Hacker Claims Feds Hit Him with 44 Felonies When He Refused to Be an FBI Spy
wired.com
wired.com
FYI the 44 counts were arrived at by charging each form submission individually, so it was really just 1 charge, just counted 44 times.
You know, rudimentary attacks that should not succeed on any type of vendor system that has been through the most basic security audit or pen testing?
I guess we should either trust the vendor or don't. No real reason why would anyone want to see if other hackers with basic knowledge can get access to a system? I'm sure there are plenty vendors with transparent public records of the authorized penetration tests that they have ordered which have been done, you can trust!
So, the only problem left is how to establish your standing to sue the lazy vendor. It is a problem since you can't actually bring them up on negligence charges if you were not actually damaged.
Well, if picking the lock is thus illegal per your analogy, then the only way to have standing would be to first submit yourself to potential unknown harm and wait for the day when a bad hacker comes!
I think your analogy falls down too, because a brick-and-mortar storefront holds its own assets and is liable (or insured) for their own losses in the event of theft. You rarely store your own private things inside a brick and mortar storefront. If you did and they are stolen, the store would normally be liable and reimburse you.
People store their private data "in the cloud" all the time, but because of arcana in law which does not correctly distinguish between pulling on the handle and picking the lock, they are not allowed to check and see if the cloud-monger actually locks the door when he goes home at night?
This is equivalent to "checking to see if the door is unlocked when it should be locked" not "trying to pick the lock after hours"
As to trusted certification - please elaborate; because many of these "certifications" are entirely worthless (some indeed indicate that a site is less likely to be safe).
It does show some kind of theoretical preference for security but it by no means assures one -- nevermind making any kind of a guarantee -- that said preference has been successfully translated into reality.
I would suspect that the rate windows or doors left accidentally unlocked between houses with security systems and without isn't a substantial enough difference to be meaningful. Sure the right might drop in half, but if it's from 4% to 2% that doesn't do much.
Having an SSL certificate is really the bare minimum that someone can do to have even a hope of a prayer of keeping data safe. There are about a dozen steps beyond that which must be taken. Worse, the effects are not additive, but multiplicative. If any one particular defense is handled improperly the properly handled other portions lend little/no assistance.
Naively one might assume that the total security score might be tabulated this way:
( 1 + 1 + 1 + 0 + 1 + 1 ) / 6 = 0.833
But in fact, it's this way:
1 * 1 * 1 * 0 * 1 * 1 = 0
Prevent this kind of scan makes all of us less safe, since it encourages negligent behavior like taking risks with data that's not yours. Frankly, I think website owners should be held liable for security vulnerabilities.
This kind of culture of systematically undermining a secure internet only serves those who abuse our trust. Do you honestly think the FBI has a chance in hell of actually catching more than a minute fraction of all malicious hackers? Not to mention the fact that their motives here and elsewhere are rather questionable - if anything, they're less benign than the hackers they're chasing, seeing as they're essentially untouchable for whatever damage they cause.
Because this is the law here and they'll always apply it as broadly and wrongly as they possibly can you have to consider the extremes on this. At what point do you draw the line? To go with the hypothetical worst case scenario, what if little bobby tables goes to sign up for a account somewhere, does he get charged with "attempted hacking"? This also puts grey and white hat hackers in a dangerous place as well (particularly grey hats which are already on shaky ground as is).
Yes they do.
>clear intent
Intent of what, exactly? Intent to make the site do something it wasn't explicitly designed to do, yes, but that does not imply exceeding authorized bounds or causing any harm.
It depends on the details.
Deliberately injecting "SELECT * FROM customers" can potentially exceed authorized bounds. (Even then the intent might not be there in all cases.)
Injecting "SELECT 1=1" to see if the system is broken is clearly not exceeding authorized bounds.
There is a huge gulf between checking for access and abusing access.
By checking all the locks, and not just a handful of them?
I don't think it's enough to show he was thorough to establish there is actual mens rea for a crime to have been committed.
I bet that site had at least 44 separate form inputs. No sense checking just a handful of them. None of the third-party certifications you suggest looking for to assess a vendor's worthiness are even roughly analogous to a bank with, for example, FDIC insurance.
If I have never undergone the certification processes myself (or perhaps even if I have, more so) they are the information-security equivalent of "tiger repellent" to me. I can only take the word of "experts" that they are good.
If I can't tug on all the exposed levers, then I guess at least I can be assured only people who are paid to do that (or people who are breaking the law) have actually tugged on them.
Can you understand how this kind of assurance would not reasonably instill any confidence of a system's security? The law does not forbid one from looking over one's own shoulder, so why should it be any more criminal to do that at every single corner you passed, even in an airport?
There is a reason info-sec experts are sometimes seen as paranoid, it's because you don't know if you don't check.
While 3rd party certifications might not hold the vigor of FDIC insurance you are unlikely to put information on a website that is as valuable or irreplaceable as what you put into a safe deposit box. Most of time we're talking about a name, address, and potentially credit card information as the maximum damage possible. Well, your name and address are almost certainly already public record. Your credit card similarly has excellent protection and aside from some incredibly rare nightmares most people who have their CC info stolen are back to normal within a few days of calendar time and less than an hour of time actually spent dealing with the issue. If you're putting something more valuable on the website you're perfectly within reason to contact the vendor and request permission to perform a security analysis or have your own trusted security analysis vendor perform such tests. This happens all the time in business.
You can feel assured that only people who are paid to tug on the levers or people who are breaking the law are the only people tugging the levers at every company you conduct business with.
And the literal "tuggin on the lever" analogy is really poor. A closer analogy would be, "I know many locks are vulnerable to being opened with a specially crafted bump key. I will walk around the building after hours and attempt to use a bump key on all the doors to ensure it's safe to conduct business here."
We are going to have to agree to disagree. You seem to think that performing SQL injection, even just to see if it is possible and with no intent to steal information or in furtherance of any crime, should be criminally prosecuted.
I think that SQL injection is such a basic attack that they should teach everyone how to perform it in introductory CS courses or earlier, as only through awareness of these basic forms can we all stamp out the threat of our own global systemic ignorance of those kind of forms.
It's not a kind of magic. Nobody is born with the knowledge that "SELECT * FROM Table WHERE #{userdata}" is completely and perfectly wrong approach to taking input from users in any production system. You have to learn it somehow, and the law practically forbids you from learning it through application in the wild. So I suppose only criminals will get to have guns, then.
> You can feel assured that only people who are paid to tug on the levers or people who are breaking the law are the only people tugging the levers at every company you conduct business with.
I understood that already, and it didn't make me feel warm and fuzzy. I don't really think there's a ghost's chance that I'm in the majority here, either, and I do find that to be a shame. Even many otherwise smart people are just totally ignorant of computers.
Which situation is preferable:
a) As a new business, I am contacted by a good Samaritan who informs me that my public website is vulnerable to a common attack. I take this information to my development staff and they verify that we are indeed vulnerable, then we fix it. Millions are saved. I send a thank-you note to my new friend in Samaria and maybe even write a check.
b) Good Samaritans are prevented from helping by laws that divide adept lever pullers into only two groups: the paid kind and the unauthorized kind. There are then never good Samaritans because every Samaritan needs to take steps to remain anonymous themselves before performing any deeds which could constitute "an attempt to obtain unintendedly authorized access".
It's clear that "The only reason to obscure the origin of a packet is in order to not be the one caught sending it." Anyone who does not want to get caught doing whatever they are doing, I think it follows obviously, can't possibly be helping but only up to no good. Now all Samaritans with knowledge of SQL injection are at odds with web service companies and all good and rational Samaritans do the smart thing and cease all helping. If anyone helps, they will do so anonymously; if they are identified, they will have to swear they only found the issue by accident and didn't even really know what to look for.
In (B), your ability to secure yourself is directly at odds with the amount of spare time those (real) hordes of bad Samaritans or other nationalities behind seven proxies can spare. Got unlimited money? If you can't pay for enough pen testing, well I hope you did security right because nobody is going to help you now. Is that really the preferable scenario?
We have varying degrees of laws protecting certain kinds of "Good Samaritans" in cases of medical emergency, they are on the books in every state. Unless or until it's an issue of something wrong on a computer. There is no such similar protection for any security pros or curious tinkerers.
People who legitimately stumbled onto vulnerable services are best advised to never report them to anyone and forget whatever issue they saw, or they are persecuted by the FBI and prosecuted through CFAA and other legal channels. This cannot be considered optimal!
Username: Lawtonfogle
Password: hunter2' OR 1 = 1;
and Username: admin
Password: hunter2' OR 1 = 1;
is quite different. Should these be treated equally as hacking?Web servers are other peoples' property, and there's no "right to tinker" with them. All you have is an implied license to use the site in the way the owner expects you to use it, the same as with a physical storefront.
Web servers are other peoples property, but they're also a public space when you open then up to the public by hosting public services on them. A private server is different from a public server in the same way private property is different from a public storefront. By making your server accessible to the public you lose some of the expectations of privacy and implicitly allow a certain degree of access.
"unlawful entry" is usually the common denominator.
From wiki: " or loitering unlawfully with intent to commit any crime, not necessarily a theft – for example, vandalism."[1]
Even once is a serious charge, but I'm not sure there were 44 crimes committed.
Fortunately, in this case, no one died.
Otherwise sounds identical except for the entrapment angle. Weaver specifically refused to become an informant against the targeted white separatists because they knew and completely loathed each other. The offer made to Salinas sounds like one that could very easily result in his getting tortured to death. For that matter, do some of these cartels go after their target's families?
If I remember the details correctly, he was erroneously informed that if he was convicted, his property would be seized because he had used it as bond collateral.
By the time Rachel was twelve, she had been a ballerina, a Brownie, an equestrian, and a Weeki Wachee Springs Little Mermaid contestant; by eighteen, she had learned to play the flute and the piano, gone skydiving, and hiked the Grand Canyon. By twenty-three, she had completed an undergraduate degree in psychology, interned at a mental-health institute, and travelled internationally. She loved to cook—she’d prepare elaborate multicourse meals for friends and deliver homemade matzo-ball soup to an ailing classmate. She was given to hatching big plans: She had initially dreamed of going into counselling, but decided to apply to culinary school. She would invent a new form of therapy, she told her dad; perhaps troubled kids who hated talking to a therapist from an overstuffed couch would open up as she taught them how to bake cakes and make spaghetti carbonara.
I will hazard a guess, not guilty on all charges. She was a druggy after all and got everything she deserved.
That is some serious messed up state of affairs that allowed this to happen.
The officers involved in the operation were suspended with pay, and the family filed a wrongful death lawsuit against the city.
Message to the officers, and to their brethren colleagues in the profession being, in so many words: "Aw shucks, it was just a little misunderstanding. After all, she didn't follow instructions, did she? Don't beat yourselves up over it."
The user above may have meant it as sarcasm, but the funny part is, this is in fact pretty much what the cops were saying about her in the weeks after her murder.
I just hate that a person's life can be boiled down to a sentence or two based on a few activities they were purportedly involved. The feel is bad.
The other day I met them again, now as an adults. It seems like one of the members of the old group took the bait and now is working for secret services or something shady. His life is miserable.
You start selling vulnerabilities for easy money and you could end badly. Those entities have so much power and too few scruples.
> vindictive indictment after a refusal to cooperate... very troubling and very improper
How is this different than indicting first and then dropping charges after obtaining cooperation? The threat is the same: work with us or go to jail.
This is just like throwing shit at the wall and seeing what sticks. It should be illegal.
But the federal sentencing guidelines are very easy to understand. It is essentially a matrix where you look up different factors. Also, the sentences would run at the same time. So 1 charge or 44 wouldn't really make a difference.
So he was realistically facing a few years and plead down to 6 months. Not as draconian as 440 years to six months huh?
My wife got a speeding ticket on a highway in a federal park. It was a reckless driving misdemeanor charge because she was going 33 over the limit. Max sentencing is like 1 year and 10k dollars. We didn't even bother getting a lawyer because they pled down to regular speeding and a fine of 330 bucks.
[1]State public defender quality varies, but the feds are very good.
Somebody who is in unfamiliar territory in this sort of situation, which would be just about everyone who isn't a lawyer, very likely would not know that. This makes the threat of financial ruination effective, even if financial ruination isn't actually their only option.
Do they really want to bring someone "in the fold" in a coercive manner like this? Someone who's entire ###existence### is about cracking systems and spreading information on what they find? They want to invite him into their own living room, knowing that he hates them and feels they screwed him?
The arrogance of these people to think they could actually manage and control someone like him, and not get burned.
Now excuse me I have to go buy a Lenovo from Best Buy...
What am I missing?
Some of the best... ahem... clandestine intelligence work is done by bringing the absolute least trustworthy sort of person into the fold. Namely, the spies of other countries or accomplished persons in some underground or another.
- Julia, 1984
That said, often LE uses false pretenses. It's quite possible they actually wanted him for his Anonymous connections. Had he worked for them they could have pigeonholed him into ratting.
I'm a website developer who patched 11 security holes after a security audit in my last contract gig. I think there is nothing wrong with probing. Actually breaking in and taking is another story.
The government generally works like the mafia, but in reverse: instead of using intimidation tactics to get you to break the law, they use intimidation tactics to get you to put other law breakers in jail. The difference is that the mafia would at least pay you for your efforts. The government just threatens you more.
The moral/ethical grey area here is that forcing someone to work for the government in exchange for not seeking what the law would call 'justice' is the equivalent of indentured servitude, a form of slavery.
With blackmail, you might normally have a reasonable expectation of privacy, and a reasonable expectation that someone will not intentionally harm or injure you. The government is not seeking to harm or injure you (well, not theoretically) when it enforces the law.
We've all signed the social contract that says that if we break a law, we will suffer the consequences, so it's not unfair for the government to prosecute crimes you have actually committed. It is also fair for them to give you a way out of them, as most cases are pleaded down, prosecutors change offenses to lesser degrees for a good track record, etc.
It's also definitely a grey area how prosecutors will often tack on "trumped-up" charges in the expectation that a judge will knock them down to a smaller list but still apply some. Both these practices need to end, or be curtailed greatly.
