3 ms·
Let's rephrase your question: "Is six months really unreasonable for an airline to fix a vulnerability that allows customer data to be stolen?" Yes, I would sa
by halviti 11y ago
Let's rephrase your question: "Is six months really unreasonable for an airline to fix a vulnerability that allows customer data to be stolen?"
Yes, I would say so.. especially since this is a 'duplicate' meaning that multiple people were already aware of this, and on top of that it seems the only reason it was eventually fixed was because they couldn't delay fixing the problem any more.
I don't think anyone would consider this reasonable.
- protomyth 11y agoWhich makes you wonder if person #3 or higher submitting this bug couldn't sell it since they are not getting a bounty. Six months is a long time to leak customer information.
- crpatino 11y agoIf 3 different whitehats found the same bug independently, it's fairly sure bet that a number of blackhats are already exploiting it.
- ryandrake 11y agoMy point is that BigBureaucracy likely considers it reasonable. In fact, my bet is that an engineering manager in whatever software team deployed this fix is getting at least an 'attaboy' for what his management sees as a lightning fast fix.
- zwerdlds 11y agoIf they were genuinely behind on patching vulnerabilities, I can sort-of understand. Then again, how hard is it for a company of their size to hire some 1099's for a brief time...
- vonklaus 11y agoAbout 10 years ago everyone got super sensitive with regards to airline security. So you problem couldn't just let a bunch of craigslist temps come in and apply some patches working on the live system. I think the guys over at US could work a bit faster, but I will grant them they aren't exactly in an unregulated industry where they can "challenge the status quo". When kalanick bears down on the red tape, people aren't reminded that taxis were the attack vector of America's biggest security event. But yeah, out-source it to one of the hundred or so DoD contractors or security professionals allowed to work on something like this, it likely wasn't that big of a job to patch that vuln.
- zappo2938 11y agoHe should have worded 'tech savvy terrorists' in his request and the result would have been much different.