R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Researcher claims police threats for reporting software holes

Reporting software holes is too risky, he says

PCW Staff, Personal Computer World 23 May 2006
ADVERTISEMENT

A researcher for the Center for Education and Research in Information and Assurance (CERIAS) at Purdue University claims it is too risky to warn software companies about holes in their products.

Pascal Meunier, the author of the Cassandra system, said the police deal with those reporting the holes as hackers.

He helped disclose a vulnerability found by a student to a production website using custom software, but ended up being quizzed by the police over how he discovered the weakness.

The police, Meunier said, suspected that as he'd found one Achilles' Heel, he may have found more but not reported them.

Writing on his blog, he said that as a 'stubborn idealist' he clashed with a detective by refusing to identify the student who had originally found the problem.

He claims the police then threatened him with court orders and charging him with felony counts, and that his university stood by and offered no support. Meunier said his job was only saved by the student coming forward and talking to the police.

Now he tells his students not to report any vulnerabilities on websites as it is not worth the risk.

This article first appeared on sister site the Inquirer.


All Bugs, Patches & Fixes
Tags: Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
United Kingdom | Douglas Borough Council
 Chief Executive's Department ICT Manager Douglas Borough Council are looking for a motivated and accomplished person to provide primary ICT support for Douglas Corporation, user administration, and the development of our ICT infrastructure, systems and ... more >
Hertfordshire, United Kingdom | SMART
 Business Development Executive, Hertfordshire, £20,000-£22,000 per annum OTE £34 -36k The role: An exciting opportunity has become available within a prestigious organisation with aggressive growth plans. We are looking to recruit an office based Business ... more >
United Kingdom | Data Transparency
.NET Software Developer,  £20,000 - £35,000 depending on experience About us Data Transparency is a small, rapidly growing company established in 2006 by an Oxford graduate. We create bespoke web-based data systems that are used in ... more >
New Cross, London, United Kingdom | Goldsmiths College
Systems and Development Support Officer, Up to £36,277 pa incl, New Cross, London Working within the Department of IT Services, you will be assisting in the management and development of our central server resources. This ... more >
More job opportunities