DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Senators introduce bill to secure Internet of Things devices; provide some protection for researchers

Posted on August 1, 2017 by Dissent

Zack Whittaker reports:

A bipartisan group of senators have introduced legislation aimed at securing internet-connected smart devices, which were at the center of a massive cyberattack that brought down large swathes of the internet last year.

The distributed denial-of-service in October lasted for less than a day, but it further fueled concerns about threats posed by insecure and easily hijacked so-called Internet of Things (IoT) devices, thanks to an industry-wide apathy toward supplying devices with even the most basic security.

Read more on ZDNet.

Keep in mind that the bill would prohibit the type of thing that researcher Justin Shafer kept trying to increase awareness about – hard-coded credentials. Shafer is currently in jail, awaiting trial on charges of cyberstalking a federal agent and the agent’s family.

Shafer’s problems with law enforcement began when he exposed the fact that numerous health-related entities were exposing protected health information (PHI) on public FTP servers. It is believed that one of the companies he exposed, Patterson Dental, tried to make it seem that he hacked them.

The new bill, if it passes, would have more protections for researchers. As Whittaker reports:

The senators also added a caveat to the bill that would expand legal protections for security researchers working in the Internet of Things space to exempt “good faith” vulnerability hunting activities from federal hacking laws.

The hope is that the exemption would draw more security experts to the field, encouraging researchers to report vulnerabilities to ensure security flaws are fixed sooner.

It would also expand legal protections for cyber researchers working in “good faith” to hack equipment to find vulnerabilities so manufacturers can patch previously unknown flaws.

Why is Shafer still in jail? Does anyone in the FBI have the integrity to come forward and tell us what really happened and why Shafer got raided THREE times and arrested when all he was doing was pursuing trying to get entities to be more responsible about securing PHI and disclosing when they failed to do so?  Why has he been persecuted this way – because entities were embarrassed that he exposed their security failures? Is that what this has been all about? If so, shame on any company that tried to portray him as a cirminal hacker, and shame on the FBI for pursuing this. Seriously. It’s disgusting.

 


Related:

  • Another plastic surgery practice fell prey to a cyberattack that acquired patient photos and info
  • How a hacking gang held Italy’s political elites to ransom
  • Uncovering Qilin attack methods exposed through multiple cases
  • Predatory Sparrow Strikes: Coordinated Cyberattacks Seek to Cripple Iran's Critical Infrastructure
  • Ex-CISA head thinks AI might fix code so fast we won't need security teams
  • UN Cybercrime Convention to be signed in Hanoi to tackle global offences
Category: Commentaries and AnalysesFederalOf Note

Post navigation

← NY: Kaleida Health notifies 2,789 patients about phishing incident
Personal Info of 650,000 Voters Discovered on Poll Machine Sold on Ebay →

2 thoughts on “Senators introduce bill to secure Internet of Things devices; provide some protection for researchers”

  1. Trent Wolodko says:
    August 1, 2017 at 9:21 pm

    I’ve often wondered the same thing.

    I think it goes back to the LANAP breach.

    http://justinshafer.blogspot.com/2016/01/williamsport-pa-databreach-update.html

    Justin was interviewed by local media, and that he was told he was a suspect. He said he was interviewed by the Dallas FBI field office as well regarding that case long before the Patterson fiasco and that the IT guy for LANAP, the practice’s lawyer and the State Police were, at least at one time, fingering him for the breach.

    According to what Justin said, the special agent who interviewed him is the same agent involved in all three raids of his home, the same agent Justin is accused of stalking/doxing on twitter/facebook.

    I distinctly recall him years ago mentioning he felt threatened by what the agent had told him at that time on the phone when discussing the LANAP breach. Justin said, and I’m paraphrasing, that the agent asked if he was a gray hat, a pentester, and if that were true then he should stop or he wouldn’t like the next call he’d get from the feds, or something to that effect.

    Then of course there’s this nugget on your site…

    Justin Shafer says:
    November 25, 2015 at 4:40 am
    “If anyone is a “hack” it would be whoever investigated this databreach.”

    I’m curious… Who investigates the investigators?

    Do they read your site? Maybe that irked someone. His computer seat detective work was rather interesting!

    1. Dissent says:
      August 1, 2017 at 9:43 pm

      I’m aware of what happened after Shafer went to media after LANAP. I had even published the threat letter he received. Someone did a sloppy job, I think, of investigating that one, as my investigation and analyses by CyberWarNews.info showed that the most recent entry in the LANAP database was circa May, 2009. In February 2010, those files were uploaded to PirateBay. In September 2012, Shafer started notifying people that PHI was in those files. When no one did anything, he went to the media the following year. How much more responsible could he have been in his disclosure??

      Anyone who knows Justin would know that there is NO WAY IN HELL he would ever upload PHI and PII like that to PirateBay. It is the opposite of what he does in his efforts to improve security.

      I can believe he got off on a wrong foot with SA Hopp, if that’s what happened. And I can believe he could be nasty or sarcastic to entities if he felt they were lying or trying to cover up a breach. But I believe that what has happened since then is an abuse of power and a travesty. And I’d be happy to sit down with the Dallas FBI to discuss this or hear their side of it, but I know damned well that some of that stuff in the PC affidavit was utter bullshit. And that may not sound very professional of me as a journalist, but we cannot live in fear of calling people or federal agencies – or the courts – out when they create and perpetuate injustice.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Checkout.com Discloses Data Breach After Extortion Attempt
  • Washington Post hack exposes personal data of John Bolton, almost 10,000 others
  • Draft UK Cyber Security and Resilience Bill Enters UK Parliament
  • Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition
  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • OpenAI fights order to turn over millions of ChatGPT conversations
  • Maryland Privacy Crackdown Raises Bar for Disclosure Compliance
  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.