Website security flaws in SA: why shoot the messenger?

In all fairness towards the companies involved, the article needed to emphasize the manner in which the incidents were reported:

CellC and Vodacom (No criminal charges)

- Reported to the companies - hacks not made public for others to follow

Sanral and COJ (Criminal Charge & Threat of Criminal Charge)

- Reported to companies and hacks published in public forums

I agree, COJ did not respond, their system was flawed, but the manner in which it was made public was the differentiating factor. Had CellC and Vodacoms' hacks been published on this forum, criminal charges would also have been laid.

Had CellC and Vodacom not responded timeously I'm sure their vulnerabilities would have become public too. Therein lies the key difference. The CoJ incompetence was exposed as a last resort, after fruitless attempts to get them to actually do something about it.
 
That is very much your opinion and not something based on the evidence at hand. I dont think they would have laid criminal charges.

It is indeed my opinion and I am 100% sure that if a public forum post appeared anywhere on how the public can access their system and view other people's data they would indeed have pressed charges.
 
That is very much your opinion and not something based on the evidence at hand. I dont think they would have laid criminal charges.

Vodacom would not have laid criminal charges. It'll be like kicking a landmine to get rid of it....
 
In all fairness towards the companies involved, the article needed to emphasize the manner in which the incidents were reported:

CellC and Vodacom (No criminal charges)

- Reported to the companies - hacks not made public for others to follow

Sanral and COJ (Criminal Charge & Threat of Criminal Charge)

- Reported to companies and hacks published in public forums

I agree, COJ did not respond, their system was flawed, but the manner in which it was made public was the differentiating factor. Had CellC and Vodacoms' hacks been published on this forum, criminal charges would also have been laid.
thats like saying all Zuma's are corrupt.. you do not know for certain what would happen because it didnt happen, so why assume? you only making an ass out of yourself!
 
Had CellC and Vodacoms' hacks been published on this forum, criminal charges would also have been laid.

Absolute BS. Cell C and Vodacom just acknowledge that they made the mistake and corrected them. Both SANRAL and CoJ have never accepted responsibility for their errors in security and are looking for someone else to blame. They are acting like Gods and cannot believe they ever made a mistake. After the CoJ disaster, I can understand that no one would ever want to inform a government organistation on a security breach. There is no other option than that people have to publish it publicly.
 
It is indeed my opinion and I am 100% sure that if a public forum post appeared anywhere on how the public can access their system and view other people's data they would indeed have pressed charges.

Since I seldom deal in certainties, Im 95% sure they wouldnt. And Im more confident in my 95% than I am in your 100%. If someone goes and posts a google exploit on a forum does google try sue them? Same with Microsoft, same with other people. If someone hacked my web business (and I have one with thousands of clients) and website and showed a proof of concept on this forum I would not sue them. That would be a little ridiculous.

I already would have egg on my face for having a breachable system. I certainly am not going to make it worse by going after the whistle blower who exposed the problems with my system. Especially if there is no ill intent (like a database dumb). That would make my company look worse. Like I am trying to hide my **** ups and cover them up with legal actions.
 
In all fairness towards the companies involved, the article needed to emphasize the manner in which the incidents were reported:

CellC and Vodacom (No criminal charges)

- Reported to the companies - hacks not made public for others to follow

Sanral and COJ (Criminal Charge & Threat of Criminal Charge)

- Reported to companies and hacks published in public forums

I agree, COJ did not respond, their system was flawed, but the manner in which it was made public was the differentiating factor. Had CellC and Vodacoms' hacks been published on this forum, criminal charges would also have been laid.

Is there evidence that the people who posted did not first alert CoJ and SANRAL?

And how in the seven hells is a security flaw a "cyber attack"?

No sirrah - these agencies are trying to rule by fear! A pox on them!
 
Government continues to demonstrate that they're ignorant. These "cyber attacks" could have been kept quiet and criminals could have taken advantage with serious consequences. The "hackers" have done nothing but help the incompetent developers building these systems.
 
Vodacom would not have laid criminal charges. It'll be like kicking a landmine to get rid of it....

Are you sure?

Someone finds a flaw, publish it on a forum, other users follow the method and some make use of scripts to harvest client data....
(I am not talking about a media publication calling the company and informing them)

Vodacom will not take any actions? They will just say fine, people's data was lost and now in public domain but we are not interested in the event other than fixing it?

Not sure the CEO will feel exactly the same...

If I was a vodacom client I would now be very, very concerned in any event since VC will not take actions if a hack was found and my data stolen.....
 
Last edited:
It is indeed my opinion and I am 100% sure that if a public forum post appeared anywhere on how the public can access their system and view other people's data they would indeed have pressed charges.

Vodacom would not have laid criminal charges. It'll be like kicking a landmine to get rid of it....

Oh dear!

/landmine explodes in House's hand - now what?/
 
house has the same mentality of sanral and CoJ, which makes it pointless arguing with him, because he will always think that he is right, no matter if he is wrong or not...
 
I don't think it's "goverment vs private business" inasmuch as it has to to with how technically savvy the organisation is. In the case of Vodacom/CellC I suspect they both understand the technicalities, ease and value of the issues that were identified. In the case of most government organisations, they do not understand these things whatsoever, they look at anything that seems out of the ordinary as a possible hack.

It's the same mentality that one gets when my mother gets a message on a website that says something unexpected, she proceeds to ask me if people are hacking into her computer. The issues are not understood, so the response and assumptions made are extraordinarily extreme as a result.

These issues should only be ever dealt with by people or a group within an organisation who understand what's going on. That means end to end, from fault identification, to resolution, to response. And please for the love of god, let those people actually be experienced and not just some technical/IT guys you found off the street.
Not applicable. These organisations have their own IT departments employing people who are expected to understand the issue raised.

They even suck at damage control, because acknowledging errors often earns you more credibility than threatening legal action.
 
Sanral and COJ (Criminal Charge & Threat of Criminal Charge)

- Reported to companies and hacks published in public forums

I agree, COJ did not respond, their system was flawed, but the manner in which it was made public was the differentiating factor. Had CellC and Vodacoms' hacks been published on this forum, criminal charges would also have been laid.

You and the CoJ conveniently "forget" that the very same CoJ issue was already reported on the 13th August @ 8:50am (10 days before it was reported a 2nd time) - so going to a forum and MyBB seems to be the logical next step since no CoJ representative wanted to listen. And TBH if it was necessary to go public to have CoJ shut down their security flawed system in order to protect customer data, then it was worthwhile doing.
 
You and the CoJ conveniently "forget" that the very same CoJ issue was already reported on the 13th August @ 8:50am (10 days before it was reported a 2nd time) - so going to a forum and MyBB seems to be the logical next step since no CoJ representative wanted to listen. And TBH if it was necessary to go public to have CoJ shut down their security flawed system in order to protect customer data, then it was worthwhile doing.

And that was exactly what lead to criminal charges being laid and will count as aggravating circumstances if a trial should ever occur.

Take a look what happened with the AT&T hacker who also found a vulnerability and decided to go to the media - http://nakedsecurity.sophos.com/201...-troll-weev-appeals-41-month-prison-sentence/

There is a right way and a wrong way of doing things.
 
Last edited:
And that was exactly what lead to criminal charges being laid and will count as aggravating circumstances if a trial should ever occur.

No criminal charges have been laid. A complaint was opened with Saps and is investigated. The complaint named me as the sole "hacker". A warning statement was issued by me almost 4 months ago and we are now all waiting :whistle:
 
Are you sure?

Someone finds a flaw, publish it on a forum, other users follow the method and some make use of scripts to harvest client data....
(I am not talking about a media publication calling the company and informing them)

Vodacom will not take any actions? They will just say fine, people's data was lost and now in public domain but we are not interested in the event other than fixing it?

Not sure the CEO will feel exactly the same...

If I was a vodacom client I would now be very, very concerned in any event since VC will not take actions if a hack was found and my data stolen.....


IIRC - sigh the guy that found the flaw in COJ system did try to advise them but got no response, hence he made it public so they could hear the shouting as it were and fix the problem.

Imagine i walk past your house, and find your front door unlocked allowing access to your home. I ring the door bell and no answer , so i go to your neighbour and tell him the idiot next doors, door is open. he contacts you and what do you do report me to the cops for breaking and entering - COJ / SCamral logic!
 
And that was exactly what lead to criminal charges being laid and will count as aggravating circumstances if a trial should ever occur.

You really don't understand that the internet is a community do you? That people on the internet try to help each other (for no personal gain whatsoever) and that this occurs in spite of governments and big business attempting to stop it from happening.

The internet is an amazing expression of human beings wanting to help each other without necessarily having a profit or power motive - big business find this hard to understand, governments refuse to accept it, because (for governments) somewhere in between being elected to serve the people and exercising that mandate, they discover the power and financial rewards with being in public office.
 
No criminal charges have been laid. A complaint was opened with Saps and is investigated. The complaint named me as the sole "hacker". A warning statement was issued by me almost 4 months ago and we are now all waiting :whistle:

Semantics.

Criminal charges have been laid and is under investigation. Once the investigation is completed the prosecutor will decide upon prosecution.
 
Top
Sign up to the MyBroadband newsletter
X