5 ms·
Why do security researchers keep being nice to these companies when said companies mistake good intentions with malicious ones and treat the security researcher
by MetalGuru 6y ago
Why do security researchers keep being nice to these companies when said companies mistake good intentions with malicious ones and treat the security researchers like shit?
- b0afc375b5 6y agoFool me once, shame on you. Fool me twice...
- schoolornot 6y agoWhy do security people feel compelled to pen test sites without a contract or formal engagement? Such a super simple lesson to be learned. If you are not approached, leave it alone. If you offer your services and they aren't accepted, leave it alone. Just because I keep my front door unlocked it doesn't mean you can walk in nor does it mean you can break the glass on my back one. Leave it alone. And thinking that some community rep on the frontlines of a Twitter account can give permission to run a security exercise is totally asinine.
- jolmg 6y ago> Why do security people feel compelled to pen test sites without a contract or formal engagement? They didn't in this case. Though, maybe you could argue that the engagement wasn't formal enough. They found the initial hint of the bug from normal use, and requested permission before doing the actual pen test. Regarding the analogy, this isn't some random house they wanted to test. It's an essential service they used and depended on. Perhaps your analogy can be improved by them being an apartment building resident interested in the security issues of the building as a whole, since it affects the security of their own apartment. Even then, it doesn't seem like a perfect analogy that accurately reflects the situation. In the analogy, you could argue that they should change buildings if they're concerned, but banking options seem way more limited in comparison.