4 ms·
I don't see how this is different from finding an ingenious way to jimmy open the lock of the door at night, figuring out how to take cash from the register, an
by Almaviva 11y ago
I don't see how this is different from finding an ingenious way to jimmy open the lock of the door at night, figuring out how to take cash from the register, and then phoning them up to tell them they need to spend money on a new door.
- chadscira 11y agoYes but this issue doesn't save customers from losing money or data so there isn't really a moral reason to disclose this. It directly impacts Starbucks, and their balance sheet. It's more like Jimmy phones up the owner, and tells the maid that there is an issue with the door, after not liking the maids response he tells a group of people about the issue, and the next day the house gets robbed...
- nothrabannosir 11y agoAm I missing something, or did you describe every bug bounty program everywhere? Isn't this exactly the definition of a security bug? Even in your dry analogy, what's the problem? Would you not want people to tell you they found a very easy way to take money out of the register? Not that it matters; this is text-book, industry standard security bug reporting. He waited with the public disclosure until it was fixed. (If he didn't; different story. Maybe I misunderstood that part? Was that it?)
- titanomachy 11y ago> After trying really hard to find anyone who cares, I managed to get this bug fixed in like 10 days. Sounds like it did get fixed, but it was a little confusing because he goes on to talk about how he could make millions counterfeiting gift cards.
- intrasight 11y agoIndeed. The author and the article lost what little credibility that existed at that point.
- TheCowboy 11y agoHow did he have little credibility? And how did he lose it? He spent his own time helping Starbucks improve their security. Starbucks insinuates or suggests he committed fraud and malicious actions for finding AND trying to alert them of the problem so that it could be fixed. Starbucks was out of line here, not him. While not eloquently expressed, it should still be obvious to most readers of this site that he is not implying that next time he will go and steal millions when he finds a bug. He is articulating that corporations that respond this way create a culture where they will only find out about vulnerabilities when it's too late, because no one will want anything to do with them. If anything, the more serious bug is the attitude of Starbucks as an institution here, and people not holding Starbucks accountable.
- maxerickson 11y agoA damaged lock needs to be replaced. If you must have an analogy, I think it's more like walking up to an unattended cash register during business hours and fiddling with it, figuring out how to take $0.10 out of it, and then putting the $0.10 back. Not clearly harmless (or it wouldn't make so many people object), but the counting of the damages stops at a quite low number.
- snowwrestler 11y agoNo, it's like seeing a door ajar, then calling the company to tell them that they forgot to close and lock their door. It takes a pretty dumb company to get mad about that.
- unethical_ban 11y agoSame way pirating a movie is the same as stealing a car.