch of a house you don't own and finding a key.
- eastbound 3y agoEnough with building comparisons. The vendor put the master keys of the main database in a publicly-accessible package. It’s insane. Of course the researchers tested the keys, to check whether it was true. If it can be proven that it was used for nefarious reasons, then ok for blaming him, but as far as we know, the researcher just used it to get convincing evidence and left the system. The company is to blame 100%, and the research should get an encouraging award for white-hat reporting. Not this.
- lamontcg 3y agoIf you're just a "researcher" and you're not a cop then your job isn't to get convincing evidence of anything.
- eastbound 3y agoIf you’re a company then your job is to keep our bank accounts safe. See, I can do it too. Now that we’ve made clear that no-one is doing its job, YES, free citizen should be able to try to poke into the awful security of corporate IT systems and report it in good faith without even spending a second dealing with trouble.
- lamontcg 3y agoNo it really doesn't work that way. Companies don't go around testing the physical security of the banks that they use. They rely on the legal system and insurance to deal with any failures that the bank has. The right to pen test businesses doesn't actually exist.
- Prickle 3y agoI think an electronic keypad works better as a example. You get to a door, and there is a postit note on the door saying "Keycode is 2424". You know your job is in the building. Your keycard let you into the room with the door. Therefore, if this door lead to a "high-security" area, surely they wouldn't put a postit note there? Maybe, as the bug exterminator, or maintenance person, it is expected that I should be able to enter that room?
- lamontcg 3y agoExcept that this is an API which is not yours that you've found by reverse engineering. You're constructing an analogy where the authorization surface is much less distinct where you're already allowed into the building because that makes the surface much less distinct. That analogy isn't at all obvious to me and I don't think you've offered any rationale for why that is more appropriate. Once you start playing around with someone's remote API then I'd strongly advise you to consider it more like a door around the outside of a building. If you want to argue about that with me, then you may wind up arguing about that with a judge.
- d1sxeyes 3y agoHmm, big caveat there is that in most jurisdictions that would only be considered trespass if you’ve been pre-warned that you’re not allowed in. The “key” analogy though is a bit stretched. It is clear that here, the credentials were used in a way other than intended. The questions are now rather “is it reasonable to expect that a person interacting with a website normally would reasonably be permitted to use anything sent to them by that website in any way they choose?” A lot of us here are more tech-minded and would likely say “yes, if you don’t want people using credentials, don’t provide them”. The courts on the other hand may take a different view and say “well we already restrict what people can do with content on a website through copyright laws, this person should not automatically have the right to use those credentials in any way other than the way provided”. It will become even more complicated if the website has terms of service which clearly state something which has a similar technical meaning to “no trespassing”’s physical meaning.
- User3456335 3y agoIn that case, it's his job to enter holes. Nobody asked this developer to go through any holes. If you see a hole in your hotel room leading to another room, you don't go through it to see if there is anything to steal, even if you go through holes a lot for your job. You inform the owner that there is a hole.
- Prickle 3y agoHis job was to debug the program though, so wouldn't that literally be all about poking around holes? His job was to solve a problem with a database's log files. He found another second database. "Maybe this second database is causing duplicate log files?" so he goes in and looks. It makes sense to me. Based on the german article: (machine translated to english) > The software of Modern Solution had a database of the defendant's customer "fully littered with log reports," says the defence lawyer. His client was then given the order from his customer to solve this problem. > The defendant then determined that the software from Modern Solution established a MySQL connection over the Internet to the servers of the Gladbeck company. ...the defendant has first assumed that the software on his customer's server will connect to a Modem Solution database that was only intended for his customer and contained only his data. From the read-out database name, this sounded quite plausible. > However, the defendant quickly discovered that the corresponding database contained much more information. It later turned out that the data here was included Modern Solutions customers and from all end customers whose online shops were included. According to his own statement, the defendant had directly separated the database connection when he discovered that he had access to other customers' data. > the programmer contacted the affected company with the help of a tech blogger, which then closed the security gap and displayed the programmer at the police.
- Anamon 3y agoTo disconfuse: the "displayed" in the final sentence is a mistranslation from "anzeigen", which means pressing charges. "Thank you for saving us from liability hell and damages by helping us fix our shit. Police officers should arrive at your door shortly." I hope this company ends up paying dearly for this. Anything else would be a devastating precedence for information security. A business like that has no business staying in business.