episode.ascii — live render
● episode

Dead Messengers

TL;DRMissouri Gov. Mike Parsons threatened to prosecute St. Louis Post-Dispatch journalist Josh Renaud for "hacking" after he discovered teachers' Social Security numbers were exposed in plain HTML source code on a state website and…

Jordan Bloemen & Scott Francis Winder discuss one of the most dangerous jobs of all; the messenger.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: First of all, good afternoon, and thanks everybody for coming in this morning.

Speaker 2: In October of this year, Missouri governor Mike Parsons stepped up to the podium to deliver a terrible piece of news.

Speaker 1: We are working to identify the teachers who information was compromised and any others that may have been compromised.

Speaker 2: There had been a hack, and the private information, Social Security numbers of Missouri teachers had been exposed.

Speaker 1: It is unlawful to access encoded data and systems in order to examine other people's personal information. And we are con coordinating state resources to respond and utilize all legal methods available.

Speaker 2: The damage, incalculable. Between fixing the website, the cost of law enforcement to investigate, Parsons estimated that this was gonna cost taxpayers upwards of about $50,000,000 to remedy. So help him God. He will not rest until he brings those responsible to justice.

Speaker 1: But let me be clear. This administration is standing up against any and all perpetrators who attempt to steal personal information and harm Missourians.

Speaker 2: And now, Scott, I'd like to tell you in as much detail as I can possibly muster how the people responsible executed this hack and how you probably have to. If you were to open a browser and go to the Missouri state teachers website and, keep up. Right click on the site and click view source code, like the thing where you can, like, view the HTML on a website sort of like any browser can do it. And like the basic functionality. If you were to have done this on the Missouri teacher's website about a month ago, you too would have found yourself staring at the confidential information of these teachers. You too would be a hacker, worthy of the full weight of the Missouri legal system slamming down on you like a cinder block.

Speaker 1: A hacker is someone who gains unauthorized access to information or content. This individual did not have permission to do what they did. They had no authorization to convert or decode. So this was clearly a hack.

Speaker 2: But the hackers, they made one crucial mistake. Upon discovering this, you know, vulnerability, sorry, committing this hack, they informed the Department of Elementary and Secondary Education, like, hey, your site has this vulnerability, and the private information of all these teachers is available to anyone that knows, like, how to view source code on a website. And they did this because they were journalists reporting on the vulnerability. And they were telling the government so the government could fix it before they went to print. And now the government in Missouri is very, very angry about it. And I I think I'm now done being sarcastic. We've all heard the expression don't kill the messenger, and Mike Parsons has endeavored to just Rambo the crap out of these journalists and security researchers who had the gall to deliver the message that there was a vulnerability exposing these teachers' private information. Not just the three that Parsons cites, but hundreds of thousands of teachers whose data was made vulnerable by this technical failure. And this isn't the first time this kind of thing has happened. The history of hacking and the laws governing cybersecurity is the history of people getting harmed trying to warn the authorities that there's danger in front of them. So that's what I want to talk about today, about this story and a couple others that show that sometimes in the world of hacking and cybersecurity, just delivering the message that someone is in danger is a great way to end up dead. Here, on Hacked.

Speaker 1: This data was not freely available and had to be converted and decoded in order to be revealed.

Speaker 2: So let's just get something out of the way upfront. Is viewing the HTML on a website hacking, Scott?

Speaker 3: Oh, boy. Absolutely not. The the not only that. Like, I'm this it's at times like this that I wish that I was a lawyer because I would love to be the one to rip this case apart because Mhmm. The HTML of a website is actually sent to you from the web server when you make the request. So when you make the request for the website, the web server actually sends you all of that data.

Speaker 2: Mhmm.

Speaker 3: And then your web browser and each web browser does it differently, renders that data into the actual web page, which any web developer will know and hate because often they're inconsistent across multiple browsers, which makes web development a pain in the neck. So if there's a bunch of private data embedded in the HTML code and, like, hidden away so that it's not rendered on the screen, that is just god awful web app design. And looking at what you've been sent in a raw form is by no means hacking. If anything Mhmm. All of the negligence and liability needs to flow back to the people that are sending that private data out through a non confidential channel. So, yeah, that's not hacking, and I'm disgusted.

Speaker 2: Yeah. To my mind, like, the source code of a website is the thing that you publish, and a browser is just one way of viewing that published content. But it's not hacking. You haven't super, like, gone around anything.

Speaker 3: No. If you don't if you know anything about what constitutes confidentiality.

Speaker 2: Mhmm.

