4 ms·
I also have a feeling sometimes the security team never gets to read it. The guy managing their twitter account has probably no clue of even what's going on. Hi
by SwaroopH 14y ago
I also have a feeling sometimes the security team never gets to read it. The guy managing their twitter account has probably no clue of even what's going on. His supervisor is too lazy to look into this further and asks him to send a template "we are secure" response. I really feel like security@website.com should become a standard for researchers to be able to at least talk to someone who understands what they are doing.
- mgkimsal 14y agoPerhaps with some formalized amnesty? If I go to the trouble of contacting you to tell you you've got a security problem, do not threaten to call the police or FBI on me. I've had that happen once, and I've tended to stay away from contacting places even when I saw they had a clear security violation, because a) I'm not sure how they'll react (will they claim I'm trying to extort them?) b) there's never any clear way to contact a company beyond calling/emailing 'customer support'. Occasionally I've tried to poke around my linkedin network to see if I had a connection at company X to reach out to their dev team and notify them of something, but I've never been successful that way (but also haven't pushed the issue much).
- SwaroopH 14y agoYup and with an auto-responder which states their policy + PGP keys.
- mgkimsal 14y agooooh - good idea. Even sometimes working inside a company when you see bad security, you can't do anything about it - I made another post about this separately.
- simonbrown 14y agoI think the best solution would be for more companies to publish a page on their website telling people what to do if they find a security problem, like GitHub and 37signals do (Google and Facebook also offer a bounty). I guess a problem with this is stating where the line is drawn. It might be difficult to promise not to sue well-intentioned researchers without reducing their ability to sue people with malicious intentions.
- nikcub 14y agoCompanies that have security pages and contact details are also companies that understand the importance of security issues. the problem here is that most companies do not understand the issue and tend to react defensively One solution might be using an agent - setup a clearing house for security issues run by a couple of trusted people. You log the issue, the clearing house gets in touch with the company and gives them access to the issue details. It keeps the person reporting the issue one step away from the company and any potential trouble. Once the company acknowledges and fixes the issue it is made public with an optional credit If they don't acknowledge the issue it becomes public anyway after x days.
- simonbrown 14y agoWhat stops them checking their logs to find your IP?
- nikcub 14y agohiding your real ISP IP isn't that big a deal for pen testers, either VPN or Tor I don't know many (I certainly don't) who use their real IP when probing sites