Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Breach case could curtail Web flaw finders
Robert Lemos, SecurityFocus 2006-04-26

Security researchers and legal experts have voiced concern this week over the prosecution of an information-technology professional for computer intrusion after he allegedly breached a university's online application system while researching a flaw without the school's permission.

Comments Mode:
In other words, shoot the messenger 2006-04-26
Anonymous (1 replies)
Re: In other words, shoot the messenger 2006-04-26
Anonymous (5 replies)
Re: Re: In other words, shoot the messenger 2006-04-28
Anonymous
Wrong. He proved that the hole was exploitable, and provided necessary information to the proper authorities for handling. Who benefits from that action? The students whose sensitive information is at risk.

If he sold the database to spammers or the russian mafia, then his actions would have been wrong. He did not act wrongly.

The system serves up information on the internet. It is the responsibility of the system owners to serve up sensitive information in a secure manner.

McCarty didn't bring down the server, and he acted in a responsible and sensible manner after researching the system. He did nothing destructive.

However, the school acted irresponsibly in serving up sensitive information in an insecure fashion. The school as an organization is responsible for securing the students' information and should be sued for their gross negligence. Their intentions may have been good, but it doesn't matter. They put the sensitive information at risk that they are responsible for and should be held accountable.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11389/33778#33778
Re: Re: In other words, shoot the messenger 2006-05-18
Spider Jerusalem
FreeMcCarty.com 2006-04-26
Anonymous (2 replies)
Re: FreeMcCarty.com 2006-04-27
carl
Re: FreeMcCarty.com 2006-04-28
Bilz
In other words don't steal data? 2006-04-27
Anonymous (1 replies)
Imagine a world... 2006-04-27
jvf (1 replies)
Re: Imagine a world... 2006-09-26
Dve
as expected... 2006-04-27
infamous41md (2 replies)
Re: as expected... 2006-04-27
BXLE
Re: as expected... 2006-04-28
Anonymous
appearance today 2006-04-29
mv
He Should be Prosecuted 2006-05-01
Anonymous (2 replies)
Re: He Should be Prosecuted 2006-05-01
Anonymous
Re: He Should be Prosecuted 2006-05-23
Anonymous
Breach case could curtail Web flaw finders 2006-05-18
Spider Jerusalem







 

Privacy Statement
Copyright 2009, SecurityFocus