4 ms·
There’s another path - open source disclosure. I’m not seeking pay, I’m not using it. I’m just putting it right out there in the open. Should the wrong parties
by feduphackers 4y ago
There’s another path - open source disclosure. I’m not seeking pay, I’m not using it. I’m just putting it right out there in the open. Should the wrong parties abuse it, oh well.
At this point in life, I feel “responsible disclosure” is just a PR tool for shit-birds to use to dodge accountability. The only thing they will respond to is pain.
- rtpg 4y agoI do not understand the "oh well if it gets exploited" vibe. It's not the company that suffers in that case, but users of the software! Now, you might want to somehow tell these users about this, so they can get off of the software. And there's this balancing act in that case... In the abstract universe where I have a nasty exploit and the company wants to ignore it, I suppose I would just try to loudly publish a first step which is like "hey, I have this PoC which gives me RCE with this software, and the company is ignoring it", without revealing the methodology at first. Perhaps at least publishing some mitigation strategies. I am not a security researcher, but I understand that this would be hard. But I think it's not honest to say that just dumping an exploit to the world is the best alternative to stonewalling.
- vlovich123 4y agoSometimes, but not always, the stock market reacts by tanking the stock price. So the company does sometime get punished. For some vulnerabilities the end user does still end up paying more anyway though.
- Mandatum 4y agoA hack has never impacted the stock price for a company for more than a week. Look at Equifax, it had almost doubled it's stock price between 2017 and 2022. That company should be dead. Sony, Deloitte, Marriott, Tumblr, Disney, Maersk.. There's no repercussions for companies who are hacked. Until GDPR style fines are dealt, and companies are taken out back by regulatory agencies and shot - this will continue.