4 ms·
I feel like this article reflects an overall positive change in the way disclosure is handled today. Back in the 90s this was the sort of thing every company di
by f0e4c2f7 3y ago
I feel like this article reflects an overall positive change in the way disclosure is handled today. Back in the 90s this was the sort of thing every company did. Companies would threaten lawsuits, or disclosure in the first place seemed legally dubious. Discussions in forums / BBS's would be around if it was safe to disclose at all. Suggestions of anonymous email accounts and that sort of thing.
Sure you still get some of that today. An especially old fashioned company, or in this case naive college students but overall things have shifted quite dramatically in favor of disclosure. Dedicated middle men who protect security researcher's identities, Large enterprises encouraging and celebrating disclosure, six figure bug bounties, even the laws themselves have changed to be more friendly to security researchers.
I'm sure it was quite unpleasant to go through this for the author, but it's a nice reminder that situations like this are now somewhat rare as they used to be the norm (or worse).
- formerly_proven 3y ago> Suggestions of anonymous email accounts and that sort of thing. This is still the way to go even in many western countries.
- _greim_ 3y agoI wonder if this was the students' attempt to protect their future careers as much as anything—"keep quiet about this or else"—especially given the issues were quickly fixed. In that sense it differs from the classic 90s era retaliation. From the students' POV it was probably quite terrifying. I wouldn't discount intervention by wealthy parents either, but of course I know nothing of the situation or the people involved.
- lamontcg 3y agoThe problem is that it is still entirely illegal to do this kind of hacking without any permission. The fact that a lot of companies have embraced bug bounties and encourage this kind of stuff against them unfortunately teaches "kids" that this kind of thing is perfectly legal/moral/ethical/etc. As this story shows though you're really rolling the dice, even though it worked out in this case. > Discussions in forums / BBS's would be around if it was safe to disclose at all. Suggestions of anonymous email accounts and that sort of thing. This is probably still a better idea if you don't have the cooperation of the target of the hack via some stated bug bounty program. But that doesn't help the security researcher "make a name" for themselves. And you're basically admitting to the fact that you trespassed, even if all you did was the equivalent of walking through an unlocked door and verifying that you could look inside their refrigerator. The fact that it may play out in the court of public opinion that you were helping to expose the lies of a corporation doesn't change the fact than in the actual courts you are guilty of a crime.
- Buttons840 3y agoYeah, when it comes to cyber-security, we put our national security at risk so companies can avoid being embarrassed. (See my rant in another comment.)
- asynchronous 3y agoAs much as I hate using regulation as a hammer to fix things, if we did make software companies legally required to a level of security, then vulnerability testing like this could be prosecuted similar to SEC or OSHA violations and would work quite nicely
- Buttons840 3y agoProtecting white-hat hackers could be seen as a reduction in "regulation", since it permits the good guys to do good things. It allows people to do more, but some people will be not be legally shielded from embarrassment and accountability anymore. In the current status quo, everyone except the good guys gets free reign: companies can stop legal scrutiny of their security, black-hats run wild and answer to no one, and the white-hats wring their hands "please sir, may I check for myself that the services I depend on are secure?" to which the companies respond "ha ha, no, but trust us, it's secure."