Missouri's Governor Still Insists Reporter Is A Hacker, Even As Prosecutors Decline To Press Charges

from the disgusting dept

Last autumn, you may recall, the St. Louis Post-Dispatch published an article revealing that the Missouri Department of Elementary and Secondary Education (DESE) was leaking the Social Security numbers of teachers and administrators, past and present, by putting that information directly in the HTML. The reporters at the paper ethically disclosed this to the state, and waited until this very, very bad security mistake had been patched before publishing the story. In response, rather than admitting that an agency under his watch had messed up, Missouri Governor Mike Parson made himself into a complete laughingstock, by insisting that the act of viewing the source code on the web page was nefarious hacking. Every chance he had to admit he fucked up, he doubled down instead.

The following month, the agency, DESE, flat out admitted it screwed up and apologized to teachers and administrators, and offered them credit monitoring… but still did not apologize to the journalists. FOIA requests eventually revealed that before Governor Parson had called the reporters hackers, the FBI had already told the state that no network intrusion had taken place and it was also revealed that the state had initially planned to thank the journalists. Instead, Parson blundered in and insisted that it was hacking and that people should be prosecuted.

Hell, three weeks after it was revealed that the FBI had told the state that no hacking had happened, Parson was still saying that he expected the journalists to be prosecuted.

Finally, late on Friday, the prosecutors said that they were not pressing charges and considered the matter closed. The main journalist at the center of this, Jon Renaud, broke his silence with a lengthy statement that is worth reading. Here’s a snippet:

This decision is a relief. But it does not repair the harm done to me and my family.

My actions were entirely legal and consistent with established journalistic principles.

Yet Gov. Mike Parson falsely accused me of being a ?hacker? in a televised press conference, in press releases sent to every teacher across the state, and in attack ads aired by his political action committee. He ordered the Highway Patrol to begin a criminal investigation, forcing me to keep silent for four anxious months.

This was a political persecution of a journalist, plain and simple.

Despite this, I am proud that my reporting exposed a critical issue, and that it caused the state to take steps to better safeguard teachers? private data.

At the same time, I am concerned that the governor?s actions have left the state more vulnerable to future bad actors. His high-profile threats of legal retribution against me and the Post-Dispatch likely will have a chilling effect, deterring people from reporting security or privacy flaws in Missouri, and decreasing the chance those flaws get fixed.

This has been one of the most difficult seasons of my nearly 20-year career in journalism

Later in the letter, he notes that a week earlier, Parson himself had decried the treatment of his rejected nominee to lead the state’s Department of Health and Senior Services, noting that Parson complained that “more care was given to political gain than the harm caused to a man and his family.” Renaud noted that the same could be said of Parson’s treatment of himself:

Every word Gov. Parson wrote applies equally to the way he treated me.

He concludes by hoping that “Parson’s eyes will be opened, that he will see the harm he did to me and my family, that he will apologize, and that he will show Missourians a better way.”

And Parson showed himself to be a bigger man and did exactly that… ha ha, just kidding. Parson just kept digging, and put out a truly obnoxious statement, with no apology and continuing to insist that Renaud hacked the government’s computers even though — again, this is important, lest you just think the governor is simply technically ignorant — the FBI has already told him that there was no hacking:

“The hacking of Missouri teachers’ personally identifiable information is a clear violation of Section 56.095, RSMo, which the state takes seriously. The state did its part by investigating and presenting its findings to the Cole County Prosecutor, who has elected not to press charges, as is his prerogative.

The Prosecutor believes the matter has been properly address and resolved through non-legal means.

The state will continue to work to ensure safeguards are in place to protect state data and prevent unauthorized hacks.

This whole statement is utter hogwash and embarrassing nonsense. Again, there was no hacking whatsoever. The state messed up by putting information that should never, ever be in HTML code into HTML code, making it accessible for anyone who viewed the source on their own computer. The state messed up. The state failed to secure the data. The state sent that data to the browsers of everyone who visited certain pages on their public websites. Renaud did exactly the right thing. He discovered this terrible security flaw that the state put on the database, ethically reported it, waited until the state fixed its own error, and then reported on it.

Parson knew from the beginning that no hacking occurred. The FBI told the state that no hacking occurred. The state had prepared to thank Renaud and his colleagues at the St. Louis Post-Dispatch. It was only after Parson decided to deny, deny, deny and blame, blame, blame reporters for pointing out Parson’s own government’s failings, that this whole thing got out of hand.

The prosecutors have their own reasons for declining to prosecute, but the most likely reason is they knew they’d get laughed out of court and it would make them and Parson look even more ridiculous. Renaud chose give a heartfelt write up of what Parson’s nonsense put him through, and asked in the politest way possible for Parson to look deep inside at the harm he had caused and to apologize. Instead, Parson quadrupled down, continued to insist that his own government’s failings could be blamed on a “hack,” and insisting that he’s trying to “protect” the state when all he’s done is show why no serious tech company should do business in such a state.

Missouri: elect better politicians. Parson is an embarrassment.

Filed Under: , , , , , , , ,
Companies: st. louis post dispatch

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “Missouri's Governor Still Insists Reporter Is A Hacker, Even As Prosecutors Decline To Press Charges”

Subscribe: RSS Leave a comment
23 Comments
This comment has been deemed insightful by the community.
John Roddy (profile) says:

Re:

For defamation specifically, I don’t know. But knowingly using your office’s power like this is a pretty clear violation of the First Amendment.

For reference, here’s what happened when Texas governor Greg Abbott tried using his position to stomp out the FFRF.
https://ffrf.org/news/news-releases/item/38830-breaking-news-ffrf-wins-major-court-victory-against-gov-abbott-censorship

And do note that this case found itself in front of the notoriously government-abuse-friendly Fifth Circuit multiple times. They sided AGAINST Abbott every single one of them.

Anonymous Coward says:

Game Theory

Lets do some basic maths. So, you have 2 axis, a boolean "report" and "dont report", not a lot of wiggle room between the 2. On the other axis, you have intent. Lets start with "journalist" and "criminal". The outcome of the axis is "security of data".

"Journalist Reports": data can be secured
"Journalist Doesn’t Report: data still isn’t secure
"Criminal Reports": odd, but data has leaked but can be secured after the data has likely been swiped
"Criminal Doesn’t Report": data definitely stolen

So that gives a broad 25% chance the data can be kept safe, and a hard 50% chance that the data has been stolen.

Now add into that a middleground for nefariousness, like common citizen, and the likelyhood that the data is safe drops to 16%.

Granted, those a broad figures and would need more detailed numbers on how many criminals there are out there, but doubling down on blaming the one vector that could have brought light to the leakage is the dumbest possible choice.

What was he even trying to achieve? The only logical outcome would be for him to paint everyone who understands computers as a threat.

But even more so, he went down that route, what IT professional would go anywhere near his campaign and potentially protect his sites/campaigns/profiles if thats how he views it?

This comment has been deemed funny by the community.
Anonymous Coward says:

From the code on governor.mo.gov

/** @file

  • please_rescue_me()
  • if you can read this, send help
  • I am being held prisoner in a Missouri code factory
  • by an ignorant governor after confessing to having
  • "read a book on HTML".
  • Contact the Missouri Hacker Underground! Follow the
  • traceroute, I’ve left the crypto key under the router.
  • Hurry! I think he’s going to give another press release!
  • I don’t think I can hold this one back…
    */
David says:

Same motivation.

The prosecutors have their own reasons for declining to prosecute, but the most likely reason is they knew they’d get laughed out of court and it would make them and Parson look even more ridiculous.

Both parties are simply following the most likely path to keep their job. The job evaluation of Parson is done by the voters of Missouri. There is no point in letting a scapegoat off the hook when a voting majority would not be able to tell the difference anyhow.

This comment has been deemed insightful by the community.
That One Guy (profile) says:

'He wouldn't be so confident if he was wrong, so...'

Disgusting, but not surprising. He’s already declared who the guilty party is and as their Dear Leader showed by example you never admit when you’re wrong, instead just keep insisting you’re right and enough gullible(at best) people will take your confidence as confirmation of begin correct.

Anonymous Coward says:

I suggest a slight reframing of what Renaud actually did or didn’t do. He didn’t right-click and view source (although that’s probably what he did). The very language ignores how the web works. The magic intarwebs literally sent your computer the very HTML in question. It doesn’t need to be magically transformed by the browser to allow you to view it – that’s backwards thinking. The computer received the HTML just as Renaud examined it, but the job of the browser was to turn it into a pretty webpage.

Amanda Tucker says:

Get your score fixed

This is still hilarious to know that our information is not safe and our credit bureaus system is weak, I read comments about how hackers can increase credit score and decided to give it a try by contacting Credit-Score-Hacker. I had two derogatory accounts some few late payments, my credit score was at 500s. Honestly never thought credit hack was real but I followed his instructions and to my surprise I woke up this morning to my credit update increased score of 780 with all late payments cleared. thank you so much to this FICO Score Fixed, you just saved my life. guys if you are in the same situation and need help fixing up your credit across all three credit bureau’s contact his email: Creditscorehacker /@/gmail/./com this actually works, I can attest to credit repair hacks, it is real.

Add Your Comment

Your email address will not be published.

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...
Loading...