Hey, I know that guy! (Probably)

"reece.arnott" <[email protected]>
Newsgroups gmane.org.user-groups.linux.dunedin.general
Message-ID <[email protected]>
http://www.stuff.co.nz/technology/digital-living/8773406/Justice-hacker-sparks-police-probe

Summary: Someone alerted Clare Curran (Labour, Dunedin North MP) to "a 
security weakness in the Justice Ministry's computer system" is now under 
investigation by the police, at the request of Justice Minister Judith 
Collins, it seems.

If we assume that the person involved contacted Clare Curran because she 
was their local MP then its a fair bet that this person is on one of the 
lists I'm sending this too. If this is you, HI! (and my condolences on your 
treatment. If I can help out in any way, just get in contact)

The bigger problem that this uncovers though is the 'shoot the messenger' 
reflex that this suggests is within various government departments when it 
comes to exposing security flaws.

How should we go about reporting flaws in our government's technological 
infrastructure - in a way that is safe and responsible but also actually 
gets the flaws fixed?
Is there any mechanism currently in place? Does anyone have any good ideas 
for how to create such a system if it is needed?

(This post was sparked off by a similar question posted on the PPNZ - 
Pirate Party of New Zealand - email list. I'll try and cross-post any 
interesting responses)

_______________________________________________
DunLUG mailing list
[email protected]
http://lists.ethernal.org/listinfo/dunlug
DunLUG Wiki - http://dunlug.kallisti.net.nz/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.