4 ms·
I’m glad they uncovered and reported this but I’d be super reluctant to actually log in using purloined credentials if I were them. As macNchz says elsewhere in
by eduction 2y ago
I’m glad they uncovered and reported this but I’d be super reluctant to actually log in using purloined credentials if I were them. As macNchz says elsewhere in this discussion, CISA/TSA/DHS does not appear to make any assurances that they won’t prosecute what appears to be a facial CFAA violation just because someone is doing valid security research.
To be clear, I really hope they don’t, but they are also clearly trying to spin this in a way at odds with the researchers, and I’d hate to be in a position where they want to have leverage over me if I’d done this.
Brave that they did so though and I do think the severity of the vuln warrants this.