“Bye bye electronics ... all now in custody/seized”
twitter.com
twitter.com
If that's true... I just don't know. Even as a kid I've always respected the "Don't joke about a bomb as you pass through security." culture. I mean, christ, a plane flight is so f-ing short. Best practices is shut up, sit down, and keep quiet. It's hyper-public, seven powers of magnitude more touchy than screaming "Fire" in a crowded theatre.
Airplanes, airports, and other international public places are not sanctified platforms of free speech. They're special cases, like visiting your in laws that you want to be on the good side of. Religion, politics, blue-humor, graveyard whistling, none of them are appreciated by anyone, for the most part.
Right? Am I completely retardomantobhan?
Edit: I submitted this link not because the action wasn't justified (joking about hacking into the electronics on a plane obviously isn't OK) but rather as a reminder of who is listening and what can happen.
There needs to be more available venues for PenTesters and white/greyhat hackers to be paid for their line of work. But security is often overlooked because the masses aren't educated on the subject.
The number of companies that have lied about "your information is totally secure" is beyond belief. This is one of the reasons why.
These sorts of changes would need to be drastic - and therefore are unrealistic. Until something bad happens because of them... unfortunately that's the only thing that causes change.
That's what freelancers are for. If a citizen PenTester found something I guess there should be some kind of token "reward". But I can imagine that a big company doesn't want every Tom, Dick, and Harry poking at their sensitive bits.
>What about public awareness?
What about it? I think Computer Security and Security in general should be taught in school along side critical thinking. But that's not happening any time soon.
>How would the PenTester know the security flaw was patched?
That would most likely be in the compensation agreement, lots of legaleese.
I think they'd prefer whitehats over blackhats poking at their sensitive bits.
>What about it?
Situations like this can make the news. They can cause a big hubbub. They can raise awareness. Not always (this case seems like it definitely won't) - but doing these greyhat sort of pranks has a larger chance than never talking about it at all.
>That would most likely be in the compensation agreement, lots of legaleese.
I meant if it was anonymously reported (unless this is optional) - they would not be able to be contacted for compensation. I'm all for emailing/anonymous tips without expectations of compensation.
Should we really be defending companies because "they shouldn't have to pay out money to improve their security of OUR PERSONAL DATA"?
I don't care if every Tom, Dick, Jane, and Harry is poking around sensitive areas. If they're getting into 'secured' areas or stealing personal information - that's a problem for people and it's the companies job to have tighter security.
>Should we really be defending companies because "they shouldn't have to pay out money to improve their security of OUR PERSONAL DATA"?
I don't think anyone was saying that.
... and would like to add: If an idle, up to date, informal, and benign actor can poke around the sensitive bits of a company that company needs to do some serious work, possibly firing sec staff or suing previous freelancers. I think that at a high level businesses need to do due diligence, but then also trust professionals and experts that a job done is actually done.
Also, my previous statement about systemic secEd would apply here as those businesses would understand that security is a process not a destination. Right?