Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
The Sad Tale of a Security Whistleblower
Mark Rasch, 2003-08-18

Federal prosecutors in California went too far when they put a man in prison for disclosing a website security hole to the people at risk from it.

Comments Mode:
(shrug) - he had it coming. 2003-08-18
Penguinisto (6 replies)
(shrug) - he had it coming. 2003-08-18
Anonymous (1 replies)
(shrug) - he had it coming. 2003-08-18
Beelezubb (4 replies)
(shrug) - he had it coming. 2003-08-18
Anonymous (2 replies)
(shrug) - he had it coming. 2003-08-19
Anonymous
no good deed goes unpunished 2003-08-20
Anton Sherwood (1 replies)
no good deed goes unpunished 2003-08-25
Anonymous
(shrug) - he had it coming. 2003-08-18
CyCOtiC (2 replies)
(shrug) - he had it coming. 2003-08-19
Beelezubb
(shrug) - he had it coming. 2003-08-19
Anonymous (1 replies)
He was a FORMER employee, left 6 months before the e-mail was sent. So he should not have still been in possession of customer details. Presumably he either:
- kept confidential client information 6 months after his employment
- obtained confidential client information 6 months after his employment
- used knowledge of internal company e-mail aliases (unlikely with the way he was spreading the load)
- caused excessive load on their mail servers by trying random/generated e-mail addresses.

Whichever one he used he was doing something wrong, as well as revealing confidential company information to their clients.

The guy was right to inform the company about the vulnerability initially, and if he had records of that discussion, then they could not blame him if/when someone discovered & abused it.

The clients had a right to know the information, but he didn't have a right to tell them. The company itself had an obligation to tell them, so should be in massive trouble if the security had been compromised (and perhaps even if it wasn't, for covering up the problem).


[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/179/21602#21602
(shrug) - he had it coming. 2003-08-19
Anonymous
(shrug) - he had it coming. 2003-08-19
Mark D. Rasch (1 replies)
(beelezubb!) - he had it coming. 2003-08-19
scamerone
Re: (shrug) - he had it coming. 2003-08-18
Anonymous (1 replies)
Re: (shrug) - he had it coming. 2003-08-19
Anonymous (1 replies)
he had it coming? I don't think so!. 2003-08-19
Jack.R.Abbit
(shrug) - he had it coming. 2003-08-19
Anonymous (2 replies)
Analogies 2003-08-19
SCamerone (1 replies)
Analogies 2003-08-19
Anonymous-Jerk (2 replies)
Analogies 2003-08-20
Drg (1 replies)
Analogies 2003-08-26
Anonymous
Analogies 2003-08-27
SCamerone
"Free Speech"? Puh-leeze. 2003-08-21
Penguinisto (1 replies)
"Free Speech"? Puh-leeze. 2003-08-21
Anonymous
(shrug) - he had it coming. 2003-08-20
Anonymous (1 replies)
(shrug) - he had it coming. 2003-08-21
Penguinisto
(shrug) - he had it coming. 2003-08-26
Anonymous
Re: (shrug) - he had it coming. 2008-02-12
Anonymous
The Sad Tale of a Security Whistleblower 2003-08-18
Anonymous (1 replies)
The Sad Tale of a Security Whistleblower 2003-08-18
Anonymous (2 replies)
The Sad Tale of a Security Whistleblower 2003-08-19
Anonymous (1 replies)
The good, the bad and the ugly. 2003-08-18
Mabrick (2 replies)
The good, the bad and the ugly. 2003-08-18
Elc0chin0 (1 replies)
The good, the bad and the ugly. 2003-08-22
Anonymous
The good, the bad and the ugly. 2003-08-19
Anonymous (1 replies)
The Sad Tale of a Security Whistleblower 2003-08-18
Bob Radvanovsky (3 replies)
The Sad Tale of a Security Whistleblower 2003-08-18
Anonymous (1 replies)
The Sad Tale of a Security Whistleblower 2003-08-19
Elc0chin0 (2 replies)
The Sad Tale of a Security Whistleblower 2003-08-19
Bob Radvanovsky
The Sad Tale of a Security Whistleblower 2003-08-18
John Poindexter (1 replies)
The Sad Tale of a Security Whistleblower 2003-08-18
Anonymous (1 replies)
He did the right thing. 2003-08-18
Anonymous
The Sad Tale of a Security Whistleblower 2003-08-19
Ashamed US Citizen
Bill Gates deserves jail 2003-08-19
Anonymous
I was there when this happened 2003-08-19
Anonymous (3 replies)
I was there when this happened 2003-08-27
SCamerone
The Sad Tale of a Security Whistleblower 2003-08-19
Jerry Westrick
Idiot 2003-08-19
Anonymous (1 replies)
Idiot 2003-08-19
Elc0chin0
Read it yourself. 2003-08-19
Anonymous
As the saying goes... 2003-08-19
Anonymous
Rebel Without a Cause 2003-08-19
The Resonating Oscillator (3 replies)
Rebel Without a Cause 2003-08-20
Anonymous
Rebel Without a Cause 2003-08-20
Anonymous
Rebel Without a Cause 2003-08-20
Elc0chin0
The Government has gone too far. 2003-08-19
GWB (1 replies)
The Government has gone too far. 2003-08-19
Anonymous
The Sad Tale of a Security Whistleblower 2003-08-19
Anonymous (2 replies)
The Sad Tale of a Security Whistleblower 2003-08-20
Bob Radvanovsky
What about Cali's New Law? 2003-08-20
Nick Jacobsen (1 replies)
What about Cali's New Law? 2003-08-21
Mark D. Rasch (1 replies)
What about Cali's New Law? 2003-08-22
Elc0chin0
Discrepancies 2003-08-20
Kat (1 replies)
Discrepancies 2003-08-21
Elc0chin0
Why does Mark Rasch lie about his past jobs? 2003-08-20
One who knows (2 replies)
Oh, BTW, your zipper is open 2003-08-22
Anonymous
The Sad Tale of a Security Whistleblower 2003-08-22
Anonymous (1 replies)
Factual References 2003-08-26
Mark D. Rasch (1 replies)
Factual References 2003-08-26
Bob Radvanovsky
Fine 2003-08-28
agent1
Blame Hollywood! 2003-08-28
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus