3 ms·
I reported a vulnerability in blackboard when I was in college (around the same time period as you). I don't recall any sort of disclosure mailing list, and th
by Rychard 7y ago
I reported a vulnerability in blackboard when I was in college (around the same time period as you).
I don't recall any sort of disclosure mailing list, and the only contact link I found seemingly went through my college's IT department. Whether my university had applied some customization, or whether it was just me being a young college student, I'm not sure.
Anyways, a few days after I had reported the vulnerability, I was summoned to a meeting where I found myself sitting at a table opposite my academic advisor, as well as the Department Chair of the CS department, where they began to speak to me about "academic integrity".
I'm glad the story mostly ends there, as during this meeting I realized what had actually happened; someone in the IT department had misinterpreted my report as some sort of hacking threat, and they had "tracked me down on the university network", which makes no sense because I had reported the vulnerability via email directly from my .edu address.
While I wasn't exactly well-liked among the professors in the CS department, the department chair at least recognized that it was a big misunderstanding, that I wasn't doing anything nefarious, and had been acting in good faith.
After that meeting, I had approximately zero interest in disclosing vulnerabilities of any sort, for fear of being on the hook if/when they were ever exploited.
- tastroder 7y ago> I don't recall any sort of disclosure mailing list, fyi, your parent post referred to [1] here. Glad nothing too bad came of your disclosure. [1] https://seclists.org/fulldisclosure/ https://seclists.org/fulldisclosure/
- droithomme 7y ago> After that meeting, I had approximately zero interest in disclosing vulnerabilities of any sort Sales to a private broker is one alternative.