3 ms·
Not having a bug bounty or dedicated email address does not make it OK to go public immediately
by dust-jacket 5mo ago
Not having a bug bounty or dedicated email address does not make it OK to go public immediately
- mvdtnz 5mo agoYes it does actually.
- dust-jacket 5mo agoI don't feel like its hard to come up with examples where (I would say) its ethically wrong to disclose immediately. If you spotted a company's mistake that might endanger their user's lives or safety, would you put those users at risk simply because there was no obvious financial reward? If so, I guess we just have different opinions on the ethics involved here.
- alt227 5mo agoIf you are talking about some open source project then I would fully agree. But when it comes to money making corporations then personally I dont agree that revealing flaws in their product comes into ethics at all. A companies paid product is flawed, their own paid engineers didnt figure that out, why should I do it for free becasue 'ethics'? This is the entire reason bug bounty programs exist in the first place.
- fn-mote 5mo agoYou seem to have a very bright line between the acceptable behavior for “no money involved” and “money involved”. For me, it’s more subtle than that. Everybody (“almost all software”) has exploitable bugs. Are you a fool for not finding the ones in yours? Maybe. Sometimes. There is a huge difference between Project Zero finding a trivial vulnerability almost identical to one reported months earlier (close to negligence) and Mullvad having the CEO personally posting a response here in a very calm tone.
- alt227 5mo ago> Are you a fool for not finding the ones in yours? If I have a company which sells a paid product, and my paid engineers do not find bugs then I absolutely do not expect the public to willfully and freely make my product better for me. This is why I would have a bug bounty program as an incentive for the public to help me makle my product better and more secure, like any other company serious about finding security bugs. If I didnt have a bug bounty program and found out that some black hats were selling backdoors to my system online, I would consider that fully my fault for not incentivizing those hackers against doing so.
- autoexec 5mo agoDiscovering a bug that could put people's lives and/or freedom at risk if they don't do something about it makes it okay to go public immediately. That said, by all means notify the maintainer/vendor as well. It should always be assumed that someone else (if not several someone elses) have already discovered the same flaw and are currently taking advantage of it while users remain totally unaware of their actual risk. By going public immediately, you give as many of those users as possible a chance to protect themselves. Waiting to disclose something harmful when the users in danger could otherwise take steps to make themselves safe would be like not warning people entering a building not to go in because of a gas leak until after you've contacted the building owner and the fire department has shown up.
- hmry 5mo ago> Expecting people to hold off on disclosure of something harmful That's not what they said though. They said "please consider notifying the maintainer/vendor before publishing your findings, even if you intend to publish right away" (emphasis mine)
- autoexec 5mo agoI do think hitting "send" on the email to the responsible party immediately before publishing (or at least notifying them as quickly as you can afterwards) is a smart thing to do. I mean, why wouldn't you? My concern was more about the "Not having a bug bounty or dedicated email address does not make it OK to go public immediately" comment. It can sometimes be difficult to track down the right person to notify and so when the risks to people are high enough whichever one you can accomplish the soonest is probably where I'd start.
- hmry 5mo agoOh yeah fair enough
- fragmede 5mo agoDepending on the severity of the issue. Emailing support with a draft of the blog post and waiting even a couple of hours for a response so they can fix it first would have been more responsible than dropping the blog post to the whole wide world and catching Mullvad with their pants down.
- r_lee 5mo agoif they don't think it's OK, then they should have a bug bounty program. why are companies so entitled to get free security research/audits?