Viewing website HTML code is not illegal or “hacking,” prof. tells Missouri gov.
arstechnica.com
arstechnica.com
Which looks something like this in the html:
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="BASE64STUFFHERE=">
There is a choice to encrypt it, but I'm skeptical how useful that is, or that it was enabled in this case.
So the "hack" was "view source" -> decode some base64 data sitting in plain sight.
Edit: A little bonus. This bizarre video from a PAC the governor started, still trying to call this "hacking": https://www.youtube.com/watch?v=9IBPeRa7U8E
The docs on how to encrypt[0] this information has an interesting example use case:
> View state data is stored in one or more hidden fields on the page and is encoded using base64 encoding. ... In some cases controls might use view state to store information that no users should have access to. If those identifiers contain sensitive data, such as social security numbers (emphasis added), you should encrypt the view-state data in addition or instead of sending over SSL.
[0]: https://docs.microsoft.com/en-us/previous-versions/dotnet/ne...
In this case, they just really shouldn't have sent the SSN at all, as only the last 4 were ever displayed on the page.
One interesting thing about Missouri is that, in addition to the Governor swearing to take care that the laws are faithfully executed, Missouri says that violating your oath of office is per se perjury.
In my opinion, the Governor needs to be impeached and prosecuted criminally for abusing his office in this manner.
i wonder how many browser caches currently hold that list.
now the next part is interesting, seeing as the government issued that list, is it now part of a public domain? can any one who distributes or causes it [list] to be distributed, be prosecuted?
https://www.change.org/p/governor-parson-apologize-to-st-lou...
Do petitions accomplish much? I don't know. Still, someone needs to tell this guy he's an idiot.
In some states if you have screened in porch and you break the screen, it is still breaking and entering.
Even the base64 could be equivalent to the screen door.
I hope the reporter doesn't actually get prosecuted for this, but we need to fix some of our laws.
Where this page not meant to be public, I'd tend to agree with you, but it was meant to be public and was transmitting this data to use as an identifier. The encoding its in is irrelevant, encodings are not encryption and this journalist did nothing illegal.