Linked by Thom Holwerda on Tue 28th Jun 2011 22:16 UTC
Thread beginning with comment 478991
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.
"Yes? At least that's what I would do. If they won't fix a security concern, I will widely publicize it to force them to fix it.
And if they were burgled would you accept that you are an accessory to the crime? I'm no lawyer but I suspect that's the way it would be viewed... "
And if they were burgled, but the damage could've been greatly limited had you informed account holders?
RE[4]: Responsible?
by ourcomputerbloke on Wed 29th Jun 2011 00:03
in reply to "RE[3]: Responsible?"
And if they were burgled...
That is the point at which the responsible and ethical thing to do would be to come forward and say "We told them so!" Yes the crime has been committed, but you played no active part in it. Regardless of the motives I don't see anything ethical or responsible about actively facilitating a crime. You found the weakness, you reported it, you've actively tried to prevent the crime. Changing tack and becoming an active facilitator for the crime makes you no better than those who would commit the crime in the first place IMHO.
But anyway, that's the way I view it.
And if they were burgled would you accept that you are an accessory to the crime? I'm no lawyer but I suspect that's the way it would be viewed...
Standard "This is provided for informational purposes only. We assume no responsibility for how this information is used, etc." legal disclaimer applies. Not sure it would hold up. But then again, it's not like you are going to use your real name or make it easy for the feds to find you if you share information with a newspaper about how to rob a bank.
RE[3]: Responsible? - criminals already know
by jabbotts on Wed 29th Jun 2011 16:03
in reply to "RE[2]: Responsible?"
In these cases, the civilian public is the last to know. If Hackers (ethical) discoved the issue, you can be sure that Crackers (unethical) have also discovered it. They are not publicizing something that criminals do not already know about.
If I can see how one might break in through your back door, you can be sure that burgler's have also noticed this.





Member since:
2011-05-12
And if they were burgled would you accept that you are an accessory to the crime? I'm no lawyer but I suspect that's the way it would be viewed...
Edited 2011-06-28 23:39 UTC