Journalist questioned by police after reporting Facebook security flaw
thenextweb.com
thenextweb.com
The standard belief is as follows: being proactive about privacy and security costs money, and if we don't have to spend money we won't. Most people, the ones we're crowdsourcing or selling to advertisers, don't understand and won't care who actually screwed up - we'll blame the hackers and that will limit negative perceptions.
Advantage to you of trying to disclose the flaw: zero in most cases.
Disadvantage to you of trying to disclose the security flaw: possibly years in jail, hundreds of thousands of dollars spent.
It's unfortunate that this is true, but it's true nonetheless. The country needs a Computer Good Samaritan law, where those who follow a prescribed process for flaw disclosure are granted complete immunity from prosecution, civil suits and general harassment.
"According to Grubb, security expert Christian Heinrich demonstrated in front of the delegates how he had managed to acquire privacy-protected photos of the wife of fellow conference speaker Chris Gatford, who is Director at HackLabs."
Isn't it more likely that the police are investigating charges against Heinrich in relation to the presentation?
He claimed in a tweet that he was, but I kinda doubt it -- for starters he wasn't arrested for anything, and secondly if you are under arrest are you allowed to keep your phone and tweet all about it?
So, was he being over-dramatic, or did he genuinely believe he's under arrest? (Oh, and a handy hint: if the police ever ask you to go with them then make sure you ask 'em whether you're under arrest or not.)