Live data from Hacker News

Security Researcher Assaulted Following Vulnerability Disclosure

secjuice.com

11–20 of 118 posts

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#11
post #9

I was once fired from a state job (USA) for bringing a vulnerability forward in the online ethics training. You can run "setScore(100, 0, 100)" in the developer console and pass the exam without actually taking it. (The state used a third party online exam provider who I contacted). I was fired by the end of the week

In that case you fail the test for showing a lack of ethics ;)

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#12
post #9

I was once fired from a state job (USA) for bringing a vulnerability forward in the online ethics training. You can run "setScore(100, 0, 100)" in the developer console and pass the exam without actually taking it. (The state used a third party online exam provider who I contacted). I was fired by the end of the week

Did you hire an attorney, or just move on with life?

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#14
So they agreed with them about the 60,000 bounty, were waiting for a NDA agreement with the lawyers, but this didn't happen fast enough for them and so they showed up unannounced to an important conference where the company was announcing a new product to question them about it.

Obviously assault is not right at all. But was this really the right way to check on the status of a security fix?

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#15
post #8

Wouldn't the Nevada Gambling Commission be interested in this?

I mean, maybe, but do you really think they have some sort of well-staffed cyber-division that would 1. understand this and 2. know what to do with it? My guess is they're still operating like it's the 1980s. Hopefully I'm wrong!

Curious that the FBI now does vulnerability coordination. Haven't ever heard that before.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#16

So they agreed with them about the 60,000 bounty, were waiting for a NDA agreement with the lawyers, but this didn't happen fast enough for them and so they showed up unannounced to an important conference where the company was announcing a new product to question them about it. Obviously assault is not right at all. But was this really the right way to check on the status of a security fix?

After getting ignored even when the FBI got involved? What would be the right way then?

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#18
post #15
post #8

Wouldn't the Nevada Gambling Commission be interested in this?

I mean, maybe, but do you really think they have some sort of well-staffed cyber-division that would 1. understand this and 2. know what to do with it? My guess is they're still operating like it's the 1980s. Hopefully I'm wrong! Curious that the FBI now does vulnerability coordination. Haven't ever heard that before.

There could be blanket clauses like reasonable efforts to secure private information, access controls, etc. They don't have to specify on the regulation what has to be done, just let prosecutors argue that it's not sufficient.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#19
post #15
post #8

Wouldn't the Nevada Gambling Commission be interested in this?

I mean, maybe, but do you really think they have some sort of well-staffed cyber-division that would 1. understand this and 2. know what to do with it? My guess is they're still operating like it's the 1980s. Hopefully I'm wrong! Curious that the FBI now does vulnerability coordination. Haven't ever heard that before.

My guess would be yes, since so much of gambling is electronic. "Wire fraud" is pretty old.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#20
post #9

I was once fired from a state job (USA) for bringing a vulnerability forward in the online ethics training. You can run "setScore(100, 0, 100)" in the developer console and pass the exam without actually taking it. (The state used a third party online exam provider who I contacted). I was fired by the end of the week

In that case you fail the test for showing a lack of ethics ;)

[deleted]
Post reply on HN