Governor vows criminal prosecution of reporter who found flaw in state website
missouriindependent.com
missouriindependent.com
After I shopped a few other companies to see how our plans compared, I notified the marketplace operator via the only link on the website for customer service. Within about an hour, someone from their IT department rang me on the phone and started grilling me about how many other plans I browsed, and insisted that I clear my cache and browsing history, and notified me that they would be watching to make sure nobody at our IP address didn't access any other plans while the issue was being fixed.
I was pretty surprised at his response, and assumed they would be more grateful for exposing a pretty basic flaw, but I guess a natural human tendency in these situations is to try to externalize the blame. Perhaps it's more difficult to hold yourself accountable than it is to assume that others who've found your shoddy work are malicious actors.
Then they shouldn't have let you in. How are you completely absolving them of responsibility when all they had to do was say "Who the hell are you? No, you can't come in."
Do I bear responsibility for letting you in? Yes. Should you be there? No. Should you have knocked on the door? No. Should you have tried the same at my neighbor's house and every house on my block? No. In this metaphor and in the original context, everyone is acting with honest intent except the actor knowingly trying to access obviously confidential documents.
Let's drop the metaphor. The original story was that someone accessed a number of documents they weren't supposed to but technically could, and the question was whether or not that it was reasonable that the owners of the documents were upset with that.
I argue there was good reason to be upset given the facts on the ground. In this particular situation, the original poster was there to access their own document. Having accessed someone else's document, that would be the point at which the behavior crosses from legitimate to illegitimate if it continues. Leaving at that point would be one appropriate response. But systematically going through a number of different documents goes beyond a mistake and into the realm of intentionally exploiting this security issue for unauthorized purposes. That's when it crosses from "honest mistake" to "dishonest exploitation".
I have no idea about the illegality of the issue. But the fact is plain that this person was not the intended recipient of the documents, they knew they weren't the intended recipient, and then after realizing the nature of the exploit, they continued to use it.
This is not the same as knocking on a door for a legitimate reason, being let in, and then the person inside being mad you're there. It's knocking on a door for no reason or a malicious reason, knowingly doing something inside the resident doesn't want you to do, and then wondering why they are mad at you.
The way you phrase this makes it seem like accessing the documents was a mistake. Maybe the first one was, but I think the thing you are missing about the OP's story is that the behavior was repeated. I think the first instance was arguably okay. But subsequent access with the knowledge that what they were accessing was not intended for them is in my eyes beyond a mere misunderstanding.
You also have to remember that having physical or digital access to a thing is not the same as having permission to view the thing. For example, if a "Top Secret" document is delivered to your house with your name and address attached to it, if you read it without the appropriate clearance you will still be in trouble. The legality of such a thing is well established in that case, but the principle is the same: even though you have access to a thing and all you have to do is move your eyes in some direction to see it, the act of seeing it is still at minimum an ethical breach (why are you looking at things that you know don't belong to you?).
I guess this is the fundamental philosophical and ethical question: do you believe you are entitled to know any information as long as you have the technical ability to physically or digitally access that information? What if I have medical records on a screen in a room you are in, and all you have to do is move your eyes over to see my most personal info? Are you entitled to read that information because it's visible to you? Or do you think you owe it to others not breach their privacy even though you have the ability to do so? Would you be mad if someone violated your privacy, and then retorted with "well you should have a had implemented some better technology to prevent me from moving my eyes in that direction"? I guess in that scenario you would have to blame yourself and your technological abilities, and not the person violating your privacy.
1. People who kept their doors unlocked
2. Person who randomly entered doors & found things.
We need to take care of security of our properties, though stealing is wrong.
But I think that a better analogy would be asking the apartment manager to see your payment history and getting handed the entire apartment building's ledger.
The right analogy would be if I was in the apartment complex and I said to a door not mine "I'm home open up!" If the door opened and I did it intentionally, am I liable?
I still feel like yes but since you have to request the document and receive it I think it's different than just checking locks.
So the argument is a heist occurring on a train, so we've got the thing that we're trying to heist (which would be our point) and then we're shifting it from one car to another. And some of the analogies here are clearly like passenger coaches, but others are more like those... coal transporting car, whatever they are called... and at some point we move to the inappropriate railroad car and drop the point in the coal which obscures it.
Anyway, the point is that at some point you really just hope that some conventional train robbers will show up and derail the whole thing because it has gotten too convoluted to follow.
Because any physical analogy is such a poor representation of how a website actually works, everyone just cherry-picks the analogy that demonstrates the logic they believe should apply, and then tries to constrain the argument to that logic via analogy.
We don't need to reach for analogies to observe that while the theoretical ideal is to report it after just one false access, that no significant damage was done by accessing just a few more via human manipulation of the browser URL, with no recording or sharing of the results. From a human perspective, no damage was done.
Whether that legally crosses a line involves a whole lot of details that few, if any people here, will be able to speak to, because of the complication of the law, and HN's conclusion as to the legality is of marginal interest even if someone competent were to give an opinion.
We can speak to the fact that even if it does technically cross a line, a prosecutor really ought to use their discretion to not prosecute since nobody was hurt. We can say that because that's just an opinion. I expect we don't have very many people here who actually want the book thrown here (though, as always, enough read this that it's probably non-zero).
OP admitted to continue changing URLs in order to check out what plans other companies were getting and what they cost. That means OP downloaded lists of employee names, ages, SSNs, and other data. If I were an employee at one of these other companies, I'd be pissed at OP for that. I'd be even more pissed at the people who built the marketplace website for making the rookie security mistake that allowed it, but it's absolutely not ok to download other people's information when you shouldn't have access to it, and use that to your own advantage.
Sure, I don't think this is something that should be prosecuted as a CFAA violation with big fines and jail time. That's not a proportionate response. But I also don't think we should signal that it's ok to look at (and use!) other people's data just because someone else forgot to lock it up properly. I think, for example, something on the level of a parking ticket would be appropriate here.
If OP had changed the URL once, found the vulnerability, and then immediately closed the page and reported the problem, I would see nothing bad in what they did. But they didn't merely do that, and IMO crossed the line in their subsequent actions.
And you have to cause injury for it to be fraud. Is "Help I was too honest to a customer." a valid injury claim?
If you convince them that you really are X and they give you the file, i think that would be considerd fraudulent. Whether or not an injury takes place to raise it to the level of fraud i guess depends on what was in the file, but in countries with strong privacy laws, someone would probably be in a heap of trouble.
To be able to login as BoBibbidyFooBar, and subsequently access ANY company's info in the system without changing their identity from BoBibbidyFooBar does not, in any way, constitute any sort of fraud. It literally cannot, by any sensible definition.
A better analogy would you asking for your files, and then the secretary taking you to a filing cabinet containing everyone's files right there with yours. You don't have to lie about who you are, you can just look at other files because they're right there in the place that you were just given access to.
Analogies are always going to be imperfect, but I can't see the argument that the "separate request" analogy is any worse than yours, let alone "wrong".
Not at all because what you describe involves impersonating someone else.
In the OP case, they were authenticated in the session as themselves and always acted under the truthful identity and asked for a document and access was granted.
So the analogy would be going up to the desk and saying: I'm John Doe, my id number is X (truthful value), could I see file ABC? And the attendant checks that id==X does have access to document ABC, and thus hands it over.
You filled out some form to request a document from the irs. You give the form to the person they give you the document.
You notice they dont check ids, so you change the name on the form, and get someone else's document.
This definitely seems to fit the definition of fraud:
380 (1) Every one who, by deceit, falsehood or other fraudulent means, whether or not it is a false pretence within the meaning of this Act, defrauds the public or any person, whether ascertained or not, of any property, money or valuable security or any service [that's the canada definition]
All company data was, in OPs scenario, made public to any and all authenticated users.
There is no way to rationally spin this as a malicious act, in my view.
Downloading a number of them and comparing information, however, is not necessarily malicious but rather sketchy.
This definition of fraud doesn't define the word "defraud"? I don't know how I'm supposed to see if it fits or not.
It can't mean any action, or going into a store, lying about my name, and asking what aisle has baked beans would fit. Because that has "deceit" and "any service".
If I interpret things as the service being minimal and provided for free, so that I'm not deceptively getting the service, then we have to look at what actually gets sent to me, and whether it's "property, money or valuable security". And since it's just a copy of the data sent at no cost, it's much harder to argue fraud exists.
While you could construct hypotheticals where OP is using the health plan information to gain actual value, they are all so far-fetched I wouldn't buy them as a fictional plotline. Dude was probably just curious.
The closest real life example I can think of would be along the lines of: - your car is in a public parking space and someone look inside vs - the same car is in the garrage and someone breaks the door to look inside your car
You never typed google.com into the browser? I doubt it. Maybe you just mean "construct" as in edit the url to access another site - well, that's still a perfectly normal use-case. I regularly change reddit urls to old.reddit because it gives me a better user interface. Or access a subreddit by adding an "r/subname". Sure, those aren't alphanumeric IDs, but that distinction is meaningless. Some unique IDs on the web do actually consist exclusively of english words. And some numeric IDs are harmless page numbers or pagination info.
Is this system more trusting of people than it should be? Probably. Does that mean you're allowed to snoop on other people's documents -- nope.
No, it merely assumes the server is acting on authority of the organization identified by the domain name. It doesn't assume agency, only representation.
/s
Just like the IRS admin assistant in the example was, the agent to cause the transfer. The filing cabinet/server is not the agent, simply the repository responding to the system and practices in place.
No. It's like someone asking you what you need, you telling them "I want all my documents and the ones from my neighbours because I feel like it", and them proceeding to hand you everything you asked for neatly collected in a folder.
Of course it's on the user if they know they're not supposed to have access to some info and they use it to their advantage regardless. If they're a nice person they'll even report the issue (though less likely after news like this).
> just because the vending machine is broken and works without you paying doesn’t make it not stealing
So if it's broken and doesn't work despite me paying, does that make my payment a donation? No. Though it probably is theft if I knowingly abuse the error for profit.
Like you can say "URLs aren't sensitive by default" up until the guy admits that he knows it's an error and he's accessing the private data he's not supposed to see. That changes the situation completely.
A printing press also isn’t sentient and can’t guess whether its operators really mean to share every sentence on the plate. But browsers and readers of printed materials (that are left in public places) have no obligations to the publisher’s state of mind. Why should browsers of digital materials?
You can certainly assign various levels of blame and responsibility to the human "server" in those scenarios. But the human on the other side of the interaction, the one requesting information, doesn't magically become free of reproach. If they are requesting information they know they should not have access to, and then making use of that information for their own gain, they're guilty too.
There's a very narrow carve-out for the white-hat: requesting information with the intent of uncovering vulnerabilities, with the intent to help them get fixed. We expect a white-hat actor here to destroy and not make use of any information they obtain that they shouldn't have.
> If I go to the IRS to do some paperwork and notice it says "File #7881991" in the top right corner and I go to the clerk and ask them "Hey, can I have files 7881992 and 7881993, too?" and they give them to me, who is liable for that? It's quite obvious.
Yes, it is obvious: the clerk is liable for giving you something they shouldn't have, and you are liable for fraudulently representing yourself as someone who should have access to those files.
I don't get where this idea of "the other person let me do the crime, so the crime is ok" comes from. That's just not how the law works in the real world. If you then walked out of the IRS office with those files, I would absolutely expect you to get arrested. (Even if you immediately gave the files back, you'd probably be on shaky legal ground.)
It's always okay to ask for things. There would be no way for society to adapt, progress, or change if people were limited to only asking for things that they knew in advance they were allowed to have. If it's legal for a telemarketer, pollster, reporter, cop, or recruiter to contact me and ask me questions then it's just as legal for me to contact and ask a web server a question. The correct response to unauthorized requests is a 4xx, not a lawsuit.
More to the point, what makes it okay to ask a new web server for "/" without permission? Even if browse-through terms of service were legally enforceable they aren't known to the user or the browser before making the first connection and request.
If a web server doesn't want to answer questions then don't connect it to the Internet.
If you know doing x will cause y, then when you do x you are doing y and you are responsible for the consequences of doing y. It doesn't matter what x was.
This is especially true in the real world.
Sure, but how is that relevant? What material false representation was made which was relied on in deciding to provide the data?
If there was no decision, much less one based on materially false information, there can be no charge related to false pretenses. Your argument against decisionmaking is an argument against your claim of false pretenses.
> If a computer system erroneously prints an extra 0 on a check mailed out to you that doesn't mean you get to keep the money because the computer isn't the entity that decides how much money you're owed.
That's neither entirely true nor at all relevant to your false pretenses claim.
I agree that it's unreasonable to blame users for finding things like that. But if those same users are downloading all the data and making use of it for their own purposes, that's not ok. Finding a vulnerability and reporting it is an admirable thing to do; exploiting that vulnerability yourself is not.
I might forget to lock my front door one day, but that doesn't make it ok for you to wander into my house and look at all my stuff.
So if a piece of paper flies in my face and has company secrets and I manage to look at, I'm at fault here ?
> I might forget to lock my front door one day, but that doesn't make it ok
Sorry but if you're not going to secure your belongings, then expect to be robbed.
Being 'ok' has nothing to do with it.
It’s not even “getting robbed” really. Nobody here deprived the owner of anything. It’s more like:
Sorry but if you're not going to secure your belongings, then expect to have people look at your stuff.
Requesting access (ie knocking on a door/typing a url) is not illegal. If you grant that request (ie invite me in/serving a webpage), I am under no obligation to psychically infer that you didn't mean to and refuse your invitation.
If I could simply use the excuse "well, the computer gave me the information", then there would be no such thing as hacking. It's always a case of the computer sending the information to you.
Compare to a restaurant: simply walking into a restaurant is not illegal, but an owner can restrict access and ban someone from their restaurant. It takes no technical skill to break into the restaurant, the door is wide open, but without authority it is trespassing. However, it is on the owner of the restaurant to actually ban someone. For a public space, be it a restaurant or a webpage, by default you are permitted access. Attempting to enter a restaurant you've never been to before is not breaking and entering, nor is accessing a URL hacking.
If a website has some user agreement saying you will not access certain portions, or even if there is just a notice on a website saying this site is not public, then they have done all they need to do to revoke someone's authority, even though they would be incredibly easy to "hack." But as laid out under Van Buren v US, you don't lose authority to access things simply because you possess some intent undesirable to the owner. If you invite me into your home and I sleep with your wife, I haven't trespassed; if you tell me to get out and I don't leave then I have.
Further, there's a distinction between accessing something by normal, legal means and accessing something by other methods. For example if you invite me into your home only after I give you a false identity, I'm trespassing because I was never legitimately given authority to enter. Likewise if you hack a system with say a stolen password, you don't have authority to access the system no matter how easy it was. But if you grant authority to someone without them having to do anything nefarious, then they have authority regardless of whether you should have done it or not. If you have something sensitive, don't put it in a place (in the real world or online) where authority to access is granted automatically and without oversight.
Send me a 401 (or a 403) status and I’ll know I’m not authorised.
In the physical world, nobody would lawyer up and go to court if someone walked through an open door with a sign saying “public entry here” and saw something confidential.
If you have confidential information around in the physical world, you make sure you have facilities staff who know the difference between “public entry here” signs and “authorised personnel only” signs. You also have facilities staff who know how to fit door locks and door closers, and security staff who know how to choose appropriate locks and to enforce compliance of locking doors. And if all that breaks down, it’s not Joe Concerned-Citizen who tells you about it, or even Mallory from your competitor who waltzes out with trade secrets who gets held to account, it’s the manager and/or executive in charge of facilities and security who’d be answering the difficult questions, probably with their lawyer at their side.
It sad that the legal system hasn’t yet started to hold people to account for having incompetent web developers and server operators.
If the security system is broken and you do exactly what it should be preventing, then you report it and get upset because they ask questions about you doing exactly what you did?
First, it's trivial to just use a different IP address. Second, even if you could track people perfectly, which you can't, who the hell thinks it's okay for data to get leaked as long as you know who it gets leaked to?
An IT employee who doesn't know about VPNs. Sigh.
It's pretty obvious that when you find a flaw you simply don't approach the people responsible for it, unless they have an EXCELLENT reputation of dealing with this. Otherwise do an anonymous full disclosure (edit: if you have an entity that routinely handles this sort of thing and has an EXCELLENT reputation, that would work too). If nothing happens, provide a PoC.
Of course people, even in IT, are kind of weird here. Somehow responsible disclosure got into people's minds as The Good And Proper Thing to do, and full disclosure being somehow irresponsible. Analogy: Some guy finds out the mayor is completely corrupt or does some illegal stuff. What do you do? a) Disclose this through e.g. the press b) Approach the mayor and try to get him to fix his stuff. Somehow, when it comes to IT security, people wanna see hackers do b) because a) would clearly be irresponsible. Wtf?
If changing a few characters in a URL was a crime, I'd be gone for life.
edit: and, I'm using "normal" in the same sense as the comment I was originally responding to: to indicate an everyday occurrence
She used responsible disclosure to let the CDU know of this flaw, got sued in response.
After an outcry from the community the CDU apologized to her and retracted the complaint and the proceeding was suspended in the end of August 2021.
It's pretty sad to see how people who act upon their best intentions, intentions which are beneficial to the society, are hit so strongly by those who are afraid to admit that they made a mistake. Hit in such a manner, that it tears apart the daily routine in a very negative way for months.
You are correct that they did not hold an absolute majority (more seats than everybody else combined), ensuring that they always had to form a coalition to achieve that.
Nevertheless, it might be better to use unambiguous terms like "plurality", or define ones terms, when writing for an international audience.
If one contacts the corrupted major for a timed disclosure, he gets time to hide crimes or can continue being corrupted, but the press running the story only damages the major.
If I run to the press with a vulnerability, everyone is empowered in exploiting it. Sure it puts lots of pressure on the devs, but devs can only work so fast, which creates a window of opportunity which damages both them and their users. A timed disclosure doesn't prevent exploitation that's already happening, but doesn't increase the problem by itself
The desired outcomes in the two cases are different, and it's no surprise different strategies are optimal.
Sadly, time and time again, what in practice ends up happening is the window of opportunity is wasted by the devs being instructed to work on new features rather than fix critical security bugs the company thinks are not widely known.
Apple’s response to four zero days being only the most recent high profile example of that.
Huh? This analogy doesn't really make sense. The difference for software is extremely basic: if you publicize a vulnerability immediately, you give more opportunity for it to be exploited while it's being fixed. Malicious actors who hadn't found the vulnerability yet now get it handed to them on a silver platter.
Private notification simply gives the operator a head start on closing the hole before it's more widely known by potential attackers.
Again, it's not about Optimally Mitigating Corporate Security Fuckups, it's much more basic than that: it's about keeping you safe. This should obviously be priority #1. Anyone telling anyone else to do responsible disclosure by default because That's What Good Guys Do And You're Not A Good Guy If You Don't is quite clearly not putting the safety of the reporter at #1.
if it’s live it’s already being exploited. simple principle, but very effective.
