Slashdot Mirror


Clarificiation on the IP Address Security in Dropbox Case

Bennett Haselton writes A judge rules that a county has to turn over the IP addresses that were used to access a county mayor's Dropbox account, stating that there is no valid security-related reason why the IP addresses should be exempt from a public records request. I think the judge's conclusion about IP addresses was right, but the reasoning was flawed; here is a technically more correct argument that would have led to the same answer. Keep Reading to see what Bennett has to say about the case.

At issue was the list of IP addresses that had accessed the Dropbox account of Orange County Mayor Teresa Jacobs. A public interest group called Organize Now wanted to know whether the documents in her Dropbox account had been shared with outside parties, such as lobbyists, and filed a public records request to obtain the access logs. The county provided the logs with the IP addresses redacted, claiming that they were withheld for security reasons; Orange County asked a court to declare that there was no legitimate security-related reason for the IP addresses to be blacked out. On Monday, Judge Robert Egan ruled that the county had to release the unredacted version of the logs.

In the judge's ruling, he trivially rejected some arguments that the county had made, determining for example that IP addresses by themselves were not "data processing software" (duh). The trickier question was whether the IP address logs could be considered "information relating to security systems", and whether publishing the IP addresses in the logs could enable a security breach.

Judge Egan correctly wrote that all the IP addresses did was "identify specific computers used to access Dropbox" (actually, of course, computer IP addresses can change, and if the computer is behind a proxy server then it will be the proxy server's IP address that shows up in the log; but that's close enough, let's give it to him). He rejected the county's analogy to another case, in which a judge ruled that the city of Clearwater did not have to turn over the names and addresses of residents who had installed a particular alarm system; Judge Egan said that confidentiality in that case was more obviously justified, because there's no public interest in giving thieves a list of houses to avoid hitting.

However, in declaring that there was no good reason for the IP addresses to be redacted, Judge Egan wrote:

While the County has expressed a legitimate concern that disclosure of IP addresses would constitute an additional security threat because they would identify specific computers used to access Dropbox, which would then become potential targets for hacking, it also acknowledged that it already identifies 20,000-30,000 intrusion attempts daily and it has measures in place to deal with those attempts.

When Judge Egan says "it already identifies 20,000-30,000 intrusion attempts daily", it's not clear whether "it" refers to Dropbox, or the county's own computer system (presumably the latter, since 30,000 seems a bit low for Dropbox). But either way, the argument fails because the "measures in place" only refer to protection for the Dropbox servers and/or the county's own servers. If the mayor ever connects to Dropbox from her home computer, and the logs can be used to identify her home IP address, then the "measures in place" won't do anything to stop an attacker from trying to attack her home computer. And if an attacker can take control of her home computer, and her home computer is set up to log into Dropbox automatically, then the attacker can use her home computer to access the Dropbox files, and those accesses will look indistinguishable from legitimate accesses from the mayor herself.

In this scenario, the biggest obstacle to an attacker is that knowing the mayor's home IP address would normally not be enough information to take over her computer. Even if the attacker had knowledge of a security vulnerability in the operating system being used on the mayor's home machine, it's usually impossible for an outsider to connect directly to a user's machine, because the machines are behind wireless routers which are shared with other computers in the same house. (An attacker could first find a way to hack the security of the router, and re-program it to forward incoming Internet traffic to the mayor's computer, and then find a way to compromise the home computer -- but that's two security systems that have to be hacked independently, and every extra hurdle reduces the chances that you'll be able to clear all of them to pull off an attack.)

A much easier attack would be to try to get the mayor to view a web page from one of her computers -- either her home computer or her office computer, as long as it's one of the computers that she uses to access the Dropbox account -- and then try to infect that computer using code on the web page itself which exploits a security vulnerability in the web browser. (Web browser security vulnerabilities are quite common, compared to the far more rare security holes which allow you to take over a computer by sending traffic to its IP address.) To do that, all you need would be to reach the mayor directly, or talk to someone who would pass information on to her: "I'm a concerned constituent, and here's a web page that I've set up describing my plight and how the county government could help." Wait, scratch that: "I'm a concerned consituent, and here's a web page describing the dirt that I've dug up on your opponent."

And if the mayor does visit your web page, even if you don't succeed in infecting her computer or taking it over, at least now you've got her IP address.

So a better line of reasoning would have gone something like this:

"It's not inconceivable that someone could use the IP addresses in the logs to facilitate an attack, and anyway, the county's 'security measures' wouldn't do anything to prevent an attack against, say, the mayor's home computer. However, it would be much easier for an attacker to attempt an attack by other means (e.g. a browser vulnerability), and in any case it would not be hard for an attacker to find the mayor's IP address indirectly, without even resorting to any security breaches. So the disclosure of IP addresses has only a negligible effect on the odds of a break-in."

Run that through your standard judicial IWentToHarvard-izer, replacing a couple of random words with their longest equivalent in the thesaurus, and you've got a pretty solid legal opinion.

Then again, maybe some other Florida public servants are in more urgent need of training in how IP addresses work. After the judge's ruling, Rafael Mena, the mayor's Chief of Information Systems & Services, said in a statement:

"We don't agree with the decision. We are responsible for protecting crucial public health and safety infrastructure, including our 911 systems, our jail facilities, and providing clean drinking water to more than a half million residents. Internet Protocol (IP) addresses control everything from the cameras at the courthouse to the locks on the jail cells. We're also concerned about the security of the health records and financial information of thousands of citizens. Releasing IP addresses leaves organizations vulnerable to the type of security breaches that the public sees every day on the news."

Drinking water. OK, forget press releases for a second: If you were the head of security, and you asked your assistant head of security to evaluate the impact of releasing the IP addresses that had accessed the mayor's Dropbox account, and your assistant gave you a reply like the one above, what would you think? Would you put up with that nonsense from someone who worked for you?

Well, government security officials do work for us. The people of Orange County should tell Mr. Mena: If you want to try and bamboozle people with irrelevant factoids and scare them with veiled references to terrorist threats, go get a lucrative job in the private sector! As soon as you finish stocking up on botted water.

152 comments

  1. "Keep reading to see what Bennett has to say" by 93+Escort+Wagon · · Score: 5, Insightful

    Uh... no.

    --
    #DeleteChrome
    1. Re:"Keep reading to see what Bennett has to say" by war4peace · · Score: 2

      Don't you wanna read about "clarificiations"?

      --
      ...gis sdrawkcab (usually not responding to ACs; don't bother posting as AC)
    2. Re:"Keep reading to see what Bennett has to say" by Anonymous Coward · · Score: 1, Insightful

      If I had mod points, I'd mod up all 11 first posts telling Bennett to go fuck himself. I think this must be some kind of record.

      Slashdot readers, I want to thank you for your kind and enduring service to your community. You are all great citizens. Thank you very much. May your karma scores remain Excellent, may your trolls be well-received, and may your neckbeards grow long and silky. Thank you.

      CAPTCHA: decency (something BH lacks)

    3. Re:"Keep reading to see what Bennett has to say" by Anonymous Coward · · Score: 2, Insightful

      Tagging these stories as "nothanks"

    4. Re:"Keep reading to see what Bennett has to say" by Anonymous Coward · · Score: 0

      Genius idea. I'm with you!

    5. Re:"Keep reading to see what Bennett has to say" by Anonymous Coward · · Score: 0

      Spoiler: it ends with botted water.

    6. Re: "Keep reading to see what Bennett has to say" by Anonymous Coward · · Score: 1

      I'm confused. Is this the frequent contributor or another person of the same name? I need to know so I know who to trust and where to form my opinion on this issue

    7. Re:"Keep reading to see what Bennett has to say" by Anonymous Coward · · Score: 0
    8. Re:"Keep reading to see what Bennett has to say" by Anonymous Coward · · Score: 0
    9. Re:"Keep reading to see what Bennett has to say" by sexconker · · Score: 3, Informative

      Use this greasemonkey script to hide Bennett's shit from the main (and "older") pages. http://pastebin.com/RWCxT0jJ
      (I disable it once in a while to check for his shit so I can tell people about the script.)

    10. Re:"Keep reading to see what Bennett has to say" by grcumb · · Score: 1

      Don't you wanna read about "clarificiations"?

      Indeed. Now, most of you are out in the world seeking clarity. But, as long-time contributor Bennett Haselton writes, much more important than that is 'clarifice', the ability to explain truthiness without resorting to expertise or insight. Keep reading to see Bennett's clarification of how over two hundred years or jurisprudence can be usefully transposed onto decades-old technology....

      --
      Crumb's Corollary: Never bring a knife to a bun fight.
    11. Re:"Keep reading to see what Bennett has to say" by grcumb · · Score: 1

      ARRRGGGHHHHH.... CLARIFIC-I-ATION. I can't even spell it wrong when I WANT to!

      --
      Crumb's Corollary: Never bring a knife to a bun fight.
    12. Re:"Keep reading to see what Bennett has to say" by Anonymous Coward · · Score: 0
    13. Re:"Keep reading to see what Bennett has to say" by jimmetry · · Score: 0

      ""However, it would be much easier for an attacker to attempt an attack by other means (e.g. a browser vulnerability), and in any case it would not be hard for an attacker to find the mayor's IP address indirectly, without even resorting to any security breaches."

      Run that through your standard judicial IWentToHarvard-izer, replacing a couple of random words with their longest equivalent in the thesaurus, and you've got a pretty solid legal opinion."

      "well it's easy anyway so why not" is not a solid legal opinion.

    14. Re:"Keep reading to see what Bennett has to say" by Bite+The+Pillow · · Score: 1

      Too bad, you missed this.

      Run that through your standard judicial IWentToHarvard-izer, replacing a couple of random words with their longest equivalent in the thesaurus, and you've got a pretty solid legal opinion.

      Fuck a bag of shit in the morning. That's not how the legal system works. It was priceless. Ignorance in little parts pisses me right the feck off. But grand-scale ignorance, the kind that could gag a gigantosaurus, is fricken hilarious.

      I could stab a guy with a dictionary, watch him bleed out, and remove his brain, and when I say "You're still smarter than Bennett" he'd reply, "Who, they still let that cock on the internet?"

    15. Re:"Keep reading to see what Bennett has to say" by Fnord666 · · Score: 1

      Use this greasemonkey script to hide Bennett's shit from the main (and "older") pages. http://pastebin.com/RWCxT0jJ
      (I disable it once in a while to check for his shit so I can tell people about the script.)

      If we ever meet IRL I owe you at least one beer for this!!

      --
      'The tyrant will always find pretext for his tyranny.' - Aesop's Fables
    16. Re:"Keep reading to see what Bennett has to say" by Jane+Q.+Public · · Score: 1

      Use this greasemonkey script to hide Bennett's shit from the main (and "older") pages. http://pastebin.com/RWCxT0jJ (I disable it once in a while to check for his shit so I can tell people about the script.)

      Give Haselton a break. He has done us all not just one but many public services.

      Having said that... let's be honest: sometimes Haselton expounds on things that are very clearly not in his area of expertise, and certain Slashdot editors (for that is exactly what they are) probably give him too much "air time" on Slashdot. Especially, it seems, when he is expounding on something that is not in his area of expertise.

      But while this one is rather long-winded, it IS an issue everyone here should pay attention to, regardless of whether we happen to agree with Haselton and his analysis.

      If Haselton bores you, blame the editor(s) for putting him up too often, in regard to things he is hardly an acknowleged authority.

    17. Re:"Keep reading to see what Bennett has to say" by Jane+Q.+Public · · Score: 1

      Pardon me for hijacking this higher position, but a serious pet peeve has been triggered.

      Hey, Bennett, or samzenpus, or whoever did it:

      You do NOT put your own hypotheticals in quotes. Got it? Quotes are used for QUOTING OTHER PEOPLE. That's their purpose. Learn it. Use it. And it's usually best if readers can tell who is being quoted, even if only via context.

      Thank you very much.

    18. Re:"Keep reading to see what Bennett has to say" by Hognoxious · · Score: 1

      sometimes Haselton expounds on things that are very clearly not in his area of expertise

      You're not too bad at understatement.

      --
      Confucius say, "Find worm in apple - bad. Find half a worm - worse."
    19. Re:"Keep reading to see what Bennett has to say" by dave420 · · Score: 1

      Oh dear oh dear. Yes, quotation marks can be used to show quoted content, but they can also be used to highlight euphemisms, slang, sarcasm etc. They can also be used to highlight the using of a reference (to a work).

      Your pet peeve is not founded in reality, much like the majority of the drivel you see fit to repeatedly spew forth in the midst of otherwise decent discussions.

      Get a grip - you really need some help.

    20. Re:"Keep reading to see what Bennett has to say" by dave420 · · Score: 1

      Wait, didn't you just berate someone for using quotes when not quoting someone? You really are not very good at this, are you?

    21. Re:"Keep reading to see what Bennett has to say" by war4peace · · Score: 1

      I had to be doubly-extra.careful when typing the twisted word myself, I feel your pain bro.

      --
      ...gis sdrawkcab (usually not responding to ACs; don't bother posting as AC)
    22. Re:"Keep reading to see what Bennett has to say" by sexconker · · Score: 1

      Noticed that too. Hilarious.

    23. Re:"Keep reading to see what Bennett has to say" by dnebin · · Score: 1

      Sign the petition to get rid of bennett haselton: http://petitions.moveon.org/si...

  2. Technically correct?? by Anonymous Coward · · Score: 1

    That's the best kind of correct!

    1. Re:Technically correct?? by Noah+Haders · · Score: 1

      I think the issue here is not with security but with privacy. for many people the ip address is PII (personally identifiable information). My hope ip is static and only used by me. so any records showing my ip address are equivalent to showing my home address. If we're going to protect people's PII we should be protecting IP addresses too.

    2. Re:Technically correct?? by JackieBrown · · Score: 2

      I thought we argued on all the downloading stories that an IP is not an identifier?

    3. Re:Technically correct?? by fustakrakich · · Score: 1

      If they are logged and stored, they are impossible to protect without destroying the records. The best defense of privacy comes from spoofing. Unfortunate, but that's the way they want to play it.

      --
      “He’s not deformed, he’s just drunk!”
    4. Re:Technically correct?? by Anonymous Coward · · Score: 0

      I think the issue here is not with security but with privacy. for many people the ip address is PII (personally identifiable information). My hope ip is static and only used by me. so any records showing my ip address are equivalent to showing my home address. If we're going to protect people's PII we should be protecting IP addresses too.

      Well, sue the county for violating your privacy, there's laws for that, and make the judge declare the earlier ruling null and void.
      It won't do much except set a precedent in favor of privacy, and precedents favoring privacy are a good thing.

    5. Re:Technically correct?? by bennetthaselton · · Score: 0

      That's interesting. Possible counter-points: (1) It could be argued that if the mayor accessed her work Dropbox account from her home IP address, then that introduces her home IP address into the public record, and if she didn't want that, she shouldn't have accessed it from home. (2) I don't think revealing a person's IP address is quite as bad as revealing a person's home address, because there are "attacks" you can mount against someone once you know their home address (e.g. robbing or vandalizing their house) but the point of the article is that there's relatively little you can do to someone just by knowing their IP address. (3) As I noted, someone could also get the mayor's home IP address anyway just by finding a way to contact her and telling her to visit a certain website.

      I don't think it achieves anything to group all of someone's personal information under a heading like "PII" with the implication that it should all be treated the same way. Some things deserve more privacy protection than others, depending on what harmful things someone would be able to *do* with that information.

    6. Re:Technically correct?? by Anonymous Coward · · Score: 0

      You post with an automatic -1. That's fucking awesome. That made my day.

      Please continue to die in a fire.

    7. Re:Technically correct?? by dgatwood · · Score: 2

      For home users, it is not a useful identifier because it usually changes regularly. For government users and business users, it is a fairly robust identifier, because most of those folks have static IPs (or at least fixed IPs assigned by a DHCP server).

      Of course, there's not a 1:1 mapping between user and IP. So it would be more accurate to describe it as familially identifying information.

      --

      Check out my sci-fi/humor trilogy at PatriotsBooks.

    8. Re:Technically correct?? by Anonymous Coward · · Score: 0

      It absolutely is an identifier. It's just not a reliable or (necessarily) persistent identifier.

      This means that it could give information about who was involved, but you can't use it to say they were definitely involved.

      So, the copyright folks using it as proof of involvement is flawed; but, giving the information away could still infringe on privacy.

    9. Re:Technically correct?? by weiserfireman · · Score: 1

      IMO, IP Addresses of visitors to the Drop Box account of the Mayor, should be no more protected than the Mayor's appointment book.

      It is a list of visitors. That is all it is. And if we think the Mayor is being lobbied improperly, we should be able to have that information.

    10. Re:Technically correct?? by Noah+Haders · · Score: 1

      what are you talking about? just redact the records. Records are often redacted to protect sensitive information for FOIA requests.

    11. Re:Technically correct?? by gnasher719 · · Score: 1

      I think the issue here is not with security but with privacy. for many people the ip address is PII (personally identifiable information). My hope ip is static and only used by me. so any records showing my ip address are equivalent to showing my home address. If we're going to protect people's PII we should be protecting IP addresses too.

      But that was the idea. The intent was to find out who accessed a dropbox account. That information wasn't available directly, but apparently the IP addresses were available. If someone has a legitimate reason to want to find the person, then there is no reason not to hand over IP addresses.

    12. Re:Technically correct?? by Noah+Haders · · Score: 1

      that's fine perhaps, my point is that ip addresses need to be treated with the same sensitivity as names and mailing addresses. To balance privacy against disclosure, there are rules for when names and addresses are withheld and when they are released. These rules should also apply to IP addresses.

    13. Re:Technically correct?? by lucm · · Score: 1

      Of course, there's not a 1:1 mapping between user and IP. So it would be more accurate to describe it as familially identifying information.

      Your mom's IP is so big, she needs two routing tables.

      --
      lucm, indeed.
    14. Re:Technically correct?? by muridae · · Score: 1

      And, if the mayor had been holding private meetings with a sign-in ledger, and a public action group wanted a copy of that to see if the mayor was meeting with known lobbyists, a judge would have turned over the "personally identifiable information" of a list of names. The mayor thought they could outsmart the system by having the meeting online, and claiming "security" or something to cover what is supposed to be public information to begin with.

      TL;DR: if you meet with a government official, your name (maybe job) is on public records. That is not protected information in a democracy.

    15. Re:Technically correct?? by fustakrakich · · Score: 1

      Please, forget that I even exist.... Excuse me for bumping into you. I'm playing a different game that doesn't seem to apply here.. Maybe tomorrow, when I'm sober...

      --
      “He’s not deformed, he’s just drunk!”
    16. Re:Technically correct?? by Anonymous Coward · · Score: 0

      There are in fact situations where absolutely everybody is wrong. The judge was wrong in his ruling, yet it is understandable why the ruling was made that way. The IT chief was alarmist, stupid, and pretty sloppy in wording, and yet the notion of not broadcasting the structure of one's network isn't really a bad idea even if it is kind of irrelevant in this particular case.

      The thing here is that public records law in Florida is more often used to abuse private citizens and violate their privacy than it is to hold government officials accountable for anything. For every case like this, hundreds of thousands of people get their personal information published online for all to see for the innocuous acts of buying a home or purchasing a car, and God help you if you get a traffic ticket because your mailbox will be stuffed full of offers from traffic schools, attorneys, etc. Other states manage to not publish personal information on their citizens in alarming volumes and yet manage to deal with traffic cases, real estate transactions, etc.

      This case is a bit of an outlier. It is a perfect example of how public records laws SHOULD be used, and yet it makes for horrible precedent precisely because the use of such laws in this particular manner is a rarity. The simple fact is that regular disinterested parties and normal citizens are probably not accessing the Mayor's dropbox account. It is that fact that protects the privacy of innocent parties here, not the law. Put another way, what if this request was for the webserver logs of machines hosting information for help on domestic violence, or certain politically sensitive health issues, or whatever? Think marketers, lawyers, and insurers might want that information someday? That's the sort of thing hyper-open records laws and rulings like this allow.

      Now seeing as how there's no law requiring government agencies (at least in Florida) to retain IP logs at all, the easiest solution on the part of IT admins would be to simply turn that off. As any IT pro can attest, doing so significantly hinders certain necessary capabilities in security and system troubleshooting, but the calculus is going to be can we live with those things vs. the annoyance of dealing with stuff like this? Can't do that with Dropbox? Well, there's a good argument for not using consumer grade cloud anything for business use, but that's another debate.

      Bottom line is that this stuff is a double edged sword that absolutely cuts both ways.

  3. This is your big draw? by Anonymous Coward · · Score: 0

    Keep Reading to see what Bennett has to say about the case.

    And you expect this to increase page hits? Does the Spock in your universe have a beard?

    1. Re:This is your big draw? by jones_supa · · Score: 1

      They know that it increases page hits when everyone comes to complain about Bennett.

    2. Re:This is your big draw? by NormalVisual · · Score: 1

      Does the Spock in your universe have a beard?

      Closest thing to useful info associated with one of Bennett's posts. Spock's Beard is an awesome band.

      --
      Please stand clear of the doors, por favor mantenganse alejado de las puertas
  4. Fuck This Shit by weilawei · · Score: 4, Insightful

    Please stop using the front page as your personal blog. May you <insert-untimely-thing-here> in a <insert-energetic-thing-here>.

    1. Re:Fuck This Shit by Anonymous Coward · · Score: 0
    2. Re:Fuck This Shit by diamondmagic · · Score: 1

      /. has always been a personal blog, it just happens to have a lot of links to other people's articles.

      Did you forget, or do I need to engage on a UID pissing match?

    3. Re:Fuck This Shit by Anonymous Coward · · Score: 0

      Are you seriously comparing Rob Malda with Bennett Cockface Fuckshit?

    4. Re:Fuck This Shit by dnebin · · Score: 1

      Petition to drop bennett: http://petitions.moveon.org/si...

  5. Probably not the first... by Anonymous Coward · · Score: 0, Troll

    but... go to hell Bennet. Go to hell Slashdot. Please stop with this shit.

    1. Re:Probably not the first... by Anonymous Coward · · Score: 0

      Seconded

    2. Re:Probably not the first... by Anonymous Coward · · Score: 0
    3. Re:Probably not the first... by Anonymous Coward · · Score: 0
  6. Dear Editors by Anonymous Coward · · Score: 0

    Please please please stop posting Bennett Haselton's crap

    1. Re:Dear Editors by Anonymous Coward · · Score: 0
  7. fuck off bennett by Anonymous Coward · · Score: 2, Insightful

    i started reading, looked interesting, spotted the name - goddam trolled again. fuck you bennett, why the fuck are you blogging here you wet blanket soppy mug squidgy brained muthafucker

    1. Re:fuck off bennett by Anonymous Coward · · Score: 0
  8. Bennett please MARRY ME! I turn GAY for you! by Anonymous Coward · · Score: 0

    I am on my one remaining knee.

    1. Re:Bennett please MARRY ME! I turn GAY for you! by Anonymous Coward · · Score: 0
  9. Why is this bullshit on slashdot? by Anonymous Coward · · Score: 0

    I mean that, why? This is an incredibly crappy post. As is anything Bennet writes... The readers of this site avidly hate Bennet. Why do you keep posting his crap?

    1. Re:Why is this bullshit on slashdot? by Anonymous Coward · · Score: 0
  10. First.... um... by flopsquad · · Score: 3

    ...oh it's Bennett. Anyone else want to post here first? Anyone? Maybe you're all still reading the 28 paragraph TFS?

    --
    Nothing posted to /. has ever been legal advice, including this.
    1. Re:First.... um... by Anonymous Coward · · Score: 0
    2. Re:First.... um... by dysmal · · Score: 1

      I wish i had mod points so that i could mod this up!

      BTW, Benny needs to go find a nice quiet field where he can ponder all of his BS he wants to "submit" to Dice... er.... /. and then take a hammer and hit himself in the face. A lot.

      (NOT posted as AC)

  11. Clarificiation? Learn to fucking spell. by Anonymous Coward · · Score: 0

    Please learn to fucking spell before you post. "Clarificiation"? I mean fuuuck. I don't expect much from Sammypuss, but I expect Bennet Hasselhoff, the great and glorious leader of GayWAD to do better!

    GayWAD! GayWAD! GayWAD!

    You know what, screw it. Just piss off already.

  12. Need a logo by Anonymous Coward · · Score: 1

    We need a logo for posts that are just about swearing at Bennett. Dunce cap?

