, 2003-08-18
Federal prosecutors in California went too far when they put a man in prison for disclosing a website security hole to the people at risk from it.
Expand all |
Post comment
(shrug) - he had it coming.
2003-08-18
Penguinisto (6 replies)
Penguinisto (6 replies)
(shrug) - he had it coming.
2003-08-18
Anonymous (1 replies)
Anonymous (1 replies)
(shrug) - he had it coming.
2003-08-18
Beelezubb (4 replies)
Beelezubb (4 replies)
(shrug) - he had it coming.
2003-08-18
Anonymous (2 replies)
Anonymous (2 replies)
(shrug) - he had it coming.
2003-08-18
CyCOtiC (2 replies)
CyCOtiC (2 replies)
(shrug) - he had it coming.
2003-08-19
Mark D. Rasch (1 replies)
Mark D. Rasch (1 replies)
Re: (shrug) - he had it coming.
2003-08-18
Anonymous (1 replies)
Anonymous (1 replies)
(shrug) - he had it coming.
2003-08-19
Anonymous (2 replies)
Anonymous (2 replies)
The Sad Tale of a Security Whistleblower
2003-08-18
Anonymous (5 replies)
Anonymous (5 replies)
The Sad Tale of a Security Whistleblower
2003-08-18
Anonymous (2 replies)
Anonymous (2 replies)
The Sad Tale of a Security Whistleblower
2003-08-18
Anonymous (1 replies)
Anonymous (1 replies)
The Sad Tale of a Security Whistleblower
2003-08-18
Anonymous (2 replies)
Anonymous (2 replies)
The Sad Tale of a Security Whistleblower
2003-08-19
Anonymous (1 replies)
Anonymous (1 replies)
The good, the bad and the ugly.
2003-08-18
Mabrick (2 replies)
Mabrick (2 replies)
The Sad Tale of a Security Whistleblower
2003-08-18
Anonymous (8 replies)
Anonymous (8 replies)
The Sad Tale of a Security Whistleblower
2003-08-18
Chris Humphries (3 replies)
Chris Humphries (3 replies)
The Sad Tale of a Security Whistleblower
2003-08-18
Bob Radvanovsky (3 replies)
Bob Radvanovsky (3 replies)
It might have been better to talk to the press.
2003-08-18
Anonymous (2 replies)
Anonymous (2 replies)
The Sad Tale of a Security Whistleblower or How to cover your corporate @$$ when sweeping a problem under the rug
2003-08-19
Ashaman (1 replies)
Ashaman (1 replies)
The Sad Tale of a Security Whistleblower or How to cover your corporate @$$ when sweeping a problem under the rug
2003-08-19
Elc0chin0 (1 replies)
Elc0chin0 (1 replies)
Just where he has got the email addresses from?
2003-08-19
Anonymous (1 replies)
Anonymous (1 replies)
What about Cali's New Law?
2003-08-20
Nick Jacobsen (1 replies)
Nick Jacobsen (1 replies)
The Sad Tale of a Security Whistleblower
2003-08-22
Anonymous (1 replies)
Anonymous (1 replies)

Assuming you're not fed up yet, here's
my analogy:
1. I used to work for a company A, developing
product X. (Pick whatever industry you can imagine, e.g. Firestone tires)
2. There's a security problem with the product and I try to convince management
to fix it.
3a. I quit the company because they're
idiots and I was stupid enough to let them
know what I think of them while I was working
there.
Obviously they don't like me too much.
or
3b. I get fired because I'm an annoying pain
in the posterior who doesn't contribute to
the dilbertesque bottom line. Now I'm pissed.
4. Regardless of motivitation 3a or 3b, I decide something needs to happen to either
help the customers or get even with company A. We will never know the real motive.
5. Action! I get myself some client addresses through google, e.g. 10-50 per day and start emailing them anonymously.
Whether that's a crime or not is for the law to decide, but jail seems a little harsh.
My guess is that company A is more pissed of at Bret than he is at them.
Final conclusion is this is not a company I would like to work for. Having said this they just created double damage for themselves.
P.S.: Was trying to be objective and not trying to defende this guy.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/179/21629#21629