OR let us reverse the analogy
You find out Facebook is running an international slave trade by using their data to find vulnerable teenage girls sending them invites and then kidnapping them. Do you A) approach Facebook and try to get them to stop their practice B) alert everyone immediately.
The answer is you alert everyone immediately because Facebook in this example is doing corrupt and illegal things. There is a difference in how you should react concerning security problems that others can take advantage of and willfully committing illegal and corrupt acts.
At what point does it cross the line into IT malpractice? I would say that not even bothering to verify the current user has the access to view what is being requested is well over that line.
When you're dealing with PII, HIPAA, etc, there should be a standard level of competence. If I go into a doctor's office with a runny nose, and they remove my liver, simply stating that they practiced medicine "poorly" shouldn't be a defense.
Something shouldn't have to be literally illegal to be considered shitty behavior. (Of course, people are often incentivised to be shitty, which is why legislation should also be applied to the issue)
Perhaps responsible disclosure could pass through his entity?
It's a way of anonymising the source to keep them safe, and centralising the risk to someone who is already highly regarded by companies and governments.
Incompetence is very different than malfeasance.
Large governments and corporations are not your friends. They will hurt you if it benefits them, often very short-sightedly and regardless of the root problem. There are far too many articles like this one to think "responsible disclosure" is a safe practice. I remember one case where the red team was hired by the agency involved explicitly to perform pentesting, and when they found a vulnerability the government pressed charges!
If the case you’re remembering is the one where the red team assumed (without asking) that physically breaking into the courthouse at night was “in scope” of their engagement, I’m of the opinion the short-sightedness there was not the agency…
https://www.cnbc.com/2019/11/12/iowa-paid-coalfire-to-pen-te...
It’s _maybe_ grey area. But there’s no way I’d escalate a pen test to breaking in to a courthouse without explicit in writing permission from someone clearly authorised to give it, including in writing assurances that all relevant law enforcement had been notified (at least at high levels, if part of the authorised physical pen test was actually testing on-ground law enforcement capabilities).
https://krebsonsecurity.com/2020/01/iowa-prosecutors-drop-ch...
They did fail to verify that law enforcement was aware (the client specifically asked them not to) and they seem to have misunderstood the building's ownership structure. The end result was that they fulfilled their contract and were arrested for it after encountering one idiot with power, after which the local politicians piled on in order not to look weak.
Yeah once you start using a vulnerability maliciously to obtain confidential data for your own personal gain, even if its a stupid vulnerability, you're not really good-guy security researcher anymore.
If all you did was the bare minimum to demonstrate the vuln exists, that's cool. If after you do that you continue to use it to obtain confidential info for your own gain or curiosity, that's not so cool.
> Perhaps it's more difficult to hold yourself accountable than it is to assume that others who've found your shoddy work are malicious actors.
You literally just admited to being a malicious actor in the paragraph above.
And the details of different plans is not the kind of confidential info that innately deserves protection. Investigating or recording personal information would be bad, but they didn't do that.
Apply for jobs at the other companies with better plans, proceed with interviews, offers and then finally accept one and quit their job at their current employer... To reap the rewards of their malicious hacking...
What does "keep or memorize" have to do with anything? They intentionally abused a misconfiguration to view private information.
I think it's reasonable to disagree about the ethics of that, but I don't think it's really debatable that it was intentional.
"private" information is too vague of a term.
What harm was done by someone comparing prices? What organization lost money? Who got worse health service?
"Unethical" and malicious is the current, profit-driven health insurance system.
I know you're coming at it from an absolutist perspective, but I disagree entirely with passing judgement.
Furthermore, the fact that you seem more upset with the person who glanced at a few plan prices rather than at the healthcare system, or the incompetent website operators, is telling.
It removes the information asymmetry, which protect the profits of the seller.
All i'm saying is if you find an exploit, and after you verify it works, you contunue to use it for your own personal ends, you're no longer benign and you shouldn't expect a warm welcome from the security team.
The line is when you start to use exploits on computers not owned by yourself for your own ends instead of for the purpose of verifying and reporting the vuln. Sure you could cross that line a little bit or a lot, but you're not innocent if you're over it.
I think this is what people may have been missing from your original post: at some point things can go from innocent to malicious.
"Crime of convenience" is the most common type, after all.
"I'm not the type to steal, but the cash was left on the counter, and …"
The appropriate response from the security team (after verification) is to pull the site down or immediately patch the vulnerability, if possible. Making an outbound call to a third-party is pointless and irresponsible.
malice implies intent. If we take author at their word, there wasn't any, though you could say they took it too far by looking at other stuff they probably knew it was ethically wrong to do so.
Though, sometimes it isn't clear you're in compromising territory until you're in it.
If any of the confidential information obtained wrongly gets used to advantage … that's malice.
If the parent set out to exploit the insurer by finding inconsistent/unfair pricing, etc etc … that's malice.
The network team could not work it out. The vendor could not work it out. But one of the IT managers had an explanation: me. Firstly, it was due to an OpenVPN I installed on a server (with permission-as a stopgap measure so we could remotely access the “next-gen data centre” because the networking team was taking too long to get the real VPN installed and it was blocking other teams on the project.) The explanation didn’t make any technical sense: the VPN is just an application, nothing to do with the core routers; but he wasn’t technical enough to understand that. They told me to shut it down, so I did (even though doing so inconvenienced the project), and lo and behold, it made zero difference to the problem. Then, he apparently even suggested at a management meeting (I wasn’t there but I heard about it) that I was sneaking in to the data centre at night or on the weekends to sabotage things, and that was why the new routers didn’t work. Apparently they even asked campus security for my physical access logs, which revealed I hadn’t been doing any such thing.
Eventually, the vendor worked out the problem. When you install the router, there was a step you had to change the VRRP IDs to give every router a unique ID on the network. Clearly explained in the documentation, obviously essential, apparently our networking team didn’t read that part. You plug one new router in, everything is fine; plug the second one in, well it still has the OOTB default VRRP ID, so now two core routers on the campus network have the same VRRP ID, and all the other routers got confused, and the whole thing fell apart. Both our networking team and the vendor’s support team were so focused on chasing some obscure bug they didn’t see the basic config issue.
If you wind up putting your tax returns in the 'little free library' you set up on your front yard, you can't blame others for reading them, then handing them back to you and not telling anyone else.
That's the proper analogy for what happened in the original article.
Like sure I’m accepting a risk that you could do that but you’re still a dick if you actually do.
Publishing to a public web server is analogous to that little free library, out in the yard. No keys, anyone can look in it at any time. If you accidentally put something sensitive in there, where anyone can see it without any access control, you can't blame them for doing so.
Each time a breach like this or in the original post happens, it makes me feel that our tools are just not there yet. If there were simple tools that caught vulnerabilities like this we would improve the standard of security.
EDIT: Remembering it now, there were also email addresses with the Iranian navy as they coordinate with other navies to fight piracy too. Perhaps instead of sending a Rickroll I could have sent a mass email with Lennon's "Give Peace a Chance."
And they may also hurt him.
https://en.wikipedia.org/wiki/Weev
He's also a neo-Nazi and white supremacist. I do believe in free speech, but some of the things he does seem to take it way too far.
And he famously doxed Kathy Sierra, a female technical writer who created the Head First series. I actually quite like some of the books in the series, and it's incredibly sad to hear incidents like this which actively discourage females in tech.
https://en.wikipedia.org/wiki/Kathy_Sierra
I suspect there's more to the AT&T incident than just, oh, I found a flaw, let me responsible report this to the relevant parties in responsible disclosure.
"Yes, I'd give the Devil benefit of law, for my own safety's sake!"
And it should be noted, that weev's turn towards overt neonazism (rather than just antisocial trolling) took place in prison, where he was mistreated.
I once infiltrated some of the IRC channels he used in 2010 or so and have logs of him saying extremely antisemitic things in earnest.
(The groups I infiltrated also doxxed people and used that information in smear campaigns, which is why I'm using a throwaway for this comment. I checked HN's rules and guidelines and couldn't see anything against this; if I'm wrong about this, I apologise.)
So I'm hopeful that the courts are slowly starting to wisen up in that respect.
What you did was walk down the block, pull on the doors of random houses, and if you found one unlocked, went in and took a look around. If you found my door unlocked and left me a note, I would be grateful. If you went in and took a look around, then did it to all of my neighbors, we would have you arrested.
The bug here is an unlocked door. It being unlocked is a security risk, and people are thankful if you let them know. If after identifying the security risk you proceed to commit a crime, you're surprised people aren't "grateful?"
>difficult to hold yourself accountable
isn't it though...
>are malicious actors
so you.
A url is not a door, but an archway, or possibly a door frame.
And, if I'm in City Hall, the mechanism that keeps me from entering the Mayor's office should be the security guards and key-cards, not my disinclination to open a door.
you mistakenly wandering in is not illegal. however your strawman is not what the OP did. it's a paragraph of text for crying out loud. please at least read the story before commenting.
You might have missed this part. I did, too, on first reading. They did sift around.
If that company decided to file charges against him, this HN post is an admission of guilt for a crime.
It's really a lot more simple:
> After I shopped a few companies to see how our plans compared
This isn't white-hat, it's grey-hat at best. Found the vuln, and then used it.
I don't agree with the dramatic reading that I'm responding to.
