Slashdot Mirror


The Paradox of Grey Hat Hackers (windowsitpro.com)

v3rgEz writes: Troy Hunt, a security researcher who tracked breached websites, reflects on the recent "grey hat" hacking of VTech, in which a hacker downloaded millions of kids' photos, chat logs, and more, to blow the whistle on a serious vulnerability. The attacker went way beyond responsible disclosure, offering the data directly to a reporter, but the ensuing publicity got VTech to clean up their act and maybe helped parents better understand the dangers of lax security. Is grey hat ok when it's done for the greater good?

95 comments

  1. "helpful" hackers point out security bugs by Anonymous Coward · · Score: 4, Insightful

    A hacker group hacked my school's website last year... They posted about it on their facebook page and the kids from my school commented on the post. They responded that they were doing this to help the school website be more secure by showing one of the bugs. They even "backed up" our server data supposedly. If they hadn't pointed out the security bug by hacking the website and replacing it with a page showing their logo and asking us to like their facebook page (and playing pretty EPIC music by the way) our website could have been more at risk to another hacker with perhaps not so benevolent intentions. To think if this was a credit card company or something you would want to know if there were security issues or bad stuff could happen.

    1. Re:"helpful" hackers point out security bugs by jellomizer · · Score: 0, Troll

      But what happened if they just reported it to school authorities, without all the public fan-fair?
      Was this even attempted first? If so was there enough information given out to the nature of the problem and possible areas to look at to fix it?

      By stating it is for the "Greater Good" is just explaining their bad behaviors.
      If you are going to do a "Greater Good" lets try the most good first. (Privately contact organization explain the problem)
      Then if they don't respond or ignore it. Follow up after a week or two (they may be trying to fix it but have red tape they need to go threw)
      Finally if they just ignoring you, then you can try a bit more drastic measures.

      --
      If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    2. Re:"helpful" hackers point out security bugs by slashdot_commentator · · Score: 1

      What I find tragic about the situation is the likelihood that this is an unfixable situation. The reality is that there aren't enough competent computer specialists, let alone computer specialists with competence in security issues in the private sector. So how the hell is a school district going to be able to shell out an adequate salary to hire them, or even determine which ones aren't idiots?

      Unfortunately, there's no "simple" way to address the systemic issue. Frankly, in this situation, the school district is better off having a benign hacker group publicly embarrass them, rather than have a more "professional" criminal loot their information. If you want to stop "hacker" groups from publicly embarrassing your school district, its simple. Hire a competent legal firm, have them hire a competent computer forensic specialist. It takes little effort to collect evidence against a "hacker" group that primarily operates on attention (& personality dysfunction). Hand it over the FBI or state prosecutors, while the law firm prepares the civil suit to destroy the individuals responsible.

      After the spectacle of ruining the hackers lives, eventually the district will cease to be publicly embarrassed. It may cost a couple of million for the district, who will then have to take it away from the educational budget. But what people aren't grasping is that this is a predictable fixed cost. No one is grasping that the real solution is going to have to be implemented on a societal level.

      --
      There is no America. There is no democracy. There is only IBM and AT&T and DuPont, Dow, General Electric, and Exxon
    3. Re:"helpful" hackers point out security bugs by slashdot_commentator · · Score: 3, Insightful

      What we need is... Bathacker. A man with the skills to track down these nefarious hackers, and give them the beating of their lives. That will stop sociopathic hackers from ever breaking into a school's website!

      Sounds ridiculous? So does your suggestion. No one hacks a website, and then make a public spectacle of it, in order to do "good". They do it because they're (relatively) computer talented attention whores. Just think about what you're suggesting. "Oh gee, if the crooked school administrator only stole a small amount, then nobody would really be harmed."

      Furthermore, you don't know if this problem was first pointed in the manner you suggested. District superintendents are hired by local politicians called "school board members". You can have people who are housewives basically making decisions on finance and corporate operations. School district superintendents are basically Fortune 10,000 CEOs; small company business owners. Yes, they have a requisite managerial background, but that doesn't make their staff good at hiring competent system administrators (or able to justify their salaries to district voters).

      A hacker group publicly embarrassing a system administrator is only a symptom of a much larger problem. The problem doesn't go away by convincing hackers to be more "discreet" at first.

      --
      There is no America. There is no democracy. There is only IBM and AT&T and DuPont, Dow, General Electric, and Exxon
    4. Re: "helpful" hackers point out security bugs by loufoque · · Score: 5, Insightful

      Then it would just be ignored. I speak from experience.
      People need to be hacked to act on vulnerabilities, especially the less tech-savvy.

    5. Re:"helpful" hackers point out security bugs by Anonymous Coward · · Score: 5, Insightful

      I graduated in 1999, and our school had just put up their website for the first time. One of my friends reported to school officials that when they put up the website, they didn't change any of the default passwords for the website software they were using (Perl based, if I remember right). and on top of that, they had opened up VNC to the world with no password. He didn't change anything and only logged in once to see how far he could get.

      He was quickly suspended from school and arrested for a huge list of crimes that included computer tampering, misuse of public property, etc. All the charges did end up getting dropped, but he missed most of the last semester of his senior year, didn't get to graduate with us and sat in jail for 3 months.

      Every time the website got defaced for the next few years (it happened a lot because the IT at the school didn't know what they were doing), he got a knock on the door from the local police and was taken into custody.

      So, yeah. Being the good guy isn't always a good option either.

    6. Re:"helpful" hackers point out security bugs by Anonymous Coward · · Score: 0

      There is actually a simple way to address the issue. Take action against those organizations which get hacked. Right now, they issue a "mea culpa", everyone forgets the break-in occurred, and there's no incentive to ever do any better aside from fix the specific issue they got dinged on.

    7. Re:"helpful" hackers point out security bugs by Anonymous Coward · · Score: 0

      But what happened if they just reported it to school authorities, without all the public fan-fair?

      Nothing. Absolutely nothing.
      Every time that is attempted it is ignored.

      It isn't the grey hats responsibility to secure the page. That responsibility belonged to the school and they failed at that.
      They should be thankful that the person who found out that they haven't done their job didn't use it for something malicious.
      Public ridicule is a small price to pay for incompetence.

    8. Re:"helpful" hackers point out security bugs by Anonymous Coward · · Score: 0

      I forgot to lock my door one day.

      I was in the back yard when this guy, who I guess was doing a "security check" on my house (for my own good, of course) came in and starting loading my stuff into his truck. When I confronted him he said it was for my own good. So I thanked him and then shot his thieving, fucking ass.

    9. Re:"helpful" hackers point out security bugs by Anonymous Coward · · Score: 1

      This is pretty much my experience. I am not a hacker by any definition of the term, I just fiddle around with technology. Generally telling somebody about a problem (a) makes them angry and (b) they never get around to fixing it.

      However if you find a problem and exploit it, the problem gets fixed pretty quickly. I would never do anything truly malevolent but I have no problem with defacing a website or something else relatively simple to correct.

    10. Re: "helpful" hackers point out security bugs by Anonymous Coward · · Score: 0

      Wow, you are a moron. Seriously.

      Nothing of value is lost with these hacks. Now I do admit he might have gone a little too far by releasing all the info to reporters like he did. But he did what he thought was right. Who am I to judge what someone else feels is right or wrong.

    11. Re: "helpful" hackers point out security bugs by sycodon · · Score: 1

      Umm...What someone feels is right and wrong is judged all the time, via the law.

      Just because you think it's the right thing to do doesn't make it Right. Society has implemented a system for judging Right vs Wrong and we all have a voice in that system. If people can have their own definition Right, then you have anarchy. Suddenly, my right to swing my fist doesn't end at the tip of your nose, but at the back of your head...simply because I say so.

      --
      When Fascism comes to America, it will call itself Anti-Fascism, and tell you to give up your guns.
    12. Re: "helpful" hackers point out security bugs by Anonymous Coward · · Score: 0

      Ungrateful! He was just helping you!

    13. Re: "helpful" hackers point out security bugs by Anonymous Coward · · Score: 0

      Bullshit. No one puts a kid in jail for 3 months for reporting security issues. Even if he represented himself, this wouldn't happen. I call shenanigans on this bullshit. He either said some shit, did some shit, or fucked half a dozen daughters of all the adults involved.

      I know people who were raided for downloading ISP passwords for thousands of customers, and they got 1 year probation and zero jail. They probably got worse from their parents.

    14. Re: "helpful" hackers point out security bugs by cwsumner · · Score: 1

      Bullshit. No one puts a kid in jail for 3 months for reporting security issues. ...

      I don't know about this particular story, but during the "over-reaction" period there were some kids that got put in jail.

      Never underestimate the stupidity of bureaucrats.

  2. Someone will always say no - so run by dbIII · · Score: 4, Insightful

    Hacking in and blowing the whistle without doing any damage can earn the same jail time as making a mess that cannot be ignored so at least the Judicial system does not see it as any worse.
    Is it OK?
    The people embarrassed or inconvenienced will always say no even if it is "white hat" hacking and even if it is to the great benefit of society as a whole.

    Someone will always say no, it's not OK - so run like Snowden even if you are exposing crimes.


    P.S. The sad reality is a lot of web platforms are shit that is full of holes run by people that don't care. Exposing a hole is like pointing out a starlet is not wearing pants - both to be expected and will get you in trouble if you provide evidence.
    You will not win any medals by pointing out a way to get into a poorly secured website and even well intentioned reports have landed people in deep shit.

    1. Re:Someone will always say no - so run by jellomizer · · Score: 1

      It is important to draw the line. Sharing the information they want to keep private is crossing the line into black hack hacking. Filename/Dates should be enough to explain there is a problem.

