<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Man Charged For Notifying USC of Vulnerability</title>
	<atom:link href="http://emergentchaos.com/archives/2006/04/man-charged-for-notifying-usc-of-vulnerability.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2006/04/man-charged-for-notifying-usc-of-vulnerability.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Mon, 15 Mar 2010 15:02:09 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Dominic White</title>
		<link>http://emergentchaos.com/archives/2006/04/man-charged-for-notifying-usc-of-vulnerability.html/comment-page-1#comment-2116</link>
		<dc:creator>Dominic White</dc:creator>
		<pubDate>Wed, 26 Apr 2006 01:17:27 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=1659#comment-2116</guid>
		<description>Agreed :)
</description>
		<content:encoded><![CDATA[<p>Agreed :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://emergentchaos.com/archives/2006/04/man-charged-for-notifying-usc-of-vulnerability.html/comment-page-1#comment-2115</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Tue, 25 Apr 2006 20:35:40 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=1659#comment-2115</guid>
		<description>I think this is a good case for prosecutorial discretion.  Where&#039;s the deep harm?  A trial will cost (I think) $100,000 for legal fees.  That&#039;s a deterent, in and of itself.
</description>
		<content:encoded><![CDATA[<p>I think this is a good case for prosecutorial discretion.  Where&#8217;s the deep harm?  A trial will cost (I think) $100,000 for legal fees.  That&#8217;s a deterent, in and of itself.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dominic White</title>
		<link>http://emergentchaos.com/archives/2006/04/man-charged-for-notifying-usc-of-vulnerability.html/comment-page-1#comment-2114</link>
		<dc:creator>Dominic White</dc:creator>
		<pubDate>Tue, 25 Apr 2006 16:00:26 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=1659#comment-2114</guid>
		<description>Whoops sorry about the double posting. Damn GPRS.
</description>
		<content:encoded><![CDATA[<p>Whoops sorry about the double posting. Damn GPRS.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Iang</title>
		<link>http://emergentchaos.com/archives/2006/04/man-charged-for-notifying-usc-of-vulnerability.html/comment-page-1#comment-2113</link>
		<dc:creator>Iang</dc:creator>
		<pubDate>Tue, 25 Apr 2006 15:59:06 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=1659#comment-2113</guid>
		<description>The prosecution and any popular press article will cover their butts by claiming that the &quot;researcher&quot; was really &quot;hacking&quot;.  If you believe the prosecutor, or SecurityFocus, I&#039;ve got a bridge to sell you.  If you want to wait for the facts, I&#039;ve two bridges to sell you!  This isn&#039;t to say that the guy *wasn&#039;t* hacking ... but ... as a security researcher or practitioner, if you go anywhere near a security site, you risk prosecution.  You risk setting off a chain of events that results in you having to defend your actions before the judge, and he isn&#039;t interested in your arcane opinions of security or any informal permissions.
The easily visible but predictably unforseen consequences are that a security researcher would be mad raving nuts loony to do any security research in any sense at all near a company unless  he was backed up by clear contracts, disclaimers, promises and was married to the boss&#039;s daughter.  And even then, he could get into trouble.  Check the prices on liability insurance for ethical hacking.  So costs for defence will rise because most programmers will wisely look the other way when they see a flaw.
Which inevitably means that net security as a whole will decrease.  Especially as none of this applies to the (real) attacker.
</description>
		<content:encoded><![CDATA[<p>The prosecution and any popular press article will cover their butts by claiming that the &#8220;researcher&#8221; was really &#8220;hacking&#8221;.  If you believe the prosecutor, or SecurityFocus, I&#8217;ve got a bridge to sell you.  If you want to wait for the facts, I&#8217;ve two bridges to sell you!  This isn&#8217;t to say that the guy *wasn&#8217;t* hacking &#8230; but &#8230; as a security researcher or practitioner, if you go anywhere near a security site, you risk prosecution.  You risk setting off a chain of events that results in you having to defend your actions before the judge, and he isn&#8217;t interested in your arcane opinions of security or any informal permissions.<br />
The easily visible but predictably unforseen consequences are that a security researcher would be mad raving nuts loony to do any security research in any sense at all near a company unless  he was backed up by clear contracts, disclaimers, promises and was married to the boss&#8217;s daughter.  And even then, he could get into trouble.  Check the prices on liability insurance for ethical hacking.  So costs for defence will rise because most programmers will wisely look the other way when they see a flaw.<br />
Which inevitably means that net security as a whole will decrease.  Especially as none of this applies to the (real) attacker.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dominic White</title>
		<link>http://emergentchaos.com/archives/2006/04/man-charged-for-notifying-usc-of-vulnerability.html/comment-page-1#comment-2112</link>
		<dc:creator>Dominic White</dc:creator>
		<pubDate>Tue, 25 Apr 2006 15:57:02 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=1659#comment-2112</guid>
		<description>I fully agree, but we[1] do prosecute some things which are a crime, and breaking into databases is one of them.
I think the incentive here is that he should be let off the hook for not intending to do harm, but rather good. This is the kind of analysis a trial is supposed to perform.
My real bone of contention is that you are making it sound like disclosing flaws will get you in jail. That is true in some cases and should be fought against. But in this instance it isn&#039;t the disclosure which got him into trouble, it was the breaking in to the database. Given that it is possible to seperate the two i.e. disclosure could have happened without him breaking the law, there is no point conflating them.
[1] By we, I mean Merkins, I am not a Merkin and may have missed some subtleties of Merkin law.
</description>
		<content:encoded><![CDATA[<p>I fully agree, but we[1] do prosecute some things which are a crime, and breaking into databases is one of them.<br />
I think the incentive here is that he should be let off the hook for not intending to do harm, but rather good. This is the kind of analysis a trial is supposed to perform.<br />
My real bone of contention is that you are making it sound like disclosing flaws will get you in jail. That is true in some cases and should be fought against. But in this instance it isn&#8217;t the disclosure which got him into trouble, it was the breaking in to the database. Given that it is possible to seperate the two i.e. disclosure could have happened without him breaking the law, there is no point conflating them.<br />
[1] By we, I mean Merkins, I am not a Merkin and may have missed some subtleties of Merkin law.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dominic White</title>
		<link>http://emergentchaos.com/archives/2006/04/man-charged-for-notifying-usc-of-vulnerability.html/comment-page-1#comment-2111</link>
		<dc:creator>Dominic White</dc:creator>
		<pubDate>Tue, 25 Apr 2006 15:55:57 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=1659#comment-2111</guid>
		<description>I fully agree, but we[1] do prosecute some things which are a crime, and breaking into databases is one of them.
I think the incentive here is that he should be let off the hook for not intending to do harm, but rather good. This is the kind of analysis a trial is supposed to perform.
My real bone of contention is that you are making it sound like disclosing flaws will get you in jail. That is true in some cases and should be fought against. But in this instance it isn&#039;t the disclosure which got him into trouble, it was the breaking in to the database. Given that it is possible to seperate the two i.e. disclosure could have happened without him breaking the law, there is no point conflating them.
[1] By we, I mean Merkins, I am not a Merkin and may have missed some subtleties of Merkin law.
</description>
		<content:encoded><![CDATA[<p>I fully agree, but we[1] do prosecute some things which are a crime, and breaking into databases is one of them.<br />
I think the incentive here is that he should be let off the hook for not intending to do harm, but rather good. This is the kind of analysis a trial is supposed to perform.<br />
My real bone of contention is that you are making it sound like disclosing flaws will get you in jail. That is true in some cases and should be fought against. But in this instance it isn&#8217;t the disclosure which got him into trouble, it was the breaking in to the database. Given that it is possible to seperate the two i.e. disclosure could have happened without him breaking the law, there is no point conflating them.<br />
[1] By we, I mean Merkins, I am not a Merkin and may have missed some subtleties of Merkin law.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://emergentchaos.com/archives/2006/04/man-charged-for-notifying-usc-of-vulnerability.html/comment-page-1#comment-2110</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Tue, 25 Apr 2006 11:28:17 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=1659#comment-2110</guid>
		<description>Dominic,
I don&#039;t think everything that&#039;s wrong is a crime that ought to be prosecuted.  I also don&#039;t think that we should structure incentives to discourage noticing problems.
</description>
		<content:encoded><![CDATA[<p>Dominic,<br />
I don&#8217;t think everything that&#8217;s wrong is a crime that ought to be prosecuted.  I also don&#8217;t think that we should structure incentives to discourage noticing problems.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dominic White</title>
		<link>http://emergentchaos.com/archives/2006/04/man-charged-for-notifying-usc-of-vulnerability.html/comment-page-1#comment-2109</link>
		<dc:creator>Dominic White</dc:creator>
		<pubDate>Tue, 25 Apr 2006 10:13:39 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=1659#comment-2109</guid>
		<description>That&#039;s silly.
If I break into a database with malicious intent and only view a handful of records, I have commited a crime. My sentencing will take into account that it was only a handful, but it isn&#039;t grounds to dismiss the case.
I could spend my life developing a nuclear weapon to destroy the world, my not doing that does not count in my favour. I&#039;m not going to slap my work mates on the back and thank them for not going on a murderous romp throught the office (well, there is this one guy...).
Many of us have been there, sitting with the live system, sure that your exploit will give you the access you want and dying to take it further. The reality is, you aren&#039;t allowed to. Rather chat to the admins and get their permission to test the exploit.
</description>
		<content:encoded><![CDATA[<p>That&#8217;s silly.<br />
If I break into a database with malicious intent and only view a handful of records, I have commited a crime. My sentencing will take into account that it was only a handful, but it isn&#8217;t grounds to dismiss the case.<br />
I could spend my life developing a nuclear weapon to destroy the world, my not doing that does not count in my favour. I&#8217;m not going to slap my work mates on the back and thank them for not going on a murderous romp throught the office (well, there is this one guy&#8230;).<br />
Many of us have been there, sitting with the live system, sure that your exploit will give you the access you want and dying to take it further. The reality is, you aren&#8217;t allowed to. Rather chat to the admins and get their permission to test the exploit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Walsh</title>
		<link>http://emergentchaos.com/archives/2006/04/man-charged-for-notifying-usc-of-vulnerability.html/comment-page-1#comment-2108</link>
		<dc:creator>Chris Walsh</dc:creator>
		<pubDate>Mon, 24 Apr 2006 11:07:25 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=1659#comment-2108</guid>
		<description>@Scott:
Security focus link: &lt;a href=&quot;http://www.securityfocus.com/brief/191&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/brief/191&lt;/a&gt;
&quot;The flaw could have allowed an attacker to send commands to the database that powered the site by using the user name and password text boxes. USC&#039;s Information Services Division confirmed the problem and shuttered the site, which contained data on nearly 280,000 applicants, on June 20 as a precaution. The university believes, and the prosecutors allege, that only a handful of records were actually accessed.&quot;
As I read this, they KNOW he looked at a handful, but he COULD have looked at 280K (or done a &#039;DROP database&#039; for all we know.  Whether looking at a handful of records (which could easily have come from a single select statement) is worthy of prosecution is a judgment call. I&#039;m with Adam on this.
</description>
		<content:encoded><![CDATA[<p>@Scott:<br />
Security focus link: <a href="http://www.securityfocus.com/brief/191" rel="nofollow">http://www.securityfocus.com/brief/191</a><br />
&#8220;The flaw could have allowed an attacker to send commands to the database that powered the site by using the user name and password text boxes. USC&#8217;s Information Services Division confirmed the problem and shuttered the site, which contained data on nearly 280,000 applicants, on June 20 as a precaution. The university believes, and the prosecutors allege, that only a handful of records were actually accessed.&#8221;<br />
As I read this, they KNOW he looked at a handful, but he COULD have looked at 280K (or done a &#8216;DROP database&#8217; for all we know.  Whether looking at a handful of records (which could easily have come from a single select statement) is worthy of prosecution is a judgment call. I&#8217;m with Adam on this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott</title>
		<link>http://emergentchaos.com/archives/2006/04/man-charged-for-notifying-usc-of-vulnerability.html/comment-page-1#comment-2107</link>
		<dc:creator>Scott</dc:creator>
		<pubDate>Mon, 24 Apr 2006 09:56:21 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=1659#comment-2107</guid>
		<description>A wee spot of jumping to conclusions, don&#039;t you think?  Clearly, if the prosecution is about the demonstration of the flaw it is overzealous for our tastes.  Equally clearly, if the guy took a tour through the database because he could before reporting the flaw, he should be prosecuted.  The SecurityFocus article (link?) hints that his viewing wasn&#039;t gratuitous, but the full facts are not presented.
The clear message: have the facts before drawing a conclusion.
</description>
		<content:encoded><![CDATA[<p>A wee spot of jumping to conclusions, don&#8217;t you think?  Clearly, if the prosecution is about the demonstration of the flaw it is overzealous for our tastes.  Equally clearly, if the guy took a tour through the database because he could before reporting the flaw, he should be prosecuted.  The SecurityFocus article (link?) hints that his viewing wasn&#8217;t gratuitous, but the full facts are not presented.<br />
The clear message: have the facts before drawing a conclusion.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
