CIO Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
Daily Briefing for Technology's Top Decision-Makers
Tuesday, February 9th 
Home
Enterprise Software
Enterprise Hardware
Network Security
Compliance
CRM Systems
Data Storage
Chips & Processors
Operating Systems
Communications
World Wide Web
Wireless Tech
Small Business
CIO Issues
Business Briefing
After Hours
Press Releases
 

Advertisement
Tech Trends

Security Researcher Sued for Reporting Flaws

Security Researcher Sued for Reporting Flaws
January 12, 2005 11:47AM

Bookmark and Share
"If independent researchers cannot analyze security software and publish their discoveries, users will just have marketing press releases to assess the quality of software," says accused security researcher Guillaume Tena. Suing him is like Ford suing someone for finding a defect in a car's brake system, he says.


Security researcher Guillaume Tena is being threatened with jail time and fines in a Paris court as a result of publishing information about vulnerabilities in an antivirus application.

In 2001, Tena, who is also a researcher in molecular biology at Harvard University, found a number of flaws in the Viguard antivirus software published by French firm Tegam International.

He published his research online in March 2002, including a long analysis of how the program worked, tests with real-world viruses, and security flaws that went against the company's claims that Viguard stopped 100 percent of viruses.

The War Begins

Tegam responded by first calling Tena a "terrorist," according to a description of the case that Tena has posted to his Web site.

As a matter of fact, Tena actually used to be a virus writer and wrote the first e-mail virus ever, Happy99, according to Mikko Hypponen at F-Secure. "He appears to be a good citizen now," Hypponen told NewsFactor, "but there might be some animosity still felt against him at antivirus companies."

Tegam eventually filed a formal complaint against the French-born researcher in a Paris tribunal. Since Tena's Web site is hosted in France, authorities seized his computer and redirected site traffic.

Tena has said the case is like Ford suing someone for finding a defect in a car's brake system Relevant Products/Services. "If independent researchers cannot analyze security software and publish their discoveries, users will just have marketing press releases to assess the quality of software," he writes.

Tegam has defended its actions and is calling the validity of Tena's research into question. The trial began on January 4th, with a final ruling due on March 8th.

Potential Ramifications

Although the outcome of Tena's case likely will affect security research in France most directly, it could have ramifications for security reporting in other countries as well.

If the court rules that Tena violated copyright laws, companies in other countries might pursue similar litigation to keep their software flaws from being made public.

"As a matter of public policy, this kind of research ought to be protected," Ben Edelman, also a Harvard security researcher, told NewsFactor.

Truth or Consequences

The Tena vs. Tegam case highlights the ongoing tension between security researchers and hobbyists who disclose vulnerabilities and companies that publish software.

Microsoft Relevant Products/Services often is critical of individuals who publish exploits, claiming the company is not given sufficient opportunity to correct problems before they are made public.

Researchers, on the other hand, feel they are providing a valuable service Relevant Products/Services and making the Internet a safer place to work and play.

"Finding flaws in security software is absolutely essential, in order to help improve the security of the software we all rely on," Edelman said.

"Pointing out a company's false claims is important to help consumers distinguish high-quality software from software that's poorly designed," he added.

Advertisement



 Tech Trends
1. The Dearth of Female Entrepreneurs
2. U.S. Losing in Clean-Tech Innovation
3. Will Fans Love Hulu If It's Not Free?
4. What Happened To the Tech Rally?
5. Intel & Micron Double Flash Memory


advertisement


 Most Popular Articles
1. Facebook Users Can Get McAfee Virus Protection
2. Reporters Invited To an Apple Event Set Next Week
3. New York Times May Charge for Its Online Content
4. Adobe, Oracle Make Up for Light MS Patch Tuesday
5. Zuckerberg's Comments Unleash Firestorm of Dissent


advertisement


 Random Bytes
Marketing E-Mails Fail To Arrive Social Networks: A Hacker's Delight
AT&T Will Invest in Network Fixes Mobile Firefox Runs on Nokia N900

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Google May Make Gmail More Social
  Analysts Expect iPad Price To Drop
  China Busted Hacker-Training Site
  Nook E-Reader Heads to Retail Stores
  Veteran SAP CEO Abruptly Resigns

 Technology Marketplace
Compliance
Stand out from other IS Professionals and increase your earning potential.®).
 
Enterprise Hardware
Now is the best time to buy a new APC Smart-UPS!
HP ProLiant G6 Servers: Perform like a superstar, Save like an accountant www.hp.com
 
Enterprise I.T.
Learn how Microsoft server upgrades can create efficiencies
Stand out from other IS Professionals and increase your earning potential.®).
 
Hardware
Find out why now is the best time to buy a new APC Smart-UPS!
 
Microsoft/Windows
Read about how to add efficiencies with Microsoft Virtualization.
 
Network Security
AT&T Synaptic Compute as a Service. Boost your power on demand.
 
Mobile Enterprise Spotlight

Analysts See iPad Price Drop, with Some Cannibalization
Just weeks before Apple officially rolls out the iPad, financial analysts are making pricing predictions. But could the analysis itself hinder the initial demand for the pricey tablet computer?

Bar Codes Go Mobile, Get Hip Again
For decades, retailers have used patterns of black dots and lines to encode data onto products. Now, bar codes are gaining favor as an easy way for cell-phone users to view ads and other data instantly.

'Dead Simple, Dirt Cheap' JooJoo Tablet Shipping Soon
The JooJoo, a web-browsing tablet device that is the subject of a high-profile legal dispute, appears on track to reach buyers at the end of February, but the tablet scene has dramatically changed.

Advertisement
Enterprise Software Spotlight

Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.

SAP CEO Abruptly Resigns; Co-CEOs Will Take Over
Business-software maker SAP announced an abrupt strategic shift in the corporate suite with Léo Apotheker resigning as CEO, to be replaced by co-CEOs Bill McDermott (left) and Jim Hagemann Snabe (right).

Cybersecurity Vendors Look Hot in 2010
Tech-security companies are poised to become Wall Street darlings this year, thanks in part to Google's tiff with China, which reinforced an already positive outlook for major security vendors.

Advertisement
Navigation
CIO Today
Home/Top News | Enterprise Software | Enterprise Hardware | Network Security | Compliance | CRM Systems | Data Storage
Chips & Processors | Operating Systems | Communications | World Wide Web | Wireless Tech | Small Business | CIO Issues
Business Briefing | After Hours | Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 CIO Today. All rights reserved. Article rating technology by Blogowogo.