[HN Gopher] City of Columbus sues expert who exposed extent of c...
       ___________________________________________________________________
        
       City of Columbus sues expert who exposed extent of cyberattack
        
       Author : hendler
       Score  : 195 points
       Date   : 2024-08-30 14:44 UTC (8 hours ago)
        
 (HTM) web link (www.10tv.com)
 (TXT) w3m dump (www.10tv.com)
        
       | bell-cot wrote:
       | Sounds like a straightforward 1st Amendment case.
       | 
       | Might there be any lawyers with opinions (& disclaimers,
       | obviously) in the house?
        
         | rolph wrote:
         | i think it hinges on what is a threat vs what is mitigation.
         | 
         | should people be informed, thus enabled to respond, or should
         | people be etoliated, and kept ignorant of even requiring a
         | response.
        
           | ForOldHack wrote:
           | My compliments on your vocabulary:
           | 
           | etoliated: Def 2. literary. weakened; no longer at full
           | strength. "Her voice was thinner than I recalled..."
        
             | courseofaction wrote:
             | Especially by a lack of sunlight. Fitting.
        
       | rolph wrote:
       | i really wish the scarewords like darkweb would go away.
       | 
       | the internet is not google, no amount of sand over the head or in
       | the eyes will change that.
       | 
       | Columbus officials chose to invalidate threat to public safety by
       | way of misinformation, then retaliate when the threat and true
       | situation was revealed.
       | 
       | keeping people ignorant of threatscape is not good government.
       | 
       | thinking the 'darkweb' is some sort of containment by obscurity,
       | is beyond naive.
       | 
       | the city of columbus is actually inhibiting a proper response and
       | perpetuating a cavalier security stance.
       | 
       | this is not going unnoticed.
       | 
       | [1] [This is a bigger issue here': Columbus resident wishes the
       | city told residents about the data breach sooner]
       | 
       | https://www.10tv.com/article/news/local/columbus-woman-wishe...
       | 
       | [2] Second class-action lawsuit, representing police and
       | firefighters, filed against city after cyberattack
       | 
       | https://www.10tv.com/article/news/local/second-class-action-...
       | 
       | [3] Ginther confirms personal information of Columbus residents
       | exposed in cyberattack
       | 
       | https://www.10tv.com/article/news/local/ginther-press-confer...
        
         | ForOldHack wrote:
         | Point, point, point, point, point, Game, set, Match.
         | 
         | "this is not going unnoticed." Oh thank god!
         | 
         | "the city of Columbus is actually inhibiting a proper response
         | and perpetuating a cavalier security stance."
         | 
         | "On Aug. 13, Mayor Andrew Ginther said the data stolen by
         | hackers was either corrupted or encrypted, meaning it was
         | likely useless. Hours later, Goodwolf told 10TV that wasn't
         | true and he showed what kind of personal information he was
         | able to access"
         | 
         | "City officials announced they are providing free credit
         | monitoring to Columbus and Franklin County Municipal Court
         | Clerk employees and judges and have asked city employees to use
         | different passwords for their accounts."
         | 
         | Elvis and common sense has left the building.
         | 
         | https://schneiderdowns.com/our-thoughts-on/city-of-columbus-...
        
         | gsk22 wrote:
         | As far as I can tell, darkweb has no actual meaning anymore
         | anyway.
         | 
         | I saw an article recently claiming that something like 80% of
         | people under 30 access the dark web at least once a week. 80%
         | of under-30s use Tor? Seems highly unlikely.
        
           | kjkjadksj wrote:
           | My understanding is it merely meant sites not indexed by
           | search engines. Your employers internal websites or the sites
           | for your college coursework would count.
        
             | sidewndr46 wrote:
             | Don't forget bit torrent. There are teenagers out there
             | committing several world GDP worth of piracy on the daily
             | if you believe the entertainment industry
        
             | Izkata wrote:
             | "Not indexed" is the deep web. The dark web is ones that
             | use alternate protocols on top of the web so they can't be
             | indexed by web search engines (includes things like Tor and
             | Discord).
             | 
             | I suppose ones that require authentication (like internal
             | employer sites) could also be dark web.
        
               | gsk22 wrote:
               | Surely Discord can't be counted as dark web? It's not web
               | at all.
        
               | wizzwizz4 wrote:
               | Sure it is. I open my web browser, and Discord is in it.
        
       | josefritzishere wrote:
       | This is a very clear case of a restraining order being used
       | punatively. The body of first amendment case law is very clear.
       | The city has no reasonabel expectation that they will win. Their
       | intent is to restrain, and intimidate legitimate criticism.
        
       | edm0nd wrote:
       | A perfect case for the EFF or ACLU to pickup and help defend
       | against such a silly and weaponized restraining order.
        
       | passwordoops wrote:
       | ""This is not about speech. It's not. It's about the actual
       | action of going on the keyboard, going into the dark web,
       | gathering the information, downloading it to your computer and
       | then disseminating it to people who are in the press or
       | otherwise," Klein said"
       | 
       | No, this is about how you lied to your public about the nature
       | and format of the data that _you_ failed to protect
        
         | sidewndr46 wrote:
         | I love how politicians invoke "the dark web" like its some
         | bogeyman that hides in the night and preys upon young children.
         | It's literally a bunch of websites. That's it.
        
           | superkuh wrote:
           | Everything not on Facebook/Google/Twitter is the dark web.
        
             | kabdib wrote:
             | _Especially_ sketchy places like Hacker News. Just look at
             | the name!
        
       | sva_ wrote:
       | https://archive.is/dEBJT
       | 
       | (blocked in EU)
        
       | sillysaurusx wrote:
       | Former pentester here. Though I'm largely sympathetic with
       | Goodwolf, note that releasing actual data is almost always a bad
       | idea. It's why bug bounty programs have limited scope.
       | 
       | The city seems upset that he shared data about ongoing
       | investigations and undercover police reports. Depending on what
       | exactly he shared, it's hard to fault the city for that. It
       | doesn't really matter where the data currently exists; grabbing
       | it and handing it off to others is obviously not a good idea.
       | 
       | If his goal was to prove to the reporters that such data existed
       | and was available for download, he had many options that didn't
       | require accessing the data: screenshot the forum posts, send
       | links to the reporters, detail what kind of data was there
       | without actually showing any of it, and so on.
       | 
       | Now, if that's what he did, and the city is still reacting this
       | way, that's obviously abuse. But it doesn't seem unreasonable to
       | order someone to stop disseminating data about ongoing
       | investigations to reporters. Would you want your private cases to
       | be more widely spread?
       | 
       | I'm really sympathetic to him, because this is an easy mistake to
       | make. Before I got into the industry, I thought that this was
       | white hat hacking; it's obviously good that he's spreading
       | awareness about the breach. But _how_ you do it really matters.
       | 
       | (Caveat: I worked in the industry for about a year in 2016, so
       | maybe things have changed. But I'd be shocked if distributing
       | actual data from any breach was condoned by anyone who works as a
       | pentester, even today.)
       | 
       | > the city says Goodwolf is threatening to publicly share the
       | city's stolen data in the form of a website that he will create
       | himself. Goodwolf previously told 10TV he does plan to set up a
       | website, but it would only allow people to see if their name was
       | part of the data breach.
       | 
       | This isn't the same as setting up a site to see if your password
       | was compromised. It could let anyone type in someone's name and
       | see whether they're a witness in a criminal investigation.
        
         | nostrademons wrote:
         | It's somewhat unclear exactly what was shared and how. The
         | article and the linked article about the data breach itself
         | suggested that Goodwolf downloaded the data to verify its
         | contents and then _showed the data to a reporter_ , but he
         | didn't actually release any data, nor distribute it into the
         | permanent possession of the reporter. This is akin to Boeing
         | saying "We had no knowledge of the 737 MAX's problems", and
         | then an employee showing screenshots of confidential memos to
         | the media saying "Yes you did, here is the truth."
         | 
         | I agree that creating a website where you can look up a name
         | and see if they've been part of a police investigation is a bad
         | idea, but he didn't actually do that, he only had plans to.
        
