TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Viewing website HTML code is not illegal or “hacking,” prof. tells Missouri gov.

97 点作者 glitcher超过 3 年前

6 条评论

tyingq超过 3 年前
Ah, so finally the detail. The site was apparently an ASP.NET site, and they were putting the whole SSN into the &quot;VIEWSTATE&quot; object.<p>Which looks something like this in the html:<p>&lt;input type=&quot;hidden&quot; name=&quot;__VIEWSTATE&quot; id=&quot;__VIEWSTATE&quot; value=&quot;BASE64STUFFHERE=&quot;&gt;<p>There is a choice to encrypt it, but I&#x27;m skeptical how useful that is, or that it was enabled in this case.<p>So the &quot;hack&quot; was &quot;view source&quot; -&gt; decode some base64 data sitting in plain sight.<p>Edit: A little bonus. This bizarre video from a PAC the governor started, still trying to call this &quot;hacking&quot;: <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=9IBPeRa7U8E" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=9IBPeRa7U8E</a>
评论 #28995110 未加载
评论 #29001775 未加载
breckenedge超过 3 年前
My biggest fear is that nothing comes of this. The elected representatives of Missouri are making accusations that should be laughed out of court.
评论 #28993008 未加载
评论 #28993351 未加载
_dg6h超过 3 年前
If you care about this issue, please consider signing this petition urging Governor Parson to apologize.<p><a href="https:&#x2F;&#x2F;www.change.org&#x2F;p&#x2F;governor-parson-apologize-to-st-louis-post-dispatch-which-responsibly-disclosed-data-leak" rel="nofollow">https:&#x2F;&#x2F;www.change.org&#x2F;p&#x2F;governor-parson-apologize-to-st-lou...</a><p>Do petitions accomplish much? I don&#x27;t know. Still, someone needs to tell this guy he&#x27;s an idiot.
评论 #28996970 未加载
wly_cdgr超过 3 年前
Incredible and terrifying that this needs to be explicitly asserted
literallyaduck超过 3 年前
Decoding viewstate might technically be illegal according to the DMCA, but shouldn&#x27;t be and if the journalist is convicted they should be immediately pardoned.
评论 #28995800 未加载
huatilla超过 3 年前
The Computer Fraud and Abuse Act outlaws &quot;unauthorized access&quot;. The website owner clearly did not authorize access to that, so the letter of the law may have been violated. Maybe the law should require malice, criminal intent, and actual harm to have happened for &quot;unauthorized access&quot; to be a crime.
评论 #28996379 未加载
评论 #28996895 未加载
评论 #29008605 未加载