Chinese dev jailed and fined for posting DJI's private keys on GitHub
theregister.co.uk
theregister.co.uk
> "I am done. I will go to jail, and I have to take this stain ... in my life. My girlfriend begin to break up with me, woooo, my family are broken. Fuck!!! What are terrible things! Maybe the only thing I can do now is to die; it is so hard. I need to be free.”
This is horrifying. It honestly makes me feel sick for this poor developer. Companies and nations this cruel have no place in modern society.
But also, this person is only facing six months and $30,000. That is no reason to consider suicide. Of course it sucks, but their life isn't over.
The similarity is the ott aspect.
Feel free to ask more questions.
That's exactly the direction modern society IS moving towards
I'm making no comment on if the punishment fit the crime, just that by reading the article it does seem that this was very much intentional.
Like it's easy to make the same mistake if you weren't alerted to it the first time.
If this guy was going for intentional sabotage, why not sell the keys on the dark web? Why not anonymously publish them on pastebin?
Why would he just upload them to github under his own name?
For example, I worked in a place which hires co-op students and every year there'd be at least one university-educated student who --after being told not to-- would put their nondescript FOB security key card in their wallet. In the event they lose their wallet, any stranger can google the name found on their drivers license to find out information about them, their friends, or their place of employment.
Then there are the countless startups where the boss has decided they don't need to worry about security so their communal password is "password" and they keep their user database in plain text. Nobody takes security seriously until it blows up. And that tends to be the common attitude from business management: worry about it when it's a problem.
On this example, I don't think it's a problem as well. First, the keycard has a PIN. After 3 failed attempts, it would either self-destruct the private key or lock itself down until a secret recovery code is provided. Second, private keys on keycards that are reported as lost can be revoked immediately.
But what specifically are they supposed to do with the security key card? What mode of securing and transportation do you envision?
For the Phantom 2, I think the root password to ssh into the drone was something like "12341234". For the Phantom 3, they make it more secure by upgrading the password to "Big~9China".
Sued and jailed for submitting vulnerability. Open through google search. https://www.caixinglobal.com/2016-10-17/are-chinas-ethical-h...
Until 2016, when the government arrested its founders.
* WSJ: China’s ‘White-Hat’ Hackers Fear Dark Times After Community Founder Is Detained
https://blogs.wsj.com/chinarealtime/2016/08/01/chinas-white-...
* China Arrests 10 White Hats from WooYoun Ethical Hacking Community
https://news.softpedia.com/news/china-arrests-10-white-hats-...
If you accidentally run someone over with a car, then there was definitely a failure of something, but it wasn't a moral failing. Punishment should never be used when correcting the underlying problem will have a more lasting positive impact.
In the car example, what do you think would be better - jailing the person who drove the car, or developing systems to prevent future such accidents?
Obviously, there is a real "It depends". Hit and kill an individual with your car because you were distracted? That could mean jail. Accidentally pushed code to the wrong repo? Should that mean jail time?
The only reason I can think of to not mention the nation that jailed someone for accidentally leaking their employers keys would be because the default assumption would be they are an American.
This wasn't a hack, there was no criminal intent. I think most people assume that the worst consequence for an accident like this is losing your job. The absurdity here is being fined, jailed, and receiving a criminal record.
The Register decided that adding the nationality was good for clicks. :(
> "Otherwise please use the original title, unless it is misleading or linkbait; don't editorialize." - https://news.ycombinator.com/newsguidelines.html
Register "post" - The Register is not a Chinese publication. The nation/legal system involved can't be assumed from the source, and is a vital part of the story since it's about a legal matter.
> "the Shenzhen Municipal People's Procuratorate – the local version of the Crown Prosecution Service – successfully prosecuted the developer in early April, before the Shenzhen District Court."
Had The Register _not_ included "Chinese" it could have been accused of "click baiting" since the Register's predominantly non Chinese[1] readership might have thought this was about laws that applied to them and clicked through.
Had the source been a Chinese publication writing about a American developer jailed, I'd imagine they would use "American dev jailed..." for exactly the same reasons.
1. "The Register is a leading global online tech publication, with more than nine million monthly unique browsers worldwide. The core audiences are the UK and US, accounting for more than six million. The bulk of the remaining readership are located in Canada, Australia and northern Europe." - https://www.theregister.co.uk/Profile/about_the_register/
I understand HN guideline here. I am talking about the Guardian's post.
Leaking private information to the public even unintentionally , that compromise the security of software and may cause public harm is illegal no matter which country you go. So the nationality of the one who leaked it is irrelevant as far as I am concerned.
By this principle it's not a crime for a delvery man to be in posession of contraband that he has no knowledge of. This isn't to be confused with not knowing something is illegal. That's no defense. It's about knowing or not knowing the consequences of your action.
That said there are lesser offences, misdemenors or summary offences, where mens rea is not required. They usually have fines but also can have limited jail time. For example, you can be punished for speeding and whether you knew you were doing it or not is irrelevent.
What's unclear in this case is whether the developer knew or ought to have known there were secrets in the code, or that his push was to a public place. It's also unclear, at least to me, whether Chinese law requires mens rea.
Human elected leader of country.
Weather occurring in geographic region.
Team lost game. Team won game. There will be more games.
Human incarcerated after conviction of crime.
Click and see, it's fascinating.
* GitHub commit search: “remove private key”
https://news.ycombinator.com/item?id=14262124
Although most keys removed are just useless automatically generated test keys, but genuine keys do exist. Someone should write a crawler to monitor these commits, creates digital signatures from private keys to prove the leak, and notify the CA issuer to revoke them automatically.