Sued For "Hacking" With HTML

Поделиться
HTML-код
  • Опубликовано: 21 сен 2024

Комментарии • 2,4 тыс.

  • @3G2J
    @3G2J 2 года назад +1459

    Journalist: **Presses F12**
    Governor: *What they did is beyond unethical.*

    • @HauntGD
      @HauntGD Год назад +6

      55 likes and no comments, let me fix that.

    • @blackneos940
      @blackneos940 Год назад +2

      I'll help. :) There.

    • @billyboy8866
      @billyboy8866 9 месяцев назад +5

      I wonder what they would say if they really stole their data and sold it

    • @TomJakobW
      @TomJakobW 15 дней назад +2

      Blazing applause erupts from the NFT crowd (all 12 of them). “Show em, Mike!”, a moonbro named “HodlThePhone69” yells from within the crowd.

    • @bonniesitessolutions7728
      @bonniesitessolutions7728 2 дня назад +1

      What the governor did is beyond unethical!

  • @annawhite652
    @annawhite652 2 года назад +4332

    I hope the Governor gets sued because that’s just messed up that someone in good faith reports a bug and then gets threatened and slandered, also if there was a violation of law as the prosecutor said, I’d think it would be by the Missouri government for failing to secure sensitive data appropriately

    • @BellCube
      @BellCube 2 года назад +220

      (I'm not a lawyer, this is not legal advice, all that)
      Well... no matter how insecure, if the data is not publicly available, accessing it is considered unauthorized computer access, a crime in the US.
      Either way though, website HTML is-and always will be-open source (assuming no fancy obfuscation from the backend).
      Browsers allow you to view the HTML they're rendering for many reasons, chief among them are web development and debugging. However, it is not "unauthorized." If you send the data, there is no guarantee of how it will be parsed. Therefore, any competent lawyer can easily convince a competent judge that the data was publicly available. Decoding the Base64 (a medium of transfer) does not make it any less "publicly available." After all, if that were the case, you could make the same argument for literally anything on the internet because of binary.
      Unfortunately, poor security is not (yet) a crime in the US. I do hope that changes though.

    • @stumpywumpy2909
      @stumpywumpy2909 2 года назад +87

      @BellCube If you are holding classified information, hand it to a stranger, then they tell the government you did so: then you have the right to sue the person who gave it to you if you had to fight legal proceedings. That's literally what's going on here. There's nothing illegal about hitting f12, it's actually not accessing anything not already on the page. A brief example: if a page is the color magenta, then hitting f12 would just show you the hex# for magenta. Just saying he actually has a case to sue :)

    • @TheOzumat
      @TheOzumat 2 года назад +27

      End gerontocracy!

    • @BellCube
      @BellCube 2 года назад +20

      You're right, I missed that angle (hence the disclaimer). The information is itself classified.
      (The disclaimer from above still applies) Note that the plaintiffs would have to be the teachers in this case. That is, every teacher in Missouri could, at least in theory, sue. I see a Class-Action!
      As a side-note: LOVE that example!

    • @mycelia_ow
      @mycelia_ow 2 года назад +37

      @@BellCube you clearly didn't watch the video, or even 1/4th of it when you commented. He didn't "access private data" he viewed the sourced code which you can do right clicking a page, and reporting what he read. There was no crime, hacking, or anything negative happening here. End of story, no need to say anything more.

  • @FiReLScar
    @FiReLScar 2 года назад +802

    As a developer this hurts, I have lost about 300 brain cells just even seeing that governor’s face.

    • @TomJakobW
      @TomJakobW 15 дней назад +23

      I lost 4 months of my life, because I don’t think that blood pressure spike is healthy.

    • @mohammedothman5667
      @mohammedothman5667 7 дней назад +1

      I lost 10years of my life as madscientist kid at 11 who programs!

    • @FiReLScar
      @FiReLScar 7 дней назад +6

      @@mohammedothman5667 bro what?

    • @Halbolonenn
      @Halbolonenn 2 дня назад +3

      @@mohammedothman5667mad scientist?

    • @mikemikel1629
      @mikemikel1629 Час назад

      ​@@HalbolonennIt's so cool! Sonuvabitch.

  • @wojtekpolska1013
    @wojtekpolska1013 2 года назад +852

    "Decoded HTML source code"
    "Multi-step process"
    Im honestly surprised they didnt even consider getting an opinion from any cybersecurity expert before releasing that speech. they would've clarified everything in a few words. Due to a misconfigured server, it was telling everyone who wanted the Social Security number of any teacher.

    • @essem4979
      @essem4979 Год назад +60

      Lol literally EVERYONE who visited the website had those numbers, they simply didn't notice it

    • @user-6b7973
      @user-6b7973 Год назад +14

      the fact they could've just blacklisted those values instead of storing them in html just doesnt make sense. ntm base64 as "encryption"

    • @cdorman11
      @cdorman11 Месяц назад

      ​@@user-6b7973 They could have run the SS#s through a hash tag and stored them on a sequel server using a Tolkien ring.

    • @Stefan_-eh2bb
      @Stefan_-eh2bb 16 дней назад +24

      It wouldn’t even need to be an "expert", just literally anyone who has had a computer for some time and likes to try things

    • @pcfverbeek
      @pcfverbeek 16 дней назад +9

      This matter is a serious matter!

  • @ruhto828
    @ruhto828 2 года назад +636

    Once in IT class I used F12 to troll my friends. Then the teacher thought I was hacking the website and my parents needed to get to the school. How tf was that teacher teaching IT

    • @fss1704
      @fss1704 Год назад +22

      To be honest, you can do some crazy shit using f12 if you know how

    • @giviko1709
      @giviko1709 Год назад +115

      ​@@fss1704 you could if the website is THAT badly written.
      almost no modern website is THAT bad, basic security practices are used by almost every skilled dev

    • @fss1704
      @fss1704 Год назад +9

      @@giviko1709 You'd be really surprized at what you can do with some creativity

    • @ro0b0
      @ro0b0 3 месяца назад

      ​@@fss1704I really wouldn't

    • @TomJakobW
      @TomJakobW 15 дней назад +11

      Do you know that South Park episode where Mr. Mackey teaches computer class and the kids all just play Call of Duty (S12E14)?
      There’s your answer.

  • @pelic9608
    @pelic9608 2 года назад +2424

    $50 million to fix this?! 🤯
    That's it. I'm moving to Missouri! They obviously pay their programmers gooood. 😄

    • @St0RM33
      @St0RM33 2 года назад +68

      he meant damages..even when the issue was disclosed and fixed before the announcement.. seytonic didn't listen well but still what a CLOWN

    • @pelic9608
      @pelic9608 2 года назад +95

      @@St0RM33 The whole thing is a joke, my comment is a joke...
      You coming in here now being all serious looks less smart than you probably thought it would. 🙄

    • @coctailrob
      @coctailrob 2 года назад +13

      Plus the benefit of if you make an error someone else gets to be the scapegoat!

    • @NIGHTMARE-zy7tq
      @NIGHTMARE-zy7tq 2 года назад +6

      @Xi Jinping Sorry I wish that was true. My info was leaked by the VA, when an Admin left her computer in her car that was stolen. About 200,000 veteran's S.S where leaked.

    • @MarcCools1964
      @MarcCools1964 2 года назад +17

      I fix that for 49 million ... and I ain't even a programmer.

  • @nextlifeonearth
    @nextlifeonearth 2 года назад +288

    Those teachers should sue the government for literally sharing their social security number to anyone who asks, they just need to decode it.

    • @fss1704
      @fss1704 Год назад +26

      I would say they just need to read the language, even decode is a bad word for this situation

    • @MrRosco
      @MrRosco 8 месяцев назад +1

      they didn't even know this happened because if they don't stay up to date with politics they wouldn't have known this happened

    • @sc3dev
      @sc3dev День назад +3

      its base64 its barely even decoding just put it in a website/literal 3 line script and youre done

    • @thezipcreator
      @thezipcreator День назад

      @@sc3dev if you want to be technical, it is "decoding". what it isn't is "decrypting".
      "encoding" simply just means to put something in some data format, and "decoding" is taking it out. the text in this comment is encoded in something called UTF-8. your computer decodes it and turns it into characters you can see on your screen. things that are encoded are _meant_ to be decoded; this comment is encoded in UTF-8 so your browser can decode it and display it.
      meanwhile "encrypting" is to scramble something to make it purposefully hard to "decrypt" (i.e. see what the original message was).

    • @sc3dev
      @sc3dev День назад +1

      @@thezipcreator yeah

  • @fosytutorials9955
    @fosytutorials9955 10 дней назад +183

    Sueing a Bug Hunter is crazy.
    Actually should sue the State for Publicizing the SSN.

    • @variancewithin
      @variancewithin 21 час назад

      100%

    • @variancewithin
      @variancewithin 21 час назад +2

      I would do 2 counter sues, 1 for wasting my time and another for publishing social security numbers unencrypted

    • @watamatafoyu
      @watamatafoyu 8 часов назад

      How does an idiot understand it's an idiot? Especially if it has power over you.

  • @CrippleX89
    @CrippleX89 2 года назад +77

    "Governor Parson believes everyone is entitled to their privacy, ESPECIALLY OUR TEACHERS"
    THEN DONT FUCKING SEND UNENCRYPTED SOCIAL SECURITY NUMBERS OVER THE INTERNET IN THE FIRST PLACE!

  • @MyBinaryLife
    @MyBinaryLife 2 года назад +105

    This governor should resign. What a clown.

  • @v0rap
    @v0rap 2 года назад +1745

    This whole situation pissed me off so much when it was unfolding... This is the exact opposite of what you want to do against people who are responsibly disclosing security vulnerabilities. All this does is send the wrong signals and makes them look like idiots.

    • @OfficialPooYT
      @OfficialPooYT 2 года назад +84

      Helping is a crime now.. lol

    • @BjornGrylls
      @BjornGrylls 2 года назад +115

      Next time the journalist ain't gonna bother telling the gov. He'll be selling the SSNs, then creating a guide on wikiHow.

    • @v0rap
      @v0rap 2 года назад +68

      @@BjornGrylls Exactly... Responsible disclosure is something you should really encourage! Who'd want to do that if you run the risk of being sued?!

    • @friedrichdergroe9664
      @friedrichdergroe9664 2 года назад +32

      Those who designed the website are the ones who should be excoriated. There is no excuse for this. What moron would pump sensitive informaiton like social security numbers out like that?
      So sick of this itenerant nonsense. Next time they should try hiring someone other than a high school junior to do their site!!!!

    • @raginranga3494
      @raginranga3494 2 года назад +8

      @@friedrichdergroe9664 Probably a future dev idea that went into Production

  • @gFamWeb
    @gFamWeb 2 года назад +1033

    It's actually insane that they're claiming the journalist breached the teacher's privacy when it was actually the government themselves! That's like them leaving a file cabinet full of sensitive documents outside in public and then suing those who open it. Fucking ridiculous.

    • @terrsus7676
      @terrsus7676 2 года назад +31

      The hypocracy is real, but it's about money and power, even when unjust

    • @mkpanda
      @mkpanda 2 года назад +21

      I agree, but actually getting data by doing something (even just deleting "display: none" from the HTML) can be considered hacking in many countries (not sure about US). However, I don't think that people who report these bugs should be threatened, unless they misuse this knowledge.

    • @coctailrob
      @coctailrob 2 года назад +42

      Since the web servers effectively had already delivered the information to the web browser I would say it is more like delivering the information request by mail but also having another envelope enclosed with the SSN inside it.

    • @terrsus7676
      @terrsus7676 2 года назад +54

      @@mkpanda you didnt get the data yourself, it got sent to you. You press a key and can see what has been sent over to you.
      If this was a bad thing, why was it sent? Is it my responsibility that someone sends me data?
      Especially if i then don't do anything wirh said data, and report it to the government to fix?
      I'd consider hacking as doing things to manipulate the server, be it forgery and whatnot

    • @mkpanda
      @mkpanda 2 года назад +1

      @@terrsus7676 It is tricky, but yes, here it is that getting any data that you are not meant to see by manipulating the webpage in any way (even just viewing the source) counts as "hacking" and you can be sued for that. However if it is just sent to you and you never see the data, you can't be charged with anything (again depends on how you got the data, but in this case a normal user couldn't be charged with anything).

  • @adder23
    @adder23 2 года назад +523

    It's like they are shipping a box full of secret documents to you address. When you open it they sue you for breaking into their building and stealing documents.

    • @xliquidflames
      @xliquidflames 2 года назад +57

      Oh, that's good. I'm a sucker for a good analogy and that's a good one.

    • @justincombs7433
      @justincombs7433 2 года назад +32

      And that boys and girls is called entrapment.

    • @My1xT
      @My1xT 2 года назад +30

      @@xliquidflames i have an even better one. The ship a letter to you totally normal properly addressed to you and at the back of the paper they hid the SSNs but in Chinese number characters

    • @Xaddre
      @Xaddre 2 года назад +20

      It’s not even that it’s more like they ship you the box you open it see that it’s not your stuff and contact them to tell them they shipped you it on accident and they sue you for telling them.

    • @alexisroux2448
      @alexisroux2448 16 дней назад +2

      @@Xaddre so accurate tbh

  • @jstjerne1
    @jstjerne1 2 года назад +57

    Even toasting my fucking bread is a "multi step process"

    • @mrkoyunreis
      @mrkoyunreis 21 час назад

      Ah! The complex multi step process of pressing F12, Ctrl+C, googling "base 64", clicking the first result and Ctrl+V! The horror!

  • @TidalWaveDan
    @TidalWaveDan Год назад +77

    The Governor was very tech illiterate. His campaign manager spearheaded that whole thing. That being said the Governor was more than willing to participate in publicly shaming and attacking a law abiding citizen to score a few political points and appear to be tough on crimes. And, that’s why this country is in its twilight years as far as respect and greatness.

  • @mdo
    @mdo 2 года назад +569

    And this is how a well intended ethical hacker and security specialist says "Screw this shit" and goes to the dark side.

    • @essem4979
      @essem4979 Год назад +68

      If he sold those 100.000 security numbers on the dark web he would have made a lot of money, and avoid his life being basically ruined, so yeah people always make good guys regret their good actions

    • @oodlescanoodles
      @oodlescanoodles Год назад +8

      @@essem4979 he also probably would have been arrested lol

    • @essem4979
      @essem4979 Год назад +45

      @@oodlescanoodles people get away for much more serious stuff, he won't get caught if he knows how these things work

    • @oodlescanoodles
      @oodlescanoodles Год назад

      @@essem4979 idk man selling 100,000 peoples social security numbers on the deep web is pretty serious

    • @giviko1709
      @giviko1709 Год назад +14

      ​@@oodlescanoodles There's a lot of ways to avoid that lmao.
      Good guy for not doing that, so sad what happened

  • @niklas8565
    @niklas8565 2 года назад +300

    Now everybody knows that if they ever find a critical vulnerability by mistake on any official website of Missouri, they should never disclose it to anyone. The risk of getting sued for responsibly disclosing a security threat should be zero.

    • @danielbrenzel292
      @danielbrenzel292 2 года назад +29

      In germany a similar thing happend to a party. They sued the hacker, the prosecuter said. No breaking of "security functions". But the process was opened and the party got a fine for disclosing of personal data.

    • @niklas8565
      @niklas8565 2 года назад +5

      @@danielbrenzel292 Yeah, the CDUconnect app was not the most secure app 😅

    • @BlenderDefender
      @BlenderDefender 2 года назад +25

      @Niklas Wasn't the API public, just as the data in that website was? I can't understand why calling a public API should be a hack. It does not make sense. And it especially makes no sense to sue someone with good intentions. Why? That's like killing your dog for defending your home because it is a "dangerous animal that has hurt people". And in the end, you wonder, why you got robbed...

    • @niklas8565
      @niklas8565 2 года назад +14

      @@BlenderDefender by german definition this is not hacking. Public APIs are not called public for no reason 😅

    • @BlenderDefender
      @BlenderDefender 2 года назад +7

      @@niklas8565 Well, the CDU had another definition of hacking. Fortunately, the lawsuit was not successful.

  • @Fantasy2k
    @Fantasy2k 2 года назад +2134

    this multi-step video had me on the edge of my seat

    • @raginranga3494
      @raginranga3494 2 года назад +13

      Edgy words indeed

    • @semikolondev
      @semikolondev 2 года назад +37

      Multi step process is the jargon they use in USA.
      Open browser, f12, copy paste 64, type code or use software, the hack is complete.
      *multi step hacking of the world*

    • @dertythegrower
      @dertythegrower 2 года назад +6

      You are a bot, and you need to get a job kid because its obvious

    • @dertythegrower
      @dertythegrower 2 года назад +5

      Fantasy .. Yet another one of the (Dark verified comment bot nets)

    • @dertythegrower
      @dertythegrower 2 года назад +2

      @@semikolondev Dude, its a bot, you replied to a bot that uses a thesaurus... 100% for sure kid... lol

  • @TheRealBigYang
    @TheRealBigYang 6 дней назад +11

    Politicians should be banned from even talking about things they don't understand, but then they'd have to never talk again

  • @Silver_x86
    @Silver_x86 2 года назад +53

    The governor should take a real hard look at the consequences that would've occurred if this vulnerability hadn't been reported. To run the dudes name through the mud for protecting others is flat out inexcusable, and the governor should be punished.

    • @KathrynBrock1
      @KathrynBrock1 17 дней назад +5

      Exactly. They should be grateful this guy caught it, and not someone else. (Well, hopefully...)

  • @x0kosmus0x
    @x0kosmus0x 2 года назад +944

    I think this was a malicious attempt to shift the focus on the journalist and distract from the fact, that such a vulnerability should have never made it to production. Also the state should provide the teachers with some sort of security monitoring for the next years, because it's impossible to know how many social security numbers where stolen.

    • @Bvic3
      @Bvic3 2 года назад +61

      Never attribute to malice what can be explained by incompetence.
      It's a clear case of an incapable state administration that relies so much on overpriced contractors that they have nobody in house who understood what the problem was.
      And once the administrative started attacking, there was no way to back down without being even more ridiculous.

    • @spaghettiking653
      @spaghettiking653 2 года назад +27

      @@Bvic3 If an administration is incompetent, then it behooves everyone in the organization to take responsibility and frankly, oust any incompetent buffoons who put on a farce like this. Carrying out a government duty this negligently ought to be a crime.

    • @Bvic3
      @Bvic3 2 года назад +13

      @@spaghettiking653 It's a vicious cycle. The US culture of small government prevents the state to compete for useful services and forces the use of contractors.
      As a result, there is no prestige for working in state engineering. But still lots of money to distribute to contractors.
      As a result, capable and virtuous people avoid working for the state and you only get the power hungry morally bankrupt ones joining. And they partner with equally corrupt contractors.
      Meanwhile, in countries with a history of powerful states, it is prestigious to work for state enterprises and the most brilliant graduates each generate join the state.
      Given how the US is collapsing with its race warfare and overall rent seeking behaviours, the state isn't going to improve anytime soon.

    • @spaghettiking653
      @spaghettiking653 2 года назад +1

      @@Bvic3 I see. Thanks for the insight

    • @monsterhunter445
      @monsterhunter445 2 года назад

      Has the site been patched?

  • @9ofeX
    @9ofeX 2 года назад +178

    "decoded the html source code" Thats must be the funniest thing I heard today.

    • @cdorman11
      @cdorman11 Месяц назад +6

      Decoded it into...?

    • @Saver310
      @Saver310 10 дней назад

      ​@cdorman11 .txt obviously

    • @brys6577
      @brys6577 10 дней назад

      More html ​@@cdorman11

    • @byteafterlife
      @byteafterlife 9 дней назад +1

      frr

    • @LiEnby
      @LiEnby 3 дня назад +3

      its funny because it was found by specifically *not* decoding it

  • @newbunny93
    @newbunny93 2 года назад +138

    This Governor has clearly never accidentally hit the F12 key. "A multi step process to hack our systems" (Hacker presses F12) Guess I'm going to jail.

    • @Anvilshock
      @Anvilshock 2 года назад +8

      You know too much.

    • @tablettablete186
      @tablettablete186 2 года назад +17

      @@Anvilshock Image when he (the governor) finds out about JS and CSS!!!!

    • @Anvilshock
      @Anvilshock 2 года назад +19

      @@tablettablete186 Or un-hiding extensions for known filetypes.

    • @ronmcleod4717
      @ronmcleod4717 2 года назад +7

      "This Governor has clearly never accidentally hit the F12 key". I'm willing to bet that this guy doesn't even know how to use a computer.

    • @MrRosco
      @MrRosco 2 года назад +1

      @@ronmcleod4717 he doesn't have a pc in his office

  • @Holphana
    @Holphana 2 года назад +28

    The $50mil number comes from the security measures they will make to double check those social security accounts for fraud.
    It is ridiculously bloated and they use the highest estimate when the law gets involved as a bartering technique.

    • @Nords555
      @Nords555 10 дней назад

      ...as a....

  • @TheBrotherHolmes
    @TheBrotherHolmes День назад +2

    The Governor should pay the guy and publish a public apology video.

