News: 1620986527

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

NHS-backed org reacted to GitHub leak disclosure with legal threats and police call, complains IT pro

(2021/05/14)


+Comment IT pro Rob Dyke says an NHS-backed company not only threatened him with legal action after he flagged up an exposed GitHub repository containing credentials and insecure code, it even called the police on him.

Dyke, who has [1]previously appeared in this organ, in March said he received letters from lawyers representing the Apperta Foundation after he told the business he had found a public repo containing the source code for an insecure online portal and its database containing usernames, hashed passwords, email addresses, and API keys.

We're told the repository contained two branches, and dated back to 2019. It clearly shouldn't be public as it could be used to view internal purchasing, receipting, budgets, and expenditure information through the portal. The material was left visible to the public for so long that the Internet Archive mirrored a copy of it, which indicated the files were committed to GitHub by a now-deleted account that appeared to belong to a senior Apperta person.

[2]

[3]

[4]

What happened next united infosec professionals across the world as well as triggering a crowdfundraiser and a behind-the-scenes legal war: we're told Apperta sent Dyke legal demands, and followed those up by alleging to the cops that he broke Britain's computer security laws.

The story is not straightforward though shows that vulnerability disclosure and the response to disclosure can be a minefield – especially if both sides have previous history of falling out with each other.

Found some stuff you don’t want online

Having discovered the public-facing repository at the end of February, and notified the company on 1 March with a written report of his findings, Apperta’s first response was good, Dyke told The Register , and that he was thanked by the organization. “The repo quickly went private, and they took their portal website offline,” he said.

We understand Apperta – which is a not-for-profit company that provides tech, support, and funding for health and social care – has taken down its GitHub repo, and replaced its exposed API keys.

Here's where the wheels come off. When privately disclosing his findings, Dyke told Apperta he would retain a copy of the files he found for three months. As he wrote on his crowdfunding [5]page , set up to raise £25,000 to foot his legal bills to fend off Apperta:

I stated in my disclosure that I would keep the materials for 90 days (encrypted) and then destroy them and certify that I had by email.

Apperta interpreted this as the unlawful copying of its data, and that this internal information was being retained by a third party without permission for some unknown purpose. A week after receiving Dyke's report, the company's lawyers wrote to him demanding he destroy his copy of the files.

‘Data you unlawfully extracted’

Why keep the data at all? Dyke told us he held onto the information in case it would be needed again as the situation unfolded, post-disclosure. “It was a log of my actions," he said. "And it was important for me to keep it in case there was a wider cyber incident that I was not aware of.”

Views on the ethics and lawfulness of taking copies of exposed data vary. In the UK, it is frowned upon.

[6]

Dyke, who is a cloud platform engineering lead at a global consultancy, reminded Apperta that he only viewed webpages that had been publicly accessible, that he would remove a fork he made of the repo on GitHub to study it, and said he would destroy his copy of the data after three months had passed, among other undertakings. The next morning, Apperta's lawyers said this wasn't good enough, and urged him to sign a document promising he had deleted the materials.

The solicitors also picked up on something Dyke had put in his report: he said Apperta's portal "should be considered compromised" given its code, database, and vulnerabilities had been on show for anyone to find for years.

“And this is where a little bit of domain literacy goes a long way,” Dyke told us. “So in my report to them, I said, you should consider the Apperta portal compromised. Now that has a technical word in it; it has a meaning in infosec.”

[7]

Apperta, said Dyke, interpreted the word “compromised” as a threat or admission of malicious activity by Dyke himself. His tweets in which he said he had found and studied the contents of repo, without naming the owner, were also taken by the company as boasts of "unlawful extraction" of its data and as a threat to leak the non-profit's files. Dyke said this interpretation was absurd.

This all led to the solicitors demanding he sign a document that gave...

… your confirmation that you have not, and will not, publish the data you unlawfully extracted.

“As I'm not stupid, there was no fucking way I was going to sign that,” said Dyke, as it would pretty much be signing a confession that he "unlawfully extracted" data from Apperta's systems. Had Apperta not asked he admit a criminal act, he would have signed their undertaking, he added. Instead, things ground to a halt as Dyke’s lawyers responded to Apperta’s lawyers, going back and forth for weeks, as Apperta made it clear it wanted to apply to the High Court of England and Wales for an injunction against the IT pro. Such a court order would ban him from publicly divulging any information he had obtained.

