4 ms·
I don't understand why that would be important. The only value in responsible disclosure is protection of users. If you figure out there's a way to harm a boat
by foerbert 5y ago
I don't understand why that would be important.
The only value in responsible disclosure is protection of users. If you figure out there's a way to harm a boatload of people, it's nice to do what you can to ensure it can't happen before telling everybody how. It makes sense. But there's a very good reason it comes with a not-too-distant deadline before you give up on it.
But this? We're talking about finding ways that people are being actively harmed. How does "responsible disclosure" come into play here?
The only thing it would seem to do is to protect companies and their bad decisions. That's not the point. At best they've screwed up, and at worst they're actively malicious. How do users not deserve to know that they are being harmed as soon as possible? How do potential users not deserve to know that they will be harmed by using the product, and that the company is either doing a poor job of protecting them or actively trying to exploit them?
There's no reason to try to attach any ideas of "responsible disclosure" here unless you're explicitly trying to protect the vendor.
- tailspin2019 5y agoI’m not suggesting a delay. Responsible disclosure was the wrong term to use. The distinction I was trying to draw is rather than just blogging about it or unleashing a Twitter storm and jumping straight to an adversarial public crucifixion of the vendor (and by all means do that as well), there should be a standardised process of also contacting that vendor directly and engaging with them to give them an opportunity to fully understand what is being reported, reproduce the issue (in the case of it being unexpected) and fixing the problem. Some vendors won’t engage or will stick their head in the sand, but others may actually choose to address the problem. This is also in the users’ best interests. Some issues will hit Hacker News or gain visibility in other ways, but other issues that are published may not naturally reach the eyes of someone at a vendor unless the person publishing actually takes steps to contact them. That’s the point I was trying to get across. Not suggesting any of that is a prerequisite to publishing anything publicly in parallel.