CA bar says attorney records leaked through database flaw, not hack
reuters.com
reuters.com
https://www.calbar.ca.gov/About-Us/News/Data-Breach-Updates
Notably:
- they now acknowledge that it wasn't unlawful for judyrecords to access (and republish) the records that were unlawfully published
- they talk about judyrecords using a 'unique method' to access the records; I'm guessing the method is something simple like 'incrementing an integer', and that they are trying to make it seem more mystical.
Insecure = no access control/authorization
Direct Object reference = URL
https://cheatsheetseries.owasp.org/cheatsheets/Insecure_Dire...
"Direct Object Reference is fundamentally a Access Control problem."
Maybe they used graphql and their api expectantly allowed access to data that it shouldn't of had access too?
[0] - https://www.techdirt.com/2013/09/30/dojs-insane-argument-aga...
I am unaware of any case going to trial using that interpretation of the CFAA since, though.
Which interpretation would that be? That unauthorized access is illegal?
It means that the stakeholders of the system, normally its owners, do not mean for you to have access. Here's one way you can estimate whether the owners intend that you should have access:
Imagine an in-person conversation with the owner or controller of the data, or their most knowledgeable representative. If you asked them verbally whether you may access the data, and they said "no," then you "shouldn't" have access to the data.
> If you are granted access to a valid request then what other interpretation can there be . . .
See above. This is also the interpretation that will be relevant in court if you are sued or arrested, so mark it carefully.
Hackers love to think that they’re captain Kirk outsmarting the computer, but real life isn’t Star Trek and judges are very much humans and don’t look kindly on such stunts.
A reasonable person would know that you aren’t authorized to dump AT&Ts customer database by incrementing an integer on their site.
Or I guess I can just start up a website at "youre-unauthorized.com", so a every reasonable person is duly noticed that they aren't authorized to see it, put my secrets there, set the web server to allow access to all requests everywhere, and then file a criminal complaint on everyone who accesses my secrets that I put out in public.
A reasonable person knows intuitively that only crime committed was that of embarrassing the rich and/or well connected.
That's obviously true under some formulations, but it doesn't matter, because they won't be on trial. The person who performed the unauthorized access will be.
> A reasonable person knows intuitively that only crime committed was that of embarrassing the rich and/or well connected.
I consider myself a reasonable person and I'm perfectly happy to have unauthorized access punishable under the law. I value the fact that society takes an onion-like approach to information security. There are incentives for private organizations to secure data, but when they fail to, the risk of criminal sanctions probably prevent some breaches that would otherwise occur. I also do not value the ability to look at computer systems on an unauthorized basis -- i.e. I do not think it brings any value to society -- so by my lights, I lose nothing by it being illegal.
Not only that, but despite what views borderline-ASD hackers might hold, courts do make decisions about vague things like “intent” on a daily basis.
A reasonable person might fail to properly lock their door. Try that defense in front of a judge, odds are you’ll end up in prison.
> Not only was the organization so derelict in their affairs that they failed to protect sensitive customer data, they didn't even notice the "crime" had taken place
None of this would reduce the intruders liability. Perhaps the company should be tried separately for their failure to protect customer data, but that’s a different issue.
Was it alleged that judyrecords had mens rea?
https://www.law.cornell.edu/wex/mens_rea
The [Model Penal Code (MPC)] and Mens Rea
Most states use the MPC's classification for various mentes reae. The MPC organizes and defines culpable states of mind into four hierarchical categories:
1. acting purposely - the defendant had an underlying conscious object to act
2. acting knowingly - the defendant is practically certain that the conduct will cause a particular result
3. acting recklessly - The defendant consciously disregarded a substantial and unjustified risk
4. acting negligently - The defendant was not aware of the risk, but should have been aware of the risk
Thus, a crime committed purposefully would carry a more severe punishment than if the offender acted knowingly, recklessly, or negligently. The MPC greatly impacted the criminal codes of a number of states and continues to be influential in furthering discourse on mens rea.Some have expanded the MPC classification to include a fifth state of mind: "strict liability." Strict liability crimes do not require a guilty state of mind.
