4 ms·
Is protocol if you find these things a security researcher not to share the link? I read about these leaks a lot and am always interested in viewing them but ne
by cbau 7y ago
Is protocol if you find these things a security researcher not to share the link? I read about these leaks a lot and am always interested in viewing them but never can find them. I assume the links are shared with people carefully because a small number of people will use them maliciously.
- LocalPCGuy 7y agoDepending on the severity of the breach, yes it's generally considered best practice to notify the service first and give them time to deal with it. Depending on how bad it is, the person reporting it may be compensated for finding it. The company would generally fix the issue, and then the person who found it can make it public (based on their agreement with the company sometimes). The time period is often 90 days, but it could be worked out independently per case. As with anything like this, consult a lawyer who knows this area of the law of you find yourself in this situation.
- Bnshsysjab 7y agoIt’s never good to disclose PII. Dropping vulns after responsible disclosure is mostly considered ok, not so much with PII - it’s not the victims fault and can be damaging longer term. If the vendor refuses to fix the issue, providing the media with enough redacted info to have them publish a story will force the vendors hand.