Speaker 3: Like, that that information is so publicly disclosed that the server would send it out in, like the server would send it out in its entirety out to you. So it's like, it's not confidential. It can't be confidential. You're literally broadcasting it. Therefore, it is no longer confidential information. And if it was confidential information, the issue should be with who broadcast it, not with who received it.

Speaker 2: So sometime in the week or so leading up to October 12, this was just last month, a journalist named Josh Renaud with the Saint Louis Dispatch finds himself having, you know, discovered this vulnerability, having discovered that they've published this information. And we can speculate as to why he was looking for it, there's some evidence to that effect later, but the point is that Missouri's Department of Elementary and Secondary Education maintains this public facing website that lets you look up teachers, find their basic publicly available information, their public servants, their watching children. Here's almost like a telephone book of who they are, where they teach. Sure. That's pretty much it. Makes sense.

Speaker 3: Yep.

Speaker 2: And And Renault discovers that if you go to one of these profiles and you view source code, well, now you're looking at a bunch of not public information. Social Security numbers of these teachers. We've already talked a little bit about how that's certainly not hacking, and we'll get to that more later. But, like, can you maybe guess why that would even happen? Why that information would be in the source code at all?

Speaker 3: Sheer like, and this is if this sounds offensive, it's because it probably is, and it should be. Sheer sheer laziness. Because, obviously, that information is coming from the same and this, like sorry. I'm gonna distract myself here. But it's, like, that information is clearly coming from the same database table. And instead of just pulling the select pieces of information that they need to make the web page, they're pulling it all. And then they're just not rendering or showing the stuff that should Mhmm. That they shouldn't have. They're just hiding it, which two two problems with one, they should only be pulling what they need. And two, the second and bigger problem is that they shouldn't they shouldn't be pulling from the same database table. Like, there should be, you know, a wall between private and public data. Like, if somebody hacks that web server, they shouldn't have access to all of the teachers' private records.

Speaker 2: Mhmm.

Speaker 3: You know, socials, pain role, etcetera like that. That stuff should all be on on information that's inside of the enterprise, not information that's sitting on the web servers or in database servers that are accessible from the web servers. Like, that's

Speaker 2: Right.

Speaker 3: You know, security one zero one.

Speaker 2: So So not only should they not have been publishing this, even if it was into non visually rendered HTML, not only should they not have published it, but they shouldn't have even been storing it on the same infrastructure, if storing it at all, as the content that they were trying to publish.

Speaker 3: Yeah. 100%. Like, if you could anything like, if you if you put a server outside the like, in the demilitarized zone, like, out in the world, you put a server on the web, you can assume that that server will maybe potentially get hacked at some point, and those hackers will then have access to the network and the infrastructure that that server has access to. And if that server has full database access to, like, all of the confidential records, then the hackers will have you should, assume that the hackers will get full database access to all of the confidential records. So the best thing to do is to replicate over only the data that you need to render the website to a database server that, you know, the web server then has access to. So prevent you know, you put walls up between pieces of infrastructure to something that's public and something that's confidential, the better. Does that make sense?

Speaker 2: Yeah. No. That makes sense. So the journalist, Renault, reaches out to a cybersecurity professor at the University of Missouri Saint Louis named Shaji Khan. And Khan replies to him over emails that we now have access to saying, quote, yeah. We've known about this type of flaw for at least ten to twelve years, if not more. The fact that this type of vulnerability is still present in the DESA web application is mind boggling. And unfortunately, these types of flaws and poor design choices are more common than we'd like. Local and state governments across the country are often still using applications designed many years ago, potentially containing serious security flaws. Khan uses a really relevant word there. He says it's still present in these web applications. Because this wasn't like a general observation. This kind of thing had happened already. And it sort of goes to explain why Renault, as a journalist, would have had some reason to be checking for these basic basic vulnerabilities on a DESE website. The state auditor's office had previously flagged the department's data collection practices during an audit in 2015. And during that 2015 audit, they found that the DESC, same group, was storing students' Social Security numbers and other very easily identifiable personal information in its information system for no discernible reason whatsoever. They had the information from they gathered it at some point and for some strange reason they were continuing to store it and it was also very vulnerable. And the audit urged them stop doing that and start creating a comprehensive policy for responding to data breaches. And the department said, yeah, we hear you. We have complied. Box checked. All is well. And that was five years ago before this happened. So Renault makes this discovery. DESC is still continuing to do the same thing that they got in trouble for before he writes his article. It was a common practice when it comes to journalists covering, like, a leak of confidential information kinda like this. Mhmm.

Speaker 3: You see

Speaker 2: it a lot in whistleblower cases. The basics, before you go to print, you have a journalistic and ethical responsibility to go to the relevant parties and say, like, hey, we're gonna publish this, and we're giving you warning to make sure you do whatever you need to do to make sure us publishing doesn't do any harm.

Speaker 3: Mhmm.

Speaker 2: Like if you're gonna publish a data leak about the military, it could put real humans who did nothing wrong in harm's way. And so even if you have a responsibility to publish, you also have a responsibility to talk to the people you're kind of exposing and make sure a row detail doesn't do any harm. You have to disclose. Mhmm. So, Renault, journalist who finds this, reaches out to the DESC, gets put in touch with their spokesperson, a woman named Mallory McGowan, who replies, very spokesperson y way, we've worked with our data team in the office of administration to get that search tool pulled down immediately, so we can dig into the situation and learn more about what has happened. Kind of response you'd expect. They're looking into it. McGowan says on Tuesday of that week that the department's gonna look at the findings, and they're gonna talk to the newspaper, gonna get back to them with a quote by Wednesday evening. But by 3PM, McGowan, the spokesperson, has stopped replying to emails. And some new character shows up into the whole play, the department's chief counsel, their lawyer, Sarah Madden, who says, hi. I'm their lawyer. We're not gonna be talking about this anymore. And that's when everything kinda starts to take a little bit of a turn. And on Wednesday, the Department of Education sends out a letter. They blast up a press release, and, Mike Parsons steps up to the podium to deliver their formal, you know, response to all this. And he delivers that speech we heard at the top of the show. This is not a vulnerability. This is a hack. These are not journalists. They're hackers. It's gonna cost us up to $50,000,000 bucks to investigate and fix this. And, we're gonna get into the laws later, but whether or not it's a criminal charge, we're actually legally allowed to pursue civil charges, and you should expect them.

Speaker 1: State statute also allows us to bring civil suit to recover damages against all those involved.

Speaker 2: Full scorched earth. They're not happy. We like, where does 50,000,000 just to briefly dwell on it. Where the where does $50,000,000 come from? Like, how could this cost $50,000,000 to remedy?

Speaker 3: But but here well, here's the other thing is, like, maybe they have to rebuild all of their data systems, and they don't have the budget for it. And maybe they think a civil lawsuit is gonna pay for that. Like, maybe this is like a man manufactured lawsuit for funding.

Speaker 2: Right. Right. Right.

Speaker 3: But it's like like the The

Speaker 2: Kickstarter.

Speaker 3: In what you just said, saying that you these problems have existed for twelve years, like Yeah. How are the teachers, not a class action lawsuit, back to this organization to be like, you've been broadcasting my private information on the internet for twelve years. Like, you're liable for that. And if you know that it's been happening for twelve years, you're like especially liable for it. Like, you know, when you when you find out there's a problem in the automotive that you're making and you don't fix it, you're even more responsible and liable. Yeah. You're culpable for it. It's like, if you're broadcasting personal information on the internet, and I'm gonna keep using the word broadcasting because that's what they're doing. And especially if they ever paid for any online advertisement to drive traffic back to their website, they were not only broadcasting it, but they were paying Promoting it. And promoting it. So it's like, you know, how is it your I don't that's it's I'm so baffled by this story. But I'm assuming they have to redo all of their data systems and all the rest of it, and they're saying that it's gonna cost $50,000,000. So they're essentially blaming the person who brought their attention that this problem still existed. They're saying, well, it's gonna cost $50,000,000 to fix it, and therefore, you owe me $50,000,000. Because if you didn't bring this to my attention, we would be just fine.

Speaker 2: Yeah. Sure. Which is

Speaker 3: kind of insane.

Speaker 2: It's like someone pointing out that your house is on fire and you get angry. It's literally killing the messenger is the name of the whole thing.

Speaker 3: Yeah. It's like I call a I call a I call a contractor, and I'm like, hey, there's some moisture seepage below my window. And he's like, oh, you have black mold. You have to replace your wall. And I'm like, I'm suing you for my wall.

Speaker 2: See you in court.

Speaker 3: Yeah. See you in court.

Speaker 2: So Renault and Kahn, you know, the journalist and researcher, are now staring down this legal and political offensive from, like, the Missouri governor's office, which is a pretty crappy place to find yourself. But as the story gets out, and the details of the vulnerability and what Parsons is claiming, become clear, people start, you know, commenting on it. And in a sort of cross the aisle unison that gives me some small hope for the future political discourse in The US. Like, everybody, all political stripes, all backgrounds, collectively holding each other's hands singing Kumbaya say, that is the dumbest fucking thing I've ever heard, Mike. Republican state representative Tony LaVasco, who according to his biography has like worked a little bit in software deployment Perfect. Tweets on Thursday, of that week, it is clear that the governor's office has a fundamental misunderstanding of both web technology and industry standard procedures for reporting security vulnerabilities. Journalists responsibly sounding an alarm on data privacy is not criminal hacking.

