<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Blogger Discovered LHDN e-Filing Security Vulnerability</title>
	<atom:link href="http://www.sabahan.com/2007/04/11/blogger-discovered-lhdn-e-filing-security-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sabahan.com/2007/04/11/blogger-discovered-lhdn-e-filing-security-vulnerability/</link>
	<description>About Computers, Blogging, Making Money Online, Marketing and Interesting Stuff</description>
	<lastBuildDate>Fri, 03 Feb 2012 09:22:46 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: LHDN e-Filing Security Problem Fixed &#171; Sabahan.com</title>
		<link>http://www.sabahan.com/2007/04/11/blogger-discovered-lhdn-e-filing-security-vulnerability/comment-page-1/#comment-24399</link>
		<dc:creator>LHDN e-Filing Security Problem Fixed &#171; Sabahan.com</dc:creator>
		<pubDate>Tue, 17 Apr 2007 05:05:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.sabahan.com/2007/04/11/blogger-discovered-lhdn-e-filing-security-vulnerability/#comment-24399</guid>
		<description>[...] posted earlier about a discovery made by a blogger about the data leak he was experiencing why filling his tax [...]</description>
		<content:encoded><![CDATA[<p>[...] posted earlier about a discovery made by a blogger about the data leak he was experiencing why filling his tax [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WATTAHACK?</title>
		<link>http://www.sabahan.com/2007/04/11/blogger-discovered-lhdn-e-filing-security-vulnerability/comment-page-1/#comment-24373</link>
		<dc:creator>WATTAHACK?</dc:creator>
		<pubDate>Mon, 16 Apr 2007 14:55:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.sabahan.com/2007/04/11/blogger-discovered-lhdn-e-filing-security-vulnerability/#comment-24373</guid>
		<description>Please post update on this matter so others know its resolved.

http://wattahack.blogspot.com/2007/04/resolved-lhdn-e-filing-leaking-data.html</description>
		<content:encoded><![CDATA[<p>Please post update on this matter so others know its resolved.</p>
<p><a href="http://wattahack.blogspot.com/2007/04/resolved-lhdn-e-filing-leaking-data.html" rel="nofollow">http://wattahack.blogspot.com/2007/04/resolved-lhdn-e-filing-leaking-data.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gaman</title>
		<link>http://www.sabahan.com/2007/04/11/blogger-discovered-lhdn-e-filing-security-vulnerability/comment-page-1/#comment-24341</link>
		<dc:creator>Gaman</dc:creator>
		<pubDate>Sun, 15 Apr 2007 10:43:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.sabahan.com/2007/04/11/blogger-discovered-lhdn-e-filing-security-vulnerability/#comment-24341</guid>
		<description>The guy is just a blogger to start with and he is not bound by any procedure or law to report any vulnerabilities overlooked by any organization - at least for now (as far as I am aware)

What he did is a common practice among bloggers in developed countries like in the US. It&#039;s even worst there where they sometimes publish all the juicy details at will.

Does this do more harm then good? 

It could be harmful but in a way this forces the organization to shorten their response time further. They take security even more seriously instead of delegating beta testing to the unwilling general public.

I agree with you though that ideally the guy should had reported it first. Sadly the reality is less than ideal.</description>
		<content:encoded><![CDATA[<p>The guy is just a blogger to start with and he is not bound by any procedure or law to report any vulnerabilities overlooked by any organization &#8211; at least for now (as far as I am aware)</p>
<p>What he did is a common practice among bloggers in developed countries like in the US. It&#8217;s even worst there where they sometimes publish all the juicy details at will.</p>
<p>Does this do more harm then good? </p>
<p>It could be harmful but in a way this forces the organization to shorten their response time further. They take security even more seriously instead of delegating beta testing to the unwilling general public.</p>
<p>I agree with you though that ideally the guy should had reported it first. Sadly the reality is less than ideal.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bengodomon</title>
		<link>http://www.sabahan.com/2007/04/11/blogger-discovered-lhdn-e-filing-security-vulnerability/comment-page-1/#comment-24339</link>
		<dc:creator>bengodomon</dc:creator>
		<pubDate>Sun, 15 Apr 2007 09:57:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.sabahan.com/2007/04/11/blogger-discovered-lhdn-e-filing-security-vulnerability/#comment-24339</guid>
		<description>With the right escalation system, it should be very quick for the details to reach the correct person. In all probability, system development and maintenance is done by a 3rd party (private company), as is the case with most federal app development projects. If the private company is good, they would get to work right away.

Informing firstly the PIC of the organisation in charge of the application is standard ICT security procedure. I think informing the general public of the vulnerability, even if not the whole juicy details, does more harm than good.

Once the relevant authorities does something about it, then only would I consider going public about it.</description>
		<content:encoded><![CDATA[<p>With the right escalation system, it should be very quick for the details to reach the correct person. In all probability, system development and maintenance is done by a 3rd party (private company), as is the case with most federal app development projects. If the private company is good, they would get to work right away.</p>
<p>Informing firstly the PIC of the organisation in charge of the application is standard ICT security procedure. I think informing the general public of the vulnerability, even if not the whole juicy details, does more harm than good.</p>
<p>Once the relevant authorities does something about it, then only would I consider going public about it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gaman</title>
		<link>http://www.sabahan.com/2007/04/11/blogger-discovered-lhdn-e-filing-security-vulnerability/comment-page-1/#comment-24337</link>
		<dc:creator>Gaman</dc:creator>
		<pubDate>Sun, 15 Apr 2007 07:29:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.sabahan.com/2007/04/11/blogger-discovered-lhdn-e-filing-security-vulnerability/#comment-24337</guid>
		<description>Unfortunately not everyone is motivated enough to do that.

Unlike a smaller company, it would probably take forever to escalate the issue to the right person in LHDN - all this at the expense of the general public because of the bureaucracies in the system.

If I discover a vulnerability in a system, I would blog about it but leave out the details about the exploit itself. At the same time I&#039;ll contact the relevant authorities - and it&#039;s up to them to act.</description>
		<content:encoded><![CDATA[<p>Unfortunately not everyone is motivated enough to do that.</p>
<p>Unlike a smaller company, it would probably take forever to escalate the issue to the right person in LHDN &#8211; all this at the expense of the general public because of the bureaucracies in the system.</p>
<p>If I discover a vulnerability in a system, I would blog about it but leave out the details about the exploit itself. At the same time I&#8217;ll contact the relevant authorities &#8211; and it&#8217;s up to them to act.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bengodomon</title>
		<link>http://www.sabahan.com/2007/04/11/blogger-discovered-lhdn-e-filing-security-vulnerability/comment-page-1/#comment-24335</link>
		<dc:creator>bengodomon</dc:creator>
		<pubDate>Sun, 15 Apr 2007 06:54:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.sabahan.com/2007/04/11/blogger-discovered-lhdn-e-filing-security-vulnerability/#comment-24335</guid>
		<description>What he should&#039;ve done is report the problem straight to LHDN first, and not post to his blog. With his action, he could&#039;ve caused more harm than good.

In the past, have also discovered several vulnerabilities, including one that was developed by a MSC-status company, but I always contacted the PIC first.</description>
		<content:encoded><![CDATA[<p>What he should&#8217;ve done is report the problem straight to LHDN first, and not post to his blog. With his action, he could&#8217;ve caused more harm than good.</p>
<p>In the past, have also discovered several vulnerabilities, including one that was developed by a MSC-status company, but I always contacted the PIC first.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: toxicle</title>
		<link>http://www.sabahan.com/2007/04/11/blogger-discovered-lhdn-e-filing-security-vulnerability/comment-page-1/#comment-24301</link>
		<dc:creator>toxicle</dc:creator>
		<pubDate>Fri, 13 Apr 2007 05:24:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.sabahan.com/2007/04/11/blogger-discovered-lhdn-e-filing-security-vulnerability/#comment-24301</guid>
		<description>Just when I&#039;m about to use it I get this news. Hrmm ... I hope they fix it before the end month dateline.</description>
		<content:encoded><![CDATA[<p>Just when I&#8217;m about to use it I get this news. Hrmm &#8230; I hope they fix it before the end month dateline.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

