3 ms·
And that's one of the reasons if you're not a security expert and stumble upon someone's security problems, you do nothing (at least in US).
by rational-future 12y ago
And that's one of the reasons if you're not a security expert and stumble upon someone's security problems, you do nothing (at least in US).
- jnbiche 12y agoNot sure why this is downvoted. Reporting a security problem, particularly a significant one, puts you at high risk for unjust prosecution and imprisonment. Unless lives are at stake due to the security lapse, it's pretty clear to me that the only reasonable response is to go "oh, that's interesting" and then close your browser window and never tell a soul.
- lotsofmangos 12y agoWhat part of "server containing medical data about thousands of patients." indicates to you that lives were not at stake? edit - the folk saying that this guy was stupid for doing anything are completely irresponsible.
- jnbiche 12y agoWhat part of archived medical data would put lives at risk? I mean, it sure as hell puts their privacy at risk, but can you describe what scenario you are imagining that puts lives at risk? Just because it has the word "medical" doesn't mean it's life or death (and this appears not to be).
- click170 12y agoFrom my point of view this is what anonymous full disclosure is for. Naming and shaming typically gets some kind of a response. Keeping quiet does not. I know not everyone agrees with full disclosure but I assert there is a time and a place, and after a demonstration like this one, IMO this university is one of those places. Edit: typo