Speaker 3: God bless this man. God bless this man.

Speaker 2: I know nothing about him, but hopefully, god bless this man.

Speaker 3: I'm I'm sure that's something they would say in Missouri. So God bless you, sir.

Speaker 2: Joseph Martenau, the attorney for the newspaper came out saying, and I like this one, a hacker is someone who subverts computer security with malicious or criminal intent. Here, there was no breach of firewall or security and certainly no maliciousness of intent. And, like, intent gets kind of muddy. We're gonna talk about the laws a little bit later because it can mean a lot of different things. But Chris Vickery kinda spoke to what you were talking about, Scott, a California based data security expert, told a journalist who reported about this that the Department of Education was, quote, publishing data it shouldn't have been publishing, and that's not a crime for journalists to discover it. Putting social security numbers within HTML, even non display rendering, which you brought up, is a stupid thing for the Missouri website to do and is the type of bone headed mistake that has been around since day one of the Internet. No exploit, no hacking or vulnerabilities involved here. You mentioned non display rendering HTML. There are parts of the source code of a website that are meant to not be seen by the viewer. Right?

Speaker 3: Oh, there's loads of it. Like like I would say, like most of it is just instructions to the browser. Right? Like HTML is literally just a a markup language to tell the browser what to do with things. Style sheets are now the predominant way of like styling it and making it look ways, but you can you can you could put an infinite amount of information in a website and hide it. Like, it the there's basic instructions for how to hide stuff in there. Like, truthfully, if you look at some websites, there's funny little messages sometimes embedded in the headers and things like that. Like, some people put, like, ASCII art, like drawings of small ducks. Like, you know, like, there's there's often little Easter eggs. Like, for funny, like, hacker websites and stuff like that. Like, you often find stuff in the source code because everybody looks at it. Also, that guy sounds great. Whoever said the exact same things as me sounds like a really great guy.

Speaker 2: Yeah. Real champ. We're gonna quote him again in a second. Vickery seems to know what's up. So in explaining how governor Parsons hopes, you know, this reporter and the news organization are gonna be prosecuted, he points to a state statute defining the crime of tampering with computer data, where a court ruled that someone violates the law when they access files or other information that is off limits to them. In Missouri, Chris Vickery, same guy, says that the state was, quote, publishing the HTML source to the public Internet with no hurdles of a password or other requisite forms of authentication challenge, meaning the public can reasonably assume to be authorized to view that content for the purposes of laws related to computer trespass forms of offense. So if this story starts as, you know, you know, what is a hack are these hackers? It it does end on a bit of a definition beyond just did they mean to, which is that you gotta circumvent something. A password, a policy, a program, like a person at a desk that's supposed to say no who you get to say yes. Even according to the most abstract broad definition of hacking. Just viewing content that someone publishes in a way other than how they intended it to be viewed is not hacking. Twitter user Rachel Tilbach wrote, by this definition, my cat walking across my keyboard and sitting on the f 12 key is now a serious punishable cybercrime. You shall now hear by named Oh my god. Advanced persistent pet, Wish I just like that pun.

Speaker 3: You know, HTML is the thing that is delivered from the web server. Your browser is simply a renderer for it. But literally, you can like, the h t the raw HTML is the thing being broadcast by you. So if you're putting confidential information in there, that's your fault. So it's like I don't know. The I I hope that this one gets tossed on its head and I hope there's a civil lawsuit in law on the other direction, and I hope somebody retires peacefully after having to deal with all

Speaker 2: this b s. Yeah. If there's one thing I've noticed about, governors, it's they love admitting a mistake and stepping down is a shame.

Speaker 3: Hey. I'm sure that I'm sure that I'm sure the farther that he starts keeps putting good money after bad and, you know, the same sentiment with, like, you know, social, social influence. The longer he keeps persisting that this is a hack, the worse it's gonna be when the civil lawsuit comes back on them.

