City of Columbus sues expert who exposed extent of cyberattack
10tv.com
10tv.com
The city seems upset that he shared data about ongoing investigations and undercover police reports. Depending on what exactly he shared, it’s hard to fault the city for that. It doesn’t really matter where the data currently exists; grabbing it and handing it off to others is obviously not a good idea.
If his goal was to prove to the reporters that such data existed and was available for download, he had many options that didn’t require accessing the data: screenshot the forum posts, send links to the reporters, detail what kind of data was there without actually showing any of it, and so on.
Now, if that’s what he did, and the city is still reacting this way, that’s obviously abuse. But it doesn’t seem unreasonable to order someone to stop disseminating data about ongoing investigations to reporters. Would you want your private cases to be more widely spread?
I’m really sympathetic to him, because this is an easy mistake to make. Before I got into the industry, I thought that this was white hat hacking; it’s obviously good that he’s spreading awareness about the breach. But how you do it really matters.
(Caveat: I worked in the industry for about a year in 2016, so maybe things have changed. But I’d be shocked if distributing actual data from any breach was condoned by anyone who works as a pentester, even today.)
> the city says Goodwolf is threatening to publicly share the city's stolen data in the form of a website that he will create himself. Goodwolf previously told 10TV he does plan to set up a website, but it would only allow people to see if their name was part of the data breach.
This isn’t the same as setting up a site to see if your password was compromised. It could let anyone type in someone’s name and see whether they’re a witness in a criminal investigation.
I agree that creating a website where you can look up a name and see if they've been part of a police investigation is a bad idea, but he didn't actually do that, he only had plans to.
Note that showing the data to the reporter counts as distribution. He didn’t need to do that to prove to the reporter that the data was out there. Even sending screenshots of the data would’ve been ok if he’d redacted anything remotely confidential (it would be obvious from context that the document is probably legit, and the reporter would dig in further).
If he didn’t send any sensitive data to anyone, then I completely agree with you. But pentesters generally don’t send actual data to prove a breach exists to anyone but the target of the breach. Publicizing the breach itself is fine, but the article is pretty clear that’s not why they’re going after him.
Reporters and their editors are meant to be the experts on the ethics and legalities of what should be redacted and what level of detail is in the public interest to report.
You should be able to fork over everything to a reporter securely and let them defer to their ethics, consult with their lawyers, liaise with law enforcement, etc. to determine what level of disclosure is appropriate.
He still should. The dispatch article has more information, this was data that has already been leaked, there is no means of protecting it anymore. The only thing to do is release it so people know if they've been exposed.
https://www.dispatch.com/story/opinion/columns/2024/08/30/co...
Like it sucks that this is the best option but you can't make it go away, the data is free.
Are we talking about a Troy Hunt-style (haveibeenpwned) website? If so, I don't consider a giant hashset-of-hashes a "release" because if that data (haveibeenpwnd's database) gets leaked it's of zero use to anyone because it doesn't contain any original data anymore.
But if you mean Wikileaks-style: put it all in a .rar file and publicise it, maintaining that the-ends-justify-the-means approach despite all the irresponsible-journalism, then absolutely no. Yikes. No.
You can sue for prior restraint if someone is threatening you.
Unless that article is seriously mischaracterising what happened, I can’t see how this is anything other than a massive civil liberties infringement by the city, who are just trying to scapegoat this Goodwolf person. All of the damages they are describing were caused by their own negligence.
I’m really far on the side of hackers here, but I’m having trouble justifying sending any data whatsoever to journalists related to criminal investigations. Even one witness’s name, sent merely to prove that the breach happened, could be enough to cause direct harm to that case if the reporter decided to reveal it. You don’t need to do that to show a reporter that the breach happened. And it’s up to the reporter themselves to prove the breach is real.
As is described in the article, this is one of the best cases of responsible disclosure I can think of in recent memory - refuting a government lie that put at-risk people's lives in danger.
I’ve been following this since early August because I grew up in Columbus and still have family there.
Ginther is a terrible mayor and has handled this mess about as poorly as you can. The researcher they’re trying to quiet exposed that Ginther was lying about the data being unusable.
