Student Charged With Three Felonies For Finding Security Flaw — and Report
Well, yet another teenage hacker who "did the right thing" by reporting a security flaw is being punished for his actions. Although it definitely sounds like the whole story may not be in the clear yet, a 15-year-old New York high school student has been charged with three felonies claiming that he accessed a file containing social security numbers, driver's license numbers, and home addresses of past and present employees ... and then sent an anonymous email to the principal alerting him to the security flaw. "All that was needed to access the information was a district password. School officials have admitted that thousands of students, faculty and employees could have accessed the same file for up to two weeks."
Was there any bit of responsible disclosure, because it sounds a bit like "killing the messenger". While there may be discipline in order, this seems to be overkill if he was really intending to do the right thing.
Twitter supports and protects racists - by smearing their critics with the "Hate Speech" label.
Reporting a security hole is not noble, it's stupid.
As in, being hit with the law book.
I RTFA but see no sign of this. At best is this bit from a followup link in TFA:
But for fuck's sake, three felonies at 15? For a fucking non-violent, non-destructive "offense"?
Poor kid is screwed for life.
stupid people fear smart people
The Admin and the Engineer
This is like Boston freaking out over Lite-Brites. I hope the kid not only calls their bluff and asks for a jury trial, but finds some way to counter-sue.
And one who breaks security is like the one who alerts the king about wearing no clothes. You WILL get punished. You WILL be dealt with.
I saw this all the time at schools, jobs and like. People dont like smart people. People who intentionally find broken ideas and mechanisms will be dealt with, not glorified and congratulated. Highlighting a security problem means they have to put in the effort to fix what you brought to their attention, or threaten you to STFU.
If you are smart about security, keep your mouth shut. There's not much you can do, except yourself be a target.
If you're baiting your honeypot with real data, you're doing it wrong.
Blank until
Forget that this kid was doing a service to report the flaw, they are more concerned with why the kid was trying to access the site in the first place.
OK, I know Slashdot is collectively in holier-than-thou rage over this poor, "innocent" kid, but why was the kid trying to access the site in the first place?
It seems to me that he's not being punished for reporting something, he'd being dealt with because he probably broke the law.
Of course, the officials responsible for the shoddy security and data protection should also be dealt with under whatever laws apply in that jurisdiction. But that doesn't excuse a kid who actively went on a fishing expedition. The end cannot be allowed to justify the means in cases like this, or you undermine the basic principle of the laws: you give carte blanche to crackers to have a go at whatever they like, since if they get in, they can just report it and pretend they were doing the world a favour.
If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
You keep using that phrase, "copied the files to his computer". I don't think it means what you think it means.
In discussions like this, it might merely mean that the kid accessed a protected area by accident, and his web browser "copied the file to his computer". Law Enforcement sometimes misuses the mere presence of data on the suspect's computer as the standard for proof of guilt, which is sometimes only the browser cache or even the cache for a filesharing program, when the user may not even know what the heck was in it.
The file name undoubtedly was not "click here to get 3 felony charges file against you and seriously fuck up the rest of your life" . The kid appears to have been doing the right thing. Now, if he tried to sell any of the data that he saw, sure, charges might be appropriate. Based on what little public information is available, this appears to be a case of shooting the messenger.
If you mod me down, I shall become more powerful than you could possibly imagine.
What, exactly, do they mean by that? Remember, we're talking about governmental entities that have a long history of not understanding much about computer security. For example:
$ ftp ftp.myschool.edu
Connected to ftp.myschool.edu
User (none): guest
331 Enter email address for anonymous login password
Password: myusername@yahoo.com
230 User guest logged in.
FTP>
Law Enforcement: "Clearly he was trying to impersonate Mr. Guest!"
You: !@#@#$
You think that's too silly? It's no worse than any number of other things I've heard about from such people. Or consider this:
You: "Let's see if that cute girl Angela in my English class has put up a home page on the school computer system. Let's see, use Firefox to browse to www.myschool.edu/~angela/ ... That's odd, doesn't look like what she'd have on her home page. What's this file?"
Cops: "Clearly he was trying to break into the Assistant Principal Angela H's computer work area!"
I don't think these examples are unrepresentative of the typical computer security understanding of law enforcement, unfortunately.
At least a couple of the articles say that the password he used (whatever that means, see my other comments on the subject) belonged to "another student." Oh, really?! Why did that other student have access to the data?! And why isn't he being charged?!
Clearly what we have been told about this incident is highly misleading. Either
(1) The file was in a location that could be accessed by ANYONE on the school network, or
(2) it had already been hacked by another student, who for some reason is not being charged, or
(3) He hacked into an administrative area, where the file may have been inadequately secured. Comments by the administration and law enforcement to the effect that the password he used belonged to another student are either incorrect or misleading.
Something is clearly rotten about this story, unfortunately it is difficult to tell if he did anything wrong or not, or whether he is a criminal or a scapegoat. Not only do we have to get information filtered through the administration and law enforcement (for whom computer security is usually at best an arcane art that they understand only poorly if at all), but all the primary sources are articles written by local news journalists rather than technical journalists, who are generally not much better at understanding the technical details.
It would appear however that unless he needed to hack into a reasonably well protected account in order to obtain the data, the school is clearly facing a serious HIPAA breach. That alone could be making them overreact, by trying to find some way - any way - to pin the blame on someone else.
The lesson here is to get better at sending "anonymous" e-mail to report this stuff.
I might know what I'm talkin' about, but then again, this is Slashdot...