Reporters Threatened, Labeled Hackers For Finding Security Hole
colinneagle writes "Scripps News reporters discovered 170,000 records online of customers of Lifeline, a government program offering affordable phone service for low-income citizens, that contained everything needed for identity theft . Last year, the FCC 'tightened' the rules for the program by requiring Lifeline phone carriers to document applicants' eligibility, which led to collecting more sensitive information from citizens. A Scripps News investigative team claims it 'Googled' the phone companies TerraCom Inc. and YourTel America Inc. to discover all of the files. A Scripps reporter asked for an on-camera interview with the COO of TerraCom and YourTel after explaining the files were freely available online. That did not happen, but shortly thereafter the customer records disappeared from the internet. Then, the blame-the-messenger hacker accusations and mudslinging began. Although the Scripps reporters videotaped the process showing how they found the documents, attorney Jonathon Lee for both telecoms threatened the 'Scripps Hackers' with violating the Computer Fraud and Abuse Act (CFAA)."
That will teach you to use responsible disclosure.
In America, two business principles apply:
1. It is none of your business when shit hits the fan, and
2. It is never our fault.
goes unpunished.
I honestly can't understand the point of shooting the messenger here. Is it entirely to try to convince their customers (who are likely not very tech savvy) that they have nothing to worry about? I can understand the letter they sent out blaming the reporters for that, but to actually sue them doesn't make sense. Do they actually believe they can spin this to the FCC as the reporters going all James Bond to access files that were reasonably secured? Or is this just a lawyer who is racking up more billable hours, and his clients are too stupid to realize what a waste it is? Is this actually a roomful of executives saying "FUCK THOSE GUYS! Send the lawyers after them! That'll learn the press to google us!"
I realize these companies have made some seriously bad decisions, and dumb decisions by committee are even worse, but this makes no sense.
Call 'em hackers enough time, and people will be distracted by their alleged malice to the point where they forget or don't even believe anymore that the files were literally just out there for anyone to see. It's like leaving a $100 bill on the sidewalk and waiting to see who turns it in at the lost and found so you can call 'em a thief to distract from your own leaving it lying around.
In SOVIET RUSSIA... erm...NSA AMERICA, the Internet logs onto YOU!
...should be a course in Computer and Internet Obviousness (naughty words omitted to make it sound more official, fucking god dammit). And certified as passing this course should be a requirement to be a judge or lawyer in the US with a 6 month renewal term. Any lawyer not holding a certificate should be disbarred post haste and any judge should be removed from his/her seat post haste. Post haste. Haste.
You can dance if you want to.
It's deflection.
If they were "hacked" then the folks who's data was leaked blame the wily hackers. If they let it stand that the data was just freely available on the web, it's a liability to the telecoms involved; i.e. "it's not our fault, it's THOSE guys."
Solving Unix problems since 1989...
First of all, both these comapnies web sites are identical. Second of all, they look like some 14 year old put them together.
Look, this is just some sweatshop lawyer who wrote q $200 threatening letter. The threat has no value, and should be ignored.
If you want news from today, you have to come back tomorrow.
1. wget is just a means to automate. Would you type all the URLs manually?
2, 3, 4. As insecure as anybody else downloading it. They have no duty of care that publicly available data that shouldn't be publicly available is not publicly available.
5. A blurred screenshot allows plausible deniability. After all, the blurred bits could be anything. It could even be a completely different page blurred in Photoshop to smear the good name of these dickheads^W fine upstanding members of the community.
If they have a complete data dump, it is most likely someone else does as well. Someone who is more interested in profiting from shoddy practices.
"Wait. Something's happening. It's opening up! My God, it's full of apricots!"
He's parodying certain religious leaders who say this exact same shit about Florida, California, New York, or the US in general.
Go look up Poe's Law.