      --
      If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    2. Re:Someone will always say no - so run by AmiMoJo · · Score: 2

      I've stopped reporting vulnerabilities I find to companies that don't have a bounty programme, or at least a written policy. I just post them on a public disclosure mailing list under and pseudonym, so at least the users can protect themselves.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    3. Re:Someone will always say no - so run by slashdot_commentator · · Score: 1

      Yes, when confronted by reality, make a rule. That will always fix the problem.

      dbill has it right. No good deed goes unpunished. If you're going to do it, run like hell.

      --
      There is no America. There is no democracy. There is only IBM and AT&T and DuPont, Dow, General Electric, and Exxon
    4. Re:Someone will always say no - so run by chispito · · Score: 1

      The people embarrassed or inconvenienced will always say no even if it is "white hat" hacking

      "White hat" generally means with permission, or without violating the law. Think penetration testers or other hired consultants. That's why this is about grey hat hacking, where the motives or the end game might be ethical but the means aren't entirely so.

      --
      The Daddy casts sleep on the Baby. The Baby resists!
  3. It's not complicated by TechyImmigrant · · Score: 4, Insightful

    > Is grey hat ok when it's done for the greater good?

    Yes. It's great for all the people who benefit. It sucks for the person who put their liberty at risk to bring those benefits to people.

    --
    I should use this sig to advertise my book ISBN-13 : 978-1501515132.
    1. Re:It's not complicated by Anonymous Coward · · Score: 0

      There are people who don't mind putting their liberty at risk for fame and lulz. Also, there are people young-and-stupid enough that they fail to realize just how at risk their liberty is, but technically skilled enough to pull off hacks like this.

      In either case, such gray hat hacking will probably not be stopped by people moralizing on the Internet.

    2. Re:It's not complicated by Anonymous Coward · · Score: 0

      The problem is, who gets to define "the greater good"???

      Is it okay for a greyhat to hack a business owned by someone that is gay, because "the greater good" would be served if there were no gays?

    3. Re:It's not complicated by Anonymous Coward · · Score: 0

      The problem is, who gets to define "the greater good"???

      Is it okay for a greyhat to hack a business owned by someone that is gay, because "the greater good" would be served if there were no gays?

      It's case dependent.
      In the VTech case, the children were put at risk of having their personal information released to evil-doers.

      The grey-hat did them a favour by forcing VTech to fix the problem by releasing the information to a journalist so VTech would no longer ignore their own technical negligence with the children's data.

      Now the grey hat gets screwed for doing these people a favour.

  4. It defeats the purpose by Erik+Hensema · · Score: 2

    Doing more damage than strictly necessary defeats the purpose: opinions will turn against the hacker. Now the hacker is the bad person, in stead of the company with bad security.

    Another commenter already brought up Snowden. Snowden did exactly the same thing wrong: Snowden exposed way too much classified information. In doing so, he compromised national security and turned public opinion against him. Now the message of Snowden is mostly lost to the general public, which is a shame. The general public now thinks to know stricter laws are necessary in order to protect information. Stricter laws are needed to ban encryption. Stricter laws are needed to penalize hackers. Thanks Snowden. Good job.

    --

    This is your sig. There are thousands more, but this one is yours.

    1. Re: It defeats the purpose by Anonymous Coward · · Score: 1

      If Snowdon hadn't done what he did, you'd be buying into the 'low level incompetent contractor who misinterpreted a few crumbs he saw and has a crazy conspiracy grudge against us.'

      Thanks to the massive evidence release that narrative is now impossible.

    2. Re:It defeats the purpose by slashdot_commentator · · Score: 1

      > Snowden exposed way too much classified information.

      Says who? The bureaucrats breaking the law, if not raping everyone's Constitutional rights?

      > In doing so, he compromised national security and turned public opinion against him. Now the message of Snowden is mostly lost to the general public, which is a shame.

      When the general public, after the ass raping of their privacy rights, are watching the TV, and are convinced by paid whores that Snowden has committed a greater crime, that is the shame.

      --
      There is no America. There is no democracy. There is only IBM and AT&T and DuPont, Dow, General Electric, and Exxon
    3. Re:It defeats the purpose by DarkOx · · Score: 4, Insightful

      Snowden was down to choices really do nothing more and just give up or release at least as much of what he had as he did.

      He tried the official channels was ignored. The 'public' as a whole was not prepared to listen without some demonstration made. People who thought the NSA and more broadly the intelligence complex was up to no good already had reason to suspect much of what Snowden disclosed. We knew this from inferences that could be drawn about data center sizes, power being used, purchases of equipment that were public, whisperings form employees at various telco and equipment vendors etc. There was just no solid proof. It was to easy to get everyone who was speaking out dismissed as conspiracy nutters by a public that just wanted to feel 'safe'

      Any foreign intel operators probably knew even more and were not the least bit surprised, they were most likely operating already under the assumption the NSA monitoring capabilities were at least at the level the Snowden releases indicated. If the officials want us to believe any real harm was done, I say its on them to show some proof of that!

