logoalt Hacker News

jimztoday at 4:34 PM0 repliesview on HN

The VRP is a wholly manufactured and in the long-term, unsustainable model to begin with. It's the most duct/duck-taped solution that, with a virtually entirely tech-illiterate police force, can work under the interpretation of the CFAA prior to the van Buren decision in 2020. In practice it's easily ludicrously inefficient and requires trust that simply can't exist. In fact the tech-illiteracy is so profound that even post van Buren, which fixes some of the most glaring problems Orin Kerr has spent his career screaming into the void on with the CFAA, a law drafted 6 years before the web came about but with such vague and broad language and it manages to cover, at this point, almost anything (see also: wire fraud, money laundering statutes, the Mann Act aka the White Slave Traffic Act of 1910 and on the flip side, how RICO primarily serves as a tool of coercion because in practice if you take it to trial the charge will not stand, but a host of more minor but still overwrought and expansive felonies will do the job). It's the stopgap of stopgaps and the fact that it at any point had any buy-in was a minor miracle. I once submitted a bug report only to find that no, the company's intent was to defraud its users, and they simply put the (entirely unenforceable but are you going to test that? I've defended a federal criminal case and didn't lose - hung jury - and that took so much that it was almost a pyrrhic victory but it also without a doubt ruined any political aspirations of the AUSA. Anything less than that and it's pointless.) clause that they are indeed attempting to defraud you, and you just have to take it, in laymen's terms, into their ToS, without notice. Same company also has an working admin key in their production apk for their Algolia cluster and guess who isn't reporting it? There's no point. To quote Yates in his prime, "No likely end could bring them loss/Or leave them happier than before."

The correct way to address this had always been to modify or entirely get rid of the CFAA and start from scratch with a framework that actually works, that isn't punitive, that make some sense, that did not come into existence thanks to Ronald Reagan's admiration for the uncanny realism in the 1983 film WarGames. But we have a constituency now that relies on the inefficiency machine for their living and their votes will be in their self-interest, security be damned. The best people have been sent on a fool's errand for generations. The incentive structures are entirely misaligned now. I published a PoC last weekend that indirectly but pretty clearly shows that the FBI was relying on an anonymous twitter's account's assertions, none of which were going to be admissible in court in the alternate universe where that matters, to avoid saying "I don't know" by blaming North Korea, something that someone with open source tooling that existed back then, who have never taken a STEM course past 11th grade AP Stats, whose terminal degree is a JD, could whip up and test in under an hour, probably shorter except my home lab with the GPU was occupied. We go through the motions but really, those with power are relying on the inherent imbalance of power and well, lying, essentially, to keep order. How is that sustainable?

The whole model needs to go but it likely never will and that's perhaps the real legacy of Reagan and our moribund power structure. Looking at the payout rate in hackerOne's heyday, why would anyone ever report anything to the companies? My assumption is that people who have any rationality are doing just that. Most data breaches are never disclosed officially but at best passed in rumors. I have no hard evidence that I can disclose, but the least leaky operation is a one-man operation and attorney-client is forever.

By the way, your AI benchmarks in the legal realm aren't tested on criminal matters because how do you benchmark two probablistic systems that are both subject to the prisoner's dilemma and imperfect information? If they did the score would likely be low. You'd need to build out so much back-knowledge just to set up any scenario that really any answer is "it depends" is not a joke but the best answer. Any suggestion that we simply take the status quo as is and run with it cannot be taken seriously. It's a foolish system made by clueless men who hit the lottery and didn't even see the ticket until years after. It was then exacerbated by politically ambitious AUSAs who do not care about getting the right person behind bars but someone behind bars. Fast forward 30 years and this is the state of things. Your sophisticated defenses may have been thoroughly hand-reversed years ago but to dodge the DMCA the source was put somewhere like Gitee instead of Github. I'm not sure if you can finish the signup flow without a Chinese ID at this point, but a decade ago you can, at least. Those are outliers too, but outliers in charity. Good luck with the rest. I'm not being cheeky: just because there's a vulnerability does not imply knowledge to how to maximize its impact. Data breaches are put in the open frequently because of petty feuds and a failure to recognize the importance of the data. After all, China does not run on private credit, and hence, your identity being stolen there is virtually meaningless, as meaningless as you having next to the biometric ID card data of all of their citizens. Like harm, value is contextual, and constructed so that it's framework dependent, and we at least know the frameworks that exist broadly. And what you don't know, well, you don't know.