Security Incidents mailing list archives
RE: Who's liable?
From: "Chris Mason" <masonc () masonc com>
Date: Sat, 13 Oct 2001 18:47:59 -0400
Sounds like time for the rubber hose to me :-) But seriously, any criminal investigation would have may parts, the IP address is not going to be enough evidence in any case, we all know that can be spoofed. Once the FBI interviewed all possible people who had access at the time, they would probably know with a fair degree of certainty who did it, and a few choice question would probably find out for certina. Chris Mason masonc () masonc com Box 340, The Valley, Anguilla, British West Indies Tel: 264 497 5670 Fax: 264 497 8463 Take a virtual tour of the island http://www.anguillaguide.com/ The Anguilla Guide Find your perfect rental villa www.mycaribbean.com Talk to me in real time with Instant Messenger: masonc92 () hotmail com or ICQ 118159388 Signature F331 8AD1 36FB B3B0 DF9F D95B 8024 D1EA 7450 D50C -----Original Message----- From: Michael F. Bell [mailto:mike_b () rhinobyte com] Sent: Saturday, October 13, 2001 6:12 PM To: incidents () securityfocus org Subject: Who's liable? These are fictional scenarios that I am SURE that other people would like to discuss. Lets say you are a small realty agency, and you provide internet access to your employees and one of your employees hacks into the Whitehouse website from your internal network. You do not have any logging going on from your SOHO firewall and the FBI shows up at your door one day with a warrant to search your computers for evidence of hacking into the Whitehouse website. The FBI searches all 10 computers in your network and comes up without any hard evidence from these 10 machines linking them to the the hack into the Whitehouse website. Your company is not doing any firewall logging and you do not have any public servers that could have been hacked so someone could have remotely launched the attack? All that the FBI has is your publicly NAT'ed firewall address. Who is liable?? What can the FBI do at this point? The above scenario is all fictional from my standpoint. I could imagine that this is someones reality though... Lets change the victim from a Goverment agency to a private one. Lets say that EBAY got hacked and they launched the same sort of investigation with the same findings.. What can be done from a legal /financial standpoint if an attack is detected from your company network and there is no proof on exactly who did it? Can the victims take legal action against you, or is there some sort of protocol from a legal standpoint that hinders this?
Michael Bell mike_b () rhinobyte com
---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
Current thread:
- Who's liable? Michael F. Bell (Oct 13)
- Re: Who's liable? hvdkooij (Oct 13)
- Re: Who's liable? macdaddy (Oct 14)
- RE: Who's liable? Dom Genzano (Oct 14)
- Re: Who's liable? Kelly Martin (Oct 14)
- Re: Who's liable? macdaddy (Oct 14)
- Re: Who's liable? hvdkooij (Oct 13)
- Re: Who's liable? Jay D. Dyson (Oct 13)
- Re: Who's liable? - fbi Alvin Oga (Oct 13)
- Re: Who's liable? Alvin Oga (Oct 13)
- RE: Who's liable? Chris Mason (Oct 13)
- RE: Who's liable? Liam Burrow (Oct 13)
- RE: Who's liable? Russell Berry (Oct 13)
- RE: Who's liable? Brian Taylor (Oct 14)
- Re: Who's liable? Frank (Oct 14)
- RE: Who's liable? Michael Conlen (Oct 14)
- <Possible follow-ups>
- RE: Who's liable? Rob Keown (Oct 13)
- Re: Who's liable? Kelly Martin (Oct 13)
- Re: Who's liable? Doug Foster (Oct 14)
- Re: Who's liable? Kelly Martin (Oct 14)
- RE: Who's liable? Shashi Dookhee (Oct 14)
- Re: Who's liable? Kelly Martin (Oct 13)