Student Who Found Security Flaws in Police Protocol Gets Suspended Sentence
news.softpedia.com
news.softpedia.com
DON'T DISCLOSE SECURITY FLAWS TO UNWILLING OWNERS.
If you stumble across a security flaw in a proprietary system, check whether they have a bug bounty. If so, great. If not, keep your mouth shut and get on with your life. (Unless, of course, you've decided to sell it on the black market; if you're okay with the ethics of that, so be it. But my advice, that needs to become the standard advice to everyone, is to just keep your mouth shut.)
Don't bite the hand that feeds you - and don't feed the mouth that's going to bite you.
Based on the numbers I've seen doing contract work for a big blue chip in the UK, you could see it as an opportunity to sell penetration testing services. If this one is unwilling, there could be 5 more willing to pay a good sum to have these sorts of flaws identified and fixed.
I get the feeling a lot of pen. testing companies run a standard set of checks for vulnerabilities. The report I saw was simply a bunch of metasploit results. They were charging some many thousands for this. Offering above and beyond could be a good opportunity.
Merely sending a emails and awaiting a response (if that's what happened) is an ineffectual tactic as it depends on a chain of unaccountable people within the org making the right decision about who to forward the email to.
But I'm also lazy and/or not very good at dealing with large corporations to find the right person to report these things to, even if they have a bug bounty.
Are there any organizations -- uhh, non-criminal organizations -- that will take a security report, find the right person at the company to report it to, see that it is addressed, and maintain my anonymity, so that I can wash my hands of it and go back to what I prefer to do with my time?
they'd need to document these security holes so that the same bug isn't reported several times simultaniously. so, they'll have a database of security holes a documented way to break into them...
this would be more than just a honeypot for every black-hat hacker out there. they'd be swarming them
Breaking into a computer system is like criticizing someone's ideas, not breaking into a house. Since anyone can trivially break into a house, we judge people by their intent, and thus authorities are trained to wonder "why was he doing that at all?" Whereas with computers malice is taken for granted and security has to be by design.
Most people understand that criticism does you a favor. Maybe we should explain that security systems are like public debates, and that successful hackers just happened to say something first.
"Security by design" seems to imply "oh, this is just a game." Nope. If you now require all people to be part of an electronics security arms race, this is a problem.
It may well be that there should be a mechanism for the police to refer such a kid to others in e. security to enculturate him or get him a network to be part of.
Its more like walking past your neighbors house and finding the person who is supposed to be looking after it has left all the windows and doors open and a shopping list of things to steal pinned to the wall.
Then when your friend doesn't do anything about it.
Telling your other friends what an idiot he is.
The reason telling people they are insecure has been criminalised is the security agencies are the ones doing all the stealing.
So we've had three decades of systems security being cast as a dirty word only criminals care about.
Kid should have just sold his hack to the highest bidder and skipped the country. Denounce me as unethical as all you want but his situation would be objectively better if he hadn't cooperated with the authorities.
I don't agree, but I could imagine feeling this way in another universe.
While I'm not down with selling the hack, not interacting with police is always good advice.
It's shown over and over again that official contact with the police rarely has good results, at best has neutral results, and sometimes has VERY bad results.
The path of least resistance is mutely accepting that it's a bad idea to talk to police, or otherwise engage with authorities.
Those who hold so much power over our lives must be held to much higher standards: of responsibility, ethics, and behavior. If you want change, take the path of maximum resistance.
Your second statement roughly mirrors the parent comment in saying that the guy would have been served better by selling the vulnerability, but surely you don't believe that that's the only criterion for determining if something is ethical, right?
Do you have in mind a buyer who would make such a sale ethical? I would imagine intelligence agencies of major European powers, as well as the US and Russia, as the nation-state buyers, plus organized crime as another possible buyer. Among that field of upstanding people, who do you imagine this exploit could be sold to without clearly and knowingly contributing to massively unethical operations? Perhaps the NSA wouldn't be too terrible a result, because they would just use it to watch everyone rather than cause instability and threaten officials, but for that extra potential it seems like organized crime would be the bigger buyers. Or do you excuse everyone so long as they're not the final link in the chain, the one firing the gun?
I hope that I've just written all of this out of a misunderstanding of your comment, because in no world is selling this vulnerability ethical. If Slovenia were a huge liability, likely to start World War III at any time, maybe, but that's just not the case.
It would be ethical to report about vulnerability but without disclosing your name. And if it won't fixed, disclose it at public.
I imagine state actors as the most likely buyers and way worse offenders, than organized crime. In the world, you believe in, it might be unethical to sell to them. In the world, where the state actors are the enemies of the people and the enemies of each other, it might not, but passively not doing anything might be.
Really? If the thing is used for anything important, just sell the intercepted data on darknet :) And it seems this was passive reception of radio traffic - it'd take them a while to find him.
The whole story just illustrates the danger of doing security research in the open. If he tipped them anonymously, he could simply pass the news to the media after a month and they'd have to shut up and fix their shit.
I once refrained from reporting a web vuln for similar reason - I didn't trust the owner to handle this professionally and, unfortunately, I didn't use tor because I attempted the hack just for fun wanting to see how they are protected from that - turns out, they weren't at all.
>Officials also conducted a search of his house a month later, in April 2015. Besides seizing his computer and a $25 custom equipment with which Ornig was able to intercept TETRA communications, officers also found a fake police badge, and also accused him of impersonating a police officer.
As for the fake police badge, I bet this was unrelated —Costume party, BDSM, an old toy…
Still, running from the police because they won't fix their insecure communications is ridiculous. Regardless of whether or not you made any money.
That's not fair at all.
(yeah, I know. But they're two entirely different countries)
Is there any evidence of this? Simply owning a fake badge doesn't even prove intent, let alone being actual evidence that it happened.
Well, not in the US. Many other countries take a dim view towards citizens owning anything that even remotely resembles the accruements of official power and authority.