Simple clear advice in plain English

Researcher claims police threats for reporting software holes

Reporting software holes is too risky, he says

A researcher for the Center for Education and Research in Information and Assurance (CERIAS) at Purdue University claims it is too risky to warn software companies about holes in their products.

Pascal Meunier, the author of the Cassandra system, said the police deal with those reporting the holes as hackers.

He helped disclose a vulnerability found by a student to a production website using custom software, but ended up being quizzed by the police over how he discovered the weakness.

The police, Meunier said, suspected that as he'd found one Achilles' Heel, he may have found more but not reported them.

Writing on his blog, he said that as a 'stubborn idealist' he clashed with a detective by refusing to identify the student who had originally found the problem.

He claims the police then threatened him with court orders and charging him with felony counts, and that his university stood by and offered no support. Meunier said his job was only saved by the student coming forward and talking to the police.

Now he tells his students not to report any vulnerabilities on websites as it is not worth the risk.

This article first appeared on sister site the Inquirer.

Article tags

Reader Comments

   

Add your comment

All fields must be completed. Your email address will not be displayed or used to send marketing messages.

All messages will be checked by moderators before appearing on the site.

See our Privacy Policy for more information.

Related articles

Ombudsman services

Dealing with complaints about your broadband provider

Unhappy with your broadband service? No luck with the helpline? We explain how to solve problems and get answers from your broadband provider

340-f3-lp

Take control of your Facebook account privacy settings

Using Facebook can reveal your personal data to everyone on the social networking site – we explain how to keep it hidden

Internet Explorer

Internet Explorer 9 set for UK launch on 15 March

The latest version of Microsoft's web browser will be released at 4am on Tuesday

Question & Answer

Q.How do I store musician and other information about...

> Read the answer

Q.Why can't my browser find the website address I typed...

> Read the answer

Q.All updates have been downloaded, so why won't Windows...

> Read the answer

Best deals on the web

img

THREE E585 Mi-Fi Take it Away Mobile Broadband - 5GB allowance

£44.97- Buy it now

img

T-MOBILE 3G Pay As You Go iPad Micro SIM

£0.10- Buy it now

img

THREE Huawei E353u Take It Away Mobile Broadband - One Month Rolling Contract

£4.99- Buy it now

Great benefits for subscribers!

Poll

Which is your preferred web browser

Jargon Buster

Computing terms explained in plain English

CAD

Computer Aided Design. Software used to create 3D models.

Great shopping deals from Computeractive