French journalist "hacks" govt by inputting correct URL, later fined $4,000+
arstechnica.com
arstechnica.com
[1] http://www.maitre-eolas.fr/post/2014/02/07/NON%2C-on-ne-peut...
One can then discuss whether this law is fair or not, whether things would have been different had Bluetouff not made this key admission, whether it is reasonable to consider that the login page was sufficient to indicate that the documents weren't intended to be public, and whether the 3000 EUR fine is balanced or not.
Meanwhile, Bluetouff has appealed the ruling to the Cour de cassation, France's last-resort court for civil and criminal cases, whose role is to break rulings where the law was not correctly applied (without discussing the findings, only the application of the law and the adequate forms). I do not think we know yet how Bluetouff will phrase his appeal, but Eolas estimates that there would be a possible way to attack the ruling based on the court's finding that Bluetouff's retrieving the documents constitutes "vol" (theft) though it does not fall within the scope of the formal definition of theft (because the ANSES was not deprived of the files).
Do we know how he accessed the documents? Did he crawl the directory with a login or without a login (meaning the directory is not protected)?
And why would he share such document with his fellow writer? What for?
The fact that a judge can't comprehend technical explanation according to the article seems to be the main issue here. Was he given a fair hearing?
Which countries will use that against you?
IE: You are required by law to answer questions/turn over passwords when suspected of such things. David Miranda being a recent and well known example.
You got a cite for that?
According to former White House Counsel Alberto Gonzales (later the former attorney general), “[t]he stream of intelligence would quickly dry up if the enemy combatants were allowed contact with outsiders during the course of an ongoing debriefing.” Warren Richey, “Beyond Padilla Terror Case, Huge Legal Issues,” Christian Science Monitor, August 15, 2007, http://www.csmonitor.com/2007/0815/p01s08-usju.html. Yoo also explains that introducing a lawyer immediately after capture of an enemy combatant would disrupt interrogation as any competent defense counsel would tell his/her client to remain silent. Yoo, War by Other Means, 151.
But this also happens to immigrants or those stopped at the border in general. [0] The right to counsel is being eroded at the edges (apparently not applied to non-citizens whenever possible).
Over the past year, the American Immigration Council, along with the American Immigration Lawyers Association (AILA), has documented instances where the DHS immigration agencies—Customs and Border Protection (CBP), Immigration and Customs Enforcement (ICE), and U.S. Citizenship and Immigration Services (USCIS)—have deprived noncitizens of access to counsel. For example, ICE also has taken the position that there is no right to consult with a lawyer during an interrogation. Likewise, many CBP offices outright deny access to all lawyers. [1]
[0] http://law.psu.edu/_file/Immigrants/LAC_Right_to_Counsel.pdf
[1] http://immigrationimpact.com/2012/01/23/its-time-to-improve-...
Although I'm not sure the correct word here is "hacking". Law and government should stop using the word to mean "any adept use of computer knowledge or skills that result in undesirable effects for some party". That could be used to accuse anyone with a computer and an opinion. There needs to be a proper legal definition (similar to how we distinguish between degrees of murder, manslaughter and involuntary homicide).
Compare "They just used the Windows Remote Access feature/You just changed the document_id part of the URL" to "You just dropped that coin in your pocket".
The line between "hacking" and "expected behaviour" can get very blurry, the more knowledgeable a person is. And in the end, like with magic tricks vs con men, it's the intent that makes it right or wrong (IMO).
We have pretty much the same law in the Netherlands. What I understand (IANAL), this goes as far as observing an open WiFi access point with the SSID named "UNAUTHORIZED ACCESS PROHIBITED", if you willingly connect to it (ignoring the message), you'll be in violation.
This is of course not security, and maybe it's kinda stupid, but the rule is also pretty clear and pragmatic. It's analogous to having a door with a "NO ACCESS" sign on it, even if it turns out to be unlocked, you're still not supposed to go there. Often such a sign will cite "Article such and such from the Book of Criminal Law Code" in smaller letters (Dutch people will know what type of signs I'm talking about), but afaik this is not necessary for the legal power of such a sign.
