Tag Archive for: Missouri

Missouri governor threatens to prosecute journalist for sharing web security flaw


Missouri Governor Mike Parson might want to read up on the differences between disclosing and exploiting security flaws. According to The Missouri Independent, Parson accused a St. Louis Post-Dispatch reporter of being a “hacker” for having the audacity to… report security holes. The journalist disclosed a Department of Elementary and Secondary Education web app flaw that let anyone see over 100,000 teachers’ Social Security numbers in site source code, and Parson interpreted this as a “political game” meant to “embarrass the state” — that is, a malicious hack.







JEFFERSON CITY, MO - MAY 29: Gov. Mike Parson listens to a media question during a press conference to discuss the status of license renewal for the St. Louis Planned Parenthood facility on May 29, 2019 in Jefferson City, Missouri. Parson stated that the facility still had until Friday to comply with the state in order to renew the license. (Photo by Jacob Moscovitch/Getty Images)


© Jacob Moscovitch via Getty Images
JEFFERSON CITY, MO – MAY 29: Gov. Mike Parson listens to a media question during a press conference to discuss the status of license renewal for the St. Louis Planned Parenthood facility on May 29, 2019 in Jefferson City, Missouri. Parson stated that the facility still had until Friday to comply with the state in order to renew the license. (Photo by Jacob Moscovitch/Getty Images)

The governor has already referred the case to the Cole County Prosecutor, and even has the Missouri Highway State Patrol investigating. An attorney for The Post-Dispatch maintained that the reporter “did the responsible thing” by sharing the flaw with the government to get it fixed. The lawyer also helpfully refreshed Parson on his internet lingo. A hacker is someone who “subverts” security with sinister intent, not a reporter trying to bolster security by sharing publicly available information.

Loading...

Load Error

This flaw wasn’t recent, either. University of Missouri-St. Louis professor Shaji Khan told The Post-Dispatch that this kind of vulnerability had been known for “at least” 10 years, and that it was “mind boggling” the Department would let these problems linger. Audits in 2015 and 2016 had highlighted data collection issues at both the Department and school districts.

No, prosecutors probably won’t file charges. It’s a bit difficult to convict someone whose ‘hack’ effectively amounted to clicking “view page source” in their browser. However, this highlights an all-too-familiar problem with politicians that don’t understand tech. It doesn’t just lead to embarrassments, such as

Source…

Government Generously Hands Back Two-Thirds Of The $626,000 It Stole From Two Men Driving Through Missouri

A case out of Missouri is highlighting yet again the stupidity and vindictiveness that defines civil asset forfeiture. In January 2017, law enforcement seized $ 626,000 from two men as they passed through the state on their way to California. According to the state highway patrol, the men presented contradictory stories about their origin, destination, and the plans for the money found during the traffic stop.

The complaint filed against the money made a lot of claims about the government’s suspicions this was money destined for drug purchases. Supposedly evidence was recovered from seized phones suggested the two men were involved in drug trafficking, utilizing a third person’s money. Despite all of this evidence, prosecutors never went after the men. They only went after the money.

Records searches of both state and federal courts did not identify any criminal charges against Li, Peng or Huang.

Even the speeding that predicated the stop (in which a drug dog “alerted” on the rental vehicle that contained no drugs) went unprosecuted.

This is where the stupid begins: alleged drug dealers allowed to continue their drug dealing by state and federal agencies more interested in the men’s cash.

But it gets stupider. This was offered up in the complaint against the seized money as evidence of the men’s criminal activities.

Authorities noted in the complaint he lived “9 houses” away from the site of a residence where drug transactions were occurring and a contact in his phone was recently the subject of a civil forfeiture action.

That’s some mighty fine evidence. If you happen to live in the same neighborhood as a known criminal, I guess you’re a criminal, too. That’s just how society works, ladies and gentlemen. Move to a better neighborhood if you don’t want to be lumped in with your worst neighbors.

The other part is stupid, too. According to this line of thought, if law enforcement has stolen cash and property from someone in your Contacts list, you must be a criminal. Only criminals would associate with people whose stuff has been taken by the government but have never been convicted of criminal activity.

Also apparently suspicious: traveling and not attempting to avoid mandated IRS reporting.

Peng had a number of bank transactions the complaint states were “highly unusual” including multiple deposits and wire transactions for about $ 100,000 each. Financial records also showed three trips between Chicago and California and one from Chicago to New York in a three-month period between November 2016 and January 2017.

You just can’t win. Keep deposits too low (under $ 10,000) and the federal government thinks you’re engaged in structuring. Keep them well above the mandatory reporting mark and you’re probably a drug dealer.

It appears the agencies involved in this seizure didn’t think they had enough real evidence to follow through on this forfeiture. More than two years after the $ 626,000 was seized, the government is returning it to its rightful owners. That’s where the vindictiveness comes in. The government hasn’t won a criminal or civil case against any of the people involved, but it’s still going to keep a third of the cash just because.

U.S. District Attorney for Western Missouri Tim Garrison, in a settlement agreement dated April 25, wrote the government will return almost $ 418,000 to claimant Lu Li, of Chicago, and will keep almost $ 209,000.

Even when the government loses, it still wins. One-third of $ 626,000 remains in the hands of a government that couldn’t prove anything it alleged, even in a civil case where the standard of proof is considerably lower.

In the end, we have three people short $ 200,000 and a government that can’t competently prosecute people or their money, even when the latter can’t defend itself in civil forfeiture litigation. [waves American flag with one blue stripe frantically while humming ‘The Ballad of the Green Berets” for some reason]

Permalink | Comments | Email This Story

Techdirt.

Nearly $1 million NSF grant to bolster cyber-physical systems security – Missouri S&T News and Research

Nearly $ 1 million NSF grant to bolster cyber-physical systems security  Missouri S&T News and Research

A team of researchers from Missouri S&T has received a National Science Foundation research grant of nearly $ 1 million to develop stronger safeguards for a …

“computer security news” – read more

Missouri City, Houston men caught up in alleged espionage scheme involving Chinese company

  1. Missouri City, Houston men caught up in alleged espionage scheme involving Chinese company  Chron.com
  2. Full coverage

china espionage – read more