5 ms·
No. Even though the company does not care about their lack of security, the OP could risk opening himself up to legal issues if he announces the exploit and pro
by mryan 11y ago
No. Even though the company does not care about their lack of security, the OP could risk opening himself up to legal issues if he announces the exploit and provides enough detail for it to be exploited.
- sneak 11y agoWhat legal issues, specifically?
- mryan 11y agoI'm not going to research specific statutes for you, if that's what you are asking. But some examples off the top of my head... Assume for the sake of argument that Nexmo is based in the UK. Using this exploit to access someone else's Nexmo.com account would be a violation of the Computer Misuse Act. Writing a blog post detailing exactly how you achieved this would be a public admission of violating the Computer Misuse Act. Another example: Person A publishes instructions detailing how to exploit this issue. Person B follows the steps, and causes financial harm to Nexmo. Nexmo sues Person B for exploiting their systems, and also names Person A in the lawsuit because their publication led directly to Person B's actions. I'm not certain either of these cases would hold up in court, but there is certainly a risk that Nexmo would take the second approach. In the OP's shoes, the safest thing is not to publish. I'm not saying that's the right choice - just the safest from a legal perspective.