Readit News logoReadit News
ta3927590 commented on Reporter may be prosecuted for using “view source”   stltoday.com/news/local/g... · Posted by u/tkdc926
nimbius · 4 years ago
So it seems Parsons administration decided this is the hill to die on in 2021.

he had every opportunity to pump the brakes on this investigation but decided doubling down on a journalist had a better payoff, and a more prominent ability to cast him as a white knight protecting the state of Missouri against fiendish hackers.

the 'view source' prosecution strategy is certainly something id hope to keep out of the spotlight as long as possible as its chum in the water for technologists and privacy groups. the EFF could easily eviscerate it in court, as could the FSF and god help you if a cyber security firm takes interest. although most computer privacy laws in the US are written with a fire hose to catch anything remotely pertaining to an integrated circuit, these laws all generally restrict themselves to the domain of interstate commerce, healthcare, and energy.

Parsons fight is against an established journalist using an established and well respected process to report an information security exploit...so its really tough to see if or how a competent prosecution hopes to land any charges outside the governors "Lol do it anyway" edict which, fwiw, feels eerily similar to the malarkey Aaron Schwartz was put through.

ta3927590 · 4 years ago
Malarkey may be the intent. Knowing the case is nonsense and having no expectation of winning, you press on because even if eventually found not-guilty, the process of the defendant getting there if prosecuted can be used to destroy their career, reputation, finances, etc. Enough that it still feels like a win to the state, who rarely has much to lose in a relative sense.
ta3927590 commented on Reporter may be prosecuted for using “view source”   stltoday.com/news/local/g... · Posted by u/tkdc926
smhenderson · 4 years ago
Powerful Hacking Tool view source

Even the FBI agent quoted in the article got it wrong, stating “allowed open source tools to be used to query data that should not be public.” - as if proprietary browsers don't provide a View Source feature, only "evil" open source tools. Maybe I'm reading too much into it and it's a minor mistake but given the context even a potentially innocuous statement like that rubs me the wrong way for being incorrect.

ta3927590 · 4 years ago
As anyone could probably guess, LEOs that do actual technical work are rarely the same ones talking to the public about that technical work. Thus what gets said to or published for the public is rarely reflective of the actual internal understanding.

Dead Comment

ta3927590 commented on Sega Europe suffers major security breach   vpnoverview.com/news/sega... · Posted by u/aaronwp
phnofive · 4 years ago
Is it common, now or historically, to follow up a notification of compromise with self-directed PoC and privilege escalation exercises on the resources of a company with which you're not under contract? My naïve take is that this was a series of well-intentioned but possibly criminal actions used to illustrate a lesson we could all be reminded of from time to time.

Also, the HackerOne page doesn't appear to be claimed by SEGA Sammy, so notices might dead-end there as well.

ta3927590 · 4 years ago
Historically, definitely. Currently? Fairly common. However, what's both historically and currently uncommon is having the sense to not do so while also identifying yourself. For the h4x0r cred, or whatever. Which is of course childishly idiotic, but makes my job a whole lot easier. In my experience, if you're not under any such contract and even if you are going to report such a compromise in complete good faith and have done no damage, you are far better off doing so as anonymously as possible. Nobody likes to be embarrassed, and it's a lot simpler for a corporation with a stock price and public image to think about to pin the whole situation on those damn hackers than own up to even the slightest degree of incompetence. Typing at work in sort of a hurry so, please forgive grammatical issues.

u/ta3927590

KarmaCake day5December 30, 2021View Original