Saturday, 15 October 2011

Vulnerability testing, bugs, responsible disclosure and liability...

There is an interesting story from Australia, showing one of the many pitfalls facing those who spot (or, perhaps, set out to find) security problems in third party properties, even where their only action after determining the problem is notifying the affected institution.

Based on what was posted in the article, I'm struggling to determine why the bank thought that it might be in its interests to contact the police (otherwise than a required NRA notification, if indeed required under Australian law), let alone suggest it might be entitled to recoup the costs caused by its own security problem. Not great from a PR point of view, really!


A security consultant who quietly tipped off First State Superannuation about a web vulnerability that potentially put millions of customers at risk has been slapped with a legal threat demanding he allow the company access to his computer, and warned he may be forced to pay the cost of fixing the flaw.


More details here.

No comments:

Post a Comment