Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Post to Bugtraq -- Go to Jail
Mark Rasch, 2002-08-05

HP's ill-advised DMCA threat actually had a few legal teeth. Will federal prosecutors soon start chomping at bug finders?

Comments Mode:
Post to Bugtraq -- Go to Jail 2002-08-05
ktwo (1 replies)
I support the DMCA wholeheartedly. The DMCA keeps vulnerabilities and exploits underground and prevents seurity measures form being implemented. KILL WHITEHATS....

[ more ]  [ reply ]
Post to Bugtraq -- Go to Jail 2002-08-07
Anonymous
So in this case K2 couldn't you go to trial too since you wrote and published an exploit for the same hole? I believe this was posted to bugtraq in Sept 2001?


/* Copyright (c) 2000 ADM */
/* All Rights Reserved */
...

[ more ]  [ reply ]
FUD FUD FUD Post to Bugtraq -- Go to Jail 2002-08-05
FUD PATROL
Rasch is a FUD Monger. There is no "engineer", there is no "employer",no "message" to Bugtraq describing anything and there is no "use" of the DMCA. He makes their threat of the DMCA seem as a statement of fact. That they could use it, and that it can be used. Nonsense.

SnoSoft: "a loosely organi...

[ more ]  [ reply ]
Post to Bugtraq -- Go to Jail 2002-08-06
Anonymous (1 replies)
"A few days after the HP letter was made public, a company public relations official reversed course, noting that the initial threat "was not consistent or indicative of HP's policy" and that "HP will not use the DMCA to stifle research or impede the flow of information that would benefit our custom...

[ more ]  [ reply ]
Post to Bugtraq -- Go to Jail 2002-08-13
EMATT
So..... HP knew about this bug in Tru64 a year ago?
They knew about it before they bought Compaq and Tru64?
And they should have fixed it a year ago?...

[ more ]  [ reply ]
Post to Bugtraq -- Go to Jail 2002-08-07
Psuedo-Anonymous Coward (1 replies)
In the letter from HP, extortion under Massachusetts General Law, Chapter 265, Section 25, was mentioned. "Finally, SnoSoft and its members may face additional penalties under various criminal statues of the Commonwealth of Massachusetts including, but not limited to, criminal extortion (M.G.L. c. 2...

[ more ]  [ reply ]
Post to Bugtraq -- Go to Jail 2002-08-13
Mark D. Rasch
Saying fix your software or I will hack you may be extortionate or otherwise criminal. Saying fix your software or I will reveal the vulnerability is probably protected speech. Saying, fix your software or I will release an exploit for others to hack into you is sort of in between....

[ more ]  [ reply ]
Post to Bugtraq -- Go to Jail: Now hacker can get in! 2002-08-07
Alberto Cozer
HP had a "very smart" approach. Now the Security Specialists that usually subscribe to those mail lists won't get the information about new security threats.

On the other hand, all the professional hackers that exchange messages about vulnerabilities and threats in the underground will be able t...

[ more ]  [ reply ]
Post to Bugtraq -- Go to Jail 2002-08-08
Anonymous
Sounds like Security Research should post from outside the US....

[ more ]  [ reply ]
Post to Bugtraq -- Go to Jail 2002-08-10
blacklight
HP is making the following points to all of us by threatening prosecution: (1) HP is not a responsible vendor - everybody has bugs, but the dividing line between a responsible vendor and an irresponsible one is the willingness to deal with the bugs as they are being announced; (2) HP's top priority ...

[ more ]  [ reply ]
Post to Bugtraq -- Go to Jail 2002-08-12
Mel
DMCA is a lousy law. I don't see the justification for it in the first place. Unauthorized use of copyrighted material (unless covered by Fair Use) is a crime. Why do you need another law (badly open to abuse) to make it a crime to defeat a measure which is seeking to prevent you from commiting a cr...

[ more ]  [ reply ]
Post to Bugtraq -- Go to Jail -- Redux 2002-08-12
Annoyed at this whole mess
This little 'threat' or FUD is just the latest parting shot by Vendors who don't want to have to take the time to write their code securely. This is further complicated by the rash of 'security professionals' that have recently added themselves to this field of endeavor after the lure of money in t...

[ more ]  [ reply ]
Post to Bugtraq -- Go to Jail 2002-08-13
T-1000

Seems someone missunderstand how it's dangerous to kill bu g report information which SHOULD be posted to bugtraq. There's only two ways:

1) If OS/software errors is posted to bugtraq, the software/OS patch comes quickly and people can avoid to get their systems compromised by hackers(do not mi...

[ more ]  [ reply ]
Post to Bugtraq -- Go to Jail 2002-08-13
Gonlo
IMHO the law and the justice often are in disagree.

Isn't the mission of the consumer to show the factory bugs of the products. If the provider sent to the jail a person for show that, then all others customers can send to the jail the provider in order to release a very risk and unstable hw/sw p...

[ more ]  [ reply ]
Post to Bugtraq -- Go to Jail 2002-08-14
A disgrunted American
Goddamn, there is something wrong with the country/world when somebody has the ability to educate the world and it becomes illegal for education in the greatest form, security.

If one man can beat you to the vulnerability, beat him to the patch.

You missed the code, your goddamn fault HP!...

[ more ]  [ reply ]
Post to Bugtraq -- Go to Jail 2002-08-16
Coldman
One side - software vendors are not responsible for software bugs and make no warranties, but they sue consumers.

Other side - consumers doesn't have any right to sue vendors, just because they (vendors) explicitly refrain from any responsibility.

This is strange world...
...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus