Some highlights include authorization to attempt entry by tail gating, lock picking, place devices once access has been gained, etc. It's a total vindication for Coalfire (IMO).
Some highlights include authorization to attempt entry by tail gating, lock picking, place devices once access has been gained, etc. It's a total vindication for Coalfire (IMO).
People do get arrested doing this type of work. It hasn't happened to me, but it has happened to people I know. Usually it is quickly and quietly resolved without the press being involved.
What I believe is at issue here is authority. Can a state entity authorize testing of county buildings? Some people just assume "the government" is one entity. This same type of issue arises in corporate work as well - can a tenant authorize testing against a landlords building? You need to get both to agree.
(Disclaimer: I do this type of work so I might be biased)
I think you are correct, the question is if the right stakeholders authorized this. You can't break into a 7/11 because some person working there authorized it. Authorization needs to be from all proper stakeholders.
Then is it also the fault of the two testers in this case that they too did not verify that all the correct stakeholders were brought in?
It would suck to be in the position of the testers having little or no recourse.
I work in professional services (although not pentesting), so I curious about what would happen to me if I was in a similar position.
IANAL but I've been tracking this pretty closely since I'm also a pentester; everything seems to reasonably indicate that the two guys should be released, but someone else is likely ending up in a court over this.
How?
I can see a situation where the decision to stay or swap off a system is being debated. If one party can send in testers and call out some vulns that might play to their hand.
My initial comment pointed more generally to an example of politics within a company though.
Yes, the two employees could be liable for accepting a request from someone who obviously didn't have the authority to give it. But they wouldn't be the only people liable, and it seems silly to claim that they would be the first people liable.
Why is it that the only two people arrested are those who had the least amount of responsibility and ability to check on the authority of the State department?
That outcome is why the word "pawn" is being thrown around.
If the current cases were to actually go to trial, then even the most incompetent attorney would start asking for subpoenas of everyone involved, likely reaching into the highest political and law enforcement offices. These are people who can exert tremendous pressure in order to evade having to give sworn testimony.
I don’t know if the local prosecutors understand the massive political retaliation their are inviting.
> Many of the pentesting actions would violate hacking laws.
No. Just like the physical penetration, if you are authorized by a legal authority to access a computer system then you aren't breaking any law when you penetrate it. The question is whether these parties were in fact a legal authority.
They DID have permission to lockpick, and maybe the state asked for testing after 6pm MST but hasn't released the request (per the blurb below)
"Requests for testing outside this time period outside the above may result in additional charges per the terms of the MSA"
IANAL, but have written more than my share of SOWs and contracts of this type. Drafters tend to always default to the position of greatest optionality for them. Hence, "expected to be".