  • @valletas
    @valletas 2 года назад +180

    Honestely i hate this kind of crap
    When a politician decides to fuck over someones life just for his campaign

    • @ph33d
      @ph33d 2 года назад +2

      And to my understanding, Gov. Hee Haw isn't even running for re-election. He embarrassed himself merely for the pleasure of trying to "stiggit" to the Post Dispatch. You see, Missouri Republicans hate the free press.

    • @The-Devils-Advocate
      @The-Devils-Advocate 2 года назад +1

      Nice pfp

    • @atlrvrse
      @atlrvrse 2 года назад +3

      based pfp

  • @RipVanWinkle_Nature_Discovery
    @RipVanWinkle_Nature_Discovery 2 года назад +387

    Both. Stupid AND malicious. The reporter should definitely sue.

    • @danieleremin1924
      @danieleremin1924 2 года назад +11

      Uno reverse card

    • @Tyler-jd3ex
      @Tyler-jd3ex 2 года назад +6

      absolutely.

    • @samuelgibson780
      @samuelgibson780 2 года назад +8

      Well you can't let lawmakers get away with something that absurd. This is why math and tech literacy are so vital. Nobody who was informed would have called that "hacking" and it's dangerous to let anyone do so. That's how progress and science get stifled. I am not a lawyer, but I get the feeling the ACLU would have a field day with that one.

    • @samuelgibson780
      @samuelgibson780 2 года назад +2

      I don't know if they would need to sue them for money to make the point, but there should be some public awareness about what really constitutes malicious "hacking" versus what is a laudable exploration of technology and/or math. Seems like the kind of thing the ACLU would be interested in protecting.

  • @volactic8495
    @volactic8495 2 года назад +80

    This is a prime example of why states should have "technical courts" where the judge is a technically literate person who actually knows what he's talking about

    • @reprovedcandy
      @reprovedcandy Год назад +2

      judges need law degrees.. not too many technical people with law degrees

    • @volactic8495
      @volactic8495 Год назад +9

      @@reprovedcandy That's true but with the amount of technology that will be in the future, they could at least have someone on standby who is technically literate to help the judge better understand what happening.

    • @TomJakobW
      @TomJakobW 15 дней назад

      ⁠​⁠@@volactic8495 well, that’s what external experts are for. In this sense, reprovedcandy is right: if you combine competences too much, you won’t have enough people who can do it. This ain’t gonna work in practice.
      There are procedures for this. Apparently, they aren’t good enough.

    • @KeeganKopas
      @KeeganKopas 5 дней назад +2

      What's really needed IMO is just general technical education. In a court room, experts are frequently brought in to explain these sorts of things. What's disgusting is the fact that this sort of case was even considered. If we're going to build a society reliant entirely on technology, people needed to have at least a basic concept of how it works.

  • @ardurabangarang7397
    @ardurabangarang7397 2 года назад +6

    2:50 H..T..M..L
    Don't remember the last time someone said it that slowly

  • @MasterBroNetwork
    @MasterBroNetwork 16 дней назад +6

    *presses CTRL + SHIFT + I or F12 while in browser*
    Missouri: You're getting sued.

  • @jameschapin7150
    @jameschapin7150 2 года назад +352

    I can’t even begin to explain how many times non-technical execs and program managers have had no clue what is going on with the technology that they rely on for business.
    This is not a hack. This is a simple step that should have been followed by their development team to verify the security policy compliance of their code before pushing it to production.
    It’s deplorable that malicious ignorance results in attacks on good Samaritans. Then people don’t understand why the sense of community has disappeared from our hometowns and favorite places to visit.
    Thanks for pointing out this story. This ignorance deserves to be put in check.

    • @shapelessed
      @shapelessed 2 года назад +21

      Literally all they had to do is to install postman, thunder client or other similar software/IDE extension and fiddle with the API a little to see how it handles malformed input and what it responds with... Hearing about all of this I bet they've got some SQL injection just waiting there to wreck their backend completely...

    • @ggtechno9093
      @ggtechno9093 2 года назад +16

      Like how the hell do you sue someone for using F12, that's a feature built-in to all most every web browser and like, if you get hack using this, it is your bad web lmao

    • @raginranga3494
      @raginranga3494 2 года назад +3

      @@shapelessed and 1=1 should let you know without trying

    • @henrym5034
      @henrym5034 2 года назад +3

      @@raginranga3494 a multi-step process

    • @terrsus7676
      @terrsus7676 2 года назад +9

      @@henrym5034 yeah.
      1. Observe screen
      2. Respond by moving your index finger to the F12 key
      3. Move it downwards, this will cause the key to be pressed down.
      Hacker

  • @bina7513
    @bina7513 2 года назад +363

    This is both super stupid and malicious on the part of the government. F12 is something everyone can use and the journalist just found a vulnerability in the website. If anything, the journalist should be thanked for doing a service.

  • @FF-px4qm
    @FF-px4qm 2 года назад +156

    It´s frightening to see someone with so much power putting someone through hell due to stupidity and opportunism. I sincerely hope the journalist gets reimbursed and the governor put in his place. Shamefull behavior.

    • @terrsus7676
      @terrsus7676 2 года назад +5

      Blown up to epic proportions. Had no ground, so made some with lies and confidence.

    • @justincombs7433
      @justincombs7433 2 года назад +13

      @@terrsus7676 that's called an agenda. Missouri's governor is not known for his insight, flexibility, or openness.

    • @ReflectedMiles
      @ReflectedMiles 2 года назад +3

      @@justincombs7433 He has made every effort to mirror Trump, making no secret of it.

    • @amberhide04
      @amberhide04 2 года назад +2

      He should be the one getting 50 Million dollars lmao

    • @lateral1385
      @lateral1385 Год назад

      The “governor”belongs in a nursing home.

  • @NoobieNoodle89
    @NoobieNoodle89 10 дней назад +4

    Shameful. A reporter discovered a ridiculous bug and reported it, but the government is too embarrassed to accept the fact that they are not doing a great job of protecting important datas for their people, and they proceed to blackmail the reporter. Shameful.

  • @Firazoid
    @Firazoid 2 года назад +8

    I actually wrote up a paper on this for one of my college classes. I decided to print out the HTML of an NPR article that I used as a reference, because at the top of their page is a "Now Hiring Programmers" box that you can only see by looking at the source code.
    Obviously this is a fairly common practice, but I thought it would resonate more with the person grading my paper if they actually saw it with their own eyes what this journalist is being attacked for doing.

  • @whothis8933
    @whothis8933 2 года назад +188

    Wonder if they fooled him into believing this "html hack" was so sophisticated it would cost $50m to fix.

    • @XORA-CODEYX
      @XORA-CODEYX 2 года назад +38

      They just need another reason to burn tax payers money. How else would you justify taking high taxes if they aren't spend on the spot

    • @weston5614
      @weston5614 2 года назад +13

      I swear I heard him say "HTLM"

    • @trueriver1950
      @trueriver1950 2 года назад +4

      I am wondering if that's what the State paid to have it fixed...

    • @justincombs7433
      @justincombs7433 2 года назад +10

      @@trueriver1950 probably. It's probably some rule that they have to use an outside vendor for this and when a vendor said "Sure! " they charged them for their stupidity.

    • @forbiddenera
      @forbiddenera 2 года назад +7

      @@weston5614 htm ellen

  • @Top10AnimeBetrayals
    @Top10AnimeBetrayals 2 года назад +282

    There seriously needs to be an age limit for people in government. If the internet is still foreign to them, they should start living in a retirement home

    • @RaposaCadela
      @RaposaCadela 2 года назад +7

      word

    • @mickl3073
      @mickl3073 2 года назад +1

      wow someone has daddy issues; calm down there tiger.

    • @blzrL
      @blzrL 2 года назад +49

      @@mickl3073 nice ad hominem fallacy
      but you shouldnt be in any sort of power of any part of the US if you cant even use something as important as the internet

    • @blzrL
      @blzrL 2 года назад +28

      @@PefectPiePlace2 really not, if someones going to have power such as this they should be able to keep up in the modern world.

    • @majestic-domination
      @majestic-domination 2 года назад +38

      @@PefectPiePlace2 If the ones in power are so behind in times that they don't even understand how the internet works, then they're in no position to make any claims or judgements about anything related to it.

  • @relo999
    @relo999 2 года назад +68

    Government: sends teachers' private in nearly plain text information to everyone
    Journalist: "you got an issue, please fix"
    Government: WE'VE BEEN HACKED!

  • @imaperson1060
    @imaperson1060 2 года назад +10

    How did nobody find this sooner? Also, how did that journalist have to get a lawyer? If anything, the government violated the teacher's privacy by sending the data in the first place.

    • @roberto8650
      @roberto8650 День назад

      Why wouldn't he have to get a lawyer?

    • @imaperson1060
      @imaperson1060 День назад

      @@roberto8650 i mean, sure, it's still a lawsuit. but it's such a baseless accusation that shouldn't even go to court. "the defendant is charged for pressing a key on his keyboard and revealing information leaked by a government website."

  • @feelincrispy7053
    @feelincrispy7053 2 года назад +6

    Our ‘fuck up’ is going cost you the ordinary tax payer 50million because of this malicious attack.
    * behind closed doors “ we’ve done it Gary! We are going to be rich! Pay that programmer $500 to fix the bug and let’s get the fuck out of here”

  • @wisteela
    @wisteela 2 года назад +101

    "clearly a hack"
    Clearly wasn't
    Seen this covered by somebody before, but this has more detail, and is much better.
    Makes me want to press F12 more.

    • @terrsus7676
      @terrsus7676 2 года назад +11

      Don't you'll run into legal trouble viewing public information!

    • @justincombs7433
      @justincombs7433 2 года назад +9

      You'd be surprised how much BAD web design is out there. Granted, it's waaay better than it used to be, but for rural and small government offices? It's a joke.

    • @chri-k
      @chri-k 2 года назад +3

      but the decoded the h.t.m.ellen trough a multi-step process!!!!!

  • @theguy920
    @theguy920 2 года назад +89

    You do have to be really careful, I did something similar to this, but with my schools email software (I emailed one other student, which was not supposed to be possible), and got kicked out of my tech classes (in fear of the future) and suspended for a week (later reduced to 1 day). People are stupid, and no matter how many times you explain things to them, they will still be stupid

    • @danmakufan
      @danmakufan 2 года назад +13

      my school had the same initial password for their LMS accounts so I literally had to tell people to change their passwords
      I got into like 2 or 3 random accounts at that time lmao

    • @skilledscript2725
      @skilledscript2725 2 года назад +10

      @@danmakufan Same thing with me lol, I was on a random school computer once and somebody had their account saved (but logged out) so i tried putting in the initial passcode and it worked.

    • @skilledscript2725
      @skilledscript2725 2 года назад +9

      although, my school does say that people should change their passwords when they first login but people dont care

    • @_underscore_9271
      @_underscore_9271 2 года назад +16

      My school exclusively used chrome os, left the terminal so it could be used, and left devmode on, I found out that you could type anybody's username in (which being on chrome was their publicly available, school assigned email address)
      And the terminal would return their email/computer password.
      And on another occasion, I found out that one of the teachers used "admin1" as her username, and password to the unrestricted internet,
      I don't think my school put much thought towards security

    • @skilledscript2725
      @skilledscript2725 2 года назад +5

      @@_underscore_9271 bruhhh atleast my school disables linux terminal lmao. Crosh shell isnt though

  •  2 года назад +332

    Such an absolute embarrassment to everyone involved

    • @dertythegrower
      @dertythegrower 2 года назад +23

      Yet another one of the (Dark verified comment bot nets)
      Crazy=100% bot, for sure.. reselling accounts, just like Dark, X, A, B, and all the other verified Dark bots

    • @hypenheimer
      @hypenheimer 2 года назад +12

      bot

    • @emilyisoffline
      @emilyisoffline 2 года назад +8

      @@dertythegrower you are on a seytonic video but dont know the definition of a botnet lol

    • @sierra991
      @sierra991 2 года назад +10

      @@emilyisoffline it's not a botnet. it's an account that copies other liked comments

    • @emilyisoffline
      @emilyisoffline 2 года назад

      @@sierra991 I know what it is. That is my point. They do not know what they are saying lmao

  • @GameMaker3_5
    @GameMaker3_5 8 дней назад +4

    As a citizen of Kansas, I'm encouraged to laugh at Missouri for being this silly!

  • @jordankittle
    @jordankittle 9 дней назад +3

    This is incredibly shameful. He has no idea what HTML is.

  • @brostrod
    @brostrod 2 года назад +16

    Journalist: *Reports bug privately and responsibly, not revealing any information to the public and not causing "Major embarrassment"*
    Governor: THIS'LL COST MILLIONS

  • @driedbrainfreeze2149
    @driedbrainfreeze2149 2 года назад +26

    This is how tech savvy the average US politician is, and why ransomeware works so well in the States

    • @LustigerName
      @LustigerName 2 года назад

      We Germans simply avoid all cyber attacks not through cyber security, but through good ol' fax machines

  • @Rockyzach88
    @Rockyzach88 День назад +2

    I remember this. Lol saying that it would cost you 50 million dollars in damages is a self report. If your government is that inefficient they have serious problems.

  • @Xalzia
    @Xalzia 2 года назад +3

    The only one that should get sued is the one in charge of maintaining the website by the teachers

  • @kyouhyung
    @kyouhyung 2 года назад +14

    This level of technical ignorance by politicians should warrant an impeachment of that person. Whether it was pure incompetence or there was a malicious intent, it's equally disturbing and unacceptable.

  • @patchstep
    @patchstep 2 года назад +15

    the level of digital illiteracy in the us government is frankly frightening and infuriating.
    Yes, it's highly unethical that the teachers' private information was able to be abused but it was in no way the fault of the reporter, just the complete and utter incompetence of the state of missouri.

  • @aninstantramen9994
    @aninstantramen9994 2 года назад +52

    I just hate how they always act so sure of themselves, and then get angry at others for calling them out for their bullshit

  • @official_kex
    @official_kex 10 дней назад +2

    I got sued once for making a server admin aware that hes running a outdated server version of Teamspeak 3, that had a serious vulnerability.
    You really can't make this sh*t up anymore..

  • @joachimtheboss5326
    @joachimtheboss5326 2 года назад +3

    Its like 'cheating' on a test where the answers where already given.

