TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Viewing website HTML code is not illegal or “hacking,” prof. tells Missouri gov.

97 pointsby glitcherover 3 years ago

6 comments

tyingqover 3 years ago
Ah, so finally the detail. The site was apparently an ASP.NET site, and they were putting the whole SSN into the &quot;VIEWSTATE&quot; object.<p>Which looks something like this in the html:<p>&lt;input type=&quot;hidden&quot; name=&quot;__VIEWSTATE&quot; id=&quot;__VIEWSTATE&quot; value=&quot;BASE64STUFFHERE=&quot;&gt;<p>There is a choice to encrypt it, but I&#x27;m skeptical how useful that is, or that it was enabled in this case.<p>So the &quot;hack&quot; was &quot;view source&quot; -&gt; decode some base64 data sitting in plain sight.<p>Edit: A little bonus. This bizarre video from a PAC the governor started, still trying to call this &quot;hacking&quot;: <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=9IBPeRa7U8E" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=9IBPeRa7U8E</a>
评论 #28995110 未加载
评论 #29001775 未加载
breckenedgeover 3 years ago
My biggest fear is that nothing comes of this. The elected representatives of Missouri are making accusations that should be laughed out of court.
评论 #28993008 未加载
评论 #28993351 未加载
_dg6hover 3 years ago
If you care about this issue, please consider signing this petition urging Governor Parson to apologize.<p><a href="https:&#x2F;&#x2F;www.change.org&#x2F;p&#x2F;governor-parson-apologize-to-st-louis-post-dispatch-which-responsibly-disclosed-data-leak" rel="nofollow">https:&#x2F;&#x2F;www.change.org&#x2F;p&#x2F;governor-parson-apologize-to-st-lou...</a><p>Do petitions accomplish much? I don&#x27;t know. Still, someone needs to tell this guy he&#x27;s an idiot.
评论 #28996970 未加载
wly_cdgrover 3 years ago
Incredible and terrifying that this needs to be explicitly asserted
literallyaduckover 3 years ago
Decoding viewstate might technically be illegal according to the DMCA, but shouldn&#x27;t be and if the journalist is convicted they should be immediately pardoned.
评论 #28995800 未加载
huatillaover 3 years ago
The Computer Fraud and Abuse Act outlaws &quot;unauthorized access&quot;. The website owner clearly did not authorize access to that, so the letter of the law may have been violated. Maybe the law should require malice, criminal intent, and actual harm to have happened for &quot;unauthorized access&quot; to be a crime.
评论 #28996379 未加载
评论 #28996895 未加载
评论 #29008605 未加载