On 2008-07-19, Lawrence D'Oliveiro <_zealand> wrote:
> Looks like those Dutch researchers who found a weakness in London
> Transport's Oyster Card system will be free to publish the details
><http://arstechnica.com/news.ars/post/20080718-court-rules-smartcard-hackers-can-publish-exploit-data.html>.
> They've followed all the right procedures for responsible disclosure, given
> sufficient time (seven months) for the vendor, NXP, to take remedial action
> etc.
>
> Of course, NXP doesn't agree.
Oh goodie, it can be done. It has been done. Lets see if we can beat the
October dealine. Will someone do it, and will they tell you just be in free?
A really good security system shows everyone how it works and still keeps
certain people out. This is another head in the sand approach that MS, has
had for some years now while exploits in its software have been found and
used for vandalism.
|