5 ms·
Black hat vs white hat. As soon as I would discover I could do that, I would inform the company not some scritkiddies on the internet. This is just irresponsi
by Demmme 3y ago
Black hat vs white hat.
As soon as I would discover I could do that, I would inform the company not some scritkiddies on the internet.
This is just irresponsible
- nextlevelwizard 3y agoHow often have we seen good intentions be punished?
- Demmme 3y agoMore often than not. I don't buy this and will not act shitty just because
- TeMPOraL 3y ago> This is just irresponsible And reporting to the vendor is suicidal. At least assuming the stories I hear about vulnerability disclosures are representative, which I think they are. In their place, if I were to inform the company, I'd do it anonymously. If it was an actually important issue - as this very much looks like - I'd consider informing the building manager, HOA, the gas installation company they use, and every local journalist, all together so they know about each other - and then CC that to the vendor.
- tgsovlerkhgsel 3y agoAnother option can be your country's CERT. In reasonably developed countries they generally have competent enough people to understand the concept of responsible disclosure (i.e. won't try to harass you for doing a good thing), and if they realize "oh shit, this is a critical infrastructure risk" they're probably in the best position to address not just the specific case, but also drive improvements (including via regulation) across vendors.
- TeMPOraL 3y agoYes, thank you. That's definitely a better option. And less hassle (and smalle risk of possible blowback) than making media (MSM or social) storm.