Security Expert Jailed For Reporting Vulnerabilities In Lee County, FL Elections (theregister.co.uk)
rootmon writes: Information Security Professional David Levin was arrested 3 months after reporting un-patched SQL injection vulnerabilities in the Lee County, Florida Elections Office run by Sharon Harrington, the Lee County Supervisor of Elections. Harrington's office has been in the news before for voting systems problems (for example in during the 2012 election, 35 districts in Lee County had to remain open 3 hours past the closing of polls due to long lines and equipment issues, wasting $800,000 to $1.6 million of taxpayer money on incompatible iPads for which her office is facing an audit. Rather than fixing the issues in their systems, they chose to charge the whistleblower with three third-degree felonies. The News Press also has several related interviews.
I hope the courts recognize that white hats are the good guys. I hope that paves the way for Levin (and EFF) to sue Lee County and Harrington for damages. And I hope that discourages other politicians from lashing out at the good guys.
He was arrested for actually hacking the website. Stop it with the clickbait headlines. This isn't the Star.
According to an episode of The X-Files, "all the nuts roll downhill" state.
I wish best for this guy. He did what was right and now faces several felonies. I hope this gets thrown out and he can files a big fat civil lawsuit at the count. He has his felony charges published all over the news and in postings. He'll never be able to get top secret clearance. Any potential employer will Google this guy and may consider him to be too hot to handle.
You say things that offend me and I can deal with it. Can you?
Replying because I mis-click moderated you.
Was going for +1 Funny and clicked -1 Troll instead.
My eyes reflect the stars and a smile lights up my face.
Next time make the reported results so preposterous it's obvious that shenanigans are involved.
Make 'Vermin Supreme' get 110% of the votes. Give the mainstream candidates large enough negative vote counts to give the national popular vote to 'Vermin Supreme'.
Until someone does this, to a system directly feeding data to the news networks, the system will continue to be reported as 'secure and working as designed'.
John McAfee 'It was like that time I hired that Bangkok prostitute; to do my taxes, while I fucked my accountant'
How do you find a vulnerability without actually testing it?
It almost shouldn't matter in this case. It does, but it shouldn't. When you bring felony charges for basic pen testing, people who find a system is vulnerable are not going to report it. Even if they shouldn't have been snooping around in the first place, isn't it better if they're willing to report the vulnerability before someone does real damage?
Basic SQL injection vulnerabilities are so trivial to guard against these days that it is the person who spec'd or coded the system who should be facing severe punishment, not the person who ran a penetration test. It is very much like leaving a ballot box unguarded and unlocked at a polling place, and then arresting the person who lifts up the lid and says "hey, someone left this unlocked!" Sure, he shouldn't have been checking, but he's not the one who dropped the ball and you don't arrest him for it.
In a worse case, this could have been done easily by a random tech guy barely out of high school, a malicious government, a ransomware operator, or anyone who wanted to steal the election. Many people love this kind of soft target. The local government should be thanking their lucky stars it was done by someone who reported it instead of using it to elect the candidate slate of their choice.
Real lawyers write in C++
The correct approach for fixing security issues in a voting system are to elect yourself, then appoint a team of people to correct the issue while funneling you money.
"There is more worth loving than we have strength to love." - Brian Jay Stanley
Security professionals and tech enthusiasts should take note of this technique and apply it in reverse: instead of reporting vulnerabilities to the government institutes who caused them, bring those guys to court. Sue them for unsafely handling the information you entrust them with. Things are not going to get better unless this kind of incompetence can cost someone's head.
I'll go with the Simpsons: "Florida, America's wang."
I've abandoned my search for truth; now I'm just looking for some useful delusions.
Frankly I'm disgusted that there's no "+1 Funny Troll" option.