Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

this is dumb on many layers - threatening white hat who could be held accountable but could be hired to do further audit; failing to come to grips that if you are insecure enough to threaten someone, you know - internet will find out that you rather than fixing holes in your system rather use expensive lawyers to intimidate people who on the whole trying to a good thing for you.

The whole thing about unauthorized access - not sure about. If you get burglarized and live worse part of town - because you did not lock your front door - is this you fault or criminal's? Ultimately buck stops with you, you would look very stupid arguing that a stranger walked off the street and pinched your laptop, better yet, if you leave your laptop on your front lawn.



Pardon my language, but that is such utter horseshit, and I think you know it.

Just because my door is unlocked, or my digital property is unsecured, you do NOT have permission and should not assume you can take access. That is the scummiest argument I've heard in quite some time. You do not have permission to steal something just because it's super convenient to do so; regardless of whether it is physical or digital.


It in no way diminishes the effect of a crime if a person does not lock their front door. It is not the victim's fault if they did not install bulletproof glass and employ a security guard. If you think differently you have a twisted outlook on life, a sort of might-makes-right view of righteousness.

Such rationale is the rationale of a lowlife. "The front door was unlocked so its their fault I stole from them." "If they didn't want me to steal their lawnchair, they shouldn't have left it unchained on their porch." Nothing is inexcusable with that line of thinking. "If she didn't want to get raped, she shouldn't have been all alone in the middle of the night in a dark alleyway." "If he didn't want to get brutally assaulted, he shouldn't have left such a stupid comment on HN."


Agreed. You don't get a pass for breaking into someone's house just because you say you weren't there to cause any harm. Yes, it's good to be pragmatic and understand that there's always something the owner of the house could have done to help prevent the break in -- close the door, lock them, get locks that are harder to pick, install security cameras, etc. etc. -- but the person breaking into your house is still wrong for doing so, even if they claim they just wanted to tell you about the weaknesses of your house's security. I don't see any reason the same reasoning shouldn't apply to digital property.


I think what makes it tricky is that the systems are automated and intent and authorization aren't so clear.

We never call up the owner of a web server and ask them for permission to browse their site. We just connect to port 80 or 443 and go to town. This is universally accepted as authorized use.

Now, say you're running a vulnerable sshd such that if you send just the right bytes, it'll log you in as root without the password. I imagine most will say that this is unauthorized use.

But what's the difference really? In both cases, you're asking the server to do something, and then it does it. In the real world, we have various things to look for. Private dwellings are off limits without an invitation. Elsewhere, a lock means you don't go in, even if it would be trivial to defeat. Or just a sign that says you should stay out. It's not so clear with computers.

People have been convicted of a crime for taking a public URL and chopping off the last component and getting a directory listing from the server. To one side, the fact that you had to edit the URL and the fact that the directory listing wasn't what the rest of the site was like was enough to establish that as "unauthorized". To the other side, the guy just asked the server, "Can I have what's located here?" And the server replied, "Yep, sure, here you go."

A few weeks ago, there was a story here about a blackjack player who cheated a casino out of a bunch of money. He asked for a dealer who spoke Mandarin. His confederate then asked the dealer in Mandarin to turn certain cards upside down for luck. Normally this would be fine, but the cards at this particular casino weren't quite symmetric on the back, so they could tell them apart. The request would be suspicious, but they used a language the bosses couldn't understand, so they didn't realize what was going on.

In the end, the casino sued the guy for hefty damages. And yet all he did was ask and then receive what he asked.

In many ways, servers are like that dealer. You talk to it in a weird language that the owner can't understand (or he can, but he doesn't listen in on everything) and sometimes you can ask it for something the owner would refuse, but the server/dealer says yes.

So while it's clear that walking off with somebody's laptop just because they left the front door open is wrong, it's much less clear to me where you draw the line with networked computers, and it doesn't look like others have a particularly clear idea either. Given that fundamental lack of clarity, I don't think it's completely unreasonable to characterize these guys as locating spots where access is authorized (and thus legal) but shouldn't be, rather than locating spots where unauthorized access can be gained.


The difference between lawfully entering a 7-11 and trespass is just as you describe the situation with a server. Authorization can be implied, and "unauthorization" can be trivial.

The real problem is that a lock on a door is more obvious than a URL scheme. The government is saying that entering a 7-11 that is unlocked, but walking in backwards, is criminal trespass because that's not what the 7-11 intended for the customer to do. That's nonsense. Implicit authorization in physical property is just so much more straightforward, and the government is trying to maliciously take advantage of the lack of common sense on what is unauthorized, helped along by a Congress that willfully authorizes such action.

And I like your server dealer analogy. The question is whether or not a computer is an agent of its owner and whether its decisions, right or wrong, can be relied upon in business dealings as the actions of its owner.

So what is the digital equivalent of a lock on a door? Must the law explicitly say a lock on a door signifies lack of authorization to enter? Is walking into a 7-11 store backwards implicitly unauthorized?


Comparing requests to a server to edge sorting in blackjack is really insightful. The analogy isn't totally similar, though, since in the edge sorting case, the player walks away with money, while URL chopping just gives information.

I should mention that the player involved, Phil Ivey, is probably the most famous poker player in the world. According to Wikipedia, "Ivey is regarded by numerous poker observers and contemporaries as the best all-round player in the world today...his other nickname is 'The Tiger Woods of Poker'." [1]

[1] http://en.wikipedia.org/wiki/Phil_Ivey


Where I come from it does. The police will blame the victim if they left their door unlocked and got burgled. Also, insurance will sometimes won't pay out.


A better analogy would be someone entering your house if the door is left open, and then them shouting to see if someone is home or if they left for work - in view of closing the door for them.


And then someone called the police when they found someone random was in their house without authorization. And the intruder said "I was only there to shut the door for them."


Which parallels white hats getting arrested for legitimate security research.

Hence my analogy stands.


Yes, your analogy does stand. And it stands to reason that the intruder should be punished, and/or sued, for trespass. It is not a legitimate reason to be in someone else's house.

Going around trying to open everyone's doors is a similar analogy to some other security research. And while its not as clear-cut, in fact arguably not a commonly cognizable crime, it certainly is suspicious and its reasonable for law enforcement to investigate such activity.


So if I suspect that someone else will steal from a house if the door is left open, (And I have strong evidence for this)

And I see that the door is significantly ajar (one can see valuables through the open door)

And the house appears to be empty,

And the doorway is flush against the sidewalk, where I am walking by on my way somewhere else (the door opens inwards and is not in my way)

If I knock on the door (holding it so as to not make it swing inwards further and hit the wall) and ask if anyone is there,

And recieving no responce, close the door,

I should be punished?!?

If I see someone injured and unconcious on a sidewalk, should I just walk around them in order to avoid infringing on their personal space?

What if I have relevant medical experience?

Am I to let them lie there?

If someone (a stranger) is unconscious from drinking alcohol to excess, and is lying on their back, am I to refrain from turning them on their side, and instead allow them to choke on their own vomit and die, so to avoid running afoul of laws intended to protect against pickpockets?

If someone has a problem and is in danger of significant loss, but is unaware of it, and I am unable to inform them of it, but I am able to easily lessen the danger, at no cost to them or any other person, through an interaction that bears some similarity with some action that would be reasonable to forbid due to causing harm, Should I not help that person simply due to that similarity?

Edit:

It's possible that I misunderstood what was said somewhat. I'm not sure.


I am just a simple country boy, but my understanding of "White Hat" is about hacking done with explicit permission. The article suggests activities that cross the line.


Exploring open systems is a right, hence the open internet. If you don't want people walking the streets maybe you should put up a fence, close the door. Since internet protocols provide authorization via login/authentication token functionality - that what people should use to provide restricted services - not sic lawyers when someone elses packets land in their networks. RTF-RFCs.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: