Live data from Hacker News

What to do when a company refuses to fix a vulnerability I disclosed to them?

reddit.com

31–40 of 74 posts

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#31
I don't know how big the company is, but after a certain bigness, all of the people who could fix problems like this have moved on. The only people left are managers who fix "problems" with lawyers. A classic "when all you've got's a hammer" situation.

They might not be refusing to fix the problem. They might actually be unable with the tech talent they've got left.

My advice? Don't look like a nail.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#32
post #22
post #5

I think you're supposed to exploit the vulnerability in relatively innocuous but deeply disturbing ways, get banned, then complain about how you only meant well, then be lauded on Hacker News as a martyr who should have been embraced by the hacked company.

Or rather you contact them. Then they ban you and possibly send the FBI after you for "illegally accessing a remote computer system" or other such crime and then you are punished for all your work. If you tell them you will disclose your research on a certain date they'll go after you for extortion. I wrote this before and I'll say it again. I don't believe in "White Hacker" as a label. Corporations do not do well wh…

I don't believe it is extortion since all he is asking them to do is fix their own vulnerability. I believe extortion requires the demand of money or services in exchange for action/inaction.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#33
post #26
post #7

Earlier quoted context omitted.

If you do publish it, odds are they'll issue a DMCA takedown and try to sue. My experience is quite to the contrary. Even Intel, as poor as their security response was, didn't try to take legal action against me. (I was lucky that I was unemployed at the time, though...)

> didn't try to take legal action against me But that is an interesting attitude. Instead of being indignant that they didn't offer to pay you for doing their security research for them ( or at least publicly thanking you) you just seem glad that they didn't sue you. It is like volunteering to help someone and then just being glad they didn't beat you up in the end. So it seems like there is not much benefit to doing…

Building a reputation can still be valuable. (E.g. Colin's work on hyper-threading and side channels did help me decide to sign up for tarsnap.)

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#34
post #5

I think you're supposed to exploit the vulnerability in relatively innocuous but deeply disturbing ways, get banned, then complain about how you only meant well, then be lauded on Hacker News as a martyr who should have been embraced by the hacked company.

I prefer the homakovs of the world rather than the Anons (they would take full advantage) of the world. To have one vulnerability that could lead to another is undesirable. Homakov's actions could be considered aggressive, but sometimes that's exactly what is needed in order to push something. (no pun intended)

The world does not divide into those two kinds of people.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#35
post #2

There are security companies that buy these kind of information from you (like antivirus companies), so that they can patch the breaches themselves and proudly announce they discovered a breach and only by using their software you can be protected. I don't know how legal it is, and I understand that the breach finder wants to publish his findings himself (for "reputations points" maybe ?), and he might lose this righ…

Nobody is going to buy a rate limiting bug in some random mobile application. Actually: nobody is going to buy a rate limiting bug at all.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#36
post #10

Public disclosure won't help btw. half of sites here didn't fix anything( http://homakov.blogspot.com/2012/03/hacking-skrillformer-mon... )

Did you reach out to each company and tell them, or did you assume that by creating a public blog post about them and submitting it to Hacker News they were bound to find out?

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#37
post #6

Nothing. If they're unwilling to fix it, they'll end up facing the consequences when someone less scrupulous than yourself discovers it. If you do publish it, odds are they'll issue a DMCA takedown and try to sue. Speaking from experience...

Security research is exempt from the DMCA. Even before the exemption, the DMCA applies only to vulnerabilities that circumvent content protection schemes.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#38

If only the company is put in danger and they stubbornly refuse to resolve the issue, I'm not exactly sure why anyone would work so hard to convince a company to do this. The job of reporting the issue is done, a corporate decision has been made. If that decision is to remain vulnerable, as long as it does not affect users directly, why bother? Unless, as others suggested, you can legally make a profit out of it, the…

I agree with you. Given some of the stories we've seen lately, my approach, after disclosing the vulnerability once, would be a three step process:

1) Do nothing. 2) Fuck 'em. 3) Not my problem.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#39
post #22
post #5

I think you're supposed to exploit the vulnerability in relatively innocuous but deeply disturbing ways, get banned, then complain about how you only meant well, then be lauded on Hacker News as a martyr who should have been embraced by the hacked company.

Or rather you contact them. Then they ban you and possibly send the FBI after you for "illegally accessing a remote computer system" or other such crime and then you are punished for all your work. If you tell them you will disclose your research on a certain date they'll go after you for extortion. I wrote this before and I'll say it again. I don't believe in "White Hacker" as a label. Corporations do not do well wh…

If you tell them that unless they pay you or retain you as a contractor by a certain date that you'll publish, you are in fact extorting them.

People who have found vulnerabilities and also been naive about the law have run aground on this before.

Post reply on HN