Hacker News new | past | comments | ask | show | jobs | submit login

Just listened to the Darknet Diaries Courthouse podcast about the pentest gone wrong that was referenced in the article. Highly recommended.

https://darknetdiaries.com/episode/59/




That wasn't a good look for their employer, "Coalfire", and not only because no one answered when they got their jail phone call. How did Coalfire not notice that the target was owned by a completely different entity than the organization that signed the contract?


> How did Coalfire not notice that the target was owned by a completely different entity than the organization that signed the contract?

The courthouse was owned by who? The sherriffs? I thought the ownership was okay, but it was the over-eager law enforcement that refused to budge because they weren't informed.


They had a contract with some office in the state government. The courthouse is owned by a county, as most courthouses in USA are. Later the fig-leaf of "they use a state-administrated computer program there" was constructed so as to limit the injustice inflicted on two humans, but county buildings are no more owned by the state than state buildings are owned by the feds.

And yes, stipulated, the sheriff is an asshole, but even he would have honored a contract between Coalfire and Dallas County, Iowa.


Thanks for the clarification




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: