3 ms·
This is just "feel-good" bullshit that doesn't actually solve any real problem. In my life, I have only reported two different vulnerabilities to two different
by disconnected 9y ago
This is just "feel-good" bullshit that doesn't actually solve any real problem.
In my life, I have only reported two different vulnerabilities to two different vendors.
One of them didn't care at all. They were transmitting usernames and passwords in plaintext and I actually showed one of their engineers this, live, in person, and he just shrugged.
The other one told me something to the effect of "yes, this is very serious. We'll look into it right away" and actually fixed it... 3 years later.
Your biggest hurdle isn't reporting vulnerabilities. That's the easy part.
The biggest hurdle is getting someone to care.
- subcosmos 9y ago>In my life, I have only reported two different vulnerabilities to two different vendors. Interesting. I don't think this is for you. Ever have the task of needing to report a security issue to 10k sites and wish you could have any hope of automating it? I certainly haven't. More like 100k! Don't be so negative when people try to do good.
- manigandham 9y agoYou needed to contact 100k sites about security? Do you have more details on this? The example security.txt for this site currently has a twitter handle as the contact. How are you going to automate that?
- mzzter 9y agoOne may want to notify many website owners at once that it’s a good time to apply a patch in response to a security vulnerability affecting a technology they are using. Ex: WordPress, node.js, MongoDB, etc.
- manigandham 9y agoThere are 100s of millions of sites, who’s going to crawl all of them and send out alerts? How would you know what backend tech is being used? Major risks and CVEs are already published in the appropriate news channels, which is far more efficient and effective.
- subcosmos 9y agoIt should be, but it isn't, and more importantly, there's lots of critical infrastructure out there that is highly vulnerable.
- manigandham 9y agoWho is running critical infrastructure that you cant easily reach right now? Are you saying you know of a major CVE that has no coverage?
- subcosmos 9y ago> You needed to contact 100k sites about security? Do you have more details on this? There's a number of people out there anonymously helping others close their holes. Some holes can be easily scanned.
- anonymousjunior 9y ago> One of them didn't care at all. They were transmitting usernames and passwords in plaintext and I actually showed one of their engineers this, live, in person, and he just shrugged. Here, now that I've shown you that, let me show you the MITM I've been running during the conference! So far I've collected NNN credential sets