Ultimately, Dyke relented before it got to court, and informed Apperta he had deleted the files and, he told us, sent them some proof. “I had already sent them the summary which had the screenshots, and a copy of the repo and my report. I deleted those things,” he said.

Dyke also named Apperta on Twitter, and made his [8]findings public . The infosec community rallied around him.

Security researcher [9]@robdykedotcom recently discovered and responsibly disclosed security vulnerabilities to [10]@AppertaUK about sensitive information stored on their publicly accessible repositories. He now faces legal retaliation. Let's help him. [11]https://t.co/cq6dXwxVNg — Hacking is NOT a Crime (@hacknotcrime) [12]April 27, 2021

At the time of writing, his crowdfunding effort had raised more than £15,000 towards paying his legal bills. Dyke also tweeted a High Court claim form and penal notice, partially filled in, which he said had been sent to him by Apperta’s solicitor.

If you've never seen high court injunction papers before, allow me

1/... [13]https://t.co/8uoGcw1cEX [14]pic.twitter.com/54h9aSLuDO — Rob Dyke (@robdykedotcom) [15]April 25, 2021

For Apperta's part, it confirmed to The Reg that this brouhaha did not get as far as going to court, and that its actions were reasonable. It also curiously claimed there had been an "unauthorised entry" into its systems:

In early March we were alerted to a security incident which concerned some of our own financial reports and unauthorised entry to a confidential internal database in our systems. We took immediate action to isolate this breach and secure our system.

The Apperta Foundation has not issued legal proceedings against Mr Dyke. Mr Dyke has now provided Apperta with an undertaking in relation to this matter. We believe our actions have been entirely fair and proportionate in the circumstances and we have been guided by the Information Commissioner’s Office (ICO) and our legal advisers regarding our duties as a responsible organisation.

It also said: "While Mr Dyke claims to have been acting as a security researcher, he used multiple techniques that overstepped the bounds of good faith research, and he did so unethically," adding that this had "been confirmed by independent experts."

It did not detail what those techniques were nor whom it had retained to check Dyke's work.

So, we meet again

Dyke said he had previously worked with Apperta on NHS open-source projects. Indeed, he had a copy of its information security policy from that time, he told us, and claimed he followed that when he disclosed the GitHub blunder to Apperta.

We have heard allegations of personal fallings-out between those involved in this case, which are of tangential interest to the vulnerability disclosure and legal response. As far as the disclosure went, The Register has seen evidence that the repo in question was uploaded two years ago by a senior Apperta person, and it shouldn't have been made public.

Northumbria Police confirmed to us its officers had dropped a probe into [16]a report of "computer misuse," with a spokesperson saying: "We can confirm there is no longer an investigation."

As for any potential civil disputes, Dyke has since given a legal undertaking to Apperta, as both parties confirmed to The Register separately. He thanked his legal team and infosec bod Sick Codes, Disclose.io, and Twitter campaign account HackingIsNotACrime for their support.

Comment: What to learn from this?

Vuln disclosure can be a fraught process. Someone in Dyke’s position in future may be better off asking a trusted organisation or confidante to disclose a security hole on his behalf rather than doing it personally, especially in a situation where an existing relationship has turned sour for whatever reason. Bug bounty schemes and similar vuln disclosure programs are the best methods where available as there should be a well-defined process for passing on evidence and details in a way that doesn't end up with a report to the police.

Telling an organization that has screwed up its security, especially its lawyers, that you will retain a copy of the leaked data will rarely trigger a positive reaction. Keeping data post-remediation shouldn't be the norm, we think.

In a different context, Westminster Magistrates’ Court in London, England, held that copies of leaked data on hardware seized by police was [17]a strong reason not to return the hardware to its lawful owner.

If the company in question directs its lawyers at you, get a lawyer of your own. Dealing with legal negotiations by yourself could have an expensive and painful outcome. Some household insurance policies come with legal cover and it is worth looking closely at these. ®

Get our [18]Tech Resources



[1] https://www.theregister.com/2017/06/30/nhsbuntu_nhs_revolution/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YJ6emkaFsC-BZIfg1dfTOQAAAEA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJ6emkaFsC-BZIfg1dfTOQAAAEA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJ6emkaFsC-BZIfg1dfTOQAAAEA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.gofundme.com/f/responsible-rob

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJ6emkaFsC-BZIfg1dfTOQAAAEA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJ6emkaFsC-BZIfg1dfTOQAAAEA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://robdyke.com/howto-disclose/

[9] https://twitter.com/robdykedotcom?ref_src=twsrc%5Etfw

[10] https://twitter.com/AppertaUK?ref_src=twsrc%5Etfw

[11] https://t.co/cq6dXwxVNg

[12] https://twitter.com/hacknotcrime/status/1387061473554411522?ref_src=twsrc%5Etfw

[13] https://t.co/8uoGcw1cEX

[14] https://t.co/54h9aSLuDO

[15] https://twitter.com/robdykedotcom/status/1386314581400866816?ref_src=twsrc%5Etfw

[16] https://twitter.com/robdykedotcom/status/1374667465955938306

[17] https://www.theregister.com/2019/02/19/lauri_love_computer_appeal_rejected/

[18] https://whitepapers.theregister.com/

Zippy´s Sausage Factory

I have a feeling that some investors might interpret this as management incompetence, and a misuse of company funds summoning lawyers to cover up their incompetence.

For the benefit of any lawyers listening, I'd like to point out that I am not investor in said company, so such thoughts could not possibly cross my mind, but I can easily imagine there are some corporate entities less charitable than I am that might take that view.

Chris G

They probably don't have any investors as they are a not for profit but it may put others off of the notion of dealing with them in any way.

I would be reluctant to engage a company that appears to attemp to cover it's own inadequacy by taking legal action against whoever pointed out said inadequacy.

As an NFP whose money were they using to pay for their lawyers?

Anonymous Coward

Wouldn't a NFP not care too much if they run up a legal bill within their funding model of "as long as we don't make a profit".

Or is that my simplistic view on it ?

That wasn't sarcasm btw, but if they publish accounts its just another cost and they might always have legal cost lines in there because they allays react like this to any negative news.

General Purpose

Not-for-profit basically means you're not for the benefit of shareholders. It doesn't mean you don't want to make a surplus to develop the organisation, repay loans or build up reserves.

It certainly doesn't mean you've got an unlimited supply of money for paying lawyers. If anything, you're more constrained because you can't opt to pay a smaller dividend this year. Worst case, you're going to have to cut back operations or cancel plans.

Doctor Syntax

Not for profits might not make profits but they can make a surplus.

They will be funded by somebody. It might be membership if it's something like a user group. It might be by offering services. It might be by some corporate with an interest in what it does - again, a user group is an example, having seen that from the inside, as it were. In this case TFA suggest it might be the NHS.

It's worth remembering that the salaries, however, large, paid to officers and staff nor payments to outsourced management do not count as profits.

Ochib

I think the answer to the question "whose money" is our money, via the Dept of Health

Rob Dyke

Apperta, for those that don't know, was created by NHS England in 2015 and given £500k to support open source projects. At the time Peter Coates, NHS England's Open Source Programme Manager and now a Director of Apperta, told Digital Health News that Apperta would: 'be fully transparent, with information published online regarding where money has come from and where it has gone.'

See https://www.digitalhealth.net/2015/06/open-source-super-cic-created/

For some reason NHS England don't want to talk about the funding granted to Apperta: https://www.whatdotheyknow.com/request/the_apperta_foundation_cic_3

I smell a rat here.....

Lilly Dillon

Curious.....

Looking at your FOI request, I see that it was submitted by an Andrew Roberts who you have admitted to being. (that's ethical, right?) Mr Roberts seems to have quite an interest in the financial dealings of Apperta. I did a little digging here (something that the majority of your "supporters" have either been unwilling to do or too trusting to do) There are multiple requests that he has made over the last 2 or so years.

https://www.whatdotheyknow.com/user/andrew_roberts_3

Doesn't this seem odd when we move forward to the present and You suddenly find yourself in a legal bind with Apperta over access to their financial data, that you then refused to delete ? I have followed this story with interest and seen mention of Apperta's alleged "vendetta" against you, however, it feels to me that this "vendetta" may originate from you and that you got caught with your fingers in the cookie jar so-to-speak.

Hmm, and a gofundme too? Amazing how fools and their cash are easily parted when they hear a well spun fairystory.

Re: I smell a rat here.....

Doctor Syntax

So do I. First post, I see.

Re: I smell a rat here.....

sev.monster

This just in, newposter found to be employee of Apperta, news at 11...

Caveat Emptor

Coversely, it is a simple case of company got sick of bitter ex-comrade publically bitching at them for the last few years and decide enough was enough. Some people might even admire Apperta for taking clear action to stop an ongoing unpleasant situation.