  • @dannywhittaker978
    @dannywhittaker978 2 года назад +28

    This video had me in tears. I wish I could've become a pentester by simply viewing a public webpage and decoding a b64 string. I would've saved so much money

    • @westbrook0853
      @westbrook0853 6 дней назад +3

      It was actually an incredibly sophisticated multi-step process that involved decoding the encoded html source code

  • @y_strikes2770
    @y_strikes2770 2 года назад +28

    Politicians nowadays are literally every movie that says "I'll create a GUI interface to trace the IP address on the mainframe"

    • @ngkngk875
      @ngkngk875 2 года назад +7

      Going to need a lot of RAM to do that

    • @ThePC007
      @ThePC007 2 года назад +4

      @@ngkngk875 Nah, a Gigabyte of RAM should do the trick.

    • @starleaf-luna
      @starleaf-luna 2 года назад +1

      @@ThePC007 you sure you don't need a good motherboard with 10 ram boards with 4gb each?

    • @knownas2017
      @knownas2017 2 года назад +1

      It appears you have a feedback loop in the induction coils of your DB3 signal processor.

    • @regav62
      @regav62 2 года назад +1

      Extra underrated

  • @kurtsanches8819
    @kurtsanches8819 2 года назад +98

    Hope the Journalist set up a crowd funding for this event, if he doesn't have the budget to fight, I'm sure a lot of people who understand exactly what is happening here are willing to help, including myself.

    • @guptabhishek
      @guptabhishek 2 года назад +7

      I'm from India and I'd donate to this

    • @nietur
      @nietur 2 года назад

      @@guptabhishek go care about your own problems, rly

    • @WolfJustWolf
      @WolfJustWolf 2 года назад

      I'm in.

  • @alubhau
    @alubhau 2 года назад +4

    1:21 it's just a way of displaying text, like text can be displayed in morse code or binary, or French 😭

  • @anonym1984
    @anonym1984 7 дней назад +1

    Reminds me of that great multi-step bank heist I committed when I was a kid; I went to the local savings bank, deposited some cash I had made shovelling snow for my neighbours, took a piece of candy from the bowl at the counter, and when offered by the teller said I had already taken one but was told I could have another for being such a nice young man.
    These two pieces of candy cost my local savings bank at least 40 trillion dollars, and is the clear reason why it closed down. I have yet to be brought to justice and still take candy when offered to this day.

  • @midimusicforever
    @midimusicforever 2 года назад +36

    Someone should get sued, but it's not the journalist!

  • @cpuuk
    @cpuuk 2 года назад +21

    First casualty in Politics is the truth- this was just something to score political brownie point. If I was the 100,000 teachers I'd sue the State for shoddy workmanship under their state Data Protection.

  • @awake31337
    @awake31337 2 года назад +17

    the same thing happened to me when I tried to responsibly disclose ppi being leaked by a pager vendor. I was thanked by the IT at the health care provider, then served a cease and desist by the vendor.

    • @vimicito
      @vimicito 2 дня назад

      For shame on the vendor’s part, but that’s why you can go public after 90 days I guess. PR wankery on the vendor’s part should never be the MO when it actively hurts their security posture. Did you publicly disclose it in the end? And did they fix it in time?

  • @Julian-pw5mv
    @Julian-pw5mv 2 года назад +2

    I love how they call it a multi-step hack, when its literally one click of the f12 button.

  • @brandonz404
    @brandonz404 Год назад +1

    Is our governor actually this incompetent? A simple Google search could've prevented this embarrassment. Also I'm pissed for that journalist. He did the right thing and got sued for it.

  • @awgybop1
    @awgybop1 2 года назад +15

    This is the equivalent of sending someone a letter in the mail with accidental personal information left in it, and then the recipient getting sued for reading it.

    • @Buglin_Burger7878
      @Buglin_Burger7878 2 года назад +1

      I believe mail is actually protected by Federal Law at least in the US and you can actually get in trouble for that. I could be mistaken, but you're willfully opening the letter you know is not for you and can read who is the sender.
      So you'll know it is information you should not be viewing, should not have gotten this, and should not open this.
      In the case of F12 you're looking at the information sent to you, or a letter sent to you for you with information they didn't mean to give you.

    • @awgybop1
      @awgybop1 2 года назад +9

      @@Buglin_Burger7878 My example implies that the recipient of the letter was the intended recipient, but the sender accidentally left private information in the letter, and then sued the recipient for reading the letter that was addressed to them.

  • @lawrenceplays
    @lawrenceplays 2 года назад +28

    I think especially since this was politician making the claims of "hacking" he was playing the malicious card as a way of diverting the attention away from his governments flaws, and when that back fired he played dumb.

    • @xliquidflames
      @xliquidflames 2 года назад +6

      That's exactly what I said in my comment. If it got out that their website was _that insecure,_ it would be a huge embarrassment. The governor seems like a savy, career politician. He knew exactly how to spin an embarrassment into a campaign strength. The reporter was a convenient scapegoat. Luckily for the journalist, everyone saw right through it.

    • @akiranara6404
      @akiranara6404 2 года назад

      @@xliquidflames Unfortunately, I doubt everyone was that smart. Unless his opponent's PAC used it to attack him; I could definitely see that happening.

  • @mariolol8333
    @mariolol8333 2 года назад +6

    that's actually really sad. how can such powerful people not even have a normal basic understanding of the internet

  • @Cyberlisk
    @Cyberlisk День назад +1

    We had something similar in Germany, an app from our conservative party had a security issue where you could get personal data by using an open REST API (aka just typing the right URL to your browser). A hacker informed the party about that, and as a response, they tried to sue her.
    That some people actually vote for guys like that to run our country baffles me every time.

  • @handlingitwell
    @handlingitwell 2 года назад +4

    Any infant could have pressed F12 and 'accidentally' copy-pasted the information somewhere. I was perfectly capable of using HTML in elementary school.

  • @Zetornator
    @Zetornator 2 года назад +20

    when he said "Decoded the HTML code"
    ...i was so shocked that i almost choked from my own laugh

    • @BlueJDev
      @BlueJDev 2 года назад +2

      Man's a browser

    • @ThePC007
      @ThePC007 2 года назад +1

      You could make the argument that since the base64-encoded social security numbers were part of the HTML code, and he indeed decoded them, he did technically decode the HTML code (at least the part that needed decoding). Though you're right, the people writing this had no idea what they were talking about.

    • @Zetornator
      @Zetornator 2 года назад

      @@ThePC007 yes technically the phrase was correct but coming out to the public to say all that was the funny part of all and i really admire the person who wrote that speech.

  • @xliquidflames
    @xliquidflames 2 года назад +61

    The campaign ad makes it obvious the governor knew exactly what he was doing. He may have never heard of HTML before but he's not dumb. What he knew is if it got out that the website was _that insecure,_ it would be a huge embarrassment. It might even lead to lawsuits from anyone that had info stored in their databases.
    The prosecutor calls it what it is, a data breach, not a hack. That prosecutor's press release goes on to talk about how they have zero tolerance for "improper taking and using of personal information." They conspicuously omit the word "storage" from that sentence. Improper storage of personal information was the problem here. No one took anything. It was in plain sight.
    I don't think the governor is intimidating journalists. I think he was seizing an opportunity and turning an embarrassment into a campaign strength. I mean, look at the guy. He's been in politics for a long time. He knew exactly how to handle this and spin it in his favor. The journalist was a convenient scapegoat.

    • @davidciprys7811
      @davidciprys7811 2 года назад +4

      He could also choose not to go public in the first place. The journalist said he would not post anything about it (if he did, that could be considered as a crime). Governor had two options either go public and twist the situation in his favor or ask anybody with at least two braincells if this is a good idea.

    • @slickrick2420
      @slickrick2420 2 года назад +4

      Republicans always play dirty politics like that

    • @_underscore_9271
      @_underscore_9271 2 года назад +5

      @@slickrick2420 honestly, democrats do too, I don't think any official is elected for their ability to lead, I think the campaigns always come down to who can talk the smoothest

    • @RaposaCadela
      @RaposaCadela 2 года назад +1

      @@slickrick2420 99% of politicians in general, all over the world they're a social disease

    • @Buglin_Burger7878
      @Buglin_Burger7878 2 года назад +3

      @@_underscore_9271 Everyone of every group can be evil, it is so rare for people to realize both sides of the coin are corrupt. It makes me happy seeing someone recognize this.

  • @mark.fedorov
    @mark.fedorov 2 года назад +6

    Eating soup with a spoon is a multi-step process... They just needed to add more meaningless words to make it sound serious

    • @grubbygeorge2117
      @grubbygeorge2117 2 года назад +1

      I think it’s a lawyer thing where they can try to prove the intent to hack because accessing the data required taking multiple steps

  • @Qwetzxl
    @Qwetzxl 2 года назад +1

    how can they possibly say "they decoded it from OUR HTML" and not think maybe the "hacker" wasn't doing anything

  • @peatral
    @peatral 2 года назад +30

    Similar stuff happened a while back in germany where the addresses of voluntary electorial assistants were exposed through an api by changing the parameters in the url. The researcher did not make a big fuss and went the responsible disclosure route, but than after it got fixed and it went public she got hit with a lawsuit. IIRC in the end the lawsuit got dropped becuse she just accessed publicly available data, but the CCC said they won’t ever report any security issues to that party in the case they find one again. Shooting the messenger is not cool, especially if you got no knowledge on the topic and the whole thing is just a shitshow.

    • @keiyakins
      @keiyakins 2 года назад +4

      Not only is it not cool, it's just terrible policy. It means if someone finds it who doesn't want you harmed, they won't tell you, so you can't fix it before someone who *does* want you harmed finds it too

    • @fss1704
      @fss1704 Год назад

      Good luck finding security experts after fucking with the CCC, 90% of the people there won't work with you no matter what, 9.9% will not work with you because they might get a lawsuit and that 0.1% who will work will make you pay 50x more or just plain black hats.

    • @TomJakobW
      @TomJakobW 15 дней назад

      Now, I am not saying that this can’t happen with any party (heck, or any country), but I still can’t suppress my urge to add salt to the wound and not add the information that this happened to, well, let‘s say the German party that would exactly be the one this Missouri Governor would be from, were he to be active in german politics. 😅

  • @Togher01
    @Togher01 2 года назад +12

    This is ridiculous... Do American law markers not take advice from other people? Like if you don't know something just ask. It's not a sign of weakness.

    • @MrMediator24
      @MrMediator24 2 года назад +1

      That's just the system their - politicians have to take extreme stances on issues and be exact opposite of... opposition. Also typical boomer being out of touch

    • @ThePC007
      @ThePC007 2 года назад +3

      Considering that he read the word “HTML” as if it was the first time he ever saw it, I assume he didn't even write the script himself. So, I suppose he already got the advice from other people, except those people had no idea what they were talking about either.

  • @TheTrainWatch
    @TheTrainWatch 2 года назад +32

    “There is an argument to be made that there was a violation of law.” Didn’t interpret this as a red flag as you said, but rather as a creative jab at the Governor. Almost like “There is an argument to be made that the earth is flat.”

    • @user-lk2vo8fo2q
      @user-lk2vo8fo2q 2 года назад +3

      right "...but i wont be the one making it" is the addendum

    • @_profile
      @_profile 2 года назад +2

      "This matter is a serious matter"

  • @chrikke
    @chrikke 4 дня назад +2

    "Decoded the HTML source code" is my new favorite sentence

  • @SzaboB33
    @SzaboB33 3 дня назад +2

    The government talk about this like I write about a missing CSP header

  • @christopherlawless713
    @christopherlawless713 2 года назад +6

    The people who are in the Government are the best and brightest in our nation. So smart they pay 50 million for a problem that can be done for practically nothing. 😆 🤣

  • @vincentguttmann2231
    @vincentguttmann2231 2 года назад +8

    I think I'm just going with Hanlon's razor: Never attribute to malice that which is adequately explained by stupidity.
    But I'm not even sure if this is better or worse. It's bad enough that they governor had no idea what he was talking about, but it is even worse that there still isn't a federal law that protects cybersecurity whistleblowers.

    • @Bvic3
      @Bvic3 2 года назад

      The problem wasn't that the speaking face wasn't technically literate, most executives aren't. The issue is that there was no internal IT department to handle the issue.
      The US rotten culture of small government leads to that mess. State organisations are forced to hire absurdly expensive contractors because they aren't allowed to have state software development agencies.

    • @vincentguttmann2231
      @vincentguttmann2231 2 года назад

      @@Bvic3 Oh my god

  • @djpiercy1235
    @djpiercy1235 2 года назад +64

    I'm going to say that regardless of intent, this almost certainly fits the legal definition of actual malice. Someone (and someone in a position of authority no less) has decided to repeatedly make false claims and pass them off as fact, with disregard for their truth and what effect they would have, arguably for their own gain. Even if the journalist can't recover damages for legal fees, he could almost certainly sue for slander.
    (not a lawyer, but I have seen way too many legaleagle videos where he has to explain the legal definition of actual malice.)

    • @andrewdreasler428
      @andrewdreasler428 2 года назад +6

      Add in to the number of "dog whistles" the governor throws out (He actually says "fake news media" combining the claim of fake news and the discrediting of news reporters), I could identify his party affiliation even if I didn't know which party was in control of Missouri.
      The way things are going, I don't think I'll be able to trust a statement made by an Elephant politician ever again. If one pointed at the Sun, I would need to find another source to confirm that he's not really pointing at the Moon.

    • @kipter
      @kipter 2 года назад +3

      @@andrewdreasler428 Democrats and Republicans are both owned by the same corporations that own the Media, distrusting the media isn't a dog whistle, it's common sense.

    • @unlucky-animal
      @unlucky-animal 2 года назад +1

      Especially considering they want $50M for it... that REALLY sounds like they just want an excuse to blow through $50M..

  • @karasuchrono
    @karasuchrono 2 дня назад +1

    Governor deserves to be trolled. What a clown. Didn't even bother getting a cybersecurity expert's opinion before jumping in.

    • @wiwita63
      @wiwita63 День назад

      This shit is so stupid it doesn't even need any specialist in any field, a normal person who uses the internet would be able to tell you what's going on 😭

  • @nathanmorgan9807
    @nathanmorgan9807 2 года назад +2

    One very important thing to remember about the US government at ANY level... they're not stupid, they know what they're doing and they never do anything unless they themselves directly benefit from it.

  • @mortified776
    @mortified776 2 года назад +9

    It was both malicious and stupid. It is the dynamics of a abusive relationship. The abuser attempting to turn every thing around and make themselves the victim when they get exposed. The stupid part was thinking everyone else would be stupid enough not to see it for what it is.

  • @MissFoxification
    @MissFoxification 2 года назад +27

    Next in the news: "Old man doesn't understand how the internet works."
    If it was intentional I doubt he would have mentioned specifics and would have used vague wording which sounds more intimidating. At least the prosecutor realised what was going on and that it wouldn't stand in court.

    • @ThePC007
      @ThePC007 2 года назад +2

      Not to mention the way he pronounced HTML as if he never heard of it before. He clearly had no idea what he was talking about.
      Which does beg the question, though. If this is indeed the first time he read about HTML, who wrote the script?

    • @akiranara6404
      @akiranara6404 2 года назад +1

      @@ThePC007 Probably an aid. He probably had seen the name before during the meeting, but wasn't quite familiar enough with it to pronounce it with confidence.

  • @monkemode8128
    @monkemode8128 2 года назад +6

    This could be used as a South Park script

  • @joshm3342
    @joshm3342 2 дня назад +1

    This is horrible. I'm relieved that Gov Parson is terming out in 2024. He should be punished.

  • @Forien
    @Forien День назад

    It baffles me they called it "private information". If something is sent to any and all browsers that access the site without a need for authorization, it is a public information. Therefore, all those security numbers became publicly available information.

  • @coffeemaddan
    @coffeemaddan 2 года назад +8

    Shows the level of advisors and tech competency of politicians. There should be popular documentaries produced to highlight the absurdity of this situation and how the 'government' can bully journalists or citizens to mask their incompetence. The old git should be held accountable for throwing his weight around without understanding the facts.

  • @Barzz
    @Barzz 2 года назад +10

    Waiting for "Getting sued for existing"

    • @chri-k
      @chri-k 2 года назад

      Getting sued for not existing

  • @joshuamix6064
    @joshuamix6064 2 года назад +5

    Dear god, this was painful to learn about.

  • @Theaksten
    @Theaksten День назад

    The school and governor defamed the journalist to avoid taking responsibility for incompetent and negligent handling of personal data. Like WTF! Why would a publicly accessible web server serve SSN to clients visiting a publicly accessible page? Why the duck does a public web server even store or have access to personal SSNs to begin with! WTF!

  • @johnnywaldron5402
    @johnnywaldron5402 2 года назад +1

    Ignorance has no limits, that governor just embarrassed himself and probably doesn't even realize it.

  • @friedrichdergroe9664
    @friedrichdergroe9664 2 года назад +34

    This is not the first time a politician blew something stupid out of all proportions. Of course, the website should NOT have been sending the teacher's SSNOs to the webpage.
    Perhaps this was more a deflection to escape repsonsibility for such a slipshod website design???
    Politicans. Bureaucrats. Monkeys. Which one throws the bone up in the air better? :)

    • @blinking_dodo
      @blinking_dodo 2 года назад +2

      USA becoming more like the USSR every day...
      deflection of responsibilities, propaganda, scare tactics, blaming the enemy instead yourself, "you will own nothing"...

  • @jonathannoneofyourbusiness4123
    @jonathannoneofyourbusiness4123 2 года назад +19

    Was this done intentionally? I do tech support for a living, and I garuntee you that as he read “HTML” he didn’t even understand the concept of what it was. He’s an old man that is rich enough to pay others to understand technology for him, and through some absence if grey matter had somehow connected the description of what happened to “hack”.

    • @comet.x
      @comet.x 2 года назад

      shhh don't tell him they're paying us loads for easy fixes

  • @hacked2123
    @hacked2123 2 года назад +5

    They probably just had a rulebook of steps to follow in order to qualify for insurance money to cover the identity theft protection that they'll need to buy for the 100,000 teachers.

  • @waasar
    @waasar 2 года назад +5

    Both the paper and the individual reporter surely have grounds to sue for damages over this absolute disaster

  • @cianmoriarty7345
    @cianmoriarty7345 3 дня назад +1

    The governor believes everyone is entitled to their privacy. That's why he doesn't give a fig about ensuring state databases are secure and instead of spending money on cybersecurity he goes after citizens trying to help secure teacher's social security numbers.

  • @timothius9000
    @timothius9000 2 года назад +16

    has anyone looked into whether there was a IT contractor who could be blamed? if yes there's always the possibility that said contractor might have links to the governor

  • @Tom-cf2wk
    @Tom-cf2wk 2 года назад +127

    True story, I found a decent security vulnerability in a payment processing service. I wont disclose the name, but they are similar to square. Anyway, I was able to obtain the business names and products of each of their clients. That itself I suppose isn't the end of the world, but it was definitely a bug, and at least would have made me uncomfortable being them. So I composed a report and sent it over to them. They then told me I was wrong. I so badly wanted to just compile the list and send it to them. But we were using their services and had spent a great deal of time setting our system up to do so. So I didn't compromise our relationship with them, I just let it go. Two months later, they issued an email to our their customers requiring their action, a layer of authentication had been added they said. Without getting into too much detail, it was a fix to the bug I found. Wish they would have at least given me some credit.
    My guess, whatever technician my report originally reach, got escalated to some senior tech, who naively and stubbornly insisted it was impossible. Then went home and while sleeping that night went over it in his head and eventually came to the "oh fuck maybe he's right" realization. Then too embarrassed never emailed me back thanking me. Then took them two months of fix it, requiring all their users to take manual action to correct their bug.

    • @justincombs7433
      @justincombs7433 2 года назад +28

      If they were willing to ditch you as a client over you being right, maybe you shouldn't be their client. But that's between you and them. At least they fixed the issue though.

    • @Tom-cf2wk
      @Tom-cf2wk 2 года назад +5

      @@justincombs7433 You're not wrong at all. But after spending as long as we did reverse engineering their api and integrating it with our product. It just wasn't worth it. The company we went with here, also had some decent / favorable ways in which their contract treats the user payment information. So for example, I think with square if you part ways with them, they are not obligated to transfer the credit card information and such of your customers. With this platform they are, which was important to us. And didn't seem common. But yeah I totally agree with you.

    • @davidt01
      @davidt01 2 года назад

      You should have checked if they had a bug bounty program, because you can get paid for reporting vulnerabilities if they do.

    • @Tom-cf2wk
      @Tom-cf2wk 2 года назад +3

      @@davidt01 Yeah that was my initial correspondence with them when sending the report over. I asked if they had one and they said no but they would take a look at what I had and maybe could work something out if it was legitimate. But then told me I was wrong. Which I wasn't lol. So yeah, was either just ignorance or denial. I appreciate your response though. Yeah that was my initial interest. I know google for example has some pretty large bounties.

    • @SpiritmanProductions
      @SpiritmanProductions 2 года назад

      Maybe it's childish, but I would have been far less forgiving in that situation. I'm sure some of those exposed companies would've liked to know what was accessible on that site, even if the information reached them anonymously.