> "This is not about speech. It's not. It's about the actual action of > going on the keyboard, going into the dark web, gathering the information, > downloading it to your computer and then disseminating it to people > who are in the press or otherwise," Klein said.
... sounds a lot like free expression (especially when the city is lying)
Here’s an example from my own life: I created books3, an AI training dataset of almost 200k books. This was thanks to The Eye, who hosted a copy of Bibliotik, a popular shadow library. But everyone is suing the AI companies themselves for using the training data, even though the original harm was caused by The Eye and Bibliotik.
> not this one person who said "the city failed to secure the data - anyone can get it".
If he simply said that, there wouldn’t have been a problem. He sent actual data related to ongoing criminal investigations, and was on the record saying he might set up a website to more widely disseminate information about that data — which could include names of witnesses in those investigations.
Is showing some reporters some sample data to show that the data exists malicious? Because I believe that's all he's been accused of doing.
> was on the record saying he might set up a website to more widely disseminate information about that data
As to whether the website he would make one day would contain the information on investigations: this is disputed. To me, it seems the city misconstrues his quotes about letting people determine if names were contained in the entire dataset.
Snowden was, according to all available evidence, not trying to expose abuses. He was trying to commit espionage against the US, and it's extremely clear to anyone who has passing experience with the leaks and a shred of intellectual honesty, because the vast majority of the files were completely unrelated to domestic surveillance programs, and instead concerned foreign surveillance programs.
Stop bringing up Snowden; all of the evidence indicates that he was lying about his motive.
> I don't think it is as surprising that he took more files than he should have.
It's extremely surprising if he claims to have been acting in the public's interest by uncovering domestic spying programs and then over 90 percent of the files he took were completely unrelated to that stated goal. That's a very strong indicator of dishonesty.
"Narcisstic tendencies" is a very common smear / throwaway labelling we hear a lot -- about bosses, exes, manipulative relatives and what not. In some cases it's valid, but in most it's simply not. Unless you can point to specifics, we'll have to include this labelling of Snowden in that category as well.
But even if it did apply -- it would also be perfectly consistent with the possibly that he simply considers himself a fearless do-gooder. I don't rule out your alternatives, but Occam's Razor (combined with the fact that there's no visible evidence of him having profited in any way; and his general bearing and demeanor do not correspond to those of the publicity whore type) does favor the former.
(Not to say that he is or is not a fearless do-gooder; just that it's not at all unlikely that that's what he considers himself to be).
Just the pugnacious way you choose to phrase this ("It's sooo obvious, and if you don't simply full-on agree you must be clueless and/or a lying scumbag yourself") makes me doubt this version of events. That, plus the fact that (even after all this time) no one has come forward with any actual dispositive evidence for such a narrative.
It's all just speculation.
> because the vast majority of the files were completely unrelated to domestic surveillance programs, and instead concerned foreign surveillance programs.
It is exactly because the common response to the evidence is this kind of deceptiveness that I have to point it out.
> That, plus the fact that (even after all this time) no one has come forward with any actual dispositive evidence for such a narrative.
> It's all just speculation.
I described the evidence, provided by Snowden himself and publicly available for anyone to check, which directly disproves your claim that "it's all just speculative". The actual evidence significantly favors the theory that it was espionage over the theory that it was whistleblowing.
Before I offer anything else -- you are welcome to provide quotes and sources for the respective items of evidence described above.
second result on ddg for "Snowden files", wasn't hard to find...
And either way -- this whole discussion is plainly moot.
For starters, the initial argument made in [0] was just not coherent to begin with. There's no way to interpret "commit espionage against the US" other than to mean in the service of some adversary (as others have indeed accused Snowden of doing, with similar vehemence and invariably lacking hard evidence). The commenter withdrew that assertion, which is okay I guess, but that made for an awfully sloppy start.
And even so, the basic logic of what was left in their post (that it was "extremely clear" that Snowden was on some kind of nihilistic rampage against the government, rather than out to expose abuses) just doesn't hold up. Okay, so the guy was sloppy and scattershot in his choice of what to leak. But that by itself doesn't establish destructive nihilism or even vindictiveness toward his former employer as the primary motive.
