4 ms·
A day isn't really enough time to wait for a response. A critical ticket can be overlooked by an overworked help desk for days before it reaches anyone with aut
by alt_ 14y ago
A day isn't really enough time to wait for a response. A critical ticket can be overlooked by an overworked help desk for days before it reaches anyone with authority to schedule or, in the case of a contracted-out system, even hire someone to investigate the issue.
On the matter of disclosure after not receiving any reply within _weeks_, I have no personal experience (and IANAL), but I'd think a safe bet would be to set up a "Call for Assistance" blog post, or the like, announcing that you've discovered a bug in Company X's system, _without_ mentioning any details on how to reproduce it, but that you cannot reach them for responsible disclosure and asking anyone with contacts to the company to have them get back to you.
Give this a few more weeks or months and you should have enough evidence of good will to disclose the details.
- deleted 14y ago[deleted]
- alt_ 14y agoThe problem with this posting is just that you've already revealed details on what the exploit accomplishes and how to go looking for it. Revealing the company's identity now will narrow the search enough to make the disclosure irresponsible. This makes it harder to get help with contacting them.