"White hat" Facebook hacker gets 8 months in jail
bbc.co.uk
bbc.co.uk
Given the chance, I always bang the "don't talk to authorities" drum. So now you have to wonder, how did his "copious admissions" help him? Seriously, if you are suspected of anything, no matter how innocuous or momentous: Shut. The. Hell. Up. Get a damned attorney.
Of course the classic video needs to be linked: http://www.youtube.com/watch?v=6wXkI4t7nuc
http://en.wikipedia.org/wiki/Miranda_warning#England_and_Wal...
F.U.D. made law. Well done England.
Fortunately England still requires a Jury, and Jury's still acquit people despite the police and prosecution spouting outright lies from the moment a person is arrested. If you naively believe that the police do not do so, see if anyone in your circle of friends is a defense lawyer/solicitor who has represented people at police stations and have a candid conversation with them.
If you get arrested in the UK (or anywhere) shut up and say only "I invoke my right to silence. Get me my lawyer."
They are their own breed of scum you have to avoid like the plague as they sleep, eat and drink with the arresting officers and are definitely not impartial. Actually that is pretty much the same for most of the legal profession in the UK. Half of them are friends, the other go to the same masonic lodges - fine example at [1]
The UK is 100% guilty until proven innocent.
As for trial by Jury - seriously speaking they are usually manned by idiots most of the time.
[1] http://www.independent.co.uk/news/uk/this-britain/police-def...
That is, unfortunately, a universal problem anywhere that there are jury trials.
Cops are people too and when they walk up to your window after pulling you over, they may actually be scared. And you know fear leads to anger, anger leads to hate, hate leads to your suffering in traffic court.
So the next cop who pulls you over, wind down your window before he gets there, get your drivers license out so you don't have to fish your pockets, put your hands on the wheel so he can see you're not going to blow his brains out and if it's not more than 20 miles over the limit, try admitting guilt and being nice. You might be surprised.
Both are cops. But they are entirely different people.
Reaching for anything when pulled over is the absolute worst thing you can do to an officer no matter how innocuous you may think you seem.
Please, just keep your hands on the wheel until they're at the window.
That's because, in those countries, it NEVER happens (i.e for someone pulled over to shoot the cop). So you can go get your ID or whatever, and then you have a chat, and they maybe give you a fine for speeding or whatever.
Wow you must be really good at that. In all my life I never managed to talk myself out of a ticket once I was stopped by the police.
This is not your best strategy if:
(a) You are driving on a suspended license
(b) You or anyone in your car have anything in the car to hide
(c) You have a radar detector (just give up)
I bring this up because, for me at least, there's no skill involved in "talking my way out of a ticket". There's no magic words, and it doesn't involve charm, just a little mindfulness.
The 65 in a 55 I pulled over as soon as I saw him slow down to turn around, the rest of the time I just admitted I was probably going too fast. Again, nothing special just mindfulness.
The important thing to keep in mind of course is that with a speeding ticket, at worse you'll have to pay a few bucks for something you maybe even didn't do. This is as opposed to spending a few years in jail for a crime you did not commit...
If you're caught speeding, suck it up and take the ticket.
As stated above though, if you're accused of something serious just keep your mouth shut.
A cop who's investigating a real crime wants to get a conviction. And they aren't in a position to do plea bargaining (like a traffic cop), that's the DA's job (then the judge's, if it gets that far). It's not a terrible idea to negotiate with the DA and judge, but you need a lawyer to help you do it.
It's important to remember that there is not right to silence here, and Judges can make inferences based on a person's silence during police question.
Better advice is to ask for a solicitor, and say calmly that you'll only talk when you have legal representation.
If you're innocent it's important to give a minimal account (with legal representation) of your actions, because not doing so could lead to a false conviction.
Judges can do that here, too. No constitution can stop them from making inferences.
A US judge saying that would leave the case open to appeal.
When you are first arrested, you should plead the fifth (or the British equivalent thereof), and ask to see a lawyer.
"If you give us a reasonable time to respond to your report before making any information public and make a good faith effort to avoid privacy violations, destruction of data and interruption or degradation of our service during your research, we will not bring any lawsuit against you or ask law enforcement to investigate you."
His attempt to access data was outside our whitehat guidelines, had clear malicious intent, and included extensive and destructive efforts to remain undiscovered and anonymous. In addition, he made no effort to contact Facebook with his discoveries, and even denied involvement when initially questioned. His attempt to claim he intended responsible disclosure only after faced with criminal action is false and insulting to the community of responsible security researchers.
...insulting to the community of responsible security researchers
Bravo.At first glance at the article, it seemed that Facebook may have reneged on its offer of protection, but based on your explanation, it now seems that the hacker was indeed malicious, and only used the "white hat defense" as a shield.
I'm a huge advocate of ethical and responsible disclosure, so kudos to you for encouraging it where appropriate.
You think you can sue someone for sharing vulnerability information?
If you're curious, the EFF has published a number of great articles on the topic:
https://www.eff.org/issues/coders/vulnerability-reporting-fa...
https://www.eff.org/deeplinks/2010/12/knowledge-power-facebo...