I would say it's more like:
You are walking down the street, and notice that there is a public noticeboard. It has a list of names, yours among them, associated with a number of steps each. It instructs you to walk a certain number of steps down the street, and then look up at the paper taped to the sidewalk that many steps down.
So, you do, and upon looking down, you see some personal information about yourself! You are a little perplexed, since this doesn't seem very secure. So you take one step back, and look down. Wow, yep, not very secure, there's information there too!
Being a human, you are naturally a little nosy and curious, and as these are publicly posted, after all, you glance through a couple more before finally regaining control of your better sense of civic duty, and report to the owner of the notice board that there is a problem with their "security".
I think this is a better analogy because:
* browsing to a web page is NOT the same thing as going into someone's house. * the internet is public. * there was CLEARLY no malicious intent. The OP clearly didn't harm or intend to harm anyone here, even if perhaps he should have immediately stopped when he began to suspect the website had a flaw and he shouldn't be able to see this information. I see no evidence of malice here.
I do agree that in general, just because a system responds 200 OK, you're not necessarily clear to do anything you want when when you're doing is obviously wrong. But at the same time, we should NOT be prosecuting or blaming people when they're able to access more than they're supposed to be able to PLAINLY due to the software's design insufficiencies and there's otherwise clearly no intent to cause harm.
We really need to take a more even-handed approach to this. And, we REALLY need some kind of a professional bar in software engineering. I would expect a student in their final year of CS to be able to produce a more secure system than what the OP described, so the fact that it exists in a quasi-government website is a complete fucking joke, if you'll pardon my language.
Or perhaps, "Here's a binder with numbered pages; turn to page 345 for your information." You wonder what's on page 346, so you turn the page, and lo and behold, someone else's information.
If once you find the information on page 346, you then keep flipping and looking at people's private information on the next hundred pages like the OP did, you have now committed a crime. The fact that you can easily access something, does not give you the right to access it. If you think otherwise, you think malware that steals your contact and banking info is legal. No, not the one that hacks into your computer. The solitaire game you download and install that has a trojan in it.
After all, you gave the solitaire game access to your hard drive to save and read its own games. Perfectly fine for it to scan the rest of your files. You gave it access to your network card so you can upload your scores. Perfectly fine for it to capture all other network traffic. All trojans are now legal as long as they're packaged with software you voluntarily install.
I agree that morally, the guy should certainly not have continued to look through what he knew was private information he wasn't meant to have access to. I'm not sure the law sees a difference between looking at pages 347-350 and and looking at page 346 however.
Page 346 was an accident - your intent was to read Your data. In viewing Further pages, as the OP stated for the explicit purpose of viewing other people's confidential medical data, the intent is a crime. It's the same thing as walking up to someone's desk in an office you're allowed to be in, and looking through their files.
I don't know what the actual law is, but given the benefits to society of "good people" reporting this kind of issue, I think that toying around with something like that should be considered not a crime at all, rather than being considered a lower-severity crime.
He did not report the issue after finding it. He abused the security hole for his own benefit. He is a criminal.
Low severity? In civil court, they can take every penny he has, every penny he'll ever earn, and his house. In criminal court, he can be charged with unauthorized access to a computer system, one charge each time he did it. And he did it a lot, and they have logs. Which is all literally in his post.
Viewing other people's medical information is not a low severity crime btw.
This was going to the doctor's office, and while sitting in the room with your files, seeing a bunch of other patient files just left on the desk in eyesight.
Not in an unlocked filing cabinet, not in an envelope, but in the open.
Changing a URL is not "malicious use" nor is it considered doing something you're not supposed to.
As a web client, I should be able to change or manipulate the URL to my heart's content, it is 100% the server's job to restrict my access and make sure that I cannot access resources I shouldn't.
This is entirely the fault of the operators, not the user, and they were mad at them because they _allowed_ the user to access things they should not.
They weren't just in the open. A copy of these records were pushed, unsolicited, to the user's device and the user simply looked at what was sent to them.
and as soon as you get this data and you read all that information sent to you by mistake instead of seeing it's not yours and stopping, you have committed a crime. what exactly is it that you don't understand here? what the op did is literally against the law.
>pushed
you should look up how http works. the request to get the data comes from the client browser. it's called a GET. the op requested to GET someone else's records from the server, after knowing the GET request he sent to the server would get him this information.
so again I ask - what is it that you don't GET here? The OP very literally committed a crime. a crime being very easy to commit, does not make it legal.
There's no such crime. If you disagree, by all means cite a statute.
> you should look up how http works.
I'm intimately familiar with http. Upon issuing a request for your records (the request, GET or otherwise), you receive a response, pushed to you, with records you did not request.
I think you may want to re-read my comment, this time more carefully and thoughtfully.
as far as the crime, it's called unauthorized access to a computer system, and many people are in jail for it. whether that system is password protected or not makes absolutely zero legal difference.
As I've mentioned, my metaphor is request, response. This additional data is included, unsolicited, piggybacking on the response. I think this is clear.
Regarding the crime, no, this is completely incorrect. It sounds like you're referencing 18 USC § 1030. This law cannot apply whatsoever to this situation because there is no unauthorized access. The data was pushed, unsolicited, as part of an authorized access. It's being sent to all users when they use the system in a normal authorized fashion.
Viewing the data takes place on the user's own device, because the state itself put the information there. We are all authorized to access our own devices as much as we please.
The suggestion that the CFAA might apply here is nothing short of absurd.
So the data was pushed, very much solicited, as part of a new access. That the user's browser held an authorization (cookie?) for a previous access to the user's own data doesn't quite, AFAICS, mean that this new access to other data was also actually authorized.
...and then proceeding to rifle through a bunch of those files to satisfy your curiosity.
Finding a vulnerability and reporting it -> Good
Continuing to exploit the vulnerability after you've found it just to satisfy your curiosity -> Bad
the law disagrees
as far as your doctor's office strawman - it's a strawman. To see those files, you don't have to actively do anything, if they are left at the desk. Now, if you pick up one of those closed folders, open it, then start looking through it - you have an equivalent comparison. You also have an arrest record.
But don't argue with me. What he did is literally illegal.
Then, while you're at the clerk's counter you notice a menu up high above, like at a fast food restaurant, listing random commands with no explanation. Curiously, you call one out to the clerk and see what happens. The clerk returns with a crushed can. You call out another. The clerk dumps a roll of pennies on the counter.
That's not fraud, it's negligent supervision and stupid design.
(Playing devil’s advocate here)
Tell me, what happens if you, heavyset_go, send an invoice to Apple, and the invoice says you're "Cisco" and they pay it. Do you get to keep the money, or does the prison get to keep you?
The OP was already authorized and authenticated on their own company account. They never falsified their authorization or their identity, they just requested documents at a specific URL and the other party had no problem replying with said documents.
Proper response would have been "Wow! Thanks!" and at worst "Please don't share what you saw, and thanks again."
Instead of a normal company having a bug bounty and sometimes even with cash prizes.
Do you think google "will watch your IP" after you reported a bug? or will they give yo money?
What helps in the short run? and what helps in the long run?
I honestly think they'll do both - but they won't tell you they're watching your IP because it's needlessly antagonistic.
They should check their own logs instead of relaying on a 3rd party that may not tell the truth. This shows incompetence.
It makes one wonder if this is the case with the healthcare site you used, and whether or not this outsourcing of dev is common practice among government vendors? If so, it seems that we can only hope for something to fix these situations, given that government seems to only care once shit hits the fan
"We investigated ourselves and found ourselves clear of any wrongdoing."
I think as soon as anything healthcare adjacent comes up most people will feel the need to get very nosey about what you accessed. It's possible they would have needed to file an incident (though, honestly, they should've regardless of what the reporter responded with) and gone through some procedure.
It's unfortunate the guy was a dick about it - but asking the extent of the data you accessed probably isn't unreasonable and may have been legally mandated.
Your own outrage to your data being exposed would have been perfectly reasonable.
Which is a fascinating discussion, but has nothing to do with the case at hand which is where the underlying html on a publicly accessible search result page contained SSNs of the teachers returned in the search.
All the analogies about ‘it’s like asking the IRS for another document’ are all wonderfully applicable to this comment, but not remotely applicable to the actual article.
But the shoot the messenger aspect of reporting vulnerabilities is also very relevant. It’s just the nature of forums like this that some things bubble up to the top and dominate the discussion. Hard to say it’s your fault for retelling a story.
1: https://web.archive.org/web/20210428154433/https://apps.dese...
They are scared because their leadership is likely also afraid - and so unable to provide protection by taking responsibility.
This is the vibe of an organization where mistakes lead to blame and punishment instead of quick resolution and learning.
There's no way I'm telling them I did that, haha!
Rule 1: Never tell people they're making a mistake unless you trust them to trust you.
I would have thought using incrementing IDs in a URL was as beaten of a dead horse as sanitizing your strings in a SQL query. Then again, ACA websites behaved as lowest bidder was selected.
A friend of mine bought a book online, that was just a link to a pdf in an S3 url.
I chopped off the /book.pdf part, and it was just in an S3 bucket with all the other books they sell.
Oy vey, that was a mess though. Breaches happen, everyone knows it, even companies dealing with PHI that are beholden to crazy HIPAA fines. My report ended up conflicting with a bunch of dates a former supervisor, who at that point wasn't even involved in the department, had knowingly misrepresented to the state. After the fix was merged and I documented the whole scope of the breach, I go and look at the emails and reports on the matter. She's gone told the state all about the scope of the breach, misquoted release dates of the fixes, just minimized a bunch of things with which my report directly conflicted. This person who wasn't in our department anymore shouldn't have even been involved in the first place, yet here I am looking at publishing a report that'll land her in trouble. It put me in a difficult spot. I didn't want to get her in trouble and I thought about misrepresenting my own report. In the end I figured she made her bed, my report was the definitive statement on the matter and her emails were largely reactive so maybe they'd just forget what she said. It was, and they did.
The most important thing you need to do during a breach is be honest. On the other end be vocal and trust in the fact what you're doing is ultimately helpful. The government doesn't want to fine businesses. The only thing that'll end up screwing a company is if they're found to be negligent or dishonest. Negligence is easy to avoid because all you need to do is reasonably try to fix the problem once you've been made aware of it. Dishonesty on the other hand is a foot... that like a diaper-bound chubby baby, some people can't help shoving into their mouths. Don't throw IT under the bus though man, even if that guy on the phone was rude there were some good people on the matter. Some people just don't know how to act when they're caught up in a problem.
"In the letter to teachers, Education Commissioner Margie Vandeven said “an individual took the records of at least three educators, unencrypted the source code from the webpage, and viewed the social security number (SSN) of those specific educators.”
I guess webpages are kinda like encryption for idiots.
Edit: sorry, forgot the /s
The actual quote states that the data was first "unencrypted" before viewing the source. This is in fact correct if not poorly phrased, but who'd expect proper terms used when we're talking about "these" people?
Its like saying you stole documents from a sealed container when that container had your name on it, it was addressed to you, and you had the key.
Now they’ll sue browser makers for distibuting hacking tools.
This is how I found out how much I, and all other contractors were being paid. And also how much the contracting company was actually charging the clients. All the data was being returned in a json but the very little was being displayed.
Looking at the story, this is more of a posture thing. I'm sure the Governor is surrounded with people who can tell him that no hacking took place, but why miss an opportunity to show you take the privacy of Missourians to heart.
Obviously if you broke into someone's house and then asked them to pay you for your 'vuln discovery', err...
However, I think looking at HTML code on a public facing web page is not that. If you hang naked pictures of yourself on your front door, you don't get to complain when people take pictures of them.
1. https://www.calyptix.com/top-threats/port-scanning-legal-ans...
View Page Source.
That's 2 steps. Hence, multi-step.
:)
This is the same reason why I think most of the general public don't understand how much data social media apps can collect on them. I know a lot of average technology users, who allow every single permission whenever an App asks them, because they're like obviously its not going to do any harm. Without realizing how every action they take is recorded in a database somewhere, which will get compromised sometime in the future.
I'm not a mobile developer, but it would be interesting if iOS provided a service that allowed data to never leave the phone and provided an API for Apps to get particular types of data and showed warning levels in the App, each time more sensitive data is accessed. The App store needs to be a place where if I download an App from, I need to have the peace of mind that it won't cause more harm than good.
I'm not sure I follow. Do you mean the app wouldn't be allowed to send any data over the network? As soon as the app can send any data, it's trivial to hide in there whatever the app wants to send home.
You either have to completely trust the developer today and forever after, or you need to make some fundamental advancements in homomorphic cryptography. "Secure data store that can be queried with a permissions box" doesn't work.
In this case, it sounds like the SSNs were included in their entirety in the HTML. My first response is that its a stupid and obvious mistake, but I think it might be too suspiciously easy to only blame the developers here.
I think we have a larger problem - which is that there's a hidden cost to adding extra layers of magic to software. And on the web, we seem to just not be able to help ourselves. The cost is that developers often skip actually understanding how the new layers work. And the abstractions are leaky with respect to performance and security, and sometimes functionality.
Its easy to imagine how this bug slipped through. They had a database query which fetched the data for rendering. Then they used some "magic" framework which does server side rendering & hydration. So the server sent the JSON it used to render to the client to dehydrate the page, and that JSON happened to include the raw database rows (with SSNs). The system is magic enough so you don't have to understand how that process works; but not magic enough to protect you from the consequences.
Junior devs use the magic anyway and get stuck, or make mistakes like this. Senior devs feel like we have to learn everything and get overwhelmed.
Other examples of this:
- Recently I wanted to use some rust code (compiled to wasm via wasm-pack) in a svelte project with snowpack or rollup. I know how to include wasm in a webpage, but the bundlers needed special plugins to handle this. And the plugins for wasm are halfbaked, poorly maintained and janky.
- I worked with a team a few years ago who was using some graphql wrapper around contentful. (Before contentful had an official graphql endpoint). The wrapper was very good, but we needed to run some queries that weren't supported by the wrapper. This was close to impossible. Nobody on the team was strong enough to read the graphql code to figure out how to solve our problem. I did it eventually - via some custom endpoints. But I shouldn't have. After I left the team had no idea how to maintain or modify the code I wrote, and they were entirely stuck.
- The "web obesity crisis" comes from projects pulling giant amounts of javascript into their webpages. Our tooling makes this easy (npm install) and safe (incompatible versions of the same package are included separately). So its easy to end up with libraries like web3, which include about a dozen different versions of bn.js resulting in 2.3mb of uncompressed JS which takes nearly a second to parse on a modern computer. - [1] https://github.com/ChainSafe/web3.js/issues/1178
I don't know what the answer here is, but I know when I was writing qbasic as a kid it wasn't like this. Maybe we need to stop going "up the stack", and instead go sideways - throwing things out as we add more. I worry this whole problem will get much worse before it gets any better.
But it would probably be even more interesting if you could send out, say, the adress of a Web page you wanted to see in your browser.
The State labeling a reporter as "a hacker".
* https://dese.mo.gov/media/pdf/educator-data-incident-commiss... * https://twitter.com/mocommissioner
State Education Commissioner refers to reporter only as a "individual". The Commissioner signs the letterhead "PhD". Sarcastically, I presume the PhD corresponds to the increase in level of correctness, from "hacker" to "individual".
I prefer to call them muggles.
He either has staffers who told him the real issues and he discounted them to score points, or hired incompetent staffers who gave him B.S., or he hasn’t found anyone to give him the real info. Those are the disqualifiers.
Memories of Mitt Romney appearing to actually dig into tunneling and adhesives during an investigation of Big Dig flaws in Massachusetts. He might have been posturing but at least it was the right posture.
It seems stupid to us, but non-techies just won't understand unless we come up with reasonable analogies.
About 12 years ago, someone smashed the window of my car and grabbed my messenger bag, including my cheap prepaid smart phone and shitty laptop— I was a line cook at the time, and those were my most valuable possessions except my knives. Filed a report and moved on. Hours later, I later saw a picture of a person I didn't know standing next to a car with a visible license plate automatically auto-uploaded to my Facebook account from my stolen phone. I called up the detective assigned to the case, but as soon as I said "uploaded" he said I needed to talk to the "computer guy," who called me the next day. After— no shit— 15 minutes of back-and-forth, this expert absolutely could not understand that I wasn't trying to report the new crime of someone accessing my Facebook account without authorization. He had no clue how it possibly could have been related to a telephone. In 2009.
Before I cooked, I'd worked in support from entry-level call centers to code level third-tier support. I am completely confident in my ability to explain WAY more complicated technical ideas to folks who've never used computers before... but I just had to give up. I didn't know what else to do. He was possibly the least technically capable person I've ever encountered and I used to help 90 year olds remove spyware from windows 98 machines. I said never mind and hung up the phone. Depressing.
> "According to the Post-Dispatch, one of its reporters discovered the flaw in a web application allowing the public to search teacher certifications and credentials. No private information was publicly visible, but teacher Social Security numbers were contained in HTML source code of the pages."
It's events and negligence like this that give credence to credentialing requirements for software engineering.
Also, pretty sure that you have to be at least somewhat narcissistic to think that you should be president, and somewhat sociopathic to actually succeed.
along your lines of considering the forum, wouldn't it need to be aiding && abetting? i don't know how to bitwise compare aiding to abetting.
What a "hacker" is is a matter of definition.
But, the fact is the state was using "encryption" with such a level of security that pressing one button on any computer with a browser is all that is required to defeat it.
"The Governor is in possession of software on his personal computer that allows him to decrypt the personal details of thousands of constituents who may have voted for or against him."
The "software" being a web browser, of course.
/not sarcasm, I wish I was joking...
> Information needed by an attacker to begin looking for possible vulnerabilities in a web browser includes any information about the web browser and plug-ins or modules being used. When debugging or trace information is enabled in a production web browser, information about the web browser, such as web browser type, version, patches installed, plug-ins and modules installed, type of code being used by the hosted application, and any back-ends being used for data storage may be displayed
I wish I were making this up.
[1] https://en.wikipedia.org/wiki/Security_Technical_Implementat...
[2] https://stigviewer.com/stig/microsoft_internet_explorer_11/2...
[3] https://www.stigviewer.com/stig/microsoft_edge/2021-02-16/fi...
[4] https://www.stigviewer.com/stig/google_chrome_current_window...
I can only imagine how much taxpayer money has been set on fire by developers having to debug single-page applications running on these systems without the aid of Dev Tools... these types of material wastages are created in an imperfect attempt to prevent the mere possibility of something that could be more effectively mitigated through training and web content filtering.
Is this saying that when you viewed a certain page (which I assume had only one person's SSN visible, or perhaps other teacher information like names), the "invisible" SSNs were just hidden with `display: none` or similar?
Literally a reporter's job.
Someone about to experience the Streisand effect in FULL force.
If they lose in court it turns into a two for one as they get to rail against 'activist judges' and whip their base to go out and vote.
Surely no official interprets it to mean: protecting the public image of officials by way of hiding pertinent information from the public, right?
https://en.wikipedia.org/wiki/New_York_Times_Co._v._United_S...
It’s not even a partisan thing, it seems like almost all our major parties seem to lose 40 IQ points when the internet is involved. Everyone from Blair onwards has been a tinpot authoritarian when it comes to digital rights.
More than half of sampled Maps couldn't calculate the probability of two heads in a row from a fair coin
I really don't understand the whole "double down" approach to doing things.
Those scheming reporters! /s
And the governor's helping!
But.
Every time I see something like this, it just about drains my spirit to nothingness. I want to embrace nihilism and just quit giving a fuck about anything or anybody when I see stupidity on this level, and displayed by somebody who managed to get elected governor of a %@%#ng US state. It really is hard sometimes, to not just withdraw into a shell of isolation and decide "fuck it, this world is too damned stupid for me to bother with."
I don't like feeling that way mind you, and I actively try to fight the urge to give in to that kind of thinking, but it seems to get harder and harder with every passing year. Am I weird in this regard, or are other people experiencing this as well?
This is what we need to work on correcting. If a judge laughs your case out of court, there should be a severe penalty, especially if you're the government.
Hard disagree. If you're arguing that it's malice, and not stupidity, on the part of governor and others that put out this nonsense, then at least they are surely depending on the stupidity of their constituents at large for not laughing them out of office.
And to be clear, I'm not at all taking the position that people who don't have a deep depth of technology are stupid. But pretty much everyone in the US knows how to use a web browser these days, and believing people will buy the governor's completely lobotomized argument [1] is totally embarrassing, either for the governor or his constituents that elected him.
1. https://twitter.com/GovParsonMO/status/1448750830857904129
I want to believe that, but after watching the Trump administration and how people seemed to embrace him more and more despite his continuing shameful acts, it's just hard to sustain belief that this all leads anywhere.
Sorry guys, not trying to be Debbie Downer here. I guess I'm just in a shitty mood today for some reason.
No they aren't. Not even remotely close. I'm exhausted by "both sides". "Both sides" arguments cause apathy in people because what is even the point in voting if, "both sides".
I'm with you 100%. I don't want to be there, but there I am. And sometimes it all feels utterly pointless – civilization, the human endeavour, everything. My particular slippery slope goes like this:
Humanity is going to waste the one-time gift of fossil fuel accreting the already-grotesque hoards of a few hundred individuals. Then these people will die, nothing will have been gained on the whole, and instead of infrastructure which we could have used to pivot to some recognizable future, our descendants will be left with nothing but unrest and some variety of ecological hot potato. And then we will all die out or revert to a pre-technological state, and either way all the gains of science and human ingenuity will be lost.
Is that how yours goes too?I don't know what to do about all that, but usually I can convince myself that working on some tiny project to help things not go that way is a worthwhile effort. And of course it's pretty much all I can do.
Also here are a couple quotes that help me get out of such perspective ruts:
* "Even though I'm always in pain, it's worth sticking around to make my corner of the world a slightly better place." -Ricky Gervais' character from After Life
* "I cringe at my arrogance. Actually, cringing at my arrogance is just another, more rarified, level of arrogance." -Alison Bechdel
* "Goodness: You got to make it out of badness. Because there isn't anything else to make it out of." -Robert Penn Warren
I stepped out of public engagement for a while, then moved to Portland when I was ready to get back in. That was a whole new lesson: the lefty/progressive types are just as bad at governing. And the leftist/progressive voters are just as likely as the right to treat politics like a team sport. Portland is more dangerous for black people than Chicago now #BlackLivesMatter. Developers keep pulling out of affordable housing developments because of planning bullshit, and the city thinks its a good idea to mandate that contractors be women owned. Meanwhile, thousands are sleeping rough.
The politicians are awful, but in a democracy, the fault for that lies 100% with the people. Elected office, like next-door, doesn't make people bad; it simply reflects the rotten core of 21st century civil society.
Absolutely maddening is the lack of interest in concrete policy or actually using data to analyze changes and measure success.
I think I'm about ready to stop caring and have a nice life while my species hurtles towards the great filter. Life and the universe are meaningless anyway.
Yes and no. Yes in that the politicians are selected from people they represent (in theory), but also no in that once a person becomes a politician, their incentives change and they are no longer representing the people that elected them.
Further, once in power, the systems can be "rigged" into maintaining that power (gerrymandering is an example of this). DJT couldn't become King of America without first becoming president. Once he became president, though, he definitely tried to rig the system to make him, effectively, King of America.
Democracy is a convenient way for the ruling class to hand-pick the people who are allowed to run for office and blame the voters for any bad results. There's research showing that there's very little correlation between the policy goals of the voting public and policy outcomes, but there's a strong correlation between policy goals of the ruling class and policy outcomes.
If you accept that there is such a thing as a 'ruling class', then presumably the only way to define them is 'the people who get their policy goals accomplished'. Because that's what 'ruling' means.
- in the top .1% of net worth
- in executive leadership positions
- attend elite universities
- frequently possessing generational wealth
I hope this helps.
In moderation, I think this is actually the correct response. Unless you live in Missouri, who cares what stupid things the Governor of Missouri says?
In a previous era, you never would have heard about this story at all. It's just a politician in a minor state trying to score some political points. It's very unlikely they'll actually charge the reporter with anything, much less convince a jury to convict.
In today's connected world, it's easy to get news from anywhere at anytime and be outraged. Sometimes you just have to ignore it for your own sanity.
Because that person literally rules over millions of people, the overwhelming majority of which didn’t vote for him (1.7m votes out of the 6.1m population). Right now he is literally threatening state violence against a reporter for looking at a government website that accidentally leaked personal information.
Getting a prosecutor to risk their career on prosecuting a journalist for politics is quite a bit more difficult. Journalists are well aware of their rights, and have lawyers between them and law enforcement.
I think its dumb, but as a former photojournalist who had a very large oil company (Haliburton) use a very small police department to come after me for trespassing, I can assure you that the newsroom is NOT scared right now.
But that's what's got me so depressed over the past 5 years or so. It used to be, in the not too distant past, that politicians were embarrassed to be caught in an easily demonstrable lie or stupid gaffe.
These days they just yell "fake news", repeat the lie/gaffe louder and more frequently (which is EXACTLY what the governor is doing on Twitter [1]), perhaps maybe pair it with a catchy slogan, and that seems to be a winning strategy.
1. https://twitter.com/GovParsonMO/status/1448750830857904129
Basically, we are living inside a spaghetti mess of a civilisation.
But I’ve also spent twenty years working in various big balls o’ mud codebases, at companies that had big systematic problems that got them that way, and in that time I’ve found some strategies that can make positive changes, even under conditions of extreme chaos & status-obsessed executives. And they all start the same way:
Find a coworker, ask them how their work is going, and then really listen.
Don’t go in with any agenda except building a relationship with you coworker. If the have stuff they are proud of, tell them what you like about it. If they have stuff they are struggling with, you can commiserate. You might be able to help, but probably not: you are both living in a giant mess of a disaster world full of incentive systems that push people to behave the ways they are behaving.
But by setting that aside, by prioritizing your relationship with even just one other person over that perverse system that exists today, you are resisting. Authentic, caring conversations that prioritize people over process are radical acts.
Maybe the first person or the first dozen aren’t interested. That’s okay. Eventually you’ll have a second genuine conversation, and now you have two relationships. You can introduce those two people to each other, and suddenly you have a community.
A community can get things done none of us could do alone.
I learned these techniques from the grouchiest, grumpiest old grey beards I worked with, because they were how they built support for the infrastructure they wanted to use. I’ve use the technique for different purposes (livable code, low alert volumes, sufficient time & space to mentor junior engineers into being the mentors of junior engineers, not selling contracts to Palentir, more than two weeks vacation time, fixing user problems before adding shiny new whistles to get the PM promoted, not planning two years of work at once, etc), but fundamentally it is the same. Positive changes start with building a tiny little corner where we set aside our doubt, gather up our courage and build a community rooted in sufficiency and willing to trust.
The only message here is "be careful embarrassing fascists."
HN notices it when it's a tech issue, but it happens in economics, medicine, basically everywhere. They have zero incentives to accept responsibility.
Was Obama a fascist? I have no desire to engage in whataboutism, they all show their true colors when they're in power and shown corrupt or incompetent.
Then don't.
I think Snowden should be pardoned and considered a national hero, but he unquestionably committed a very serious crime. There was no crime committed in the State of Missouri on this matter.
i’m not from the US, but is it common in the US to use these kinds of accusations? seems ultra far fetched.
If you aren't among one of the two sides it can be humorous to watch at times.
https://www.washingtonpost.com/news/the-intersect/wp/2017/08...
"It’s Time to Call Nazis ‘Nazis’"
https://www.thedailybeast.com/its-time-to-call-nazis-nazis
Chap behind Godwin's law suspends his own rule for Charlottesville fascists: 'By all means, compare them to Nazis'
https://www.theregister.com/2017/08/14/godwins_law_creator_r...
And there's the law itself. Mike Godwin takes pains to clarify that it's not about valid or invalid comparison, or who's "winning" or "losing" the discussion, as it is an observation that productive discussion within the thread is over.
Specifically:
So - *WHAT DOES IT MEAN*?
Fine, fine - it means that somebody's eventually going to say
something about the Nazis in any thread that lasts very long. When it
happens, the thread is going to start either degenerating into a long
flamewar over Nazi Germany or about Godwin's Law. Either way, the thread
is effectively over, and you can safely killfile the thread and move on.
