I can't make enough sense of their definition to decide if it really does disagree with me though, it just thrashes about with this idea about "beneficiaries" of a bug without really making any headway. The authorised / unauthorised partition that has plagued that article over its history is a classic error of the sort that should encourage caution about the idea of "non security" bugs. If a customer has an account with us to buy vegetables they are doubtless an _authorised_ user of the purchasing system. Nevertheless I do not want them to obtain a list of everybody's financial records so the existence of an SQL injection that works only after logging into the purchasing system is still a security bug.