Jump to content

Recommended Posts

Posted
The text of the amendment is

 

Nope, it's in PJ 2006. Look here:

 

http://www.publications.parliament.uk/pa/cm200506/cmbills/119/06119.27-33.html#j381

 

there is fine line when it comes to useage of tools...

 

They're not commercial and I don't publish them, but NT security is one of my things and in the last decade I have "made" lots of tools. Some of these were pure research, proof-of-concept stuff with no other obvious use besides breaking security and stealing things.. oh and having informed arguments with the MS security folk about what needs fixing.

 

Anyway, I'm currently not employed as a security professional (e.g. pen-tester) and I would really, really, really resent it if it essentially becomes illegal to do what I've done unless you are employed by Qinetiq or whoever.

Posted

Full disclosure is also a founding principle of computer security (at least in opensource/internet circles). There's lots of good reading about it in the wikipedia article.

 

http://en.wikipedia.org/wiki/Full_disclosure

 

These changes in the law mean that companies can bully security experts who've found problems rather than fixing the software.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...