Four years ago, Croatian government subsidised loans for buying properties. They used public money to help people without any savings to go in debt, so they can buy houses. Why? Because during the construction bubble, banks invested a lot in buildings that can't be sold (world crisis hit). Under disguise of helping young people getting their first property, they helped banks get rid of the dead capital and earn more money on loans. Subsidies went for interests for the first four years of payment.
What about rational hard working people who saved and didn't need a loan? They got nothing.
Why this wasn't in Washington Post? Government paying you to go in debt in a country high in debt isn't controversial, but banks cancelling it for people who can't pay it off is?
You think this move is bad for the banks and telco's? I bet it was their idea in the first place, government is too impotent and incompetent for anything. Throwing whole families out on the street is bad PR, for them and the government, and this way they can pay it off with some change money they were never going to see anyway.
If you are in business of finding vulnerabilities in IT systems, you should be aware of it. If for noting else, to save yourself form situations like this.
This guy is not a security professional (yet), but running vulnerability scanners on other people systems definitely puts him in context.
Good point, I wouldn't call reconnaissance hacking. For two reasons: 1) It's a passive method 2) It's not done on the attacked system.
Scanning is an active method and it's done on the attacked system. Web scanning is not the same as web crawling (downloading pages of the site). It include all kinds of invasive tests, like SQL Injection, XSS, command injection and other attack attempts. It can cause many kinds of problems, named here in this thread.
From security perspective, scanning is an attack. Everyone who uses these tools should be aware of this.
I explained my point below in more detail regarding the equation and why I think it should be remembered.
When someone is scanning your system and you haven't authorized it, you will definitively treat it as malicious. In a given moment, you don't care about attacker's inside motives, because your system is under attack and you better act accordingly.
I know a story about a guy who lost his job because of the unauthorized Nessus scanning in his company. Every story with a convicted hacker has some kind of a scanning tool (at least nmap) that was used in scanning phase, you can bet on it. Every scanning tool is an attack tool. In fact, scanners are most useful tools for any kind of attack, because they minimize amount of manual effort needed.
I don't know much about Canadian law, but most current laws forbid unauthorized access and _atempts_ of doing it.
Regarding this guy's intention, you're probably right. The main reason why I'm commenting here is that guys with good intentions don't get themselves in the trouble for not knowing what they're doing.
Finding vulnerabilities in software on your machine and hacking other people's systems are entirely different things. By testing software you're not violating anything (except maybe EULA for some licences). By hacking other people's systems, you're committing a crime.
> What do you think would Google do, if this student used scanner(or something else) on gmail and found bug and then told Google about it?
At first, they would treat it like an attack. Like almost any other company would do. I have no idea what would happen later.
You missed my point. Like I said, I'm not commenting the penalty. In my opinion, it's too hard. But this is only my opinion after hearing (just like you said) just one side of the story.
The main problem with unauthorized testing (putting aside technical problems) is that person who performs it is in _very_ difficult position explaining her intentions. She already did what is considered the _second_ stage in hacker attack. Until she can prove her good intentions, this is rightfully treated as a malicious attack.
This is what my equation means. I think everybody on this forum should be aware of this. Don't get yourself in trouble for not knowing this.
The actions of Mr. Al-Khabaz were unlawful and unethical. If he only accidentally found the flaw and reported it to the responsible person, things would be fine. But security testing without the permission of the system owner is the same as unauthorized access attempt!
I work as a security professional for 7 years, and I recently did a guest lecture on the college discussing the example like this. Most students were not aware where the problem is. Maybe it would help imagining how would story like this look in the physical world:
Let's suppose you come back home and find someone picking on your door lock with a lock picking tool. You ask him "what are you doing?" and he says "I'm just checking is your lock safe. I do it for your security." Would you believe him? Or would you call the police immediately, without asking him anything?
Let's add to this that security testing tools can sometimes degrade the tested system's performance or sometimes even crash it. In this case, it's not just unauthorized access attempt, but successful denial-of-service attack!
Never, ever, do a security testing of the system without the written permission of the system owner. If you get the permission, you will probably be asked to sign an NDA in return. You will also need to provide some information, like source IP address you're using and emergency contacts that can be used to stop the testing in case of problems (like crashes, etc.). This is the only lawful and ethical way to do these kind of procedures on someone else's system.
I'm not discussing if the penalty is OK in this case. It really doesn't matter if most people here cannot tell what he did wrong in the first place.
It's pretty clear why Kyle hasn't anticipated this kind of reaction to his project. After exposing his whole life online during his previous projects, he obviously lost kind of sensitivity most people have about their own privacy. He studied some laws and rules and decided it's OK, but it would be better if he asked some of his non privacy-stunt-artist friends what do they think about his idea. His story nicely shows how our ideas of ethics are influenced by our own personality and behavior, not just out environment.