Website security flaws in SA: why shoot the messenger?

You really don't understand that the internet is a community do you? That people on the internet try to help each other (for no personal gain whatsoever) and that this occurs in spite of governments and big business attempting to stop it from happening.

The internet is an amazing expression of human beings wanting to help each other without necessarily having a profit or power motive - big business find this hard to understand, governments refuse to accept it, because (for governments) somewhere in between being elected to serve the people and exercising that mandate, they discover the power and financial rewards with being in public office.

.... and this is exactly the reason why these articles are still being published.... and why criminal charges have been instituted. A lack of legal knowledge tend to end you up on the wrong side of the law.

I think, the bigger questions one need to ask is:

1. Will Magicdude ever post full details of a flaw (for any website) in a public forum again?
2. Why did the VC and CellC reporters not publish their findings in a public forum.

The answers are clear, no, Magic will not do it again. The other two learnt from Magic's incident or they knew the law.
 
Last edited:
Are you sure?
Pretty sure.

If it was a malicious attack, for example where the data was mined and sold, it would be a very different case.

A few years ago we had a similar situation but it was published on MyBB before we knew about it. We did exactly the same; fixed it and thanked the chap. Though we clearly prefer the process Chris followed.
 
house has the same mentality of sanral and CoJ, which makes it pointless arguing with him, because he will always think that he is right, no matter if he is wrong or not...

Keep to the topic. This is not about House, this is about views around exploit whistle blowers. Whether or not House or anyone else thinks he is always right neither adds or takes away from the debate in the slightest. Keep on the ball.
 
I am totally in agreement that it is pathetic of the COJ not to act when reports started coming in. As for Sanral, I don't know if it has been reported to them of just plainly published in public.

However, the differences in the manner in which the COJ matter was dealt with vs the way the CellC and VC incidents were dealt with are clear.

Unfortunately, COJ were well within their rights to open criminal charges.
 
Semantics.

Criminal charges have been laid and is under investigation. Once the investigation is completed the prosecutor will decide upon prosecution.

Semantics are important when it comes to law. And trying to compare the Weev case to CoJ or Sanral is just laughable - does anyone ever read all the facts behind everything? Irrespective that Weev is a complete nutjob if you trust Wikipedia (http://en.wikipedia.org/wiki/Weev), he was convicted under the CFAA (the same laws, which resulted in the suicide of Aaron Swartz) and which are being challenged. The US is not necessarily a good example for cyberlaws - considering that the country of the free has developed into a police state. I think the US CFAA (especially now with the NSA issues) will be challenged during 2014.
 
Unfortunately, COJ were well within their rights to open criminal charges.

They can, waste of money, time and resources for 1 person. More will come as the hatred grows for SANRAL and government, seeing it takes months for a single person/case justice will prevail.

I want the major violent riots to start now
 
I refuse to believe this in these cases - it's a thought out PR/Damage Control strategy - when caught, shout loudly that someone else has wronged you - it's a time-tested propaganda tactic.

I am with you on this one. 1st world countries, individuals resign when caught out. For us in (South) Africa it is always the blame game, from the guy sitting next to the road to the president sitting up top. Always blaming, even if it is the innocent voter being blamed, but never ever taking responsibility (only money). The last time I recall somebody taking responsibility was when Nelson Mandela acknowledged and thanked the judiciary for stopping a new law that was unconstitutional. If only we had people like him to set a better example for people like Vusi Mona :(
 
Semantics are important when it comes to law. And trying to compare the Weev case to CoJ or Sanral is just laughable - does anyone ever read all the facts behind everything? Irrespective that Weev is a complete nutjob if you trust Wikipedia (http://en.wikipedia.org/wiki/Weev), he was convicted under the CFAA (the same laws, which resulted in the suicide of Aaron Swartz) and which are being challenged. The US is not necessarily a good example for cyberlaws - considering that the country of the free has developed into a police state. I think the US CFAA (especially now with the NSA issues) will be challenged during 2014.

Many of our cyberlaws have their origin from US laws. And, yes, you can indeed compare the two incidents, it is just the two different sets of laws here and there. However, looking at the COJ incident and that of Weev, it is clear why people need to be policed, and freedom may not always be the best option.
 
In your world of lies, deceit and FUD. Sure Vusi.

Glad I'm not living in your world.

What would become of the Internet when you allow a group of people to target websites freely looking for flaws and then publishing those flaws on open public platforms.

I just see practices like these becoming a haven for criminals to prey on in getting information from a number of sources all the time.

Where you get a society believing it is their right of speech to do just this, I believe, like in the US, this is where laws and government should jump in and restrict that rights.

Again, there is a right way and a wrong way in doing this.
 
What would become of the Internet when you allow a group of people to target websites freely looking for flaws and then publishing those flaws on open public platforms.

I just see practices like these becoming a haven for criminals to prey on in getting information from a number of sources all the time.

Where you get a society believing it is their right of speech to do just this, I believe, like in the US, this is where laws and government should jump in and restrict that rights.

Again, there is a right way and a wrong way in doing this.

In all of these relevant (SA) cases - were the whistleblowers targeting those websites for security flaws?
How do you know that this was malicious?

What is malicious - is the way in which CoJ and SANRAL are going about trying to cover up their incompetence.
And I for one am fairly certain that it won't just be egg on their faces when this is done.

As for your second line in your response: It's already a way of life for criminals since the first byte was transmitted.
Don't be silly. There are no criminals at work in these current cases.
 
Last edited:
What would become of the Internet when you allow a group of people to target websites freely looking for flaws and then publishing those flaws on open public platforms.

I just see practices like these becoming a haven for criminals to prey on in getting information from a number of sources all the time.

Where you get a society believing it is their right of speech to do just this, I believe, like in the US, this is where laws and government should jump in and restrict that rights.

Again, there is a right way and a wrong way in doing this.

It's time you reveal your identity and who you represent.

It is clear you are here with an agenda.

In fact you should register as a rep on this forum.
 
What would become of the Internet when you allow a group of people to target websites freely looking for flaws and then publishing those flaws on open public platforms.

I just see practices like these becoming a haven for criminals to prey on in getting information from a number of sources all the time.

Where you get a society believing it is their right of speech to do just this, I believe, like in the US, this is where laws and government should jump in and restrict that rights.

Again, there is a right way and a wrong way in doing this.

There is a reason for the US having a whistleblower protection act. In the mind of a government agency having a massive security flaw or a faulty multi-billion-Rand billing system it is obvious that anyone highlighting issues will be "on the wrong side of the law" and will be branded as malicious, or hacker or anything else to distract from the actual problem.

Forbes themed 2014 as the year of the whistleblower and recent incidents such as NSA are just the beginning where the internet community will take companies and governments to task. Just because a government believes something is right, does not mean it has to stay this way - otherwise we would still be stuck with apartheid in South Africa and nazi's roaming Europe. I think your view is very narrow-minded and wrong at best most of the times.

It is also very naive to think that just because no-one raises an issue, no problem exists. I can guarantee you that right at this moment thousands of hackers are targeting websites all over the globe - you are just not aware of it, as no-one informs the public about it. Any MyBB member working for an ISP or within networking at corporates will know about the number of DDoS attacks, phishing attempts and brute-force attacks targeting their companies having occurred at their premises within the last few weeks.

Good citizenship demands to inform the public and the government of issues and try to assist in resolving the problems at hand - unfortunately sheer arrogance does not allow for a proper conversation in this regard.
 
In all of these relevant (SA) cases - were the whistleblowers targeting those websites for security flaws?
How do you know that this was malicious?

What is malicious - is the way in which CoJ and SANRAL are going about trying to cover up their incompetence.
And I for one am fairly certain that it won't just be egg on their faces when this is done.

As for your second line in your response: It's already a way of life for criminals since the first byte was transmitted.
Don't be silly. There are no criminals at work in these current cases.

Look, don't get me wrong here. I have absolutely nothing against Magicdude. In fact, I do not know him at all.

However, two wrongs do not make a right.

Although in the COJ case Magic has not been malicious, but he did indeed offer criminals a window of opportunity in gathering personal identifiable information by posting - in detail - the method of accessing the information.

The same applies to the Sanral incident.

While these reporters may be of the opinion that they are doing the right thing, they may be causing more harm in the process, hence the laws and the charges.
 
Top
Sign up to the MyBroadband newsletter
X