@MagicDude4Eva: If you had to do it over, would you still report the flaw, report it anonymously, or just keep it to yourself?
In other words, what's your advice to someone who finds a security flaw in a public system, and doesn't have the lawyers/time/money to get tangled up in the "hacking conspiracy"?
Especially having it discussed with my legal team and looking at the chain of events, I would not do anything different. Although a potential court-case will be the result of it, I do think that in the end it has achieved what I had intended - i.e. stop the leak of rate-payer information. The CoJ was already alerted to this issue on the 13th August and then again by myself on the 20th August. If you look at all the events you will notice that CoJ demonstrated sheer arrogance and ignorance and refused to even listen to the issue. The user reporting it on 13th of August never received a response, I received an email response from the CoJ 6 days (!) after my report which read: "Good day value customer, we are aware of that and IT is working on that".
The information exposed was in the public domain since 2012 (for more than 12 months) prior to my discovery (as well as the discovery of another MyBB user before me). I tend to believe that other people might have alerted the CoJ prior to this, but remained quiet due to the fear of facing prosecution.
My legal team and I are of the firm belief that nothing criminal has been done and as such will defend the accusations of the CoJ in a criminal and/or civil matter to ensure that those allegations are cleared up for good. As a municipality, the CoJ has the obligation to provide us rate-payers with the appropriate service (refuse, electricity, water, billing, road infrastructure etc) and the "big shots" in the CoJ tend to forget that they are actually servants of us and only have a job because we pay rates and taxes. As such it is a reasonable expectation from all of us to provide a service with honesty and integrity, which the city officials and their IT service providers have not done to date.
It comes as no surprise that the city is facing it's 4th (!!!!) qualified audit - this means the city has not been able to properly balance it's books and account for money received by rate payers. If you are incapable of managing your finances how do you think anything else will be managed?
So in short, I would not do anything different, as I had exhausted all avenues prior to releasing the information. Unlike CoJ maintained, there was no malicious intent and the information was accessible for years and you can be certain that this information has been sold on for a long time. I also believe that should the CoJ see a court date, that it will not just remain in the magistrate's court, but will result in the ECT being challenged.
Unlike some "law experts" on this forum, we have a fairly good understanding of the ECT act and to date no person was ever convicted based on ECT 86.1 (un-authorised access). House tends to refer to the only ECT case (Douvenga where the accused stole customer data and sold it to the competition) in SA as a precedent, which it is not. The most recent reference is to the Weev case (search for AT&T hacking) who, when properly researched was convicted based on a number of technicalities as part of the CFAA (similar to Aaron Schwarz who eventually committed suicide).
Also, important to note is that FUD is spread about going to prison for ECT 86.1 and to be honest, the maximum charge is no worse than being convicted for drunk driving - so as bleak as some make it out to be, even if the legal system fails you completely and you get convicted across all courts and appeals fail you will in the best case get away with a suspended sentence/fine and in the worst case sit in prison for 3 months.
While my legal defense will eat a deep hole into my savings, I do believe it was the right thing to do. My advice to anyone else: I would continue making it public. Doing it anonymous will not keep you safe from possible malicious/vindictive prosecution - you will see this with Sanral - they will probably issue subpoenas against MyBB, Google (for Youtube and G+) to establish who Moe1 is and perhaps he was good as hiding his true identity, but to be honest as a citizen trying to improve our public service or corporate governance, we should not have to hide out of fear for being prosecuted for trying to highlight and fix an issue.
I am not sure if Moe1 tried to alert Sanral, but from my insights the flaw was already tested beginning of December and it is very possible that Sanral was alerted and aware of it, but similar to CoJ chose to ignore it.
I do think that this country needs a governance body which allows citizens to report issues which are then promptly addressed. We have public protector, CPA and a number of other bodies pretending to be that, but they are incapable to do this - so as a last resort sometimes drastic measures such as going public is necessary.
BTW: It is really unfortunate how amateurish the media reports on incidents like that. Issues like CoJ or Sanral are not of highly complicated technical nature and impossible to explain, but yet, the news media is unable to report in a balanced manner.