           | sillysaurusx wrote:
           | Sure, but the fact that it's unclear is exactly what the city
           | is reacting to. The point of the restraining order is that
           | they have a reasonable belief that he might have distributed
           | it to reporters, and he's on the record saying he might
           | create a website where anyone can see information related to
           | ongoing criminal investigations or witness identities.
           | 
           | Note that showing the data to the reporter counts as
           | distribution. He didn't need to do that to prove to the
           | reporter that the data was out there. Even sending
           | screenshots of the data would've been ok if he'd redacted
           | anything remotely confidential (it would be obvious from
           | context that the document is probably legit, and the reporter
           | would dig in further).
           | 
           | If he didn't send any sensitive data to anyone, then I
           | completely agree with you. But pentesters generally don't
           | send actual data to prove a breach exists to anyone but the
           | target of the breach. Publicizing the breach itself is fine,
           | but the article is pretty clear that's not why they're going
           | after him.
        
           | Spivak wrote:
           | > I agree that creating a website where you can look up a
           | name and see if they've been part of a police investigation
           | is a bad idea, but he didn't actually do that, he only had
           | plans to.
           | 
           | He still should. The dispatch article has more information,
           | this was data that has already been leaked, there is no means
           | of protecting it anymore. The only thing to do is release it
           | so people know if they've been exposed.
           | 
           | https://www.dispatch.com/story/opinion/columns/2024/08/30/co.
           | ..
           | 
           | Like it sucks that this is the best option but you can't make
           | it go away, the data is free.
        
             | DaiPlusPlus wrote:
             | > The only thing to do is release it so people know if
             | they've been exposed.
             | 
             | Are we talking about a Troy Hunt-style (haveibeenpwned)
             | website? If so, I don't consider a giant hashset-of-hashes
             | a "release" because if _that_ data (haveibeenpwnd 's
             | database) gets leaked it's of zero use to anyone because it
             | doesn't contain any original data anymore.
             | 
             | But if you mean Wikileaks-style: put it all in a .rar file
             | and publicise it, maintaining that the-ends-justify-the-
             | means approach despite all the irresponsible-journalism,
             | then absolutely no. Yikes. No.
        
         | AmericanChopper wrote:
         | According to what I read in that article, Goodwolf didn't
         | release the data. The hackers released the data, the city lied
         | about it, Goodwolf went and retrieved the publicly accessible
         | data and gave it to journalists to prove the city's lie.
         | 
         | Unless that article is seriously mischaracterising what
         | happened, I can't see how this is anything other than a massive
         | civil liberties infringement by the city, who are just trying
         | to scapegoat this Goodwolf person. All of the damages they are
         | describing were caused by their own negligence.
        
           | sillysaurusx wrote:
           | Retrieving publicly accessible data and then giving it to
           | anyone else is the problem when the data contains the
           | identities of witnesses for ongoing criminal investigations.
           | 
           | I'm really far on the side of hackers here, but I'm having
           | trouble justifying sending any data whatsoever to journalists
           | related to criminal investigations. Even one witness's name,
           | sent merely to prove that the breach happened, could be
           | enough to cause direct harm to that case if the reporter
           | decided to reveal it. You don't need to do that to show a
           | reporter that the breach happened. And it's up to the
           | reporter themselves to prove the breach is real.
        
             | Spivak wrote:
             | And that's why you send the data to reporters. Literally
             | the people whose job it is to handle this correctly. They
             | are the next stop when the city doesn't give you the time
             | of day. He didn't send it to some disreputable news
             | podcaster, they're the primary newspaper for the city.
        
             | dccoolgai wrote:
             | But that "harm" was caused by the City failing to secure
             | the data - not this one person who said "the city failed to
             | secure the data - anyone can get it".
        
               | sillysaurusx wrote:
               | Intent matters. The city was incompetent, but
               | distributing data about active criminal investigations is
               | malicious, or at least dangerous. And unlike Snowden, he
               | wasn't trying to expose abuses by sending the documents
               | to reporters.
               | 
               | Here's an example from my own life: I created books3, an
               | AI training dataset of almost 200k books. This was thanks
               | to The Eye, who hosted a copy of Bibliotik, a popular
               | shadow library. But everyone is suing the AI companies
               | themselves for using the training data, even though the
               | original harm was caused by The Eye and Bibliotik.
               | 
               | > not this one person who said "the city failed to secure
               | the data - anyone can get it".
               | 
               | If he simply said that, there wouldn't have been a
               | problem. He sent actual data related to ongoing criminal
               | investigations, and was on the record saying he might set
               | up a website to more widely disseminate information about
               | that data -- which could include names of witnesses in
               | those investigations.
        
             | nick238 wrote:
             | I mean, if the city keeps saying, "no, there wasn't any
             | data released", then maybe backs up and says "there wasn't
             | any _sensitive_ data released ", and keeps backing up, at
             | some point you need to cut to the chase and be like, "OK,
             | here's the most salacious shit possible. Explain that."
             | 
             | I don't know how to do that responsibly (just share it with
             | a reputable reporter?), but I definitely get the feeling if
             | you're constantly subjected to bad faith.
        
               | sillysaurusx wrote:
               | Oh, I agree. But let the reporters do that. It's their
               | job. Just point them towards the data and they'll do the
               | rest.
               | 
               | If someone's butt is going to be on the line, it should
               | be a corporation's (the news agency), or perhaps an
               | individual investigative journalist. Not you. Not for
               | something like this, anyway. If it was just social
               | security numbers I might agree with you, but police
               | databases are obviously dangerous to disseminate, even if
               | it's just to prove they exist. He could've sent redacted
               | screenshots.
               | 
               | Point being, we don't know what he sent, but sending
               | anything at all from a _police database_ is a bad idea.
               | No lawyer would ever say that that's legal, let alone
               | ethical.
        
               | rolph wrote:
               | i think i get it.
               | 
               | you are in danger but you dont need to know that, its not
               | your job to protect yourself, thats our job.
        
             | AmericanChopper wrote:
             | The people who compromised and published the data (and the
             | people who allowed them to do that) are responsible for
             | 100% of the harm caused here. Once the data has been
             | published, the harm is already done, and from a legal
             | perspective any questions about accessing it and further
             | communicating it are protected by 1A.
             | 
             | By the time Goodwolf got to the data, it had already been
             | compromised and published. The only way he could have
             | possibly contributed to the harm was by drawing attention
             | to it. If you take that perspective, then the city has
             | further contributed to that harm themselves by taking legal
             | action against Goodwolf. Furthermore, you could also
             | conclude from this argument that the city had some moral
             | responsibility to lie to the public about the nature of the
             | breach, and that all those who knew the truth would also
             | have the moral responsibility to protect that lie.
             | 
             | I would say this is an incredibly perverse position to
             | take. All of the data compromised in this breach was
             | already published, and in the hands of criminals. For
             | anybody whose data was included in this breach, the city
             | lying about it was just putting them in further jeopardy.
             | Now they will at least have the opportunity to learn about
             | the breach. The journalists are hardly likely to abuse it.
             | The only legitimate harm caused by Goodwolf was to harm the
             | integrity of the lying city officials. They deserve that
             | harm, and the other side of that coin is that the public
             | benefits when corruption is exposed.
        
             | rockskon wrote:
             | Unless I'm mistaken, the city lied about the data existing
             | in a form unusable to the hackers. That lie is, itself,
             | giving a false sense of security to witnesses for ongoing
             | criminal investigations. Witnesses whose data is data is
             | accessible on a website primarily (though not exclusively)
             | accessed by criminals.
             | 
             | As is described in the article, this is one of the best
             | cases of responsible disclosure I can think of in recent
             | memory - refuting a government lie that put at-risk
             | people's lives in danger.
        
               | kabdib wrote:
               | It looks fractally terrible, but:
               | 
               | > "This is not about speech. It's not. It's about the
               | actual action of > going on the keyboard, going into the
               | dark web, gathering the information, > downloading it to
               | your computer and then disseminating it to people > who
               | are in the press or otherwise," Klein said.
               | 
               | ... sounds a lot like free expression (especially when
               | the city is lying)
        
         | lima wrote:
         | This is data that criminals _already_ publicly released.
        
         | kayodelycaon wrote:
         | I happen to know this guy. He has an extremely bad reputation
         | in the furry community for doxing people and bringing up old
         | criminal records to publicly shame and cancel people. He
         | actively tries to hurt people.
         | 
         | He's about as far from an ethical hacker as you can be. He's on
         | a crusade.
         | 
         | Now that doesn't mean this should be illegal but I'm not on his
         | side.
        
           | someguydave wrote:
           | It could be that there are assholes on four sides here
           | (blackhat guys, city, whitehat guy, journalists)
        
           | Spivak wrote:
           | This is a bit "what were you doing at the devil's sacrament"
           | but I digress it's not that important.
           | 
           | You should be able to be the worst person in the world and
           | not hung for it. There's no reason to not be on his side, it
           | doesn't mean you endorse him. The other side is an
           | embarrassed government throwing their weight around to hang
           | him for what isn't and shouldn't be a crime.
        
             | tourmalinetaco wrote:
             | > You should be able to be the worst person in the world
             | and not hung for it.
             | 
             | Do you just believe that someone should be allowed to do
             | anything they want and not face repercussions?
        
               | kbelder wrote:
               | Well, they should be able to do anything they want that's
               | _legal_ without facing _legal_ repercussions.
        
               | tourmalinetaco wrote:
               | He's facing _civil_ repercussions. He, as a worker of the
               | city, disseminated information to the press that reveals
               | undercover police reports, witness names and testimonies,
               | and various other sensitive information. That may not be
               | illegal, but if he broke a contract or other agreement
               | then it's expected that he faces repercussions.
               | 
               | The city may be in the wrong for downplaying the
               | severity, but he's in the wrong for directly handing over
               | the hacked information he has to journalists.
        
               | Spivak wrote:
               | No, I'm saying your rights aren't conditional on whether
               | or not you're an asshole.
        
               | tourmalinetaco wrote:
               | They are, though, considering how poorly we treat non-
               | violent felons. That's beside the point though, because
               | his legal rights are not being infringed. Being sued and
               | being charged are completely different. One is civil, the
               | other is criminal.
        
               | sbuttgereit wrote:
               | Civil asset forfeiture is not criminal, but civil, and
               | the legal matter is against the property, not the
               | property owner. Still, I would argue that the property
               | owner's rights are often violated is such actions.
        
               | late2part wrote:
               | "against the property"
               | 
               | You probably think identity theft is a customer's
               | problem, not the bank too.
               | 
               | Just because the narrative calls it something, doesn't
               | make it right.
               | 
               | It's silly for a nation-state to sue cash, it should
               | never have been considered reasonable.
        
               | yimmothathird wrote:
               | Only if that person is me
        
             | foundry27 wrote:
             | It's easy to downvote and move on, but I don't think that
             | does justice to the valid underlying concerns this parent
             | comment raises. I don't agree with the idea that there's
             | "no reason" to question the guy's actions - because his
             | methods do raise serious ethical and safety concerns - but
             | I think it's right to caution against kneejerk reactions
             | that might lead to government overreach. We should be wary
             | of how power can be used to silence people, even if those
             | people did shitty things in the past or are controversial
             | figures.
             | 
             | Ignoring the underlying point being made won't make it go
             | away, and won't help educate any of our peers who might
             | take some of this stuff at face value.
        
               | andrewflnr wrote:
               | My recommended remedy is to write your own sibling
               | comment that makes the same point in a less downvotable
               | way. Most of us are against government overreach, but
               | we're against logical overreach too, and the GP comment
               | did a lot of that. Just not very well argued on a very
               | sensitive topic.
        
             | kayodelycaon wrote:
             | Law isn't black and white. Motives do matter in the US
             | legal system.
             | 
             | For an extreme example, murder requires intent. Most
             | computer crimes also fall into this.
             | 
             | In this case he crossed the line a professional security
             | researcher would not have by showing the data to a third
             | party.
        