    1. Re:Need a logo by flopsquad · · Score: 2

      We need a logo for posts that are just about swearing at Bennett. Dunce cap?

      AC, that's a capital idea! I like dunce cap, but allow me to propose some alternative icons for Bennett articles:
      - A hot air balloon
      - A whoopie cushion
      - The smiling poop emoticon
      - Rageface
      - That truck window sticker of Calvin peeing, but he's peeing on TFS

      That's just a few off the top of my head. Feel free to add suggestions!

      --
      Nothing posted to /. has ever been legal advice, including this.
    2. Re:Need a logo by Anonymous Coward · · Score: 0

      I'd like to nominate some variation of this image. Please feel free to photoslop your own "praise" for Bennet the Haselcock.

    3. Re:Need a logo by flopsquad · · Score: 1

      Love it

      --
      Nothing posted to /. has ever been legal advice, including this.
    4. Re:Need a logo by Anonymous Coward · · Score: 0
    5. Re:Need a logo by Anonymous Coward · · Score: 0
    6. Re:Need a logo by Anonymous Coward · · Score: 0
    7. Re:Need a logo by AthanasiusKircher · · Score: 1

      How about an image of shoveling a pile of poop, maybe something like this?

  13. No. Go away, babblemouth by Obfuscant · · Score: 2

    Judge Egan correctly wrote that all the IP addresses did was "identify specific computers used to access Dropbox" (actually, of course, computer IP addresses can change, and if the computer is behind a proxy server then it will be the proxy server's IP address that shows up in the log; but that's close enough, let's give it to him).

    No, moron, let's not "give it to him", unless "it" refers to "a firm tongue lashing for getting it wrong wrong wrong." He's just created exactly the precedent that you don't want created: "the IP address identifies specific computers". It's not "close enough" when **AA claims it in court, it's not "close enough" when a judge says it regarding a FOIA case.

    1. Re:No. Go away, babblemouth by bennetthaselton · · Score: 0

      I think it has to be interpreted in context; what he presumably means here is that the IP address can be used to help identify specific computers (with a certain degree of probability, and maybe depending on whether the ISP has retained customer logs), but emphasizes that that's all it can be used for, and knowing the IP address does not make it easier for an attacker to breach the system's security, so it wasn't a valid reason to reject the FOIA request.

    2. Re:No. Go away, babblemouth by Anonymous Coward · · Score: 0

      Thank you for your interest in joining the Gay Wigger Association of DICE* (GayWAD)! GayWADs worldwide are happy that you'd like to become part of our

      constantly enlarging member ship (come sail away 8====D~)

      Unlike other geek fraternities that you might have heard about, GayWAD accepts members of all races, creeds, and colors. We don't even have a technical inclination requirement. As our founders stated in the Annals of GayWAD, Chapter 1: "You don't have to be a geek, as long as you like it Greek." They were, of course, referring to the penis in anus style of sexual relations. Don't despair, as attaining full fabulous lifetime status in GayWAD is easy. The only prerequisites for membership in Gay Wigger Association of DICE* are that you meet all of the following conditions:

              1. Ownership of penis, anus, or both

      To submit your Gay Wigger Association of DICE* Membership Application, simply do nothing. Congratulations, you're now a GayWAD!

      If you require a specific membership number for purposes such as framing, docking, or prestigious inclusion upon your business cards and resume, please take down this number: 69.

      Optionally, you may complete the following survey by replying to this post, indicating affirmative responses with an X in each appropriate box:

      GayWAD Membership Survey (OPTIONAL)

      [ ] I am gay
      [ ] I am a wigger
      [ ] I have used SLASHDOT BETA to find a sex partner

      After completion of this optional survey, your Slashdot post ID shall serve as your unique Gay Wigger Association of DICE* membership ID.

      Your GayWAD membership kit** is on its way.

      * GayWAD is neither affiliated with nor endorsed by DICE.COM.

      ** GayWAD membership kit no longer includes HIV self-test catheter.

      *** President Bennet Haselton reminds you to always practice unsafe sex.

  14. Interesting... by Anonymous Coward · · Score: 0

    Who the hell are you?

  15. Please post a Message from Kabul by Anonymous Coward · · Score: 0

    So we can be over with this shit, JonKatz2.0

    http://tech.slashdot.org/story/01/11/17/204207/message-from-kabul

  16. Relevance? by pz · · Score: 4, Insightful

    Someone, who has no apparent power, wants to correct a judge. Just because they think they're right and the judge had inaccurate reasoning, despite coming to the same conclusion. (There's a good XKCD comic on the subject of correcting people in the Internet.) The critic's opinion will carry no legal weight. The same critic has a history of proposing long-winded, half-baked ideas to correct issues he sees with various societal inefficiencies that have gone no-where. I'm not going to waste my time.

    Would someone be so kind as to please remind me how we can block posts from a given author?

    --

    Put my fist through my alarm clock with its ding-dong death inside my ear. - The Blackjacks.
    1. Re:Relevance? by Reason58 · · Score: 1

      "Would someone be so kind as to please remind me how we can block posts from a given author?"

      Bennett's name is specifically not a link, so that you cannot author block him.

  17. I don't get it... by Ecuador · · Score: 4, Insightful

    Every slashdot reader and their mother, to say nothing of the dog, hate reading these inane Haselton blog posts, why do they keep being posted? I mean most of the posts on these "stories" are about how stupid the "story" is, showing it is probably the only Slashdot feature that is more annoying than the beta, and yet they keep on coming... Is there some sort of strong affiliation? Is slashdot simply paid by this Bennett guy? If it is, I would probably be more understanding - I know how the world works - just tell us it is so and we will move on...

    --
    Violence is the last refuge of the incompetent. Polar Scope Align for iOS
    1. Re:I don't get it... by Anonymous Coward · · Score: 0
    2. Re:I don't get it... by flopsquad · · Score: 1

      1) I think Dice gets ad revenue based on page views, and... maybe posts per article factors in?

      2) They know when they put up some dubious Bennett novella, we'll all swoop in and post "What the fuck?!"

      3) ???

      4) Profit?

      --
      Nothing posted to /. has ever been legal advice, including this.
    3. Re:I don't get it... by Anonymous Coward · · Score: 1

      In following proper /. tradition, I skip right over these "articles" and go straight to the comments. And I must say that the Bennett bashing is usually pretty funny.

      As much as I would like to see him gone, part of me would miss reading the responses to his "articles."

    4. Re:I don't get it... by dnebin · · Score: 1
  18. It's clarificated now by Anonymous Coward · · Score: 0

    That was an interesting clarificiation.

  19. fuck off. by nedlohs · · Score: 1

    Filter error: You can type more than that for your comment.

  20. Good call. by khasim · · Score: 4, Insightful

    Bennett Haselton spends 1341 words on what should be a 3 sentence summary.

    If you want to know whether X accessed the mayor's dropbox (why is the mayor using dropbox in the first place) then you need to
    a. get the IP addresses & times that they were used to access it
    b. match the IP addresses to ISP user accounts at those times

    Now, if the judge does not support you, personally, having access to the IP addresses then the judge can appoint a disinterested 3rd party do handle it. You are only interested in the ISP user accounts and whether those belong to lobbyists.

    There! Done! And no need for Bennett Haselton's weird tangent on cracking via web browsers.

    1. Re:Good call. by Anonymous Coward · · Score: 0
  21. Question by Anonymous Coward · · Score: 1

    Sorry to interrupt the usual "hate on Bennett" fest, but I read the article and have a question.

    In the judge's ruling, he trivially rejected some arguments that the county had made, determining for example that IP addresses by themselves were not "data processing software" (duh).

    And if the mayor does visit your web page, even if you don't succeed in infecting her computer or taking it over, at least now you've got her IP address.

    Alright, so with that in mind, lets say your at home, laying in bed, kinda half asleep. It's dark, but you glance over and see something shimmering near the trash can you keep across the room. You kinda wake up enough to look closely at it and notice movement. Paniced you flip on your bedside lamp and are horrified to see spiders, lots of spiders, just pouring out of the trashcan. I'm not talking like one of those little nest things breaks open, I'm talking like a carpet of spiders, way more then should physically be able to occupy the space in the trash can, just pouring out covering the whole floor. You grab your blanket for what protection it provides and shimmy into the corner of your bed as they begin crawling up the frame. Just as you think you are about to completely lose your mind, they stop. In the sea of spiders covering your floor, walls, and half of your bed, you notice one spider that stands out. Slightly larger and a bit shiny, it makes its way through the crowd of its brothers and sisters toward you. Stopping just at the edge of your bed sheet it looks straight at you and asks a single question.

    What do you think that question would be?

    1. Re:Question by Anonymous Coward · · Score: 0

      "Do you taste good with ketchup?"

    2. Re:Question by Anonymous Coward · · Score: 0

      What do you think that question would be?

      "Are you or have you ever been Bennett Haselton? Cause we're here to put a stop to that."

      One could only hope.

    3. Re:Question by Anonymous Coward · · Score: 0
    4. Re:Question by Ian+A.+Shill · · Score: 1

      "What would Bennett Haselton do?"

      --
      For hire.
  22. Fuck Benecock by Anonymous Coward · · Score: 0

    I will trade you my firstborn pygmy possum to pull this proactively pissy prose from the front page of Slashdot.

    In other news, can we just ban Bennet? Can't we report every post he makes, tag every story he posts as "nothanks", and just generally downmod him until he can't post more than twice a day?

    Please die.

    1. Re:Fuck Benecock by Anonymous Coward · · Score: 0
  23. Chief of Information Systems & Services knows by Teun · · Score: 2
    The interesting part of this story is this:

    Rafael Mena, the mayor's Chief of Information Systems & Services, said in a statement:

    Because what this Chief dipshit saw was totally wrong. And even our favourite blogger noticed it.

    --
    "The likes of Facebook and WhatsApp are free to those whose privacy is of zero value."
  24. Judge Bennett issues a Concurring Opinion by Midnight_Falcon · · Score: 1

    ...and no one cares. I think we should however appeal to some sort of internet tribunal as to whether wasting so much space on this, on such a high traffic website like Slashdot, warrants a sentence of an electronic gag device.

    1. Re:Judge Bennett issues a Concurring Opinion by Anonymous Coward · · Score: 1

      You can do your part by tagging Bennet submissions as "nothanks" and downmodding any posts of his you might encounter.

      Thank you for your service, loyal Slashdot newbie.

    2. Re:Judge Bennett issues a Concurring Opinion by Anonymous Coward · · Score: 0
    3. Re:Judge Bennett issues a Concurring Opinion by Anonymous Coward · · Score: 0
    4. Re:Judge Bennett issues a Concurring Opinion by Anonymous Coward · · Score: 0

      high traffic website

      Slashdot

      lolwut?

  25. No more! by Anonymous Coward · · Score: 0

    Keep Reading to see what Bennett has to say

    Nope. I guess I've already learned my lesson. The only reason I clicked into this story was to add my complaint to the list of comments. Bennett's posts have too much of a track record for inferiority. I join those who do not want to see that name on the main page.
    If articles from Bennett must be included, may they be a sub-board or default-collapsed or whatever.
    Posting Bennett articles generates additional complaints.

    1. Re:No more! by Anonymous Coward · · Score: 0
  26. A plan for Bennett by Okian+Warrior · · Score: 3, Interesting

    If Bennett is so completely unwanted on this blog, why don't we do something about it?

    In the manner of the fine people at 4chan, suppose we referred to Bennett in the past tense - as if he had passed away. Make all of our responses polite and sincere, but with the assumption that he is no longer with us.

    Here's the kicker: the internet works by consensus. If there's an abundance of commentary referring to him in the past tense, it'll get picked up and echoed everywhere, possibly by Wikipedia. I don't know what the full ramifications would be, but hopefully it will play hob with his attempts to get traction on the net. Anyone who googles for him by name or things he has said will get the impression that he's unavailable for comment, interviews, and possibly employment.

    Of course, we need to give Bennett fair warning, so I propose the following:

    Starting with the next Bennett Haselton article on Slashdot that's more than 2 short paragraphs, we start referring to Bennett in the past tense - as if he had passed away. We're going to start a new internet meme.

    Pleading, complaining, and asking has had no effect and we've certainly done due diligence.

    It's time to take action.

