Updated 1/20/15
Viridian Sciences, a producer of business management software and other solutions for the cannabis industry, recently posted a blog titled, "Major Cyber-Security Flaw in Washington State’s Cannabis Tracking System!" According to the blog, which is written by the company's CEO, the company "has been working on integrating with the Washington State cannabis 'Seed-to-Sale'Â traceability software built by BioTrackTHC."Â The blog also says that the company has not only found "a major hole in the security of the Washington state cannabis tracking system, but also has learned that BioTrackTHC had full knowledge of this fact and has greatly misled the licensed participants. … Â BioTrackTHC programmatically tells the users that they are logging into a secure system when they are, in fact, not."
According to a statement from the Washington State Liquor Control Board (WSLCB), there is "no evidence of anomalies or any breach." Here's the statement from Brian E. Smith, Communications Director for the WSLCB:
"It has been reported online that Washington State’s recreational marijuana seed-to-sale traceability system has shown potential vulnerabilities that could lead to the software system being compromised. It has also been reported that the system could be temporarily shut down.
We are confident in the security of the system. As with any steward of private data, we ensure that strenuous precautions are taken to prevent any vulnerabilities. Our vendor has scanned the system and has seen no evidence of anomalies or any breach.
The Washington State Liquor Control Board and our vendor, BioTrackTHC, were not contacted for comment or fact-checking before this story was published. We recognize that attempts to hack an organization’s software systems is commonplace in today’s society. We will continue to ensure that the system is protected using the latest and best security practices."
BioTrackTHC also released a statement, saying, "As a market leader in the United States for regulatory compliance, BioTrackTHC knows that by holding this coveted spot there are lesser competitors providing erroneous information to the public and the media for the purpose of creating harm against our hard earned, sound reputation. BioTrackTHC leads the industry in both regulatory compliance government programs and in seed-to-sale enterprise commercial systems."
In response to a post on Twitter suggesting that all Washington State businesses using the tracking system need to change their passwords, BioTrackTHC replied: "It's a commonly accepted best practice in cyber security to change password information from time-to-time. It is a sound practice under any circumstances whether in our industry or any business sector."