3 ms·
Wow look at that - once made aware of the vulnerability Onity responded with a fix. The last post I saw on this mentioned that the security researcher did not
by dos1 14y ago
Wow look at that - once made aware of the vulnerability Onity responded with a fix.
The last post I saw on this mentioned that the security researcher did not responsibly disclose the vulnerability because he just knew they wouldn't do anything. Looks like he was wrong.
- daeken 14y ago> The last post I saw on this mentioned that the security researcher did not responsibly disclose the vulnerability because he just knew they wouldn't do anything. Looks like he was wrong. I'm the security researcher in question (and author of this post). What a company does when pressured by their customer base and what they do when no pressures exist are two very, very different things. Had I approached them with these vulnerabilities ahead of time, it's highly likely that they would have used their considerable cash reserves to strong-arm me legally into not releasing this data, and the issue would not have been resolved. As I said in my original paper/slides, this was the best way to get the issue in front of hotel owners so that it could be resolved; this is the intended behavior.
- dos1 14y ago> I'm the security researcher in question (and author of this post). What a company does when pressured by their customer base and what they do when no pressures exist are two very, very different things Totally agreed. > Had I approached them with these vulnerabilities ahead of time, it's highly likely that they would have used their considerable cash reserves to strong-arm me legally into not releasing this data, and the issue would not have been resolved. I guess we'll never know will we? Edit: To be fair, I don't have a stake in this either way, and I'm glad the end result is that they're taking the threat seriously.