10 ms·
City of Columbus sues expert who exposed extent of cyberattack
- chrisjj 2y ago[flagged]
- bell-cot 2y agoSounds like a straightforward 1st Amendment case. Might there be any lawyers with opinions (& disclaimers, obviously) in the house?
- rolph 2y agoi think it hinges on what is a threat vs what is mitigation. should people be informed, thus enabled to respond, or should people be etoliated, and kept ignorant of even requiring a response.
- ForOldHack 2y agoMy compliments on your vocabulary: etoliated: Def 2. literary. weakened; no longer at full strength. "Her voice was thinner than I recalled..."
- courseofaction 2y agoEspecially by a lack of sunlight. Fitting.
- pvaldes 2y agoetiolated
- rolph 2y agoi really wish the scarewords like darkweb would go away. the internet is not google, no amount of sand over the head or in the eyes will change that. Columbus officials chose to invalidate threat to public safety by way of misinformation, then retaliate when the threat and true situation was revealed. keeping people ignorant of threatscape is not good government. thinking the 'darkweb' is some sort of containment by obscurity, is beyond naive. the city of columbus is actually inhibiting a proper response and perpetuating a cavalier security stance. this is not going unnoticed. [1] [This is a bigger issue here': Columbus resident wishes the city told residents about the data breach sooner] https://www.10tv.com/article/news/local/columbus-woman-wishes-the-city-told-residents-about-the-data-breach-sooner/530-1c6ca9fe-3886-46c4-967d-cd30f20733f8 https://www.10tv.com/article/news/local/columbus-woman-wishe... [2] Second class-action lawsuit, representing police and firefighters, filed against city after cyberattack https://www.10tv.com/article/news/local/second-class-action-lawsuit-is-filed-against-the-city-of-columbus/530-96de3bf6-ed79-40b2-a324-b96677a015ef https://www.10tv.com/article/news/local/second-class-action-... [3] Ginther confirms personal information of Columbus residents exposed in cyberattack https://www.10tv.com/article/news/local/ginther-press-conference-columbus-data-breach/530-97a4bc42-8140-47c1-ae8a-8c8d32381653 https://www.10tv.com/article/news/local/ginther-press-confer...
- ForOldHack 2y agoPoint, point, point, point, point, Game, set, Match. "this is not going unnoticed." Oh thank god! "the city of Columbus is actually inhibiting a proper response and perpetuating a cavalier security stance." "On Aug. 13, Mayor Andrew Ginther said the data stolen by hackers was either corrupted or encrypted, meaning it was likely useless. Hours later, Goodwolf told 10TV that wasn't true and he showed what kind of personal information he was able to access" "City officials announced they are providing free credit monitoring to Columbus and Franklin County Municipal Court Clerk employees and judges and have asked city employees to use different passwords for their accounts." Elvis and common sense has left the building. https://schneiderdowns.com/our-thoughts-on/city-of-columbus-ohio-ransomware-attack/ https://schneiderdowns.com/our-thoughts-on/city-of-columbus-...
- progmetaldev 2y agoAppreciate the breakdown! Sounds like the typical cover-up, where it's honest disclosure (in appearance), until it slowly works its way out that it was far more severe than reported, and suddenly we're offering free credit monitoring. I'm not sure how much data was exposed, but I've recently gotten a warning from Ticketmaster that my SSN (US social security number) was exposed. I absolutely did not provide that information, so it's either an outright lie, or there's a lot more sharing going on behind the scenes than the standard public is to believe.
- gsk22 2y agoAs far as I can tell, darkweb has no actual meaning anymore anyway. I saw an article recently claiming that something like 80% of people under 30 access the dark web at least once a week. 80% of under-30s use Tor? Seems highly unlikely.
- kjkjadksj 2y agoMy understanding is it merely meant sites not indexed by search engines. Your employers internal websites or the sites for your college coursework would count.
- josefritzishere 2y agoThis is a very clear case of a restraining order being used punatively. The body of first amendment case law is very clear. The city has no reasonabel expectation that they will win. Their intent is to restrain, and intimidate legitimate criticism.
- zadokshi 2y agoWell they do win by intimidating people who want to whistleblow.
- edm0nd 2y agoA perfect case for the EFF or ACLU to pickup and help defend against such a silly and weaponized restraining order.
- passwordoops 2y ago""This is not about speech. It's not. It's about the actual action of going on the keyboard, going into the dark web, gathering the information, downloading it to your computer and then disseminating it to people who are in the press or otherwise," Klein said" No, this is about how you lied to your public about the nature and format of the data that you failed to protect
- sidewndr46 2y agoI love how politicians invoke "the dark web" like its some bogeyman that hides in the night and preys upon young children. It's literally a bunch of websites. That's it.
- superkuh 2y agoEverything not on Facebook/Google/Twitter is the dark web.
- kabdib 2y agoEspecially sketchy places like Hacker News. Just look at the name!
- progmetaldev 2y agoUnfortunately it's how those with less technological knowledge help the government to place restrictions on freedom, because there is a disconnect with reporting accurate news and making a name for yourself. Walled gardens are easier to police (although often allowing more sinister things through than standard websites), and the public is becoming more and more aligned with social media being "the internet" similar to how AOL was setup in the 90's. Those of us that were around in that time period saw how much more was possible outside of these walled gardens, and I believe even those that weren't around in those days that have any tech-literacy are able to see the benefit to being able to exist outside of social media. There is always going to be some kind of crusade in the name of something that tugs at everyone's heartstrings, but it's only to chip away at the freedoms of those that don't partake in the terrible acts (which there's no doubt terrible acts do occur, but not enough to have us all give up our freedom to make it easier to stop). I hope it's clear that I agree with you, and it is scary how easily swayed the public is (and that's coming from a father that definitely wants protections for our children, but also understand that a lot of that needs to start at home with communication more than limiting technology).
- sva_ 2y agohttps://archive.is/dEBJT https://archive.is/dEBJT (blocked in EU)
- sillysaurusx 2y agoFormer pentester here. Though I’m largely sympathetic with Goodwolf, note that releasing actual data is almost always a bad idea. It’s why bug bounty programs have limited scope. The city seems upset that he shared data about ongoing investigations and undercover police reports. Depending on what exactly he shared, it’s hard to fault the city for that. It doesn’t really matter where the data currently exists; grabbing it and handing it off to others is obviously not a good idea. If his goal was to prove to the reporters that such data existed and was available for download, he had many options that didn’t require accessing the data: screenshot the forum posts, send links to the reporters, detail what kind of data was there without actually showing any of it, and so on. Now, if that’s what he did, and the city is still reacting this way, that’s obviously abuse. But it doesn’t seem unreasonable to order someone to stop disseminating data about ongoing investigations to reporters. Would you want your private cases to be more widely spread? I’m really sympathetic to him, because this is an easy mistake to make. Before I got into the industry, I thought that this was white hat hacking; it’s obviously good that he’s spreading awareness about the breach. But how you do it really matters. (Caveat: I worked in the industry for about a year in 2016, so maybe things have changed. But I’d be shocked if distributing actual data from any breach was condoned by anyone who works as a pentester, even today.) > the city says Goodwolf is threatening to publicly share the city's stolen data in the form of a website that he will create himself. Goodwolf previously told 10TV he does plan to set up a website, but it would only allow people to see if their name was part of the data breach. This isn’t the same as setting up a site to see if your password was compromised. It could let anyone type in someone’s name and see whether they’re a witness in a criminal investigation.
- nostrademons 2y agoIt's somewhat unclear exactly what was shared and how. The article and the linked article about the data breach itself suggested that Goodwolf downloaded the data to verify its contents and then showed the data to a reporter, but he didn't actually release any data, nor distribute it into the permanent possession of the reporter. This is akin to Boeing saying "We had no knowledge of the 737 MAX's problems", and then an employee showing screenshots of confidential memos to the media saying "Yes you did, here is the truth." I agree that creating a website where you can look up a name and see if they've been part of a police investigation is a bad idea, but he didn't actually do that, he only had plans to.
- coding123 2y ago> This is not about speech. It's not. It's about the actual action of going on the keyboard, going into the dark web, gathering the information, downloading it to your computer and then disseminating it to people who are in the press or otherwise Lol, unless the article is reporting something off, features like Chrome or Firefox reporting one of your passwords may have been compromised would be illegal. The reality is that this city is wrong.
- xbar 2y agoEmbarrassed city sues annoying jerk who told everyone how full of crap city should was. Suing security researchers for investigating the contents of disclosed information is ineffective at protecting anyone.
- xyst 2y agoReminds me of a story on Dark Net Diaries. Researchers are hired by state to do physical penetration testing at some court house in the middle of nowhere. Pentesters get caught. Pentesters comply with security and local PD and explain situation. However some other asshole shows up to the scene claiming jurisdiction (county sheriff?), raises hell, makes a random call (county officials?), then arrest the pen testers on the spot for B&E. State leave them out to dry in some county jail cell. I think the state ultimately ended up getting embarrassed and tried to sue the company and pen testers for some civil damages and pursue criminal charges. In the end, they end up getting dropped and reputation of pen testers were ruined for a period of time.
- progmetaldev 2y agoThis is definitely the current state of security within government. I can't say it's anything new, it's just that the technology changed. Now it's about officials protecting themselves from being scrutinized by throwing around the law to aid in silencing those that find issues with technology. In the past it was exactly the same, except it was about officials protecting themselves from being scrutinized by throwing around the law to aid in silencing those that find issues in government policy, or government officials that skirted the law in the name of protection of the US people, etc. I think it's easier to go after people under technology laws than it was over finding information through informants and full whistleblowers. More scenarios to find information come about, and more draconian laws follow.
- justinclift 2y agoProbably this story, though this is the Ars Technica thing about it: https://arstechnica.com/information-technology/2019/11/how-a-turf-war-and-a-botched-contract-landed-2-pentesters-in-iowa-jail/ https://arstechnica.com/information-technology/2019/11/how-a... Follow up a few months later: https://arstechnica.com/information-technology/2020/01/criminal-charges-dropped-against-2-pentesters-who-broke-into-iowa-courthouse/ https://arstechnica.com/information-technology/2020/01/crimi...
- yieldcrv 2y agoHacking syndicate: not sued Public website hosting hacked records: not sued Lying public servant: not sued Joe Schmoe for pointing out all three: sued
- nick238 2y agoI wonder if the ideal way to expose this would have been to approach some law firm showing that you (just you) were wronged by the City, here's the data, some basic auditing showing where it was from, statements by the city, hackers, etc. Then just be like, yeah, there's like 3 TB of data there, maybe it's class-action worthy, hint, hint.
- jmyeet 2y ago"Let's go burn down the observatory so this will never happen again."
- kabdib 2y agoOur property values were great until they installed the seismographs.
- theginger 2y agoI get access denied to 10tv.com No idea why, do they ban UK / EU readers?
- lobsterthief 2y agoA lot of local news publishers in the US do that to save money and not have to deal with compliance in other countries. It’s beyond stupid and lazy
- SpicyLemonZest 2y agoHow is it stupid or lazy? I wouldn't expect any random organization in Ohio to invest in European regulatory compliance. It's not like local news is a cash cow, there's gotta be better uses for any marginal dollars they end up with.
- BeFlatXIII 2y agoWhy would they care about compliance in other nations? If they don't have assets in the foreign countries, tell them to pound sand when they attempt to collect fines. Unless, of course, Congress stabbed the American public in the back by agreeing to enforce such fines in a trade agreement.
- xyst 2y agoeven us readers with ad block get a paywall. https://archive.ph/dEBJT https://archive.ph/dEBJT
- progmetaldev 2y agoI'm not defending the action, but some companies/government officials want to spend very little on their hosting. Often a Cloudflare account is put in front of the website, and all but US, or even local accounts are blocked. I have been forced to do it with clients that are not willing to spend more money on hosting, and they have a site that has regular updates where I can't cache everything, or the cache is commonly "cleared" for making changes to global elements. I have done a lot of work to "section out" parts of a website that update often, and replaced those areas with dynamic JavaScript to bypass page caching. Even then, it's a tough subject because clients often get confused when the content they updated doesn't show up, even with a custom CMS with a page level cache-clearing mechanism (using Umbraco, which has allowed me to start with zero layout, and create anything the designers and clients come up with). I've had to build all the cache breaking mechanisms by hand, using the Cloudflare API.
- mmsc 2y agoAdd it to the list: https://github.com/disclose/research-threats https://github.com/disclose/research-threats
- xyst 2y agoThis is wild. Researchers are simply pointing out how bad the security system is for the City of Columbus, OH. > On Aug. 13, Mayor Andrew Ginther said the data stolen by hackers was either corrupted or encrypted, meaning it was likely useless. Hours later, Goodwolf told 10TV that wasn't true and he showed what kind of personal information he was able to access. lol - the entire city leadership needs to be recalled. They get caught with their pants down (no security), lie to the public (“it’s encrypted bro!1! trust me I’m a politician!!), lies get rightfully called out, and their response is to pour gas on the fire with this silly lawsuit funded by the local tax payers.
- progmetaldev 2y agoI agree, and unless someone in a very large city can tell me otherwise, this seems to be how local government works. Everyone is living off the basis that they "did they best they knew how", and that seems to remove them from liability. I have seen lots of crazy things over the years, and I believe that erasing any kind of liability based on someone's account of how security works is at best willful ignorance. If we want local government to hold personal data, then we need local government to be responsible with that data. Saying, "I didn't know any better," is not acceptable in 2024 (and really hasn't been for at least a decade or more).
- foundart 2y agoThis seems like a better write up. https://arstechnica.com/security/2024/08/city-of-columbus-sues-man-after-he-discloses-severity-of-ransomware-attack/ https://arstechnica.com/security/2024/08/city-of-columbus-su...
- noobermin 2y agoLived in columbus for many years. This absolutely tracks. There's something about being a blue city in a red state that makes the government rather brazen in protecting themselves.