HN user

miw-sec-work

18 karma
Posts0
Comments9
View on HN
No posts found.

More to it than that...

lets say you exploit that bug in the internet banking application and you access my account.

Then you start logging into other peoples accounts and copying their address, balance, transaction lists.

Then you publish all this information you have stolen and say "Oh dont use internet bank -- they don't protect your private information"

the bank should have done better to protect that information, granted, but you have also performed an unethical and criminal act by publishing this information.

both the bank and the person that leaked that information should be punished.

Responsible disclosure to the vendor is one thing. Taking the fruits of your exploits and publishing it for glory and a "I leaked all that information because you wouldn't fix it" attitude is quite another.

I would hope that if you discovered a vulnerability in one of my web applications you would contact me first and allow it to be resolved. Might even be lucrative for you.

If you used that vulnerability to steal my database and publish it to the public domain -- when it has no place in the public domain, i would expect the DoJ to hunt you down.

I never said anything about not being friendly. But if you are playing with peoples identities, their lives, this is not friendly at all.

i think the semantics in the method in which weev retrieved this data is far overruled by the fact he LEAKED it afterward.

Real people were hurt here by having their PII exposed. Don't forget that.

weev still thinks that AT&T 'published' this information. AT&T had no intention on 'publishing' this information, he abused their system in order to obtain it, then he leaked it.

No weev, you found a bug in their web app, then _YOU_ willfully published other peoples personally identifying information for your own fame and glory. Unfortunately, someone who's name and details you leaked didn't like that, and called in a favor. The DoJ came after you hard.

Your little tech crunch article chooses to omit crucial facts, and you are riding on the back of AAron Swartz again. You are nothing like AAron.

Also, "Aarons law" was raised 1 year ago by the same Congressperson under a different name.

This is nothing but personal political quests using our martyr for justification. I'm insulted.

A better AArons law would be to force publicly funded research be released freely and under a Creative Commons license. They did this in EU, why not the US?

Weakening the Computer Fraud laws, and naming it after Aaron trivializes his quest for free flow of information.

Of course this wont happen -- too much money tied up in selling research.

Graphical 'signatures' cannot be legally binding as they are trivial to forge.

I also don't understand this retrograde step. I will repeat it. It is trivial to COPY and FORGE a graphical signature! And from a cloud provider??

What about S/MIME and PGP? These are cryptographically strong, essentially unforgable signatures that capture time and can ONLY be signed by the party that holds the private key. That is what i would want from a 'signing' provider.

I used to love the FireGPG plugin for firefox to "do this on gmail from firefox", however the javascript model in firefox meant that this plugin needed to be discontinued. (It could lead to private key disclosure).

Also S/MIME and PGP are open, free, standards that totally make 'graphical' signatures ancient exploitable technology.