      The only harm Snowden did to the NSA and its efforts was political. Had he released any less nobody would have paid attention.

      --
      Repeal the 17th Amendment TODAY! Also Please Read http://www.gnu.org/philosophy/right-to-read.html
  5. Shades of grey ... by Martin+S. · · Score: 4, Insightful

    This dichotomy is the whole point for the Grey Hat moniker. There is no Black and White, it is always shades of Grey,.

    One man's Black Hat is another's White Hat. Where many Black Hats believe they are fighting for the greater good and conducting Illegal activities but for ethical reasons and also so called White Hats acting legally but unethically while taking the corporate dollar.

    1. Re:Shades of grey ... by Opportunist · · Score: 2

      So I guess I'm in the unethical white hat corner of the game? It's unethical to make sure customer data is protected and not open to being used by malicious hackers? It's unethical to secure the personal information of people from being lifted and abused?

      I'm such a horrible, horrible person.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    2. Re:Shades of grey ... by Anonymous Coward · · Score: 0

      Relax. Martin S. is waxing philosophy at a site where knowledge of philosophy is looked down upon. In other words, ignore him and the people that upmodded that post for their lack of knowledge and intellectual depth on ethical concerns.

  6. Why is it called grey? by Anonymous Coward · · Score: 1

    The term intrigued me from title on and I hoped I'd find something to distinguish grey hat from white hat but couldn't find any in this case.

    1. Re: Why is it called grey? by Anonymous Coward · · Score: 0

      Gandalf the grey, he has a grey hat.

    2. Re:Why is it called grey? by Anonymous Coward · · Score: 0

      we're color blind. it's actually green hats (the color red was taken).

    3. Re:Why is it called grey? by flopsquad · · Score: 1

      I tend to think of the "grey" in "grey hat" as being used in the dithering sense.

      I.e. a collection of tactics/actions comprising both "white hat" and "black hat" behaviors, such that when viewed together they appear "grey".

      --
      Nothing posted to /. has ever been legal advice, including this.
  7. implying by Anonymous Coward · · Score: 0

    Grey hats don't necessarily care what you think in terms of morality. I'd argue most are kids, amateurs and apprentices of "infosec" until they progress into the whitehat realm of sysadmining, programming or whatever buzzwordy sub-field. Until then they're just fucking whatever they can get their hands on, morality is secondary.

    Blackhats are those who are in it for profit, be it as a mercenary/APT force or directly via your "hacks".

  8. Why is this a question? by cerberusss · · Score: 2

    The attacker went way beyond responsible disclosure, offering the data directly to a reporter, but the ensuing publicity got VTech to clean up their act

    Yes, let's fight fire with fire. See how far that gets you.

    --
    8 of 13 people found this answer helpful. Did you?
    1. Re:Why is this a question? by Anonymous Coward · · Score: 0

      Old Andalusian proverb:

      It's always better to fight fire with fire than to fight fire with a slightly damp sausage.

    2. Re:Why is this a question? by drinkypoo · · Score: 1

      Yes, let's fight fire with fire. See how far that gets you.

      As it turns out, pretty far. It's time to put that saying to death.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    3. Re:Why is this a question? by Opportunist · · Score: 1

      It obviously loses a bit in translation...

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  9. The End Justifies the Means by Anonymous Coward · · Score: 0

    After all, that's what all our politicans and industrialists are teaching us, no?

    - Kill our environment to keep the consumerist machinery running
    - Quabble about assad-or-not-assad while people are killing each other. In the meantime kill those your respective interests deem as "tarrist"
    - Curtail every citizen's rights because "tarrists" and/or "children"
    - Ban encription although the problem is that actual and publicly available signals are missed regularly

    What's a bit of grayhatting here and there?

  10. It's called a dilemma, not a paradox by BitterKraut · · Score: 4, Insightful

    When I was a kid, I didn't believe my mother when she told me not to touch the hotplate. The pain of burning my palm was a memorable lesson, though. Here, it's the difference between "I could have deleted your hard disk" and "So your hard disk has been formatted? Well, if you can explain to me how this could have come about, I might even provide you with a backup copy." It may not feel quite right to think of hacker kids as educators of the general public -- wasn't that a transient phase of the 80's? -- but while the current state of general irresponsibility in matters of systems security persists, we do need the occasional burnt palm.

    1. Re:It's called a dilemma, not a paradox by Anonymous Coward · · Score: 0

      ... we do need the occasional burnt palm.

      While I agree with the principle you espouse, the law and 'think of the children' activists have a different principle. Injuries to yourself are between you and health insurer. Injuries to others are the domain of courtrooms, with the judge on the side of the police or better-paid lawyers: The type of lawyers who make sure the 'being blameless isn't an excuse; you can't sit on your arse; you're always responsible for somebody' principle of civil law isn't heard once.

    2. Re:It's called a dilemma, not a paradox by Anonymous Coward · · Score: 0

      Maybe we need a law that states you get fined if you're made aware of security issues and you don't fix them in some definition of a timely manner. Then any white-hat can report the issue and know someone will fix it.

    3. Re:It's called a dilemma, not a paradox by Opportunist · · Score: 1

      Provided the fine is big enough. Remember, in a corporate setting the question of whether a law is ignored follows the formula of fine*chance of being caught vs. cost to implement.

      In other words, if the fine is too low, it's a matter of cost calculation. If the chance to get caught is too low, risk management is the department to go to. Only if both are high enough the mess hits security.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    4. Re:It's called a dilemma, not a paradox by Anonymous Coward · · Score: 0

      Percentage of gross world wide revenue sounds like a good starting place.

  11. The answer is, yes. And no. by Anonymous Coward · · Score: 0

    Gray is okay if it exposes some other company's flaws. Gray is not okay if it exposes my company's flaws.

    So, really, it's all in black and white, now isn't it.

  12. Unsurprisingly, it's a grey area. by Euphorinaut · · Score: 1

    What is most at issue isn't just the direct effect of the attack or the indirect effect on our awareness of security and vulnerability in terms of judging the entire umbrella of grey hat. Those two forms of effect are unique to each example and should be judged on a case by case basis. The issue that isn't dependent on case by case analysis is the one of rule of law. It is possible to violate the letter of the law without violating the spirit of the law, but if a culture of taking enforcement into your own hands and your own interpretation grows, harm will also grow no matter whether or not some cases were handled with all the care necessary to assure that their effect was altruistic, and no matter how altruistic your direct effects are as a grey hat, your publicity will promote the prevalence of grey hat culture. The positive effects cannot negate the negative ones, and the negative ones cannot negate the positive ones.

  13. Threat by Anonymous Coward · · Score: 0

    I would think even the threat of it ("next week I will hack your website and see if you patched it") would probably get most sysadmins on their toes checking for security issues.

  14. I got a definition for ya by Anonymous Coward · · Score: 0

    A "grey hat hacker" is just a black hat hacker that is under the delusion they are a white hat hacker. That hacker should have got a serious slap on the wrist as a hey-idiot-WAKE-UP-CALL by the government while VTECH should just liquidate and salt the ground their offices and factories stand on.

    1. Re:I got a definition for ya by slashdot_commentator · · Score: 2

      An anonymous coward is someone who thinks their opinion matters when they express it anonymously.

      --
      There is no America. There is no democracy. There is only IBM and AT&T and DuPont, Dow, General Electric, and Exxon
    2. Re: I got a definition for ya by Anonymous Coward · · Score: 0

      Yes. Your point being?

  15. Necessary due to corporate defense mode by pla · · Score: 4, Insightful

    On learning of a vulnerability, most companies have demonstrated one of two responses:

    1) Ignore it, or
    2) Attack the messenger.

    Given that corporate climate of "hostile indifference" to their own flaws, grey-hats fill a very necessary niche. No more of this kumba-ya "tee hee, would you mind fixing this embarassing massive security breach, Mr. Fortune-500 CIO" bullshit - Just name and shame right up front.

    The "nice" way would work well if anyone cared; until it makes the NYT, though - No one cares. So lets stop giving Russian hackers an extra six months to exploit known problems, and skip right on to the NYT solution.

    1. Re:Necessary due to corporate defense mode by Anonymous Coward · · Score: 0

      The "nice" way would work well if anyone cared; until it makes the NYT, though - No one cares. So lets stop giving Russian hackers an extra six months to exploit known problems, and skip right on to the NYT solution.

      If we want them to care, set it up so that 'kumba-ya' email gets BCC'd to various authorities to establish legally when the CIO got informed--and that triggers a nice cheerful set of liabilities. IANAL but I suspect a sufficiently devious lawyer could certainly manage to successfully build a case, possibly even a criminal case, with already existing laws. There's already laws requiring at least some security, and if they know the 'security' is insufficient...neglect and indifference, in the legal sense, come to mind.

  16. Re:No such think as "hats". by pla · · Score: 1

    Nice worldview you have there.

    Please do tell, on which side of that bold razor-wire-topped fence do you put teens interested in security and casually messing around with malformed Fiddler requests to see what they can get the server to respond with?

    Not "professionals", so I guess you would classify them right along side the Russian Mafia?

  17. Let's think about the children! by Anonymous Coward · · Score: 0

    yup

  18. old hats by Tom · · Score: 4, Insightful

    Old discussion, rehashed. /. could use a "re-post my comment from 2002" feature.

