Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Panel Debates Hacker Amnesty
Kevin Poulsen, SecurityFocus 2002-03-25

Should hack-and-tell intruders who warn companies about security holes do time with hardened criminals? Security experts probe the ethics of hacking.

Comments Mode:
Panel Debates Hacker Amnesty 2002-03-26
Anonymous (2 replies)
Panel Debates Hacker Amnesty 2002-03-26
Anonymous (1 replies)
Panel Debates Hacker Amnesty 2002-03-26
Anonymous
Panel Debates Hacker Amnesty 2002-03-26
Surreal (1 replies)
Panel Debates Hacker Amnesty 2002-03-26
Anonymous
Panel Debates Hacker Amnesty 2002-03-26
Robert P (1 replies)
Panel Debates Hacker Amnesty 2002-03-26
Anonymous
Panel Debates Hacker Amnesty 2002-03-27
FlorX
Say a system is vulnerable.

A "bad" hacker stumbles upon it, hacks it an damages/abuses/sells important information of the server.

Then the company will have to pay a large amount of money to recover what was lost without tracing back the hacker (if he was a good one).

else

A "good" hacker runs a "security check" (application of various methods to gain access without abusing priviledges or modifying logs) in order to provide the company that owns the server important information regarding its system and its security.

This senario would illustrate an On-line Banking Costumer that discovers that the system is exploitable by a bug he (or someone else discovered). How would he act? If he reports it, then it means he hacked it or gained illegal access. If he doesnt, he leaves his and other customers information available to malicious hackers.

Which would you prefer?

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/358/11446#11446
Panel Debates Hacker Amnesty 2002-03-27
Martin
Panel Debates Hacker Amnesty 2002-03-27
Anonymous
Panel Debates Hacker Amnesty 2002-03-27
Ichinin (Ichinin (at) suespammers (dot) org [email concealed], TEXT messages only NO HTML)
Panel Debates Hacker Amnesty 2002-03-27
To the armchair sec analysts
Panel Debates Hacker Amnesty 2002-03-27
Anonymous
Panel Debates Hacker Amnesty 2002-03-27
Andy Richmond
Panel Debates Hacker Amnesty 2002-03-27
Patrick
Panel Debates Hacker Amnesty 2002-03-28
Dimitri Sinchovich
Panel Debates Hacker Amnesty 2002-03-28
Anonymous
Panel Debates Hacker Amnesty 2002-03-28
Anonymous
Panel Debates Hacker Amnesty 2002-03-29
Snagnbytz
NYT Should Prosecute... 2002-03-29
Brian Powell (1 replies)
NYT Should Prosecute... 2002-04-01
Anonymous
Panel Debates Hacker Amnesty 2002-03-31
Anonymous
Panel Debates Hacker Amnesty 2002-03-31
Anonymous
Damn the man! 2002-04-01
RK2K
What else did he get in to? 2002-04-01
CrazyNetworkGuy
Panel Debates Hacker Amnesty 2002-04-02
Hamster1
Panel Debates Hacker Amnesty 2002-04-02
John in Virginia
After reading these posts... 2002-04-02
Robert Perriero (1 replies)
I agree completely 2002-04-02
Scorp
Panel Debates Hacker Amnesty 2002-04-02
John P.
Panel Debates Hacker Amnesty 2002-04-02
Anonymous Lady
Panel Debates Hacker Amnesty 2002-04-03
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus