Report a Vulnerability?

pudge on 2003-08-18T22:17:58

Read this story about a hacker who reported a security vulnerability and went to jail for it. Forget for a moment that he might have been violating an NDA, or that he might have had less-than-pure motives. Focus on the fact that he was convicted and jailed for causing an "impairment to the integrity or availability of data, a program, a system, or information without authorization" by disseminating the information.

I note that I have committed this "crime" more than once, reporting security vulnerabilities about Slash. Many of you reading this likely have as well, with other projects.

Now think about whether or not you will release security notices again any time soon.

Now Playing: Without You (Bonus Track) - Lenny Kravitz (5)


Did you see this comment?

Purdy on 2003-08-21T14:46:04

Comment from a former co-worker

Scary thought that an ISP is replicating e-mail into a SQL database, but from the comment, it sounds like the company is a scary place altogether.

Peace,

Jason

Re:Did you see this comment?

jdavidb on 2003-08-26T16:34:32

I love that guy's sig.