4 ms·
Unfortunately this happens more than you might think and other Australian companies seem to have a similar approach to dealing with security findings. Many year
by zemaj 15y ago
Unfortunately this happens more than you might think and other Australian companies seem to have a similar approach to dealing with security findings. Many years ago I found a huge hole in a large company's Australian website that allowed me to download their entire database of customer records including addresses and plain text passwords, by a similar method of just changing url parameters. This was millions of consumer records from a -big- international brand.
Instead of warning the public, that their records may have been compromised, they focused on me. I was immediately slapped with legal threats via phone, email and mail. They took my original email apart, saying that by modifying the url and downloading the database I had illegally obtained this data, I could be prosecuted under xyz law etc... They ended it by saying that if I ever spoke about it publicly I would be taken to court.
Needless to say I attempted to take my issue directly to several Australian newspapers. I talked to a couple, but none wrote a story. I don't understand why - this was 7 years ago, perhaps they didn't understand the issue. I spoke to a lawyer who told me that there was nothing I could do. They'd given me a way out so I should just take it and try to forget what happened. In the end I convinced myself that perhaps I was in the wrong. No one would listen to me. At the time I was a lot younger and had less resources. I would of course not deal with it the same way now. However, I'm not interesting in digging up the past - the proof is long gone, but the lesson stays the same.
There should be a government body to whom security breaches like these can be reported. Companies can not be trusted to police themselves when it comes to private data.
- guard-of-terra 15y agoThe sad thing is: the only way those people would learn is when every hole would be pastebinned after such response. After two or three loud cases, they would probably figure it out. Or not. I pity their customers, tho.
- VMG 15y agoThere should be a government body to whom security breaches like these can be reported. Companies can not be trusted to police themselves when it comes to private data. If the government is incompetent enough to prosecute you for making HTTP requests with non-obvious URLs, do you really have much hope for an smart government agency dealing with this?
- ashishgandhi 15y agoI'm in Singapore and have been brought up in India, so out of curiosity, how is the scene in the US? (Because I don't know about how things are in practice but from the outside it still looks to me as the land of the free.)
- VMG 15y agoI wouldn't know, I'm from Germany. But personally, I'm scared of a German government agency defining and deciding web-app security.
- Xylakant 15y agoActually, the BSI (Bundesamt für Sicherheit in der Informationstechnik) may not be high-profile but seems in general reasonably knowledgeable and neutral. But I guess in Germany you'd report such a failure via the CCC or a similar organization.
- ChrisNorstrom 15y agoFor the longest time I didn't understand why 'anonymous' and 'lulsec' and others went around hacking into sites. Now I know why... When you're punished for being good, it feels so good to be bad.
- rmc 15y agoit feels so good to be bad. Or, they (lulzsec) think they are doing good and ignore when the police et al. say they are being bad, because those same police and agencies also say this guy in the submitted article is being bad.
- caf 15y agoThere should be a government body to whom security breaches like these can be reported. Companies can not be trusted to police themselves when it comes to private data. You could try the DSD CSOC. They're mainly interested in threats to Government agencies but may pass it on.
- ra 15y agoAt least this time around SMH have apparently understood the situation and called out First State Super. Also; NSW Police said it was not taking any further action on this matter. "There was no criminal offence committed and the company in question has been informed of the outcome. It was more a case of a civic-minded person reporting a potential security breach." I 100% agree that the government should handle these situations, unfortunately the closest thing we have is The Privacy Commission - which is completely toothless.
- pavel_lishin 15y ago> I 100% agree that the government should handle these situations Isn't that like asking the government to intervene when I notice that my next-door neighbor leaves his car unlocked with the keys in the ignition when he comes home from work?
- mikeash 15y agoSecurity of one's own property is a completely different matter than a bank's security of its holdings of other people's property.
- pavel_lishin 15y agoWhat if the car belongs to the local bank manager who left his work laptop on the passenger seat?
- mikeash 15y agoIf his work laptop contains customer-related information which endangers their accounts, that would definitely be a matter for the police.