    There are two sides, and they will never reconcile. Some people think (based on past experience) that corporations generally won't take security seriously unless it impacts their business or their image, so only disclosure works. Other people think (based on past experience) that disclosure reads to the creation of exploit toolkits which leads to higher damage to more people and gives vendors not enough time to fix a problem. And a few especially delusional people think that a timer on disclosure and a few rules to make the whole thing "responsible" solves the unsolvable problem (it doesn't. Vendors will a good track record already fix quickly, vendors with a bad track record merely consider the delay additional time they don't have to do anything.)

    And I think that pretty much sums it up, everything else is just elaboration.

    --
    Assorted stuff I do sometimes: Lemuria.org
    1. Re:old hats by Anonymous Coward · · Score: 0

      solves the unsolvable problem (it doesn't. Vendors will a good track record already fix quickly, vendors with a bad track record merely consider the delay additional time they don't have to do anything.)

      And I think that pretty much sums it up, everything else is just elaboration.

      Seems like the solution there. Good track record, delayed disclosure. Bad track record, full disclosure. No track record, benefit of the doubt (good track record). Change response when required.

    2. Re:old hats by Anonymous Coward · · Score: 0

      The only time when outing the information immediately isn't a dick move is when the company has a prooven history of screwing the pooch. Otherwise consider it corporate espionage.

      Submit the issue anonymously including a time window for public disclosure and document the disclosure to the company forensically. Let them know they need to either make a patch available, fix the issue by then, or issue a press release. Give them a ultimatum\drop dead date, let them know if it has not been fixed it will be submitted to the press.

      This move CYA's you from damages.

      Deadline hits, give it to the press. DB Table and all in it's bare-assed glory.

      Fact is, if you're breaking laws and public common sense, and someone outs you and gives you time, then shame on you.

    3. Re:old hats by Tom · · Score: 1

      The only time when outing the information immediately isn't a dick move is when the company has a prooven history of screwing the pooch. Otherwise consider it corporate espionage.

      Old argument, made a thousand times. No need for redundancy.

      In fact, everything you say has been said a hundred times, just as I already outlined. Likewise, the arguments pro and contra have been made extensively. I see no need to repeat the discussion. That was the point: If you want to discuss this topic, go to one of the many, many, many archived discussions, you will find everything you can come up with and one hundred other arguments there.

      --
      Assorted stuff I do sometimes: Lemuria.org
    4. Re:old hats by Tom · · Score: 1

      Seems like the solution there. Good track record, delayed disclosure. Bad track record, full disclosure. No track record, benefit of the doubt (good track record). Change response when required.

      Who decides what the track record is?

      Oh wait, even that discussion has been had a hundred times already. Why we go around in circles? Because we are human beings and we can't accept that someone simply has a different opinion, comes to a different conclusion even from the same facts. We think that if someone disagrees, one of us must be wrong, and most likely they.

      But if everything has been said a thousand times, and smart people on boths sides of the debate still can't agree on a common position, then maybe that is just how it is and instead of repeating the same futile excercise again, we should simply accept that there are at least two positions, both equally solid even if we personally only agree with one of them.

      --
      Assorted stuff I do sometimes: Lemuria.org
  19. Collateral? by wkwilley2 · · Score: 1

    Grey hat hackers will always be more useful than your white hats.

    What sounds better to you.

    WH: Hey guys!!!! I found an issues in your system, you should fix it.
    GH: Hey guys!!!! I was able to see your credit card numbers using this exploit on your website, you should fix that.

    --
    Have you ever fallen asleep at the keybhanusdiog?
    1. Re:Collateral? by Opportunist · · Score: 1

      Same outcome. Really.

      A sensible company that takes security serious will, if you WH them, hire some penetration testers to do what GH did. They will hand them the information and ask what damage could be done, either let the testers access their system or provide them with a 1:1 copy to avoid direct damage.

      A company that doesn't give a fuck about security will ignore either of them.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  20. Re:No such think as "hats". by Anonymous Coward · · Score: 0

    I'd strongly advise those "teens interested in security" to find other interests. What do you do to teen trespassing on private property? What do you do to teen caught shoplifting? Same things must happen to teen caught hacking: illegal is illegal.

  21. Shades of Grey by DFDumont · · Score: 1

    The only truly 'white' hat is the one paid to attempt a break in, with full knowledge and cooperation of the target, who delivers the results directly to the company paying the bill, without disclosing their results to anyone else. A 'Black' hat is the one that does a similar thing entirely for their own benefit and the specifics of the exploit used are never disclosed to anyone. As you can see by these definitions, there is a great deal of spectrum between those two extremes. Therein is also a reasonable definition of 'Grey' hat - one who discloses beyond the target, or at all.
    And thus the problem. As in the story of The Emperor's New Clothes, calling out the 'nakedness' is fraught with peril. In doing so you are, among other things, saying 'I'm so much smarter than you' to the target. Most people don't appreciate that and will retaliate out of self preservation.
    So what motivates a 'Gray' hat? Sometimes it is arrogance. Sometimes it is charity or a sense of the greater good. Sometimes it's just dumb luck when you stumble over something while testing out your latest kit. There are many shades of grey.