I've only seen Dyke's carefully curated screen caps of the legal documents he received and legal fees paid, but none indicated legal action was ever taken against him. Appertas legal documents have draft written on them and are not stamped as court submissions. They appear to have been provided in terms of showing what court submissions would be made if Dyke would not agree to guaranteeing he had deleted the information he had oddly chosen to keep. He's now agreed to that, so legal action won't start.

Dyke did something silly, with a company he has history doing silly things to. They asked him to stop. He panicked then agreed to stop.

Rameses Niblick the Third Kerplunk Kerplunk Whoops Where's My Thribble?

I have to say I'm somewhat unclear as to why he felt the need to keep a copy of the exposed data once it was apparent they'd fixed the issue? After all this seems to have been the only problem with the process and where everything else came from.

Not taking sides, I'm just hoping someone can clear this up for me.

Sam Crawley

I get the impression (just from what's in the story) he held on to the copy temporarily in case they simply denied it happened and accused him of making it all up.

Gordon 10

AND so what if they do? If you are worried about that you send a parallel disclosure to the relevant authorities.

Retained materials

Rob Dyke

I told Apprta I had a copy of the repos (encrypted). I deleted the repos when contacted by lawyers.

I retained the PDF of the security disclosure(s) as a record - with screenshots heavily redacted. I later deleted those and provided confirmtion of the same.

Gordon 10

Im still unclear on why he needed to keep ANY data other than a couple of screenshots.

Using the leaked creds once is technically unauthorised access even if just checking they work. Using them to exfiltrate data (which is what appears to have happened) goes way beyond the pale regardless of how well intentioned he might have been.

I do think from a technie point of view the company over-reacted but that just human nature and security "researchers" should be aware and prepared for this.

FWIW I think the guy went from White Hat to Grey Hat when he stopped confining his work to disclosing the hole, and instead appears to have appropriated the data as "evidence" either to avoid the company covering it up, or for academic curiosity. It wasnt his job to investigate the extent of the breach.

Regardless of how egregious the hole discovered making moral judgements about a companies response or potential response is out of the scope of White Hattery and emotionally and corporately naive. You shouldn't be doing this activity for anything more your own satisfaction, and should not be expecting anything more than a grudging acknowledgement and cover up, and if such a thing occurs - unless that breaks a local disclosure law - you dont get to judge.

Boris the Cockroach

More likely is the case

"I've just found a glaring security hole in e-crappo's discount data storage service.... here's how I did it, heres the data"

And you store that e.mail (and data) to prove el-crappos is exactly what it says on the tin and to have a reasonable defence in case el-crappo turns around and tells the police

"he a l33t h4XX0r and hacked our database.... "

The guy can turn around and say "The root account was 'Admin" and the password was "1234" and it allowed logins from where ever instead of a white list of allowed IP addresses" and heres the proof (and emails I sent them)

close

Rob Dyke

If there was badly written code, in, for example, a Registration Form calling the RegistrationController@create(), this wouldn allow someone to create a new user account, login and elevate priviledges.

teknopaul

This is the point entirely: he found a door open, informed the owner it was open, who promptly shut it.

Should be end of story but..

In the mean time he nipped in and took photographs of everything he could see.

Now he tries to tell people he didn't do that to prove to himself and his mates that he was there. I don't believe that. It is a standard hacker habit to take something to prove that you were there.

I vwanted to see if you had any unlocked safes in the room I found open is no defense.

Each country need a responsibile disclosure office. InfoSec bods should have the right to responsibility disclose to the owner and the arbitrator, and no one else.

Taking stuff from behind an open door is still theft.

Adair

'Someone in Dyke’s position in future may be better off asking a trusted organisation or confidante to disclose a security hole on his behalf rather than doing it personally, ...'

This seems the key bit of good sense. Is there/are there already 'official' bodies willing/able to take this role formally, so that everyone knows where to go, and things are handled reliably and consistently?

Anonymous Coward

Im sure St Julian would oblige, if it came with an opportunity to be a publicity whore.

Anonymous Coward

I think in this case there probably were channels available via national NHS tech organisations e.g. NHS Digital.

How easy those are to find and engage with are maybe a different story.

Don't shoot the messenger

tiggity

When companies do this, it sends a bad message to people who do the right thing & responsibly reporting vulnerabilities.

.. especially when lots of companies don't offer bug bounties, or they are pitifully small (compared to what's on offer from the "bad guys" for decent exploits (this one sounded like it was a real "keys of the kingdom" exposure) so doing the right thing is usually a matter of being a good citizen, it typically is a less financially attractive option than going the dark side route.

Learn from the ransomeware bods...

Peter Prof Fox

Step 1 : Find security cockup (Document but don't retain data.)

Step 2 : Inform lax organisation "I've found a whopping hole in your system. £5,000 for more info."

Re: Learn from the ransomeware bods...

Rob Dyke

Although Apperta and I have not always seen things the same way, I had no desire to embarass them or exploit the GitHub leak or the open access fiunancial reports published via Zoho.

I sent a quiet advisory. I didn't name them when I started to speak about the legal threats received in March. It only named Apperta after the decided to report this sorry circumstrance to the police.

My 2 cents

Pascal Monett

Stop bothering with Apperta.

Let them fuck up as large as they feel they can't be bothered to care.

Re: Learn from the ransomeware bods...

idiot taxpayer here again

@Rob Dyke

I agree with you in general but he kept a copy of the info. We would also have reported him for that reason only.

Just because if I am stupid enough to leave a door to my house wide open, it does not give anyone the right to take stuff does it?

Re: Learn from the ransomeware bods...

eionmac

Um! House door and software are very different fish.

I pinch your chair. (No chair left for you to use, sole unique thing)

I copy a publicly accessible data stream, also in archive files. Very different You made it available. No theft, you still have original data.

Just your carelessness, of a very different thing from a house door.

Re: Learn from the ransomeware bods...

Anonymous Coward

Let's try a different analogy. Instead of taking the chair I let myself in and read your bank statements, any personal letters, and your diary? I then take photographs.

You still have access to them but your privacy was needlessly violated.

The correct action is to advise the company that they made a mistake and give them the directions to show how they can verify your statement. You do not need to download a copy of the data and tell the company that you are keeping that data for 90 days.

If he'd deleted the data when asked there would not have been any problem. However, it took court action for him to do so.

Re: Learn from the ransomeware bods...

idiot taxpayer here again

@Peter Prof Fox

Step 2 Inform us "I've found a whopping hole in your system. £5,000 for more info."

Our response "Thanks for telling us, we will find it ourselves now we are aware. Your 5.000 quid? Fuck off. We don't respond well to blackmail"

Doctor Syntax

It sounds as if, apart from learning a few much needed lessons about IT security, Apperta need to have a word with Ms Streisand.

Go to court

steamnut

I think he should have gone the whole way into court. Apart from exposing the ungrateful way he was treated after informing them of the security hole, some case law could have been established as to the best way to go about telling a company that they have cocked up. After all, less scrupulous individuals could have done real harm with no conscience at all and from a foreign country where the law would not reach them.

Re: Go to court

Rob Dyke

If you can GoFundMe @steamnut.... https://www.gofundme.com/f/responsible-rob

Re: Go to court

Anonymous Coward

Are they still pursuing you legally?

Aaiieeee

The passwords / API keys were not supposed to be public; by keeping a copy you are creating the possibility of holding them to ransom for their private data in future, to which they reacted quite understandably.

AKA:

"I noticed you forgot to lock your house before going on holiday so I went and checked it out. Be grateful I am telling you. By the way I am keeping these compromising photo that I found; don’t worry, I only need them in case you deny your mistake."

Not a good look

SsiethAnabuki

As much as there were things done wrong by both parties here, I can't help but feel that the real take-home here is that you are far safer just anonymously dumping vulnerability data into public spaces and forcing the hand of corporate entities than you are actually acting responsibly.

Responsible disclosure so often results in a hostile response or complete indifference to the vulnerability disclosed

(and for the lawyers reading this - I'm not advocating anything, just pointing out some inferences that can be made from the behaviour in this case and many others)

Plest

To quote the the TV show Frasier...

"Oh let someone else worry about it!"

"What an appalling attitude! Suppose everyone thought like that? Where would we be then?"

"Everyone does think like that!"

Yes, your conscience might tell you to do the right thing, to be the good citizne and sometimes you simply need to listen to your common sense and just walk on by...

Most non-Catholics know that the Catholic schools are rendering a greater
service to our nation than the public schools in which subversive textbooks
have been used, in which Communist-minded teachers have taught, and from
whose classrooms Christ and even God Himself are barred.
-- from "Our Sunday Visitor", an American-Catholic newspaper, 1949