Superpowers - they are all the same and never learn.
One of the strong and unquestioned implications was this sort of entrapment was wrong, and one of the things that distinguished the US from the USSR. Fast forward to Ruby Ridge, and Randy Weaver's refusal to try to become an undercover agent against a group of white supremacists, which he was not, and they knew that and hated him with a passion, i.e. it would have been suicide, brought the full weight of "the law" on him, resulting in the Feds murdering his wife and son.
When things have gotten so bad, Americans should take example from other countries and only count the biggest charge when sentencing someone to prison. Minimum sentences + abusive plea bargains don't help the current system either (they do help vengeful government tax-paid employees, though, in destroying the life of anyone they wish).
[1] - http://www.threefeloniesaday.com/Youtoo/tabid/86/Default.asp...
edit: http://skeptics.stackexchange.com/questions/22530/does-the-a...
The book claims "How can the average American commit three arguable felonies in the course of a given day?". Yet your example of charge stacking is contingent on carrying a felonious amount of drugs, something the average (mean, median and mode!) American avoids doing.
If you click to the website provided above, the first example is of someone "convicted for using plastic bags to transport lobsters". If you look up the case, they were convicted of criminal conspiracy and smuggling, with the horrible plastic bag charge being stacked on:
http://www.justice.gov/archive/opa/pr/2000/November/647enrd....
And the plastic bag charge isn't about the plastic bags, it's about Honduras having laws designed to protect their lobster fisheries from abusive exports (fisheries are harmed by over harvesting, but someone looking to make near term profits might not care about that, so regulation is sensible).
It's incredibly easy as the felony amounts have been made very small. Further, the police generally weigh the container the drugs were/are in so if you have a plastic container that weighs 1 ounce, prettymuch no matter the quantity of drugs inside it's a felony.
Also, the estimated number or drug users is 23.9 million Americans as of 2012. While that might mean that the "average" American isn't a drug user, it does mean that there are more drug users than say Asians in the US and a very large percentage of the Black or Hispanic/Latino populations.
By your logic, we shouldn't worry about those folks because they aren't the average american (mean, median, mode) and yet the civil rights movement arguably disagrees with you.
Furthermore, when it comes to convictions the average American isn't a felon, won't ever go before the court, etc. And yet we offer these people protections (various Amendments to the Constitution, various Federal, State and local laws, Miranda rights, etc) even though they're not average as per your definition.
Given that the justice system is setup the way it is, your casual dismissal of it seems strange.
EDIT: links
http://www.drugabuse.gov/publications/drugfacts/nationwide-t...
My logic isn't that we should ignore sentencing problems in the US, my logic is that bringing bullshit book marketing into the discussion is counter productive.
I'd be interested in exactly which of my statements you view as a casual dismissal of the problems with the justice system.
I said The book claims "How can the average American commit three arguable felonies in the course of a given day?". Yet your example of charge stacking is contingent on carrying a felonious amount of drugs, something the average (mean, median and mode!) American avoids doing., but that wasn't to dismiss anything about the sentencing in those situations, it was to point out that you probably don't want to argue the blurb from the book if you are having a discussion about drug sentencing.
If you read the book, the source of the "3 felonies a day" claim, is mostly related to the "honest services" laws, which were narrowed in scope somewhat by the Supreme Court after the book was published. If a prosecutor were to very liberally apply the "honest services" law, typical white lies like calling in sick to work when you're not sick or screwing around on the internet can be elevated to felony status.
Another key area supporting the claim is that participating in a transaction where a foreign law was broken is also a felony. I believe the (absurd/bizarre) prototype for this was somebody charged with a felony for possessing warm-water lobsters that were inappropriately packages according to the law of some central american country. (I believe they were in wax paper instead of plastic)
The point was that ordinary people in the ordinary course of business and life can be subject to extraordinary punishments for vaguely defined crime. That means that you're freedom is subject to the whims of an all-powerful prosecutor, which is contrary to generally accepted notions of justice and democracy.
The book reaches super hard to make the argument that we have too many laws. It would do better to simply make the argument that we have too many laws.
It's also the case that the injustice in the US system is not aimed primarily at lobster smugglers and dumb lawyers (two of examples cited at the link).
The point of linking that worst of stack exchange is that you don't even have to read the book to eviscerate the factertisement, so it's not really a great "fact" to introduce into a discussion.
edit: corrected 10 years to 5 years.
The argument of the book is that we have too many vague laws, some of which are nearly meaningless to a lay person. If you're familiar with how the various computer crime statutes are enforced, I think it is difficult to question that assertion.
The other aspect of the book to consider is that your typical middle class working person doesn't see the overreach in things like drug laws as something relevant to them. It's a wake-up call that the fundamental injustice that has been a way of life for the poor and minority community is expanding.
That's true whether Stack overflow and I have misjudged the book or not.