Live data from Hacker News

Ask HN: Found a leak of US citizens personal data. Should I report it?

news.ycombinator.com

71–80 of 85 posts

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#74

Earlier quoted context omitted.

Isn’t any group “vulnerable”? What does that word even mean?

Vulnerable groups are physically, mentally, or socially disadvantaged persons. Can be groups like disabled folks, migrants/refugees, and children.

Everyone is vulnerable when it comes to identity theft, but the OP’s position, should they notify anyone, is a lose-lose one regardless.

Morally they should “do the right thing”, but as many have explained in the comments, this will end up costing anything from reputation to money to freedom.

It really sucks that the only sane advice here is to sit on it and move on :(

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#75

Ask if they have a bug bounty program first. From ProtonMail.

Proton isn’t an anonymity silver bullet, and, as others have indicated, your opsec is generally worse than you believe it to be anyway.

Also, to have your first contact with the company be “I’ve found a problem and I want money” might get Legal rather than IT involved, and then you’re on the back foot.

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#76
post #70

These comments are doom and gloom from people who have read articles but haven't been there. I've reported over a dozen medium size leaks and not once has the company tried to come after me. They haven't all fixed them, and for those I haven't pushed, but most of the time they're grateful. If you're worried, contact Troy Hunt and have him be an intermediary for you, as others have suggested.

These comments are doom and gloom from people who have read articles but haven't been there. I've crossed the local railway tracks, blindfolded and earmuffed, for over a dozen times, and not once has a train hit me. If you're worried, contact a random australian dude working for one of the biggest cybersecurity threats on the planet, who also seems to pass time by counting cars that pass over a nearby bridge, and hav…

Have you ever disclosed a vulnerability? Ever had one to disclose?

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#77

These comments are doom and gloom from people who have read articles but haven't been there. I've reported over a dozen medium size leaks and not once has the company tried to come after me. They haven't all fixed them, and for those I haven't pushed, but most of the time they're grateful. If you're worried, contact Troy Hunt and have him be an intermediary for you, as others have suggested.

At best you get a pat on your back, at worst you go to jail: why should anyone take the chance?

For the same reason you should stand up to the police when you know your rights, because if you don't, what's the outcome then?

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#79

Maybe tell someone like Troy Hunt from haveibeenpawned. He has a pretty good reputation/following for verifying this kind of thing and telling the right people.

Or use one of the organizations that have a secure drop instance running [0]

[0] https://securedrop.org/directory/

Re: Ask HN: Found a leak of US citizens personal data. Should I report it?

#80

Ask if they have a bug bounty program first. From ProtonMail.

Proton isn’t an anonymity silver bullet, and, as others have indicated, your opsec is generally worse than you believe it to be anyway. Also, to have your first contact with the company be “I’ve found a problem and I want money” might get Legal rather than IT involved, and then you’re on the back foot.

Hi, do you have a bug bounty program? Or do you operate a private bug bounty program for security researchers? If so, what is the process to be invited?

No? Zerodium.

Post reply on HN