Thursday, August 14, 2008

Shooting The Messenger

I've been keeping quiet about this for a while, but now I feel I should mention it.

Judge orders halt to Defcon speech on subway card hacking
Vulnerability Assessment Report

This whole business of corporations suing people who discover their security problems is retarded. That's right, I used the 'r' word. People who discover security problems and share it with "the good guys" should be rewarded for their ingenuity and hard work. Because if they've discovered security vulnerabilities, you can bet "the bad guys" have too.

The bad guys aren't going to be nice and let the good guys in on their secrets.

Edited to add:
Even more important than a way to ride the metro for free, here is the case of shooting the messenger involving the DNS vulnerability. And this guy even tried to do the right thing about it.

No comments: