[PLUG] The lion in Salem
Cliff Wells
logiplex at qwest.net
Thu Aug 28 11:32:02 UTC 2003
On Wed, 2003-08-27 at 21:49, Dylan Reinhardt wrote:
> On Wed, 27 Aug 2003 16:25, David Pool wrote:
> > Maybe it's the transition to the threat that we're misunderstanding one
> > another. I've just asked that the damaging information be discussed
> > openly on a publicly archived list-serve. Once that's done, it's done.
>
> What damaging information? The damaging information you proposed to
> produce by unethical exploration of state servers?
>
> If you approach a politician and propose to promote the public
> discussion of embarrassing information, that's not an offer that will be
> much welcomed. Whether doing so is your right as a citizen or a
> criminal act depends in large part on the provenance of the information.
>
> If the information you want to discuss is already public or can be
> properly acquired, do what you want and let the will of the public
> prevail. But if you're proposing to acquire *privileged* information by
> *unethical* means, proposing to disclose it in public *is* a threat.
That depends upon what you mean by privileged and public. A server
attached to the Internet is by definition public. Running nmap against
it to see what ports are open and perhaps determine what software is on
it is not unethical. It might be illegal, but legality and ethics have
about as large an intersection as hot girls with big brains (apologies
to the OP of that comment).
> The fact that you're angling for business at the same time makes it look
> even worse. You probably didn't *intend* to suggest a quid pro quo, but
> that's exactly what a reasonable person would think you've done.
I for one, having a least a marginal sense of humor, didn't read the
posts regarding basing a "business" off of this too seriously. Anyone
who did should probably take a week off.
> > My idea of a threat implies an "or else". Like I'd take my new found
> > information about how easy it is to crack the entire system and call up
> > the speaker and threaten to crash the whole system if she doesn't do
> > what I want. (whether that's pass a bill or hire me as a consultant).
>
> That's almost exactly what your suggestion sounded like. Except for the
> "crashing the system" part... but you weren't going to *crash* the
> system, you were just promoting a frank and open exploration of its
> security flaws and let the chips fall where they may.
Let us all be assured that it doesn't take a discussion on a
not-so-widely-circulated mailing list to attract a hacker. I would say
that openly posting such info here would have exactly nil effect on
whether the state's systems get attacked or not. Personally, I find the
idea that confidential information, perhaps regarding you or myself
resides on unsecured systems. If they *are* secure, then discussing
them openly shouldn't be a problem, should it? The fact that even
*asking* about it raised such an alarm suggests that perhaps a lot of
people are afraid that the systems aren't secure. Now *I'm* alarmed.
>
> > I suppose I can't expect you to assume that I'm too morally upstanding
> > to do that.
>
> If you aren't able to acknowledge the seriousness of what what you
> proposed, why should your subsequent arguments hold weight?
That's illogical.
> > But, well, first of all, you don't threaten people publicly
> > about making something public.
>
> A threat does not have to be rational in order to be credible.
Agreed.
> > That's where it either doesn't make
> > sense, or you're assuming I'm a moron.
>
> You're assuming that a rational explanation for your actions is relevant
> or necessary. Honestly, I'm at a complete loss to explain what you did.
> I can't imagine how you thought you were advancing any cause at all.
Nor I, but the response was about as ridiculous as the query.
> > Well, look, if the state is running their systems in an illegal and
> > risky fashion
>
> That's a pretty big "if" you've got there.
Then why the fuss?
> Even assuming your unsupported conclusion as established fact...
>
> > I may well use that fact to
> > try to sell them a better system.
>
> ...your hubris is astonishing. Are you really *that* much smarter than
> the army of IT professionals the state already employs?
Comments about state workers aside, what makes you think numbers amounts
to competence? If anything the opposite is true. Perhaps you should
read "The Mythical Man-Month" to get a better idea of what I'm referring
to.
Additionally, as the number of staff increases, the level of
accountability decreases fairly proportionately. If the system were
hacked, who would be to blame (besides the hacker)? Probably no one in
particular.
> If I were the
> state, I'd be skeptical of anyone green enough to claim he can rebuild
> and improve a complex system without having examined it in any detail.
Rebuild? Who said rebuild? I thought "secure" was the operative word.
> > I can see how you could misread it the first time through. After several
> > explicit explainations of my intent
>
> I value results more than intentions. I can't imagine what you
> *intended* to accomplish, but I'll tell you loud and clear what I think
> you did: I think you embarrassed this community.
And you're adding to it.
> I promote open source by doing the hard work of listening to people's
> needs and delivering services they care enough about to actually pay
> for. As such, I feel entitled to point out that exercising a greater
> level of responsibility will go a lot further to promote open source
> than attempting to humiliate influential people in public.
That depends. Politicians often respond to nothing else. I don't think
that's the general case, but often it is. The speaker's ridiculous
position certainly suggests that perhaps she is among those for whom
only public ridicule (or corporate money) has any influence.
> > you basically either
> > believe I've got the best interests of my state in mind or that I'm
> > lying and am just a gold-digger who's not bright enough to threaten
> > people in private.
>
> I'm not attempting to plumb the depths of your psyche, David. I'm
> taking exception with your irresponsible behavior. That's it. I don't
> claim to know (nor do I *care* to know) what your state of mind was.
>
>
> > it
> > seems like people are implying that I'd publicly threaten a high level
> > politician
>
> Not implying, stating. You did it. You publicly threatened a high level
> politician. If you don't do anything else, I'd strongly consider
> sending her an apology.
I must have missed that. Not being a smart-ass here, but how about
reposting that bit for my edification. I've scoured David's emails for
the last few days and I thought I'd read them all, but apparently I
missed the one with the actual threat in it.
> It takes character to admit that you screwed up.
Agreed.
--
Cliff Wells, Software Engineer
Logiplex Corporation (www.logiplex.net)
(503) 978-6726 (800) 735-0555
More information about the PLUG
mailing list