TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

State Bar of California addresses breach of confidential data

209 点作者 borepop大约 3 年前

11 条评论

danso大约 3 年前
According to this LA Times [0] story, the records were apparently found on judyrecords.com, a project recently discussed in a Show HN [1]<p>&gt; <i>State Bar officials learned about the posted records on Feb. 24. As of Saturday night, all the confidential information that had been published on the website judyrecords.com — which included case numbers, file dates, information about the types of cases and their statuses, respondent and complaining witnesses names — had been removed, officials said.</i><p>&gt; <i>...Full case records were not published. Officials said they don’t know whether the published information was the result of a hacking incident. Judyrecords.com is a website that aggregates nationwide court case records.</i><p>edit: The &quot;Info&quot; link [2] on judyrecords.com has updates related to this event. It asserts that the confidential data was available on the CA Bar&#x27;s own website:<p>&gt; <i>These records were all (confidential &amp; non-confidential) previously publicly available at <a href="https:&#x2F;&#x2F;discipline.calbar.ca.gov" rel="nofollow">https:&#x2F;&#x2F;discipline.calbar.ca.gov</a> (now offline).</i><p>[0] <a href="https:&#x2F;&#x2F;www.latimes.com&#x2F;california&#x2F;story&#x2F;2022-02-27&#x2F;california-bar-investigates-possible-data-breach-after-discipline-records-published-online" rel="nofollow">https:&#x2F;&#x2F;www.latimes.com&#x2F;california&#x2F;story&#x2F;2022-02-27&#x2F;californ...</a><p>[1] <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=30399881" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=30399881</a><p>[2] <a href="https:&#x2F;&#x2F;www.judyrecords.com&#x2F;info" rel="nofollow">https:&#x2F;&#x2F;www.judyrecords.com&#x2F;info</a>
评论 #30503135 未加载
评论 #30502331 未加载
reset-password大约 3 年前
Why is it so impossible for these people&#x2F;organizations to accept that they made a mistake and own up to it? The entire response by the State Bar of California is nothing but a deflection of blame that rests solely on themselves and their chosen vendor(s).<p>What are they going to do next, call Missouri&#x27;s governor and ask for the playbook to follow? The humans behind the scenes at the bar are looking incredibly pathetic here.
评论 #30504221 未加载
评论 #30503109 未加载
评论 #30504890 未加载
评论 #30511470 未加载
评论 #30504473 未加载
评论 #30507655 未加载
评论 #30503124 未加载
ejb999大约 3 年前
Doesn&#x27;t sound like a breach to me - sounds like the state bar association inadvertently gave out the information, and now they are looking for someone to blame - someone else that is.
评论 #30502334 未加载
cyral大约 3 年前
&gt; We apologize to anyone who is affected by the website’s unlawful display of nonpublic data<p>Sounds like Missouri teachers SSN leak again... The website that judyrecords scraped, discipline.calbar.ca.gov, contained all of these &quot;nonpublic&quot; records for anyone to see.
评论 #30502890 未加载
adolph大约 3 年前
Apparently the State Bar has been breaking the law.<p><i>The State Bar announced today that it is taking urgent action to address a breach of confidential attorney discipline case data that it discovered on February 24. A public website that aggregates nationwide court case records was able to access and display limited case profile data on about 260,000 nonpublic State Bar attorney discipline case records, along with about 60,000 public State Bar Court case records. The site also appears to display confidential court records from other jurisdictions.</i><p><i>Under California Business and Professions Code 6086.1(b), all disciplinary investigations are confidential until the time that formal charges are filed, and all investigations are confidential until a formal proceeding is instituted.</i><p><i>The nonpublic case profile data from the State Bar appears to have been displayed on this public website in violation of this statute. It includes case number, file date, case type, case status, and respondent and complaining witness names. It does not include full case records. We do not yet know how many attorney or witness names were disclosed.</i>
评论 #30502585 未加载
tossitafter大约 3 年前
I used judyrecords to check myself after it was posted here. I had a charge from over a decade ago listed as a felony that had been reduced to a misdemeanor. The state system shows as a misdemeanor. I paid good money to an attorney for a misdemeanor. I&#x27;m not sure why judyrecords shows it as a felony, and it has me wondering about the effectiveness of my legal defense.<p>edit: If you&#x27;re wondering if I&#x27;m a hardened criminal with a wake of victims left behind, the answer is no. I was 22 and got caught in the midwest with an ounce and a half of cannabis. This website, as far as I&#x27;m concerned, is displaying inaccurate information about me that that could have serious negative consequences for myself.
评论 #30504628 未加载
gnicholas大约 3 年前
On a related note, the California Bar website employs dark patterns that mislead members into paying inflated annual dues.<p>When you renew your membership, there are a variety of addon payments you can opt into by checking boxes for these items. Then, on a later page, there are various addon payments that you have to opt out of.<p>Making things even trickier, these aren&#x27;t pre-checked boxes, which might lead the user to realize he needs to uncheck them. Instead, there is a list of &quot;adjustments&quot; with a dropdown menu for each. The dropdown defaults to &quot;none&quot;, which would lead users to think that they are not paying for an extra item. But when you click on the dropdown, you see the option to &quot;deduct $x&quot; if you don&#x27;t want to pay the additional fee.<p>I&#x27;ve never seen a dark pattern like this anywhere else. Perhaps the folks who run the calbar website could spend less time finding ways to trick members into overpaying and more time securing private information.
评论 #30504511 未加载
评论 #30506689 未加载
rahimnathwani大约 3 年前
&quot;Under California Business and Professions Code 6086.1(b), all disciplinary investigations are confidential until the time that formal charges are filed, and all investigations are confidential until a formal proceeding is instituted.&quot;<p>Does this part of the code apply to everyone, or only the folks in charge of the investigations, or in charge of safeguarding the information?<p>If someone is in a bar and overhears a Bar employee talking loudly about an investigation, do they have a legal duty to keep what they heard confidential?
评论 #30509046 未加载
user3939382大约 3 年前
This is probably a stupid question to those who work with these concepts often: can all the user data in the DB be hashed with the user’s password so that nothing is gained from a breach? Is this mostly a CPU resource problem or would would jwt architecture preclude that from working? (I haven’t built auth systems for several years)
评论 #30502295 未加载
评论 #30502716 未加载
评论 #30502298 未加载
评论 #30502251 未加载
评论 #30502567 未加载
评论 #30502243 未加载
评论 #30502255 未加载
bastardoperator大约 3 年前
Surprised this site isn&#x27;t managed by CDT (<a href="https:&#x2F;&#x2F;cdt.ca.gov&#x2F;" rel="nofollow">https:&#x2F;&#x2F;cdt.ca.gov&#x2F;</a>)
jahewson大约 3 年前
&gt; We take our obligations to protect confidential data with the utmost seriousness<p>Really?