, 2003-08-18
Federal prosecutors in California went too far when they put a man in prison for disclosing a website security hole to the people at risk from it.
Expand all |
Post comment
The Sad Tale of a Security Whistleblower
2003-08-18
Anonymous (5 replies)
Anonymous (5 replies)
The Sad Tale of a Security Whistleblower
2003-08-18
Anonymous (2 replies)
Anonymous (2 replies)
The Sad Tale of a Security Whistleblower
2003-08-18
Anonymous (1 replies)
Anonymous (1 replies)
The Sad Tale of a Security Whistleblower
2003-08-18
Anonymous (2 replies)
Anonymous (2 replies)
The Sad Tale of a Security Whistleblower
2003-08-19
Anonymous (1 replies)
Anonymous (1 replies)
The good, the bad and the ugly.
2003-08-18
Mabrick (2 replies)
Mabrick (2 replies)
The Sad Tale of a Security Whistleblower
2003-08-18
Anonymous (8 replies)
Anonymous (8 replies)
The Sad Tale of a Security Whistleblower
2003-08-18
Chris Humphries (3 replies)
Chris Humphries (3 replies)
The Sad Tale of a Security Whistleblower
2003-08-18
Bob Radvanovsky (3 replies)
Bob Radvanovsky (3 replies)
It might have been better to talk to the press.
2003-08-18
Anonymous (2 replies)
Anonymous (2 replies)
The Sad Tale of a Security Whistleblower or How to cover your corporate @$$ when sweeping a problem under the rug
2003-08-19
Ashaman (1 replies)
Ashaman (1 replies)
The Sad Tale of a Security Whistleblower or How to cover your corporate @$$ when sweeping a problem under the rug
2003-08-19
Elc0chin0 (1 replies)
Elc0chin0 (1 replies)
Just where he has got the email addresses from?
2003-08-19
Anonymous (1 replies)
Anonymous (1 replies)
What about Cali's New Law?
2003-08-20
Nick Jacobsen (1 replies)
Nick Jacobsen (1 replies)
The Sad Tale of a Security Whistleblower
2003-08-22
Anonymous (1 replies)
Anonymous (1 replies)

FWIW, if I were this guy, I'd just post the vuln and its explanation to Bugtraq and similar lists, and be sure to name names. If that didn't shame Tornado into fixing the problem, then they deserve whatever gets laid on them by the first script kiddie to take advantage of it.
It just doesn't make sense to go in (esp. if you're no longer an employee) and take matters into your own hands.
As far as the prosecution, IMHO they had a wide variety of laws that had already been broken by the guy - there was no sense in convoluting a law just to make an example of him.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/179/21525#21525