2 ms·
First, and this is very important, send them a new mail disclosing the vulnerabilities that says in clear words that if you do not get a response on this in a f
by quantummkv 9y ago
First, and this is very important, send them a new mail disclosing the vulnerabilities that says in clear words that if you do not get a response on this in a fixed number of days, you will go public with your disclosure. Send that mail to everyone concerned in the org.
If you do not get a response, then go ahead and make a blog post about it. Be sure to mention that you failed to get a response from the org in the post.
- bb88 9y agoI would not put a blog post about it, since an injunction would be enough to get it taken down. I would email a security list since email is not retractable once sent.
- deleted 9y ago[deleted]
- quantummkv 9y agoIf the service is publicly available to people, I doubt it would matter. Vulnerabilities are disclosed daily for publicly available services. I remember someone publicly disclosing the vulnerabilities in the Indian government's Aadhar app, a public service, on twitter a few days back. I doubt they took down his tweets. If the service is not publicly available or is some kind of internal, enterprise tool, then it would be a different matter.