           | summermusic wrote:
           | > Goodwolf is the name he uses for interviews and is not his
           | legal name.
           | 
           | I read this and immediately suspected that he is a furry
        
           | superkuh wrote:
           | Do you though? I could say the same about kayodelcaon, but
           | it'd be against HN rules just like your unsupported character
           | attack that addresses none of the legal claims against him
           | is.
           | 
           | The facts of it are that he did not do the hacking and did
           | not make the information information online. He's just
           | mirroring the easily available information because the city
           | was lying about it. That's journalism. If the city wants to
           | sue someone they should look internally and at the initial
           | hackers/posters of the information in public.
        
             | kayodelycaon wrote:
             | Take a look yourself at what others have said. Go to
             | en.wikifur.com and look at the Connor_Goodwolf page. That
             | doesn't even begin to scratch the surface. Even if you
             | think some of his causes are good, he does not do his due
             | diligence and does not care if he's wrong.
             | 
             | My personal experience is from my own conversations with
             | him and conversations with people in Cincinnati, Dayton,
             | and Columbus.
        
           | lupusreal wrote:
           | I looked this guy up on the furry wiki like you suggested and
           | it seems the "old criminal records" he tries to shame people
           | for are being sex offenders and animal abusers. I'm not
           | surprised to hear the furry community finds this is
           | controversial. _Gag_
           | 
           | > _Goodwolf maintains the K9 Sentry webpage and Facebook and
           | Twitter accounts._
           | 
           | > _K9 Sentry scours mainly the furry community 's main sites
           | and social media services[3] for signs of malfeasance
           | regarding those furries[4] involved in criminal activities of
           | sexual (sex child abuse, zoophilia, bestiality, etc) or
           | violent type (cruelty to animals et al)._
           | 
           | > _The site maintains several help services and
           | directories[5] to keep track of the convicted furs in the
           | fandom and keeps abreast of past and present cases by posting
           | the latest on the K9 Sentry site, its social media accounts,
           | and on the furry wiki, Wikifur._
        
             | kayodelycaon wrote:
             | Those aren't the only criminal records he brings up. I also
             | said:
             | 
             | > Even if you think some of his causes are good, he does
             | not do his due diligence and does not care if he's wrong.
             | 
             | If you can't see what I'm talking about, read the whole
             | list of everything he's done, read the article above, and
             | try to understand the person.
             | 
             | It is him, his methods, and the innocent people he has
             | harmed that are controversial, not the things he stands
             | against.
        
         | ang_cire wrote:
         | This was not "releasing" information, though, it was already
         | public. The "dark web" isn't someplace you require some special
         | invite-only connection to, it's just regular websites (even if
         | they use TOR) that anyone can access if they know where to
         | look.
        
           | unethical_ban wrote:
           | It is naive to suggest that it is equally easy for the
           | general public to search the dark web for an illicit data
           | breach vs. go to a a publicized website.
           | 
           | Hell, I am in infosec and it would probably take me a few
           | hours or more to find raw data. A grandma can click a website
           | on CBS and type a name.
        
           | tourmalinetaco wrote:
           | Except there is a reasonable chance that he distributed
           | illegally obtained uncensored data to people outside of the
           | investigation, while being part of the investigative team.
           | That's not something you do, even if it's not illegal.
        
             | bitnasty wrote:
             | > part of the investigative team
             | 
             | The article doesn't mention this...
        
         | rockskon wrote:
         | ????
         | 
         | I'm not quite certain what law he's accused of violating. He
         | didn't download the info from the gov website so there couldn't
         | be allegations of unauthorized access. He didn't hack the
         | website either.
         | 
         | What gives?
        
         | unethical_ban wrote:
         | This is an important distinction that the city fails to
         | articulate.
         | 
         | The city lied about the breach, so getting a restraining order
         | immediately looks petty and abusive.
         | 
         | But you make a good point that such a website would not
         | actually be useful. Anyone who is in those documents knows it,
         | and allowing the public web the ability to look people up by
         | name is dangerous.
         | 
         | The "hacker" is correct to speak loudly about the lies the city
         | told. He would be incorrect to create a lookup.
        
