4 ms·
I stopped reporting any security bugs I find in web apps because first time I did it I almost got arrested by the police. The second time I did it they contact
by rukshn 4mo ago
I stopped reporting any security bugs I find in web apps because first time I did it I almost got arrested by the police.
The second time I did it they contacted my employer directly without even getting back to me saying they were unhappy of me reporting it and wanted to write about it after they fixed the issue.
Since then I decided it’s not worth all the hassle and I will let them be and I can also have a peaceful day.
- lionkor 4mo agoYou could try reporting them (the exploits) anonymously to a government agency
- ranger_danger 4mo agoSo they can exploit it in secret for their own benefit?
- lionkor 4mo agoIf you have so little trust in your government (maybe you're American?) it might be time for change!
- voakbasda 4mo agoNo shit. Mind telling us how? Because elections sure aren’t going to do it. edit: sorry, there is so much of this sentiment, and the system is proven to be rigged. We know that things have gotten bad. Really bad. And there’s little hope of it self-correcting. The corruption is too deep and now seems unabashed. I seriously do want advice on how to change things, but three out of the four boxes meant to preserve liberty have proven to be inadequate. I see no future that doesn’t involve violent upheaval. Convince me otherwise.
- lionkor 4mo agoI agree with the violent upheaval idea. I believe that all systems which promote and enforce radical patriotism "no matter what" are bound to end up there. It's also getting more and more difficult for your country to keep allies, what with bombing and assaulting every single possible place for maximum profit extraction. Lots of people in the world have a hatred for the USA (as an entity) that is only paralleled by e.g. Nazi Germany. The only way to make a change is to get up and make a change, and if you can't because you're that deep in the hole, as you said, violent upheaval. I really wish that the USA would just wake up one morning and decide to make a change, without violence and bloodshed, to look at other Western countries for inspiration and create a more human society.
- ranger_danger 4mo agoConsidering Snowden files have shown they intentionally hoard 0days, I don't think it's so much a lack of trust as it is a proven track record of their behavior.
- phartenfeller 4mo agoThe German "Chaos Computer Club" (hacker club) has a disclosure service. They approach the affected party as the club, hiding the persons identity. Not sure if they do it internationally as the page is in German. But nice idea and not a government agency. https://www.ccc.de/disclosure https://www.ccc.de/disclosure
- Lukas_Skywalker 4mo agoThey did notify Collins Aerospace in the past, so I assume they do report internationally.
- p0w3n3d 4mo agoThat's really sad to hear, you must have felt really bad. Just because they do not know about the vulnerability, it won't disappear. And they won't fix it too. Ignorance is a bliss, but not in this case...
- SlightlyLeftPad 4mo agoIt should be obvious who the real criminals are in this case.
- snvzz 4mo ago[flagged]
- subscribed 4mo agoDo not bother. I was wearing a white hat professionally for quite a while but I can't fault you - at this point trying to be honest and helpful is dangerous. If you decide to sell the vulnerabilities, so be it.
- Permik 4mo agoIf you want to, you can report any vulnerabilities to the Finnish Cyber Security Centre and they'll handle all of the reporting and mediating the issue with the affected party. You can do this wholly anonymously, so you don't have to worry about some trigger-happy corpo ruining your life. Traficom's FCSC has been a great asset for white hat security reseachers globally by allowing them to just keep contributing to the common good.
- rvnx 4mo agoYou now have the worst of both worlds. You report yourself to the police for trying to hack into a computer-system and you report yourself to the website that can now decide to sue you. All of that without any benefits.
- Aachen 4mo agoIf it's anything like the Dutch or German infosec agencies, "worst of both worlds" is about as far from the truth as you can get. Maybe it works that way in Saudi Arabia but it's not "reporting yourself" here
- chadgpt3 4mo agoI wouldn't trust anything like that in Germany, where everything is rules-based. Hacking is illegal, so if the police find out you hacked and can prove it, they will arrest you and you will be convicted, period. In Germany there's no common sense applied to the rules. Arguing that you hacked and then reported it responsibly won't reduce your criminal penalty for hacking.
- ahartmetz 4mo agoApart from a certain general incompetence in IT related topics, common sense is a rather important part of German legal interpretation. Intention, proportionality and such. There are some infamous counter-examples, but you can find these in any country and it's these that make the news.
- 4mo ago
- harrouet 4mo agoSome may criticize regulations, but the EU-mandated cyber-resilience act (CRA) actually forced companies to have a clear contact point for vulnerabilities reporting, and to act upon it.
- hiAndrewQuinn 4mo ago2026-09-11, save the date folks. That's when all companies selling products with digital elements in the EU have to have a reporting pipeline for actively exploited vulnerabilities and severe incidents.
- avazhi 4mo ago[flagged]
- Izmaki 4mo ago[flagged]
- hennell 4mo agoI once tried to report an incident to a train line who had done "~a nice thing for a person~" and had photos about it on their social media. One photo was in their office and in front of a wall with a A4 page of usernames and logins for various systems on it. I tried three different contacts I could find, only one came back to me and wanted to know what the systems did what the risk was etc. I pointed out I have no idea, and I'm absolutely not logging into mysterious systems to find out - pass it to your own IT so they can see what needs to be changed, rotated etc. I did eventually get a message back from someone who thanked me for my diligence and said it was solved as they had now removed the photo... I really hope they had someone who understood look at it, but I decided not to engage further...
- lofaszvanitt 4mo agosell them to a vuln or exploit broker. problem solved.