disclose / research-threats

Collection of legal threats against good faith Security Researchers; vulnerability disclosure gone wrong. A continuation of work started by @attritionorg
https://threats.disclose.io/
Creative Commons Zero v1.0 Universal
280 stars 19 forks source link

Researcher "AmmonRa" discloses unresolved bus fare card vulnerability, police informed #15

Closed TCFox closed 2 years ago

TCFox commented 3 years ago

At Kiwicon 7 (2013-11-09), researcher "AmmonRa" disclosed a series of vulnerabilities regarding Christchurch's "Metro Card" bus fare system. He previously reported the security flaw to Environment Canterbury, the group that oversees the bus network, three months prior, but nothing had been done.

After disclosing the vulnerability publicly, Environment Canterbury director operations Wayne Holton-Jeffreys had called the police (but was unsure if any charges would be laid).

sickcodes commented 3 years ago

Thanks for that! Did you want to submit as a PR :)?

sickcodes commented 2 years ago
2013-11-10 Christchurch Public Transport Card (ECan) William "AmmonRa" Turner Insecure Public Transport Card System At Kiwicon 7 (2013-11-09), researcher "AmmonRa" disclosed a series of vulnerabilities regarding Christchurch's "Metro Card" bus fare system. He previously reported the security flaw to Environment Canterbury, the group that oversees the bus network, three months prior, but nothing had been done. Without merit, after disclosing the vulnerability publicly, Environment Canterbury director operations Wayne Holton-Jeffreys had called the police (but was unsure if any charges would be laid). In essense, the Director of operations, Wayne Holton-Jeffreys, failed to protect their own systems and passed the buck to a hacker for exposing a loophole where 70,000 free rides were allegedly ridden following the talk at Kiwicon. ECan "called the police" over the flaws that they themselves created, and ignored.