3 ms·
This is a perfect guide on how to not respond to the release of a security researcher. Also, for context, here is the original article from the security resear
by nezza-_- 9y ago
This is a perfect guide on how to not respond to the release of a security researcher.
Also, for context, here is the original article from the security researcher: https://scotthelme.co.uk/nomx-the-worlds-most-secure-communications-protocol/ https://scotthelme.co.uk/nomx-the-worlds-most-secure-communi...
- j_s 9y agoDiscussed here yesterday: https://news.ycombinator.com/item?id=14209874 https://news.ycombinator.com/item?id=14209874
- floatboth 9y agoHahaha the best thing is how, because the admin panel is not HTTPS, the researcher's browser literally says "Not secure" :D
- darklajid 9y agoGiven HOW broken the setup was (it wasn't even a remotely decent mail server setup in the first place, let alone 'the only secure solution' of course), what did we expect? The marketing material was already screaming snake oil. Now they're trying to put out the fire with .. more snake oil, avoiding any specifics related to the original criticism. Sad. Absolutely expected, but sad nonetheless.
- tgragnato 9y ago> as we’ve demonstrated to the blogger, the media and our customers There's no demonstration, and they can't know if a customer has been compromised or not. Selling snake oil is .. well, let's say despicable; but clearly lying when exposed is perhaps even worse. I expect the decency to be silent, please.