WebApp Sec mailing list archives

Re: Web security breach changes the lives of 119 people


From: ed.tracy () aspectsecurity com
Date: Mon, 21 Mar 2005 10:46:42 -0500 (EST)

El,

I really don't understand your position that this is Harvard's fault. You
claim the "issue" isn't applicants hacking but rather Harvard's failure to
prevent their hacking. Well sure Harvard could and should do better, but
that doesn't diminish the culpability of these applicants one bit! That's
like saying the bank robbers did nothing wrong cause it was the bank's
fault they left the vault open!

Frankly, I think our industry is riddled with this type of sentiment. And
that some of us have become so warped by our security expertise so as not
to use logic when assigning blame. For example, Harvard rejected these
applicants NOT as a fix to their problem," but rather because the
applicants showed a character flaw, hacking.

-ed


Current thread: