Feeds

Full disclosure put on trial in France

Security research faces the guillotine?

  • alert
  • submit to reddit

The Power of One eBook: Top reasons to choose HP BladeSystem

The trial of a French security researcher last week has become a cause celebre. Its outcome will decide if interested parties can "peek under the bonnet" in testing the road-worthiness of security products without falling foul of French law.

The case began more than three years ago when Guillaume Tena (AKA Guillermito) released proof of concept code to highlight security bypass and worm evasion flaws in Viguard, an antivirus product, from French company Tegam. Tena produced exploits showing that Tegam's generic anti-virus failed to stop "100 per cent of known and unknown viruses" as claimed. He posted his findings to a French usenet newsgroup in the summer of 2001 before published the research on a website in March 2002.

Tegam reacted by denouncing Tena as a 'terrorist', before sending its lawyers against him. In June 2002, Tena was prosecuted under violation of French copyright law. Tegam argued a warez version of its software was used in Tena's tests and claimed that he decompiled or disassembled Viguard and distributed part of its source code on his website. Tena denies these accusations. Tegam claims tens of thousands of Viguard users in France. However, the product is little used outside the country.

Tegam's case against Tena came to trial at a Tribunal correctionnel in Paris last week (4 January) with the prosecution calling for the 35 year-old to receive a suspended sentence of four months and a fine of €6,000. Tegam has raised the stakes and is demanding €900,000 in damages, a vast sum even the prosecutor isn't supporting. Tena, a French national researching molecular biology at Harvard University while working at Massachusetts General Hospital, hopes for an acquittal. A verdict is due to be returned on March 8.

Tena said the case could have a big impact on the French computer security community. "This case is not about violating intellectual property, it's about Tegam trying to shut me up," he told El Reg. "If security research is stifled, companies could produce a flawed product and no-one would know any better."

Although a molecular biologist by profession, Tena has maintained a hobby in computing (in particular anti-virus and steganography) since 1995. "I like to look inside programs for the same reason I'm interested in finding out the inner workings of cells," he explained.

Tena developed new viruses to test Tegam's product but he didn't post them on his website. He downplayed any suggestion his research could give ideas to malicious hackers or virus writers. Full disclosure postings are an effective means to pressurise vendors into producing more secure software, he argues.

French security researchers are alarmed at the possible impact of the case. "Full disclosure could become illegal in France," Gilles Fabienni, a security engineer at K-OTik Security Research, told The Register. He added that Tena's case predates the introduction of the EU Copyright Directive which tilts the scales of justice even further against French security researchers. ®

Related stories

California enacts full disclosure security breach law
Elcomsoft not guilty DoJ retreats from Moscow
Jury scrutinises DMCA in ElcomSoft case
DMCA strikes again in N2H2 filtering list case
Slammer: Why security benefits from proof of concept code

Designing a Defense for Mobile Applications

More from The Register

next story
DARPA-derived secure microkernel goes open source tomorrow
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
Four fake Google haxbots hit YOUR WEBSITE every day
Goog the perfect ruse to slip into SEO orfice
Putin: Crack Tor for me and I'll make you a MILLIONAIRE
Russian Interior Ministry offers big pile o' roubles for busting pro-privacy browser
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.