TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Coalfire Comments on Penetration Tests for Iowa Judicial Branch

100 pointsby ajay-dover 5 years ago

8 comments

sullivanmattover 5 years ago
Here&#x27;s the scoping doc: <a href="https:&#x2F;&#x2F;iowacourts.gov&#x2F;static&#x2F;media&#x2F;cms&#x2F;Rules_of_Engag_E9D807B3D13D3.pdf" rel="nofollow">https:&#x2F;&#x2F;iowacourts.gov&#x2F;static&#x2F;media&#x2F;cms&#x2F;Rules_of_Engag_E9D80...</a><p>Some highlights include authorization to attempt entry by tail gating, lock picking, place devices once access has been gained, etc. It&#x27;s a total vindication for Coalfire (IMO).
评论 #21018087 未加载
评论 #21017971 未加载
评论 #21017986 未加载
equaluniqueover 5 years ago
There is a legend from the time of my Uncle&#x27;s tenure at the US DOJ. During the Clinton administration, he hired so-called hackers he met at DEF CON to conduct a pen test of an immigration processing center somewhere around New England. The hackers were given some form of &quot;get out of jail free card&quot; for use during the pen test. In spite of it, they were arrested anyway by the overzealous administrator of the center. My uncle&#x27;s group in the DOJ had a hard time getting those hackers out of jail, and when they finally came out, they were quite mad, since the whole fiasco had put their permanent records at risk of a bad mark. The pen test project was still on, and it seems they went to extra lengths to exact their revenge on that overzealous administrator. As proof of their total compromise of the immigration processing center, the then Attorney General Janet Reno received in the mail from a green card for a Kang G. Roo. Subsequently, said administrator was demoted and reassigned to some cold desolate part of Alaska. (So the story goes, anyway.)<p>Edit: The &quot;reassignment&quot; may have led to an almost-immediate resignation.
评论 #21018362 未加载
Slenthover 5 years ago
This article [1] seems to imply the reason for the arrest is a disagreement between the county sheriff&#x27;s department and the state as to who has the authority to sign off on them attempting to break in to the building.<p>[1] <a href="https:&#x2F;&#x2F;www.desmoinesregister.com&#x2F;story&#x2F;news&#x2F;crime-and-courts&#x2F;2019&#x2F;09&#x2F;18&#x2F;iowa-courts-dallas-county-courthouse-coalfire-contract-judicial-branch-test-security-ia-crime-arrest&#x2F;2356047001&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.desmoinesregister.com&#x2F;story&#x2F;news&#x2F;crime-and-court...</a>
评论 #21018009 未加载
评论 #21019910 未加载
评论 #21018091 未加载
matthewdgreenover 5 years ago
Why is this still going on? It made sense before when there was a possibility of confusion, but at this point it is <i>at worst</i> a mistake, not someone with intent to commit a crime. Are charges still being pressed?
评论 #21018206 未加载
评论 #21018346 未加载
评论 #21018848 未加载
评论 #21018112 未加载
exabrialover 5 years ago
Sounds like yet another over-zealous prosecutor hell bent on putting non-violent [and non-criminals] behind bars.
评论 #21017884 未加载
评论 #21017797 未加载
评论 #21019163 未加载
评论 #21017537 未加载
Animatsover 5 years ago
One of the many books on CIA training describes how they handle this. The CIA has written agreements with law enforcement in the areas where they do training exercises. Trainees are given a number to call. If they call it, someone from CIA HQ comes over, with, as one trainee put it, the &quot;rumored but never seen get out of jail free letter&quot;.<p>This usually means the trainee failed the exercise.
sandworm101over 5 years ago
&gt;&gt; It&#x27;s a total vindication for Coalfire (IMO)<p>But think about this from the perspective of the cops. The contract can get coalfire out of any liability for damage done to the building and any potential break and enter. That is consent between contracting parties. But an alarm was set off. The police were called. This isn&#x27;t exactly a case of them filing a false police report, but the police were indeed called under false pretenses.<p>I used to work in a building with remote monitoring and extensive security, including armed response (military). We did these tests monthly. But as soon as the alarm was triggered, someone was on the phone to the military police. If their supervisor decided to roll the cars and test his officer&#x27;s response time that was with his permission. We would never, ever, have insist that cops stop what they were doing, possibly something dangerous&#x2F;real&#x2F;important, and physically respond to our not-real security test.
评论 #21019961 未加载
heyflyguyover 5 years ago
Are these bot comments? Looks like a simple contractual misunderstanding, probably exasperated by a bureaucratic communication issue of some sort. I&#x27;m sure we&#x27;ll discover that coalfire had ducks in a row and Iowa didn&#x27;t know what they bought. Nobody communicated it and here we are.
评论 #21017758 未加载