... 2. What happens if we're actually talking about Nazis?
Then you've already invoked Godwin's Law, and the chances are that
your thread isn't going to last all that much longer as a sane discussion.
Them's the breaks.
3. What about arguing with Neo-Nazis?
Arguing with Neo-Nazis is probably the quickest path to getting
Nazi invocations, because, well, they're actually accurate. Still, trying
to invoke Godwin's Law near a Neo-Nazi isn't really a good idea because
it's not terribly original and they'll probably get off on it anyway.
Just ignore them and occasionally publish a FAQ detailing what actually
happened during the Holocaust and such; arguing probably isn't going to
help you.
http://wiki.killfile.org/projects/usenet/faqs/godwin/This thread has reached the discussion-of-Godwin's-law stage, so there's that.
And remember that "it can't happen here" is also a fallacy.
It's not an exaggeration. Stephen Miller, Steve Bannon, Richard Spencer, all these people in Trump's inner circle are self-described "alt-right," "white nationalist," or some other euphemism for ethno-fascist.
Racism and fascism in the US are very real, serious problems, and have become synonymous with the Republican party.
edit, here is a link or two:
https://www.vanityfair.com/news/2017/05/stephen-miller-duke-...
https://www.npr.org/2019/11/26/783047584/leaked-emails-fuel-...
If it was in the HTML source code, then it was publicly visible, so it is unclear what the article is trying to say.
And look at the age of the governor, clearly shows that he is inept with the fundamental of the internet.
I forgot to add one more thing. Did they not realize that there are scrappers who will scrap every bit of information of everything including the HTML code. I wonder how mcuh scammers/ID theft scrapped the data before this come to light?
“Webmasters”, where they exist at all anymore, tend not to “design code”.
> Did they not realize that there are scrappers who will scrap every bit of information of everything including the HTML code. I
“...scrapers who scrape...” should be the concern here, not “...scrappers who scrap...”
> And look at the age of the governor, clearly shows that he is inept with the fundamental of the internet.
Gov. Parsons is 12 years younger than Vint Cerf and the same age as Sir Tim Berners-Lee.
https://news.stlpublicradio.org/government-politics-issues/2...
"Missouri Gov. Mike Parson on Thursday launched a criminal investigation of a St. Louis Post-Dispatch reporter... The investigation begins today, and Parson said the investigation could cost taxpayers as much as $50 million but did not detail those costs or take questions at a news conference Thursday."
$50m over this now? They say never to assume malice when outright incompetence will do, but I'm beginning to wonder if some corrupt dealings involving IT contractors might be going on under the table.
Whichever one it is, at this point I think the governor should just apologize and resign immediately. Not holding my breath.
Edit: Looks like the governor is tweeting about this now. Straight from the horse's mouth:
https://twitter.com/GovParsonMO/status/1448697768311132160
Really couldn't make this stuff up if I tried: "This individual did not have permission to do what they did. They had no authorization to convert and decode the code."
>“Journalists responsibly sounding an alarm on data privacy is not criminal hacking,” he said.
I worry that we're heading in a direction where somebody like Lovasco won't be willing to break with somebody of the same political party even for something like this.
It's already incredibly easy to code this story as a PR "win" for Democrats by embarrassing a prominent Republican.
So then isn't giving a common-sense perspective in this circumstance kind of just a betrayal of everything your side stands for?
I mean it's pretty unlikely that anything of legal import actually happens to the reporter, so for the "greater good" of accomplishing your wider agenda, or perhaps even more importantly preventing the other side's agenda, it might be better to just stay quiet and let this blow over as partisan bickering.
To make matters worse, incrementing a number in the URL cycled through different hospital waiting rooms.
I emailed the vendor who build the tool about the issue and they responded letting me know that system worked as it was designed, and that no HIPPA violations existed since there was no full last name.
I meant to make a bigger deal about this, but then got busy.
I mean someone it the freaking state bureaucratic hierarchy should at least be lucid enough to consult someone who has an actual clue about things as these.
Politician: Socials are on the web site, who fucked up?
IT: the web page is encrypted, we didn’t fuck up, the hacker decrypted the source
Politician: sounds good to me, no fuckup on our part, let’s call the cops and prosecutors
Given the impact of technology on society, we absolutely can and should blame politicians who are technically illiterate.
I can and will blame them for not getting (And listening to!) a tech savvy advisor.
That right there (probably without the age bit) would be the ideal one liner response from the reporter or an attorney from the paper.
He's using the public's fear to try to gain political points by looking "hard on crime".
Obviously, he's stupid. But part of the problem is the public also think this was a "hack". Basic understanding of the web is not apparent amongst an enormous swathe of the public.
Why are you letting the leader off the hook and charging the underlings for being responsible for something a leader should be responsible for? Age of the leader is irrelevant because the leader chose to become a leader.
Now imagine what this situation teaches all the younger bureaucrats who think they can work hard and make things better.
This incident is just one example of this in action.
No, but it is both South-adjacent and is considered to be largely within the Bible Belt, which is almost exactly coextensive with the South, except that it excludes parts of Southern Florida and includes all or part of several South-adjacent states, so it's not an entirely hard fo understand mistake.
This seems libelous. Can you provide a single example of such a statue? I drive through several county seats in Missouri multiple times a week. There are WWII and Vietnam memorials, and actually several Civil War Union memorials, but not a single confederate memorial.
Chernobyl suffered from compounding of reactor and test design flaws and human error. Fukushima suffered from (retrospectively) insufficient risk assessments, which resulted in a design meeting a rare event beyond it design limit sooner than expected.*
I'm unaware of a human society, in fact any animal society, where politeness does not involve some degree of deference. So saying these accidents were caused by a culture of deference is essentially meaningless without some more "who, what, why, how" and importantly 'how much' and 'compared to what'.
From the IAEA report: "This common mode failure reached a scale considerably beyond that usually addressed in the assessment of BDBAs. [ed: beyond design basis accident]". https://www-pub.iaea.org/MTCD/Publications/PDF/AdditionalVol...
https://www.coursera.org/lecture/intercultural-communication...
This attitudes fits the majority of workplaces. I know it probably makes you feel better to pass the blame off on a specific group that you can try to avoid but I've worked all over the US and it's the same crap everywhere you go.
I don't think age should excuse this guy at all, nor do I buy into the meme that age has much of anything to do with technical literacy. Consider that Brian Kernighan is ~78, Tim Berners-Lee is 66 (the same age as Governor Parsons here), James Gosling is also 66, Rob Pike is 65, Steve Wozniak is 71, Geoffrey Hinton is 73, and so on. And that's not even considering folks who were around so early they've already passed away, like Marvin Minsky, Dennis Ritchie, John McCarthy, etc.
I would question that assertion, depending on how exactly we choose to define "few". Computers have been a fairly ubiquitous part of our society (in developed nations anyway) for a good 40 years or more now. And they've been absolutely ubiquitous for probably a good 30 years... ubiquitous enough that it's hard to see how any person who considers themselves an educated, competent adult wouldn't have had the opportunity to develop some baseline of technical literacy.
Personally I believe that anybody who is a functioning adult in our society today, who doesn't have that technical literacy, lacks it due to their choices not due to their age.
Younger people tend to be more open to new things and less set in their ways, which certainly makes a difference in this case. Note that I'm again not talking in absolutes, but about matters of tendency. Naturally, in the individual case all things come down to opportunity and choice, but it seems curious to deny the statistics of the matter.
Younger people tend to be more open to new things and less set in their ways
Even if that were true - and that's a pretty dubious claim, IMO - it does not necessarily follow that
... certainly makes a difference in this case.
Yes, so did I. I find it curious that we seem to remember that period so differently.
I can easily find sources saying things like "between the ages of 25 and 60 people's ability to use websites declines by 0.8% per year", that's 28 percentage points difference in the ability to use a website.
But I'll stop arguing, it doesn't seem very promising at this point.
I certainly can. They have plenty of money to hire staff, and that should include people to make sure they understand the technology that is integral to the every day lives of their constituents, or at least to push back when they do/say something completely counter to how the world works.
Republican state Rep. Tony Lovasco, who according to his legislative biography has worked in software deployment and maintenance, tweeted Thursday that “it’s clear the Governor’s Office has a fundamental misunderstanding of both web technology and industry standard procedures for reporting security vulnerabilities.
“Journalists responsibly sounding an alarm on data privacy is not criminal hacking,” he said.
>Through a multi-step process >decoded the HTML source code
Somebody has been watching B-list hacker movies.
Step two: Press U
2. Hover over developer menu item
3. Click View Source
Three-step process - even more nefarious!
2. Press finger downward
> “Finstas are fake Instagram accounts. Finstas are kids’ secret second accounts. Finstas often are intended to avoid parents’ oversight. Basically, Facebook depends on teens for growth,” Blumenthal said. “Facebook also knows that nearly every teen in the United States has an Instagram account; it can only add more users as fast as there are new 13-year-olds.”
"Gov. Mike Parson was labeling the Post-Dispatch reporter a 'hacker' and vowing to seek criminal prosecution."
L O L. Everyone who has hit F12 in a browser is now considered a hacker.
I hope the prosecutors and law enforcement come to the right conclusion quickly and tell the governor no crime was committed. My experiences have left me with little faith of that happening.
I don't think this will cost them their career. Every semi-intelligent person can see what's going on. It will certainly create some shortterm headaches though.
