Password manager maker Keeper sues Ars Technica and reporter Dan Goodin for story on a vulnerability in Keeper software, first highlighted by Google researcher
the company behind the product— is suing Dan and Ars. In the extraordinary complaint, Keeper says Dan ‘intended’ to cause harm http://www.documentcloud.org/ ... via @zackwhittaker http://twitter.com/... Matt Blaze / @mattblaze : In my professional opinion, suing those who discuss software vulnerabilities is itself a reliable indication of dangerously vulnerable software and incompetent security practices. For that reason, I will be avoiding Keeper Security products. https://twitter.com/... Kim Zetter / @kimzetter : This suit is ridiculous and will go away, but what a bad precedent this is for a security firm to set and what a dishonorable way to treat a journalist who has covered security for years and takes great pains to get things right @keepersecurity https://twitter.com/... Robert Graham's naughty list / @erratarob : Confirmed: Dan Goodin is not simply technical, but extraordinarily interested in getting the story right. This one time he interviewed me for a story, then told me I was wrong, and he was right. https://twitter.com/... Nicholas Weaver / @ncweaver : Let me get it straight, Keeper claims this is defamatory solely because the browser extension isn't mandatory, but a “separate program”? Who tolerates using a password manager without the corresponding browser extension?!? https://twitter.com/... Rafael Rivera / @withinrafael : Keeper story is interesting; the app isn't vulnerable, but the separately installed Browser Extension is. So technically, the vulnerable app wasn't preloaded, hence the defamation lawsuit. Tom Warren / @tomwarren : I wondered why this Keeper password manager junk ended up on my Windows PC. The maker is now suing a Ars Technica reporter for reporting on it. Bad look @keepersecurity http://www.zdnet.com/... Joseph Cox / @josephfcox : Keeper is looking for damages to be awarded, and have the article removed. Didn't even read the article last week, thanks for letting everyone know about it Keeper pic.twitter.com/y1virUSvm2 Matt Blaze / @mattblaze : As I've said repeatedly, how a vendor responds to reports of a vulnerability reveals far, far more about the security of a product than the vulnerability itself. Processes are much more significant than any particular bug. Keeper Security is failing badly in this respect. https://twitter.com/... See also Mediagazer