5 ms·
This is why I stand by anonymous public disclosure. Companies will not budget for security unless you make them.
by NinetyNine 15y ago
This is why I stand by anonymous public disclosure. Companies will not budget for security unless you make them.
- blahedo 15y agoIt's true. About five years ago my bank upgraded their systems and, no kidding, set everyone's password to their login name as part of the transition. When I called them on it, they stonewalled me and repeatedly claimed that I was being unreasonable, and as far as I know never fixed it, and fearing something like the OP I never pushed it. (I closed my account and switched banks.) Edit: My summary of that saga, posted at the time: http://www.blahedo.org/blog/archives/000836.html http://www.blahedo.org/blog/archives/000836.html
- nodata 15y ago"So, I sent a detailed email to the bank's address" I've found that a one-line response (i.e. no explaining why, no technical details, no explanations of explanations) generally works a lot better: "Wouldn't this mean that everybody now has easy to guess passwords?"
- kylec 15y agoAgreed. There is no such thing as "responsible disclosure". If you discover a security vulnerability, either say nothing and move your business elsewhere or make an anonymous public report. Identifying yourself only makes you a target.
- mkjones 15y agoIt's worth mentioning that some places embrace responsible disclosure, even going so far as to offer bounties when people do: Facebook: https://www.facebook.com/whitehat/bounty/ https://www.facebook.com/whitehat/bounty/ (disclaimer: I work here). Tarsnap: http://www.tarsnap.com/bugbounty.html http://www.tarsnap.com/bugbounty.html Mozilla: http://www.mozilla.org/security/bug-bounty.html http://www.mozilla.org/security/bug-bounty.html Chromium: http://blog.chromium.org/2010/01/encouraging-more-chromium-security.html http://blog.chromium.org/2010/01/encouraging-more-chromium-s...
- nitrogen 15y agoDoes anybody ever address the fact that you have to violate the TOS of most sites (even if unintentionally) to do any white hat discovery in the first place? Edit: though I do believe that reporting systems with bounties like those you linked are exactly the way to compete with the black market for vulnerabilities.
- tomjen3 15y agoThe problem is how can you be sure they will treat you nicely? I will grant you tarsnap is pretty safe since it is a one man operation and Mozilla and Chromium are both depending on the goodwill of the community, but Facebook is company which has been pretty aggressive in the way it shits over its users (I can remember about 3 or 4 privacy debacles).
- mkjones 15y agoI guess you have to trust that the company wouldn't go to the trouble of setting up a program (and making payouts) if it were going to treat vulnerability reporters poorly. I think treating them poorly is generally a pretty bad long-term plan though, because of the negative light it casts the company in, the lack of future responses it will garner, and the hostility it may bring out (hello, Sony). Do you feel like Facebook has ever "shit over" legitimate security researchers? I can see if I can help if you have examples.
- nl 15y agohttp://petewarden.typepad.com/searchbrowser/2010/04/how-i-got-sued-by-facebook.html http://petewarden.typepad.com/searchbrowser/2010/04/how-i-go...
- mkjones 15y agoI wasn't involved with that situation at all, but I don't think it involved any responsible disclosure of a security vulnerability.
- Volpe 15y agoSo release peoples private information, just to point out security flaws. He could have pointed out the security flaw without downloaded peoples details. Admittedly the reaction was over the top. But sending hundreds of peoples personal data around to 'prove' there is a security problem is a bit irresponsible.
- slowpoke 15y agoIt's not nearly as irresponsible as countless of companies straight out ignoring or even denying security breaches while trying to shoot the messenger. The sad truth is, you can only make these companies move by hurting them. Another sad truth is that the best (and more often than not the only) way to hurt these companies is to hurt their customers.
- ballard 15y agoHurting customers is like an issue group's protest blocking traffic. It doesn't make the average person want to help such a cause, quite the opposite. "Evil is a decision, often of unthinking, not to be honorable."