Speaker 2: Yeah. He has a he has one last move, and we're gonna get to it right at the end because it's it's pretty amazing. I think there's, like, a temptation when a person of a certain, you know, technological background, certain age, whatever, get something this this wrong to assume that it's coming purely from a place of ignorance. And, like, guaranteed, Mike Parsons does not seem to know a lot about how computers work. But that's not the only reason he's doing this. And we know why he's a little bit more about why he's doing this because of a really, really incredible piece of political advertising that he ran explaining why he's doing it. And we're gonna get to that. But before we do, this all got me wondering, you know, what are some of the other motivations people have for going after the person delivering the message of a vulnerability? The other reason folks, you know, shoot the messenger in stories like this. So we're gonna take a look at another one of those stories and some of the laws behind it before getting to Mike Parsons' incredible political advertising right after this break. Starting some new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shop ify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.

Speaker 4: All new drinks are now at McDonald's with refreshers like the strawberry watermelon refresher and the mango pineapple refresher with popping boba to crafted sodas like the Sprite Berry blast with berry flavors and cold foam. Who knew ice cold drinks could be so fire? Try them all now at McDonald's.

Speaker 2: Refreshers contain caffeine. Copyright 2026, The Coca Cola Company. Sprite is a registered trademark of The Coca Cola Company.

Speaker 5: When you need to build up your team to handle the growing chaos at work, use Indeed sponsored jobs. It gives your job post the boost it needs to be seen and helps reach people with the right skills, certifications, and more. Spend less time searching and more time actually interviewing candidates who check all your boxes. Listeners of this show will get a $75 sponsored job credit at indeed.com/podcast. That's indeed.com/podcast. Terms and conditions apply. Need a hiring hero? This is a job for Indeed sponsored jobs.

Speaker 6: This summer, serve up the cookout classics, Oscar Mayer hot dogs and Heinz mustard. Grill up a dog, add classic yellow mustard, or load it Chicago style. We all know it's not a cookout without Oscar Mayer and Heinz.

Speaker 2: Here's a fun story. It takes place way back in March 2016. And this one isn't quite as cut and dry. It's the story of a dead messenger, but it's not quite the same as the story of Renault, Kahn, and Mike Parsons. It's a little bit kind of foggier. And it's the story of a security researcher named David Michael Levin, at the time 31 years old, of Estero, Florida. David is a security researcher. He runs a cybersecurity company called Vanguard. And one day, right before the twenty sixteen US election, he decides to crack open a piece of free SQL testing software called HAVAGE for testing, you know, SQL injection vulnerabilities. Mhmm. Broadly speaking, Scott, what is an SQL vulnerability?

Speaker 3: Well, Jordan, an SQL injection vulnerability, because there's multiple SQL vulnerabilities. But injection vulnerability is essentially I can break this down in something easy so that people understand it. Say I'm on the on a website, and there's a form that lets me, like, search for certain pieces of data. Maybe there's, like, six filter fields in this form. Like, imagine I'm looking at, like, some form of data records from a store, or a store is is perfect. I'm looking at inventory items or previous orders that I've had, and I can filter that by, you know, date ranges or order number or whatever. Typically, the the whatever you type in that, like, search box becomes a part of an SQL query that goes off to the server and says, hey. Like, you know, this person's searching for orders, and they've asked that any order that has this in the title, and then it returns that to the to the to the web server, which then sends back the HTML code, which then gets rendered in the web page. So an SQL injection vulnerability is inside of that box on the page. If I can figure out how to pass in alternative pieces of SQL code so, you know, maybe the filter field is like description searching. But in the description stuff that I type into that box, I've pulled myself out of the the piece of text that it's gonna look for. And then I add additional information, like, you know, I wanna see anything that has description that equals, you know, order, and I wanna see user ID equals this, and I wanna see this, and I I add additional search functions or additional pieces of query into the box, which then the server takes in and actually executes. So, you know, you can bypass a lot of security if you can get the SQL server to believe or to essentially execute SQL language that you're passing in. Does that make sense? Mhmm. I feel like that's

Speaker 2: not a

Speaker 3: harder concept to kinda get across really quickly.

Speaker 2: Yeah. No. It does make sense. It's almost like the, like the questions and comments box. That little slot that you put the comment through. That's the form on a website and this is a vulnerability to let someone get into something they're not supposed to through that little that little slot in that box.

Speaker 3: Yeah. So like the one of the things well, a long time ago in a world a long, long time ago, you used to be able there was back when there was Internet cafes, they were often very locked down and you could just have access to the web browser and you couldn't get access to anything else. Or maybe the web browser would only let you look at a specific web page. You could use the search form on a lot of those web pages to actually get access to the file explorer and actually get access to the real computer just by, like, simply searching for c colon slash windows slash explorer dot e x e. And then, it would pop you up a link to it, which Internet Explorer would execute on and actually open you a copy of file explorer. So, all of a sudden, you've taken full access and gotten full control to one of these, like, Internet PCs at, like, a at a random Internet cafe in Thailand, per se. And then and then you could do whatever you wanted. You know? You could open up your own version of of the web browser. You could go to whatever website you felt like or you could spend more time on it than you were supposed to be allocated, etcetera, etcetera. So all of these like search and HTML and SQL injections have always been a, like, a classic web hacking tool.

Speaker 2: So Levin takes this classic tool, and he hops over to the Lee County elections website. And he checks it out, and what do you know, he discovers a critical SQL injection vulnerability, which allows him to get access, as you said, to the site's database, including usernames and passwords. So Levin, security researcher, responsibly reports the vulnerability to the respective authorities, and over the weeks that follows helps them pass all the loopholes on the elections website. So far so good. This is what you wanna see. See. Everyone's cooperating, a researcher finds a vulnerability, reports it, and they all work together to fix it. Great. Then, Levin goes on an interview show with a guy named Dan Sinclair, who at the time was running as supervisor of elections against the incumbent, a woman named Sharon Harrington. Dan Sinclair is running to supervise elections. Levin goes on and says, here was this big vulnerability in the elections website. Explains what happens, talks about the vulnerability, and it kind of immediately becomes a little bit of a football, politically speaking, because this is really good for Sinclair. He wants to supervise elections, look how vulnerable they are. Here's a security researcher to unpack all of it. Almost two weeks after that video goes up online, Florida police raid Levin the researchers house and seize his computers, when he was arrested and charged for allegedly breaking into this election's website, The one where he found the vulnerability and helped them fix it. He then spent six hours in jail before being released on $15,000 bond. Florida police claimed that Levin never asked for permission, prior to, you know, doing this pen testing on any of these state owned servers. Sinclair, the guy running for office said, no. Levin was the one who helped the authorities fix it. He shouldn't be in trouble. So at first, this one reads a lot like Mike Parsons in Missouri. Someone finds a vulnerability and then gets just railroaded for helping.

Speaker 3: Ish. Ish. Big big ish on this one.

Speaker 2: But there's two differences. The first one, I think you've already figured out because he actually did technically do a hack. But there there's there's another little thing going on here. See it turns out that Levin researcher was actually good friends with Sinclair before all of this. The guy running for this position. The one whose YouTube show he went on. And it got the authorities kinda looking into you know where did this fall why were you looking into this vulnerability? And they started discovering that there was this friendship between Levin and Sinclair. It turns out, according to Sinclair, that this all started when Levin calls him back in December after taking an online federal course with some DOD people on pen testing. And Levin comes to him and says, you know the supervisor position that you're running for overseeing these these these elections in this website? I could really, really easily get into that website. The arrest report makes clear that Sinclair didn't ask Levin to hack into it, but that Levin, the second he did it, calls Sinclair up to tell him what he'd done. So this whole thing starts kind of looking a little bit like maybe a a political stunt, which Harrington, the incumbent, agrees with. She says the timing of this is all very interesting. Mhmm. David Michael Levin pleads guilty, misdemeanor, count connection with hacking the website. He serves twenty days in jail. The whole thing kind of goes away. And this one, you already kinda caught up on part of what makes it interesting is that it's interesting because what he did was, I I think, good. Like, he found a vulnerability and he reported it. Should that be considered hacking?

Speaker 3: I'm not really sure. He did hack, but he did it theoretically for the right reason, for the wrong reason. You're you're you're you're you're entering a very philosophical conversation about the law. But I will say that, like, I the difference is very very profound, I would say. Yeah. Somebody looking at the source code that's being broadcast to them For sure. Is like it's insane to consider that hacking. Actually insane. Somebody pen testing a server without permission. It's getting dodgy. Yeah. You're you're getting very close. You know? Like Mhmm. Like, the difference between this being a, oh, he's definitely hacking and a, what what do we think about this philosophically?

Speaker 2: Is the

Speaker 3: fact that he reported it? Yeah. For sure. You know?

Speaker 2: The second guy was hacking. It's like He did the right thing with the information that he acquired for a bad reason, potentially.

Speaker 3: Correct. This is, this is, let's just say, a lesson that young Scott learned in his life as somebody who helped friends secure things. Yeah. Very different story to be asked to do it and reduces your exposure if somebody's requesting that you perform a service rather than you just doing it out of the goodwill of your heart.

Speaker 7: It's

Speaker 3: very hard to justify goodwill with a paper trail, if that makes sense.