When this was pointed out in [1], the commenter's followup led off with, not a substantive retort -- but a straight-up character smear. Another huge red flag.
To the extent that they did attempt to address the critique -- still, their logic just didn't add up. Even if 90 percent of the files were related to foreign rather than domestic programs -- that doesn't mean Snowden was simply out to cause as much damage as he possibly could. The simplest and far more plausible explanation is that he thought he could stop (or at least warn people about) abuses in foreign countries as well.
So with that, and the plainly obnoxious, browbeating tone they adopted from the get-go (at the readers of HN, not even at me specifically) I came to a point where I had had enough. As a last resort I was hoping someone could point to something resembling a coherent analysis from some trusted external source (as obviously no one has time sit down and dig through those PDFs, and no one not deeply immersed in this field can honestly say that they can quickly come to conclusions about anything after just a quick sampling). But their response to that was hand-wavy and combative, as well.
So that's it for me. I'm not vested in this topic, and have no particular sympathies for or against Snowden. But I don't pretend to know what his "true" motives were, either.
All I know is that I definitely don't trust what the commenter of [0] has to say about anything in regard to this topic. Not because they're right or wrong. But just from how they choose to communicate, and especially their attitude toward those who don't immediately buy into their (at best, sketchy) interpretations of the narrative record.
This is not relevant. You have the ability to read through the data, sample it, and see how many documents are related to domestic vs foreign surveillance - you just are refusing to do so.
The claim that you need a "trusted source" to evaluate data that you can literally look at yourself is also an appeal to authority.
You're also moving the goalposts (even worse - goalposts that you never set up in the first place) from "there's no evidence" to "there's no analysis of the evidence". You also moved the goalposts that you set up from "you are welcome to provide quotes and sources for the respective items of evidence described above" to "you provided sources, but you didn't provide an analysis of the sources".
> There's no way to interpret "commit espionage against the US" other than to mean in the service of some adversary
This is flatly untrue. "Espionage", according to many dictionary definitions, as well as the way that the US government defines it, does not have to involve working for a particular adversary, but can merely mean the illegal/illicit collection of controlled information. "the act of obtaining secret or confidential information" https://en.wikipedia.org/wiki/Espionage
> Okay, so the guy was sloppy and scattershot in his choice of what to leak. But that by itself doesn't establish destructive nihilism or even vindictiveness toward his former employer as the primary motive.
This is a strawman argument. I never claimed that it established that conclusively - only that it's evidence that does point to destructiveness/vindictiveness, and there's virtually no evidence against that - which is true.
> The simplest and far more plausible explanation is that he thought he could stop (or at least warn people about) abuses in foreign countries as well.
...so he wanted to commit espionage against the US, and was not trying to "expose abuses" in the US, like the original commentator implied.
> As a last resort I was hoping someone could point to something resembling a coherent analysis from some trusted external source
More deflection and appeal to authority. "Trusted external sources" are irrelevant when you can examine the data yourself, and when it's as easy to evaluate as it is here.
> obviously no one has time sit down and dig through those PDFs
Which is an extreme exaggeration to the point of being a lie. The vast majority of people in the US (let alone HN users) have more than the requisite hour or so to spend digging through a small sample of the data.
In particular, given the significant amount of time that you've spent trying to explain why you shouldn't have to look at the data, you in particular certainly have the time for it. Your refusal is out of unwillingness to change your mind, not inability to do so.
> I don't pretend to know what his "true" motives were, either.
This is a strawman fallacy. I never claimed that I did - I just claimed that the available evidence indicated that he was lying.
> All I know is that I definitely don't trust what the commenter of [0] has to say about anything in regard to this topic.
...and then you say things like this. There's no "trust" involved here - the data is available, and you are refusing to look at it. You are throwing "trust" in as a red herring because you want to deflect from the fact that you are unwilling to observe the world with your eyes.
