5 ms·
Look at it this way, you could also have been "rewarded" with a 30-year jail sentence. Please don't mess with big corps.
by melvinmt 10y ago
Look at it this way, you could also have been "rewarded" with a 30-year jail sentence. Please don't mess with big corps.
- TeMPOraL 10y agoIf bpchaps would mess with Comcast directly then maybe; if he sold the knowledge somewhere else than not really. I don't recall hearing of any case where a hack was traced all the way back to the third party that found and sold the vulnerability.
- 67726e 10y agoWell considering it's Comcast, I'd be more then happy to "accidentally" disclose those vulnerabilities.
- TeMPOraL 10y agoYeah, it's one of those companies that are really asking for it. In some cases it's hard to do the ethical thing :).
- bpchaps 10y agoThe thought crossed my mind. ;) But being able to say "$GOODTHING happened because of me" felt so much better. It just means in the end that 50% of my meals are lentil based :P.
- ars 10y agoBut small corps are OK?
- bpchaps 10y agoYour attitude is so amazingly fear based - fuck that sauce. What makes you think I'm actually messing with big corps? I'm not. I disclosed the issue properly and safely. I have a good lawyer who would step in to help if something bad happened. But hell, if something bad did happen, where I can't get out of a sentence like that, then fine. It is what it is. But letting that fear of 30 years of prison prevent me from disclosing something that could have long term effects for millions? Fuck. That. I wasn't even doing any of this for money. I found it, I wanted to correct it. That's it. But for their CISO to drop a giant deuce on me like that without as much as a "Thank you" from her? Heh. It's a little annoying.
- melvinmt 10y agoHave you ever heard of a thing called the "Computer Fraud and Abuse Act"? Even the act of disclosing a vulnerability to the company itself can be misconstrued by paranoid big corps as a "security breach", hence the possibility of a 30 years sentence. I'm just saying it's not worth the risk. At least not in the US.
- bpchaps 10y agoI'm well aware of what the risks are. It was something from github, so it's not like I was doing anything crazy, anyway. During my disclosure, I told them the kinds of port scans I did, and the types of individuals I shared the information to. As full disclosure as I possibly could have been. I'd rather not fall into this trap: https://theintercept.com/2016/04/28/new-study-shows-mass-surveillance-breeds-meekness-fear-and-self-censorship/ https://theintercept.com/2016/04/28/new-study-shows-mass-sur...
- lawnchair_larry 10y agoThat isn't possible under the CFAA.
- sangnoir 10y ago> Your attitude is so amazingly fear based - fuck that sauce. I really think this part: > > I really don't get it. I could have just as easily sold everything in there for big monies, or could have personally done havoc of my own. would have earned you a prison sentence (if caught). The most obvious ways to 'profit' from security bugs for corps with no bug bounties are illegal.
- bpchaps 10y agoRight. I'm just sharing my experience at this point, though. Can't get caught if I'm not doing anything to get caught. And again, I went through the proper, ethical channels to get this raised.