mailing list archives
[Security Weekly] Pen Testing and the Canadian anti-spam law
From: Jamil Ben Alluch <jamil () autronix com>
Date: Tue, 1 Jul 2014 11:36:16 -0400
I wanted to get some points of view in regards to the newly implemented
anti-spam law that entered into effect today in Canada.
There are cases where during pen-testing projects, we are in a way required
to send emails in order to test out phishing attempts, malware downloads
These would have to be crafted in a way that is appealing to the targeted
end-user and often will have some kind of appealing sales connotation or
fake business application.
Now according to the CASL <http://fightspam.gc.ca/>, this would entitle
senders to up to CA$1,000,000 in fines, if you are an individual, and
$10,000,000 in fines if you are a business.
Obviously in our line of work, in order to perform our duties as
pen-testers, this could turn out to be a problem and remove the possibility
of trying out sets of attack vectors relying on emails.
I'd like to get some opinions on this matter.
*Jamil Ben Alluch, ing. jr, GCIH*
[image: Autronix] <http://www.autronix.com>
*Information Technology & Security Consulting*
jamil () autronix com
securityweekly mailing list
securityweekly () mail securityweekly com
Main Web Site: http://pauldotcom.com
- [Security Weekly] Pen Testing and the Canadian anti-spam law Jamil Ben Alluch (Jul 02)