Imagine HTML is a TV in Social Security office. The way the storage of SS numbers was designed, is that they are hidden in a backroom, however, anyone can come into the office and scream a persons name to view all the information on the screen. The flaw is clearly in the system.
I found flaws in Costco system before, I guess I should be in prison for letting them know and saving them thousands of dollars.
getting a 403 here without a vpn, but https://cybersecurity.mo.gov/ doesn't look like its been updated since 2018 The last CISO left in 2018 (~3months after the current governor took office), and the current ciso was appointed by interim then https://www.govtech.com/blogs/lohrmann-on-cybersecurity/miss...
I honestly pity him a bit, because he has no clue about any of the technical details, but on the bright side he's about to get a crash course.
I have to wonder what he's thinking, though, with the brazen slander. He must have some very deep pockets.
This governor is a fricking idiot.
I understand not everyone can know everything. The fact that it is deemed unacceptable to admit not having all of the information to make an informed decision/comment where someone in a position of authority makes shit up to just sound authoritative is a sad state of affairs. It's not like being a governor is the same as posting things on an internet forum.
If the reporter searched teachers and located (for example) their teacher ID, then discovered an endpoint (from looking at the JS) that took the ID as input and returned an SSN, they have potentially violated the CFAA (as written).
Do I agree that they should be prosecuted? No.
Is the CFAA a terrible law that criminalizes most netsec research? Yes.
Yes, everything that makes us look bad is part of a conspiracy by the other team. Ignore the facts, please. Pressing CTRL-U is hacking!
For an in-production system, there is a good chance that they have no responsibility for ongoing maintenance, and no special information beyond what is on the website as to who is responsible for maintenance.
You are better off contacting (anonymously or otherwise) the responsible agency. But, sadly, probably the most effective way to get it changed (after the flurry of butt covering) is to anonymously notify the media.
This was many years ago, a few years after it first happened I looked again and it had been fixed.
The website takes a LONG time to load because of how many javascripts it loads!!
They are obviously trying to deflect their incompetence - nobody audited the design nor the resulting implementation.
If the journalist acted as described it is professional behavior (notify and postpone publication to give the Website operator a chance to fix things), it is ethical and complies with security disclosure best practices.
My bet is the SSN was used as the GUID for a table row or list item.
"As governor, Parson signed a bill criminalizing abortion after eight weeks of pregnancy and opposed Medicaid expansion. He oversaw the state's response to the COVID-19 pandemic, where he issued a temporary stay-at-home order in April 2020, allowed schools districts to decide whether or not to close, and limited postal voting during the 2020 U.S. elections. Parson also oversaw Missouri's reaction to the George Floyd protests, during which he pledged to pardon Mark and Patricia McCloskey, the couple involved in the St. Louis gun-toting controversy, if they were convicted of any crimes; he issued their pardons in August 2021."
Sounds like a great guy.
I gather the previous (also Republican) governor, Greitens, who may or may not have been into some weird/illegal sex stuff and was forced out over it, was actually pretty good. Seemed to truly care about governing well and improving the functions of state government, at least, which Parson does not.
I assume they'll start with the head of the Office of Administration Information Technology Services Division whose team allowed such a glaring vulnerability in the first place.
If IT management held some responsibility for breaches, then maybe it wouldn't be so hard to get funding for security measures.
"The hacking is coming from inside the (state) house!" /s
How is an HTML page source not considered "publicly visible"?!
[0] https://en.wikipedia.org/wiki/Greg_Gianforte#Election-eve_as...
My friend attempted to submit his and when he tried to download the paperwork that needs filing he discovered that not only was it very slow but they basically threw a webserver at a Windows PC’s C drive and turned indexes on and proxied it into a subfolder. So he could browse the entire computer and similarly could access the private data of every employer and their employees in the country. He wrote a few emails to relevant places and by the next day the entire thing was offline. I believe they never put it back up, and I know for sure they delayed applying the law by an entire year, maybe through some emergency decrees or idk. They didn’t really publicise it outside of saying that it’s been delayed. You now have to submit it in person.
[1] https://fox2now.com/news/missouri/missouri-education-departm...
Talk about corruption - spending taxpayer money to cover-up mistakes made by government employeers - AND libellous statements made by government officials...
In this case, I'm not terribly surprised since that governer is from the party which frequently equates educated people as being "elite" - a characteristic to be avoided.
Remember when the state of Florida labelled an epidemiologist, who they had previously fired for not cooking the books on covid cases to make the state look less bad, a "hacker" because she sent email to a state-run mailing list? https://www.tampabay.com/news/health/2020/12/07/florida-poli...
The mailing list was claimed to be "secure", but there was nothing secure about it. Other than the fact that merely by convention only certain people were supposed to know about it and use it, it was completely unsecured.
Then I guess HN better find a new name.
Seriously though, this defense bugs me because it outright dismisses the idea of ethical hacking by re-defining "hacker" as someone with "malicious or criminal intent". They should embracing the label and explaining the difference between white hat hackers and black hats (the actual criminals).
Our world needs more white hat hackers. All it takes is one security flaw to compromise a system and the deck is always stacked against those securing it. Re-defining "hacker" as a term to describe criminals stacks that deck even worse by dissuading future would-be white hats.
“political game by what is supposed to be one of Missouri’s news outlets.” Now they get to ignore any and all responsibility and the governor is seen as standing up to the liberal media. It did not even have to be a big deal, just fix it, say its been resolved and move on. Everything is gamified and politicized now; to the point they are willing to send someone to jail over their own flaw. Its not even about being good leaders and helping citizens its just about winning elections and owning the libs or conservatives or your favorite brand of "snowflake". Human decency has left the building. I wish we could go back to business as usual but we have really entered a post truth society.
> "a race to the bottom to see who can be meaner and madder and crazier. It is not enough to be conservative anymore. You have to be vicious." The viciousness doesn’t necessarily reside in the individual souls of Republican leaders. It flows from the party’s politics, which seeks to delegitimize opponents and institutions, purify the ranks through purges and coups, and agitate followers with visions of apocalypse
I feel this article summarize it well: https://www.theatlantic.com/ideas/archive/2018/12/how-did-re...
Newt Gingrich seems to be responsible for that more recent attempt at this, and everything happening now seems to be the end game of what he started, though the party seems to have a history of it to some extent.
I know some people might say that the Atlantic is partisan and maybe Democratic leaning (I think?), but personally except for the part where the article seems to say they don't like what the Republican party is making of democracy, everything else seems pretty accurate and factual to me. I'd love to hear counterpoints, like is there anyone who doesn't think this characterizes the Republican party properly?
I feel there's an enormous education/awareness gap when it comes to basic security practices and it's going to hurt all of us sooner or later by having our private information leaked, sold, abused, maybe ultimately deemed irrelevant in itself -- ie what would the world look like if all (or a significant chunk) of private information was leaked and you couldn't trust the old tokens of identity?
Was this a drive-by "view source"? Why is the highway patrol investigating?
In a number of states, the “Highway Patrol” is—either through role expansion, merger with a preexisting State Police, or otherwise—the general-jurisdiction law enforcement agency of the State.
They definitely have a different definition of "publicly visible"
Terribly idealistic, I know. One can dream... :|
The state's website was sending SSNs to the browser of every visitor. Visitors didn't ask for that info but got it anyway. Everything the state sent was viewable thru View Source.
I almost didn’t report it, since the kind of shit as described in the link above gets reported so regularly. But I did, and it got fixed quickly. Now I’m just sat here hoping I don’t get served a lawsuit next week by some idiot hoping to cover their ass and make me out to be some kind of malicious actor. (Advice welcome...)
Any precautions that you recommend when reporting this kind of vulnerability/data leak? (Apart from "do not access other people's data if you can avoid it")
For example here is one from the Guardian: https://www.theguardian.com/securedrop. Here is one from the Washington Post: https://www.washingtonpost.com/anonymous-news-tips/
"According to the Post-Dispatch, one of its reporters discovered the flaw in a web application allowing the public to search teacher certifications and credentials. No private information was publicly visible, but teacher Social Security numbers were contained in HTML source code of the pages."
I expect there will be no consequences for the mindless idiot who put SSNs in the HTML output.
https://www.robotsinplainenglish.com/e/2021-10-14-blame-sham...
I hope HN readers will (gently) correct any mistakes or provide clarifications to make it better. Thanks!
No this didn't actually happen but it's the analogy that came to mind.
He does not, however, feel like expanding on what that means. Several people tried to reach him on that, without success.
Does anyone have "lawful" access to the site? I want to see for myself how those bits of PII showed up in the markup.
Dumb move on his part.
It's a damn shame such political dinosaurs have such a major impact in hacking.
Its not hard to see how someone with only a rural sixties highschool education might conflate this particular revelation with treasonous intent.
<call target="broker">
<communication command="buy">
<stock>Orville Redenbacher</stock>
</communication>
</call>Maybe like, the state mails letters out, and a reporter realizes that if you slit the envelope open, you can see that sensitive information was accidentally printed inside?
Because that's what you seem to want ... quit electing morons.
So "view source" is now hacking.
So now 'View Source' is an decryption tool use by those pesky "hacker" types?
Many politicians are much older than me.
At their brains just hard-wired to see an enemy everywhere?
I'm not asking if it should or shouldn't be.
I'm asking if it is, with the laws as written and interpreted today.
Somebody who's been out of touch for the past 20 years could easily see responsible disclosure as the beginning of an extortion attempt. "I can access your data and I'll publish sensitive information about it in 30 days." sounds like it's about to be followed up with "...unless you send me a pile of money in unmarked bills".