- Joined
- Jan 17, 2021
- Posts
- 2,057
I wanted to make a separate thread about this because there's all kinds of stupidity to unpack here.
www.vice.com
Basically, someone wrote an incredibly shitty and insecure web app that exposed SSNs of employees right in the web page's source which anyone could view by right clicking on the page and selecting "View Source". A journalist discovered this and reported it to the sate government. Now the governor wants to prosecute the journalist for "hacking". WTF?
This article also makes a really good point that now no one will want to report issues like this for fear of being prosecuted. What an idiot governor.
www.theverge.com

Governor Wants to Prosecute Journalist Who Clicked ‘View Source’ on Government Site
A St. Louis Post-Dispatch journalist found 100,000 Social Security numbers exposed in a government website, and reported the flaw to the government.

Basically, someone wrote an incredibly shitty and insecure web app that exposed SSNs of employees right in the web page's source which anyone could view by right clicking on the page and selecting "View Source". A journalist discovered this and reported it to the sate government. Now the governor wants to prosecute the journalist for "hacking". WTF?
This article also makes a really good point that now no one will want to report issues like this for fear of being prosecuted. What an idiot governor.

Missouri governor threatens reporter who discovered state site spilling private info
A masterclass in how not to handle disclosures.
