5 ms·
I'm not defending the Sentinel in any way, but maybe the author could've avoided downloading other people's passport information. An alternative way to confirm
by pzh 9y ago
I'm not defending the Sentinel in any way, but maybe the author could've avoided downloading other people's passport information. An alternative way to confirm the vulnerability would have been to only access their own data from private mode or through VPN. That way they could prove that the vulnerability exists without getting implicated in an unauthorized access charge.
- deleted 9y ago[deleted]
- Kalium 9y agoThat's a great thought! I can see exactly how you got there. Surely the author could have proven their point just as effectively while still respecting all the privacy of others, right? Clearly Sentinel is a professional organization that would have responded appropriately! What's unfortunate about this scenario is that it shows a company reacting in fear. We can see denial, minimization, legal threats, and attempts to silence. These are the signs of an immature organization that cannot be trusted to react professionally to the sort of approach you wisely describe. Consider. I am a reasonable person under a lot of stress, betting a lot on technologies I don't fully understand or control. Some rando claims my technology is incredibly reckless with a lot of people's personal information, and their proof is that they can view their own docs. Of course they can see their own docs - that's the point! There's no issue here at all... Does that sound like a plausible scenario to you? Because it's painfully realistic to me. There's a reason I use an identity that's difficult to trace to my legal self when reporting vulnerabilities to companies that I can't trust the maturity of.
- itsdrewmiller 9y agoTelegram is not the organization in question here - they were just named as a medium for communication about the organization that had the vulnerability.
- Kalium 9y agoYou are correct. I'll fix my comment.