3 ms·
Have you ever heard of a thing called the "Computer Fraud and Abuse Act"? Even the act of disclosing a vulnerability to the company itself can be misconstrued b
by melvinmt 10y ago
Have you ever heard of a thing called the "Computer Fraud and Abuse Act"? Even the act of disclosing a vulnerability to the company itself can be misconstrued by paranoid big corps as a "security breach", hence the possibility of a 30 years sentence. I'm just saying it's not worth the risk. At least not in the US.
- bpchaps 10y agoI'm well aware of what the risks are. It was something from github, so it's not like I was doing anything crazy, anyway. During my disclosure, I told them the kinds of port scans I did, and the types of individuals I shared the information to. As full disclosure as I possibly could have been. I'd rather not fall into this trap: https://theintercept.com/2016/04/28/new-study-shows-mass-surveillance-breeds-meekness-fear-and-self-censorship/ https://theintercept.com/2016/04/28/new-study-shows-mass-sur...
- lawnchair_larry 10y agoThat isn't possible under the CFAA.