  22. a gray hacker by Anonymous Coward · · Score: 0

    is a hacker who hopes to be let off the hook by calling his wrong doing ethically justified.
    he is still a hacker and unless he had permission to hack into a third party system, that's a crime.
    if he had permission he would be a consultant and not a hacker.
    big difference.

    1. Re:a gray hacker by Opportunist · · Score: 1

      Call me consultant again and I'll replace you with a very small script! A consultant is someone who takes 500 bucks an hour from you to tell you what you already know, and if not you could have gotten that information from the cleaning lady by paying for her 50 cent coffee.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  23. He was in the wrong. Period. by B33rNinj4 · · Score: 1

    You go to the company first, not the fucking media.

    1. Re:He was in the wrong. Period. by Anonymous Coward · · Score: 0

      Who is the company? Is it every customer who purchased one of Vtech's devices? It is their privacy that has been breached. It seems the easiest way to contact all of the effected users is through the media.

    2. Re:He was in the wrong. Period. by B33rNinj4 · · Score: 1

      Vtech should be notified first, so they can fix any future issues. If they ignore you, then go to the media. Going directly to the media without allowing the company time to react is in poor taste.

  24. RESPONSIBLE disclosure by Anonymous Coward · · Score: 0

    That is the key right there. There wasn't any reason he couldn't have told the reporter but not offered up all the data and then with the reporter gone to the company.

  25. What else? by BartWillems · · Score: 1

    Disclosing vulnerabilities directly to a corporation, without public disclosure, results in "solving" the problem by wiping it under the carpet. Sure, you can go to the company first. With the knowledge that nothing will be done to solve the problem until it is disclosed to the public.
    So why wait?

  26. Re:No such think as "hats". by pla · · Score: 1

    I'd strongly advise those "teens interested in security" to find other interests.

    That advice leads to effectively zero security experts, of any color hat, one generation from now.

  27. Bulletproof vest analogy by Shoten · · Score: 1

    Both Whitehat and Greyhat find that a particular make of bulletproof vest degrades after a year and no longer offers protection. They both notify the manufacturer, who blows them off. Then the paths diverge:

    Whitehat: contacts a member of the press and demonstrates the problem for them by putting one of the vests on a mannequin and shooting the mannequin through the vest. (Extra points if he puts a DVD copy of the movie, "Mannequin," inside the vest and shoots a hole in that too.)

    Greyhat: contacts a member of the press and demonstrates the problem by shooting people who happen to be wearing the vest in public.

    The latter may be a bit better at getting the attention of the press, the public, and the manufacturer, but it's not an acceptable way to accomplish that goal. The ends do not automatically justify the means.

    --

    For your security, this post has been encrypted with ROT-13, twice.
  28. How is this grey-hat? by drolli · · Score: 1

    Tell me if something about my definition is unusual:

    White-hat: only cares for ethics, does not want money
    Black-hat: only cares for money/power. is not concerned about ethics
    Grey-hat: accepts that he gets money/power/advantages for his skills, but only within his ethical boundaries.

    Please tell me why i should not consider this guy a white-hat (tipping off journalists is *not* publishing). Side remark: While responsible disclosure is reasonable, i understand (given the reactions of companies) that younger and more impatient white-hats have their issues with it.

  29. Mod him up to +5 folks... apk by Anonymous Coward · · Score: 0

    See subject: I've said that MANY times myself here on /. - "great minds think alike" & it's true as far as I'm concerned... however - I don't agree w/ just "doing it" minus letting the parties concerned know about it.

    ONLY PROBLEM THERE? "Responsible disclosure" & "procedure" have GOTTEN THE 'researchers' busted even!!!

    WTF!

    APK

    P.S.=> It seems like you're damned if you do, & the parties 'hacked/cracked' are damned if you don't + THEY WILL "DAMN YOU" if you try it, even responsibly... the world's gone insane as far as I'm concerned (not completely but it's getting there) - I'm amazed @ it personally (& not just in tech/computing levels, but all over it) - I do my part (responsibly, as I feel it's YOUR DUTY AS A HUMAN BEING if you have the ability, to help change the world for the better if you can. in "little revolutions") -> http://start64.com/index.php?o... to help make folks safer, faster, more reliably connected online via using what you already natively have vs. "Bolting on 'MoAr'" that does less yet eats more resources illogically... apk

  30. How can this be for the greater good? by PFritz21 · · Score: 1

    THE GREATER GOOD.

  31. Re: No such think as "hats". by Anonymous Coward · · Score: 0

    Yes... Because not allowing teenagers to race on F1 cars led us to have no F1 drivers. There are things called schools where one can learn in a safe and controlled environment. Do you think European countries do not have armed forces anymore because they don't allow the populace to own guns? You are an idiot or a petulant small child. Dismissed.

  32. I can get behind grey hat hackers if ... by CaptainDork · · Score: 1

    ... the hackers have reported an exploit to the owner and the owner just doesn't give a shit and the grey hat officially declares a grace period before going public.

    Then, I could see the grey hat grabbing a SMALL amount of data, as a proof of concept, to share with the owner with the warning that if something isn't done during another grace period, the shit's going to hit the fan.

    The grey hat had better have the sense god gives a piss ant to be anonymous, of course.

    --
    It little behooves the best of us to comment on the rest of us.
  33. Re:No such think as "hats". by Opportunist · · Score: 1

    So do I! I don't need those snooty kids to muscle into my territory. They took my juuuuub!

    No, seriously. We need those kids. I was one of them, and pretty much everyone I work with has at some point in time played around with computer systems and security. This ain't something you can sensibly teach in a clinical setting like a school. We need people with the "what does this button do?" mentality to computer systems who can not only press that button but also analyze the funny colors the various bits have that rain back down after the explosion and tell you why it blew up.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  34. The problem is less one of the hacker by Opportunist · · Score: 1

    The problem is more the way corporations treat such events and the information about them being vulnerable.

    Corporations consider such events first and foremost a problem of PR and goodwill. THIS is the actual problem. And they do so also because their customers treat it as such. It's not a technical issue, it's not a security issue, at least not to them. To them it is one of trust in a brand.

    And they handle it as such. The first goal is to avoid damage to the brand. I.e. no disclosure. Zip. Nada. No info may go out that could damage the trust in our brand. That includes that the person who brings up the issue should preferably go away. Even if the company involved does actually want to do the "good thing" and deal with the issue (and not just sweep it under the rug), but the first thing that they want is no disclosure.

    My job is in security. I do actually do that for a living, trying to break the security of networks and servers. The very first thing, even before talks even start, is an NDA that is shoved under your nose. And I'm certain if you didn't absolutely HAVE to know the company you're dealing with (since you're entering a contract with them), they would love to keep that secret from you, too, before you signed that NDA. Personally I'm rather astonished that companies don't go out and slap it on their webpage that they hired us. We're a rather well known company with a good name in security consulting, I'd probably scream it from the top of a mountain that I consider security SO important that I even afford (our company) to stress test our infrastructure to ensure your data is secure with me... nobody ever does.

    Nobody wants to talk about security. Odd if you think about it. Security features in cars are huge selling points, car manufacturers brag how much money they spend on crash tests and show how their cars get slammed into walls to show off just how much they care about security. Why is this so much of a taboo issue in IT? Wouldn't people want to go to a data center that can show them their data is secure because they have one of the biggest and best security and emergency response team pretty much in house?

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  35. Re: No such think as "hats". by Anonymous Coward · · Score: 0

    When you were a kid, playing around with a computer had no consequences to speak of. These days this kind of behaviour can cause disruption at best, disaster at worst. When I was a kid we used to play with chemicals that are now banned, and rightly so. Things change. They evolve. We are maturing as a society and part of that process is learning and accepting that there are things we simply cannot afford to allow anymore.

  36. No by Anonymous Coward · · Score: 0

    Only gather and release as much data as required to prove it could be obtained. The rest is easily inferred. In my opinion if you hack it you are responsible for that data. When I still audited things independently I released a proof of concept exploit and not the specific data itself but only as a last resort. I first try to get the 'vendor' to fix it. When it becomes obvious they won't or cannot even be made aware by any other means I would release the proof of concept and or contact 'reporters' to turn up the heat. Only when all that fails do I even consider going further. I don't feel it is my place to release the data (or even collect it beyond what I need to know I can get at it) that can be obtained. Of course with the proof of concept someone else could obtain the data and release it or use it for whatever purposes.

  37. yes, by unami · · Score: 1

    it's o.k., if it's for the greater good.

  38. Re: No such think as "hats". by pla · · Score: 1

    Maybe Google can have a two week girls-only bootcamp for it. Then we'll have more highly skilled security experts than we could ever possibly want, right?

  39. Sue insecure sites. by GrantRobertson · · Score: 3, Interesting

    What we need is a business model for law firms to profit from suing insecure sites just as the music industry has law firms that support themselves entirely from suing copyright infringers. Said law firms would solicit for "expert witnesses" to provide information as to which sites may be insecure. The law firm then does research (through legal means) to find enough people, who have information on the site, to constitute a class action lawsuit. They file the suit and pay their expert witnesses a fee for their testimony. No one can retaliate against the expert witness because that would be witness tampering. The expert witness would be working on behalf of the plaintiffs rather than working independently.

  40. Re: No such think as "hats". by Opportunist · · Score: 1

    So ... sodium chlorate and sugar didn't explode violently when you were a kid? And now it does, so it has to be banned?

    I'm kinda confused.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.