Speaker 2: So there's two pieces of federal law in The US, and there's versions parallel versions of them in other countries that have modeled their laws after them that are relevant in both these stories. The Computer Fraud and Abuse Act of 1986, CFAA, and the DMCA, Digital Money and Copyright Act. These are the two big laws that have been used to go after researchers. Whether or not they were hacking, those are the two laws in the middle of all

Speaker 3: this. Mhmm.

Speaker 2: These two stories and countless others. And as we get into this, I think it's worth saying that these laws were written for fundamentally different digital worlds than the ones that we live in right now. And they include penalties for behavior that I I think is pretty vital for security testing. And neither one of them carves out any kind of general or permanent exemption that makes any legal distinction between a researcher trying to help and intentionally malicious behavior that the laws were written to prohibit. So the term bug bounty was coined in 1995 by Netscape. It was for their program that they'd set up to reward people who reported bugs with, you know, prizes depending on how big that that bug was. And even in this like earliest version of what a bug bounty was it acknowledged that users who were reporting security bugs were one of the most valuable contributions in keeping their system secure. They'd figured that out way back in 1995. And right now, a lot of companies have sort of followed along in that general sentiment. They have, you know, disclosure programs are incredibly common and they carve out a little bit of a a niche in their terms of service for making sure that if a researcher, regardless of why they were digging around, does find an, you know, report a vulnerability, they have some kind of a protection. But those are corporate policies, not laws. And the laws are not forgiving in this case. And researchers have very rarely found a receptive audience with companies whose products they are testing. The laws just aren't on their side. When they wrote the CFA, the big law in question here, it was three years before Tim Berners Lee even invented the World Wide Web. Congress passed the CFA in 1986. It was written, for a different internet by Congress who was thinking about just a different kind of cybercrime. The House Judiciary Committee called the 1983 film War Games, which we've talked about here, which for anyone that doesn't remember that episode, is about a Seattle teen who's hunting for video games and he breaks into like a nuclear warhead silo. They refer to that film in congress on the record, as a quote realistic representation of the access capabilities of the personal computer. And that law CFA makes it illegal to access any computer quote without authorization. Which is really important term in all this. And It's the kind of vague language that has empowered maybe the worst versions of this type of story. Again, importantly, based on what Parsons threatened to do to Renault and the journalist, the CFA also carves out a big exemption allowing companies to sue in civil court alleging CFAA violations even if law enforcement doesn't pursue charges. And all of this is built on a foundation that doesn't define what accessing a computer without authorization means, or what it means to exceed authorization. And for most of the last couple decades, there have been different conflicting interpretations of what those terms mean at different levels of court. And this sort of just sustained absence of clarity has allowed this law, CFA, to be used as like a cudgel to stop countless different security researchers from looking at products. It's been used to limit competition between companies, and it's been used to go after people for engaging in normal Internet behavior like viewing the source code on a website. Researchers report regularly getting cease and desist letters setting, you know, a possible CFA violation. And it's just sort of become this really common tool for intimidation by companies that don't want the bad press of a vulnerability. Mhmm. In cases that did go to court we see this pattern where that crucial word authorized in the CFA had no consistently enforced technical definition and was just sort of in most cases defined by that company's terms of service. In other words the companies kind of get to write the law themselves on a case by case basis. It's the law that Parsons and the Missouri governor's office are citing and going after Renault. It's the law in the middle of all this.

Speaker 3: You know, the cases like this bring to light, you know, things like bug bounty programs, and and in internal security researchers. And, you know, the companies that clearly take security seriously look for this stuff. They pay people to look for this stuff. They pay professionals who are good at this to do this. And that's if you really care about security. If you don't care about security and you just care about, you know, obscurity, then you, you know, file charges to anybody that shows that there's a weakness in your or that you have a vulnerability. You know, that is the last thing you wanna do. You know, the when you know, Microsoft is, I think, pivoted in that light, you know, since way old old days Microsoft, every time somebody found another IIS problem, it was just, you know, hackers and this, to now being, like, you know, big on this stuff and being, like, oh my god. Thanks for reporting it. We'll fix it right away. And everybody takes it very seriously, you know?

Speaker 2: Amazing disclosure programs. Yeah.

Speaker 3: Yeah. And that's just it. It's like you can you can see the the innovation, the transition, the the corporate world's going through. Like, I I can't remember who it was. I think it was Tesla. Tesla used to have a bug bounty program that paid a fortune because they know They

Speaker 2: get it.

Speaker 3: They get it that they know that if they have a a massive security breach that allows somebody to take over somebody else's moving vehicle, that it's gonna cost them way more than it will if they can fix that problem. Like, giving you giving you $500,000 as a compensation for finding that problem is way cheaper than the 50,000,000 that they're gonna pay out in legal fees and and lawsuits or 500,000,000. You know?

Speaker 2: One of the five world class engineers that we're paying couldn't find it, clearly, it's worth something. Like

Speaker 3: To totally. Totally.

Speaker 2: In his press release and at this event, governor Parsons, I think, showed his hand a little on the subject of why he was pursuing these charges. And I have to imagine that at some point between them learning about this and then making the announcement that someone explained to him, you know, this is not a hack. These are not hackers. But there's a couple key lines, not from the official release, which very carefully avoided this sentiment, but from his speech that I think reveal what's happening here, why his office chose to go after the messenger. Quote, this person is not a victim. They were acting to compromise personal information to embarrass the state and sell headlines for their news outlet. Which brings us to this, an advertisement created and published within, I think, seven days. It's a quick turnaround on the subject of this hack.

Speaker 8: Latest from the Missouri's fake news factory is from the Saint Louis Post Dispatch where a reporter has been digging around HTML code on a state website. The state technology division said the hacker took the records of at least three educators, decoded the HTML source code, and viewed the Social Security numbers of teachers from a state website. Governor Parson believes everyone is entitled to their privacy, especially our teachers. Governor Parson is standing up to the fake news media and is committed to bring to justice anyone who obtained private information. The Saint Louis Post Dispatch is purely playing politics. Exploiting private information is a squalid excuse for journalism, and hiding behind the noble principle of free speech to do it is shameful.

Speaker 3: Oh my god.

Speaker 2: Seven days. They they turned it around quick.

Speaker 3: Hey, Jordan. To be fair, we could have done it in one day.

Speaker 2: Yeah. I think we could have knocked this out a little bit quicker.

Speaker 3: This is a very strange way to go on the offensive against somebody who probably doesn't like you very much publicly. Mhmm. Oh my god.

Speaker 2: If you embarrass a powerful person or company or institution on the grounds of their technology, there is a non zero chance they're gonna call you a hacker. And it doesn't matter whether you didn't hack them like Renault, or you maybe kinda hacked them but maybe to help them like, you know, Levin. If you embarrass them with internet stuff, they might come at you. And as long as these laws governing that are vaguely written and inconsistently enforced, they might actually pull it off. And that kinda really sucks. Because the more times this happens, the more it tells the next person who discovers that something is broken and needs to be fixed, that maybe they should just keep that to themselves. Because maybe they're gonna get in a ton of trouble for doing generally the right thing. Maybe they should let someone else get hurt so that they don't. Forty one minutes of cybercrime law. That's right patrons on Patreon. You just empowered, forty one straight minutes of cybercrime law stories and whoof whoof, does it just mean the world to me. To our new patrons this month, Trev, Trev Goldring, Hacker x I'm just gonna enunciate these too much. Trev Goldring, thank you. Hacker x y z, thank you. Matthew Saint Vincent, Mathis Garrets, Josh, and Nick Owens. You're our new patrons. You're you are responsible for this. You did this. And if you wanted to do this to support the show, visit patreon.com/hackedpodcast that's patreon.com/hackedpodcast if you want to support our little show. Put a toonie in the tip jar as we call them up here in Canada. Thank you so much for listening. Thank you so much for making it to the end of this one. It means the world. Catch you catch you on the next one.

Speaker 9: Visible puts the ultimate wireless hack in the palm of your hand. You get unlimited five gs data and hotspot designed to keep you connected. All powered by Verizon's five gs network. Plans start at $25 a month or get the premium Visible plus pro plan and save $10 on your first month with promo code hack. Tap the banner to switch today. Terms apply. See visible.com for plan features and network management details.

Speaker 10: Athletic Brewing Company crafts award winning non alcoholic beers for those who wanna be part of every round. With over 185 flavor awards, they're exceptional NA beers that fit your lifestyle and any social occasion. Summer's full of good times and athletic fits right in. Go to athletic brewing dot com to have brews delivered to your door or find them at a bar, restaurant, or store near you. Near beer, athletic brewing company fit for all times.

Speaker 7: When I found out I was gonna be a parent, I immediately felt a lot of anxiety and worry. So I went on to BetterHelp to try to look for a therapist to help me with that.

Speaker 5: My relationship with my family and with my boyfriend and with myself were suffering. I really needed help.

Speaker 11: I was ruminating a lot. Really getting those thoughts out to a therapist and getting feedback was just life changing.

Speaker 2: Discover what BetterHelp online therapy can do for you. Visit betterhelp.com today.