Given your repeated refusals to actually examine the evidence, goalpost moving, strawman fallacies, appeals to authority, incorrect definition of an important English word, and disingenuous claims that "nobody has time to look at the evidence", it's clear that you are not arguing in good faith - you are yet another person who cannot defend Snowden based on facts, but instead resorts to what they want to believe.
If you don't want to provide a constructive response to what was asked, that's your prerogative of course.
It's also a blatant lie to claim that "no one has time" to spend 10 seconds on a Google search to find the files and 5-10 minutes to sample them and see how many are related to domestic collection.
Your response clearly indicates that you have neither read the files nor have the intellectual honesty to admit that you haven't read them and don't want to because it'll refute your existing beliefs.
Future HN readers: notice how this user is unwilling to read documents that are the first page on a Google search for "Snowden files", and uses any excuse necessary to avoid doing so and deflect when called out. This is an excellent confirmation of my claim that the majority of the documents are unrelated to domestic collection.
I don't know how to do that responsibly (just share it with a reputable reporter?), but I definitely get the feeling if you're constantly subjected to bad faith.
If someone’s butt is going to be on the line, it should be a corporation’s (the news agency), or perhaps an individual investigative journalist. Not you. Not for something like this, anyway. If it was just social security numbers I might agree with you, but police databases are obviously dangerous to disseminate, even if it’s just to prove they exist. He could’ve sent redacted screenshots.
Point being, we don’t know what he sent, but sending anything at all from a police database is a bad idea. No lawyer would ever say that that’s legal, let alone ethical.
you are in danger but you dont need to know that, its not your job to protect yourself, thats our job.
By the time Goodwolf got to the data, it had already been compromised and published. The only way he could have possibly contributed to the harm was by drawing attention to it. If you take that perspective, then the city has further contributed to that harm themselves by taking legal action against Goodwolf. Furthermore, you could also conclude from this argument that the city had some moral responsibility to lie to the public about the nature of the breach, and that all those who knew the truth would also have the moral responsibility to protect that lie.
I would say this is an incredibly perverse position to take. All of the data compromised in this breach was already published, and in the hands of criminals. For anybody whose data was included in this breach, the city lying about it was just putting them in further jeopardy. Now they will at least have the opportunity to learn about the breach. The journalists are hardly likely to abuse it. The only legitimate harm caused by Goodwolf was to harm the integrity of the lying city officials. They deserve that harm, and the other side of that coin is that the public benefits when corruption is exposed.
Hell, I am in infosec and it would probably take me a few hours or more to find raw data. A grandma can click a website on CBS and type a name.
Ref:
https://surfshark.com/blog/how-to-use-tor
https://www.expressvpn.com/vpn-service/tor-vpn
https://protonvpn.com/support/tor-vpn/
https://nordvpn.com/blog/what-is-tor/
https://www.privateinternetaccess.com/blog/how-to-use-privat...
Hard to claim it's secret information IMO.
How would that even work? You linked to something that Google didn't index, so you're liable for spreading private info, but another person who posted the same data, but whose reference site was indexed by Google, isn't liable?
I’m in infosec as well.
Kids (12+) know how to use Tor because we’ve made the “dark web” a cool place at this point.
And the Rhysida ransomware onion can be found with a simple Google search. The knowledge that’s it was Rhysida is public information .
STEPS TO REPRODUCE:
1. Download and install Tor
2. Search for Rhysida on Google
3. City of Columbus data is on the front page
The article doesn’t mention this…
It's not hard at all. The people like the decisionmakers here inflict violence upon people's willingness to help them with very bad cybersecurity issues. Which are everywhere. If we lived in a healthy society, whoever decided to prosecute this would be sacrificed to a volcano (metaphorically).
But redistributing a police database (even just to reporters) is obviously going to cause the city to file a restraining order to stop further distribution. Especially when he said he plans to make a site that would share details related to that database.
If nothing else, it was probably a bad idea to do what he did. I was only trying to caution overeager outsiders against doing similar things.
What do you make of all this? The lawsuit itself seems dubious, even if the restraining order made sense.
I think something people are getting hung up on here is that just because something is technically public, doesn't mean you can assist in distributing it.
Example: Controlled drugs are public in that you can easily go to a certain area in downtown and obtain them. However, if you do so, and then you start distributing it yourself, you will be charged with a crime. Nobody has issues understanding this but they seem to have issues understanding when it's data instead of physical goods for some reason.
I'm not quite certain what law he's accused of violating. He didn't download the info from the gov website so there couldn't be allegations of unauthorized access. He didn't hack the website either.
What gives?
The city lied about the breach, so getting a restraining order immediately looks petty and abusive.
But you make a good point that such a website would not actually be useful. Anyone who is in those documents knows it, and allowing the public web the ability to look people up by name is dangerous.
The "hacker" is correct to speak loudly about the lies the city told. He would be incorrect to create a lookup.
Not if the lookup simply acknowledged whether a name exists in the records, without giving other context (e.g. property tax, DMV, criminal investigation, etc.).
Like how was he planning to enforce that? Trust and honesty?
Or maybe you upload your ID to him first?
I think that he's playing all weaselly now that there's some pressure.
He’s about as far from an ethical hacker as you can be. He’s on a crusade.
Now that doesn’t mean this should be illegal but I’m not on his side.
I read this and immediately suspected that he is a furry
You should be able to be the worst person in the world and not hung for it. There's no reason to not be on his side, it doesn't mean you endorse him. The other side is an embarrassed government throwing their weight around to hang him for what isn't and shouldn't be a crime.
For an extreme example, murder requires intent. Most computer crimes also fall into this.
In this case he crossed the line a professional security researcher would not have by showing the data to a third party.
Ignoring the underlying point being made won't make it go away, and won’t help educate any of our peers who might take some of this stuff at face value.
Do you just believe that someone should be allowed to do anything they want and not face repercussions?
The city may be in the wrong for downplaying the severity, but he’s in the wrong for directly handing over the hacked information he has to journalists.
I think they city would need to actually believe witnesses or investigations were actually harmed, and I don't mean picking whatever belief is most convenient for them. Maybe they do believe it. If they can prove it, they should win their suit.
You probably think identity theft is a customer's problem, not the bank too.
Just because the narrative calls it something, doesn't make it right.
It's silly for a nation-state to sue cash, it should never have been considered reasonable.
Huh? I'm relaying what the law considers civil asset forfeiture to be. It's not my opinion and it is not a "narrative". In fact, here's some commentary addressing the issue I raised.
"Technically, civil asset forfeiture involves a government lawsuit against the personal property itself or, in legal terms, `in rem`. As strange as it may seem, the inanimate property, whether a yacht or a bag of cash, is the defendant in such a proceeding." --- (https://www.findlaw.com/criminal/criminal-rights/what-is-civ...)
If you don't believe that, maybe you'd believe the Justice Department on issue:
"Civil Judicial Forfeiture: In rem (against the property) court proceeding brought against property that was derived from or used to commit an offense, rather than against a person who committed an offense." --- (https://www.justice.gov/afp/types-federal-forfeiture)
What you ignored is the only opinion I expressed and the context of that expression: "Still, I would argue that the property owner's rights are often violated is such actions." How does this square with anything about identify theft responsibility?
> It's silly for a nation-state to sue cash, it should never have been considered reasonable.
Actually, the historical origin of civil asset forfeiture has some rational basis, though, as with most sensible legal moves, gets corrupted by those willing to exploit the letter of the law in spite of its spirit.
Nonetheless, unless there's something I'm missing I don't find your retort particularly coherent. I urge you to reread the original comment to which I replied and my reply and try again.
The facts of it are that he did not do the hacking and did not make the information information online. He's just mirroring the easily available information because the city was lying about it. That's journalism. If the city wants to sue someone they should look internally and at the initial hackers/posters of the information in public.
My personal experience is from my own conversations with him and conversations with people in Cincinnati, Dayton, and Columbus.
No, this is about how you lied to your public about the nature and format of the data that you failed to protect
There is always going to be some kind of crusade in the name of something that tugs at everyone's heartstrings, but it's only to chip away at the freedoms of those that don't partake in the terrible acts (which there's no doubt terrible acts do occur, but not enough to have us all give up our freedom to make it easier to stop). I hope it's clear that I agree with you, and it is scary how easily swayed the public is (and that's coming from a father that definitely wants protections for our children, but also understand that a lot of that needs to start at home with communication more than limiting technology).
