Cardinals Face F.B.I. Inquiry in Hacking of Astros’ Network
nytimes.com
nytimes.com
And the only way they were caught was because they likely leaked some of the information they found to Deadspin. I remember at the time of the original Astro's leak, it was very interesting what specifically was leaked. It was not anything that could damage the Astros from either a legal, financial, or competitive standpoint. It only served as an embarrassment to the front office, almost as if the specific information leaked was meant as petty revenge while trying to walk a line by abiding by a certain competitive and moral code.
Just a hunch, but I've seen it many times at past employers.
It's a no-no when the provider has a duty to the user, such as when the user is a paying customer. It's probably OK when the provider is the employer and the user is merely an employee? I say this because employers regularly do much worse stuff, like running MitM proxies that log bank passwords...
In some cases it may be necessary to see the application from another user's perspective. In this case you build a function analogous to "sudo -i -u user" which lets the privileged employee use his own account to get a session under another user's account, while generating an audit trail.
However this is usually not the right answer. Google Apps does not provide an "impersonate" function, but API endpoints which let you dump all mail to your own archiving system (where your company can search it for investigations, legal discovery, etc.) This is more efficient anyway, and doesn't require the disclosure of user passwords.
You can also do this crudely by resetting the password in the database, gathering whatever you need to, and then changing the password back by replacing the old hash directly in the database. Then at least the impersonation is evident in your MySQL logs.
If there is an Excel sheet of passwords shared among managers, and someone does something nasty from an account whose password is on that sheet, good luck figuring out whether the perpetrator is the account owner, one of the n managers with access to the passwords list, or someone else entirely.
Though if the FBI finds that the GM/high level execs knew about the activity... this will be unprecedented. The penalties would be staggering as MLB would want to crack down extremely hard to deter future bad behavior.
The cynical side of me says that Selig and MLB will try to maybe milk this for some rating or something, considering the meme going around that baseball is dying.
(full disclosure, Twins fan here, so I'm gonna be cynical about anything that Selig does)
[1] http://www.si.com/longform/astros/
Edit: Guess I missed that Selig retired in January. Damn you, work!
The Patriots filmed the Jets' sideline during an actual NFL game that was happening in front of like 80,000 people. It isn't even illegal to film opposing coaches on their sideline, you just can't do it from your own sideline[1]. That's what Spygate was. Is that really spying? Is it outright spying?
[1]: https://en.wikipedia.org/wiki/2007_New_England_Patriots_vide...
[1]: https://en.wikipedia.org/wiki/2007_New_England_Patriots_vide...
> almost certainly
From the Wikipedia article you linked:
- "[The NFL] found no evidence to substantiate the Super Bowl XXXVI allegations or any other transgressions beside those the NFL had already penalized the Patriots for."
- "NFL investigators found practical limitations to the allegation; the Patriots' video equipment that was set up the day before the game had neither battery packs nor a nearby power supply in order to run." In other words, filming the walkthrough was not plausible on a technical level.
- "The Boston Herald [who initially published the story based on an anonymous source] published an apology to the Patriots and their fans for publishing the February 2, 2008, story ... alleging the Patriots had taped the Rams' walkthrough prior to Super Bowl XXXVI. ... They wrote, they should not have published the story, which they deemed to be false."
I'll be honest, I didn't even know about this aspect of Spygate before reading the Wikipedia article, but it seems like the allegation was investigated, the NFL found nothing, and the Boston Herald apologized for a story that was seemingly without merit. Where are you getting "almost certainly"?
I'm just taking issue with the guy calling it "outright spying" which is a pretty exaggerated characterization when you're filming what a coach is doing in front of 50,000 people. If that's spying, then I spy on NFL games pretty regularly.
By the letter of the law, this is a crime. You may be correct, but something substantially more could happen.
"Investigators believe Cardinals officials, concerned that Mr. Luhnow had taken their idea and proprietary baseball information to the Astros, examined a master list of passwords used by Mr. Luhnow and the other officials who had joined the Astros when they worked for the Cardinals. The Cardinals officials are believed to have used those passwords to gain access to the Astros’ network, law enforcement officials said."
"Believing that the Astros’ network had been compromised by a rogue hacker, Major League Baseball notified the F.B.I., and the authorities in Houston opened an investigation. Agents soon found that the Astros’ network had been entered from a computer at a home that some Cardinals officials had lived in. The agents then turned their attention to the team’s front office."
Probably not going to go down like that, but it's a matter of punishment, as well as compensating the team that was the victim. (I'm from Houston, so probably biased)
However, if the Cardinals are as smart (and perhaps as ethical?) as they previously seemed, they'll get out in front of this, and voluntarily give up their 2013 pennant, as well as fire whoever was involved in this harebrained scheme.
I'm a Cardinals fan, I admit it, but that's basically an insane suggestion. It's not going to happen and it's not smart. Why in the world do you think that would be smart?
Until there are details on what was done and by whom the Cards should do nothing more than fully cooperate with the investigation. Then and only then should the Cards and MLB decide how to respond.
Fanhood notwithstanding, this is really bad. Unless the FBI finds that someone planted a device on the network of the house that originated the ill-advised logins, someone has to burn for this. (I guarantee that Mike Matheny feels the same way.) It's not quite at the level of Pete Rose (who really ought to be forgiven by now) or the Black Sox, but like those cases it completely undermines the integrity of the sport. I used to be impressed by the Cardinals' great farm system, and I felt it indicated something about Midwestern thrift, practicality, and eccentricity. I don't feel that way anymore.
Well, ironically, that system was built by Luhnow, so I think you're allowed to continue feeling that way :)
Im pretty sure that in F1 one team hacked another for design details. That said, I cant find a source. IIRC, it was Renault hacking Ferrari, but Im not sure.
Hardly. I'm sure there are countless examples of employees improperly using access given to them by their previous employer.
https://en.wikipedia.org/wiki/2007_Formula_One_espionage_con...
Use self-destructing cookies or a plugin like it to delete the cookie everytime you close the tab and you won't run into the NYT paywall.
Alternatively, you could use a plugin like refcontrol and set your referrer on NYT as news.google.com and be in the clear if you like hanging on to cookies for some strange reason.
Really? I'd suspect it to be the other way around. For reference, here are some HN stats: https://news.ycombinator.com/item?id=9219581 .
I wouldn't be so sure of that; considering my own pattern, even when my reading is being driven by HN, I usually do several google searches for related content, including frequently Google News searches for related news items from other sources, for each page I go to directly from HN. And not all of my reading -- even related to development/startup things -- is driven by HN.
Regardless of their weak password storage scheme (which must be fixed), a simple set of changes (like disabling public access to their system, disabling VPN for terminated users, and changing passwords) would have stopped this from ever occurring.
Also, the Cards staff probably shouldn't have logged in from home.
Also, how on Earth is this a valid use of the FBI's resources? Fix your broken crap yourselves, Astros.
So that's probably why the FBI would care.
RE downvoters: http://www.nytimes.com/2014/05/04/magazine/only-one-top-bank...
Right now, "unauthorized access" is any after-the-fact declaration that someone didn't want someone else looking at something.
If there had been broken encryption, 0-day exploits, SQL injection attacks, etc... THAT is hacking. Not accessing a public endpoint that lets you in.
There seems to be a very popular misconception that the law criminalizes "hacking", as in "0-day exploits" and "SQL injection". No: thankfully, the law doesn't so much care about how you get access. It cares that you knowingly access things without permission, no matter how you do it.
Or if the fact that the key is physical gives you pause, let's say you nave a numeric keypad lock, and at work one day you commented that you had it set to the same setting as the lock at work to make it easy for you to remember. Do I get to take your stuff?
I think putting password protection on something isn't "after-the-fact", it's pretty obvious they didn't want someone else looking.
It's clear, too, that the Astros' staff brought this on themselves. When one is hired away to a competing organization, start using new passwords! Sheesh.
FIFA's shenanigans also costs Americans money, in the form of the bribes and backdoor deals the various TV networks have had to pay to get the TV rights, which directly or indirectly consumers end up paying.
I don't know if what the Cardinals did rises to the level of organized crime that FIFA seems to be, but MLB teams are publicly funded (via stadium-building subsidies) companies, and deserve scrutinization just like any other business.
[1] http://www.motherjones.com/mixed-media/2015/05/chart-fifa-de...
This is two goals, stated as four:
1. There should be more technology developed under a patent system than otherwise.
2. People should stop keeping their technology secret.
> Main article: History of patent law
> Patents were systematically granted in Venice as of 1450, where they issued a decree by which new and inventive devices had to be communicated to the Republic in order to obtain legal protection against potential infringers.
Goal #2 is the origin of the system, and the only goal that the system directly addresses.
So let's take a common example of a trade secret protected by American law: a company's customer list.
I don't see the argument that businesses wouldn't bother developing customers in the absence of trade secret law. Nor do I see why protecting that information is in the interest of anyone outside that particular company. It's definitely contrary to the interests of the customers.
The Uniform Trade Secrets Act explicitly states that it's intended to protect businesses who believe that their information is nonpatentable:
> "In view of the substantial number of patents that the courts invalidate, many businesses now elect to protect commercially valuable information by relying on the state trade secret protection law."
And hey, for secrets like a customer list those businesses are surely correct. But who cares? Trade secrets are by definition something the business felt was worth the effort of developing regardless of patentability concerns. Any hypothetical benefits to society are, at best, extremely precarious -- that's why we have patent law. Trade secret protections are an undisguised, pointless giveaway, and they undermine the goals of the patent system.
It's not just about one team spying on another team, there are ripple effects here of people who might have been negatively impacted by the illegal activity of the Cardinals.
The FBI is a huge organization. They can investigate illegal computer access as well as slavery rings. Their sports investigations are no different than any other corporation.
W/R/T your other objections, regarding financial and surveillance issues, well, it's clear that your opinions differ from those in power. To continue calling for investigation of financial shenanigans is, well, your choice, but it's not something I'm getting upset about. (Not because I don't think it's wrong, but because I don't like getting upset over things I have zero control over.)
Well, if your network is open to the public and not properly secured, that's on you. Especially multi-million dollar organizations that can afford to pay security experts.
Bad or no security is not in itself permission to enter.
Yes, the Astros do bear some responsibility to make sure things are not easily accessible. That doesn't change the fact that what the Cardinals did was wrong.
I'll be sure to use that line at my deposition
We have criminal laws for things besides murder, which would be kind of pointless if we didn't allocate criminal law enforcement resources to things besides murder.
So yes, FBI.
This perhaps is another indictment of the Astros' security policies. It certainly should be on the FBI checklist for "should we help these clowns figure out how they got hacked?"
The analogy works well enough, since we're dealing with private property (home, network) concealed by points of entry (doors, windows, nodes). Types of responses and feelings of security, etc are outside the scope of the analogy.
By the way, it's disingenuous to introduce a scenario (of dubious relevance) that inspires strong feelings and then to deny you intended to evoke those feelings.
What I cannot get over is how absurd is it that the Federal Government has been able to insert itself so deeply into a problem that doesn't warrant FBI involvement in the slightest. Athletic teams have been cheating for centuries. Sometimes that cheating involves ruined careers for both the cheater and the cheated, and sometimes they involve teams losing money. But what they rarely involve is the FBI. And the only times I can think of when they have involved law enforcement have been narcotics or gang related.
To me, this sounds no worse than various other advantages that teams unethically gain for themselves. That our legal system allows for this particular type of cheating to potentially be a federal crime is frightening. Let MLB handle this internally, and play ball.
[edit: holy shit. I get it. The FBI is acting within its legal right (and duty). This is a moral statement about the law that they are tasked with enforcing.]
So it looks like the Astros/MLB were unable to determine internally how their network was compromised and then contacted the FBI. This seems perfectly reasonable to me.
A guy was completely careless with his password, and a competitor used it to steal information. The analogy to "stealing signs" in baseball is almost perfect. In one case, we laugh. In another, the guy goes to federal prison.
Or to put it another way, I'd much rather the FBI spent it's time prosecuting crimes committed by large companies than screwing over kids like Aaron Schwartz for their minor indiscretions.
Instead, I would look at this as two multi-million dollar businesses engaging in corporate espionage. When seen from that angle, it is exactly the sort of thing the FBI should be involved in.
Is there a federal law that makes doing that a federal crime, and, if so, is there not a federal law enforcement agency besides the FBI that has been designated to exclusively enforce the applicable law?
If yes to both of those, then, sure, there is a good case for the FBI getting involved, because its their job. Otherwise, no, they, shouldn't, because its not.
I'm saying that the act of transforming an everyday action into a federal crime just because unauthorized computer access was involved is a horrible, dangerous system for us to have.