3 ms·
Maybe the standard practice sucks. No matter how you turn it around, it does sound like blackmail. Just because you disclose a vulnerability to an org doesn’t m
by thiht 8mo ago
Maybe the standard practice sucks. No matter how you turn it around, it does sound like blackmail. Just because you disclose a vulnerability to an org doesn’t mean you have any right or legitimacy to impose a deadline on them, you’re not their boss. This is some vigilante shit and it has not justification whatsoever. Report to the org, report to the authorities as needed and move on.
- ThunderSizzle 8mo agoWithout a deadline of some form, when do you escalate to public knowledge so customers can know they might get defrauded in some capacity?
- rdtsc 8mo ago> Without a deadline of some form, when do you escalate to public knowledge so customers can know they might get defrauded in some capacity? You set a deadline after an initial conversation and urging them to fix it, if they don’t respond. I think the idea would be to escalate slowly. Like the original poster said large tech companies like know how to do this and streamlined the process. But, to someone not familiar with the process it looks like threats and deadlines imposed by a random person. I am not defending the company just presenting their possible point of view. It’s worth seeing things with their eyes so to speak to try to understand their motivations.
- master-lincoln 8mo agoBut that is the intention, isn't it? The company showed neglect. The researcher has a moral right ( and I would say duty) to make that public. It's nice of them to give the company some time to get their shit together. After the vulnerability has been fixed there is no issue for customers in publishing about the neglect. The bad press for the company is deserved.
- rdtsc 8mo agoThe idea was change the initial approach and not mention deadlines and just see if they’ll fix it. Point to the law indicating they should notify the authorities. Then if they don’t respond, give them a timeline tell them you’re notifying them. Like the original post said this is not Google, not a tech company, this looks like extortion of some sort to them. So it’s not that surprising what their response was. It all depends on the goal. Is the goal for them to fix it most of all? To get them embarrassed? To make a blogpost and get internet points?
- nebulous1 8mo agoBlackmail to gain what? Speedy update to the site? The OP is going to disclose the vulnerability. The only matter up for debate is the timing.