TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

City of Columbus sues expert who exposed extent of cyberattack

311 点作者 hendler9 个月前

17 条评论

sillysaurusx9 个月前
Former pentester here. Though I’m largely sympathetic with Goodwolf, note that releasing actual data is almost always a bad idea. It’s why bug bounty programs have limited scope.<p>The city seems upset that he shared data about ongoing investigations and undercover police reports. Depending on what exactly he shared, it’s hard to fault the city for that. It doesn’t really matter where the data currently exists; grabbing it and handing it off to others is obviously not a good idea.<p>If his goal was to prove to the reporters that such data existed and was available for download, he had many options that didn’t require accessing the data: screenshot the forum posts, send links to the reporters, detail what kind of data was there without actually showing any of it, and so on.<p>Now, if that’s what he did, and the city is still reacting this way, that’s obviously abuse. But it doesn’t seem unreasonable to order someone to stop disseminating data about ongoing investigations to reporters. Would you want your private cases to be more widely spread?<p>I’m really sympathetic to him, because this is an easy mistake to make. Before I got into the industry, I thought that this was white hat hacking; it’s obviously good that he’s spreading awareness about the breach. But <i>how</i> you do it really matters.<p>(Caveat: I worked in the industry for about a year in 2016, so maybe things have changed. But I’d be shocked if distributing actual data from any breach was condoned by anyone who works as a pentester, even today.)<p>&gt; the city says Goodwolf is threatening to publicly share the city&#x27;s stolen data in the form of a website that he will create himself. Goodwolf previously told 10TV he does plan to set up a website, but it would only allow people to see if their name was part of the data breach.<p>This isn’t the same as setting up a site to see if your password was compromised. It could let anyone type in someone’s name and see whether they’re a witness in a criminal investigation.
评论 #41402931 未加载
评论 #41402962 未加载
评论 #41403559 未加载
评论 #41417417 未加载
评论 #41402966 未加载
评论 #41404058 未加载
评论 #41403666 未加载
评论 #41403886 未加载
评论 #41403044 未加载
评论 #41405305 未加载
passwordoops9 个月前
&quot;&quot;This is not about speech. It&#x27;s not. It&#x27;s about the actual action of going on the keyboard, going into the dark web, gathering the information, downloading it to your computer and then disseminating it to people who are in the press or otherwise,&quot; Klein said&quot;<p>No, this is about how you lied to your public about the nature and format of the data that <i>you</i> failed to protect
评论 #41403270 未加载
xyst9 个月前
This is wild. Researchers are simply pointing out how bad the security system is for the City of Columbus, OH.<p>&gt; On Aug. 13, Mayor Andrew Ginther said the data stolen by hackers was either corrupted or encrypted, meaning it was likely useless. Hours later, Goodwolf told 10TV that wasn&#x27;t true and he showed what kind of personal information he was able to access.<p>lol - the entire city leadership needs to be recalled. They get caught with their pants down (no security), lie to the public (“it’s encrypted bro!1! trust me I’m a politician!!), lies get rightfully called out, and their response is to pour gas on the fire with this silly lawsuit funded by the local tax payers.
评论 #41406063 未加载
xbar9 个月前
Embarrassed city sues annoying jerk who told everyone how full of crap city should was.<p>Suing security researchers for investigating the contents of disclosed information is ineffective at protecting anyone.
评论 #41404512 未加载
edm0nd9 个月前
A perfect case for the EFF or ACLU to pickup and help defend against such a silly and weaponized restraining order.
foundart9 个月前
This seems like a better write up.<p><a href="https:&#x2F;&#x2F;arstechnica.com&#x2F;security&#x2F;2024&#x2F;08&#x2F;city-of-columbus-sues-man-after-he-discloses-severity-of-ransomware-attack&#x2F;" rel="nofollow">https:&#x2F;&#x2F;arstechnica.com&#x2F;security&#x2F;2024&#x2F;08&#x2F;city-of-columbus-su...</a>
yieldcrv9 个月前
Hacking syndicate: not sued<p>Public website hosting hacked records: not sued<p>Lying public servant: not sued<p>Joe Schmoe for pointing out all three: sued
sva_9 个月前
<a href="https:&#x2F;&#x2F;archive.is&#x2F;dEBJT" rel="nofollow">https:&#x2F;&#x2F;archive.is&#x2F;dEBJT</a><p>(blocked in EU)
noobermin9 个月前
Lived in columbus for many years. This absolutely tracks. There&#x27;s something about being a blue city in a red state that makes the government rather brazen in protecting themselves.
coding1239 个月前
&gt; This is not about speech. It&#x27;s not. It&#x27;s about the actual action of going on the keyboard, going into the dark web, gathering the information, downloading it to your computer and then disseminating it to people who are in the press or otherwise<p>Lol, unless the article is reporting something off, features like Chrome or Firefox reporting one of your passwords may have been compromised would be illegal.<p>The reality is that this city is wrong.
mmsc9 个月前
Add it to the list: <a href="https:&#x2F;&#x2F;github.com&#x2F;disclose&#x2F;research-threats">https:&#x2F;&#x2F;github.com&#x2F;disclose&#x2F;research-threats</a>
josefritzishere9 个月前
This is a very clear case of a restraining order being used punatively. The body of first amendment case law is very clear. The city has no reasonabel expectation that they will win. Their intent is to restrain, and intimidate legitimate criticism.
评论 #41406088 未加载
theginger9 个月前
I get access denied to 10tv.com No idea why, do they ban UK &#x2F; EU readers?
评论 #41406122 未加载
评论 #41404271 未加载
评论 #41404527 未加载
nick2389 个月前
I wonder if the ideal way to expose this would have been to approach some law firm showing that you (just you) were wronged by the City, here&#x27;s the data, some basic auditing showing where it was from, statements by the city, hackers, etc.<p>Then just be like, yeah, there&#x27;s like 3 TB of data there, maybe it&#x27;s class-action worthy, hint, hint.
bell-cot9 个月前
Sounds like a straightforward 1st Amendment case.<p>Might there be any lawyers with opinions (&amp; disclaimers, obviously) in the house?
评论 #41401682 未加载
rolph9 个月前
i really wish the scarewords like darkweb would go away.<p>the internet is not google, no amount of sand over the head or in the eyes will change that.<p>Columbus officials chose to invalidate threat to public safety by way of misinformation, then retaliate when the threat and true situation was revealed.<p>keeping people ignorant of threatscape is not good government.<p>thinking the &#x27;darkweb&#x27; is some sort of containment by obscurity, is beyond naive.<p>the city of columbus is actually inhibiting a proper response and perpetuating a cavalier security stance.<p>this is not going unnoticed.<p>[1] [This is a bigger issue here&#x27;: Columbus resident wishes the city told residents about the data breach sooner]<p><a href="https:&#x2F;&#x2F;www.10tv.com&#x2F;article&#x2F;news&#x2F;local&#x2F;columbus-woman-wishes-the-city-told-residents-about-the-data-breach-sooner&#x2F;530-1c6ca9fe-3886-46c4-967d-cd30f20733f8" rel="nofollow">https:&#x2F;&#x2F;www.10tv.com&#x2F;article&#x2F;news&#x2F;local&#x2F;columbus-woman-wishe...</a><p>[2] Second class-action lawsuit, representing police and firefighters, filed against city after cyberattack<p><a href="https:&#x2F;&#x2F;www.10tv.com&#x2F;article&#x2F;news&#x2F;local&#x2F;second-class-action-lawsuit-is-filed-against-the-city-of-columbus&#x2F;530-96de3bf6-ed79-40b2-a324-b96677a015ef" rel="nofollow">https:&#x2F;&#x2F;www.10tv.com&#x2F;article&#x2F;news&#x2F;local&#x2F;second-class-action-...</a><p>[3] Ginther confirms personal information of Columbus residents exposed in cyberattack<p><a href="https:&#x2F;&#x2F;www.10tv.com&#x2F;article&#x2F;news&#x2F;local&#x2F;ginther-press-conference-columbus-data-breach&#x2F;530-97a4bc42-8140-47c1-ae8a-8c8d32381653" rel="nofollow">https:&#x2F;&#x2F;www.10tv.com&#x2F;article&#x2F;news&#x2F;local&#x2F;ginther-press-confer...</a>
评论 #41402795 未加载
评论 #41402807 未加载
jmyeet9 个月前
&quot;Let&#x27;s go burn down the observatory so this will never happen again.&quot;
评论 #41404045 未加载