5 ms·
You could remove your accounts and move on but that does nothing for their other customers. Depending on how much time you've given them this sounds like a per
by click170 11y ago
You could remove your accounts and move on but that does nothing for their other customers.
Depending on how much time you've given them this sounds like a perfect candidate for the Full Disclosure mailing list, just post anonymously.
- OberonXanatos 11y agoFull disclosure mailing list seems intriguing, I have not actually thought of this before. Are companies generally receptive to this kind of disclosure. If someone maliciously dumps all their customer records and posts them on pastebin is it likely that I may get in legal trouble?
- Sanddancer 11y agoWere you to post to full-disclosure, you'd probably not see a lick of trouble. You exercised due diligence. You gave them more than ample time to acknowledge the bug, and they continue to have a flaw that allows arbitrary people to see personal information. Then again, given the information you've given, there's a different route you can probably take. This sounds very much like a HIPAA violation, and the federal government takes those very seriously. Report it here: http://www.hhs.gov/hipaa/filing-a-complaint/what-to-expect/index.html http://www.hhs.gov/hipaa/filing-a-complaint/what-to-expect/i... if they are a health entity that would fall under HIPAA rules.
- click170 11y agoCompanies being generally unreceptive to this kind of feedback is partly why full disclosure is so necessary. If they won't treat a security incident with the importance it deserves its time to elevate it to a PR incident by posting to full disclosure.
- click170 11y agoTo clarify, posting data that you exfiltrated crosses a line and you shouldn't do this. Publishing a proof of concept for the exploit instead is widely considered acceptable especially when the publisher attempted to contact the vendor and got a wall of silence.