3 ms·
Surely a DM message to the AskAmex account, with some actual details written in clear English, not jargon or "hacker lingo stuff" would have been more suitable?
by Robin_Message 15y ago
Surely a DM message to the AskAmex account, with some actual details written in clear English, not jargon or "hacker lingo stuff" would have been more suitable? Or asking someone on here like Thomas to make a phone call?
I understand the argument between full disclosure and responsible disclosure, but if the author could have DM'd it on Twitter. Or posted it on Twitter wholesale, since its now public anyway.
- redthrowaway 15y agoThe operator of the AskAmex account seemed completely clueless on security-related matters. I doubt saying, "visit this URL: https://www.americanexpress.com/?debug=true&heroOverride=%3c%73%63%72%69%70%74%3e%61%6c%65%72%74%28%27%68%61%78%27%29%3c%2f%73%63%72%69%70%74%3e https://www.americanexpress.com/?debug=true&heroOverride... would have registered as a problem for her. AMEX made it incredibly difficult for this guy to report the issue to anyone who had the slightest clue as to its severity. Banging his head against the wall until someone finally clued in would not have fixed that communication issue. Full disclosure just might.
- Robin_Message 15y agoAll the more reason to make as clear and straightforward a declaration as possible. Not "I have vulnerabilities", but a DM saying "American Express is leaking customer information at this URL and it is imperative this is reported to your security department." It's their problem to escalate if they don't understand, but you have to give enough information to make escalation possible.
- danvideo 15y agoAgreed Robin - it's likely that the person operating the twitter account for most huge companies has minimal, if any, interaction with IT/security and its lingo. Speak plainly people.
- redthrowaway 15y agoHow much more plain than "Who can I contact regarding security vulnerabilities in your system" can you get? When she asked what kind of vulnerabilities, would saying, "unsecured admin panel and xss allowing for session jacking and spoofing" really have been more meaningful than what he said? Even saying "unsecured admin panel" on twitter would have sent people scrambling for it. He was attempting responsible disclosure before he turned to full disclosure.
- darklajid 15y agoRight. All you guys (not targeted specifically at you here) that say 'He tried it in a clear way': Call one of the lesser technical inclined people in your family/among your friends. Tell them you've just read about a security vulnerability and wonder if they could describe what that is to one (possibly less technical inclined) people in their family/among their friends. That's essentially what you're looking at if you throw these words at a corporate marketing (with some links to support) drone that needs to fill in his/her supervisors to make anything special happen.
- emp_ 15y agoYou cannot send a direct message to a user who is not following you.
- callahad 15y agoThat's no longer universally true: http://mashable.com/2011/07/05/twitter-dm-verified-account/ http://mashable.com/2011/07/05/twitter-dm-verified-account/