Security researchers can get into trouble faster than they imagine, even if their intentions are noble. Consultant Mark Burnett decided to release ten million passwords accompanied by usernames, which could be interpreted as a crime, but on his official site he indicates several reasons why the FBI should not arrest him, including the fact that the information was already available on the Web.
When it comes to testing the security of a system, protocol, service, or any other tool designed to protect the end user, collaboration between researchers is essential. Reporting a bug no longer seems sufficient these days, and some companies demand more than one confirmation before moving a finger. In other cases, vulnerabilities are a direct consequence of lack of budget and personnel, as has happened with Heartbleed (and by extension OpenSSL). But the blame is not exclusive to developers. To tell the truth, it never was. A bad implementation on a server can expose the data of millions of users, including their credentials and passwords. That's how the databases that researchers work with are created, and they usually share that material. Consultant Mark Burnett decided to collaborate with a data package containing ten million passwords with their usernames, but he did not give the file to his colleagues, instead posting it on BitTorrent so everyone can download it.
The file is in text format and consists of two simple columns. Those who want to discover behavioral patterns in password generation must already be rubbing their hands. However, Burnett had to write an entire article to justify the release, citing the conviction of Barrett Brown, a journalist apparently linked to Anonymous, accused of maintaining links to hacked material. Brown must remain in prison for 63 months (he has already served more than half) and pay almost 900,000 dollars in damages.
Needless to say, Burnett doesn't want to end up like Brown. To avoid that, he explained on his official site that the database lacks information on domains, companies, financial institutions, credit cards, government, and military authorities. As if that weren't enough, the database combines passwords exposed during the last ten years, so there are no solid reasons to accuse him of fraud or promoting illegal computer activities. If we are realistic, most of those passwords are probably no longer valid. The law has become very sensitive on these issues, and if a journalist ended up behind bars, a security researcher could well follow the same path.