7 ms·
tl;dr: Programmer doing competitive analysis on a competitor's new financial product discovers that it has poor security. Unsure of the how to correctly report
by jimrandomh 5y ago
tl;dr: Programmer doing competitive analysis on a competitor's new financial product discovers that it has poor security. Unsure of the how to correctly report vulnerabilities to the competitor, he raised the question to management inside his own company. His company's management, presumably not being infosec people, gets confused and the vulnerability report is lost in the corporate shuffle. Later, someone else rediscovers the same vulnerability and uses it to steal. The competitor that wrote the vulnerable app also botches the investigation, and blames the programmer, since his account appears in weird log-file entries from back when he was investigating.
I'd say the main mistake here was, after finding the vulnerability, handing off the reporting responsibility to people who couldn't handle that responsibility rather than handling it personally.