           | kmoser wrote:
           | > He would be incorrect to create a lookup.
           | 
           | Not if the lookup simply acknowledged whether a name exists
           | in the records, without giving other context (e.g. property
           | tax, DMV, criminal investigation, etc.).
        
         | tptacek wrote:
         | For what it's worth, he didn't generate this data from an
         | attack; he's just downloading it from Tor BBSs. The term
         | "cybersecurity expert" contains multitudes.
        
       | coding123 wrote:
       | > This is not about speech. It's not. It's about the actual
       | action of going on the keyboard, going into the dark web,
       | gathering the information, downloading it to your computer and
       | then disseminating it to people who are in the press or otherwise
       | 
       | Lol, unless the article is reporting something off, features like
       | Chrome or Firefox reporting one of your passwords may have been
       | compromised would be illegal.
       | 
       | The reality is that this city is wrong.
        
       | xbar wrote:
       | Embarrassed city sues annoying jerk who told everyone how full of
       | crap city should was.
       | 
       | Suing security researchers for investigating the contents of
       | disclosed information is ineffective at protecting anyone.
        
         | xyst wrote:
         | Reminds me of a story on Dark Net Diaries. Researchers are
         | hired by state to do physical penetration testing at some court
         | house in the middle of nowhere. Pentesters get caught.
         | Pentesters comply with security and local PD and explain
         | situation.
         | 
         | However some other asshole shows up to the scene claiming
         | jurisdiction (county sheriff?), raises hell, makes a random
         | call (county officials?), then arrest the pen testers on the
         | spot for B&E.
         | 
         | State leave them out to dry in some county jail cell. I think
         | the state ultimately ended up getting embarrassed and tried to
         | sue the company and pen testers for some civil damages and
         | pursue criminal charges.
         | 
         | In the end, they end up getting dropped and reputation of pen
         | testers were ruined for a period of time.
        
       | yieldcrv wrote:
       | Hacking syndicate: not sued
       | 
       | Public website hosting hacked records: not sued
       | 
       | Lying public servant: not sued
       | 
       | Joe Schmoe for pointing out all three: sued
        
       | nick238 wrote:
       | I wonder if the ideal way to expose this would have been to
       | approach some law firm showing that you (just you) were wronged
       | by the City, here's the data, some basic auditing showing where
       | it was from, statements by the city, hackers, etc.
       | 
       | Then just be like, yeah, there's like 3 TB of data there, maybe
       | it's class-action worthy, hint, hint.
        
       | jmyeet wrote:
       | "Let's go burn down the observatory so this will never happen
       | again."
        
         | kabdib wrote:
         | Our property values were great until they installed the
         | seismographs.
        
       | theginger wrote:
       | I get access denied to 10tv.com No idea why, do they ban UK / EU
       | readers?
        
         | lobsterthief wrote:
         | A lot of local news publishers in the US do that to save money
         | and not have to deal with compliance in other countries.
         | 
         | It's beyond stupid and lazy
        
         | xyst wrote:
         | even us readers with ad block get a paywall.
         | 
         | https://archive.ph/dEBJT
        
       | mmsc wrote:
       | Add it to the list: https://github.com/disclose/research-threats
        
       | xyst wrote:
       | This is wild. Researchers are simply pointing out how bad the
       | security system is for the City of Columbus, OH.
       | 
       | > On Aug. 13, Mayor Andrew Ginther said the data stolen by
       | hackers was either corrupted or encrypted, meaning it was likely
       | useless. Hours later, Goodwolf told 10TV that wasn't true and he
       | showed what kind of personal information he was able to access.
       | 
       | lol - the entire city leadership needs to be recalled. They get
       | caught with their pants down (no security), lie to the public
       | ("it's encrypted bro!1! trust me I'm a politician!!), lies get
       | rightfully called out, and their response is to pour gas on the
       | fire with this silly lawsuit funded by the local tax payers.
        
       | foundart wrote:
       | This seems like a better write up.
       | 
       | https://arstechnica.com/security/2024/08/city-of-columbus-su...
        
       ___________________________________________________________________
       (page generated 2024-08-30 23:00 UTC)