4 ms·
I would reserve judgment until seeing everything. I am just advocating from the general perspective of a security firm. I ran one for a decade and disclosed a l
by bitexploder 3y ago
I would reserve judgment until seeing everything. I am just advocating from the general perspective of a security firm. I ran one for a decade and disclosed a lot of vulns. My experience was almost always that vendors were the ones creating issues. We tried our best due to how sensitive issues can be and viewed each vendor or company as a potential customer. Rapid7 could have easily been rude or unreasonable, but that is not the norm for sure.
It probably was a little petty, but we don’t know what the lead up was either. You just get tired of being jerked around as a security firm when you do this a lot.