The ruling said he was innocent of the first charge, since it was due to a security flaw, but guilty of the second, since he realized he was in a private system (he admitted to navigating the hierarchy and finding that the repository was "protected" by a login and password). He was also ruled guilty of the theft (the author of the blogpost, an attorney, says he should have been charged with counterfeiting instead, since that is the proper indictment for copyright violations).
It's the digital equivalent of figuring out that a house isn't locked, and concluding it's OK to loot it.
I think it's the equivalent of going down a public road and passing through a gate that was left open, onto private property.
While driving, off in the woods beside the road you notice a "no trespassing" sign, but it's not obvious that you're trespassing currently, even if you start to wonder.
A place on the disk was accessed that was unintended.
He's admitted that he kept snooping around after he fully realized that the files were online by mistake.
Besides, counterfeiting one's furniture doesn't cause any embarrassment. I'd rather equate it to photocopying your secret business plan, or your collection of naked self-pictures.
http://bluetouff.com/2013/04/25/la-non-affaire-bluetouff-vs-... http://bluetouff.com/2014/01/10/cher-contribuable-je-te-dema...
they can follow your transaction with the company once they find out, but it's going to be a little more difficult.
Leasing a server wouldn't have changed a thing in that specific case.
Anyway, bluetouff is well-versed in computer security and the co-founder of a VPN service, so I suspect the files weren't downloaded from a french IP adress.
Of course the fine seems absurd to me personally, but this excerpt hints at a couple things one should definitely not do.
If I go to, say, the twitter homepage, I will find an authentication page, and yet most content on twitter is obviously intended to be public.
If you have a secret document, when I come knocking on your door and ask for that document, you'll refuse to give it to me, or at least ask for something that convinces you that can access it. Nobody would be crazy enough to charge me by a crime if I ask you the document, and you give it to me without any kind of verification.
But now, configure a computer to do that exact thing, and suddenly you manufacture plenty of new criminals.
Again - I don't really agree with the ruling here - just trying to clarify.
Anyway, the point is, it's smarter to be explicit and also opt-out using robots.txt or something similar.
But wasn't the quote indicating that it was made clear somehow? Looking at the anses.fr site isn't particularly helpful, if that's even the site in question.
I mean, I've stumbled on FTP sites that allow anonymous users. By providing no password and still seeing content, would I have "hacked" them? It's a configuration issue, and password prompts are just that. Of course, where do you then draw the line? If you call it a security flaw that the documents were public, then accessing them could be an exploit. But... a very flimsy one, since we rarely execute injection attacks to visit websites, but we often click links on Google. The bar is clearly very low. ;-)
This might, of course, change if the access was not indicated on Google but instead on a site like shodanhq.com ...
I wouldn't infer that just because (as noted by the parent comment) https://twitter.com/ requires a login, I shouldn't look at https://twitter.com/twrbrdg_itself
Now, if all those pages I looked at before finding the login page had a banner saying "private, not for public consumption, don't share this with anyone who doesn't have an account", then I might think "hmm, perhaps I'm not supposed to be here".
As for the lock on the door comment, I'd say it's more like if you noticed a store is left unlocked in the middle of the night, and therefore assume you're welcome to go in and walk around. In fact, they probably didn't leave it unlocked as an intentional invitation.
What kind of security let's you download documents without authentication?
everyone knows you only build large public projects there if money change hands. and it usually happens that the gov official get the quotes from all the companies, call the one paying him the most and tell the other quotes and that company submit a little lower than the lowest and get the job, later including several hidden fees, etc.
the, for the sao paulo subway expansion, a journalist did a search and found documents proving all that for that specific job (yellow metro line) and published them.
gov removed the documents, waited for all signs of it ever being indexed to disappear and then sued him. i think the trial is still going and they still deny those documents ever existed.
Esp. with government documents you are safe to assume that they are public, if they are public and look public.
This is all assumption, of course, but I think it's pretty logical assumption.
Still, freedom of the press is a strong right. Though freedom, as they say, isn't free (there can be and often are consequences to exercising your freedoms). In this case I think he's lucky to just get what amounts to a hefty access fee. If he had stumbled onto U.S. documents he may well have found himself taking a ride in a black helicopter.
Their penalty was a denial of admissions, but their hack of using a specially-crafted URL was about the same.
If that's the law, then it needs to change.