4 ms·
Companies being generally unreceptive to this kind of feedback is partly why full disclosure is so necessary. If they won't treat a security incident with the i
by click170 11y ago
Companies being generally unreceptive to this kind of feedback is partly why full disclosure is so necessary. If they won't treat a security incident with the importance it deserves its time to elevate it to a PR incident by posting to full disclosure.
- click170 11y agoTo clarify, posting data that you exfiltrated crosses a line and you shouldn't do this. Publishing a proof of concept for the exploit instead is widely considered acceptable especially when the publisher attempted to contact the vendor and got a wall of silence.