Live data from Hacker News

Teen Reported to Police After Finding Security Hole in Website

wired.com

1–10 of 123 posts

Re: Teen Reported to Police After Finding Security Hole in Website

#3
It's definitely more harmful long term to arrest rather than reward. Arresting people for reporting security vulnerabilities only causes the people whom would do so reluctant or even afraid of the repercussions. Meanwhile those who exploit maliciously will continue to not report their findings. If I was to find a security vulnerability in a site I frequent, I'd most likely stay quiet about it out of fear of legal ramifications.

Re: Teen Reported to Police After Finding Security Hole in Website

#4

It's about time for legislation making it a crime to report whistleblowers to the police and a criminal offense to search or seize their equipment. Perhaps an independent review body could be set up to arbitrate these situations?

Would you cut off your own hand or leg? They definitely will not.

Re: Teen Reported to Police After Finding Security Hole in Website

#5
post #3

It's definitely more harmful long term to arrest rather than reward. Arresting people for reporting security vulnerabilities only causes the people whom would do so reluctant or even afraid of the repercussions. Meanwhile those who exploit maliciously will continue to not report their findings. If I was to find a security vulnerability in a site I frequent, I'd most likely stay quiet about it out of fear of legal ram…

After such a motivating action from the govt., they'll simply sell the vulnerabilities for some BTC to someone else.

Re: Teen Reported to Police After Finding Security Hole in Website

#6
Clearly, the government department is wholly responsible for putting up a rubbish website, but from another article on the story, "He first contacted PTV by email on Boxing Day..". I wonder if the "white-hat hacker" didn't time his notification quite intentionally knowing there was a much lower probability of action being taken promptly. If they'd just patched the security hole he wouldn't get any exposure. It makes me wonder if there's more to this story than we're hearing - that he actually found the security flaw much earlier and sat on it for a while for example. Or that he downloaded all the available information first.

As ever, a couple of short articles may not be giving us the big picture.

Re: Teen Reported to Police After Finding Security Hole in Website

#8
post #6

Clearly, the government department is wholly responsible for putting up a rubbish website, but from another article on the story, "He first contacted PTV by email on Boxing Day.." . I wonder if the "white-hat hacker" didn't time his notification quite intentionally knowing there was a much lower probability of action being taken promptly. If they'd just patched the security hole he wouldn't get any exposure. It makes…

By that logic why would he even bother reporting it and have security experts poking around the logs and potentially find traces of his download.

Personally i would have sold it to the highest bidder. Being "white hat" gets you in trouble more often than not.

Il stick to "gray hat" thank you very much. If i ever choose to disclose any vulnerability to the owners i will not reveal my identity and after arbitrary amount of time say... (1 month) if it's still present sell it to the highest bidder let them deal with the consequences.

You have to be strict when teaching people and this is no different. If you let them set the rules they could choose and unreasonable length of time like 1 year before they allow you to disclose anything.

You are the one in the position of power never let them take that away from you. By revealing you identity you give away all your power.

If you're not a threat people don't take you seriously.

Re: Teen Reported to Police After Finding Security Hole in Website

#9
post #8
post #6

Clearly, the government department is wholly responsible for putting up a rubbish website, but from another article on the story, "He first contacted PTV by email on Boxing Day.." . I wonder if the "white-hat hacker" didn't time his notification quite intentionally knowing there was a much lower probability of action being taken promptly. If they'd just patched the security hole he wouldn't get any exposure. It makes…

By that logic why would he even bother reporting it and have security experts poking around the logs and potentially find traces of his download. Personally i would have sold it to the highest bidder. Being "white hat" gets you in trouble more often than not. Il stick to "gray hat" thank you very much. If i ever choose to disclose any vulnerability to the owners i will not reveal my identity and after arbitrary amoun…

Your statement:

  Being "white hat" gets you in trouble more often than not.
Is beyond absurd.
Post reply on HN