[PLUG] The lion in Salem

Dylan Reinhardt plug at dylanreinhardt.com
Wed Aug 27 15:37:02 UTC 2003


On Wed, 27 Aug 2003 12:03:42, David Pool wrote:

[combining response to two separate posts]

> Dylan Reinhardt wrote:
> 
> > Once you allow yourself to feel entitled to be curious about someone
> > else's system, the line between hacking and cracking becomes razor thin.
> 
> Ah, there's a point of difference in our understanding. I consider the 
> state of Oregon's IT infrastructure "mine" in the sense that I help pay 
> for it and it stores data about me.

As a taxpayer, you are well within your rights to demand independent
audits.  You are not entitled to appoint yourself as auditor.


> Further, if only indirectly, as voters we get 
> to express our opinions about how well the state is managing our IT 
> resources.

Sure, express all you want.  Demand reports, audits and oversight. 
You're still not entitled to appoint yourself as auditor.


> > The desire to *probe* the security of systems that you are not
> > responsible for is something else entirely.  There is no strong case to
> > be made for your involvement at all... *particularly* not when you're
> > looking for a way to leverage personal gain.
> 
> Hm, I missed this the first read through. I'm missing your implications 
> somehow. What's the personal gain here?

Seriously?  OK...


Your PLUG post of Aug 26, 07:46
-----------------------------------
Perhaps the state of Oregon would be one of our first clients. Maybe the
Speaker of the House herself would want to know just how much the
pirated software in her office alone is worth in fines (not to mention 
the embarassment... which is priceless).
------


Your next PLUG post, Aug 26, 08:08:
-----------------------------------
I'm curious about how much of the state's e-mail is being served off of
"lion". Also, is that machine doing anything else (serving up web-pages 
with IIS perhaps)? Finally, is "lion" fully patched? [snip] Also,
frankly anything else anyone can legally reveal about the server would
be interesting. Obviously, if they are running un-registered proprietary
software, well, that would be worth mentioning.
------


You describe the state as a potential client and go on to strongly imply
that disclosure of embarrassing information might advance your cause.  

After conveying this all-but-naked threat to a leader in our government,
you proceed to seize upon a mail header as justification to ask for 
help exposing security lapses and finding damaging information.  

>From your posts, a reasonable person would probably conclude that you
intended to use this information as leverage to sell the state your
services.  Is the personal gain aspect coming into any better focus?  

Dylan





More information about the PLUG mailing list