Not only is it legal to disclose unfixed vulnerabilities, but it is legal to sell them. Presently, the biggest buyer of them is none other than the US government.
People obviously do it, all the time, against sites that haven't officially given permission (as Google and Facebook have), and most of the time they get away with it, but they are rolling the legal dice every time they do. People have been getting in trouble for doing this for years.
The people selling vulnerabilities are generally running the software themselves. Huge difference.
Are you the law?
Should you make your own rules?
Should you have your own court?
Because that's how you are operating.
You made your own law and tempted people to break "common law". Double standards.
How much data did he access?
If you're wondering whether it affected the privacy of data created by people who use Facebook, the referenced article has a statement that it was not, but it appears this was added after the article was published, so you may have missed it.
If you're wondering whether it might be a small amount that a security researcher might collect to verify their report, from what I understand it was more than that.
This is the kind of thing that makes my blood boil.
I suppose you could count the large amount of time facebook probably had to spend going through their systems to make sure they were clean. Surely the money for their security team was already spent though?
Also, isn't messing around with the records of a small business somewhere that probably doesn't even have proper backups actually more potentially damaging than poking at part of a globally distributed, multiply redundant decentralised system like facebook?
It was really the way the judge chose to phrase that whole bit that annoyed me to be honest.
I doubt Facebook's security team is just sitting idly waiting for an attacker to give them something to do. Each hour devoted to this is an hour they can't use for other tasks, besides the possibility of having to pay overtime.
If considered in relation to scale, what per cent of its wealth did Facebook have to spend on this? Not much.
Wondering if lamb fat is good to fry large fish.
Of course the argument could be made that criminal prosecution is largely a function of who you know rather than the spare resources of the judicial system, which is probably correct, but it is still food for though.
(Sources: http://www.california-criminal-lawyer-blog.com/2010/11/grand... and http://www.chinareview.info/issue2/pages/case.htm and some classes I took, but IANAL)
What the US does well is simply keep things public enough that everyone tries to at-least appear to follow the rules. And if you ever tried to do significant business in China as apposed to a Chinese company you will quickly understand that that in and of it's self is huge.
Facebook themselves have a policy of tolerance toward white hat hackery (basically `give us a reasonable amount of time before releasing to the public' and `do what you can to protect other users' privacy). I want to hear their side of this.
http://www.guardian.co.uk/technology/2011/aug/17/facebook-ha...
> Between 17 April and 9 May he is accused of downloading a computer program "to secure unauthorised access" to Facebook; of attempting to hack into Facebook's "Mailman" server; of using PHP script to secure access to another Facebook server, dubbed "Phabricator"; of sharing a PHP script intended to hack into that Facebook server; and of securing "repeated" access to another Facebook server.
>> downloading a computer program "to secure unauthorised access" to Facebook
Any basic security auditing tool falls into this category and this is something I've done all the time. Wish they would more clearly state what made his access unauthorized when my hacking attempts are welcomed.
>> attempting to hack into Facebook's "Mailman" server
I've attempted this too. It's a great target since it's 3rd party code, Facebook runs an out of date version, and some versions have publicly known vulnerabilities.
>> using PHP script to secure access to another Facebook server, dubbed "Phabricator"
I've attempted to do this and just yesterday was considering another attempt. It's a great target since it doesn't go through Facebook's normal release process, it's a large project, and it's open source.
>> sharing a PHP script intended to hack into that Facebook server
I've done this. Sometimes I need another set of experienced eyes to help me get a proof of concept working. Of course it was someone I trusted to keep my discovery confidential.
>> securing "repeated" access to another Facebook server.
I've done this too, both before and after Facebook announced their whitehat program. Before the program they thanked me and sent me swag, after introducing the whitehat program they started awarding me cash on prepaid debit cards.
I can only assume that this guy was prosecuted instead of thanked because he didn't tell Facebook promptly about his discoveries, or perhaps he used them to do something like stealing source code out of Phabricator (Facebook's code review tool). I wish the reporting of this did a better job of covering the details.
http://news.ycombinator.com/item?id=3605343
> His attempt to access data was outside our whitehat guidelines, had clear malicious intent, and included extensive and destructive efforts to remain undiscovered and anonymous. In addition, he made no effort to contact Facebook with his discoveries, and even denied involvement when initially questioned. His attempt to claim he intended responsible disclosure only after faced with criminal action is false and insulting to the community of responsible security researchers.
The FB "whitehat" pages to my reading are in no way giving you a right to "security test" their servers. Their statement appears more like an amnesty, akin to "if you did happen to shoplift from Walmart and you choose to return the goods unspoilt, packaged and in saleable condition, then we won't prosecute you".
They also say, FWIW, that "Security bugs in third-party applications" are not included in the program; so that would rule out attempting to compromise Mailman.
Moreover they say "Security bugs in Facebook's corporate infrastructure" are ruled out from their program which to my mind rules out compromises on Phabricator - it's not a part of the publicly facing Facebook site but instead is a backend tool.
knock knock
If you were in the UK you'd be getting an extradition order for this based on recent history.
I'm curious about this line, towards the bottom:
his intention throughout was to contact Facebook in due course when he had rectified their problemsSo "keeping the data to himself and doing nothing with it" is considered white hat?
I think he should be called gray hat. (Black: Harm. Gray: Does nothing. White: Helps company.)
Scroll up a bit and check arice's post:
Admitting everything in police custody is NOT responsible disclosure
This sounds like someone who was accessing Facebook for profit and made up an excuse when he got caught.
I knew a kid back in the '90s who got hauled off a couple of times by the FBI for hacking. He wasn't looking for profit — he just thought it was fun to break into systems.
Surely, there must be other options except jail?! Maybe some form of community service where he would then be an asset rather than a cost to the general public. If he can infiltrate Facebook, I am sure there are government sites and systems with much more sensitive information that he could be testing and identifying security threats.
Eight months hard time, plus the stigma of a criminal record, just seem like such a waste.
Reminds me of the movie War Games.
How small does a company have to be, where it's ok for someone to "fiddle about" in their business records?
I'm not sure what the "creation of that risk" part is supposed to mean. If it refers to the security weakness the hacker uncovered, well as I said the hacker did not "create" it, he merely "found" it.
If the risk is the potential disclosure, then what is "the cost of putting it right"? Fixing the security weakness? Well since it was not "created" by the hacker, they are just fixing something that they should have, or would have fixed anyway..
Now I'm not saying that the poor hacker should not go to jail. The article doesn't give much details so I'm not sure he should be called a "white hat". However, I'm not convinced by the argument given by the judge..
We all understand the tinkering nature of taking something apart to see how it works.
But if you are that clever and deep into hacking apart facebook, stop and make your own project with that kind of energy.
So what?? Facebook isn't a British business; why should british judical system should care that much? Even if he was that guilty.
Countries should totally quit being unpaid prostitutes to foreign companies.
Mostly this is just to evaluate the product and to see if it is trustworthy, but they'll often send along a polite FYI to the site owners letting them know if they have security issues that need addressing.
Actions like that: finding vulnerabilities, privately disclosing them, not disrupting the service, are all fairly innocuous things that most reasonable technically savvy people would consider 'white hat'.
It sucks, but if your goal is to avoid legal drama, don't test without permission.
From there, I see only 3 possibilities: (i) judge McCreath did not actually trust Mangham's alleged intentions (I'm not sure I do either), or (ii) he doesn't know enough about computer security, or (iii) other actual damages warrants the sentence (like wasted effort at Facebook's and by the law enforcement).
I bet judge McCreath wanted to punish Mangham over (i) and (iii), but it was easier to use (ii) to do so. Or, he doesn't really understand computer security, though that's less likely by the year.
You'd think tech companies would have learned something from all the retribution the cracker community has laid down in the past few years. If you have security holes, own up to them and fix them. Hire real security teams and have external pen-testing on outward-facing products. And if, after all that, you get breeched still... at least learn something from the attack, and possibly from the attacker.
If someone breaks into a company's system, surely the company has a very real obligation to help prosecute the law-breaker? While I can see where there's an argument to made in favour of not prosecuting someone who really is a white-hat hacker (although I'm personally loathe to apply that label to anyone who doesn't have a track record of responsible security research and pen testing as opposed to J. Random Hacker who happens to tell the company after the fact), this guy pretty clearly doesn't fall into that category.
While the article was light on the details (being as it was that it was about the sentencing rather than the crime), it does seem as though he both copied some of Facebook's source code or other internal data (as it mentions it being copied to an external hard drive), and it does not seem as though he reported the hole to Facebook along with any details of how he penetrated their system.
Given that, why should Facebook not help to prosecute him?
then disclosed the vulnerabilities with his real identity which means he assumed-expected to somehow benefit, probably not financial - just craved recognition / 'pat on the back' / coolness / job offer
acted like a muppet
You have to identify the actions taken by the attacker and correlate events between systems to understand the extent of stolen, destroyed, or modified information, and to ensure that no additional backdoors are left behind.
If there is an indication of malicious intent, you also have to interact with law enforcement, discover the identity of the attacker, provide enough information to get a warrant, and so forth.
In the whitehat report case, it is as simple as fixing the security hole (and identifying how it got there and how to prevent similar cases) and thanking and rewarding the reporter. However, that wasn't the case here - there was no disclosure, no reason to believe that the attacker was benign, and so an investigation needed to be done.
(I work at Facebook, but not in one of the teams involved in this investigation.)
This hacker should be awarded for finding flaws in facebook that could be misused by people who really wanted to do harm. If this hacker didnt find these flaws facebook would haver never known that they have a security flaw.
Even better: Facebook should hire this guy! He managed to break into a system that is developer by the "top notch" facebook engineers.
Get him out of prison!
His hat is not impeccable white.
Unauthorized computer access is jail-time illegal. Do not access any computer or computer network without owner's permission. Seek legal counsel if you're not 100% clear about this, and do it before you get your ass in trouble.