ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Compliance Toolkit

Security researcher faces jail for finding bugs

Munir Kotadia ZDNet Australia

Published: 11 Jan 2005 12:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A French security researcher who published exploit codes that could take advantage of bugs in an antivirus application could be imprisoned for violation of copyright laws.

In 2001, French security researcher Guillaume Tena found a number of vulnerabilities in the Viguard antivirus software published by Tegam. Tena, who at the time was known by his pseudonym Guillermito, published his research online in March 2002.

However, Tena's actions were not viewed kindly by Tegam, which initiated legal action against the researcher. That action resulted in a case being brought to trial at a court in Paris, France. The trial kicked off on 4 January, 2005, after being deferred from its initially scheduled start date of 5 October, 2004. The prosecution claims that Tena violated article 335.2 of the code of the intellectual property and is asking for a four month jail term and a €6,000 fine. Additionally, Tegam is proceeding with a civil case against Tena and asking for €900,000 in damages.

Accoridng to Tena's Web site, his research "showed how the program worked, demonstrated a few security flaws and carried out some tests with real viruses. Unlike the advertising claimed, this software didn't detect and stop '100 percent of viruses'."

Tena, who is currently a researcher for Harvard University in Massachusetts, said that Tegam responded in a "weird way" by first branding him a terrorist and then filing a formal complaint in Paris. During the resulting tribunal, Tena said the judge decided that because the published exploits included some re-engineered source code from Viguard's software, he had violated French copyright laws.

According to French security Web site K-OTik, Tena had technically broken copyright laws because his exploits were "not for personal use, but were communicated to a third party".

However, K-OTik, which regularly publishes exploit codes, claims that the ruling could create a precedent which would mean that vulnerabilities in software, however critical, could not be declared publicly without prior agreement from the software publisher.

K-OTik's editors say the ruling is "unimaginable and unacceptable in any other field of scientific research".

On Tena's Web site, he claims that if independent researchers are not allowed to freely publish their findings about security software then users will be only have "marketing press releases" to assess the quality of the software. "Unfortunately, it seems that we are heading this way in France and maybe in Europe," Tena said.

"To use an analogy, it's a little bit as if Ford was selling cars with defective brakes. If I realised that there was a problem, opened the hood and took a few pictures to prove it, and published everything on my Web site, then Ford could file a complaint against me," added Tena.

Philip N. Argy, senior partner of the intellectual property and technology group at Australian law firm Mallesons Stephen Jaques, said that if a similar case was put to trial in Australia the prosecution would be unlikely to get a conviction because of our "fair comment provisions".

"We have strong copyright protection as well as strong anti-hacking laws, but from what I can glean from the translations, all that Guillermito did was to publish the details of the parts of the code which contained serious bugs that made the software erroneously treat as a virus some legitimate software. I'd have thought that would be at least within the fair comment provisions of Australian copyright law," said Argy.

The final ruling will be made in Paris on 8 March, 2005.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
79 out of 163 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:
















Related Jobs

Service Delivery Manager - Customer Development & Food solutions - IT Manager - St. David\'s Park, Teeside , North West

Recognises, and actively seeks ways to exploit information technology to address complex business, organisational and technical issues, of both a ...

TWS Scheduling Specialist - UNIX AIX/TRU64, Windows O/S, MS Office, Shell - St Davids Park, Ewloe, Deeside

Provide 2nd level infrastructure support as required - Undertake the diagnosis and completion of Root Cause Analyses to enable Problem Management as ...

Support Analyst

Account management creation, administration and disabling of user accounts for trial and live purposes. Liaising with Customers on a daily basis and ...

Loading Video Player ....

Featured Talkback

There will be further activation issues to watch out for as Microsoft plans to offer a similar service to independent software vendors whereby they can "control" licensing through activation and other measures similar to the Software Protection Platform.

By: DefenceIT

Read full story:
Microsoft outage down to 'human error'

Sentry Posts Blog

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment

Trades Unions against ID Cards

The Trades Union Congress (TUC) has backed up airport workers protesting against ID cards, the Financial Times reports. In a letter to Home Secretary Jacqui Smith, the TUC said it... More

Post a comment