frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

County pays $600k to pentesters it arrested for assessing courthouse security

https://arstechnica.com/security/2026/01/county-pays-600000-to-pentesters-it-arrested-for-assessing-courthouse-security/
69•MBCook•1h ago

Comments

ricree•51m ago
I remember reading about this when it first happened. Glad there was at least a somewhat positive outcome.

For reference, here is the HN thread shortly after the arrest: https://news.ycombinator.com/item?id=21000273

lgats•49m ago
$600k for 6 years of legal battle and facing felony charges? no bueno
unsnap_biceps•47m ago
Darknet Diaries did an interview with the two pentesters: https://darknetdiaries.com/episode/59/
formerly_proven•15m ago
... six years ago!
QuercusMax•37m ago
So... the county sheriff showed up, decided he needed to be a big boss man, and made everything worse for everyone. Sounds pretty typical.
thinkingtoilet•6m ago
Exactly. A fragile man needed assert his authority.
OutOfHere•36m ago
For someone who is in such a position in the future, always notify the local police in writing and by phone call, if not also in person, before starting such an exercise. Make sure they have the get-out-of-jail documentation in advance of the exercise. If the police doesn't approve, don't do it. It would be better to get a no-objection letter from the police in advance. Make sure an attorney is aware of the activities and all documentation. Do not take any chances. You don't live in a kind or forgiving world. Handling unknown unknowns is the point.
sehugg•22m ago
They had written authorization from the state court and verbal confirmation from state court officials. They didn't know there would be a pissing match between the judicial branch and the sheriff.
827a•12m ago
But afaik this wasn't a state courthouse; it's a county courthouse. Legally, obviously, the state has authority and they were in the right, but functionally this is really good advice: if you're doing a penetration test of a space, you functionally need to clear it with the people who are responsible for the security of that space, and whom you might encounter defending it.

Frankly, I would not have taken this gig unless you had verbal confirmation that the Sheriff knows about it and has signed off. If you're entering a red team situation where the State wants to assess the security of their county courthouses, but doesn't want the local authorities to know its happening because they don't trust them: That is not a situation you want to be in the middle of, they gotta sort that out.

jstanley•10m ago
Easy to say in hindsight.
xmcp123•11m ago
Wouldn’t that in a lot of ways invalidate the test?

You’re trying to see what can be done and what the response is from the current security practices and the police showing up seems like an important part of that.

rappatic•35m ago
This happened in 2019. The wheels of justice turn very slowly.
lazide•21m ago
Justice delayed is justice denied.
samrus•30m ago
I kinda hate that it settled. I fully understand the plaintiffs not wanting to proceed, but i really wish the sheriff was actually punished for what he did. This sort of power tripping should be a fireable offence
worik•26m ago
An elected officer. So punishment by ballot box?
QuercusMax•25m ago
Since when are elected officials immune from prosecution for crimes?
mminer237•15m ago
Nobody was pressing (or even alleging) crimes by the sheriff AFAIK.
canucker2016•5m ago
Sheriff Chad Leonard (queue chad references...) retired in 2022.

see https://www.desmoinesregister.com/story/news/2022/08/29/dall...

zerr•20m ago
Should have been at least 6 mln for each, and 15+ years of max security jail for those who abuse power, including those who "just followed orders".

Taco writer detained–briefly–by feds

https://bigbendsentinel.com/2026/01/28/taco-writer-detained-briefly-by-feds/
1•reaperducer•1m ago•0 comments

50 Years of the Jetsons: Why the Show Still Matters

https://www.smithsonianmag.com/history/50-years-of-the-jetsons-why-the-show-still-matters-43459669/
2•fortran77•1m ago•0 comments

Topology-aware routing of 3D-printed circuits (2020)

https://www.sciencedirect.com/science/article/pii/S2214860420308952
1•v9v•2m ago•0 comments

Translate with ChatGPT

https://chatgpt.com/translate
1•mfiguiere•3m ago•0 comments

Nintendo Is Going to Make It Hard to Share Screenshots in Tomodachi Life

https://kotaku.com/tomodachi-life-living-the-dream-direct-image-sharing-screenshot-block-2000664167
1•01-_-•4m ago•0 comments

Show HN: Lok – Treating LLMs more like infrastructure, not chatbots

https://github.com/ducks/lok
1•ducks_•5m ago•0 comments

DroidDock Now on Homebrew Cask for macOS

1•rajivm1991•5m ago•0 comments

An MLIR Lowering Pipeline for Stencils at Wafer-Scale

https://arxiv.org/abs/2601.17754
1•matt_d•5m ago•0 comments

US Gains 11,300 Ultra-Fast Chargers in Bet to Lure More EV Drivers

https://www.bloomberg.com/news/articles/2026-01-28/charging-companies-bet-us-drivers-want-more-ul...
1•toomuchtodo•6m ago•1 comments

Finland is heating cities using waste heat from data-centers

https://delmergroup.com/blogs/news/finland-is-heating-entire-cities-using-waste-heat-from-undergr...
1•srean•7m ago•0 comments

Agent-shell: A native Emacs buffer to interact with LLM agents powered by ACP

https://github.com/xenodium/agent-shell
2•trelane•10m ago•0 comments

Is $1 Too Cheap?

https://flowpay.work
1•chiswanjo•10m ago•0 comments

How I Used GenAI to Rapidly Prototype MaestroML (and Why FastAPI Won)

https://keithalexanderashe.substack.com/p/how-i-used-genai-to-rapidly-prototype
1•kaa2102•11m ago•0 comments

The Wolves Are All Gone

https://jack-bradshaw.com/journal/item/the-wolves-are-all-gone/
1•jackbradshaw•14m ago•0 comments

Clawdbot Without the Mac Mini

https://stumpy.ai/blog/clawdbot-without-the-mac-mini
1•bluesnowmonkey•14m ago•0 comments

Show HN: Free QR code generator (most take your email, mine doesn't)

https://www.instantqr.org/
2•heshiebee•15m ago•0 comments

Show HN: Playground to Test Skills and MCP

https://www.mcpjam.com/blog/skills
4•chelojimenez•18m ago•0 comments

JazzSpinnerVerbsForClaude

https://gist.github.com/chrismo/b35434593e06fe4a2ea6eca13e4786da
1•the_chrismo•21m ago•1 comments

Uganda votes in fear amid internet blackout and police crackdown

https://www.japantimes.co.jp/news/2026/01/15/world/politics/uganda-election-internet-blackout-pol...
2•PaulHoule•21m ago•0 comments

Open-Slopware

https://codeberg.org/small-hack/open-slopware
2•gpi•22m ago•0 comments

On this Day...1776 – January 1: The Flag [video]

https://www.youtube.com/watch?v=sV52AUVGc6I
1•mellosouls•23m ago•0 comments

Cognition Devin Review

https://app.devin.ai/review
3•lord_sudo•23m ago•0 comments

AltStore creators introduce CSAM Store Checker app

https://www.patreon.com/posts/introducing-csam-149431432
1•_han•26m ago•0 comments

Sicherheitslücke – gesperrte Bezahlmethoden trotzdem nutzbar bei smartsteuer.de

https://anton.dachauer.org/2026-01-27-smartsteuer.html
1•rizutato•27m ago•0 comments

LlamaBarn: A cosy home for your LLMs

https://github.com/ggml-org/LlamaBarn
2•tosh•29m ago•0 comments

I dont want AI that replace my taste, I want AI that help me use my taste better

https://emsh.cat/good-taste/
2•embedding-shape•31m ago•0 comments

Why the text terminal cursor is important for Accessibility

https://blind.guru/blog/2021-06-25-brick.html
1•lynx97•33m ago•0 comments

Show HN: Accurate LLM-based password guesser

https://github.com/Tzohar/PassLLM
2•Plarsy•36m ago•0 comments

Why "The AI Hallucinated" is the perfect legal defense

https://niyikiza.com/posts/hallucination-defense/
2•niyikiza•36m ago•3 comments

Creator Studio: Apple confuses with duplicate apps

https://www.heise.de/en/news/Creator-Studio-Apple-confuses-with-duplicate-apps-11158774.html
1•doener•36m ago•0 comments