What to do when a company refuses to fix a vulnerability I disclosed to them?
1–10 of 74 posts
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#2I don't know how legal it is, and I understand that the breach finder wants to publish his findings himself (for "reputations points" maybe ?), and he might lose this right by selling an info, but at least he's getting something out of this. IANAL, but i'm pretty sure you could get in trouble for publicly posting information on how to hack a public service (or pretty much anything for that matter)
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#3Unless, as others suggested, you can legally make a profit out of it, then by all means! Otherwise, just let it go...
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#4Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#5Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#6Speaking from experience...
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#7Nothing. If they're unwilling to fix it, they'll end up facing the consequences when someone less scrupulous than yourself discovers it. If you do publish it, odds are they'll issue a DMCA takedown and try to sue. Speaking from experience...
My experience is quite to the contrary. Even Intel, as poor as their security response was, didn't try to take legal action against me. (I was lucky that I was unemployed at the time, though...)
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#8The correct way would be: 1) discover a vulnerability 2) contact them anonymously 3) if they don't fix it, anonymuosly release it to general public
That way, you can still help them while protecting yourself. The third step is optional of course.