, 2003-08-18
Federal prosecutors in California went too far when they put a man in prison for disclosing a website security hole to the people at risk from it.
Expand all |
Post comment
(shrug) - he had it coming.
2003-08-18
Penguinisto (6 replies)
Penguinisto (6 replies)
(shrug) - he had it coming.
2003-08-18
Anonymous (1 replies)
Anonymous (1 replies)
(shrug) - he had it coming.
2003-08-18
Beelezubb (4 replies)
Beelezubb (4 replies)
(shrug) - he had it coming.
2003-08-18
Anonymous (2 replies)
Anonymous (2 replies)
(shrug) - he had it coming.
2003-08-19
Mark D. Rasch (1 replies)
Mark D. Rasch (1 replies)
Re: (shrug) - he had it coming.
2003-08-18
Anonymous (1 replies)
Anonymous (1 replies)
(shrug) - he had it coming.
2003-08-19
Anonymous (2 replies)
Anonymous (2 replies)
The Sad Tale of a Security Whistleblower
2003-08-18
Anonymous (5 replies)
Anonymous (5 replies)
The Sad Tale of a Security Whistleblower
2003-08-18
Anonymous (2 replies)
Anonymous (2 replies)
The Sad Tale of a Security Whistleblower
2003-08-18
Anonymous (1 replies)
Anonymous (1 replies)
The Sad Tale of a Security Whistleblower
2003-08-18
Anonymous (2 replies)
Anonymous (2 replies)
The Sad Tale of a Security Whistleblower
2003-08-19
Anonymous (1 replies)
Anonymous (1 replies)
The good, the bad and the ugly.
2003-08-18
Mabrick (2 replies)
Mabrick (2 replies)
The Sad Tale of a Security Whistleblower
2003-08-18
Anonymous (8 replies)
Anonymous (8 replies)
The Sad Tale of a Security Whistleblower
2003-08-18
Chris Humphries (3 replies)
Chris Humphries (3 replies)
The Sad Tale of a Security Whistleblower
2003-08-18
Bob Radvanovsky (3 replies)
Bob Radvanovsky (3 replies)
It might have been better to talk to the press.
2003-08-18
Anonymous (2 replies)
Anonymous (2 replies)
The Sad Tale of a Security Whistleblower or How to cover your corporate @$$ when sweeping a problem under the rug
2003-08-19
Ashaman (1 replies)
Ashaman (1 replies)
The Sad Tale of a Security Whistleblower or How to cover your corporate @$$ when sweeping a problem under the rug
2003-08-19
Elc0chin0 (1 replies)
Elc0chin0 (1 replies)
Just where he has got the email addresses from?
2003-08-19
Anonymous (1 replies)
Anonymous (1 replies)
What about Cali's New Law?
2003-08-20
Nick Jacobsen (1 replies)
Nick Jacobsen (1 replies)
The Sad Tale of a Security Whistleblower
2003-08-22
Anonymous (1 replies)
Anonymous (1 replies)

I think you have miss read the article. He was an employee. Which in my eyes does not constitute as a breaking and steeling client details. The actual article is a double edge sword, your damed if you do damed if you don't.
What would happen if he was the security expert in charge of the maintaining integrity of data and someone else found the vulnerability? He would have lost his job just as quickly as being a whistle blower.
Bugtraq is all well and good. What happens if the developers never visit of have knowledge of bugtraq? The Organisation I work for had no reason for visiting Bugtraq and their product is full of security holes. They are one of largest super funds providers in the US, asia pacific region. I could post volumes of vulnerbilities to bugtraq, and none of them would be fixed because the developers know little about secure programming let aloan what bugtraq is. Their idea of security is lets have a firewall, and rely on microsoft to release security patches. Buffer overflows, DOS attacks and the term RDBMs are martian to these programmers. Who still program using the old card programming principles, and old cobal development techniques. What do you do about educating people who still thinks cobal rocks?
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/179/21572#21572