On CBS MoneyWatch: The perfect car for a teenager
BNET Business Network:
BNET
TechRepublic
ZDNet

May 22nd, 2008

TJX whistle blower sacked?

Posted by Larry Dignan @ 2:54 pm

Categories: General, Security, Software Infrastructure

Tags: TJX, CrYpTiC_MauleR, Security, Larry Dignan

TJX, the retailer that was hit with a major security breach, has sacked a whistle blower who was exposing the company’s security issues.

According to the ha.ckers.org site:

I had some very disturbing news today from one of the forum users - he had just been fired by TJX for whistle blowing on their security issues. CrYpTiC_MauleR, who’s posts on TJX can be found here was fired today by TJX for talking about the company’s security flaws. This is the same company who recently lost millions of credit card numbers, for those of you who don’t recall. They tracked him down by IP (we’re still not completely sure how they did this, but we think it may have to do with a DynDNS account he uses), contacted his ISP to find out who he was, brought him into the office, questioned him about what he found, asked for him to write down his thoughts on how to fix the issues and then promptly fired him.

I completely understand why a company would want to reduce their risk, but this doesn’t bode well for future would-be whistle blowers, or for the future state of security for TJX. CrYpTiC_MauleR has been a long time poster on sla.ckers.org and has made a lot of contributions…

Now this is all a little bit hard to verify–it’s not like TJX (all resources) is going to talk about personnel issues. Meanwhile, the full name of CrYpTiC_MauleR isn’t known. However, we have it on good word that this actually happened.

And now for the big question: Should this whistle blower been fired? I’d have to argue that TJX was right to fire CrYpTiC_MauleR. It’s noble to be a whistle blower. It’s another thing to disclose internal information in a hacker forum–especially as TJX was trying to recover from its security breach.

What’s your take?

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

For daily updates, follow Larry on Twitter.

Email Larry Dignan

Subscribe to Between the Lines via Email alerts or RSS.

  • Talkback
  • Most Recent of 13 Talkback(s)
RE: TJX whistle blower sacked?
Erm, has anyone read what he's actually said? The information is way too general to be of any real use to anyone... including hackers. 'Their passwords are too simple to be safe' - not a lot of inform... (Read the rest)
Posted by: Infosys employee Posted on: 10/25/08 You are currently: a Guest | | Terms of Use
...  Linux User 147560 | 05/22/08
Sort've...  endermc12 | 05/22/08
I agree, otherwise  Pliny the Elder | 05/22/08
Management?  shawn_dude | 05/23/08
not in private sector  GDF | 05/23/08
Why not whistle blower use a proxy?  Grayson Peddie | 05/22/08
Ditto  Mikey52 | 05/23/08
Not a Whistle Blower  Qlueless | 05/23/08
I agree.  spookyone1 | 05/24/08
RE: TJX whistle blower sacked?  jblanto5@... | 05/23/08
RE: TJX whistle blower sacked?  drgizmo2002@... | 05/23/08
RE: TJX whistle blower sacked?  nellwal@... | 05/24/08
RE: TJX whistle blower sacked?  Infosys employee | 10/25/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc