Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
The Sad Tale of a Security Whistleblower
Mark Rasch, 2003-08-18

Federal prosecutors in California went too far when they put a man in prison for disclosing a website security hole to the people at risk from it.

Comments Mode:
(shrug) - he had it coming. 2003-08-18
Penguinisto (6 replies)
(shrug) - he had it coming. 2003-08-18
Anonymous (1 replies)
(shrug) - he had it coming. 2003-08-18
Beelezubb (4 replies)
(shrug) - he had it coming. 2003-08-18
Anonymous (2 replies)
(shrug) - he had it coming. 2003-08-19
Anonymous
no good deed goes unpunished 2003-08-20
Anton Sherwood (1 replies)
no good deed goes unpunished 2003-08-25
Anonymous
(shrug) - he had it coming. 2003-08-18
CyCOtiC (2 replies)
(shrug) - he had it coming. 2003-08-19
Beelezubb
(shrug) - he had it coming. 2003-08-19
Anonymous (1 replies)
(shrug) - he had it coming. 2003-08-19
Anonymous
(shrug) - he had it coming. 2003-08-19
Mark D. Rasch (1 replies)
(beelezubb!) - he had it coming. 2003-08-19
scamerone
Re: (shrug) - he had it coming. 2003-08-18
Anonymous (1 replies)
Re: (shrug) - he had it coming. 2003-08-19
Anonymous (1 replies)
he had it coming? I don't think so!. 2003-08-19
Jack.R.Abbit
(shrug) - he had it coming. 2003-08-19
Anonymous (2 replies)
Analogies 2003-08-19
SCamerone (1 replies)
Analogies 2003-08-19
Anonymous-Jerk (2 replies)
Analogies 2003-08-20
Drg (1 replies)
Analogies 2003-08-26
Anonymous
Analogies 2003-08-27
SCamerone
"Free Speech"? Puh-leeze. 2003-08-21
Penguinisto (1 replies)
"Free Speech"? Puh-leeze. 2003-08-21
Anonymous
(shrug) - he had it coming. 2003-08-20
Anonymous (1 replies)
(shrug) - he had it coming. 2003-08-21
Penguinisto
(shrug) - he had it coming. 2003-08-26
Anonymous
Re: (shrug) - he had it coming. 2008-02-12
Anonymous
The Sad Tale of a Security Whistleblower 2003-08-18
Anonymous (1 replies)
The Sad Tale of a Security Whistleblower 2003-08-18
Anonymous (2 replies)
The Sad Tale of a Security Whistleblower 2003-08-19
Anonymous (1 replies)
The good, the bad and the ugly. 2003-08-18
Mabrick (2 replies)
The good, the bad and the ugly. 2003-08-18
Elc0chin0 (1 replies)
The good, the bad and the ugly. 2003-08-22
Anonymous
The good, the bad and the ugly. 2003-08-19
Anonymous (1 replies)
The good, the bad and the ugly. 2003-08-25
Tomdaq
I agree that McDanel's response was justified. In fact I believe he had an obligation to take some sort of action that would lead to improved customer privacy. Tornado is definitely obligated to do so according to California state law. Furthermore, to assume McDanel stole an email list from Tornado is just that, an assumption. There are tons of legitimate ways to find email addresses.

I personally would have taken a bit more creative approach. He should have signed himself up for the service. As a legitimate customer, he could have taken the identified vulnerability to state prosecutors and put Tornado on the other side of the table.

The following California state law gives any organization, for-profit or otherwise plenty of fiscal incentive to fix security holes. As you stated "the customer's best interest are a means to the primary purpose" which makes the customer's best interest the company's best interest by default.

"According to SB 1386, any business, government agency, or individual who conducts business in California, is required to inform their customers of any incident where their unencrypted personal information could have been accessed by an unauthorized person. The law pertains to any organization, whether based in California or in other parts of the country. Personal information includes an individual's name along with their Social Security number, driver's license number, state identification number, or credit or debit card numbers with security codes." (obtained from www.nfr.com)

Tornado is located in California so this law absolutely applies.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/179/21791#21791
The Sad Tale of a Security Whistleblower 2003-08-18
Bob Radvanovsky (3 replies)
The Sad Tale of a Security Whistleblower 2003-08-18
Anonymous (1 replies)
The Sad Tale of a Security Whistleblower 2003-08-19
Elc0chin0 (2 replies)
The Sad Tale of a Security Whistleblower 2003-08-19
Bob Radvanovsky
The Sad Tale of a Security Whistleblower 2003-08-18
John Poindexter (1 replies)
The Sad Tale of a Security Whistleblower 2003-08-18
Anonymous (1 replies)
He did the right thing. 2003-08-18
Anonymous
The Sad Tale of a Security Whistleblower 2003-08-19
Ashamed US Citizen
Bill Gates deserves jail 2003-08-19
Anonymous
I was there when this happened 2003-08-19
Anonymous (3 replies)
I was there when this happened 2003-08-27
SCamerone
The Sad Tale of a Security Whistleblower 2003-08-19
Jerry Westrick
Idiot 2003-08-19
Anonymous (1 replies)
Idiot 2003-08-19
Elc0chin0
Read it yourself. 2003-08-19
Anonymous
As the saying goes... 2003-08-19
Anonymous
Rebel Without a Cause 2003-08-19
The Resonating Oscillator (3 replies)
Rebel Without a Cause 2003-08-20
Anonymous
Rebel Without a Cause 2003-08-20
Anonymous
Rebel Without a Cause 2003-08-20
Elc0chin0
The Government has gone too far. 2003-08-19
GWB (1 replies)
The Government has gone too far. 2003-08-19
Anonymous
The Sad Tale of a Security Whistleblower 2003-08-19
Anonymous (2 replies)
The Sad Tale of a Security Whistleblower 2003-08-20
Bob Radvanovsky
What about Cali's New Law? 2003-08-20
Nick Jacobsen (1 replies)
What about Cali's New Law? 2003-08-21
Mark D. Rasch (1 replies)
What about Cali's New Law? 2003-08-22
Elc0chin0
Discrepancies 2003-08-20
Kat (1 replies)
Discrepancies 2003-08-21
Elc0chin0
Why does Mark Rasch lie about his past jobs? 2003-08-20
One who knows (2 replies)
Oh, BTW, your zipper is open 2003-08-22
Anonymous
The Sad Tale of a Security Whistleblower 2003-08-22
Anonymous (1 replies)
Factual References 2003-08-26
Mark D. Rasch (1 replies)
Factual References 2003-08-26
Bob Radvanovsky
Fine 2003-08-28
agent1
Blame Hollywood! 2003-08-28
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus