Report a bug, go to jail.A new federal prosecution again raises the issue of whether computer security experts must fear prison time for investigating and reporting vulnerabilities.
On April 28, 2006, Eric McCarty was arraigned in U.S. District Court in Los Angeles. McCarty is a professional computer security consultant who noticed that there was a problem with the way the University of Southern California had constructed its web page for online applications. A database programming error allowed outsiders to obtain applicants' personal information, including Social Security numbers.
When will they learn? As reported, previous prosecutions for such things have resulted badly for the prosecution.