    1. Re:A plan for Bennett by Anonymous Coward · · Score: 0
    2. Re: A plan for Bennett by Anonymous Coward · · Score: 0

      The best action to take is to reduce page views, comments, etc. Obscurity and eventual complete irrelevance should be the goal. Otherwise, the crap keeps coming. Just look at the number of comments regarding the author.

    3. Re:A plan for Bennett by sexconker · · Score: 2

      If Bennett is so completely unwanted on this blog, why don't we do something about it?

      Load this user script into greasemonkey - http://pastebin.com/RWCxT0jJ .
      Never see Bennett's shit on the main page (or "older") pages again.

      (I disable it once in a while to look for his shit so I can tell people about this simple script.)

    4. Re:A plan for Bennett by redmid17 · · Score: 1

      Not that I disagree with jettisoning him, but this is a stupid fucking idea.

    5. Re:A plan for Bennett by Anonymous Coward · · Score: 0
    6. Re:A plan for Bennett by Anonymous Coward · · Score: 0

      Non-action is the best action. If you ignore his posts and stop giving Slashdot page hits when he posts, then eventually, they'll realize there's no money to be made by allowing him to endlessly flog is vacuous, meandering posts on here.

      Don't post, don't comment, and don't mention him: ignore him, and eventually, there will be no point in allowing him to continue to post.

    7. Re:A plan for Bennett by Anonymous Coward · · Score: 0

      It's a shame that we'll never be able to hear what Bennett would have said about this plan. ;-(

    8. Re:A plan for Bennett by dave420 · · Score: 1

      Maybe also berate anyone posting under the name "bennetthaselton" or derivatives for besmirching the fine reputation of the deceased... That should effectively quell any dissent from a certain interested party without breaking character.

    9. Re:A plan for Bennett by dnebin · · Score: 1

      Check out the petition: http://petitions.moveon.org/si...

  27. Too funny by Anonymous Coward · · Score: 0

    The author draws more attention than the subject.

    On that note, I'm Godwinng this fucker right now:

    All propaganda has to be popular and has to accommodate itself to the comprehension of the least intelligent of those whom it seeks to reach.

    So there! PFFFT! I fart in your general direction..

  28. Why don't you idiots bothering B. Haselton by Anonymous Coward · · Score: 0

    Fuck right off, ok? We're not here to listen to your bullshit, assholes!

    1. Re:Why don't you idiots bothering B. Haselton by flopsquad · · Score: 1

      Nice try, Bennett! But wasn't it you bothering us by posting this?

      --
      Nothing posted to /. has ever been legal advice, including this.
    2. Re:Why don't you idiots bothering B. Haselton by Anonymous Coward · · Score: 0

      Your problem's you can't read: We told you to fuck off you 2" dick little douche. So fuck off.

    3. Re:Why don't you idiots bothering B. Haselton by Anonymous Coward · · Score: 0

      Who's "we"? Schizo much?

    4. Re:Why don't you idiots bothering B. Haselton by Anonymous Coward · · Score: 0

      What's it like having a 2" dick, being utterly useless, unable to make it even as a nerd? That's you, after all! A dickless fool.

    5. Re:Why don't you idiots bothering B. Haselton by Anonymous Coward · · Score: 0

      Hahahahahahaha, good one

    6. Re:Why don't you idiots bothering B. Haselton by Anonymous Coward · · Score: 0

      So just a small counter arguement. We aren't bothering B. Haselton, we have politley asked /. to stop posting his stories but the editors don't seem to want ot listen to their regular readers. So now we have moved onto new and more amusing ways of getting our point across that we don't want to see B. Haselton stories posted on /. If we posted "get rid of B Haselton" in other stories then you could correctly state that we were bothering B Hasleton but since we only respond negatively to B Haselton when he is allowed to post his drivel then we aren't bothering him ....he is bothering us and refuses to alter his behaviour.

      Sincerely,

      A large portion of the /. readership

  29. I've tried... by Zontar+The+Mindless · · Score: 1

    But I... can... no longer... resist... the tide.

    Very well. This article sucks. Most of Bennett's articles mostly suck.

    Where do I pick up my bucket of tar and feathers?

    --
    Il n'y a pas de Planet B.
    1. Re:I've tried... by Anonymous Coward · · Score: 0

      Where do I pick up my bucket of tar and feathers?

      You can start with the digital equivalent by tagging his stories as "nothanks" and downmodding any posts of his you come across.

      Thank you for your longstanding service to your community!

    2. Re:I've tried... by Anonymous Coward · · Score: 0
    3. Re:I've tried... by Anonymous Coward · · Score: 0
  30. Presumption of innocence vs privacy issues by denzacar · · Score: 1

    IP is not an ACCURATE ENOUGH identifier to send you to jail.
    Sorta the way your car's lenience plates alone would not be good enough for such a purpose.
    It must be proven beyond doubt that YOU were the one driving the car that ran over Justin Bieber.

    But it is accurate enough for someone to come to the physical address associated with IP at that time and toss a Molotov cocktail through the window to send you a message that they don't like your comments on the "Beliebers" forum.

    Hence, privacy issues.

    --
    Mit der Dummheit kämpfen Götter selbst vergebens
    1. Re:Presumption of innocence vs privacy issues by dysmal · · Score: 1

      Unfortunately (in the US) your IP address is more than enough to prove your guilt if the accusing parties happen to be the RIAA/MPAA

    2. Re: Presumption of innocence vs privacy issues by Anonymous Coward · · Score: 0

      Unless you're lucky enough to live in one of the judicial districts (like S Dist. GA) where there is literally no way a judge will hand off a subpoena to an ISP for IP addresses in a civil matter.

      The best thing to ever happen to pirates was the first few suits being filed by pornographers overstating their cases and abusing people in negotiations

  31. The XKCD in question by sconeu · · Score: 2

    It's "Duty Calls". http://xkcd.com/386.

    --
    General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
  32. Not sufficient for prosecution. by khasim · · Score: 1

    I thought we argued on all the downloading stories that an IP is not an identifier?

    It is not sufficient for prosecution.

    First off, an IP address can be re-assigned. So you'd need an IP address and date/time to be able to link it to a specific ISP account.

    Each account can have multiple machines behind it that may or may not belong to that account (depending upon the security of their wireless network for example or whether any have been cracked already).

    So an IP address is not sufficient for prosecution BUT it can be a personal privacy issue.

  33. Bennett go home by MagicM · · Score: 1

    Bennett Haselton needs to go away.

    I love reading the comments on Bennett's posts, though. Makes me miss the old Microsoft-hate and vi-vs-emacs comments. Now everything is all level-headed +1 Informative. Bah.

    1. Re:Bennett go home by Anonymous Coward · · Score: 0
  34. You truly are a flop (in life) by Anonymous Coward · · Score: 0

    OOoooo, look @ the wannabe clever little homo fuck flopsquad *trying* to "play smart". Ever wonder why you're such a loser? Don't. Your entire life and attitude show you're just a nerd loser fuckwad that skulks in the shadows and plays wiseguy online. Have a nice life (in poverty), ya little irrelevant fuckwad.

    1. Re:You truly are a flop (in life) by Anonymous Coward · · Score: 0

      Pathetic. Troll Score: -1

    2. Re:You truly are a flop (in life) by Anonymous Coward · · Score: 0

      Truth hurt, flopsquad? Yes sir, it did. You named yourself aptly: You're a flop (in all things and you know it).

  35. We = all of /. (not you + your sockpuppets) by Anonymous Coward · · Score: 0

    Lmao: The nerd worm's STILL *trying* to "play smart". Pity you don't realize what a waste you are.

  36. R O T F L M A O by Anonymous Coward · · Score: 0

    Perfect! Judging by the ac replies after it you got to that little worm douche flopdick.

  37. You've got no power, pussy by Anonymous Coward · · Score: 0
  38. Bennett is giving legal opinions now?? by Slashdot+Parent · · Score: 1

    Did Bennett suddenly earn his JD and take his oath? If not, then he can kindly shut the fuck up.

    --
    They don't grade fathers, but if your daughter's a stripper, you fucked up. --Chris Rock
  39. For some better information on this... by Anonymous Coward · · Score: 0

    Good grief. I'm a resident of Orange County Florida. So I actually read the "summary" since I was curious.

    This has been all over the local newspaper lately. The upshot is that like many places, Florida has a public records law. The law has a cute name : "government in the sunshine". The county is storing documents in a Dropbox account. A citizens group is concerned that lobbyists may have access to the account and may be hiding some things in there from the public. So the citizens group wants to know who has accessed the account.

    If you want to read a lot more on this, don't read the summary, read these newspaper articles:

    Orlando Sentinel 9/26/2014

    Orlando Sentinel 11/12/2014

    Orlando Sentinel 11/24/2014

  40. Bennett's power by Anonymous Coward · · Score: 0

    It would be really nice if Bennett Haselton, who already has a Slashdot account, decided to make a post regarding his position of power on Slashdot. He can't possibly be ignorant of his impression by the readers - he knows how he's perceived, and despite the negative reactions to his postings he continues to make long-winded posts as if large essays are more persuasive than a few simple, clear, easy to digest sentences.

    If he explained how he came to have such an elevated position of posting power on Slashdot, it'd at least explain a few things.

    1. Re: Bennett's power by Anonymous Coward · · Score: 0

      I don't know, the way he writes is similar to a lot of people that have very high self-importance and delusions of grandeur.

      He doesn't seem like the type to read negative comments and think, "damn I am disliked." He seems like he would be completely oblivious to it even if you hit him with a bat in the face and said, "YOUR ARTICLES SUCK AND NOBODY LIKES YOU, PLEASE STOP."

      He would probably think, "ah, they just don't get it" at the most. And then keep on posting.

  41. The Slashdot blogging platform by ZipK · · Score: 2

    Now that Slashdot's blog feature is up and running, I can't wait for for something that lets Bennett pin interesting pictures to the front page!

  42. Howabout No by Anonymous Coward · · Score: 0

    tl;dr - Fuck you, Bennett. Nobody likes you, your submissions are long-winded while saying nothing, and you are a cancer on the already diseased pustule that is Slashdot. Stop trying to turn it into your personal blog and go languish on WordPress with all the other wannabe journalists.

  43. Why I read this article by NormalVisual · · Score: 3, Interesting

    I have little respect for Bennett's excessive, often not carefully considered, and mostly useless prose, so I don't come to Bennett threads to actually read what spews forth from his keyboard. I read them because I find the new and different ways he gets panned by the Slashdot readership to be entertaining. He's like the Slashdot Punching Bag - you punch him, and he invariably swings back again a little later for more.

    --
    Please stand clear of the doors, por favor mantenganse alejado de las puertas
    1. Re:Why I read this article by Anonymous Coward · · Score: 0

      I find it more than somewhat amusing that his karma is now so bad that his comments default to -1.

      He has essentially attained troll status!

      I'd still love for someone to explain to me why the hell his stuff gets posted. People joke about it, but I honestly believe there may be truth in that it gets as many page views as a useful article purely due to the hate, and people who like to watch the shaming.

  44. Let's talk by lucm · · Score: 1

    Who do you dislike the most:

    1) Bennett

    2) systemd

    3) The switch rape girl

    --
    lucm, indeed.
    1. Re:Let's talk by Anonymous Coward · · Score: 0

      Who do you dislike the most:

      1) Bennett

      2) systemd

      3) The switch rape girl

      Yes.

  45. I don't get it. by Anonymous Coward · · Score: 0

    So many people in his posts complaining. Oh, the hate does fly.

    Why not just ignore the posts if they are so unloved? Are his posts somehow stopping other posts? Preventing other important news from showing? Just skip them! Don't come in and make angry comments or belittle the guy. Treat him like a troll, and don't feed him.

  46. Who the fuck is Bennet Hasselhof anyway by Anonymous Coward · · Score: 0

    Please do yourself and everyone else a favor and shut the fuck up

    This whole "talking about technology" thing isn't for everyone. In particular, it isn't for you, so just stop

  47. "A large portion of the /. readership" = bs by Anonymous Coward · · Score: 0

    See my subject-line above? You mean you + sockpuppets you made + ac posts is more like it. Who're you *trying* to bullshit, yourself?? Are you some disgruntled old girlfriend of his or some wannabe he got the better of in technical debate, that you go through such efforts to attempt to hurt him??? It looks it. Guess it goes to show you that YOU and your sockpuppets + ac posts don't matter. The mgt. here isn't listening to your crap.