4 ms·
Yes, he logged into the server using the credentials embedded in the app. Since the server contained information from other users, this would clearly be some ki
by why_at 3y ago
Yes, he logged into the server using the credentials embedded in the app. Since the server contained information from other users, this would clearly be some kind of crime if used this access maliciously or maybe even if he just logged in knowing that he wasn't supposed to be allowed to.
But I think the salient point here is whether or not he could have known that before logging into the server. Since the credentials are in the app, should he assume that the company's security is so bad that this would give him access to all their customer data? He is obviously allowed to use the app, and the app uses these credentials so it's not too much of a leap for him to think that he should be allowed to use them as well.
Regardless, I think the result of this ruling will clearly be bad for computer security. In the future maybe someone who finds a vulnerability like this won't report it out of fear of legal retribution.
- 2muchcoffeeman 3y agoI guess the moral of the story is, if you find hardcoded credentials, immediately inform whoever is in charge without actually using the credentials. Or can that still get you sued?
- tiluha 3y agoI'd probably not say anything. At most anonymously. I'm not taking the risk as i stand nothing to gain
- aqme28 3y agoI don't think the "hardcoded" part is at issue here. If this wasnt a MySQL database but an API that exposed other customer information, he would have the same moral duty to disclose and the same legal liability, I think.
- tptacek 3y agoMaybe not? Again, only speaking to US law, but your intent matters a lot here, and you have more plausible deniability sending API requests than you do making a direct connection to a database.
- aleph_minus_one 3y ago> you have more plausible deniability sending API requests than you do making a direct connection to a database. A direct connection to a database is an API, too. :-)
- tptacek 3y agoNot normally. Which matters here.
- aleph_minus_one 3y agoBut in this case, it is, since this is the way the client connects to the (database) server here.
- justsomehnguy 3y ago$15 what there is no law about illegally accesing information systems which even define API anywhere in the world.
- tptacek 3y agoWhat's your point? People have been convicted for doing things with actual APIs when prosecutors were able to demonstrate that a reasonable person would have assumed they shouldn't have done those things.
- justsomehnguy 3y agoAPI or not API is a technicality which bothers only tech nerds. The law would bother with such nuances.
- 2muchcoffeeman 3y agoMy thinking is that prod credentials that you aren’t supposed to have were used. So if you’ve been ask to investigate, and see something this glaringly bad, then you need to stop immediately, inform your boss, and get explicit approval before continuing.
- teaearlgraycold 3y agoDo it anonymously if you do it at all. In my opinion this is like filing criminal charges because someone opened a door at the front of your business. Normally what is known to your front end is not sensitive data for the entire user base. So if you take a peak in, its the same as wondering what the extra front door is to a brick and mortar store. You’ve got the main door with the OPEN sign and then a plain door that, whoops, is unlocked and has all of your customer’s files laying out on tables. At this point you’ve done nothing wrong. If you start rummaging around you’re outside of plausible deniability.
- tptacek 3y agoNot a lawyer, and certainly not in Germany, but spend a lot of time reading and noodling about this space. There's maybe a reach-y contract lawsuit if you violated reverse engineering terms; it wouldn't win, but it could be annoying and expensive. Actually using the database creds to the point where you can tell a story about the data in the database though is enough to put you at criminal risk in the US; the DOJ doesn't prosecute good-faith vulnerability research, but depending on the kind of poking you do and the kind of logs you keep of what you find, you can put yourself in a position where your good faith isn't assumed.
- DarkmSparks 3y agoI think the moral of the story is if you stumble on such a vuln while working in Germany in the future its best practice to sell it on the darknet since you unknowingly already committed the crime anyway. might as well get paid for it. Please Dont shoot the messenger, I didnt write the stupid law.
- SlightlyLeftPad 3y agoIt’s not clear, but what is clear is Cases like this can and often do have a chilling effect on legitimate, well-intentioned reporters of vulnerabilities which leaves everyone else at even greater risk due to negligence on the part of the company. We should be highly critical of these legal outcomes particularly when there was no intent to harm.
- joshxyz 3y agoi think it all comes down to: it's not a crime to build a house that has open doors and windows. but it's certainly a crime to enter one as an uninvited guest, let alone do things with traceable logs.
- dariosalvi78 3y agoaccording to data protection laws, it's certainly a crime to leave some systems unprotected like in this case
- AnthonyMouse 3y ago> but it's certainly a crime to enter one as an uninvited guest, let alone do things with traceable logs. But this is the entire issue. It's common practice for a business to have open doors because they intend for anyone to come inside and patronize their establishment. Some of the businesses are even in residential houses, where the area is zoned for that sort of thing. The question is what that's supposed to mean for a computer system. Obviously answering requests is the intended purpose of a public-facing internet server, and the general expectation is that if you're not allowed to make a particular request, the server will refuse it. Protocols even have widely supported standards for this, e.g. HTTP 403 Forbidden. So what are you supposed to make it of it when you issue a well-formed request and the server answers it? The default expectation is naturally that they intended it to, because if it was intended to do otherwise then they'd have configured it to do otherwise. How it responds is how you know if you're allowed to do it. At some point you may be able to reason out that what's happening is the result of a misconfiguration (exceptional circumstance) instead of the standard expectation (server refuses requests if server operator intended them to be refused), but this may not be obvious to the user until after it has already happened.
- tryauuum 3y agoplease don't compare houses with databases, this is pointless and discussion usually degrades into house-related things
- tomcar288 3y agocan't you just forget you ever saw the hardcoded credentials? that seems like the safest course of action to me.