Full Disclosure mailing list archives

Re: Student expelled from Montreal college after finding vulnerability that compromised security of 250, 000


From: Stefan Weimar <full-disclosure () tanis toppoint de>
Date: Thu, 24 Jan 2013 19:59:53 +0100

Hello,

Am 24. Januar schrieb Valdis.Kletnieks () vt edu:

I've seen reference to a few more details on this - namely:

1) The kid, as part of his major, signed an ethics document.
2) He was either told or agreed to not run the scanner again.
3) He did so anyhow.

A better solution would have been to not do the steps 1 and 2 but make
an NDA ("Ok, we know and you know but that's enough by now.") instead.
I mean, some kind of responsible disclosure.

By proposing this "ethics document" it was the college being
unprofessional and not the kid.

Kind regards
Stefan
-- 
make -it ./work

GnuPG-Key: B96CF8D2 <sw () tanis toppoint de>
Fingerprint: D8AC D5E7 6865 19B1 385F  8850 2AB7 6A82 B96C F8D2

Attachment: signature.asc
Description: Digital signature

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: