• @rdyoung
    link
    English
    310 months ago

    I had not heard of that one. Was it the “internet is full of tubes” guy?

    • @CosmicTurtle
      link
      English
      2410 months ago

      No, it was a few years back when a researcher found that there was a plain text file of county employee social security numbers just sitting inside the JavaScript of a government website.

      There are too many Google results from the upcoming election for me to sort through but suffice it to say, the guy was a class A idiot.

    • @[email protected]
      link
      fedilink
      English
      1610 months ago

      I don’t think so, but it was in response to some smart people developing their government website with the database stored basically in the HTML of the website if I remember correctly. A good Samaritan reported it and was basically charged with hacking the state.

      • pixelmeow
        link
        English
        410 months ago

        The problem with this is that reading the generated HTML behind a page that has been served to your browser does not prove that data was stored in an HTML source file. The data is inserted into the page while it’s being served to the browser. That’s what the JavaScript does after it requests the data from the backend code, which gets the data from the database (or whatever storage is being used) and sends it back to the JavaScript, which puts it in the page.

        Saving data in source HTML files would mean every possible combination of data anyone might request must be saved in its own separate file, which is definitely not how web development is done. Laws should not be made by people who don’t know what they’re talking about.

      • Mario_Dies.wav
        link
        fedilink
        English
        110 months ago

        A good Samaritan reported it and was basically charged with hacking the state

        Wait, really? What would I search to read more about this? Do you remember which state?

        • lad
          link
          fedilink
          English
          510 months ago

          I remember hearing about this, so I tried searching for someone “being charged after reporting personal data exposed on a website”

          Turns out, it’s Missouri, 2019, or another article on the same topic

          • Mario_Dies.wav
            link
            fedilink
            English
            310 months ago

            Holy shit, that governor really made an ass of himself. He just kept doubling down lol

            Thanks for the links!

    • lad
      link
      fedilink
      English
      810 months ago

      Happened around 2021-10-15:

      Missouri Gov. Mike Parson said that his administration is pursuing the prosecution of a local newspaper reporter who alerted the government to website security flaws.

      It’s in the following sources, at least: TechCrunch, NPR, NY Times

    • Aatube
      link
      fedilink
      0
      edit-2
      10 months ago

      What’s wrong with that “a series of tubes” speech? It seems pretty accurate to bandwidth

      Edit: Searched it up. The part that was wrong was him blaming email delays on bandwidth.