So they agreed with them about the 60,000 bounty, were waiting for a NDA agreement with the lawyers, but this didn't happen fast enough for them and so they showed up unannounced to an important conference where the company was announcing a new product to question them about it. Obviously assault is not right at all. But was this really the right way to check on the status of a security fix?
Security Researcher Assaulted Following Vulnerability Disclosure
21–30 of 118 posts
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#22I was once fired from a state job (USA) for bringing a vulnerability forward in the online ethics training. You can run "setScore(100, 0, 100)" in the developer console and pass the exam without actually taking it. (The state used a third party online exam provider who I contacted). I was fired by the end of the week
In that case you fail the test for showing a lack of ethics ;)
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#23> When one of the security researchers [approached Jessie at a conference] and introduced himself as the researcher who Jessie had been dealing with, Jessie suddenly lunged at the researcher and violently grabbed him by his clothes on his chest before then tearing his attendee badge away from him, telling the researcher that he didn't need it anymore and that he would keep hold of it.
It was in front of other people, at a conference, and all that the article admits to happening is "grabbing by clothes", "taking his badge", and angry words.
That was not worth my time.
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#24... so more than two thousand words into the article , having built up to the title of "assaulted" in the context of casinos (which have a movie reputation of hiring big boys to beat you up for things like counting cards and, apparently, vulnerability disclosure), and being a security guy myself, this is the entirety of the assault: > When one of the security researchers [approached Jessie at a conference] and introd…
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#25... so more than two thousand words into the article , having built up to the title of "assaulted" in the context of casinos (which have a movie reputation of hiring big boys to beat you up for things like counting cards and, apparently, vulnerability disclosure), and being a security guy myself, this is the entirety of the assault: > When one of the security researchers [approached Jessie at a conference] and introd…
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#26... so more than two thousand words into the article , having built up to the title of "assaulted" in the context of casinos (which have a movie reputation of hiring big boys to beat you up for things like counting cards and, apparently, vulnerability disclosure), and being a security guy myself, this is the entirety of the assault: > When one of the security researchers [approached Jessie at a conference] and introd…
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#27So they agreed with them about the 60,000 bounty, were waiting for a NDA agreement with the lawyers, but this didn't happen fast enough for them and so they showed up unannounced to an important conference where the company was announcing a new product to question them about it. Obviously assault is not right at all. But was this really the right way to check on the status of a security fix?
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#28I was once fired from a state job (USA) for bringing a vulnerability forward in the online ethics training. You can run "setScore(100, 0, 100)" in the developer console and pass the exam without actually taking it. (The state used a third party online exam provider who I contacted). I was fired by the end of the week
In that case you fail the test for showing a lack of ethics ;)
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#29Wouldn't the Nevada Gambling Commission be interested in this?
I mean, maybe, but do you really think they have some sort of well-staffed cyber-division that would 1. understand this and 2. know what to do with it? My guess is they're still operating like it's the 1980s. Hopefully I'm wrong! Curious that the FBI now does vulnerability coordination. Haven't ever heard that before.
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#30... so more than two thousand words into the article , having built up to the title of "assaulted" in the context of casinos (which have a movie reputation of hiring big boys to beat you up for things like counting cards and, apparently, vulnerability disclosure), and being a security guy myself, this is the entirety of the assault: > When one of the security researchers [approached Jessie at a conference] and introd…
That seems to meet the legal criteria for assault and possibly even battery. Quoting from https://www.nolo.com/legal-encyclopedia/assault-battery-aggr... :
"Assault is sometimes defined as any intentional act that causes another person to fear that she is about to suffer physical harm. This definition recognizes that placing another person in fear of imminent bodily harm is itself an act deserving of punishment, even if the victim of the assault is not physically harmed."
"Historically, battery and assault were considered separate crimes, with battery requiring that the aggressor physically strike or offensively touch the victim. In that way, a battery was a “completed” assault. Many modern statutes don't bother to distinguish between the two crimes, as evidenced by the fact that the phrase "assault and battery" has become as common as "salt and pepper." These days, statutes often refer to crimes of actual physical violence as assaults."