5 ms·
I think you're supposed to exploit the vulnerability in relatively innocuous but deeply disturbing ways, get banned, then complain about how you only meant well
by aneth 15y ago
I think you're supposed to exploit the vulnerability in relatively innocuous but deeply disturbing ways, get banned, then complain about how you only meant well, then be lauded on Hacker News as a martyr who should have been embraced by the hacked company.
- excerionsforte 15y agoI prefer the homakovs of the world rather than the Anons (they would take full advantage) of the world. To have one vulnerability that could lead to another is undesirable. Homakov's actions could be considered aggressive, but sometimes that's exactly what is needed in order to push something. (no pun intended)
- tptacek 15y agoThe world does not divide into those two kinds of people.
- excerionsforte 15y agoWho said it did? I surely did not and did not imply that at all. I simply expressed my preference of the interests of two kinds of people.
- thwest 15y agoWe can still agree homakov doesn't deserve this kind of lingering resentment on behalf of the OP.
- tptacek 15y agoI don't agree that there is resentment. That comment seemed to choose its words carefully to avoid judging. But ideally this isn't going to be a subject you & I are going to end up having to argue about today.
- rdtsc 15y agoOr rather you contact them. Then they ban you and possibly send the FBI after you for "illegally accessing a remote computer system" or other such crime and then you are punished for all your work. If you tell them you will disclose your research on a certain date they'll go after you for extortion. I wrote this before and I'll say it again. I don't believe in "White Hacker" as a label. Corporations do not do well when their vulnerabilities are exposed. They don't have a way to handle "White Hackers" unless they are the ones hiring them. Most will strike back and punch you in the face no matter how good your intentions are. So if you already spent the time researching and finding the vulnerability, just disclose on a security forum or if you want to profit, sell on a black market.
- sectek 15y agoI don't believe it is extortion since all he is asking them to do is fix their own vulnerability. I believe extortion requires the demand of money or services in exchange for action/inaction.
- tptacek 15y agoIf you tell them that unless they pay you or retain you as a contractor by a certain date that you'll publish, you are in fact extorting them. People who have found vulnerabilities and also been naive about the law have run aground on this before.