6 ms·
Seems like the responsible move would be for you to submit this to their bug bounty before disclosing to the community? https://bugcrowd.com/agilebits https://b
by quartz 5y ago
Seems like the responsible move would be for you to submit this to their bug bounty before disclosing to the community? https://bugcrowd.com/agilebits https://bugcrowd.com/agilebits
- akerl_ 5y agoWhy is that more responsible than telling users?
- jmull 5y agoMaking it public before there's been a chance to fix it gives attackers a chance to exploit it. Now, those so inclined know to monitor shared vaults.
- akerl_ 5y agoAttackers don’t have to wait til it’s public to exploit it.
- quartz 5y agoThere's a whole concept of responsible disclosure[1] in white-hat security research that involves notifying the company and then notifying the public after giving the company a chance to fix the bug. It's generally understood to be the most ethical approach. [1] https://en.wikipedia.org/wiki/Coordinated_vulnerability_disclosure https://en.wikipedia.org/wiki/Coordinated_vulnerability_disc...
- akerl_ 5y agoEven that page points out that “coordinated disclosure” is a more accurate term for what you’re describing. There are a wide variety of opinions in the industry about the merits of coordinated vs full disclosure. Calling one option “responsible disclosure”, or suggesting that it’s generally understood to be the most ethical, is outlandish.
- drcongo 5y agoI think they think it's a feature.
- mirashii 5y agoThis seems like a baseless assumption. Unless you have evidence actually suggesting otherwise, try assuming good faith. 1Pass isn’t incentivized to make decisions that compromise security.
- deleted 5y ago[deleted]