Live data from Hacker News

What to do when a company refuses to fix a vulnerability I disclosed to them?

reddit.com

41–50 of 74 posts

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#41
post #13

Earlier quoted context omitted.

Its never been legit for such burglars to gain access to a building and leave a note describing the poor security on the CEO's desk. Unless, of course, you happen to be Richard Feynman. Which most of us aren't. http://www.silvertrading.net/articles_lagniappe_01_richard_f...

I've had "Surely You're Joking" on my Kindle for almost a year now and have never read it, but every time I see anything written about Feynman I realize that I'm almost certainly missing out. He sounds like the most interesting man.

You are missing out on a readable book divided into short chapters. It's basically all anecdotes. Easy to intersperse with your other reading.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#42
post #34

Earlier quoted context omitted.

I prefer the homakovs of the world rather than the Anons (they would take full advantage) of the world. To have one vulnerability that could lead to another is undesirable. Homakov's actions could be considered aggressive, but sometimes that's exactly what is needed in order to push something. (no pun intended)

The world does not divide into those two kinds of people.

Who said it did? I surely did not and did not imply that at all. I simply expressed my preference of the interests of two kinds of people.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#44
I'm curious what we could change legally to make this less an issue. There's a clear conflict of interest between doing a public good by disclosing a vulnerability and not wanting to risk (at worst) the FBI coming after you or (at best) losing clients. I would certainly consider it unethical to know of a vulnerability and not disclose that information publicly, but there are so many hurdles to doing so that I don't blame some people (especially those who are less established) for not doing so.

It almost makes me feel that there should be a law requiring disclosure of vulnerabilities.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#47
post #26
post #7

Earlier quoted context omitted.

If you do publish it, odds are they'll issue a DMCA takedown and try to sue. My experience is quite to the contrary. Even Intel, as poor as their security response was, didn't try to take legal action against me. (I was lucky that I was unemployed at the time, though...)

> didn't try to take legal action against me But that is an interesting attitude. Instead of being indignant that they didn't offer to pay you for doing their security research for them ( or at least publicly thanking you) you just seem glad that they didn't sue you. It is like volunteering to help someone and then just being glad they didn't beat you up in the end. So it seems like there is not much benefit to doing…

It is like volunteering to help someone and then just being glad they didn't beat you up in the end.

I didn't publish the hyperthreading vulnerability to help Intel. I published it to help Intel's customers.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#48

If only the company is put in danger and they stubbornly refuse to resolve the issue, I'm not exactly sure why anyone would work so hard to convince a company to do this. The job of reporting the issue is done, a corporate decision has been made. If that decision is to remain vulnerable, as long as it does not affect users directly, why bother? Unless, as others suggested, you can legally make a profit out of it, the…

It appears he wants to publish the vulnerability (might be a novice security researcher) without getting sued.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#49
post #34

Earlier quoted context omitted.

I prefer the homakovs of the world rather than the Anons (they would take full advantage) of the world. To have one vulnerability that could lead to another is undesirable. Homakov's actions could be considered aggressive, but sometimes that's exactly what is needed in order to push something. (no pun intended)

The world does not divide into those two kinds of people.

We can still agree homakov doesn't deserve this kind of lingering resentment on behalf of the OP.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#50
post #49
post #34

Earlier quoted context omitted.

The world does not divide into those two kinds of people.

We can still agree homakov doesn't deserve this kind of lingering resentment on behalf of the OP.

I don't agree that there is resentment. That comment seemed to choose its words carefully to avoid judging.

But ideally this isn't going to be a subject you & I are going to end up having to argue about today.

Post reply on HN