Not as far as I know. That's my point. They did not intend to illegally publish records, which makes it very different from weev's case.
When the access is freely given out without any subterfuge, it's not my job to self-enforce my best guess at what my access level should have been.
In this case, it would be like going through the UI and trying to access the record and getting denied because of a client side access block, so you make a direct call to the backend instead to retrieve the record. You’re making a perfectly legitimate HTTP request but for something you know you shouldn’t be able to access: illegal.
Personally, I would not bet my freedom on that assumption.
CFAA covers unauthorized access to protected computers, not piles of records on park benches.
And "protected computer" is basically all computers. Imagine if the records were on a kindle; that shouldn't change the legality and if the CFAA does so that's a bad thing.
Is it really though? What harm may come from legislation preventing you from rifling through somebody’s phone that they left on a park bench?
I’m not saying CFAA isn’t problematic, but I’m very unconvinced that this is the problematic part.
A public web server doesn't have such direct privacy issues.
When it comes to records on a bench vs. a non-personal kindle on a bench, I think they should have equal and low protection. Abusing the data should face penalties, but not poking around.
I don’t see any obvious reason as to why this should be allowed, but it’s trivial to come up with a whole plethora of reasons for why you shouldn’t be allowed to poke around such devices.
It’s not. How (and if) the door is locked makes no difference whatsoever.
Intent matters, weev knew his access wasn’t authorized. Judyrecords didn’t know they were accessing non-public data by incrementing the integer, weev did.
https://www.law.com/therecorder/2022/03/10/bowing-to-pressur...
https://firstamendmentcoalition.org/2022/02/fac-letter-to-ca...
https://s3.documentcloud.org/documents/21409065/response-to-...
"Show HN: Full text search on 630M US court cases" | 20 days ago | 269 comments https://news.ycombinator.com/item?id=30399881
"Full text search on 400M US court cases" | Nov 19, 2020 | 163 comments https://news.ycombinator.com/item?id=25150702
And the way the word gets used, it covers any usage of a service not explicitly allowed in the Terms of Service.
But in this case, it seems they reviewed their terms and realized they hadn't protected themselves FROM A LEGAL STANDPOINT
No matter what ivory tower we're talking about, there's never a reason to be in awe of the top.
I think it's because they're lawyers.
I have decidedly mixed feelings about the legal profession, but most lawyers (especially the "establishment" types most likely to be involved in the CA bar) are *very* unlikely to make deliberately false statements (or to fail to correct a past statement, one they learn it was false).
In defiance of thousands of lawyer jokes, in my experience lawyers lie the *least* of any large group of humans I've encountered – at least if "lying" refers only to the specific denotation of the words, since lawyers also love to split hairs to say something that's technically true. But the distinction between a "hack" and a "database error" is _exactly_ the sort of hair that lawyers love to split!
Source: I'm a lawyer-turned-programmer
Sarcasm alert: so the gist is engineering is hard and we should never assume actors within a system will act predictably: you don’t say!
Security is hard, but necessary, it’s never convenient. It takes relentless discipline and suspicion, which is dissonant in conventional software team dynamics.
I hear it time and time again, “this isn’t an issue”
Every time a story comes out like this, I think about how ill-equipped these organizations must be in mitigating these breaches.
I’d definitely believe other cases have happened in the last 8 years that have done a better job of clarifying the law, but I’m not aware of them.
1. https://www.techdirt.com/2013/09/30/dojs-insane-argument-aga... 2. https://www.eff.org/press/releases/appeals-court-overturns-a...
This is the most common security issue right now according to OWASP. You have to understand these issues come the fact that likely lawyers oversaw this project and they picked contractors that were "best value" (low cost).