Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
The Sad Tale of a Security Whistleblower
Mark Rasch, 2003-08-18

Federal prosecutors in California went too far when they put a man in prison for disclosing a website security hole to the people at risk from it.

Comments Mode:
(shrug) - he had it coming. 2003-08-18
Penguinisto (6 replies)
(shrug) - he had it coming. 2003-08-18
Anonymous (1 replies)
(shrug) - he had it coming. 2003-08-18
Beelezubb (4 replies)
(shrug) - he had it coming. 2003-08-18
Anonymous (2 replies)
(shrug) - he had it coming. 2003-08-19
Anonymous
no good deed goes unpunished 2003-08-20
Anton Sherwood (1 replies)
no good deed goes unpunished 2003-08-25
Anonymous
(shrug) - he had it coming. 2003-08-18
CyCOtiC (2 replies)
Beelezubb,
I think you have miss read the article. He was an employee. Which in my eyes does not constitute as a breaking and steeling client details. The actual article is a double edge sword, your damed if you do damed if you don't.
What would happen if he was the security expert in charge of the maintaining integrity of data and someone else found the vulnerability? He would have lost his job just as quickly as being a whistle blower.
Bugtraq is all well and good. What happens if the developers never visit of have knowledge of bugtraq? The Organisation I work for had no reason for visiting Bugtraq and their product is full of security holes. They are one of largest super funds providers in the US, asia pacific region. I could post volumes of vulnerbilities to bugtraq, and none of them would be fixed because the developers know little about secure programming let aloan what bugtraq is. Their idea of security is lets have a firewall, and rely on microsoft to release security patches. Buffer overflows, DOS attacks and the term RDBMs are martian to these programmers. Who still program using the old card programming principles, and old cobal development techniques. What do you do about educating people who still thinks cobal rocks?

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/179/21572#21572
(shrug) - he had it coming. 2003-08-19
Beelezubb
(shrug) - he had it coming. 2003-08-19
Anonymous (1 replies)
(shrug) - he had it coming. 2003-08-19
Anonymous
(shrug) - he had it coming. 2003-08-19
Mark D. Rasch (1 replies)
(beelezubb!) - he had it coming. 2003-08-19
scamerone
Re: (shrug) - he had it coming. 2003-08-18
Anonymous (1 replies)
Re: (shrug) - he had it coming. 2003-08-19
Anonymous (1 replies)
he had it coming? I don't think so!. 2003-08-19
Jack.R.Abbit
(shrug) - he had it coming. 2003-08-19
Anonymous (2 replies)
Analogies 2003-08-19
SCamerone (1 replies)
Analogies 2003-08-19
Anonymous-Jerk (2 replies)
Analogies 2003-08-20
Drg (1 replies)
Analogies 2003-08-26
Anonymous
Analogies 2003-08-27
SCamerone
"Free Speech"? Puh-leeze. 2003-08-21
Penguinisto (1 replies)
"Free Speech"? Puh-leeze. 2003-08-21
Anonymous
(shrug) - he had it coming. 2003-08-20
Anonymous (1 replies)
(shrug) - he had it coming. 2003-08-21
Penguinisto
(shrug) - he had it coming. 2003-08-26
Anonymous
Re: (shrug) - he had it coming. 2008-02-12
Anonymous
The Sad Tale of a Security Whistleblower 2003-08-18
Anonymous (1 replies)
The Sad Tale of a Security Whistleblower 2003-08-18
Anonymous (2 replies)
The Sad Tale of a Security Whistleblower 2003-08-19
Anonymous (1 replies)
The good, the bad and the ugly. 2003-08-18
Mabrick (2 replies)
The good, the bad and the ugly. 2003-08-18
Elc0chin0 (1 replies)
The good, the bad and the ugly. 2003-08-22
Anonymous
The good, the bad and the ugly. 2003-08-19
Anonymous (1 replies)
The Sad Tale of a Security Whistleblower 2003-08-18
Bob Radvanovsky (3 replies)
The Sad Tale of a Security Whistleblower 2003-08-18
Anonymous (1 replies)
The Sad Tale of a Security Whistleblower 2003-08-19
Elc0chin0 (2 replies)
The Sad Tale of a Security Whistleblower 2003-08-19
Bob Radvanovsky
The Sad Tale of a Security Whistleblower 2003-08-18
John Poindexter (1 replies)
The Sad Tale of a Security Whistleblower 2003-08-18
Anonymous (1 replies)
He did the right thing. 2003-08-18
Anonymous
The Sad Tale of a Security Whistleblower 2003-08-19
Ashamed US Citizen
Bill Gates deserves jail 2003-08-19
Anonymous
I was there when this happened 2003-08-19
Anonymous (3 replies)
I was there when this happened 2003-08-27
SCamerone
The Sad Tale of a Security Whistleblower 2003-08-19
Jerry Westrick
Idiot 2003-08-19
Anonymous (1 replies)
Idiot 2003-08-19
Elc0chin0
Read it yourself. 2003-08-19
Anonymous
As the saying goes... 2003-08-19
Anonymous
Rebel Without a Cause 2003-08-19
The Resonating Oscillator (3 replies)
Rebel Without a Cause 2003-08-20
Anonymous
Rebel Without a Cause 2003-08-20
Anonymous
Rebel Without a Cause 2003-08-20
Elc0chin0
The Government has gone too far. 2003-08-19
GWB (1 replies)
The Government has gone too far. 2003-08-19
Anonymous
The Sad Tale of a Security Whistleblower 2003-08-19
Anonymous (2 replies)
The Sad Tale of a Security Whistleblower 2003-08-20
Bob Radvanovsky
What about Cali's New Law? 2003-08-20
Nick Jacobsen (1 replies)
What about Cali's New Law? 2003-08-21
Mark D. Rasch (1 replies)
What about Cali's New Law? 2003-08-22
Elc0chin0
Discrepancies 2003-08-20
Kat (1 replies)
Discrepancies 2003-08-21
Elc0chin0
Why does Mark Rasch lie about his past jobs? 2003-08-20
One who knows (2 replies)
Oh, BTW, your zipper is open 2003-08-22
Anonymous
The Sad Tale of a Security Whistleblower 2003-08-22
Anonymous (1 replies)
Factual References 2003-08-26
Mark D. Rasch (1 replies)
Factual References 2003-08-26
Bob Radvanovsky
Fine 2003-08-28
agent1
Blame Hollywood! 2003-08-28
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus