Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The word "SQL injection attack" has the word "attack" right there in the name. It's not innocuous. And there are plenty of places you can go where you're permitted to perform the types of analysis you're talking about without repercussions. If you want to be a locksmith you don't wander your neighborhood randomly attempting to break into houses as part of your training.


Yes, it's called an attack, and defenses are a thing too. You can't learn to block if all comers are expressly forbidden from punching or feigning punching. This need not be a violent attack, it will not incorporate any weapons, and there is furthermore no concept of assault and battery against computer equipment. One should avoid any destruction of property when wearing the white hat. They are not "unauthorized" accesses, however. The supposed authorization controls have failed and the doors are really unlocked if the attack succeeds.

Which situation is preferable:

a) As a new business, I am contacted by a good Samaritan who informs me that my public website is vulnerable to a common attack. I take this information to my development staff and they verify that we are indeed vulnerable, then we fix it. Millions are saved. I send a thank-you note to my new friend in Samaria and maybe even write a check.

b) Good Samaritans are prevented from helping by laws that divide adept lever pullers into only two groups: the paid kind and the unauthorized kind. There are then never good Samaritans because every Samaritan needs to take steps to remain anonymous themselves before performing any deeds which could constitute "an attempt to obtain unintendedly authorized access".

It's clear that "The only reason to obscure the origin of a packet is in order to not be the one caught sending it." Anyone who does not want to get caught doing whatever they are doing, I think it follows obviously, can't possibly be helping but only up to no good. Now all Samaritans with knowledge of SQL injection are at odds with web service companies and all good and rational Samaritans do the smart thing and cease all helping. If anyone helps, they will do so anonymously; if they are identified, they will have to swear they only found the issue by accident and didn't even really know what to look for.

In (B), your ability to secure yourself is directly at odds with the amount of spare time those (real) hordes of bad Samaritans or other nationalities behind seven proxies can spare. Got unlimited money? If you can't pay for enough pen testing, well I hope you did security right because nobody is going to help you now. Is that really the preferable scenario?

We have varying degrees of laws protecting certain kinds of "Good Samaritans" in cases of medical emergency, they are on the books in every state. Unless or until it's an issue of something wrong on a computer. There is no such similar protection for any security pros or curious tinkerers.

People who legitimately stumbled onto vulnerable services are best advised to never report them to anyone and forget whatever issue they saw, or they are persecuted by the FBI and prosecuted through CFAA and other legal channels. This cannot be considered optimal!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: