, 2008-09-26
In the early 90's, I attended an academic conference in Hawaii. At one presentation, a colleague from the University of California at Berkeley whom I'll refer to as "the supervisor," told a story of young hackers, who he referred to as the Urchins.
Expand all |
Post comment
Blaming the Good Samaritan
2008-09-26
Anonymous (1 replies)
Anonymous (1 replies)
Blaming the Good Samaritan
2008-09-29
Anonymous (2 replies)
Anonymous (2 replies)
Blaming the Good Samaritan
2008-09-30
Darin (4 replies)
Darin (4 replies)
Re: Blaming the Good Samaritan
2008-09-30
RU_Trustified (2 replies)
RU_Trustified (2 replies)
Blaming the Good Samaritan - You Idiots
2008-10-01
Bill (2 replies)
Bill (2 replies)
Good Samaritan? Houston Carr shouldnt be allowed to post here again
2008-10-05
Anonymous (1 replies)
Anonymous (1 replies)
Re: Good Samaritan? Houston Carr shouldnt be allowed to post here again
2008-10-06
Anonymous (2 replies)
Anonymous (2 replies)

1) Suppose you have a safe deposit box in a bank. You read on the Internet how some safe deposit boxes have locks so crappy, you can pick them with a bobby-pin. You have a bobby pin and you try it on yours and it works. You can't believe it so you try it on another box, and it works again. Are you now a theif?
2) A mall has closed for the day. You see through the big glass doors there is a motion sensor on the inside. You remember your friend telling you how some sensors can be fools by sliding a piece a paper under the door. You try it and it works. The door unlocks. You are totally supprised it worked. You get scared and immedately close the doors. Are you now breaking and entering?
What you have is a war on the curious and the educated (and usually young). People can learn things that were once "industry secrets" and they try things out to see if they work. When someone figures out how bad a security measure is (example Krypton locks and ball point pens or a university with a crapy web application) companies become scared of that knowledge as it costs them money and reputation. The knee jerk reaction is to make the individual the bad guy, because it is that person's fault for finding the flaw, not the fact the flaw was built and baked into the system.
As long as companies take this tack with "Good Samaritans," the bad guys will win. I mean, how many times you see a bad guy say, "Oh by the way, I have been robbing you for years, but I'm rich enough now, so here is how I did it."
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/481/35174#35174