Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The part where he gets contacted over the hit-and-run reads like the curl guy’s experience with people investigating “hacking”.

I wonder how often this happens outside of software? Do fence manufacturers get emails asking to identify the culprit when someone crashes through a fence?



Actually, it wasn't unreasonable. If the guy caused the damage while picking up a sonde, to know who's sonde it was would help identify the culprit.


Responding to an email like that has basically no possible benefits for the person running the balloon tracking website, but it does introduce the possibility of some fool paying their lawyer to add you as a respondent in a lawsuit. Costing you many thousands of dollars at minimum in legal fees and travel even if you get the court to remove you from the case. Never respond to something like that unless your lawyer, whom you pay has instructed you to.

A person like that sending inquiries to website/API operators demanding data, ignore it. Always. Continue to ignore it until a process server actually shows up on your doorstep and serves you, in which case you know they're at least moderately serious, and then you need to engage your own counsel to deal with it.


This is such an USA-citizen thing to write. Doing the right thing is never even considered.


It's all fun and games until you've seen very real concrete examples of people who've spent from $5000 to $100,000 defending themselves from frivolous lawsuits. Never doubt for a moment the absurd nature of US vehicle crash related and insurance industry adjacent litigators.


Or maybe the sonde continued transmitting and they have data on where the guy took it which would help ID him.


Fair, I guess, I just can’t imagine what it’s like getting all these weird requests and demands for a hobby project. Hopefully the author is more entertained than I would be.


Not a lawyer but as a citizen I generally understand that the courts expect demands from court parties to be met.

If meeting the court's (or court parties') demands costs you something you are generally entitled to charge them for it, within reason and with justification.

As a hobbyist therefore putting a service offering page together with your preferred rate probably helps establish the nature and parameters of any such service.

Bill rates / piece rates, especially, and setting up bounds of what is reasonable to expect, in proportion to your gig and your intended effort level.

Quantity and price tiers, turnaround times, what will be included in the deliverable, how it will be delivered, SLAs, etc.

Whatever defines your service, esp as it relates to the types of requests you end up getting.


If I start listing prices, I may need to ensure that I have a business entity set up for tax purposes and to guard against liability. Especially if I’m listing SLAs.

This is not a hobby, it’s a job.

This is why all my hobbies are dark web projects, these days.


You only need to have a business entity (which, to be fair, can be yourself, although liability concerns apply) once you're about to actually enter into a contract with someone.

Merely listing prices (without an associated automated payment form which could imply a contract was en force upon successful payment) doesn't actually force you to do business with anyone. It would however 1) deter requests for unpaid work by giving them an idea of what it would cost to get what they're looking for and 2) give you an idea of the demand for said services and could give you a warm lead which you can then choose to pursue formally by getting the necessary business structure, legal/business advice, etc.


> Merely listing prices (without an associated automated payment form which could imply a contract was en force upon successful payment) doesn't actually force you to do business with anyone.

In some cases it could. If you want to say "we categorically don't do X for ethical reasons", that can sometimes be more easily defensible in a way that "we have a standard price for doing this, but we don't want to do it for you in particular" may be harder to defend. (Even though I think both should always be possible.)


Or if they'd been foolish enough to log the recovery on sondehub itself, which some of us do frequently (but not after causing property damage!).


Rings a bell, I think it was because Curl showed up as the user agent for malicious activity.

You have to be kind of lost to contact Daniel about it, but I think it's ok behaviour for junior sysadmins that are just starting out, everyone was starting out sometime, and curl is like a lightning catcher for the world's daily lucky thousand.


It's because curl is often embedded as a library or standalone executable with other software. So when a malicious or compromised piece of software is found, a less experienced investigator might see curl with its author tags in the file metadata, and follow it back to upstream.


I feel like it's a "cast a wide net" type of strategy. Doesn't really hurt to ask and there _could_ be the tiniest hint that could lead to something. Maybe?


In my first law class the prof said, "When it doubt, sue everybody."


Specially when the goal may not even be to find and demand anything from a culprit, but simply to prove there was a culprit.

Insurance. This is about insurance.

See, in my country, you could not use a car's dashcam recording as evidence in a small claims court. But I could 100% use it with insurance. They don't abide by the same rules of what counts as evidence.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: