« The real Security 2.0 | Main | Achieving a security culture change »

Irresponsible disclosure

The arguments continue about the recent court order by the Massachusetts Bay Transportation Authority to prevent MIT researchers from revealing flaws in the security of its e-ticketing system. It makes me wonder about the motivations behind contemporary research.

The real debate should not be about freedom of speech. It should be about why university research is wasted on attempts to find flaws in other people's operational systems, rather than developing useful security solutions. We all know that no system is foolproof. They all rely to some extent on security by obscurity. And you can't fix deep-seated flaws overnight. It's bad enough having a community of criminals looking to exploit ways to circumvent them. We could do without universities helping them.

TrackBack

TrackBack URL for this entry:
http://www.computerweekly.com/cgi-bin/mt/mt-tb.cgi/33412

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About

This page contains a single entry from the blog posted on August 18, 2008 9:39 AM.

The previous post in this blog was The real Security 2.0.

The next post in this blog is Achieving a security culture change .

Many more can be found on the main index page or by looking through the archives.

Powered by
Movable Type