3 ms·
I think the best solution would be for more companies to publish a page on their website telling people what to do if they find a security problem, like GitHub
by simonbrown 14y ago
I think the best solution would be for more companies to publish a page on their website telling people what to do if they find a security problem, like GitHub and 37signals do (Google and Facebook also offer a bounty).
I guess a problem with this is stating where the line is drawn. It might be difficult to promise not to sue well-intentioned researchers without reducing their ability to sue people with malicious intentions.
- nikcub 14y agoCompanies that have security pages and contact details are also companies that understand the importance of security issues. the problem here is that most companies do not understand the issue and tend to react defensively One solution might be using an agent - setup a clearing house for security issues run by a couple of trusted people. You log the issue, the clearing house gets in touch with the company and gives them access to the issue details. It keeps the person reporting the issue one step away from the company and any potential trouble. Once the company acknowledges and fixes the issue it is made public with an optional credit If they don't acknowledge the issue it becomes public anyway after x days.
- simonbrown 14y agoWhat stops them checking their logs to find your IP?
- nikcub 14y agohiding your real ISP IP isn't that big a deal for pen testers, either VPN or Tor I don't know many (I certainly don't) who use their real IP when probing sites