Australian Teen Reports SQL Injection Vulnerability, Company Calls Police
FuzzNugget writes with an excerpt from Wired, which brings us the latest in security researcher witch hunts: "Joshua Rogers, a 16-year-old in the state of Victoria, found a basic security hole that allowed him to access a database containing sensitive information for about 600,000 public transport users who made purchases through the Metlink web site run by the Transport Department. It was the primary site for information about train, tram and bus timetables. The database contained the full names, addresses, home and mobile phone numbers, email addresses, dates of birth, and a nine-digit extract of credit card numbers used at the site, according to The Age newspaper in Melbourne. Rogers says he contacted the site after Christmas to report the vulnerability but never got a response. After waiting two weeks, he contacted the newspaper to report the problem. When The Age called the Transportation Department for comment, it reported Rogers to the police.'"
And it really doesn't matter in the overall theme.
What's really messed up is to arrest someone pointing out a problem. The next time a problem is discovered it's then a lot better to just mess up the whole thing instead and let the flawed organization take the full power of the force of a failure.
If builders built buildings the way programmers wrote programs, then the first woodpecker would destroy civilization.