Live data from Hacker News

What to do when a company refuses to fix a vulnerability I disclosed to them?

reddit.com

11–20 of 74 posts

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#11
From an ignorance and slightly tongue in cheek POV...

...is there a difference between discovering a new exploit and discovering a company is open to an old or well known exploit? This sounds like the latter.

I'm all for disclosure of a newly found exploit because by doing so you are informing every one who might have the problem and that allows them to take action, etc. But if this is just one business who refuse to fix a known problem then, well, that's their stupidity, no?

See, the bit that bothers me is that publishing the "news" that one company is vulnerable has to be a bit iffy. Its like publishing a list of buildings that don't have good door locks or something. We don't see that in the real world, so why would it be reasonable for the IT world? I mean, there is no legitimate list of vulnerable buildings created by white hat burglars, is there? Its never been legit for such burglars to gain access to a building and leave a note describing the poor security on the CEO's desk.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#13
post #11

From an ignorance and slightly tongue in cheek POV... ...is there a difference between discovering a new exploit and discovering a company is open to an old or well known exploit? This sounds like the latter. I'm all for disclosure of a newly found exploit because by doing so you are informing every one who might have the problem and that allows them to take action, etc. But if this is just one business who refuse to…

  Its never been legit for such burglars to gain access to a building and leave a note describing the poor security on the CEO's desk.
Unless, of course, you happen to be Richard Feynman. Which most of us aren't.

http://www.silvertrading.net/articles_lagniappe_01_richard_f...

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#14
post #2

There are security companies that buy these kind of information from you (like antivirus companies), so that they can patch the breaches themselves and proudly announce they discovered a breach and only by using their software you can be protected. I don't know how legal it is, and I understand that the breach finder wants to publish his findings himself (for "reputations points" maybe ?), and he might lose this righ…

The link mentioned responsible disclosure and it's wikipedia page ( http://en.wikipedia.org/wiki/Responsible_disclosure ) mention two of the primary players who buy vulnerabilities as you mention.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#15
Couldn't this vulnerability simply be published without mentioning who is directly affected? E.g. "under x and y circumstances, it is possible to do z and everyone is advised to check and correct this".

If this is not an option it means it is something very specific of that company, and what would be the purpose on releasing the vulnerability to the public?

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#17

If only the company is put in danger and they stubbornly refuse to resolve the issue, I'm not exactly sure why anyone would work so hard to convince a company to do this. The job of reporting the issue is done, a corporate decision has been made. If that decision is to remain vulnerable, as long as it does not affect users directly, why bother? Unless, as others suggested, you can legally make a profit out of it, the…

I think this raises two issues:

1) It can be difficult to know whether customers are (or could be) affected. Just because the author can't find the case doesn't mean someone else can't. 2) If the company refuses to fix this broken window, they may find other broken windows that aren't worth fixing, which may affect users. By releasing the vulnerability, one can force the company to become more conscious towards security in the long-term.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#18
post #5

I think you're supposed to exploit the vulnerability in relatively innocuous but deeply disturbing ways, get banned, then complain about how you only meant well, then be lauded on Hacker News as a martyr who should have been embraced by the hacked company.

I prefer the homakovs of the world rather than the Anons (they would take full advantage) of the world. To have one vulnerability that could lead to another is undesirable. Homakov's actions could be considered aggressive, but sometimes that's exactly what is needed in order to push something. (no pun intended)

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#19
You almost sound like you're laying down an ultimatum to the company, you've done your job by notifying them so let sleeping giants rest. If it's a known exploit I don't see any reason to publish your findings, if it's something you've come across that hasn't been published than by all means publish away.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#20
post #11

From an ignorance and slightly tongue in cheek POV... ...is there a difference between discovering a new exploit and discovering a company is open to an old or well known exploit? This sounds like the latter. I'm all for disclosure of a newly found exploit because by doing so you are informing every one who might have the problem and that allows them to take action, etc. But if this is just one business who refuse to…

>I mean, there is no legitimate list of vulnerable buildings created by white hat burglars, is there?

But the interesting question is not whether such a list has ever been written. The interesting question is whether such a list is legal to write.

Maybe such a list would be beneficial in the long run. Anyone who has practiced lock-picking knows that most lock-based security is little more than an elaborate honor system.

Post reply on HN