> On Aug. 13, Mayor Andrew Ginther said the data stolen by hackers was either corrupted or encrypted, meaning it was likely useless. Hours later, Goodwolf told 10TV that wasn't true and he showed what kind of personal information he was able to access.
lol - the entire city leadership needs to be recalled. They get caught with their pants down (no security), lie to the public (“it’s encrypted bro!1! trust me I’m a politician!!), lies get rightfully called out, and their response is to pour gas on the fire with this silly lawsuit funded by the local tax payers.
Suing security researchers for investigating the contents of disclosed information is ineffective at protecting anyone.
However some other asshole shows up to the scene claiming jurisdiction (county sheriff?), raises hell, makes a random call (county officials?), then arrest the pen testers on the spot for B&E.
State leave them out to dry in some county jail cell. I think the state ultimately ended up getting embarrassed and tried to sue the company and pen testers for some civil damages and pursue criminal charges.
In the end, they end up getting dropped and reputation of pen testers were ruined for a period of time.
https://arstechnica.com/information-technology/2019/11/how-a...
Follow up a few months later:
https://arstechnica.com/information-technology/2020/01/crimi...
https://arstechnica.com/security/2024/08/city-of-columbus-su...
Public website hosting hacked records: not sued
Lying public servant: not sued
Joe Schmoe for pointing out all three: sued
(blocked in EU)
Lol, unless the article is reporting something off, features like Chrome or Firefox reporting one of your passwords may have been compromised would be illegal.
The reality is that this city is wrong.
It’s beyond stupid and lazy
Then just be like, yeah, there's like 3 TB of data there, maybe it's class-action worthy, hint, hint.
Might there be any lawyers with opinions (& disclaimers, obviously) in the house?
should people be informed, thus enabled to respond, or should people be etoliated, and kept ignorant of even requiring a response.
etoliated: Def 2. literary. weakened; no longer at full strength. "Her voice was thinner than I recalled..."
the internet is not google, no amount of sand over the head or in the eyes will change that.
Columbus officials chose to invalidate threat to public safety by way of misinformation, then retaliate when the threat and true situation was revealed.
keeping people ignorant of threatscape is not good government.
thinking the 'darkweb' is some sort of containment by obscurity, is beyond naive.
the city of columbus is actually inhibiting a proper response and perpetuating a cavalier security stance.
this is not going unnoticed.
[1] [This is a bigger issue here': Columbus resident wishes the city told residents about the data breach sooner]
https://www.10tv.com/article/news/local/columbus-woman-wishe...
[2] Second class-action lawsuit, representing police and firefighters, filed against city after cyberattack
https://www.10tv.com/article/news/local/second-class-action-...
[3] Ginther confirms personal information of Columbus residents exposed in cyberattack
https://www.10tv.com/article/news/local/ginther-press-confer...
"this is not going unnoticed." Oh thank god!
"the city of Columbus is actually inhibiting a proper response and perpetuating a cavalier security stance."
"On Aug. 13, Mayor Andrew Ginther said the data stolen by hackers was either corrupted or encrypted, meaning it was likely useless. Hours later, Goodwolf told 10TV that wasn't true and he showed what kind of personal information he was able to access"
"City officials announced they are providing free credit monitoring to Columbus and Franklin County Municipal Court Clerk employees and judges and have asked city employees to use different passwords for their accounts."
Elvis and common sense has left the building.
https://schneiderdowns.com/our-thoughts-on/city-of-columbus-...
I'm not sure how much data was exposed, but I've recently gotten a warning from Ticketmaster that my SSN (US social security number) was exposed. I absolutely did not provide that information, so it's either an outright lie, or there's a lot more sharing going on behind the scenes than the standard public is to believe.
I saw an article recently claiming that something like 80% of people under 30 access the dark web at least once a week. 80% of under-30s use Tor? Seems highly unlikely.
I suppose ones that require authentication (like internal employer sites) could also be dark web.